公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-29 13:02 UTC

arenzana / arca

age-based, auditable, secret value encryption CLI. AI-agent friendly

GoMIT★ 1 星标⑂ 0 复刻始于 2026年6月在 GitHub 上查看 ↗

arenzana/arca 的健康指数为 100 分中的 64 分,处于「中等」区间。 其得分最高的类别是Security(78/100),最低的是Community & Adoption(43/100)。 最近一次更新在 2 天前。 近期的大部分工作由 1 位贡献者完成。

64
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

64
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

Ismael Arenzana个人账户
8 关注者24 个公开仓库始于 2013年7月

该仓库由个人账户拥有。相较于组织支持的项目,单一所有者项目的延续性风险更高。

软件包生态系统

注册表软件包版本月下载量版本数最近发布
Gogithub.com/arenzana/arcav0.9.0-162 天前

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

74良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 2 天前
3.5/36提交节奏 — 52 周中有 5 周有提交
18/18提交量 — 最近一年 135 次提交
0/10OpenSSF Scorecard:Maintained — project was created within the last 90 days. Please review its contents carefully
所用输入
commits_last_year135
human_commit_share0.87
days_since_last_push2
active_weeks_last_year5

发布纪律

98优秀
评分方式
27/27有发布版本 — 已发布 16 个发布版本
36/36发布时效 — 最近一次发布版本于 2 天前
27/27发布节奏 — 约每 2.8 天发布一次
8/10OpenSSF Scorecard:Signed-Releases — 5 out of the last 5 releases have a total of 5 signed artifacts.
所用输入
releases_count16
latest_release_tagv0.9.0
releases_from_tags
days_since_latest_release2
mean_days_between_releases2.8

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

43存在风险 · 占总体的 18%
评分方式
0/60星标 — 1 个星标
0/25复刻 — 0 个复刻
0/15关注者 — 0 位关注者
所用输入
forks0
stars1
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

92优秀
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(MIT)
18/18CONTRIBUTING 指南
13.5/13.5行为准则
0/7.2议题模板
6.3/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

52中等 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0/22.5提交分布 — 头号贡献者编写了 100% 的提交
1.4/13.5贡献者广度 — 1 位贡献者
0/10OpenSSF Scorecard:Contributors — project has 0 contributing companies or organizations -- score normalized to 0
所用输入
bus_factor1
contributors_sampled1
top_contributor_share1
评分方式
0/46.8议题解决 — 没有议题或无数据
35.9/38.3PR 接受 — 已裁定的 PR 中 106/113 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/22 approved changesets -- score normalized to 0
所用输入
merged_prs106
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs7
已排除计分(无数据或不适用):议题解决。 其余权重已重新归一化。
评分方式
10/30所有权背书 — 个人(用户)账户
0/20已验证域名 — 不适用于个人账户
6.9/25所有者影响力 — arenzana 有 8 位关注者
22.2/25既往记录 — 24 个公开仓库,账户约 13 年
所用输入
followers8
owner_typeUser
is_verified
owner_loginarenzana
public_repos24
account_age_days4,745
已排除计分(无数据或不适用):已验证域名。 其余权重已重新归一化。
评分方式
25/25已发布且可解析 — go 上有 1 个软件包
35/35发布时效 — 最近一次发布于 2 天前
20/20版本历史 — 16 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesgithub.com/arenzana/arca
ecosystemsgo
any_deprecated
min_days_since_publish2

工程质量

基础的工程与文档实践是否到位?

77良好 · 占总体的 20%

工程实践

68中等
评分方式
24/24CI 工作流 — 8 个工作流
24/24存在测试
0/16Linter 配置
0/9.6Pre-commit 钩子
0/6.4.editorconfig
20/20OpenSSF Scorecard:CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

90优秀
评分方式
30/30README
25/25文档目录
15/15文档 / 主页站点 — https://arenzana.github.io/arca/
10/10仓库描述
0/10主题标签
10/10Wiki
所用输入
topics
has_wiki
homepagehttps://arenzana.github.io/arca/
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

78良好 · 占总体的 16%

安全态势

72良好
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0.5/2.5CII-Best-Practices — badge detected: InProgress
0/7.5Code-Review — Found 0/22 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5许可证 — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
5/5Pinned-Dependencies — all dependencies are pinned
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
6/7.5Signed-Releases — 5 out of the last 5 releases have a total of 5 signed artifacts.
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
4.5/7.5Vulnerabilities — 4 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate7.2
评分方式
35/35直接依赖不含已知公告 — 没有直接依赖携带已知公告
0/25间接依赖不含已知公告 — 在此范围内,传递依赖集合无法与开发和测试依赖区分
0/40没有长期未处理的公告 — 没有公告带有发布日期
所用输入
sourceosv
advisories4
affected_packages4
assessed_packages38
unassessed_packages0
affected_by_severityunknown 4
direct_affected_packages0
已排除计分(无数据或不适用):间接依赖不含已知公告, 没有长期未处理的公告。 其余权重已重新归一化。 已将 38 个已解析依赖与 OSV 比对。 该仓库未发布任何索引可解析的软件包,因此改为评估仓库依赖图。该图将开发与测试版本固定同交付的依赖混在一起,因此仅对声明的运行时依赖计分;传递性发现仅作为背景信息列出,不计入评分。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

69中等 · 占总体的 0%
评分方式
0/45代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 87 次人类提交中有 87 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
评分方式
18/18一条命令的引导启动 — Makefile
22/22自动化测试
0/11Lint / 格式化配置
11/11静态类型检查 — Go(静态类型)
10/10可复现环境 — lockfile
0/10已体现的代理实践 — 最近 100 次提交中没有代理编写的提交
8/8自动化维护 — 最近 100 次提交中有 13 次为自动依赖更新
10/10OpenSSF Scorecard:Pinned-Dependencies — all dependencies are pinned
所用输入
has_nix
has_tests
lockfilesgo.sum
has_dockerfile
typed_language
bootstrap_filesMakefile
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0
toolchain_manifestsgo.mod, tools/docsgen/go.mod
dependency_bot_commit_share0.13
评分方式
45/45可类型检查的代码 — Go(静态类型)
54.5/55可控的文件大小 — 采样的 100 个源文件中有 1 个超过 60KB
所用输入
primary_languageGo
largest_source_bytes90,985
source_files_sampled100
oversized_source_files1

关键数据

1GitHub 星标
1贡献者
135最近 12 个月提交数
2距最近推送天数
16发布版本数
1巴士系数(bus factor)
0开放议题
Go软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

更多细节

OpenSSF Scorecard 7.2 / 10
7.2综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-29 13:02 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
2CII-Best-Practicesbadge detected: InProgress
0Code-ReviewFound 0/22 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
10Pinned-Dependenciesall dependencies are pinned
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
8Signed-Releases5 out of the last 5 releases have a total of 5 signed artifacts.
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
6Vulnerabilities4 existing vulnerabilities detected
直接依赖 6
注册表软件包版本约束清单文件
Gofilippo.io/agev1.3.1go.mod
Gogithub.com/mark3labs/mcp-gov0.57.0go.mod
Gogithub.com/minio/minio-go/v7v7.2.1go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogolang.org/x/termv0.45.0go.mod
Gomodernc.org/sqlitev1.54.0go.mod
全部依赖 38

来自 GitHub 依赖图的完整解析依赖集合:6 个直接依赖与 32 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
Gofilippo.io/agev1.3.1直接
Gogithub.com/mark3labs/mcp-gov0.57.0直接
Gogithub.com/minio/minio-go/v7v7.2.1直接
Gogithub.com/spf13/cobrav1.10.2直接
Gogolang.org/x/termv0.45.0直接
Gomodernc.org/sqlitev1.54.0直接
Gofilippo.io/hpkev0.4.0间接
Gogithub.com/cespare/xxhash/v2v2.3.0间接
Gogithub.com/dustin/go-humanizev1.0.1间接
Gogithub.com/google/jsonschema-gov0.4.2间接
Gogithub.com/google/uuidv1.6.0间接
Gogithub.com/inconshreveable/mousetrapv1.1.0间接
Gogithub.com/klauspost/compressv1.18.6间接
Gogithub.com/klauspost/cpuid/v2v2.2.11间接
Gogithub.com/klauspost/crc32v1.3.0间接
Gogithub.com/mattn/go-isattyv0.0.22间接
Gogithub.com/minio/crc64nvmev1.1.1间接
Gogithub.com/minio/md5-simdv1.1.2间接
Gogithub.com/ncruces/go-strftimev1.0.0间接
Gogithub.com/philhofer/fwdv1.2.0间接
Gogithub.com/remyoudompheng/bigfftv0.0.0-20230129092748-24d4a6f8daec间接
Gogithub.com/rs/xidv1.6.0间接
Gogithub.com/santhosh-tekuri/jsonschema/v6v6.0.2间接
Gogithub.com/spf13/castv1.7.1间接
Gogithub.com/spf13/pflagv1.0.10间接
Gogithub.com/tinylib/msgpv1.6.1间接
Gogithub.com/yosida95/uritemplate/v3v3.0.2间接
Gogithub.com/yuin/goldmarkv1.8.4间接
Gogithub.com/zeebo/xxh3v1.1.0间接
Gogo.yaml.in/yaml/v3v3.0.4间接
Gogolang.org/x/cryptov0.53.0间接
Gogolang.org/x/netv0.55.0间接
Gogolang.org/x/sysv0.47.0间接
Gogolang.org/x/textv0.38.0间接
Gogopkg.in/ini.v1v1.67.2间接
Gomodernc.org/libcv1.74.1间接
Gomodernc.org/mathutilv1.7.1间接
Gomodernc.org/memoryv1.11.0间接
依赖安全公告 4

该仓库未发布可被索引解析的包,因此评估的是其自身的依赖图——共 38 个包,其中也包含从不交付的开发与测试版本固定:4 个存在已知公告,0 个为直接依赖。

软件包版本关系严重程度公告数修复版本
github.com/klauspost/compressv1.18.6间接未知11.18.7
golang.org/x/cryptov0.53.0间接未知1
golang.org/x/netv0.55.0间接未知10.56.0
golang.org/x/textv0.38.0间接未知10.39.0

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 2053,
      "has_wiki": true,
      "homepage": "https://arenzana.github.io/arca/",
      "languages": {
        "Go": 883147,
        "Makefile": 1189
      },
      "pushed_at": "2026-07-27T11:59:09Z",
      "created_at": "2026-06-29T18:51:57Z",
      "owner_type": "User",
      "updated_at": "2026-07-27T10:11:05Z",
      "description": "age-based, auditable, secret value encryption CLI. AI-agent friendly",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://arenzana.org",
      "name": "Ismael Arenzana",
      "type": "User",
      "login": "arenzana",
      "company": null,
      "location": "Fort Wayne, IN & Madrid, Spain",
      "followers": 8,
      "avatar_url": "https://avatars.githubusercontent.com/u/5133407?v=4",
      "created_at": "2013-07-31T23:31:42Z",
      "is_verified": null,
      "public_repos": 24,
      "account_age_days": 4745
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-07-27T12:03:37Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-07-24T09:55:51Z"
        },
        {
          "tag": "v0.7.2",
          "kind": "patch",
          "published_at": "2026-07-20T14:08:04Z"
        },
        {
          "tag": "v0.7.1",
          "kind": "patch",
          "published_at": "2026-07-10T09:53:23Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-07-09T15:08:52Z"
        },
        {
          "tag": "v0.6.5",
          "kind": "patch",
          "published_at": "2026-07-09T09:17:55Z"
        },
        {
          "tag": "v0.6.4",
          "kind": "patch",
          "published_at": "2026-07-08T12:36:21Z"
        },
        {
          "tag": "v0.6.3",
          "kind": "patch",
          "published_at": "2026-07-03T14:49:26Z"
        },
        {
          "tag": "v0.6.2",
          "kind": "patch",
          "published_at": "2026-07-03T12:54:34Z"
        },
        {
          "tag": "v0.6.1",
          "kind": "patch",
          "published_at": "2026-07-02T13:55:52Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-07-01T20:53:37Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-07-01T20:34:28Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-07-01T12:47:06Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-06-30T14:49:11Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-06-30T13:08:43Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-06-29T21:26:20Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "d4266fc063fe16f1045ea891941c03548a7aa735",
          "body": "…idual (#112)\n\nS6 docs: remove a dangling (see T15) cross-reference in the T2 residual and reword the $ARCA_AUDIT hatch note; document the D4 residual in CONFIGURATION.md — two spellings of one store still key to two state dirs if you symlink the store *file* (symlinks resolve on the directory, not the file) or if the parent dir doesn't exist when the key is first computed. A split is the safe direction (state looks fresh; arca doctor names the dirs to merge).",
          "is_bot": false,
          "headline": "docs: correct two S6 prose claims + document the statedir symlink res…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-27T10:09:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e7acf1a1f6bf266d6b1f6d1600fbe6c4cae3dea9",
          "body": "…tes (#114)\n\nRe-applied dependabot's SHA-pin bumps onto current main (preserving the gofmt\ngate #104 added to ci.yml) and signed to satisfy the DCO check. Supersedes #114's\noriginal commit.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>\nCo-authored-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": true,
          "headline": "build(deps): bump the gh-actions group across 1 directory with 5 upda…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-27T09:29:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e5b0acbf4b290d67ef35119a73a70e21253128b3",
          "body": "…#113)\n\nRe-applied via go get on current main and signed to satisfy the DCO check\n(dependabot's own commit carries no Signed-off-by). Supersedes #113's original.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>\nCo-authored-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": true,
          "headline": "build(deps): bump github.com/mark3labs/mcp-go from 0.56.0 to 0.57.0 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-27T09:24:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "65881bd252a23dab737ecd098eb7cefd71a3aa36",
          "body": "S22: go vet, staticcheck and gosec don't check formatting, so unformatted code merged silently. Add a gofmt step to the existing lint job (not a new job — a new job's context isn't in the required set, so it would look gated and not be). Tests the output of gofmt -l (which exits 0 even when it lists files) and prints the diff on failure.",
          "is_bot": false,
          "headline": "ci: gate gofmt in the lint job (#104)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-27T09:13:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8bc3e00a7b8230bb7e256d140bb18649b197843d",
          "body": "S19: set/generate could relax an existing secret's policy headless (--require-approval=false, --no-print=false, --require-grant=false, --rate \"\", --canary=false) — a control-plane change wearing a write command's clothes. Now anchored via requirePolicyOperator, with a deliberately narrow predicate: \n[…]\nintact.\n\nThreat model: T13's five relaxation flags close; the residual narrows to expiry extension. The now-closed sync-locking (#106) and MCP-unbounded (#105) findings are removed from Open findings.",
          "is_bot": false,
          "headline": "sec: anchor policy downgrades on set/generate (T13/R28) (#110)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-27T09:04:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4672ff60606084cf70d1f6ec2b42fe1313ac332b",
          "body": "R2: run_with_secrets / run_with_handle capped their child's captured output (1 MiB/stream, ARCA_MCP_MAX_OUTPUT) with a truncation notice, and give the child a wall-clock deadline (120s, ARCA_MCP_TIMEOUT); both overrides are clamped to a range so an agent that owns the env can't spell 'unlimited'. Th\n[…]\nest.go moves to //go:build e2e && !windows (syscall.Rlimit is undefined on Windows) so the e2e package compiles for Windows and e2e (windows) actually runs its tests instead of silently building zero.",
          "is_bot": false,
          "headline": "fix(mcp): bound exec-tool output and runtime; disable core dumps (#105)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-27T08:51:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2d2b3b2cf12d966714081d98cb1d9780ee11c7c4",
          "body": "…ack (#111)\n\nS7 (R16/R17/R18): centralize atomic file publishing in internal/atomicfile (write temp → fsync → rename → fsync parent dir), adopted by the store save and the state-dir writers.\n\n- R16: the store generation is bumped only AFTER the write that can fail succeeds, so a failed save no longe\n[…]\n can lose a concurrent-access race with 'access denied' — documented as availability, not a splice; tests tolerate it on Windows and keep the no-splice integrity assertion for successful ops (W3/W4b).",
          "is_bot": false,
          "headline": "fix: durable state writes; a failed save no longer looks like a rollb…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-27T08:44:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d9365b5ffabbc3445a0604d4c0c02087e9b94dc6",
          "body": "S4 (R1/D1): sync does all network I/O outside the store lock, then re-evaluates and commits under the lock conditional on the generation not having advanced (a local CAS mirroring the backend's) — no backend call while the lock is held, every state write under the lock. Stops an auto-sync pull silen\n[…]\n (cross-store clobber + false rollback alarm).\n\nS6 (R4/D2): a detected agent with $ARCA_AUDIT != default is refused (not silently redirected); an unrecordable canary trip fails the call (fail-closed).",
          "is_bot": false,
          "headline": "sec: sync-lock CAS, per-store state dir, audit-path refusal (#106)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-27T08:29:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c17431741dfa239eee246af4aa1ef02dac2b6f83",
          "body": "…x (#108)\n\nS3: requireOperator() anchors grant, agent allow, recipients add, reencrypt, enable and handle create to an interactive terminal (T11/T12/R27) — refuse a detected agent, otherwise confirm on /dev/tty (CONIN$/CONOUT$ on Windows), no env bypass. Also audits recipients add + adds secret-scan\n[…]\nose on the expiry path; e2e now bounds every child with a ctx deadline and checks ctx.Err() before the *exec.ExitError branch so a hang can't read as a green pass. Proven by e2e (windows) going green.",
          "is_bot": false,
          "headline": "sec: anchor the control plane to an operator terminal + W1 Windows fi…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-27T08:15:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bc194c23eac1abd4c51023a9bcd7be44acfe95c7",
          "body": "* fix: refuse an empty value that would destroy a stored secret (R3)\n\n`readValue` returned an empty slice with no error, so a pipe whose producer\nfailed silently replaced a real secret with nothing:\n\n    vault-cli read prod/key | arca set PRODKEY   # producer fails, prints nothing\n    Stored PRODKEY\n[…]\n only the disabled state refuses.\n\nCo-authored-by: Ismael Arenzana <isma@arenzana.org>\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>\n\n---------\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "S1: empty value and disabled handle (#107)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-26T07:05:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f984ce5a3c2550a0e7fb1cf3524addf5f4233e5a",
          "body": "…w self-heal (#103)\n\nBundles the feat/user-safety work: arca doctor health check, exposure visibility (who-can-read + recipient labels), safer agent defaults (deny-by-default MCP exposure under --strict), and audit-escrow self-heal + `sync reset-escrow`. See PR #103 for detail.",
          "is_bot": false,
          "headline": "user-safety: doctor, exposure visibility, safer agent defaults, escro…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-24T09:50:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7cc9c60693f3a7142cb406b0cf018619637f7699",
          "body": "…tes (#101)\n\nBumps the gh-actions group with 5 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [actions/setup-go](https://github.com/actions/setup-go) | `6.5.0` | `7.0.0` |\n| [github/codeql-action/init](https://github.com/github/codeql-action) | `4.37.0` | `4.37.1` |\n| [gi\n[…]\n version-update:semver-patch\n  dependency-group: gh-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump the gh-actions group across 1 directory with 5 upda…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T14:02:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0338aa35ecb9b83504a9cf4e6e7e6ab58ad6ccdb",
          "body": "Bumps the go-deps group with 1 update: [modernc.org/sqlite](https://gitlab.com/cznic/sqlite).\n\n\nUpdates `modernc.org/sqlite` from 1.53.0 to 1.54.0\n- [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md)\n- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.53.0...v1.54.0)\n\n\n\n---\nupd\n[…]\npe: version-update:semver-minor\n  dependency-group: go-deps\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump modernc.org/sqlite in the go-deps group (#100)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T13:55:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d1b63453fdfebd65c6d0eb1996d176106d6eba10",
          "body": "The post-command auto-sync (PersistentPostRun) printed the same\ninformational notices as an explicit `arca sync` — \"in sync: nothing to\ndo\", \"pushed/pulled generation N\". After `arca get NAME`, whose value is\nwritten with no trailing newline so it pipes cleanly, that notice landed\non the same termin\n[…]\ning,\n  so no stray blank line appears.\n\nAdds TestSyncQuietSuppressesInformationalOutput, TestNewlineGuard, and\nTestAutoSyncOutputNeverTrailsCommand.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "sync: make opportunistic auto-sync quiet and non-colliding (#102)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-20T13:32:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b744f6a89b94616e19c98110160a394c037e5cd2",
          "body": "…SEC-43) (#99)\n\nThe SEC-39 segment-key shape check used \\d{6}, but the writer keys segments\nwith %06d — a MINIMUM width, so a Seq past 999999 emits 7+ digits. An exact-6\nregex would reject arca's own segment as 'injected' and break\nlog --verify --remote permanently. \\d{6,} matches the zero-padded-mi\n[…]\n.go\ncomment (the code does fsync before rename). No behavior change beyond the\nregex; the audit otherwise found the code clean (no new HIGH/MEDIUM).\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "fix: escrow key regex accepts the writer's own keys past seq 999999 (…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-13T08:30:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "20f57febc649d3d559f5d1dca5e682a576952748",
          "body": "Bumps the gh-actions group with 1 update in the / directory: [lycheeverse/lychee-action](https://github.com/lycheeverse/lychee-action).\n\n\nUpdates `lycheeverse/lychee-action` from 2.8.0 to 2.9.0\n- [Release notes](https://github.com/lycheeverse/lychee-action/releases)\n- [Commits](https://github.com/ly\n[…]\n version-update:semver-minor\n  dependency-group: gh-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump lycheeverse/lychee-action (#98)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-13T08:09:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6d6b1766e045798c08484acc9e88b516f1a73399",
          "body": "… (#97)\n\nBumps the go-deps group with 2 updates in the / directory: [github.com/mark3labs/mcp-go](https://github.com/mark3labs/mcp-go) and [golang.org/x/term](https://github.com/golang/term).\n\n\nUpdates `github.com/mark3labs/mcp-go` from 0.55.1 to 0.56.0\n- [Release notes](https://github.com/mark3labs\n[…]\npe: version-update:semver-minor\n  dependency-group: go-deps\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump the go-deps group across 1 directory with 2 updates…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-13T08:03:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "15f708bafb661d1e46c661db4c4741b46dc38f8e",
          "body": "Bumps the docsgen-deps group in /tools/docsgen with 1 update: [github.com/yuin/goldmark](https://github.com/yuin/goldmark).\n\n\nUpdates `github.com/yuin/goldmark` from 1.8.2 to 1.8.4\n- [Release notes](https://github.com/yuin/goldmark/releases)\n- [Commits](https://github.com/yuin/goldmark/compare/v1.8.\n[…]\nersion-update:semver-patch\n  dependency-group: docsgen-deps\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump github.com/yuin/goldmark (#96)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-13T07:56:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bd8618349f4579a4e0e8851cc3a3b0b5fbd2032f",
          "body": "…tup walkthrough (#95)\n\nThe README Features table and docs index never listed sync, so the whole\nmulti-machine feature was invisible on the front page and the published\ndocs site. Adds a Sync feature row and a SYNC.md link.\n\nSYNC.md's 'a new machine just needs identity + URL' line became incomplete\n\n[…]\nrant + reencrypt + push → sync init --store-credentials →\npull), the stdin credential-passing pattern for remote hosts, and how to\nremove a machine.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "docs: surface multi-machine sync on the landing page + add a fleet se…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-10T10:50:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "63a09403b392b9f8fd6ae74bd3aa9311374db30c",
          "body": "…5..42) (#94)\n\nFrom the 2026-07-10 audit. Logic-level defenses only; the complete fix for\nthe store authenticity gap (an operator signature over the store) is a\ntracked follow-up.\n\n- SEC-35 (HIGH): pull refuses replay/rollback/recipient-broadening. The\n  rollback floor is the DURABLE high-water mark\n[…]\ned), escrow truncation + injected-key, atomic 0600 rewrite,\nS3 read-after-write + size cap via an httptest S3. Real-MinIO e2e green.\nCoverage 90.1%.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security(sync): harden the untrusted-backend pull/escrow paths (SEC-3…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-10T09:49:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b6ccc8b7458f83c9042f0eb6d6594b24b6e44aa4",
          "body": "nfpm inside the existing goreleaser run: linux amd64/arm64, reproducible\nmtimes pinned to the commit like the archives, LICENSE/README under\n/usr/share/doc/arca. The packages land in checksums.txt, so the cosign\nbundle over the checksums covers them with no new signing machinery.\nVerified by installing the snapshot rpm on Rocky 9 and the deb on\nDebian 12 in containers.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "feat(release): ship .rpm and .deb packages as release assets (#93)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-10T09:08:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed215c0f0855c9edebb804a0f61190f585846506",
          "body": "Signed-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "docs: stamp CHANGELOG v0.7.0 (2026-07-09) (#92)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-09T15:04:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9765b0b2f9024795a1f9957048ed9436c40b26bb",
          "body": "…#91)\n\n* feat(sync): optionally persist backend credentials in the state dir\n\nSync credentials came from the environment only, which made automatic\nsync depend on ambient exports — exactly what retiring the env-file\nsecrets workflow removed. 'sync init URL --store-credentials' persists\nthe ARCA_SYNC\n[…]\nal call, not the struct fields; the\n  nosec justification now sits on the right line.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>\n\n---------\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "feat(sync): optionally persist backend credentials in the state dir (…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-09T14:50:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "eb510e590f7f200877cf93f8649569d841e06004",
          "body": "… and audit escrow (#90)\n\n* feat: arca sync — multi-machine replication through an S3-compatible backend\n\nReplaces 'keep the store file in a git repo' as the only sync story.\n\n- internal/remote: Backend interface (Head/Fetch/Push/PutIfAbsent/Get/List),\n  S3 implementation on minio-go with conditiona\n[…]\n>\n\n* test: skip the read-only-dir Save case on Windows (perm bits are advisory there)\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>\n\n---------\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "feat: arca sync — S3 replication with envelope encryption, auto mode,…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-09T10:15:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "99b4186b980520ff09960d850a36988858a42b98",
          "body": "Signed-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "docs: stamp CHANGELOG v0.6.5 (2026-07-09) (#89)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-09T09:14:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9892e7b8beff267a458a1061e432bf268a75c4ea",
          "body": "The nightly govulncheck failed: GO-2026-5856 in crypto/tls, reachable\nvia crypto.Decrypt -> age.Decrypt -> tls.Conn.Read (age's plugin path),\nfixed in Go 1.26.5. go.mod only said 'go 1.26' so CI built with the\nrunner's cached 1.26.4. Pinning the toolchain makes setup-go install\n1.26.5 across every workflow; govulncheck is clean on it.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "fix: pin toolchain go1.26.5 (GO-2026-5856, crypto/tls) (#88)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-09T09:05:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0818c651d2294982ea29d07853eaf3a0f50e295d",
          "body": "Also adds the missing 0.6.3 compare link and repoints Unreleased.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "docs: stamp CHANGELOG v0.6.4 (2026-07-08) (#87)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-08T12:32:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f2152c82aa324b5bae1401a05e0ba719bc1adf2",
          "body": "…tes (#85)\n\nBumps the gh-actions group with 3 updates in the / directory: [github/codeql-action/init](https://github.com/github/codeql-action), [github/codeql-action/analyze](https://github.com/github/codeql-action) and [github/codeql-action/upload-sarif](https://github.com/github/codeql-action).\n\n\n\n[…]\n version-update:semver-minor\n  dependency-group: gh-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump the gh-actions group across 1 directory with 3 upda…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-08T12:27:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bed5f1d3d126b602aafcfc54ad21ff35a2b421e8",
          "body": "…, deeper) (#86)\n\nRolling the store and the audit DB back together yields a self-consistent\nolder state that no in-DB check can see — chain, head, signatures, and\ngenerations all agree with each other. A successful 'log --verify' now\nemits an anchor token (chained-event count + head hash) on stdout \n[…]\northy. THREAT-MODEL T9\nupdated: remaining residuals are the one-write-window rollback and the\nanchor's dependence on being minted/checked regularly.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security: external audit anchors close the joint-rollback gap (SEC-14…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-08T12:21:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c23502ee0665765e368c9a02c36149dcf34047ab",
          "body": "The docs renderer is its own module, so its dependencies were never\nbumped. Grouped weekly like the root module.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "ci: cover tools/docsgen's go.mod with dependabot (#84)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-08T12:14:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db326c8f2b52af6975c68ad83e3b9efbe6be0d88",
          "body": "--no-print promises the value never reaches stdout; --show is precisely\nthat disclosure, and previously won the conflict. Cobra now rejects the\npair before anything is generated — create with --no-print and consume\nvia exec.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security: generate refuses --no-print together with --show (FU-9) (#83)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-08T11:17:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a5d1a516d76ed91b940051e781497d07e5663bb",
          "body": "* security: sanitize DEL/C1 control characters in JSON output (FU-6)\n\nGo's JSON encoder escapes C0 but emits DEL (0x7f) and C1 (U+0080-U+009F)\nraw, so --json output and MCP tool results could carry live terminal\ncontrol sequences from a crafted description, tag, or ARCA_ACTOR — the\nsame injection th\n[…]\n@arenzana.org>\n\n* test: use escape sequences for control chars in FU-6 tests (ST1018)\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>\n\n---------\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security: sanitize DEL/C1 control characters in JSON output (FU-6) (#82)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-08T11:13:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3be3f08ff70c04da1f1111d746f47e71459f6f89",
          "body": "…re (FU-5) (#81)\n\nSEC-04 moved the decoy designation into the local registry but wasn't\nretroactive: a pre-0.6.2 store still carried canary:true in the synced\nfile, telling an off-host attacker exactly which secrets are traps. On\nload, copy any legacy flag into the local registry and strip it from t\n[…]\n leaves the flags in place (still\nhonored by isCanary) and the migration retries on the next load; a flag\nis never stripped before it was preserved.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security: migrate legacy cleartext canary flags out of the synced sto…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-08T11:03:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "50baac25b52f004b350da204e6a1c213ec4f7370",
          "body": "…dual) (#80)\n\nThe rollback warning compared the store generation to a local high-water\nmark — a heuristic a machine owner can reset. Every audit event now records\nthe generation it observed, bound into the event's hash and signature, so\n'log --verify' detects a rollback from the tamper-evident log i\n[…]\nTHREAT-MODEL T9 rewritten with the sharper residuals (single-write-window\nrollback; store+audit rolled back together needs external head anchoring).\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security: bind the store generation into the audit chain (SEC-14 resi…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-08T10:58:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3dd3770b10486ec99403a23ad8752d7e2bad02b5",
          "body": "* security: TTY-anchor the audit escape hatches (SEC-06 residual)\n\nARCA_STRICT_AUDIT=0 and get --no-log were gated on env-var-based agent\ndetection, which is advisory: an agent controls its own environment and\ncan scrub the markers to pass as a human. Anchor both to the controlling\nterminal — the sa\n[…]\nnd success at a real terminal (a developer's\nshell, or the Windows runner's console).\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>\n\n---------\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security: TTY-anchor the audit escape hatches (SEC-06 residual) (#79)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-08T10:48:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0295eeb6683de7aadcba7b1a44221e1c1a580ce7",
          "body": "The cask/scoop skip_upload templates hard-fail when the env keys are\nabsent ('map has no entry for key HOMEBREW_TAP_TOKEN'). Mirror release.yml:\ndefine them empty so the templates resolve to skip_upload=true and the\ndry-run can never push.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "ci: define empty tap/scoop tokens in release-dryrun (#78)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-08T07:52:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f77d107486f8f5c9620f0a88e6c4e0e4fdf4284",
          "body": "cosign-installer v4 installs Cosign v3, whose default bundle format ignores\nthe deprecated --output-signature/--output-certificate flags and then fails\nwith 'create bundle file: open : no such file or directory'. Caught by the\nrelease-dryrun workflow before any tag was cut.\n\nSign with --bundle produ\n[…]\nsums.txt.sigstore.json, update the dryrun\nto verify goreleaser's own bundle output, and document the new verify\ncommands in SECURITY.md + CHANGELOG.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "fix(release): adopt cosign v3 bundle format for checksum signing (#77)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-08T07:45:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "266f1d3f3de4ad9136f9ba0607fa6ac4fd71313e",
          "body": "…g (#76)\n\nThe release workflow only runs on tags, so toolchain bumps (cosign-installer,\ngoreleaser-action) go untested until a real release is in flight. This\nworkflow_dispatch job does a goreleaser snapshot build and a keyless cosign\nsign+verify over the checksums using the same invocation as the release signs\nconfig, publishing nothing.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "ci: add release-dryrun workflow to exercise signing without publishin…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-08T07:35:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "06a69dd2899c65485d9547c516ed53ab91e97062",
          "body": "Bumps the gh-actions group with 6 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [step-security/harden-runner](https://github.com/step-security/harden-runner) | `2.12.1` | `2.20.0` |\n| [actions/checkout](https://github.com/actions/checkout) | `4.2.2` | `7.0.0` |\n| [actions/dependency-review\n[…]\n version-update:semver-major\n  dependency-group: gh-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump the gh-actions group with 6 updates (#75)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-08T07:21:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cebd243023476382cca132cf58725b0bcdca28de",
          "body": "codeql-action ships init/analyze/upload-sarif as steps of one action that\nmust run the same major version; per-step bumps (#69/#72 vs the v3 init\npin) break CodeQL at runtime. Group all actions bumps so they land\natomically, matching what gomod already does.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "ci: group github-actions dependabot bumps into one PR (#73)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-08T07:04:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e77ce67525f785bb16a57b594369806c1b3c19f1",
          "body": "…analyze) (#74)\n\n* build(deps): bump github/codeql-action/analyze from 3.36.2 to 4.36.3\n\nBumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 3.36.2 to 4.36.3.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/co\n[…]\n>\n\n---------\n\nSigned-off-by: dependabot[bot] <support@github.com>\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "build(deps): bump github/codeql-action from 3.36.2 to 4.36.3 (init + …",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-08T07:00:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "956412748aea38f55e6efa476085f6c658f11252",
          "body": "Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 3.36.2 to 4.36.3.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-act\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump github/codeql-action/upload-sarif (#69)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-08T06:57:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6b8bfe3b841b2602794c78db501272d752d2ff09",
          "body": "Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 3.9.1 to 4.1.2.\n- [Release notes](https://github.com/sigstore/cosign-installer/releases)\n- [Commits](https://github.com/sigstore/cosign-installer/compare/398d4b0eeef1380460a10c8013a76f728fb906ac...6f9f17788090df1f26\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump sigstore/cosign-installer from 3.9.1 to 4.1.2 (#70)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-08T06:52:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ec4d8dea64addb7d498fd7f0fd37fbd8bc674b10",
          "body": "Bumps [actions/deploy-pages](https://github.com/actions/deploy-pages) from 4.0.5 to 5.0.0.\n- [Release notes](https://github.com/actions/deploy-pages/releases)\n- [Commits](https://github.com/actions/deploy-pages/compare/d6db90164ac5ed86f2b6aed7e0febac5b3c0c03e...cd2ce8fcbc39b97be8ca5fce6e763baed58fa1\n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump actions/deploy-pages from 4.0.5 to 5.0.0 (#68)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-08T06:49:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ca95344ee1efd895913b7e3d7c7bd004401b9980",
          "body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 5.6.0 to 6.5.0.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/v5.6.0...924ae3a1cded613372ab5595356fb5720e22ba16)\n\n---\nupdated-dependencies:\n- dependency-name: \n[…]\nirect:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "build(deps): bump actions/setup-go from 5.6.0 to 6.5.0 (#71)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-08T06:38:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8c30a59b47ad58a1894eb1214a87762caa3cb1d9",
          "body": "Consolidate the [Unreleased] entries into [0.6.3]: SEC-06/11/12/13/14/15/17 +\nFU-7, broader agent detection, and the test expansion.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "docs: stamp CHANGELOG v0.6.3 (2026-07-03) (#67)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-03T14:45:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1d6cb1fb2caf3714e0517f3597f7bf1a052b3cf6",
          "body": "recipients rm just edited the recipient list and told you to run reencrypt,\nimplying the removed key was cut off. But that key can still decrypt any copy it\nalready had — backups, clones, and every prior version of the git-synced store.\nThe only true revocation of a value is to rotate it.\n\nMake reci\n[…]\nts decryptable,\n--no-reencrypt still removes, and an e2e that asserts the full stderr warning on\nthe real binary. Coverage 90.7%; -race + e2e green.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security: make recipient removal honest about revocation (SEC-15) (#66)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-03T14:39:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6640f82df2a720f3bf3e7e9fb4fd0941d109faa2",
          "body": "… (#65)\n\nAgent detection was a hardcoded switch for Claude Code and Cursor. Refactor it\ninto an extensible table (agentSignatures) and add two agents whose runtime\nmarkers are confirmed: Gemini CLI (GEMINI_CLI) and OpenAI Codex (CODEX_SANDBOX /\nCODEX_SANDBOX_NETWORK_DISABLED).\n\nFor agents that don't\n[…]\nker, the AI_AGENT fallback + version parse, built-in precedence, and\nthe no-false-positive-on-API-keys guarantee. Coverage 90.8%; -race + e2e green.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "feat: broaden AI-agent detection (Gemini CLI, Codex) + custom markers…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-03T14:29:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f7caeebd3b7e121223f9b63acc938dfc6322eaf1",
          "body": "New e2e (real-binary) tests for behavior that only had unit coverage or none:\n- TestDisableEnable: disabled secret refused on read paths, surfaced by show/ls,\n  and enable preserves a real future expiry (SEC-13).\n- TestAnnotate: metadata-only edits (add/rm tag, desc, meta) never touch the value.\n- T\n[…]\n was spuriously failing TestHandles\nlocally). Tests that need agent behavior still set AI_AGENT via runEnv.\n\nCoverage 90.7%; -race + full e2e green.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "test: expand unit + e2e coverage for the 2026-07 security work (#64)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-03T14:20:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3230b7e5252d986fb71bda9c742ccf708906383c",
          "body": "…C-06) (#63)\n\nApproval was gated by env-var-based agent detection: ARCA_APPROVAL=allow\npre-approved a release for a caller that did not look like an AI agent. But an\nagent controls its own environment and could unset the detection vars to pass as\na human and self-approve — defeating the one control \n[…]\ns refusal\nonly). Update THREAT-MODEL T2, POLICIES, CONFIGURATION, ARCHITECTURE.\n\nNot framed as breaking: ARCA_APPROVAL=allow was effectively unused.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security: --require-approval requires a real human, no env bypass (SE…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-03T14:11:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9d1e7dc407049c45bb94b069972704d26be2b776",
          "body": "The store is a git-synced JSON file, so restoring an older copy — a git revert,\na sync conflict, or an attacker resurrecting a rotated or deleted secret — was\nundetectable; the audit log doesn't witness the store's contents.\n\nAdd a monotonic Generation counter to the store, bumped on every Save. ope\n[…]\nnces past it again.\n\nTests: Save bumps the generation; the high-water logic flags a regression, stays\nhigh across a rollback, and clears on advance.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security: warn when the store is rolled back (SEC-14) (#62)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-03T13:25:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dd5e7ccee5309a265772ea5859ce3aa3ba0b2505",
          "body": "…(SEC-13) (#61)\n\ndisable suspended a secret by stamping expires_at to now, and enable cleared\nexpires_at entirely — so disabling then enabling a secret that carried a real\nfuture expiry silently wiped it (intent data-loss).\n\nAdd a dedicated store.Secret.Disabled field: disable sets it, enable clears\n[…]\nMCP surface\nhonors it. Repurposed the old TestEnableClearsHardExpiry (which asserted the very\nbug this fixes) into TestDisableEnablePreservesExpiry.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security: model disable/enable as a distinct field, not expiry reuse …",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-03T13:18:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5be66f81d1219390055189dc82a3693382668eb3",
          "body": "- SEC-12: get --no-log no longer evades a rate limit. Rate limits count audit\n  rows, but --no-log skipped the read record, so a human could loop-read a\n  rate-limited secret past its cap. --no-log is now ignored (with a note) for a\n  rate-limited secret; still honored for ordinary secrets, never fo\n[…]\n refuses a short secret; --no-log doesn't evade a rate limit but still\nworks for ordinary secrets. Coverage 90.1%; race/vet/staticcheck/gosec clean.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security: Group A hardening — SEC-11, SEC-12, SEC-17, FU-7 (#60)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-03T13:07:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ba98955c65cf07a534fb57330bd0638b5fe4771f",
          "body": "Signed-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "docs: stamp CHANGELOG v0.6.2 (2026-07-03) (#59)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-03T12:50:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ed352254fc7db0daa1bd3d47d482956bfe0e1af",
          "body": "The version was a header line (arca X.Y.Z) at a different column than the\ncommit/built/go/platform values below it. Make it a labeled 'version' row in a\nwidth-computed aligned table so every value lines up. --json output unchanged.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "fix: align arca version output into a single key/value column (#44)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-03T12:45:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32a1f7d7fc424d51a1bbb3ae04e54c4f3fe152fe",
          "body": "The v0.6.1 cask/release checksum divergence had a deeper root cause than the\ndouble-run: the archives themselves aren't byte-reproducible. mod_timestamp\npins only the compiled binary (verified: the binary IS reproducible), but the\nbundled LICENSE/README/CHANGELOG take their on-disk checkout mtime, s\n[…]\n the\ncask — divergence is impossible, complementing the concurrency guard (#50) which\nserialized against it. Resolves the reproducibility follow-up.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "ci: make release archives byte-reproducible (FU-8) (#58)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-03T03:22:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "827a155c606682497a2edc89284a631656e64db3",
          "body": "…(#57)\n\nFollow-up fixes from the 2026-07-03 post-fix verification audit:\n\n- FU-1 (MEDIUM, completes SEC-09): the MCP list_secrets tool exposed per-secret\n  last_read time, which advances when a handle is used (the underlying exec\n  bumps the real secret's last-read). An agent holding only an opaque \n[…]\nsecrets omits last_read; run_with_handle refuses a tampered reserved\nenv name; show sanitizes a poisoned name; rename --force clears a stale canary.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security: complete SEC-09 and audit follow-up hardening (FU-1..FU-4) …",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-03T03:17:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "47a9620e3cbac0f382cb92e481b15574c15d938e",
          "body": "…ing the value (#56)\n\nThere was no way to change a secret's tags/description/metadata after creation\nwithout re-entering its value: 'set' always re-prompts for the value, and a\n--no-print secret can't be re-piped at all (its value can't be read back). This\nmade simple relabeling impossible for exact\n[…]\n+ UpdatedAt unchanged, tag add/remove/replace, meta\nset/remove, desc set/clear, works on --no-print, audited, and the no-op /\nmissing-secret guards.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "feat: add 'arca annotate' to edit tags/description/meta without chang…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-03T02:56:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "08ea515b118999d47fd68b996d487d731f52bb24",
          "body": "…ool (SEC-09) (#55)\n\nrun_with_handle is meant to let an agent use a secret without learning which\nsecret it is. But a handle-issued exec records the secret's real name with the\nhandle id (hdl_...) as caller, and the audit_log MCP tool returned events\nverbatim — so an agent could call audit_log and r\n[…]\ns, and that\nmapping is what audit_log leaked.\n\nTest: after using a handle, audit_log's handle events show the handle id, never\nthe real secret name.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security: mask the secret name behind a handle in the audit_log MCP t…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-03T02:49:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0a353ad0ef252d3e2ee9820885aefa3a9b8df103",
          "body": "The store lock released by deleting the lock file by path, and reclaimed a stale\nlock with a blind unlink. Two races followed: a process whose lock was reclaimed\ncould delete its successor's lock on release; and two processes could both\n'steal' the same stale lock, yielding two concurrent writers an\n[…]\njob.\n\nTests: ownership-checked release, heartbeat freshness, and a path-safe token\nguard. Existing lock + e2e concurrent-set tests pass under -race.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security: token-owned store lock with heartbeat (SEC-08) (#54)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-03T02:42:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ba9ec841a34a52de09cabc4ca11891af6a4ac07c",
          "body": "…C-07) (#53)\n\nls/log/show — plus grants, handle ls, canary --list, and the canary alert —\nwrote secret descriptions/tags/meta and the audit log's agent/actor/caller/\nsession columns to the terminal raw. Those fields are attacker-influenced: a\npoisoned git-synced store, or a detected agent setting a \n[…]\n keeps Unicode), and end-to-end that a\ncrafted description/tag and a crafted $ARCA_ACTOR carry no escapes into\nshow/ls/log. Combined coverage 90.1%.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security: sanitize terminal control characters in rendered output (SE…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-03T02:19:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c8d60d32106d35957ba60bd9aef04ea6a65b841b",
          "body": "… (SEC-05) (#52)\n\nrun_with_handle deliberately bypasses the require-grant/require-approval gates\n(the handle is the operator's pre-authorization), but 'handle create' only\nchecked that the secret existed. So a detected agent could mint itself a handle\nfor a require-approval/require-grant secret and \n[…]\ndeterministic regardless of what launched it (running inside a Claude Code\nsession set CLAUDECODE, which made every test caller look like an agent).\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security: restrict handle creation to close the grant/approval bypass…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-03T02:10:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5b51cf83dc3ae07e7f4b0a80101c92c398f23f3a",
          "body": "The 'this is a decoy' flag was a cleartext `canary` field in store.json, which\nis git-synced. Anyone who obtained the store — the exact exfiltration a canary\nexists to catch — could read `\"canary\": true` and step around the decoys while\nlearning which entries are real, defeating the honeytoken again\n[…]\n trips, legacy store\nflag still trips + lists, rename follows, unmark/rm clean up, and the registry\nerror/failure branches. Combined coverage 90.1%.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security: keep canary designation out of the synced store (SEC-04) (#51)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-02T14:38:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "934d3808a77ee6e40db114fc322da440f9b34faf",
          "body": "…s (#50)\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "ci: prevent duplicate release runs from publishing divergent artifact…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-02T14:21:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60cbec54cca6c8a8df69125b973f5367d737d0de",
          "body": "Signed-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "docs: stamp CHANGELOG v0.6.1 (2026-07-02) (#49)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-02T13:51:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7890c8ef2d06ee74828b9e6216f9bd6ba816870c",
          "body": "The nightly fuzz job went red on FuzzGlobMatch with:\n  globMatch(\"*\", \"\\n\") = true; regexp reference = false\n\nglobMatch is correct: it is byte-based (HasPrefix/Index/HasSuffix), so '*'\nmatches any byte including a newline — the behaviour we want when matching a\ncommand string against a grant pattern\n[…]\nVerified: the CI-minimized input now passes and 90s / 1.47M execs of fuzzing\nfound no other discrepancy — globMatch itself is unchanged and correct.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "test: fix FuzzGlobMatch oracle to match glob newline semantics (#48)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-02T13:42:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "292e2b3792e8b19df444f78795784c5b23c21f5a",
          "body": "…EC-03) (#47)\n\nlog --verify could return a clean result after a DB-writer rewrote history,\nbecause three tamper shapes were reported as benign rather than failed:\n\n1. Legacy downgrade: NULL every row's hash so the chain walk skips them and the\n   log reports Checked=0/Legacy=N/OK=true. Fixed by reco\n[…]\nd (passes signed, fails stripped, rejected without --verify).\nExisting legacy-DB / truncation / empty-log tests still pass; combined coverage\n90.2%.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security: harden audit log verification against false-green tamper (S…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-02T13:37:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "89300098e94578b96fd07a0e54d54f8a2a4d508d",
          "body": "edit gated the access but never checked NoPrint before decrypting and handing\nthe plaintext to $EDITOR. Because the caller controls $EDITOR (EDITOR=cat,\nEDITOR='cp {} ...'), 'arca edit' was a disclosure path that get/inject/env and\nMCP read_secret all refuse — defeating the flagship --no-print contr\n[…]\nore decrypting, and point the user at\nrotate (which replaces the value without revealing the old one). Document it in\nPOLICIES.md and the CHANGELOG.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security: refuse to edit a --no-print secret (SEC-02) (#46)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-02T13:26:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3f02fad675fd14d147e5e114ace1fec9b8688bd6",
          "body": "A secret name that passes the identifier shape check but collides with an\nenvironment variable the child process trusts — PATH, LD_PRELOAD, DYLD_*, IFS,\nBASH_ENV, PROMPT_COMMAND, PYTHONPATH, NODE_OPTIONS, and kin — would hijack the\nprocess when injected by exec/env/run_with_secrets/handle. Because t\n[…]\ntion\nsite — so an already-poisoned store is refused there too. Update THREAT-MODEL\nT3, which previously claimed this was handled, and the CHANGELOG.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "security: reject reserved env-var names as secret names (SEC-01) (#45)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-02T12:56:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "257641b1b39f6d19b11e08e56e21e3e3f1445397",
          "body": "Signed-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "docs: stamp CHANGELOG v0.6.0 (2026-07-01) (#43)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-01T20:50:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f08a6607d6bd1bd043c16346cdd6e34ec2e4c0ea",
          "body": "…en release publish (#42)\n\n- 'arca version' prints version + VCS commit + build date + Go toolchain + platform\n  (--json for scripts/agents). 'arca --version' still prints just the version string.\n- skills/arca/SKILL.md: a shippable Claude Code skill teaching an agent arca's\n  'use, don't reveal' wo\n[…]\nppened to v0.5.0).\n\nTests: version (human + --json) and formatVersion branch coverage. Docs: COMMANDS.md\nrow + CHANGELOG. Coverage 90.3% (gate 90%).\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "feat: add 'arca version' subcommand and a shippable agent skill; hard…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-01T20:44:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9dc35c8d65d4dd93dc5a5abd6e48aa3d9605bb58",
          "body": "Signed-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "docs: stamp CHANGELOG v0.5.0 (2026-07-01) (#41)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-01T20:24:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8fbda872fb4bc86bf288e01ec13d4a7d235ccf6f",
          "body": "…ts (#40)\n\nAdd 'arca disable NAME' / 'arca enable NAME' — a fast, reversible way to take\na secret out of service on every access path (get/exec/inject/env + MCP)\nwithout deleting it or changing its value. Implemented over the existing hard-\nexpiry mechanism (disable stamps expires_at=now, enable cle\n[…]\nclearing a hard expiry, and the not-found/no-store error paths. Docs:\nCOMMANDS.md reference + section, CHANGELOG entries. Coverage 90.2% (gate 90%).\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "feat: add disable/enable kill switch; fix env aborting on gated secre…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-01T20:18:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "48f1450856a8ac0fcde71378d2a8199ad36b789a",
          "body": "Add a Documentation section + Docs nav link to the landing page, and a\ntools/docsgen generator that renders docs/*.md into standalone HTML pages\nmatching the landing page's look, plus an auto-generated docs.html catalog.\n\nThe generator is its own Go module so goldmark stays out of arca's main\ngo.mod\n[…]\nate/deploy, so published docs never drift from their Markdown source.\nGenerated HTML is git-ignored and rebuilt in CI; `make docs` previews locally.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "docs: render Markdown docs into styled HTML in CI (#39)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-01T19:44:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a9dab6da2c6780adaf12d68a8a2b00d2ab5bb9fd",
          "body": "The README had grown to ~530 lines with the command reference, config, storage model, MCP, importing, and six sprawling policy features inline. Trim it to an overview (why/features/install/quickstart/recipes/model) plus a Documentation index, and move the detail into docs/ topic pages:\n\n- docs/COMMA\n[…]\n source recipe matrix\n- docs/CONFIGURATION.md — ARCA_* env vars, paths, storage model\n\nEach page cross-links; nothing lost. README 530 -> 350 lines.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "docs: split the README into docs/ topic pages (#38)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-01T18:15:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4e4f46186ac478991cb8b97152e02787341cbbc2",
          "body": "Second test batch plus continuous fuzzing:\n\n- FuzzShellQuote (upgraded from a weak structural check to the authoritative one): a value quoted for 'eval \"$(arca env)\"' is round-tripped through a real shell — proving it can't inject.\n- TestEnvEvalSafety: end-to-end, a secret full of shell metacharacte\n[…]\nill answers a later valid request.\n\n- .github/workflows/fuzz.yml: nightly (and manual) job runs every fuzz target ~60s and uploads any crash corpus.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "test(ci): env/inject/MCP safety tests + nightly fuzz workflow (#37)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-01T18:02:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "63274266d3c9260a9fd02778a06cfbc8bae1eec7",
          "body": "A substantial test push focused on the security-critical invariants:\n\n- Fuzz targets: redaction never leaks the value (any value/output/chunking), globMatch always agrees with a regexp reference, import parsers never surface an unsafe name, validName only accepts the safe grammar, parseTTL/parseRate\n[…]\n one), verifying gate ordering.\n- Multi-secret redaction; a few error-path/fault-injection tests.\n\nCoverage 90.3%; race/vet/staticcheck/gosec clean.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "test: fuzz targets, property, concurrency, and cross-feature tests (#36)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-01T17:42:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2848c2831d25af31f7afef3877b696e1d03630fd",
          "body": "Render log/ls/grants/handle-ls/stale as color-coded aligned tables on a terminal — bold teal header, dimmed timestamps, ops tinted by kind (green=use, amber=write, coral=alert/removal) — with no new dependencies. Column widths are computed from visible text (ANSI stripped) so colored cells align exa\n[…]\nk to plain tab-separated columns when piped so scripts stay parseable. Also fixes a latent ls header/row mismatch when the audit DB can't be opened.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "feat(ui): color-coded terminal tables (zero-dependency ANSI) (#35)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-01T17:20:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cb160028be90b793371dbd0902636f40d7d72583",
          "body": "…process (#33)\n\nThe audit log showed a blank ACTOR and a blank CALLER for get/read (only exec set the caller). Populate both: detectIdentity falls back the actor to the OS user when $ARCA_ACTOR is unset, and recordAudit defaults the caller to the parent process command (via /proc on Linux, ps on mac\n[…]\n$ARCA_ACTOR still wins; exec's command caller is unchanged.\n\nAlso add tests for strict-audit invariants, the rate-limit bad-window fallback, and rm.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "feat(audit): default actor to the OS user and caller to the invoking …",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-01T15:04:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0ada1c26b37d548f2ae354040b79969d2fa458f8",
          "body": "… (tier-2 moat B2) (#32)\n\nLet an agent USE a secret over MCP without learning its name or value, and without enumerating the store. 'arca handle create SECRET --ttl 1h [--command GLOB] [--as ENV]' mints an opaque token (hdl_...); the new MCP 'run_with_handle' tool resolves it, enforces the command s\n[…]\nMCP handler (run_with_handle incl. redaction, scope, rate-limit, canary, target-gone, run-error), and a black-box e2e over JSON-RPC. Coverage 90.1%.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "feat(mcp): opaque capability handles + redact run_with_secrets output…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-01T14:43:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "499eaa91ed9e522a9d8446b5fe1b8dc2ca915a25",
          "body": "Cap how often a secret may be used within a rolling window, to stop a runaway agent hammering it. 'set'/'generate --rate N/DURATION' (e.g. 10/1h) sets the policy; gate() refuses the access once the window's prior uses reach the cap and records the throttle (op=ratelimit), with a note on the last per\n[…]\nr roll back. Shown by 'show'; cleared with --rate ''. Honest boundary in SECURITY.md: a throttle, not a quota — a patient caller can spread use out.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "feat(rate): per-secret rate limiting (tier-2 moat B1) (#31)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-01T14:20:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af1c98bcea130bb2f066f1d610129b6cd6b7eacb",
          "body": "The site predated the agent-control-plane moats. Update the features grid and\nthe 'what makes it different' recipes to cover output redaction, the\ntamper-evident signed audit (log --verify), canary secrets, and just-in-time\ngrants; add a log --verify line to the quickstart. Design system unchanged.\n\nAlso align the README canary example's agent name with the site (malicious-agent).\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "docs(site): refresh landing page for the v0.4.0 security features (#30)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-01T13:10:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "51e3a1b8822204b7f016eb40ce148d2a4e293aa6",
          "body": "Roll the accumulated Unreleased changes into v0.4.0: import --json + ergonomics\nflags, exec output redaction, tamper-evident signed audit + log --verify, canary\nsecrets, and command-scoped just-in-time grants.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "release: v0.4.0 (#29)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-01T12:43:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eab3828e92349145ad6634742d19f444f70a76ee",
          "body": "* feat(grants): command-scoped, just-in-time grants (moat #3)\n\nBind a secret to *what* an agent does, not just whether it can see it.\n\n- New per-secret flag --require-grant: such a secret is usable only via exec /\n  MCP run_with_secrets, and only when a matching active grant exists. get / env\n  / in\n[…]\nness so grants.json and session\nsigning keys never touch the real $HOME during tests.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>\n\n---------\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "grants: command-scoped, just-in-time grants (moat #3) (#28)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-07-01T12:39:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "32e8449e9ac6bbb73fc62f74ece90f3d8e480176",
          "body": "Coverage was sitting at exactly 90.0% (the CI gate is <90). Add fault-injection\ntests for the lowest-covered error branches:\n- audit Record/Verify/LastOp/LastRead/Recent on a closed handle (DB-error paths)\n- redactWriter Write/Flush propagating a downstream writer error\n\nTotal coverage 90.0% -> 90.4%; audit package 87.7% -> 90.8%.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "test: cover DB-error and redact-writer error paths for margin (#27)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-06-30T19:33:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e30ec6b8c428ab0c4b9ec169898cc92f2a2ec494",
          "body": "… (#26)\n\nA canary is a decoy that should never legitimately be used; any use is a strong\nsignal that something is enumerating or exfiltrating secrets.\n\n- 'arca canary NAME --template stripe|github|aws|slack|generic' plants a\n  realistic-looking decoy; 'set'/'generate --canary' mark an existing secre\n[…]\nicated attacker who inspects metadata can identify\nand avoid a canary; its value is catching the common case of an agent that uses\nwhat it can read.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "feat(canary): decoy secrets that trip a signed alert on use (moat #4)…",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-06-30T19:22:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bc3172cb11c1647cf1f6b025cb0c3037b245f856",
          "body": "Turn the audit log from advisory into tamper-evident and attributable.\n\n- Hash-chain every event: hashᵢ = SHA-256(hashᵢ₋₁ ‖ canonical(eventᵢ)), so an\n  edit, deletion, or reordering breaks the chain and is detectable.\n- Sign each event's chain hash with the recording session's Ed25519 key (one\n  key\n[…]\nests: clean/signed verify, detection of edit/delete/sig-forgery/truncation,\nlegacy-DB migration, empty log, and a CLI verify-then-tamper round trip.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "feat(audit): tamper-evident, signed audit log (moat #2)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-06-30T18:58:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c174c1713c60387551887cb7123f1783a5a874e6",
          "body": "Moat #1 of the agent-control-plane set. When a command run under 'arca exec'\nprints an injected secret, arca replaces the value with «arca:NAME» in the\ncaptured stdout/stderr before it reaches the reader (an AI agent, a log), and\nrecords the catch in the audit log (op=redact) as a potential-leak sig\n[…]\n the 'the command could still print it' caveat documented in SECURITY.md\nand the threat model, restating it as redacted-by-default defense in depth.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "feat(exec): redact injected secret values from command output",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-06-30T18:21:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7bd6326b8f8ba3b3635f2f57e416b4f6bb41e70d",
          "body": "…by default\n\n- import now skips a name that already exists instead of silently overwriting\n  it; --overwrite restores replace-in-place. Stops a re-run from clobbering.\n- --dry-run previews the plan (new/overwrite/skip) and writes nothing; it\n  doesn't even take the store lock.\n- --prefix namespaces \n[…]\nnames (re-validating the combined name), and\n  --tag attaches tags to every imported secret.\n- README import table + examples and CHANGELOG updated.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "feat(import): --dry-run, --overwrite, --prefix, --tag; skip existing …",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-06-30T18:03:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "586f0eba7ef515410bd1f360677a884ad3f7f0ae",
          "body": "- import --json reads {\"KEY\":\"value\"} from stdin, the shape AWS Secrets\n  Manager / Vault / 1Password / gcloud emit, so they pipe in without jq\n  reshaping. String values pass through (multi-line JSON strings round-trip),\n  numbers/bools are stringified, null/nested values are skipped.\n- import now \n[…]\ncipe\n  matrix (sops/.env/JSON/1Password/Vault/AWS/GCP/pass/env), and set NAME < file\n  for single multi-line blobs (PEM keys, service-account JSON).\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "feat(import): JSON object input, audit every import, document sources",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-06-30T17:43:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5c7ad8cac933d9c571d0abc06dae04ee7e09c6a6",
          "body": "Signed-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "docs: show OpenSSF Baseline + Scorecard badges on the website footer",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-06-30T17:24:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b9595aaba230b9e9bb6247295cbfb3117d26ad61",
          "body": "TestConcurrentSet intermittently failed on the Windows CI runner: 8 concurrent\n'arca set' processes serialize on the store lockfile, and on a loaded 2-core\nrunner the per-hold cost (process spawn + age encrypt + audit write) for the\nwaiters ahead could exceed the 5s acquisition window. 15s leaves he\n[…]\nended writes (also relevant to many-agent and slow/networked-FS use)\nwithout masking a genuinely stuck lock, which the 30s stale-lock steal handles.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "fix: widen store-lock timeout to 15s for contended writes",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-06-30T17:04:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3ab96c123f4372542631dfac6dacc39d41b361ca",
          "body": "Signed-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "docs: add OpenSSF Baseline badge to README",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-06-30T17:04:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2bf70ab24cca940187f75b7082f6b9ffb972b8ef",
          "body": "Close the six Baseline Level 2 gaps:\n\n- DO-06.01: document how dependencies are selected, obtained, and tracked\n  (new Dependencies section in CONTRIBUTING).\n- GV-01.01/02: add MAINTAINERS.md listing members, roles, and access to\n  sensitive resources.\n- SA-01.01: add docs/ARCHITECTURE.md (actors, c\n[…]\nailer on every commit, enforced\n  by a new dco CI check and documented in CONTRIBUTING.\n\nLink the new design and threat-model docs from SECURITY.md.\n\nSigned-off-by: Ismael Arenzana <isma@arenzana.org>",
          "is_bot": false,
          "headline": "docs,ci: meet OSPS Baseline Level 2 criteria",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-06-30T16:46:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7f444214a52d683b4f82a146a58d7cf4ab38ec3c",
          "body": "TestMainEntry set os.Stdout to a pipe with a DISCARDED read end, then called main(). When the GC\nclosed that unread reader mid-write, the --version write broke ('broken pipe' / 'pipe is being\nclosed'), Execute returned an error, and main() called os.Exit(1) — killing the whole test\nbinary intermittently on any OS. Write to a temp file instead. Verified: 20x -race stress green.",
          "is_bot": false,
          "headline": "test: fix TestMainEntry pipe flake (the actual cross-OS failure)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-06-30T16:13:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24b7d6ac19957f76be5a8480740248c8e8c48ac6",
          "body": "Remove embedded metadata (including the image generator's Exif 'Signature' string) from the\nlogo, favicon, and social card. Pixels and dimensions are unchanged; images verified usable.",
          "is_bot": false,
          "headline": "assets: strip image metadata (Exif/text chunks)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-06-30T16:13:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bf151cf9589a0ef3dc8ed845a900b18630a9174d",
          "body": "The harness swapped os.Stdin/os.Stdout with os.Pipe + goroutines; on Windows a pipe whose peer\nclosed early failed the write with 'the pipe is being closed', flaking the Windows test job.\nBack stdin/stdout with temp files instead — no reader/writer race, deterministic on every OS.\nRace suite + e2e green; coverage unchanged.",
          "is_bot": false,
          "headline": "test: file-backed execArca harness (fix Windows pipe-race flake)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-06-30T16:13:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "723c3d5b4ed664bb9f6f0c11c16d36138abd081d",
          "body": "Document the three repos the project spans — arca (source), homebrew-tap and scoop-bucket\n(auto-published distribution artifacts) — in CONTRIBUTING.",
          "is_bot": false,
          "headline": "docs: list the project's repositories (OSPS-QA-04.01)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-06-30T16:13:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d0e3fb2b015e9e135b8d93099fe676dd8f74a3ac",
          "body": "- docs/: a static landing page (on-brand teal/coral from the logo) with copy-to-clipboard\n  install commands, a favicon, an OG/Twitter social card (og.png, 1200x630), and an\n  'in practice' section showing the moat (use-without-revealing, agent-can't-read, ephemeral\n  + audited). The page's logo cop\n[…]\n least-privilege, harden-runner). PRs validate only.\n- README: a Recipes section (exec/least-privilege, templating, generate+rotate, TTL, no-print/\n  approval, teams, env, MCP, audit, dotfiles, JSON).",
          "is_bot": false,
          "headline": "site: GitHub Pages landing page + deploy CI; README recipes",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-06-30T15:30:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5cb8ac57a86552232a7dba7e51d91db35d491505",
          "body": "Defines the SemVer contract for v1.0: stable surfaces (commands/flags, exit codes, store schema\nwith forward migration, arca:// references, ARCA_* config, policy semantics, --json shapes, MCP\ntool names) vs. what may change (human-readable text, internal packages, audit DB layout), plus\na deprecation policy and supported platforms. Linked from README + ToC; noted in CHANGELOG.",
          "is_bot": false,
          "headline": "docs: v1.0 stability policy (STABILITY.md)",
          "author_name": "Ismael Arenzana",
          "author_login": "arenzana",
          "committed_at": "2026-06-30T14:58:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 16,
      "commits_last_year": 135,
      "latest_release_at": "2026-07-27T12:03:37Z",
      "latest_release_tag": "v0.9.0",
      "releases_from_tags": false,
      "days_since_last_push": 2,
      "active_weeks_last_year": 5,
      "days_since_latest_release": 2,
      "mean_days_between_releases": 2.8
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/arenzana/arca",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/arenzana/arca",
          "is_deprecated": false,
          "latest_version": "v0.9.0",
          "repository_url": "https://github.com/arenzana/arca",
          "versions_count": 16,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-27T10:09:32Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 2
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 1,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod",
        "tools/docsgen/go.mod"
      ],
      "largest_source_bytes": 90985,
      "source_files_sampled": 100,
      "oversized_source_files": 1,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "github.com/klauspost/compress",
            "direct": false,
            "version": "v1.18.6",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5841"
            ],
            "fixed_version": "1.18.7",
            "advisory_count": 1,
            "oldest_advisory_days": 1
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.53.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5932"
            ],
            "fixed_version": null,
            "advisory_count": 1,
            "oldest_advisory_days": 21
          },
          {
            "name": "golang.org/x/net",
            "direct": false,
            "version": "v0.55.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5942"
            ],
            "fixed_version": "0.56.0",
            "advisory_count": 1,
            "oldest_advisory_days": 14
          },
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.38.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5970"
            ],
            "fixed_version": "0.39.0",
            "advisory_count": 1,
            "oldest_advisory_days": 14
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "unknown": 4
        },
        "advisory_count": 4,
        "affected_count": 4,
        "assessed_count": 38,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "filippo.io/age",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.3.1"
        },
        {
          "name": "github.com/mark3labs/mcp-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.57.0"
        },
        {
          "name": "github.com/minio/minio-go/v7",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v7.2.1"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "golang.org/x/term",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.45.0"
        },
        {
          "name": "modernc.org/sqlite",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.54.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "filippo.io/age",
            "direct": true,
            "version": "v1.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mark3labs/mcp-go",
            "direct": true,
            "version": "v0.57.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/minio/minio-go/v7",
            "direct": true,
            "version": "v7.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": true,
            "version": "v1.10.2",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/term",
            "direct": true,
            "version": "v0.45.0",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/sqlite",
            "direct": true,
            "version": "v1.54.0",
            "ecosystem": "go"
          },
          {
            "name": "filippo.io/hpke",
            "direct": false,
            "version": "v0.4.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cespare/xxhash/v2",
            "direct": false,
            "version": "v2.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dustin/go-humanize",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/jsonschema-go",
            "direct": false,
            "version": "v0.4.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/klauspost/compress",
            "direct": false,
            "version": "v1.18.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/klauspost/cpuid/v2",
            "direct": false,
            "version": "v2.2.11",
            "ecosystem": "go"
          },
          {
            "name": "github.com/klauspost/crc32",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-isatty",
            "direct": false,
            "version": "v0.0.22",
            "ecosystem": "go"
          },
          {
            "name": "github.com/minio/crc64nvme",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/minio/md5-simd",
            "direct": false,
            "version": "v1.1.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ncruces/go-strftime",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/philhofer/fwd",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/remyoudompheng/bigfft",
            "direct": false,
            "version": "v0.0.0-20230129092748-24d4a6f8daec",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rs/xid",
            "direct": false,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/santhosh-tekuri/jsonschema/v6",
            "direct": false,
            "version": "v6.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cast",
            "direct": false,
            "version": "v1.7.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": false,
            "version": "v1.0.10",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tinylib/msgp",
            "direct": false,
            "version": "v1.6.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/yosida95/uritemplate/v3",
            "direct": false,
            "version": "v3.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/yuin/goldmark",
            "direct": false,
            "version": "v1.8.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/zeebo/xxh3",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v3",
            "direct": false,
            "version": "v3.0.4",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.53.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/net",
            "direct": false,
            "version": "v0.55.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.38.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/ini.v1",
            "direct": false,
            "version": "v1.67.2",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/libc",
            "direct": false,
            "version": "v1.74.1",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/mathutil",
            "direct": false,
            "version": "v1.7.1",
            "ecosystem": "go"
          },
          {
            "name": "modernc.org/memory",
            "direct": false,
            "version": "v1.11.0",
            "ecosystem": "go"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 38,
        "direct_count": 6,
        "indirect_count": 32
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 106,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 7
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "arenzana",
          "commits": 122,
          "avatar_url": "https://avatars.githubusercontent.com/u/5133407?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "codeql.yml",
        "dco.yml",
        "fuzz.yml",
        "pages.yml",
        "release-dryrun.yml",
        "release.yml",
        "scorecard.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 2,
            "reason": "badge detected: InProgress",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/22 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 10,
            "reason": "all dependencies are pinned",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 8,
            "reason": "5 out of the last 5 releases have a total of 5 signed artifacts.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 6,
            "reason": "4 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "d4266fc063fe16f1045ea891941c03548a7aa735",
        "ran_at": "2026-07-29T13:02:23Z",
        "aggregate_score": 7.2,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-29T08:02:45Z",
      "oldest_open_prs": [
        {
          "number": 109,
          "created_at": "2026-07-26T06:27:52Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-27T10:09:33Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/arenzana/arca",
    "host": "github.com",
    "name": "arca",
    "owner": "arenzana"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 64,
      "inputs": {
        "security": 78,
        "vitality": 74,
        "community": 43,
        "governance": 52,
        "engineering": 77
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 74,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "commits_last_year": 135,
              "human_commit_share": 0.87,
              "days_since_last_push": 2,
              "active_weeks_last_year": 5
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 2 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "5/52 weeks with commits",
                "points": 3.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "135 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 135
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "releases_count": 16,
              "latest_release_tag": "v0.9.0",
              "releases_from_tags": false,
              "days_since_latest_release": 2,
              "mean_days_between_releases": 2.8
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "16 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 2 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~2.8 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 2.8
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "5 out of the last 5 releases have a total of 5 signed artifacts.",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 43,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 1,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 52,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 67,
            "inputs": {
              "merged_prs": 106,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 7
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "106/113 decided PRs merged",
                "points": 35.9,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 106,
                      "decided": 113
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/22 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 49,
            "inputs": {
              "followers": 8,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "arenzana",
              "public_repos": 24,
              "account_age_days": 4745
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "8 followers of arenzana",
                "points": 6.9,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 8,
                      "login": "arenzana"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "24 public repos, account ~13 yr old",
                "points": 22.2,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 24
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 13
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/arenzana/arca"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 2
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 2 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "16 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 77,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "8 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": "https://arenzana.github.io/arca/",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://arenzana.github.io/arca/",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 78,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "good",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 7.2
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "badge detected: InProgress",
                "points": 0.5,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/22 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "5 out of the last 5 releases have a total of 5 signed artifacts.",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "4 existing vulnerabilities detected",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 38 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 38
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 4,
              "affected_packages": 4,
              "assessed_packages": 38,
              "unassessed_packages": 0,
              "affected_by_severity": "unknown 4",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 38,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 69,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "87 of 87 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 87,
                      "sampled": 87
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 79,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod",
                "tools/docsgen/go.mod"
              ],
              "dependency_bot_commit_share": 0.13
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "13 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 13,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 90985,
              "source_files_sampled": 100,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/100 source files over 60KB",
                "points": 54.5,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 100,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-29T13:02:40.793934Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/a/arenzana/arca.svg",
  "full_name": "arenzana/arca",
  "license_state": "standard",
  "license_spdx": "MIT"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计Go.