matches BEFORE a trailing newline in Python, so a sha256 digest\n[…]\ned / 7 skipped, ruff clean. Not a signature forgery (the receipt\nmust be authentically signed); a strictness/canonicality gap, no One-Way-Door.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(canonicality): anchor every validator with \\A..\\Z, not ^..$ (6-le…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T14:48:06Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "f8e76cd5cee86f63d4945860953c829b46ae4141", "body": "…BDOS-01, int\u003c->str cap parity)\n\nThe 6-lens gate confirmed 1 remaining P2 (and re-confirmed RT-09/RT-10/crypto/relation/packaging and\nverify_evidence_pack/verify_sample_opening/recompute all hold): verify_bundle(dict) leaked a raw\nValueError on a huge merkle.tree_size / leaf_index (e.g. 10**5000). R\n[…]\n raw ValueError; a legit small tree_size is\nunaffected.\n\nRegression test added (bidirectional). Full suite 1952 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(never-raise): bound integer magnitude in _require_int (6-lens L2-…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T14:23:18Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "74c882aaad67673fae6d1a3b16bd39d486f38f1c", "body": "…ree (release-vorlauf)\n\nAdded \"Addendum 2 — reconciled to the shipped v3.6.1 release tree\" to the pre-tag adversarial audit\nrecord. Every number carries its command source (No-Fake, vorlauf P5), and figures that changed vs the\nv3.6.0 addendum are called out so nothing contradicts the shipped state:\n\n[…]\nl branch-base snapshot, not the shipped count.\n- 0 open P0/P1 holds (signed register). Status boundary unchanged (BETA, EXPERIMENTAL relation).\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "docs(pre-tag): P5 reconcile the audit addendum to the shipped 3.6.1 t…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T13:49:59Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "8fe8b629d40c2fd1bf8dd68731156cef739e4fda", "body": "…attest-dryrun startup failure\n\nThe published-artifact-gate's reusable-attest-dryrun job called reusable-build-attest.yml whose\nbuild-attest job declares id-token:write + attestations:write, but the workflow-wide contents:read\ncannot be exceeded by a called workflow -> the run was refused at startup\n[…]\n from PR #102 per Owner-GO, so 3.6.1 carries the fix without a separate merge). The\nreusable workflow is unchanged; CI-only, no package change.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "ci(pag): integrate PR #102 permission fix into 3.6.1 (P3) — reusable-…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T13:46:30Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "710357a8ad9ca36a554385422f49cf51f98a3f0f", "body": "…typed errors (6-lens L2/L3)\n\nThe 6-lens gate confirmed 2 P2 fail-closed defects on SECONDARY exported surfaces (it also\nre-confirmed RT-09/RT-10/crypto/relation and every primary verify_* surface hold):\n\n- L2-BDOS-01: recompute_merkle_root_b64(dict) walked merkle.inclusion_proof_b64 with an INERT\n \n[…]\n\n\nRegression tests added (load_bundle malformed matrix; recompute 100k-proof fast fail-closed).\nFull suite 1951 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(never-raise+dos): recompute_merkle_root_b64 budget + load_bundle …", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T13:37:57Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "5d35b6a371ef1c63561ba8c6304a3a4b270143d7", "body": "…enewal_policy (6-lens L2-01/L3-02)\n\nThe 6-lens gate confirmed 2 P2 never-raise leaks, both the recurring class \"an exported\nverify_*/evaluate_* surface missing a guard its sibling already has\". (My earlier claim that\nverify_prereg was clean was wrong — I tested with an empty claim, which short-circ\n[…]\nnd shape\nsurfaces are the three now-guarded ones plus verify_sequence.\n\nRegression tests added. Full suite 1949 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(never-raise): sibling-guard parity for verify_prereg + evaluate_r…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T13:04:17Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "4737356ee318af768a60b7c2b236871ef250f219", "body": "…e never-raise + bare-eval clean-skips)\n\nThe 6-lens gate confirmed 4 findings; after per-finding live re-verification against the\neditable HEAD (No-Fake), 3 were real and 1 (L2-01 verify_prereg) was a FALSE finding — the\ngate's own probe env had a stale build; verify_prereg already returns a fail-cl\n[…]\nession tests added (verify_evaluation_card bad paths; verify_sample_opening non-ASCII).\nFull in-repo suite 1947 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(never-raise+packaging): 3 real 6-lens findings (evalcard/persampl…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T12:35:59Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "a1d1d71d80e747ebeca6112d17b99c090c53ebf2", "body": "…widen pre_tag negation\n\nThe single-round 6-lens Berkeley gate confirmed 1 P0 (and confirmed every other RT-10\nguard HELD live: absent/empty/foreign-key/tamper/dangling/self-supersede/non-string-id/\nlist-typed severity-status/dup-id downgrade/lowercase p0/status!='closed').\n\n- L5-01 (P0, fail-open):\n[…]\nion tests added (rings -> anomaly, linear chain -> legit; the concession\nwords -> not counted). Full suite 1945 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(register): P0 supersession-cycle fail-open (6-lens gate L5-01) + …", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T11:52:20Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "5bf162451046cc4dc6e5196690dfc5c70e43b357", "body": "…rify_dual_hash guard (P2 L3-02)\n\nThe single-round 6-lens Berkeley gate confirmed 2 findings (and confirmed the crypto/\ncanonicality, RT-09 direct-dict budgets incl. string_len, relation subject-pin, and RT-10\nregister/pre_tag surfaces all WITHSTOOD). Both fixed:\n\n- L6-01 (P1) from-sdist \"pip instal\n[…]\ndded (verify_dual_hash non-bytes; the 5 module-skip guards exercised by the\ncleanroom). Full in-repo suite 1943 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(packaging+never-raise): from-sdist test invariant (P1 L6-01) + ve…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T11:19:34Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "bfae68b63bb4cb1ac21b2babc4990cec03fc2281", "body": "…ound gate L3-01/L3-02)\n\nThe corrected single-round 6-lens Berkeley gate (PUBLIC-contract scoped, no more\ninternal-helper over-confirmation) confirmed 2 P2 never-raise leaks on exported\nrelying-party surfaces; both fixed with zero behavioural change on valid input:\n\n- L3-01 verify_bundle(str) / reco\n[…]\nf-element; first==second None-roots) is now typed-error\nor fail-closed False, 0 raw exceptions. Full suite 1943 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(never-raise): close 2 public raw-exception leaks (6-lens single-r…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T10:39:37Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "aa502badaaccd1a5cc0b8e563bcdc063f6afe7a8", "body": "…ster severity type-confusion P1)\n\nA 6-lens Berkeley re-gate (Owner-tuned agent budget) surfaced further findings; after\nrigorous per-finding verification (PUBLIC never-raise contract applies to exported\nverify_*/evaluate_* only — internal helpers may raise, their public callers wrap them) 3\nwere re\n[…]\n, and\nthe strict public sweep confirms no public caller leaks their TypeError. Not over-fixed.\n\nFull suite 1941 passed / 7 skipped. ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(teil5): remediate 6-lens Berkeley re-gate — 3 real findings (regi…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T10:07:17Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "297a9a61818563065a4dfff9c483ba725fb6527a", "body": "…5 fixes\n\nA faithful Berkeley re-gate (10 attack classes incl. RT-09 direct-dict + RT-10\nassertion-by-absence, 3-juror refute-to-kill) found 6 real defects in this session's\nown Teil-5 work. All fixed with bidirectional regression tests:\n\n- RT10-REG-01 (P1, fail-open): findings_register.verify_and_c\n[…]\nsstehend/... The genuine 3.6.0 record\n still passes.\n\nFull suite 1938 passed / 7 skipped. ruff clean. CHANGELOG updated to the hardened state.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(teil5): remediate 6 Berkeley-gate FIX_FIRST findings on the Teil-…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T09:15:18Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "93c1dbbc2267c8e2d329f776a76aecba6dac0dcc", "body": "…toolchain\n\ncargo fmt --check disagreed with the runner's rustfmt on line breaks at\nmain.rs:1132/1496 because the toolchain was unpinned (rustfmt/clippy output is\nversion-dependent). Pin the exact toolchain in tools/pb_verify_rs/rust-toolchain.toml\n(1.95.0 + rustfmt + clippy), reformat main.rs with \n[…]\ne pinned toolchain.\n\nFindings register: PB-2026-0718-15 open -> closed (regenerated + re-signed, pinned\npubkey stable). 0 open P0/P1 unchanged.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(rust): PB-2026-0718-15 deterministic cargo fmt/clippy via pinned …", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T08:22:14Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "e1bb2f37a41738b36b62f1bbdd4d4d0999801e9a", "body": "…ces stale-substring C12.2 (PB-2026-0718-14)\n\nThe audit_candidate_matrix C12.2 \"0 open P0/P1\" check derived PASS from a lexical\n\"0 open P0/P1\" substring in a version-scoped .md, with NO freshness / supersession /\nsignature / contradiction check. A STALE record that still said \"0 open\" granted PASS\nw\n[…]\n\nsubstring semantics to the register (absent -> FAIL, not PENDING; a fake .md grants nothing).\n\nFull suite 1932 passed / 7 skipped. ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(audit-candidate): RT-10 signed structured findings register repla…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T08:17:01Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "01ab3805c0907d8ffef0e3fa27f2cb557ad766ac", "body": "…y path (PB-2026-0718-16)\n\nThe input_bytes + json_nodes + json_depth budget lives in loads_strict, which a STR\nbundle path funnels through (load_bundle -> loads_strict). A caller that hands an\nALREADY-PARSED dict to verify_bundle(dict) bypassed that chokepoint, so the structural\nbudget was INERT on \n[…]\n Shallow bundles unaffected.\n\nRegression: tests/test_sibling_never_raise_361.py::CallerPathTypedErrors::test_rt09_direct_dict_structural_budget\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(budget): RT-09 enforce structural budget on the direct-dict verif…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T07:45:41Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "805d68e1e861cc0b85d87ac08cc7411f82e6df87", "body": "…-0718 thorough-sweep closure)\n\nevaluate_public_transparency built a named-status dict verdict but a non-str\nsigned_note (123/None/list) hit an early string op → raw AttributeError before\nthe fail-closed path. Coerce a non-str note to \"\" so every checkpoint parse\nfails gracefully (all statuses FAIL)\n[…]\nrdict).\n\nRegression: tests/test_sibling_never_raise_361.py::CallerPathTypedErrors\n ::test_evaluate_public_transparency_non_str_note_is_verdict\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>", "is_bot": false, "headline": "fix(public_transparency): never-raise on non-str signed_note (PB-2026…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T07:33:08Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "1f939d5d2783aa5ec0fca6841d11def185cc8a35", "body": "…athTypedErrors regression\n\nThe new CallerPathTypedErrors regression test (pinning the bc0028a caller-path fixes) exposed a second\nvkey parser: verify_cosignature routes through _parse_witness_vkey (NOT _parse_vkey), which still raised a\nraw AttributeError on a non-str vkey. Added the same isinstanc\n[…]\ney was a valid str, not None/int.)\n\nFull suite 1924 passed; ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "fix(never-raise): _parse_witness_vkey typed on non-str vkey + CallerP…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T07:27:14Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "bc0028a98f7d6d78a0bffb166feefc60140c9a67", "body": "… checkpoint non-str vkey (final sweep)\n\nA comprehensive gate-substitute sweep (every public verify surface x budget/malformed-JSON/type-confusion,\n74 surface-attack combinations across 50 functions) confirmed the whole surface is never-raise for untrusted\nWIRE input, and closed the last two raw-exc\n[…]\nff clean; sweep CLEAN (no raw non-typed exception on any probed input).\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "fix(never-raise): typed caller-path errors — verify_bundle bad-path +…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T07:23:20Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "b9b8aeb5b5e1de481b6a979f5adf37292fec07c3", "body": "…al sweep)\n\nThe comprehensive verify_* sweep found verify_sdjwt_vc raised a raw AttributeError on a non-dict policy\n(policy.get(...)) — the same type-confusion class as decision/outcome/relation_statement. Now a fail-closed\nverdict (ok=False). (bundle.verify_bundle(\u003chuge str>) -> OSError is the docu\n[…]\n wire input; left for the gate to adjudicate.) Suite green; ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "fix(never-raise): verify_sdjwt_vc fail-closed on non-dict policy (fin…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T06:25:53Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "d191e844a15142e2ff63525de4c5b8f98dae2994", "body": "…rs never-raise, HF token budget-consistent\n\nTo break the round-by-round pattern (each Berkeley RE-GATE found the budget-leak class on one more verify\nsurface), a full sweep of every loads_strict call site closed the remaining ones in one batch:\n\n- intoto verify_intoto_dsse / verify_eval_result_dsse\n[…]\nFalse + duplicate named in detail). Full suite 1922 passed; ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "fix(never-raise): proactive loads_strict-sweep — in-toto DSSE verifie…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T06:23:04Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "6a3dec77bfb2daa7540c09fc9ef8dcbeb1c33a0e", "body": "…get family + relstmt policy + CLI inspect)\n\nThe Berkeley gate on ee923a4 found the never-raise budget class STILL LIVE on the SD-JWT family (which I had\nonly fixed for TYPE-confusion, not budget) plus two more:\n\nBUDGET (P1 x5) verify_status_snapshot / verify_key_binding / verify_sd_jwt (header+payl\n[…]\nicyGuard, CliInspectLoneSurrogate).\nFull suite 1922 passed; ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "fix(never-raise): close 9 final Berkeley RE-GATE findings (SD-JWT bud…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T06:10:35Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "ee923a48923806c0a233d90a6daa2bd83f6818ce", "body": "…part deferred to 3.6.2)\n\nThe CI fmt/clippy gate I added turned the previously-green advisory rust-parity check RED: the runner's\nrustfmt formats differently than the local toolchain (rust 1.95.0) — Diff at main.rs:1132/1496 — a classic\nrustfmt version drift. The code stays cargo-fmt + clippy-clean \n[…]\n a red advisory check (No-Fake: a red check must be a real regression).\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "ci(rust): revert version-fragile fmt/clippy gate (PB-2026-0718-15 CI …", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T05:33:32Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "29bbbbc38db87e41caa205376fb54992609c6fd0", "body": "…gate to the rust job\n\nCatches a fmt/clippy regression in the Rust second-verifier going forward (advisory rust job, annotates).\nPlus the CHANGELOG entry for the fmt/clippy code fix.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "ci(rust): PB-2026-0718-15 add cargo fmt --check + clippy -D warnings …", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T05:29:22Z", "body_truncated": false, "is_coding_agent": true }, { "oid": "4e9dbc7f4c20f77bbabf849811de2a1d0224dae3", "body": "…rity preserved)\n\nTeil-5 finding: the Rust second-verifier tree was not fmt-clean and clippy -D warnings failed\n(collapsible-match in the same-key fail-closed branch, a redundant closure). Applied `cargo fmt` and the\ntwo machine-applicable clippy fixes.\n\nNo behavior change: the fixes are cosmetic (f\n[…]\nn vectors and the same-key branch clippy touched). Release build\nclean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "style(rust): PB-2026-0718-15 cargo fmt + clippy -D warnings green (pa…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T05:28:03Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "7f6a6dc323225f329ab306c18d27bbbe3f2d09c3", "body": "…erification core (direct dict path)\n\nTeil-5 finding (Berkeley GATE-T5-02): the merkle_path budget (256) was defined but enforced NOWHERE.\nverify_inclusion / verify_consistency ran a per-step hash loop over an unbounded proof list, and the 8 MiB\ninput_bytes byte-proxy never applies when a bundle is \n[…]\nfails, legit small proof verifies).\nFull suite 1919 passed; ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "fix(budget): PB-2026-0718-16 enforce merkle-path step budget in the v…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T05:25:06Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "c13159130dc6e13cd2ac1064a25b9cb4c93eb5c8", "body": "…asses vacuously on singletons\n\nTeil-4 finding: the corpus-integrity comparator grouped cases by crossFormatId and SKIPPED any group with\n\u003c 2 members. All six xfmt-* groups had exactly one member, so the \"same scenario agrees across formats\"\ncheck was vacuously true and reported ok=true while verify\n[…]\ntic contradictory pair fails; an agreeing pair passes. Full suite 1916.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "fix(conformance): PB-2026-0718-11 cross-format comparator no longer p…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T05:14:45Z", "body_truncated": true, "is_coding_agent": true }, { "oid": "cb52ca062489eb0ec158092da483b2cbcbaa3c87", "body": "…pe-confused input\n\nExtends the breadth sweep: verify_sd_jwt (dict-returning, untrusted SD-JWT compact from a holder) raised a\nraw AttributeError on a non-str compact (.split(\"~\")); verify_commitment raised a raw AttributeError on a\nnon-str PRESENTED identifier (identifier.encode() inside salted_com\n[…]\nff clean. Regression cases added to tests/test_sibling_never_raise_361.\n\nCo-Authored-By: Claude Opus 4.8 \u003cnoreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS", "is_bot": false, "headline": "fix(never-raise): verify_sd_jwt + verify_commitment fail-closed on ty…", "author_name": "kraxo", "author_login": null, "committed_at": "2026-07-18T05:04:43Z", "body_truncated": true, "is_coding_agent": true } ], "releases_count": 47, "commits_last_year": 560, "latest_release_at": "2026-07-23T11:34:27Z", "latest_release_tag": "v3.7.0", "releases_from_tags": false, "days_since_last_push": 0, "active_weeks_last_year": 4, "days_since_latest_release": 0, "mean_days_between_releases": 0.8 }, "community": { "has_readme": true, "has_license": true, "has_description": true, "has_contributing": true, "health_percentage": 100, "has_issue_template": false, "has_code_of_conduct": true, "has_pull_request_template": true }, "ecosystem": { "packages": [ { "name": "proofbundle", "exists": true, "license": "MIT", "keywords": [ "cryptography", "merkle", "transparency-log", "ed25519", "sd-jwt", "verifiable-credentials", "attestation", "provenance", "rfc6962", "Development Status :: 4 - Beta", "Intended Audience :: Developers", "License :: OSI Approved :: MIT License", "Programming Language :: Python :: 3", "Programming Language :: Python :: 3.10", "Programming Language :: Python :: 3.11", "Programming Language :: Python :: 3.12", "Programming Language :: Python :: 3.13", "Programming Language :: Python :: 3.14", "Topic :: Security :: Cryptography" ], "ecosystem": "pypi", "matches_repo": true, "registry_url": "https://pypi.org/project/proofbundle/", "is_deprecated": false, "latest_version": "3.7.0", "repository_url": "https://github.com/b7n0de/proofbundle", "versions_count": 41, "total_downloads": null, "dependents_count": null, "deprecation_note": null, "maintainers_count": null, "monthly_downloads": 6574, "first_published_at": "2026-07-01T15:10:44.562607Z", "latest_published_at": "2026-07-23T11:48:28.208813Z", "latest_version_yanked": null, "days_since_latest_publish": 0 } ] }, "popularity": { "forks": 2, "stars": 2, "watchers": 0, "fork_history": { "days": [ { "date": "2026-07-06", "count": 1 }, { "date": "2026-07-20", "count": 1 } ], "complete": true, "collected": 2, "total_forks": 2 }, "star_history": null, "open_issues_and_prs": 5 }, "ai_readiness": { "has_nix": false, "example_dirs": [ "examples" ], "has_llms_txt": false, "has_dockerfile": true, "has_mcp_signal": false, "bootstrap_files": [ "Makefile" ], "api_schema_files": [], "has_devcontainer": false, "typecheck_configs": [ "src/proofbundle/py.typed" ], "toolchain_manifests": [ "tools/pb_verify_rs/Cargo.toml" ], "largest_source_bytes": 171563, "source_files_sampled": 257, "oversized_source_files": 3, "agent_instruction_files": [], "agent_instruction_max_bytes": null }, "dependencies": { "manifests": [ "pyproject.toml" ], "advisories": { "error": null, "scope": "repository_graph", "source": "osv", "findings": [], "collected": true, "malicious": [], "truncated": false, "by_severity": {}, "advisory_count": 0, "affected_count": 0, "assessed_count": 46, "malicious_count": 0, "assessed_package": null, "unassessed_count": 16, "direct_affected_count": 0 }, "ecosystems": [ "pypi" ], "dependencies": [ { "name": "cryptography", "manifest": "pyproject.toml", "ecosystem": "pypi", "version_constraint": ">=42" }, { "name": "rfc8785", "manifest": "pyproject.toml", "ecosystem": "pypi", "version_constraint": ">=0.1.4" } ], "all_dependencies": { "error": null, "source": "github-sbom", "packages": [ { "name": "cryptography", "direct": true, "version": null, "ecosystem": "pypi" }, { "name": "rfc8785", "direct": true, "version": null, "ecosystem": "pypi" }, { "name": "base64", "direct": false, "version": "0.22.1", "ecosystem": "crates" }, { "name": "base64ct", "direct": false, "version": "1.8.3", "ecosystem": "crates" }, { "name": "block-buffer", "direct": false, "version": "0.10.4", "ecosystem": "crates" }, { "name": "cfg-if", "direct": false, "version": "1.0.4", "ecosystem": "crates" }, { "name": "const-oid", "direct": false, "version": "0.9.6", "ecosystem": "crates" }, { "name": "cpufeatures", "direct": false, "version": "0.2.17", "ecosystem": "crates" }, { "name": "crypto-common", "direct": false, "version": "0.1.7", "ecosystem": "crates" }, { "name": "curve25519-dalek", "direct": false, "version": "4.1.3", "ecosystem": "crates" }, { "name": "curve25519-dalek-derive", "direct": false, "version": "0.1.1", "ecosystem": "crates" }, { "name": "der", "direct": false, "version": "0.7.10", "ecosystem": "crates" }, { "name": "digest", "direct": false, "version": "0.10.7", "ecosystem": "crates" }, { "name": "ed25519", "direct": false, "version": "2.2.3", "ecosystem": "crates" }, { "name": "ed25519-dalek", "direct": false, "version": "2.2.0", "ecosystem": "crates" }, { "name": "equivalent", "direct": false, "version": "1.0.2", "ecosystem": "crates" }, { "name": "fiat-crypto", "direct": false, "version": "0.2.9", "ecosystem": "crates" }, { "name": "generic-array", "direct": false, "version": "0.14.7", "ecosystem": "crates" }, { "name": "getrandom", "direct": false, "version": "0.2.17", "ecosystem": "crates" }, { "name": "hashbrown", "direct": false, "version": "0.17.1", "ecosystem": "crates" }, { "name": "hex", "direct": false, "version": "0.4.3", "ecosystem": "crates" }, { "name": "indexmap", "direct": false, "version": "2.14.0", "ecosystem": "crates" }, { "name": "itoa", "direct": false, "version": "1.0.18", "ecosystem": "crates" }, { "name": "libc", "direct": false, "version": "0.2.186", "ecosystem": "crates" }, { "name": "memchr", "direct": false, "version": "2.8.3", "ecosystem": "crates" }, { "name": "pkcs8", "direct": false, "version": "0.10.2", "ecosystem": "crates" }, { "name": "proc-macro2", "direct": false, "version": "1.0.106", "ecosystem": "crates" }, { "name": "quote", "direct": false, "version": "1.0.46", "ecosystem": "crates" }, { "name": "rand_core", "direct": false, "version": "0.6.4", "ecosystem": "crates" }, { "name": "rustc_version", "direct": false, "version": "0.4.1", "ecosystem": "crates" }, { "name": "ryu-js", "direct": false, "version": "0.2.2", "ecosystem": "crates" }, { "name": "semver", "direct": false, "version": "1.0.28", "ecosystem": "crates" }, { "name": "serde", "direct": false, "version": "1.0.228", "ecosystem": "crates" }, { "name": "serde_core", "direct": false, "version": "1.0.228", "ecosystem": "crates" }, { "name": "serde_derive", "direct": false, "version": "1.0.228", "ecosystem": "crates" }, { "name": "serde_jcs", "direct": false, "version": "0.1.0", "ecosystem": "crates" }, { "name": "serde_json", "direct": false, "version": "1.0.150", "ecosystem": "crates" }, { "name": "sha2", "direct": false, "version": "0.10.9", "ecosystem": "crates" }, { "name": "signature", "direct": false, "version": "2.2.0", "ecosystem": "crates" }, { "name": "spki", "direct": false, "version": "0.7.3", "ecosystem": "crates" }, { "name": "subtle", "direct": false, "version": "2.6.1", "ecosystem": "crates" }, { "name": "syn", "direct": false, "version": "2.0.118", "ecosystem": "crates" }, { "name": "typenum", "direct": false, "version": "1.20.1", "ecosystem": "crates" }, { "name": "unicode-ident", "direct": false, "version": "1.0.24", "ecosystem": "crates" }, { "name": "version_check", "direct": false, "version": "0.9.5", "ecosystem": "crates" }, { "name": "wasi", "direct": false, "version": "0.11.1+wasi-snapshot-preview1", "ecosystem": "crates" }, { "name": "zeroize", "direct": false, "version": "1.9.0", "ecosystem": "crates" }, { "name": "zmij", "direct": false, "version": "1.0.23", "ecosystem": "crates" }, { "name": "build", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "ecdsa", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "hypothesis", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "inspect-ai", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "jsonschema", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "mypy", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "opentimestamps", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "pytest", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "pyyaml", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "rfc3161-client", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "ruff", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "sd-jwt", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "setuptools", "direct": false, "version": null, "ecosystem": "pypi" }, { "name": "z3-solver", "direct": false, "version": null, "ecosystem": "pypi" } ], "collected": true, "truncated": false, "total_count": 62, "direct_count": 2, "indirect_count": 60 } }, "maintainership": { "issues": { "open_prs": 0, "merged_prs": 109, "open_issues": 5, "closed_ratio": 0.444, "closed_issues": 4, "closed_unmerged_prs": 9 }, "bus_factor": 1, "bot_contributors": 1, "top_contributors": [ { "type": "User", "login": "b7n0de", "commits": 130, "avatar_url": "https://avatars.githubusercontent.com/u/45888075?v=4" }, { "type": "User", "login": "tuodijihua", "commits": 3, "avatar_url": "https://avatars.githubusercontent.com/u/158809980?v=4" }, { "type": "User", "login": "MarkovianProtocol", "commits": 1, "avatar_url": "https://avatars.githubusercontent.com/u/292588966?v=4" } ], "contributors_sampled": 3, "top_contributor_share": 0.97 }, "quality_signals": { "has_ci": true, "has_tests": true, "ci_workflows": [ "ci.yml", "codeql.yml", "demo-reproducible.yml", "fork-pr-isolation.yml", "published-artifact-gate.yml", "release-integrity.yml", "release.yml", "reusable-build-attest.yml", "scorecard.yml" ], "has_docs_dir": true, "linter_configs": [], "has_editorconfig": false, "has_linter_config": false, "has_precommit_config": false }, "security_signals": { "lockfiles": [ "Cargo.lock" ], "scorecard": { "checks": [ { "name": "Binary-Artifacts", "score": 9, "reason": "binaries present in source code", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts" }, { "name": "Branch-Protection", "score": 3, "reason": "branch protection is not maximal on development and all release branches", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection" }, { "name": "CI-Tests", "score": 10, "reason": "15 out of 15 merged PRs checked by a CI test -- score normalized to 10", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests" }, { "name": "CII-Best-Practices", "score": 0, "reason": "no effort to earn an OpenSSF best practices badge detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices" }, { "name": "Code-Review", "score": 2, "reason": "Found 2/10 approved changesets -- score normalized to 2", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review" }, { "name": "Contributors", "score": 0, "reason": "project has 0 contributing companies or organizations -- score normalized to 0", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors" }, { "name": "Dangerous-Workflow", "score": 10, "reason": "no dangerous workflow patterns detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow" }, { "name": "Dependency-Update-Tool", "score": 10, "reason": "update tool detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool" }, { "name": "Fuzzing", "score": 10, "reason": "project is fuzzed", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing" }, { "name": "License", "score": 10, "reason": "license file detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license" }, { "name": "Maintained", "score": 0, "reason": "project was created within the last 90 days. Please review its contents carefully", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained" }, { "name": "Packaging", "score": 10, "reason": "packaging workflow detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging" }, { "name": "Pinned-Dependencies", "score": 3, "reason": "dependency not pinned by hash detected -- score normalized to 3", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies" }, { "name": "SAST", "score": 10, "reason": "SAST tool is run on all commits", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast" }, { "name": "Security-Policy", "score": 10, "reason": "security policy file detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy" }, { "name": "Signed-Releases", "score": 0, "reason": "Project has not signed or included provenance with any releases.", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases" }, { "name": "Token-Permissions", "score": 10, "reason": "GitHub workflow tokens follow principle of least privilege", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions" }, { "name": "Vulnerabilities", "score": 10, "reason": "0 existing vulnerabilities detected", "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities" } ], "commit": "defc3ee24cc2ef5e07d41b29bf271890d447846e", "ran_at": "2026-07-23T12:24:22Z", "aggregate_score": 6.6, "scorecard_version": "v5.5.0" }, "has_codeql_workflow": true, "has_security_policy": true, "has_dependabot_config": true }, "contribution_flow": { "collected": true, "ci_last_run_at": "2026-07-23T11:48:31Z", "oldest_open_prs": [], "last_merged_pr_at": "2026-07-23T11:08:29Z", "ci_last_conclusion": "SUCCESS", "oldest_open_issues": [ { "number": 7, "created_at": "2026-07-05T00:44:01Z", "last_comment_at": "2026-07-21T14:26:40Z", "last_comment_author": "b7n0de" }, { "number": 24, "created_at": "2026-07-07T18:00:37Z", "last_comment_at": "2026-07-07T18:16:38Z", "last_comment_author": "b7n0de" }, { "number": 26, "created_at": "2026-07-07T19:31:43Z", "last_comment_at": "2026-07-09T23:34:54Z", "last_comment_author": "b7n0de" }, { "number": 27, "created_at": "2026-07-07T19:31:45Z", "last_comment_at": null, "last_comment_author": null }, { "number": 55, "created_at": "2026-07-11T08:01:46Z", "last_comment_at": null, "last_comment_author": null } ] } }, "config": { "disabled_metrics": [], "disabled_categories": [], "disabled_components": {} }, "source": { "url": "https://github.com/b7n0de/proofbundle", "host": "github.com", "name": "proofbundle", "owner": "b7n0de" }, "metrics": { "overall": { "key": "overall", "band": "moderate", "name": "Overall health", "note": null, "notes": [], "value": 64, "inputs": { "security": 73, "vitality": 70, "community": 49, "governance": 48, "engineering": 81 }, "components": [] }, "categories": [ { "key": "vitality", "band": "good", "name": "Vitality", "value": 70, "weight": 0.22, "metrics": [ { "key": "development_activity", "band": "moderate", "name": "Development activity", "note": null, "notes": [], "value": 57, "inputs": { "commits_last_year": 560, "human_commit_share": 0.95, "days_since_last_push": 0, "active_weeks_last_year": 4 }, "components": [ { "key": "push_recency", "name": "Push recency", "detail": "last push 0 days ago", "points": 36, "status": "met", "details": [ { "code": "push_recency", "params": { "days": 0 } } ], "max_points": 36 }, { "key": "commit_cadence", "name": "Commit cadence", "detail": "4/52 weeks with commits", "points": 2.8, "status": "partial", "details": [ { "code": "commit_cadence_weeks", "params": { "weeks": 4 } } ], "max_points": 36 }, { "key": "commit_volume", "name": "Commit volume", "detail": "560 commits in the last year", "points": 18, "status": "met", "details": [ { "code": "commits_last_year", "params": { "count": 560 } } ], "max_points": 18 }, { "key": "openssf_scorecard_maintained", "name": "OpenSSF Scorecard: Maintained", "detail": "project was created within the last 90 days. Please review its contents carefully", "points": 0, "status": "missed", "details": [], "max_points": 10 } ] }, { "key": "release_discipline", "band": "excellent", "name": "Release discipline", "note": null, "notes": [], "value": 90, "inputs": { "releases_count": 47, "latest_release_tag": "v3.7.0", "releases_from_tags": false, "days_since_latest_release": 0, "mean_days_between_releases": 0.8 }, "components": [ { "key": "ships_releases", "name": "Ships releases", "detail": "47 releases published", "points": 27, "status": "met", "details": [ { "code": "releases_published", "params": { "count": 47 } } ], "max_points": 27 }, { "key": "release_recency", "name": "Release recency", "detail": "latest release 0 days ago", "points": 36, "status": "met", "details": [ { "code": "release_recency", "params": { "days": 0 } } ], "max_points": 36 }, { "key": "release_cadence", "name": "Release cadence", "detail": "a release every ~0.8 days", "points": 27, "status": "met", "details": [ { "code": "release_cadence", "params": { "gap": 0.8 } } ], "max_points": 27 }, { "key": "openssf_scorecard_signed_releases", "name": "OpenSSF Scorecard: Signed-Releases", "detail": "Project has not signed or included provenance with any releases.", "points": 0, "status": "missed", "details": [], "max_points": 10 } ] }, { "key": "abandonment", "band": "excellent", "name": "Abandonment", "note": null, "notes": [], "value": 100, "inputs": { "cap": null, "state": "unverified", "guards": [], "signals": [], "red_flag": false, "multiplier_pct": 100, "declared_reason": null, "unverified_reason": "repository_too_young", "unanswered_open_prs": null, "unanswered_open_issues": null, "days_since_last_merged_pr": null, "days_since_last_human_commit": null, "days_since_last_human_commit_is_floor": false }, "components": [ { "key": "project_is_still_maintained", "name": "Project is still maintained", "detail": "maintenance record not established from the collected data", "points": 100, "status": "met", "details": [ { "code": "abandonment_unverified", "params": {} } ], "max_points": 100 } ] } ], "description": "Is the project alive — is code being written and are releases shipping?" }, { "key": "community", "band": "at_risk", "name": "Community & Adoption", "value": 49, "weight": 0.18, "metrics": [ { "key": "popularity", "band": "critical", "name": "Popularity & adoption", "note": null, "notes": [], "value": 1, "inputs": { "forks": 2, "stars": 2, "watchers": 0, "growth_state": "unverified", "growth_factor_pct": 100, "growth_unverified_reason": "no_history" }, "components": [ { "key": "stars", "name": "Stars", "detail": "2 stars", "points": 0, "status": "missed", "details": [ { "code": "stars", "params": { "count": 2 } } ], "max_points": 60 }, { "key": "forks", "name": "Forks", "detail": "2 forks", "points": 0, "status": "missed", "details": [ { "code": "forks", "params": { "count": 2 } } ], "max_points": 25 }, { "key": "watchers", "name": "Watchers", "detail": "0 watchers", "points": 0, "status": "missed", "details": [ { "code": "watchers", "params": { "count": 0 } } ], "max_points": 15 } ] }, { "key": "community_health", "band": "excellent", "name": "Community health", "note": null, "notes": [], "value": 92, "inputs": { "has_readme": true, "has_license": true, "has_contributing": true, "has_issue_template": false, "has_code_of_conduct": true, "has_pull_request_template": true }, "components": [ { "key": "readme", "name": "README", "detail": null, "points": 22.5, "status": "met", "details": [], "max_points": 22.5 }, { "key": "license", "name": "License", "detail": "recognized license (MIT)", "points": 22.5, "status": "met", "details": [ { "code": "license_standard", "params": {} }, { "code": "license_spdx", "params": { "spdx": "MIT" } } ], "max_points": 22.5 }, { "key": "contributing_guide", "name": "CONTRIBUTING guide", "detail": null, "points": 18, "status": "met", "details": [], "max_points": 18 }, { "key": "code_of_conduct", "name": "Code of conduct", "detail": null, "points": 13.5, "status": "met", "details": [], "max_points": 13.5 }, { "key": "issue_template", "name": "Issue template", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 7.2 }, { "key": "pr_template", "name": "PR template", "detail": null, "points": 6.3, "status": "met", "details": [], "max_points": 6.3 } ] }, { "key": "ecosystem_adoption", "band": "moderate", "name": "Ecosystem adoption (downloads)", "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.", "notes": [ { "code": "excluded_no_data", "params": { "components": [ "registry_dependents" ] } }, { "code": "weights_renormalized", "params": {} } ], "value": 64, "inputs": { "packages": [ "proofbundle" ], "dependents": null, "ecosystems": "pypi", "total_downloads": null, "monthly_downloads": 6574 }, "components": [ { "key": "monthly_downloads", "name": "Monthly downloads", "detail": "6,574 downloads/month across pypi", "points": 50.9, "status": "partial", "details": [ { "code": "downloads_monthly", "params": { "count": 6574, "ecosystems": "pypi" } } ], "max_points": 80 }, { "key": "registry_dependents", "name": "Registry dependents", "detail": "not reported by this ecosystem", "points": 0, "status": "excluded", "details": [ { "code": "not_reported_by_this_ecosystem", "params": {} } ], "max_points": 20 } ] } ], "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?" }, { "key": "governance", "band": "at_risk", "name": "Sustainability & Governance", "value": 48, "weight": 0.24, "metrics": [ { "key": "maintainer_resilience", "band": "critical", "name": "Maintainer resilience (bus factor)", "note": null, "notes": [], "value": 14, "inputs": { "bus_factor": 1, "contributors_sampled": 3, "top_contributor_share": 0.97 }, "components": [ { "key": "bus_factor", "name": "Bus factor", "detail": "1 contributor(s) cover half of all commits", "points": 9, "status": "partial", "details": [ { "code": "bus_factor", "params": { "count": 1 } } ], "max_points": 54 }, { "key": "commit_distribution", "name": "Commit distribution", "detail": "top contributor authored 97% of commits", "points": 0.7, "status": "partial", "details": [ { "code": "top_contributor_share", "params": { "share": 97 } } ], "max_points": 22.5 }, { "key": "contributor_breadth", "name": "Contributor breadth", "detail": "3 contributors", "points": 4.1, "status": "partial", "details": [ { "code": "contributors_sampled", "params": { "count": 3 } } ], "max_points": 13.5 }, { "key": "openssf_scorecard_contributors", "name": "OpenSSF Scorecard: Contributors", "detail": "project has 0 contributing companies or organizations -- score normalized to 0", "points": 0, "status": "missed", "details": [], "max_points": 10 } ] }, { "key": "responsiveness", "band": "moderate", "name": "Issue & PR responsiveness", "note": null, "notes": [], "value": 59, "inputs": { "merged_prs": 109, "open_issues": 5, "closed_issues": 4, "issue_closed_ratio": 0.444, "closed_unmerged_prs": 9 }, "components": [ { "key": "issue_resolution", "name": "Issue resolution", "detail": "44% of issues closed", "points": 20.8, "status": "partial", "details": [ { "code": "issues_closed_share", "params": { "share": 44 } } ], "max_points": 46.75 }, { "key": "pr_acceptance", "name": "PR acceptance", "detail": "109/118 decided PRs merged", "points": 35.3, "status": "partial", "details": [ { "code": "decided_prs_merged", "params": { "merged": 109, "decided": 118 } } ], "max_points": 38.25 }, { "key": "openssf_scorecard_code_review", "name": "OpenSSF Scorecard: Code-Review", "detail": "Found 2/10 approved changesets -- score normalized to 2", "points": 3, "status": "partial", "details": [], "max_points": 15 } ] }, { "key": "stewardship", "band": "at_risk", "name": "Ownership & stewardship", "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.", "notes": [ { "code": "excluded_no_data", "params": { "components": [ "verified_domain" ] } }, { "code": "weights_renormalized", "params": {} } ], "value": 37, "inputs": { "followers": 2, "owner_type": "User", "is_verified": null, "owner_login": "b7n0de", "public_repos": 3, "account_age_days": 2777 }, "components": [ { "key": "ownership_backing", "name": "Ownership backing", "detail": "personal (user) account", "points": 10, "status": "partial", "details": [ { "code": "owner_personal", "params": {} } ], "max_points": 30 }, { "key": "verified_domain", "name": "Verified domain", "detail": "not applicable to user accounts", "points": 0, "status": "excluded", "details": [ { "code": "not_applicable_to_user_accounts", "params": {} } ], "max_points": 20 }, { "key": "owner_reach", "name": "Owner reach", "detail": "2 followers of b7n0de", "points": 3.4, "status": "partial", "details": [ { "code": "owner_followers", "params": { "count": 2, "login": "b7n0de" } } ], "max_points": 25 }, { "key": "track_record", "name": "Track record", "detail": "3 public repos, account ~7 yr old", "points": 16.4, "status": "partial", "details": [ { "code": "public_repos", "params": { "count": 3 } }, { "code": "account_age_years", "params": { "years": 7 } } ], "max_points": 25 } ] }, { "key": "package_maintenance", "band": "excellent", "name": "Package maintenance", "note": null, "notes": [], "value": 100, "inputs": { "packages": [ "proofbundle" ], "ecosystems": "pypi", "any_deprecated": false, "min_days_since_publish": 0 }, "components": [ { "key": "published_resolvable", "name": "Published & resolvable", "detail": "1 package(s) on pypi", "points": 25, "status": "met", "details": [ { "code": "packages_published", "params": { "count": 1, "ecosystems": "pypi" } } ], "max_points": 25 }, { "key": "publish_recency", "name": "Publish recency", "detail": "latest publish 0 days ago", "points": 35, "status": "met", "details": [ { "code": "publish_recency", "params": { "days": 0 } } ], "max_points": 35 }, { "key": "version_history", "name": "Version history", "detail": "41 published versions", "points": 20, "status": "met", "details": [ { "code": "published_versions", "params": { "count": 41 } } ], "max_points": 20 }, { "key": "not_deprecated", "name": "Not deprecated", "detail": "active, not deprecated or yanked", "points": 20, "status": "met", "details": [ { "code": "package_not_deprecated", "params": {} } ], "max_points": 20 } ] } ], "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?" }, { "key": "engineering", "band": "good", "name": "Engineering Quality", "value": 81, "weight": 0.2, "metrics": [ { "key": "engineering_practices", "band": "moderate", "name": "Engineering practices", "note": null, "notes": [], "value": 68, "inputs": { "has_ci": true, "has_tests": true, "has_editorconfig": false, "has_linter_config": false, "has_precommit_config": false }, "components": [ { "key": "ci_workflows", "name": "CI workflows", "detail": "9 workflow(s)", "points": 24, "status": "met", "details": [ { "code": "ci_workflows", "params": { "count": 9 } } ], "max_points": 24 }, { "key": "tests_present", "name": "Tests present", "detail": null, "points": 24, "status": "met", "details": [], "max_points": 24 }, { "key": "linter_config", "name": "Linter config", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 16 }, { "key": "pre_commit_hooks", "name": "Pre-commit hooks", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 9.6 }, { "key": "editorconfig", "name": ".editorconfig", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 6.4 }, { "key": "openssf_scorecard_ci_tests", "name": "OpenSSF Scorecard: CI-Tests", "detail": "15 out of 15 merged PRs checked by a CI test -- score normalized to 10", "points": 20, "status": "met", "details": [], "max_points": 20 } ] }, { "key": "documentation", "band": "excellent", "name": "Documentation", "note": null, "notes": [], "value": 100, "inputs": { "topics": [ "attestation", "cryptography", "ed25519", "merkle", "provenance", "python", "rfc6962", "sd-jwt", "transparency-log", "verifiable-credentials", "merkle-tree", "sigstore", "supply-chain-security", "ai-evaluation", "ai-safety", "llm-evaluation", "receipts", "attestations", "evidence" ], "has_wiki": true, "homepage": "https://b7n0de.com/proofbundle", "has_readme": true, "has_docs_dir": true, "has_description": true }, "components": [ { "key": "readme", "name": "README", "detail": null, "points": 30, "status": "met", "details": [], "max_points": 30 }, { "key": "documentation_directory", "name": "Documentation directory", "detail": null, "points": 25, "status": "met", "details": [], "max_points": 25 }, { "key": "documentation_homepage_site", "name": "Documentation / homepage site", "detail": "https://b7n0de.com/proofbundle", "points": 15, "status": "met", "details": [], "max_points": 15 }, { "key": "repository_description", "name": "Repository description", "detail": null, "points": 10, "status": "met", "details": [], "max_points": 10 }, { "key": "topics", "name": "Topics", "detail": "19 topics", "points": 10, "status": "met", "details": [ { "code": "topics_count", "params": { "count": 19 } } ], "max_points": 10 }, { "key": "wiki", "name": "Wiki", "detail": null, "points": 10, "status": "met", "details": [], "max_points": 10 } ] } ], "description": "Are baseline engineering and documentation practices in place?" }, { "key": "security", "band": "good", "name": "Security", "value": 73, "weight": 0.16, "metrics": [ { "key": "security_posture", "band": "moderate", "name": "Security posture", "note": null, "notes": [], "value": 66, "inputs": { "source": "openssf_scorecard", "checks_evaluated": 18, "scorecard_version": "v5.5.0", "checks_inconclusive": 0, "scorecard_aggregate": 6.6 }, "components": [ { "key": "binary_artifacts", "name": "Binary-Artifacts", "detail": "binaries present in source code", "points": 6.8, "status": "partial", "details": [], "max_points": 7.5 }, { "key": "branch_protection", "name": "Branch-Protection", "detail": "branch protection is not maximal on development and all release branches", "points": 2.2, "status": "partial", "details": [], "max_points": 7.5 }, { "key": "ci_tests", "name": "CI-Tests", "detail": "15 out of 15 merged PRs checked by a CI test -- score normalized to 10", "points": 2.5, "status": "met", "details": [], "max_points": 2.5 }, { "key": "cii_best_practices", "name": "CII-Best-Practices", "detail": "no effort to earn an OpenSSF best practices badge detected", "points": 0, "status": "missed", "details": [], "max_points": 2.5 }, { "key": "code_review", "name": "Code-Review", "detail": "Found 2/10 approved changesets -- score normalized to 2", "points": 1.5, "status": "partial", "details": [], "max_points": 7.5 }, { "key": "contributors", "name": "Contributors", "detail": "project has 0 contributing companies or organizations -- score normalized to 0", "points": 0, "status": "missed", "details": [], "max_points": 2.5 }, { "key": "dangerous_workflow", "name": "Dangerous-Workflow", "detail": "no dangerous workflow patterns detected", "points": 10, "status": "met", "details": [], "max_points": 10 }, { "key": "dependency_update_tool", "name": "Dependency-Update-Tool", "detail": "update tool detected", "points": 7.5, "status": "met", "details": [], "max_points": 7.5 }, { "key": "fuzzing", "name": "Fuzzing", "detail": "project is fuzzed", "points": 5, "status": "met", "details": [], "max_points": 5 }, { "key": "license", "name": "License", "detail": "license file detected", "points": 2.5, "status": "met", "details": [], "max_points": 2.5 }, { "key": "maintained", "name": "Maintained", "detail": "project was created within the last 90 days. Please review its contents carefully", "points": 0, "status": "missed", "details": [], "max_points": 7.5 }, { "key": "packaging", "name": "Packaging", "detail": "packaging workflow detected", "points": 5, "status": "met", "details": [], "max_points": 5 }, { "key": "pinned_dependencies", "name": "Pinned-Dependencies", "detail": "dependency not pinned by hash detected -- score normalized to 3", "points": 1.5, "status": "partial", "details": [], "max_points": 5 }, { "key": "sast", "name": "SAST", "detail": "SAST tool is run on all commits", "points": 5, "status": "met", "details": [], "max_points": 5 }, { "key": "security_policy", "name": "Security-Policy", "detail": "security policy file detected", "points": 5, "status": "met", "details": [], "max_points": 5 }, { "key": "signed_releases", "name": "Signed-Releases", "detail": "Project has not signed or included provenance with any releases.", "points": 0, "status": "missed", "details": [], "max_points": 7.5 }, { "key": "token_permissions", "name": "Token-Permissions", "detail": "GitHub workflow tokens follow principle of least privilege", "points": 7.5, "status": "met", "details": [], "max_points": 7.5 }, { "key": "vulnerabilities", "name": "Vulnerabilities", "detail": "0 existing vulnerabilities detected", "points": 7.5, "status": "met", "details": [], "max_points": 7.5 } ] }, { "key": "dependency_advisories", "band": "excellent", "name": "Dependency advisories", "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 46 resolved dependencies against OSV; 16 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.", "notes": [ { "code": "excluded_no_data", "params": { "components": [ "indirect_dependencies_free_of_known_advisories", "no_advisories_left_outstanding" ] } }, { "code": "weights_renormalized", "params": {} }, { "code": "advisories_scope_repository", "params": { "assessed": 46 } }, { "code": "advisories_unassessed", "params": { "count": 16 } }, { "code": "advisories_repo_graph_caveat", "params": {} }, { "code": "advisories_reachability", "params": {} } ], "value": 100, "inputs": { "source": "osv", "advisories": 0, "affected_packages": 0, "assessed_packages": 46, "unassessed_packages": 16, "affected_by_severity": "none", "direct_affected_packages": 0 }, "components": [ { "key": "direct_dependencies_free_of_known_advisories", "name": "Direct dependencies free of known advisories", "detail": "no direct dependency carries a known advisory", "points": 35, "status": "met", "details": [ { "code": "no_direct_advisories", "params": {} } ], "max_points": 35 }, { "key": "indirect_dependencies_free_of_known_advisories", "name": "Indirect dependencies free of known advisories", "detail": "transitive set not separable from development and test dependencies in this scope", "points": 0, "status": "excluded", "details": [ { "code": "advisories_scope_not_separable", "params": {} } ], "max_points": 25 }, { "key": "no_advisories_left_outstanding", "name": "No advisories left outstanding", "detail": "no advisory carries a publication date", "points": 0, "status": "excluded", "details": [ { "code": "advisories_no_publication_date", "params": {} } ], "max_points": 40 } ] }, { "key": "malicious_dependencies", "band": "excellent", "name": "Malicious dependencies", "note": null, "notes": [], "value": 100, "inputs": { "source": "osv", "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored", "packages": [], "red_flag": false, "assessed_packages": 46, "malicious_packages": 0, "direct_malicious_packages": 0, "withdrawn_malicious_packages": 0, "installable_malicious_packages": 0 }, "components": [ { "key": "no_dependency_reported_as_a_malicious_package", "name": "No dependency reported as a malicious package", "detail": "no dependency is reported as a malicious package", "points": 100, "status": "met", "details": [ { "code": "no_malicious_dependencies", "params": {} } ], "max_points": 100 } ] } ], "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?" }, { "key": "ai_readiness", "band": "moderate", "name": "AI Readiness", "value": 63, "weight": 0, "metrics": [ { "key": "ai_agent_context", "band": "at_risk", "name": "Agent context & guidance", "note": null, "notes": [], "value": 40, "inputs": { "has_llms_txt": false, "legible_history_share": 0.979, "agent_instruction_files": [], "agent_instruction_max_bytes": null }, "components": [ { "key": "agent_instructions", "name": "Agent instructions", "detail": "no CLAUDE.md / AGENTS.md / editor rules", "points": 0, "status": "missed", "details": [ { "code": "no_agent_instructions", "params": {} } ], "max_points": 45 }, { "key": "machine_readable_docs_llms_txt", "name": "Machine-readable docs (llms.txt)", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 15 }, { "key": "legible_commit_history", "name": "Legible commit history", "detail": "93 of 95 human commits state their intent (structured subject or explanatory body)", "points": 40, "status": "met", "details": [ { "code": "legible_history", "params": { "legible": 93, "sampled": 95 } } ], "max_points": 40 } ] }, { "key": "ai_verify_loop", "band": "good", "name": "Verify loop (build / test / typecheck)", "note": null, "notes": [], "value": 82, "inputs": { "has_nix": false, "has_tests": true, "lockfiles": [ "Cargo.lock" ], "has_dockerfile": true, "typed_language": false, "bootstrap_files": [ "Makefile" ], "has_devcontainer": false, "has_linter_config": false, "typecheck_configs": [ "src/proofbundle/py.typed" ], "agent_commit_share": 0.59, "toolchain_manifests": [ "tools/pb_verify_rs/Cargo.toml" ], "dependency_bot_commit_share": 0.05 }, "components": [ { "key": "one_command_bootstrap", "name": "One-command bootstrap", "detail": "Makefile", "points": 18, "status": "met", "details": [ { "code": "file_list", "params": { "files": "Makefile" } } ], "max_points": 18 }, { "key": "automated_tests", "name": "Automated tests", "detail": null, "points": 22, "status": "met", "details": [], "max_points": 22 }, { "key": "lint_format_config", "name": "Lint / format config", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 11 }, { "key": "static_type_checking", "name": "Static type checking", "detail": "src/proofbundle/py.typed", "points": 11, "status": "met", "details": [ { "code": "file_list", "params": { "files": "src/proofbundle/py.typed" } } ], "max_points": 11 }, { "key": "reproducible_environment", "name": "Reproducible environment", "detail": "Dockerfile, lockfile", "points": 10, "status": "met", "details": [ { "code": "file_list", "params": { "files": "Dockerfile, lockfile" } } ], "max_points": 10 }, { "key": "demonstrated_agent_practice", "name": "Demonstrated agent practice", "detail": "59 of the last 100 commits agent-authored or agent-credited", "points": 10, "status": "met", "details": [ { "code": "agent_authored_commits", "params": { "count": 59, "sampled": 100 } } ], "max_points": 10 }, { "key": "automated_maintenance", "name": "Automated maintenance", "detail": "5 of the last 100 commits are automated dependency updates", "points": 8, "status": "met", "details": [ { "code": "dependency_bot_commits", "params": { "count": 5, "sampled": 100 } } ], "max_points": 8 }, { "key": "openssf_scorecard_pinned_dependencies", "name": "OpenSSF Scorecard: Pinned-Dependencies", "detail": "dependency not pinned by hash detected -- score normalized to 3", "points": 3, "status": "partial", "details": [], "max_points": 10 } ] }, { "key": "ai_code_legibility", "band": "good", "name": "Code legibility for models", "note": null, "notes": [], "value": 81, "inputs": { "primary_language": "Python", "largest_source_bytes": 171563, "source_files_sampled": 257, "oversized_source_files": 3 }, "components": [ { "key": "type_checkable_code", "name": "Type-checkable code", "detail": "Python with type-check config (src/proofbundle/py.typed)", "points": 27, "status": "partial", "details": [ { "code": "typecheck_config_language", "params": { "files": "src/proofbundle/py.typed", "language": "Python" } } ], "max_points": 45 }, { "key": "manageable_file_sizes", "name": "Manageable file sizes", "detail": "3/257 source files over 60KB", "points": 54.4, "status": "partial", "details": [ { "code": "oversized_source_files", "params": { "kb": 60, "sampled": 257, "oversized": 3 } } ], "max_points": 55 } ] }, { "key": "ai_interfaces", "band": "at_risk", "name": "Machine-readable interfaces", "note": null, "notes": [], "value": 40, "inputs": { "example_dirs": [ "examples" ], "has_mcp_signal": false, "api_schema_files": [] }, "components": [ { "key": "api_schema_openapi_graphql_proto", "name": "API schema (OpenAPI/GraphQL/proto)", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 40 }, { "key": "mcp_server", "name": "MCP server", "detail": null, "points": 0, "status": "missed", "details": [], "max_points": 20 }, { "key": "runnable_examples", "name": "Runnable examples", "detail": "examples", "points": 40, "status": "met", "details": [ { "code": "file_list", "params": { "files": "examples" } } ], "max_points": 40 } ] } ], "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score." } ], "metrics_version": "1.13.0" }, "warnings": [ "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token", "deps.dev does not index pypi:proofbundle@3.7.0; advisories assessed against the repository dependency graph instead" ], "report_type": "repository", "generated_at": "2026-07-23T12:24:39.941015Z", "schema_version": "0.27.0", "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/b/b7n0de/proofbundle.svg", "full_name": "b7n0de/proofbundle", "license_state": "standard", "license_spdx": "MIT" }, "repoMeta": null, "notFound": false, "related": [ { "id": 30197, "full_name": "microsoft/agent-governance-toolkit", "url": "https://github.com/microsoft/agent-governance-toolkit", "description": "AI Agent Governance Toolkit — Policy enforcement, zero-trust identity, execution sandboxing, and reliability engineering for autonomous AI agents. Covers 10/10 OWASP Agentic Top 10.", "ecosystem": "npm", "ecosystems": [ "npm", "go", "crates" ], "primary_language": "Python", "languages": [ "Python" ], "topics": [ "agent-framework", "ai-agents", "ai-safety", "compliance", "governance", "microsoft", "owasp", "policy-engine", "python", "security", "trust", "zero-trust", "antigravity", "cli", "agent", "policy", "claude-code", "mcp", "copilot", "opencode", "agentmesh", "identity", "audit" ], "license_spdx": "MIT", "license_state": "standard", "stars": 4869, "forks": 772, "watchers": 66, "monthly_downloads": 12295, "latest_score": 86, "latest_band": "excellent", "latest_scanned_at": "2026-07-20T23:06:13.846894Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" }, { "id": 9450, "full_name": "chainloop-dev/chainloop", "url": "https://github.com/chainloop-dev/chainloop", "description": "SDLC evidence store and policy engine for your Software Supply Chain attestations, SBOMs, VEX, SARIF, QA reports, and more", "ecosystem": "go", "ecosystems": [ "go" ], "primary_language": "Go", "languages": [ "Go" ], "topics": [ "compliance", "cyclonedx", "devsecops", "sbom", "sbom-distribution", "security", "spdx", "supply-chain-security", "metadata-platform", "sbom-discovery", "license", "open-source-licensing", "ospo", "oss-compliance", "regulated-industry", "attestation", "in-toto", "slsa", "slsa-provenance" ], "license_spdx": "Apache-2.0", "license_state": "standard", "stars": 570, "forks": 53, "watchers": 8, "monthly_downloads": null, "latest_score": 85, "latest_band": "excellent", "latest_scanned_at": "2026-07-16T01:23:17.566089Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" }, { "id": 139, "full_name": "apache/superset", "url": "https://github.com/apache/superset", "description": "Apache Superset is a Data Visualization and Data Exploration Platform", "ecosystem": "npm", "ecosystems": [ "npm", "pypi" ], "primary_language": "TypeScript", "languages": [ "TypeScript", "Python", "Jupyter Notebook" ], "topics": [ "superset", "apache", "apache-superset", "data-visualization", "data-viz", "analytics", "business-intelligence", "data-science", "data-engineering", "asf", "bi", "business-analytics", "data-analytics", "data-analysis", "python", "react", "sql-editor", "flask", "extensions", "visualization", "embed", "embedded", "sdk", "iframe", "dashboard", "chart", "cli", "development-tools" ], "license_spdx": "Apache-2.0", "license_state": "standard", "stars": 73846, "forks": 17889, "watchers": 1535, "monthly_downloads": 1098754, "latest_score": 97, "latest_band": "excellent", "latest_scanned_at": "2026-07-15T20:41:37.957488Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" }, { "id": 10747, "full_name": "scikit-learn/scikit-learn", "url": "https://github.com/scikit-learn/scikit-learn", "description": "scikit-learn: machine learning in Python", "ecosystem": "pypi", "ecosystems": [ "pypi" ], "primary_language": "Python", "languages": [ "Python" ], "topics": [ "machine-learning", "python", "statistics", "data-science", "data-analysis" ], "license_spdx": "BSD-3-Clause", "license_state": "standard", "stars": 66748, "forks": 27200, "watchers": 2124, "monthly_downloads": 216399843, "latest_score": 95, "latest_band": "excellent", "latest_scanned_at": "2026-07-22T01:48:23.800991Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "organic", "abandonment_state": "maintained", "red_flags": [], "badge_url": "" }, { "id": 21284, "full_name": "optuna/optuna", "url": "https://github.com/optuna/optuna", "description": "A hyperparameter optimization framework", "ecosystem": "pypi", "ecosystems": [ "pypi" ], "primary_language": "Python", "languages": [ "Python" ], "topics": [ "python", "machine-learning", "parallel", "distributed", "hyperparameter-optimization" ], "license_spdx": "MIT", "license_state": "standard", "stars": 14521, "forks": 1356, "watchers": 122, "monthly_downloads": 15935670, "latest_score": 93, "latest_band": "excellent", "latest_scanned_at": "2026-07-18T12:57:58.825568Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" }, { "id": 30859, "full_name": "deepset-ai/haystack", "url": "https://github.com/deepset-ai/haystack", "description": "Open-source AI orchestration framework for building context-engineered, production-ready LLM applications. Design modular pipelines and agent workflows with explicit control over retrieval, routing, memory, and generation. Built for scalable agents, RAG, multimodal applications, semantic search, and conversational systems.", "ecosystem": "pypi", "ecosystems": [ "pypi", "npm" ], "primary_language": "Python", "languages": [ "Python" ], "topics": [ "nlp", "question-answering", "pytorch", "semantic-search", "information-retrieval", "summarization", "transformers", "machine-learning", "ai", "python", "large-language-models", "generative-ai", "llm", "rag", "retrieval-augmented-generation", "agents", "agent", "gemini", "gpt-4", "orchestration", "bert", "qa", "reader", "retriever", "albert", "language-model", "mrc", "roberta", "search", "squad", "transfer-learning", "transformer" ], "license_spdx": "Apache-2.0", "license_state": "standard", "stars": 25959, "forks": 2941, "watchers": 160, "monthly_downloads": 1022672, "latest_score": 93, "latest_band": "excellent", "latest_scanned_at": "2026-07-21T02:32:10.344140Z", "has_high_risk_jurisdiction_exposure": false, "has_malicious_dependency": false, "growth_authenticity": "unverified", "abandonment_state": "unverified", "red_flags": [], "badge_url": "" } ] } }
Offline cryptographic receipts for AI evaluation results — Ed25519 + RFC 6962 Merkle + optional SD-JWT. Integrity, not truth
b7n0de/proofbundle 的健康指数为 100 分中的 64 分,处于「中等」区间。 其得分最高的类别是Engineering Quality(81/100),最低的是Sustainability & Governance(48/100)。 最近一次更新在今天。 近期的大部分工作由 1 位贡献者完成。
指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。
每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。
| 注册表 | 软件包 | 版本 | 月下载量 | 版本数 | 最近发布 | 标签 |
|---|---|---|---|---|---|---|
| PyPI | proofbundle | 3.7.0 | 6,574 | 41 | 0 天前 | cryptographymerkletransparency-loged25519sd-jwtverifiable-credentialsattestationprovenancerfc6962 |
项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?
| 36/36 | 推送新近度 — 最近一次推送于 0 天前 |
| 2.8/36 | 提交节奏 — 52 周中有 4 周有提交 |
| 18/18 | 提交量 — 最近一年 560 次提交 |
| 0/10 | OpenSSF Scorecard:Maintained — project was created within the last 90 days. Please review its contents carefully |
| commits_last_year | 560 |
| human_commit_share | 0.95 |
| days_since_last_push | 0 |
| active_weeks_last_year | 4 |
| 27/27 | 有发布版本 — 已发布 47 个发布版本 |
| 36/36 | 发布时效 — 最近一次发布版本于 0 天前 |
| 27/27 | 发布节奏 — 约每 0.8 天发布一次 |
| 0/10 | OpenSSF Scorecard:Signed-Releases — Project has not signed or included provenance with any releases. |
| releases_count | 47 |
| latest_release_tag | v3.7.0 |
| releases_from_tags | 否 |
| days_since_latest_release | 0 |
| mean_days_between_releases | 0.8 |
项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?
| 0/60 | 星标 — 2 个星标 |
| 0/25 | 复刻 — 2 个复刻 |
| 0/15 | 关注者 — 0 位关注者 |
| forks | 2 |
| stars | 2 |
| watchers | 0 |
| growth_state | unverified |
| growth_factor_pct | 100 |
| growth_unverified_reason | no_history |
| 22.5/22.5 | README |
| 22.5/22.5 | 许可证 — 可识别的许可证(MIT) |
| 18/18 | CONTRIBUTING 指南 |
| 13.5/13.5 | 行为准则 |
| 0/7.2 | 议题模板 |
| 6.3/6.3 | PR 模板 |
| has_readme | 是 |
| has_license | 是 |
| has_contributing | 是 |
| has_issue_template | 否 |
| has_code_of_conduct | 是 |
| has_pull_request_template | 是 |
| 50.9/80 | 月度下载量 — pypi 合计每月 6,574 次下载 |
| 0/20 | 注册表被依赖数 — 该生态系统不报告此项 |
| packages | proofbundle |
| dependents | — |
| ecosystems | pypi |
| total_downloads | — |
| monthly_downloads | 6,574 |
项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?
| 9/54 | 巴士系数 — 1 位贡献者贡献了半数提交 |
| 0.7/22.5 | 提交分布 — 头号贡献者编写了 97% 的提交 |
| 4.1/13.5 | 贡献者广度 — 3 位贡献者 |
| 0/10 | OpenSSF Scorecard:Contributors — project has 0 contributing companies or organizations -- score normalized to 0 |
| bus_factor | 1 |
| contributors_sampled | 3 |
| top_contributor_share | 0.97 |
| 20.8/46.8 | 议题解决 — 44% 的议题已关闭 |
| 35.3/38.3 | PR 接受 — 已裁定的 PR 中 109/118 已合并 |
| 3/15 | OpenSSF Scorecard:Code-Review — Found 2/10 approved changesets -- score normalized to 2 |
| merged_prs | 109 |
| open_issues | 5 |
| closed_issues | 4 |
| issue_closed_ratio | 0.444 |
| closed_unmerged_prs | 9 |
| 10/30 | 所有权背书 — 个人(用户)账户 |
| 0/20 | 已验证域名 — 不适用于个人账户 |
| 3.4/25 | 所有者影响力 — b7n0de 有 2 位关注者 |
| 16.4/25 | 既往记录 — 3 个公开仓库,账户约 7 年 |
| followers | 2 |
| owner_type | User |
| is_verified | — |
| owner_login | b7n0de |
| public_repos | 3 |
| account_age_days | 2,777 |
| 25/25 | 已发布且可解析 — pypi 上有 1 个软件包 |
| 35/35 | 发布时效 — 最近一次发布于 0 天前 |
| 20/20 | 版本历史 — 41 个已发布版本 |
| 20/20 | 未被弃用 — 活跃,未被弃用或撤回 |
| packages | proofbundle |
| ecosystems | pypi |
| any_deprecated | 否 |
| min_days_since_publish | 0 |
基础的工程与文档实践是否到位?
| 24/24 | CI 工作流 — 9 个工作流 |
| 24/24 | 存在测试 |
| 0/16 | Linter 配置 |
| 0/9.6 | Pre-commit 钩子 |
| 0/6.4 | .editorconfig |
| 20/20 | OpenSSF Scorecard:CI-Tests — 15 out of 15 merged PRs checked by a CI test -- score normalized to 10 |
| has_ci | 是 |
| has_tests | 是 |
| has_editorconfig | 否 |
| has_linter_config | 否 |
| has_precommit_config | 否 |
| 30/30 | README |
| 25/25 | 文档目录 |
| 15/15 | 文档 / 主页站点 — https://b7n0de.com/proofbundle |
| 10/10 | 仓库描述 |
| 10/10 | 主题标签 — 19 个主题标签 |
| 10/10 | Wiki |
| topics | attestation, cryptography, ed25519, merkle, provenance, python, rfc6962, sd-jwt, transparency-log, verifiable-credentials, merkle-tree, sigstore, supply-chain-security, ai-evaluation, ai-safety, llm-evaluation, receipts, attestations, evidence |
| has_wiki | 是 |
| homepage | https://b7n0de.com/proofbundle |
| has_readme | 是 |
| has_docs_dir | 是 |
| has_description | 是 |
可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?
| 6.8/7.5 | Binary-Artifacts — binaries present in source code |
| 2.2/7.5 | Branch-Protection — branch protection is not maximal on development and all release branches |
| 2.5/2.5 | CI-Tests — 15 out of 15 merged PRs checked by a CI test -- score normalized to 10 |
| 0/2.5 | CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected |
| 1.5/7.5 | Code-Review — Found 2/10 approved changesets -- score normalized to 2 |
| 0/2.5 | Contributors — project has 0 contributing companies or organizations -- score normalized to 0 |
| 10/10 | Dangerous-Workflow — no dangerous workflow patterns detected |
| 7.5/7.5 | Dependency-Update-Tool — update tool detected |
| 5/5 | Fuzzing — project is fuzzed |
| 2.5/2.5 | 许可证 — license file detected |
| 0/7.5 | Maintained — project was created within the last 90 days. Please review its contents carefully |
| 5/5 | Packaging — packaging workflow detected |
| 1.5/5 | Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 3 |
| 5/5 | SAST — SAST tool is run on all commits |
| 5/5 | Security-Policy — security policy file detected |
| 0/7.5 | Signed-Releases — Project has not signed or included provenance with any releases. |
| 7.5/7.5 | Token-Permissions — GitHub workflow tokens follow principle of least privilege |
| 7.5/7.5 | Vulnerabilities — 0 existing vulnerabilities detected |
| source | openssf_scorecard |
| checks_evaluated | 18 |
| scorecard_version | v5.5.0 |
| checks_inconclusive | 0 |
| scorecard_aggregate | 6.6 |
| 35/35 | 直接依赖不含已知公告 — 没有直接依赖携带已知公告 |
| 0/25 | 间接依赖不含已知公告 — 在此范围内,传递依赖集合无法与开发和测试依赖区分 |
| 0/40 | 没有长期未处理的公告 — 没有公告带有发布日期 |
| source | osv |
| advisories | 0 |
| affected_packages | 0 |
| assessed_packages | 46 |
| unassessed_packages | 16 |
| affected_by_severity | none |
| direct_affected_packages | 0 |
该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。
| 0/45 | 代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则 |
| 0/15 | 机器可读文档(llms.txt) |
| 40/40 | 可读的提交历史 — 95 次人类提交中有 93 次说明了意图(结构化标题或解释性正文) |
| has_llms_txt | 否 |
| legible_history_share | 0.979 |
| agent_instruction_files | — |
| agent_instruction_max_bytes | — |
| 18/18 | 一条命令的引导启动 — Makefile |
| 22/22 | 自动化测试 |
| 0/11 | Lint / 格式化配置 |
| 11/11 | 静态类型检查 — src/proofbundle/py.typed |
| 10/10 | 可复现环境 — Dockerfile, lockfile |
| 10/10 | 已体现的代理实践 — 最近 100 次提交中有 59 次由代理编写或署名代理 |
| 8/8 | 自动化维护 — 最近 100 次提交中有 5 次为自动依赖更新 |
| 3/10 | OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 3 |
| has_nix | 否 |
| has_tests | 是 |
| lockfiles | Cargo.lock |
| has_dockerfile | 是 |
| typed_language | 否 |
| bootstrap_files | Makefile |
| has_devcontainer | 否 |
| has_linter_config | 否 |
| typecheck_configs | src/proofbundle/py.typed |
| agent_commit_share | 0.59 |
| toolchain_manifests | tools/pb_verify_rs/Cargo.toml |
| dependency_bot_commit_share | 0.05 |
| 27/45 | 可类型检查的代码 — Python,已配置类型检查(src/proofbundle/py.typed) |
| 54.4/55 | 可控的文件大小 — 采样的 257 个源文件中有 3 个超过 60KB |
| primary_language | Python |
| largest_source_bytes | 171,563 |
| source_files_sampled | 257 |
| oversized_source_files | 3 |
| 0/40 | API 模式(OpenAPI/GraphQL/proto) |
| 0/20 | MCP 服务器 |
| 40/40 | 可运行示例 — examples |
| example_dirs | examples |
| has_mcp_signal | 否 |
| api_schema_files | — |
每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。
来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。
| 9 | Binary-Artifacts | binaries present in source code |
| 3 | Branch-Protection | branch protection is not maximal on development and all release branches |
| 10 | CI-Tests | 15 out of 15 merged PRs checked by a CI test -- score normalized to 10 |
| 0 | CII-Best-Practices | no effort to earn an OpenSSF best practices badge detected |
| 2 | Code-Review | Found 2/10 approved changesets -- score normalized to 2 |
| 0 | Contributors | project has 0 contributing companies or organizations -- score normalized to 0 |
| 10 | Dangerous-Workflow | no dangerous workflow patterns detected |
| 10 | Dependency-Update-Tool | update tool detected |
| 10 | Fuzzing | project is fuzzed |
| 10 | License | license file detected |
| 0 | Maintained | project was created within the last 90 days. Please review its contents carefully |
| 10 | Packaging | packaging workflow detected |
| 3 | Pinned-Dependencies | dependency not pinned by hash detected -- score normalized to 3 |
| 10 | SAST | SAST tool is run on all commits |
| 10 | Security-Policy | security policy file detected |
| 0 | Signed-Releases | Project has not signed or included provenance with any releases. |
| 10 | Token-Permissions | GitHub workflow tokens follow principle of least privilege |
| 10 | Vulnerabilities | 0 existing vulnerabilities detected |
| 注册表 | 软件包 | 版本约束 | 清单文件 |
|---|---|---|---|
| PyPI | cryptography | >=42 | pyproject.toml |
| PyPI | rfc8785 | >=0.1.4 | pyproject.toml |
来自 GitHub 依赖图的完整解析依赖集合:2 个直接依赖与 60 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。
| 注册表 | 软件包 | 版本 | 关系 |
|---|---|---|---|
| PyPI | cryptography | — | 直接 |
| PyPI | rfc8785 | — | 直接 |
| crates.io | base64 | 0.22.1 | 间接 |
| crates.io | base64ct | 1.8.3 | 间接 |
| crates.io | block-buffer | 0.10.4 | 间接 |
| crates.io | cfg-if | 1.0.4 | 间接 |
| crates.io | const-oid | 0.9.6 | 间接 |
| crates.io | cpufeatures | 0.2.17 | 间接 |
| crates.io | crypto-common | 0.1.7 | 间接 |
| crates.io | curve25519-dalek | 4.1.3 | 间接 |
| crates.io | curve25519-dalek-derive | 0.1.1 | 间接 |
| crates.io | der | 0.7.10 | 间接 |
| crates.io | digest | 0.10.7 | 间接 |
| crates.io | ed25519 | 2.2.3 | 间接 |
| crates.io | ed25519-dalek | 2.2.0 | 间接 |
| crates.io | equivalent | 1.0.2 | 间接 |
| crates.io | fiat-crypto | 0.2.9 | 间接 |
| crates.io | generic-array | 0.14.7 | 间接 |
| crates.io | getrandom | 0.2.17 | 间接 |
| crates.io | hashbrown | 0.17.1 | 间接 |
| crates.io | hex | 0.4.3 | 间接 |
| crates.io | indexmap | 2.14.0 | 间接 |
| crates.io | itoa | 1.0.18 | 间接 |
| crates.io | libc | 0.2.186 | 间接 |
| crates.io | memchr | 2.8.3 | 间接 |
| crates.io | pkcs8 | 0.10.2 | 间接 |
| crates.io | proc-macro2 | 1.0.106 | 间接 |
| crates.io | quote | 1.0.46 | 间接 |
| crates.io | rand_core | 0.6.4 | 间接 |
| crates.io | rustc_version | 0.4.1 | 间接 |
| crates.io | ryu-js | 0.2.2 | 间接 |
| crates.io | semver | 1.0.28 | 间接 |
| crates.io | serde | 1.0.228 | 间接 |
| crates.io | serde_core | 1.0.228 | 间接 |
| crates.io | serde_derive | 1.0.228 | 间接 |
| crates.io | serde_jcs | 0.1.0 | 间接 |
| crates.io | serde_json | 1.0.150 | 间接 |
| crates.io | sha2 | 0.10.9 | 间接 |
| crates.io | signature | 2.2.0 | 间接 |
| crates.io | spki | 0.7.3 | 间接 |
| crates.io | subtle | 2.6.1 | 间接 |
| crates.io | syn | 2.0.118 | 间接 |
| crates.io | typenum | 1.20.1 | 间接 |
| crates.io | unicode-ident | 1.0.24 | 间接 |
| crates.io | version_check | 0.9.5 | 间接 |
| crates.io | wasi | 0.11.1+wasi-snapshot-preview1 | 间接 |
| crates.io | zeroize | 1.9.0 | 间接 |
| crates.io | zmij | 1.0.23 | 间接 |
| PyPI | build | — | 间接 |
| PyPI | ecdsa | — | 间接 |
| PyPI | hypothesis | — | 间接 |
| PyPI | inspect-ai | — | 间接 |
| PyPI | jsonschema | — | 间接 |
| PyPI | mypy | — | 间接 |
| PyPI | opentimestamps | — | 间接 |
| PyPI | pytest | — | 间接 |
| PyPI | pyyaml | — | 间接 |
| PyPI | rfc3161-client | — | 间接 |
| PyPI | ruff | — | 间接 |
| PyPI | sd-jwt | — | 间接 |
| PyPI | setuptools | — | 间接 |
| PyPI | z3-solver | — | 间接 |
该仓库未发布可被索引解析的包,因此评估的是其自身的依赖图——共 46 个包,其中也包含从不交付的开发与测试版本固定:0 个存在已知公告,0 个为直接依赖。 有 16 个无法评估——没有已解析的版本、生态系统不受支持,或不在所列包清单之内。
没有已知公告影响已评估的依赖。
公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。
{
"data": {
"repo": {
"topics": [
"attestation",
"cryptography",
"ed25519",
"merkle",
"provenance",
"python",
"rfc6962",
"sd-jwt",
"transparency-log",
"verifiable-credentials",
"merkle-tree",
"sigstore",
"supply-chain-security",
"ai-evaluation",
"ai-safety",
"llm-evaluation",
"receipts",
"attestations",
"evidence"
],
"is_fork": false,
"size_kb": 21206,
"has_wiki": true,
"homepage": "https://b7n0de.com/proofbundle",
"languages": {
"TeX": 3112,
"Rust": 65539,
"Shell": 3188,
"Python": 2932897,
"Makefile": 1927,
"Dockerfile": 293
},
"pushed_at": "2026-07-23T11:33:57Z",
"created_at": "2026-07-01T10:35:23Z",
"owner_type": "User",
"updated_at": "2026-07-23T11:08:34Z",
"description": "Offline cryptographic receipts for AI evaluation results — Ed25519 + RFC 6962 Merkle + optional SD-JWT. Integrity, not truth",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "Python",
"significant_languages": [
"Python"
]
},
"owner": {
"blog": "https://b7n0de.com",
"name": "kraxo",
"type": "User",
"login": "b7n0de",
"company": null,
"location": null,
"followers": 2,
"avatar_url": "https://avatars.githubusercontent.com/u/45888075?v=4",
"created_at": "2018-12-15T01:11:41Z",
"is_verified": null,
"public_repos": 3,
"account_age_days": 2777
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v3.7.0",
"kind": "minor",
"published_at": "2026-07-23T11:34:27Z"
},
{
"tag": "corpus-review-2026-07-22-iter9",
"kind": "other",
"published_at": "2026-07-22T16:36:56Z"
},
{
"tag": "v3.6.3",
"kind": "patch",
"published_at": "2026-07-22T08:59:57Z"
},
{
"tag": "corpus-review-2026-07-22",
"kind": "other",
"published_at": "2026-07-22T06:56:24Z"
},
{
"tag": "corpus-review-2026-07-19",
"kind": "other",
"published_at": "2026-07-19T23:27:22Z"
},
{
"tag": "v3.6.2",
"kind": "patch",
"published_at": "2026-07-19T17:51:06Z"
},
{
"tag": "v3.6.1",
"kind": "patch",
"published_at": "2026-07-18T23:42:27Z"
},
{
"tag": "v3.6.0",
"kind": "minor",
"published_at": "2026-07-17T13:48:32Z"
},
{
"tag": "corpus-review-2026-07-17",
"kind": "other",
"published_at": "2026-07-17T17:49:35Z"
},
{
"tag": "v3.3.0",
"kind": "minor",
"published_at": "2026-07-16T11:46:57Z"
},
{
"tag": "v3.2.3",
"kind": "patch",
"published_at": "2026-07-15T16:39:50Z"
},
{
"tag": "v3.2.2",
"kind": "patch",
"published_at": "2026-07-15T13:10:29Z"
},
{
"tag": "v3.2.1",
"kind": "patch",
"published_at": "2026-07-14T22:28:46Z"
},
{
"tag": "v3.2.0",
"kind": "minor",
"published_at": "2026-07-14T18:59:24Z"
},
{
"tag": "v3.1.3",
"kind": "patch",
"published_at": "2026-07-13T17:38:33Z"
},
{
"tag": "v3.1.2",
"kind": "patch",
"published_at": "2026-07-13T10:36:45Z"
},
{
"tag": "v3.1.1",
"kind": "patch",
"published_at": "2026-07-13T09:05:24Z"
},
{
"tag": "v3.1.0",
"kind": "minor",
"published_at": "2026-07-12T22:49:44Z"
},
{
"tag": "v3.0.1",
"kind": "patch",
"published_at": "2026-07-12T14:22:55Z"
},
{
"tag": "v3.0.0",
"kind": "major",
"published_at": "2026-07-12T02:41:09Z"
},
{
"tag": "v2.1.0",
"kind": "minor",
"published_at": "2026-07-10T18:54:46Z"
},
{
"tag": "v2.0.0",
"kind": "major",
"published_at": "2026-07-09T20:37:40Z"
},
{
"tag": "v2.0.0b3",
"kind": "other",
"published_at": "2026-07-06T19:00:46Z"
},
{
"tag": "v2.0.0b2",
"kind": "other",
"published_at": "2026-07-05T18:36:11Z"
},
{
"tag": "v1.9.2",
"kind": "patch",
"published_at": "2026-07-05T14:08:12Z"
},
{
"tag": "v2.0.0b1",
"kind": "other",
"published_at": "2026-07-03T06:45:40Z"
},
{
"tag": "v1.9.1",
"kind": "patch",
"published_at": "2026-07-02T21:56:38Z"
},
{
"tag": "v1.9.0",
"kind": "minor",
"published_at": "2026-07-02T20:47:20Z"
},
{
"tag": "v1.8.0",
"kind": "minor",
"published_at": "2026-07-02T17:43:59Z"
},
{
"tag": "v1.7.0",
"kind": "minor",
"published_at": "2026-07-02T16:49:36Z"
},
{
"tag": "v1.4.0",
"kind": "minor",
"published_at": "2026-07-02T14:23:47Z"
},
{
"tag": "v1.3.0",
"kind": "minor",
"published_at": "2026-07-02T12:47:48Z"
},
{
"tag": "v1.2.0",
"kind": "minor",
"published_at": "2026-07-02T11:48:11Z"
},
{
"tag": "v1.1.0",
"kind": "minor",
"published_at": "2026-07-02T01:25:50Z"
},
{
"tag": "v1.0.0",
"kind": "major",
"published_at": "2026-07-02T00:26:17Z"
},
{
"tag": "v0.9.0",
"kind": "minor",
"published_at": "2026-07-01T23:30:55Z"
},
{
"tag": "v0.8.1",
"kind": "patch",
"published_at": "2026-07-01T20:46:50Z"
},
{
"tag": "v0.8.0",
"kind": "minor",
"published_at": "2026-07-01T20:44:12Z"
},
{
"tag": "v0.7.1",
"kind": "patch",
"published_at": "2026-07-01T18:44:22Z"
},
{
"tag": "v0.7.0",
"kind": "minor",
"published_at": "2026-07-01T18:12:52Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2026-07-01T18:00:32Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2026-07-01T17:33:26Z"
},
{
"tag": "v0.4.1",
"kind": "patch",
"published_at": "2026-07-01T15:57:02Z"
},
{
"tag": "v0.4.0",
"kind": "minor",
"published_at": "2026-07-01T15:40:13Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2026-07-01T15:10:19Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2026-07-01T11:10:57Z"
},
{
"tag": "v0.1.0",
"kind": "minor",
"published_at": "2026-07-01T10:58:06Z"
}
],
"recent_commits": [
{
"oid": "defc3ee24cc2ef5e07d41b29bf271890d447846e",
"body": "release prep: version 3.7.0, changelog for both adapters, clamp-branch test",
"is_bot": false,
"headline": "Merge pull request #127 from b7n0de/release/v3.7.0-changelog-version",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-23T11:08:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "418b1538407a5c9cb996b49e3626f0ccf6b9ced7",
"body": "Six-lens falsification-first audit with refute-to-kill jury on commit 02509ca3 (version bump\nPR head): zero confirmed findings; four standing regression targets plus the two learned\nregister-integrity classes attacked by name and confirmed fail-closed. Two honest residuals\nrecorded (register freshness binding P2, dependency-free wording) as pre-publication follow-ups.\nSatisfies the version-coupled audit-record requirement (F7 / pre_tag_audit_gate).",
"is_bot": false,
"headline": "audit: pre-tag adversarial audit record for the 3.7.0 candidate",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-23T08:59:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "02509ca3c7c787772395123de561762b2109e4bc",
"body": "…h test\n\n- CHANGELOG: [3.7.0] section (lm-eval sample-count provenance #116 by @tuodijihua closing #115,\n conformance-crossimpl acceptance target folded from [Unreleased], CONFORMANCE/COMMERCIAL_BOUNDARY\n docs #107, Dependabot consolidation #119-#126); editorial note in [3.6.3] documenting that #1\n[…]\nff.\n- One test for the clamp branch: effective > original yields skipped_samples 0 with raw counts visible.\n\nRelease, tag and PyPI publish are explicitly OUT of scope here (separate owner-gated step).",
"is_bot": false,
"headline": "release prep: version 3.7.0, changelog for both adapters, clamp-branc…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-23T08:16:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "55da43da7e13d904084753d785d3203ac917f86f",
"body": "…oundary\n\ndocs: conformance authority policy + commercial boundary (W5)",
"is_bot": false,
"headline": "Merge pull request #107 from b7n0de/docs/conformance-and-commercial-b…",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-23T08:02:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "aca1fb5f7f7d38cb461e1078b40aec32493b52fc",
"body": "…ovenance\n\nBind lm-eval sample count provenance",
"is_bot": false,
"headline": "Merge pull request #116 from tuodijihua/agent/lm-eval-sample-count-pr…",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-23T07:46:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1c830f57c7679f204db159836521ce8f56858642",
"body": "…-73adf09e94\n\nci: bump the actions group with 2 updates",
"is_bot": false,
"headline": "Merge pull request #126 from b7n0de/dependabot/github_actions/actions…",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-23T07:24:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f521b40a09bd54c9ce3f0be69e81b73fd2e94cc2",
"body": "Bumps the actions group with 2 updates: [github/codeql-action/init](https://github.com/github/codeql-action) and [github/codeql-action/analyze](https://github.com/github/codeql-action).\n\n\nUpdates `github/codeql-action/init` from 4.37.0 to 4.37.3\n- [Release notes](https://github.com/github/codeql-act\n[…]\nnalyze\n dependency-version: 4.37.3\n dependency-type: direct:production\n update-type: version-update:semver-patch\n dependency-group: actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "ci: bump the actions group with 2 updates",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-22T23:53:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "748d57e8dcd9b724057e27a17663ceac1d697fdd",
"body": "ci: group actions updates, fix dependabot label config",
"is_bot": false,
"headline": "Merge pull request #125 from b7n0de/ci/dependabot-groups-labels",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-22T23:51:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7df8f5cb4b9df3a5333db79bbf827d0ffaa4c849",
"body": "…/setup-python-7.0.0\n\nci: bump actions/setup-python from 6.3.0 to 7.0.0",
"is_bot": false,
"headline": "Merge pull request #120 from b7n0de/dependabot/github_actions/actions…",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-22T22:05:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "321505a99adc4493c23f1608e3964e341a36e0cd",
"body": null,
"is_bot": false,
"headline": "ci: group actions updates, fix dependabot label config",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-22T21:19:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d683a196ce609aae1c2e6abc67557f06a81ab58a",
"body": "Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6.3.0 to 7.0.0.\n- [Release notes](https://github.com/actions/setup-python/releases)\n- [Commits](https://github.com/actions/setup-python/compare/ece7cb06caefa5fff74198d8649806c4678c61a1...5fda3b95a4ea91299a34e894583c3862153e4b\n[…]\npendency-name: actions/setup-python\n dependency-version: 7.0.0\n dependency-type: direct:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "ci: bump actions/setup-python from 6.3.0 to 7.0.0",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-22T19:25:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3f1591631a70cac40da8406c161fa9b4cd8244be",
"body": "…-action-pypi-publish-1.14.1\n\nci: bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1",
"is_bot": false,
"headline": "Merge pull request #122 from b7n0de/dependabot/github_actions/pypa/gh…",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-22T19:23:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "76c5cfd2b71672b60eda976bc2e4cbea21a37ae2",
"body": "…codeql-action/upload-sarif-4.37.3\n\nci: bump github/codeql-action/upload-sarif from 4.37.0 to 4.37.3",
"is_bot": false,
"headline": "Merge pull request #121 from b7n0de/dependabot/github_actions/github/…",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-22T19:23:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "33ed94f7544ee169d6cf5169848b8d2ae0d2f05c",
"body": "…/checkout-7.0.1\n\nci: bump actions/checkout from 7.0.0 to 7.0.1",
"is_bot": false,
"headline": "Merge pull request #119 from b7n0de/dependabot/github_actions/actions…",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-22T19:23:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "48165fca397161647bd18ff27234823bde921c75",
"body": "Bumps [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) from 1.14.0 to 1.14.1.\n- [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases)\n- [Commits](https://github.com/pypa/gh-action-pypi-publish/compare/cef221092ed1bacb1cc03d23a2d87d1d172e277b...ba38be9e\n[…]\n-name: pypa/gh-action-pypi-publish\n dependency-version: 1.14.1\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "ci: bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-22T15:55:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b34c19fa72f1f5f03fd8abd8c2dce3f86312845b",
"body": "Bumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 4.37.0 to 4.37.3.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-act\n[…]\n github/codeql-action/upload-sarif\n dependency-version: 4.37.3\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "ci: bump github/codeql-action/upload-sarif from 4.37.0 to 4.37.3",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-22T15:55:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5186239f50e27a127dd1b31e6403d8fa258eb387",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb9\n[…]\n- dependency-name: actions/checkout\n dependency-version: 7.0.1\n dependency-type: direct:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "ci: bump actions/checkout from 7.0.0 to 7.0.1",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-22T15:54:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "21f48264f0b3e1d9bb8a29de6dc696f021cdebbf",
"body": "…-20260722\n\ndocs: scrub internal platform name from public audit/roadmap docs",
"is_bot": false,
"headline": "Merge pull request #118 from b7n0de/docs/scrub-internal-platform-name…",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-22T13:17:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "11cfb434719d893a3e8d7ed1f0cbee713e72eebf",
"body": "Replace 3 references to the maintainer's private monorepo name + internal paths\n(office/governance/, globe/staging/) with a neutral descriptor in docs/audit/BASELINE_3_1_2.md\nand docs/roadmap/FRONTLOAD.md. These leaked internal infrastructure structure into the public repo.\nMeaning preserved. CHANGELOG.md:1513 keeps its historical, documentary mention (a monorepo path\n\"that never shipped here\", no platform name) intentionally, see PR note.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs: scrub internal platform name from public audit/roadmap docs",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-22T13:12:34Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "3898b18e381cd1f752076b6c35a572dfa5adc5ad",
"body": "release: 3.6.3 (never-raise residual, BETA, relation EXPERIMENTAL)",
"is_bot": false,
"headline": "Merge pull request #117 from b7n0de/release/3.6.3",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-22T08:58:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "45da1500118d17b9c344aceaa1dbc0bf0672116c",
"body": null,
"is_bot": false,
"headline": "chore: release 3.6.3 (never-raise residual, BETA, relation EXPERIMENTAL)",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-22T07:58:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bb81c2cc72ddbe1f1d052dcd0f4d6b05d1b420ca",
"body": null,
"is_bot": false,
"headline": "Bind lm-eval sample count provenance",
"author_name": "tuodijihua",
"author_login": "tuodijihua",
"committed_at": "2026-07-22T00:30:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2ad801fb84632df00ab8b9c8bf7722c38eaeb26a",
"body": "…venance\n\nBind Inspect scorer provenance and sample count",
"is_bot": false,
"headline": "Merge pull request #112 from tuodijihua/agent/bind-inspect-scorer-pro…",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-21T15:22:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b9e4133f96941eb2bbab95d17bd187bf4d33355d",
"body": "chore: remove internal codename from public comments and docs (no behavior or data change)",
"is_bot": false,
"headline": "Merge pull request #114 from b7n0de/chore/external-naming-rename",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-21T14:19:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d97d9c08ec3bb7fbbc8cfa2fbbc8cb7bdc5ab2c1",
"body": "…al naming rule)\n\nReplaces the internal gate codename with its external name in comments, docstrings\nand headings only, no behavior or data change. The name reached public main via the\nrootcommit corpus PR; the external naming rule keeps it off outward-facing surfaces.\n\nFiles: src/proofbundle/anchor\n[…]\nanchor/rootcommit/README.md,\naudit_artifacts/360/pre_tag_adversarial_audit_360.md. Vendored upstream vectors and\nmanifests untouched; digest pins remain valid. Full test suite 2030 passed, ruff clean.",
"is_bot": false,
"headline": "chore: remove internal codename from public comments and docs (extern…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-21T14:13:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e6e1420c8308836f39ffab7f356ef4f9c3f4de19",
"body": "corpus: MarkovianProtocol rootcommit v1 + v2-sig vectors (9) with own verifier, pinned at 9034202, credit Colin",
"is_bot": false,
"headline": "Merge pull request #113 from b7n0de/corpus/rootcommit-colin-9034202",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-21T12:04:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "10e76569c048325ef7cb457e004e69d7d9048524",
"body": "…ned at 9034202, with own independent verifier; credit Colin\n\nVendors the upstream rootcommit conformance corpus (rootcommit/v1: 4 vectors;\nrootcommit/v2-sig: 5 vectors; plus the two upstream manifests) as pure data,\nbyte-identical, with all 11 per-file SHA-256 digests pinned at commit 9034202.\nCred\n[…]\ng signature check needs the optional extra proofbundle[rootcommit]\n(ecdsa); without it sig_ok is None (status no_sig_lib), never a silent pass.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "corpus: add MarkovianProtocol rootcommit v1 + v2-sig vectors (9), pin…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-21T11:09:58Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "29f2a02fb9fd7f1ef8910bfd7d64cc34d5a21b4d",
"body": "Signed-off-by: tuodijihua <158809980+tuodijihua@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: allow numeric Inspect provenance fields",
"author_name": "tuodijihua",
"author_login": "tuodijihua",
"committed_at": "2026-07-21T05:05:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "acd2195400d6846907a9ee4a874c1193737fc7f9",
"body": null,
"is_bot": false,
"headline": "Bind Inspect scorer provenance and sample count",
"author_name": "tuodijihua",
"author_login": "tuodijihua",
"committed_at": "2026-07-20T21:52:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "32661bf1cf2904129abd9518ca3237b93ef741a7",
"body": "…rename\n\nchore: rename internal review-gate codename to external adversarial-audit vocabulary (rename-only)",
"is_bot": false,
"headline": "Merge pull request #111 from b7n0de/chore/external-adversarial-vocab-…",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-20T06:52:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "da62821e56d4e117520de8bd152c0080092beb5f",
"body": "fix(never-raise): 3.6.3 residual — close the three r7 sites + anchors_chia_add per-site guard (+ Berkeley re-gate siblings)",
"is_bot": false,
"headline": "Merge pull request #110 from b7n0de/fix/never-raise-residual-363",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-20T06:52:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "16b1c1296f885fdc81b10ec2e73df2763bca29be",
"body": "…ry (rationale text)\n\nReplace the internal review-gate codename with \"adversarial deep audit\" in the\nwrong-payloadtype-target case rationale (case.json) and the matching generator string +\ncomment (generate_vectors.py). Safe to edit (verified): the `rationale` field is\nschema-typed as any string and\n[…]\n2 relation vectors\ndifferential, Python==Rust) — including this vector.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
"is_bot": false,
"headline": "test(conformance): rename internal gate codename to external vocabula…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-20T01:31:38Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "bd696646ce4aac49da0e87f87cf4458e9decc5da",
"body": "…(comments)\n\nComment-only rename in scripts/mutation_check.py (two operator-provenance comments) and\nscripts/findings_register.py (one explanatory comment). No behavior change: the mutation\noperators are content-pinned (exact code-string match), so these comment edits do not\ntouch any operator targe\n[…]\n repo-wide\ncodename grep reaches zero (scripts/ is living public code).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
"is_bot": false,
"headline": "chore(scripts): rename internal gate codename to external vocabulary …",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-20T01:31:25Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "2dc92e5884ed3236757865a452fbf63d7a91c192",
"body": "… ADR 0006)\n\nReplace the internal review-gate codename with its external adversarial-audit\nvocabulary in docs/ANCHORS.md and docs/adr/0006-anchor-longevity.md. Both occurrences\nare parenthetical/attributional (\"... <codename> audit 2026-07-16, corrected\n2026-07-17\"); the surrounding sentence meaning\n[…]\nunchanged (checked per ADR review\nrule). No technical claim is altered.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
"is_bot": false,
"headline": "docs: rename internal gate codename to external vocabulary (ANCHORS +…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-20T01:31:25Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5e6d524d72b9483ec3de1662b9c8a03b1009ab16",
"body": "… + editorial note\n\nReplace the internal review-gate codename with its external adversarial-audit\nvocabulary throughout CHANGELOG.md and add a dated one-line editorial note at the head\ndeclaring the swap. Content unchanged (No-Overclaim / No-Fake): only the codename is\nreplaced. One anti-stutter cas\n[…]\nl adversarial deep-gate WITHSTANDS\" (avoids \"adversarial adversarial\").\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
"is_bot": false,
"headline": "docs(changelog): rename internal gate codename to external vocabulary…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-20T01:31:11Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4d0c41233373a4239df7964c9796f380ade0bca8",
"body": "… vocabulary (src + tests comments)\n\nComment/docstring-only rename across src/ and tests/ — the internal review-gate\ncodename is replaced by its external adversarial-audit vocabulary so the public\npackage carries no internal codename. No behavior change: every changed line is a\ncomment or docstring;\n[…]\no retarget needed) and a representative sample still\nkills as expected.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
"is_bot": false,
"headline": "refactor: rename internal gate codename to external adversarial-audit…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-20T01:31:02Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5333395d20a30974454339b36b781bdba7d6d2cc",
"body": "…ngs found by the Berkeley re-gate\n\nThe Berkeley NORMAL 3L/3I re-gate of the R7 fixes falsified iteration 1: 23 sibling\nnever-raise escapes in evaluate_relations_policy, one param over from R7-2 (same class).\nFixed and re-gated to 0 escapes:\n\n- non-dict lineage_result crashed the reject_superseded b\n[…]\n2 -> 3, 0 escapes; DEEP release-cert is the\nseparate Owner-gated step).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
"is_bot": false,
"headline": "fix(never-raise): 3.6.3 R7-2b — close evaluate_relations_policy sibli…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-20T00:07:53Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "294633d520948c36c5be1bed287e33a6c454a0da",
"body": "…_chia_add per-site guard\n\nCloses the never-raise residual 3.6.2 shipped deferred (Berkeley NORMAL re-gate of the\n3.6.2 candidate, r7). All three are P3/P4 direct-low-level-API robustness gaps on\nself-documented never-raise surfaces; NONE is reachable through the high-level\nsigned-envelope verify pa\n[…]\nt). Full suite green (1860 passed). CHANGELOG 3.6.3 (Unreleased) added.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
"is_bot": false,
"headline": "fix(never-raise): 3.6.3 residual — close the three r7 sites + anchors…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T23:57:18Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "59e2755fcd8115ddc15c452c035339cad901fb33",
"body": "test(anchors): vendor tlog-bitcoin-anchor conformance vectors + cross-impl binding tests (Stufe A)",
"is_bot": false,
"headline": "Merge pull request #109 from b7n0de/feat/markovian-tlog-anchor-vectors",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-19T23:27:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e7d538cbc04cfe0933d43486163f16c7b22a42da",
"body": "…-impl binding tests\n\nStufe A of the Markovian interop follow-up. Vendors the upstream C2SP\ntlog-bitcoin-anchor conformance corpus (MarkovianProtocol/tlog-bitcoin-anchor\n@ aaea18d, MIT) as PURE DATA under tests/fixtures/anchors/tlog_bitcoin_anchor/,\ndigest-pinned in MANIFEST.json with full attributi\n[…]\nl closed (status unbound).\nFully offline (no calendar, no Bitcoin node). A byte change to any vendored file\nfails the MANIFEST digest-pin test.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(anchors): vendor tlog-bitcoin-anchor conformance vectors + cross…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T23:11:10Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a9285bc6a140fbfa89493b3caa18b8726e181324",
"body": "…ossimpl\n\nconformance: graduate decision-receipt cross-impl to full v0.1 (block 958761)",
"is_bot": false,
"headline": "Merge pull request #108 from b7n0de/conformance/markovian-graduate-cr…",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-19T22:29:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d10eb07bf01b2fa53d31f218aa50ce6e90de9827",
"body": "…ull v0.1 (block 958761)\n\nColin (MarkovianProtocol/audit-anchor@ff6a000) regenerated the decision-receipt vector\nagainst the enforced decision-receipt/v0.1 schema and re-anchored it to a confirmed\nBitcoin block. This graduates the canonicalization-only iteration to the first full\nend-to-end decision\n[…]\nps in the vector fail closed (root binding / anchor); a wrong or\nabsent relying-party header does not confirm (block_mismatch / needs rpTrust).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(conformance): graduate the decision-receipt cross-impl case to f…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T20:31:42Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b7d512dbe23f6bb008ff9ef10f11f74c705b2caa",
"body": "…erated Berkeley re-gates)\n\nproofbundle 3.6.2 — security patch: bug-hunt + 5 iterated Berkeley re-gates (never-raise/DoS)",
"is_bot": false,
"headline": "Merge #106: proofbundle 3.6.2 — security patch (never-raise/DoS, 5 it…",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-19T17:50:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2b4415f5011a9680a8b016fb5bbdcb65e7ba5c66",
"body": "…Checkliste §9 + Phase 4)\n\nCONFORMANCE.md: the corpus as original authority — core vs external vectors,\ndigest pinning, attribution, negative tests, offline reproducibility, NO silent\nchanges to accepted vectors (versioned successors instead), change process.\nComplements conformance/README.md (mecha\n[…]\nrs,\nbasic integrations) free forever; commercial layer adds operations/reporting/\ngovernance around the core, never removes trust from it. Honest status note:\nno commercial layer exists as of 2026-07.",
"is_bot": false,
"headline": "docs: conformance authority policy + commercial boundary (W5, Schutz-…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T15:58:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4d458e831f445c6e8d830a90cebe4d482e102d52",
"body": "…e) coercion\n\nThe r3 never-raise fix changed verify_ecdsa_p256's verify call from\npub.verify(der_sig, message, ...) to pub.verify(der_sig, bytes(message), ...),\nwhich made the line-pinned mutation operator pattern stale (GAP in CI,\n75/76 ok). Re-targeted to the current text; verified end-to-end locally:\npattern found, mutant applied -> TestVerifyEcdsaP256 goes red (killed),\nrestore -> green. No production code change.",
"is_bot": false,
"headline": "test: re-target ES256 fail-open mutation operator to the bytes(messag…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T15:50:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4d8ad9391cb2b3a41e3fb5438bb1c4d2b0beaaa3",
"body": "…elease-scope honesty\n\nErgaenzt den 3.6.2-Eintrag um die codebase-weite never-raise-Klassen-Schliessung (r5-r6, _as_dict/_as_list\n+ Element/kwarg-Guards ueber 16 Module) + ehrliche Release-Scope-Notiz (No-Overclaim): der Klassen-Fix ist\ngross + verifiziert (1859 Tests, nested-fuzz 0 Escapes) aber NICHT als vollstaendig behauptet; Rest -> 3.6.3.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(changelog): 3.6.2 — nested-config-subfield class fix (r5-r6) + r…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T13:37:24Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "3f8e94d1c092af958a2050424bce9a6f52c14d18",
"body": "…sdjwt_vc/renewal/automation)\n\nNORMAL re-gate r6 found the SAME nested-config-subfield class in modules r5 never touched (the class is\ncodebase-wide, converging module-by-module). r5 closed 5 modules (policy/relation/anchors/automation/\npublic_transparency); r6 confirmed 5 escapes in trust_pack/sdjw\n[…]\nkipped. (anchors_chia_add transform reverted — it broke\nthe lock context-manager tests and was not an escape; needs careful per-site handling.)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(never-raise): codebase-wide class-fix for r6 escapes (trust_pack/…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T12:34:31Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "af12cf91093ff0849bcd6851e80abbff8c95b298",
"body": "…apes (r5, 16 confirmed)\n\nRound-5 DEEP re-gate proved the class was NOT converging via point fixes (5->12->16): the systemic\nidiom `(cfg.get(k) or {})` only replaces FALSY, so a truthy non-container (int/str) and non-dict/\nunhashable LIST ELEMENTS slipped through into .get()/iteration/set()/`in`.\n\nC\n[…]\n levels) = 0 escapes (CONVERGED);\nfull suite 1858 passed / 158 skipped, no regression. Pinned in test_round5_nested_config_subfield_regression.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(never-raise): SYSTEMATIC class-fix for nested-config-subfield esc…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T11:48:25Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c2fe20bd2d81d092797ad125de83cbd7df7eae55",
"body": "…the 12 round-4 escapes\n\nOwner directive: optimise the Berkeley gate so this class is captured in CI going forward, not only found\nby the expensive jury. The auto-enumerated denominator fuzzed ONLY the primary arg; the round-4 escapes\nlived in non-primary/nested/value slots.\n\n- _NAME_PATTERN += eval\n[…]\ngenerator-hardening, each finding a permanent corpus entry that can never silently regress.\n\nAll 4 property tests green; discovery floor holds.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "test(berkeley-v4): broaden never-raise denominator to G1/G2/G4 + pin …",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T10:40:14Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "de19c5b126668fb766c7386910a9080ca254900e",
"body": "…nested-non-primary + value guards\n\nRound-4 DEEP re-gate (wf_ce96dfb8) confirmed the class was bigger than r3's point fixes: the G1\nnon-primary-arg gap lives at SHARED SINKS and NESTED sub-fields, not just one caller.\n\n- checkpoint.witness_quorum: guard witness_vkeys IN THE SINK (verify_witnessed_ch\n[…]\ne_relation_resolution + non-dict relation_signer.\n\nAll 12 escape repros now fail-closed (typed / verdict-dict / skip); 42 affected tests green.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(never-raise): 12 Berkeley re-gate round-4 escapes — sink-level + …",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T10:37:25Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "956cbe5c3a4eaa8194ac8d99ea247068c4afaf2f",
"body": "…required_checks/fields type-guards\n\nBerkeley DEEP re-gate (round r3, wf_73054658) DOES_NOT_WITHSTAND: 1 P3 survivor + 4 completeness-critic\nescapes across the property-test's structural denominator gaps (non-primary args, name families, modules).\n\n- signature.verify_ed25519 / verify_ecdsa_p256: gua\n[…]\nields` (skip, not-applicable).\n\nAll 5 escape repros now fail-closed (typed error / False / level=None); 41 affected tests green, no regression.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(never-raise): 5 Berkeley re-gate escapes — message/witness_vkeys/…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T09:37:58Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4ce01a936391f53b0675ee2e6630b9d01ba52942",
"body": "… load_claim_text, and BROADEN the denominator\n\nThe WITHSTANDS re-gate found the never-raise class still open on the predicate-validation surface, AND the\ncompleteness critic exposed that the round-7 property test's own denominator was incomplete — the exact\nclass-level-thinking failure v4 warns abo\n[…]\nor by design.\n\nBroadened one-pass sweep: 70 surfaces x 15 corpus vectors = 1050 calls, ZERO escapes. Full suite 1856 passed,\nruff + mypy clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: Berkeley re-gate round 8 — subject_binding RecursionError root +…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T08:22:25Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "412cb1c8badfd23ad4fe8c41bc1820de6b3b69ef",
"body": "…te v4 centerpiece, in-repo PoC)\n\nThe round-by-round re-gates converged 11 -> 3 -> 2 -> 1 but never to zero in one round because the fix target\nwas \"the one repro\" and the surface FAMILY was never an explicit machine-checked denominator. This test is that\ndenominator: it auto-discovers every public \n[…]\n-gate v4 thesis (make v3 §15/§17/§18 executable and required: enumerate the\nfamily, close the CLASS, not the instance). Full suite 1856 passed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "test: auto-enumerated never-raise class-closure property (Berkeley-ga…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T07:26:45Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a97f1b4e57b044d9a72bf1008495070ce378aba6",
"body": "…CLASS with a shared property test\n\nThe round-7 re-gate + completeness critic found the never-raise \"non-str/non-bytes/non-dict primary arg\nreaches an unguarded .split()/len()/.get()\" class was swept surface-by-surface and left four unswept siblings\nin the SD-JWT / eval-claim family. Per the critic'\n[…]\nface that forgets the primary-arg guard now fails here, not in a future re-gate round.\n\nFull suite 1854 passed, 158 skipped, ruff + mypy clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: Berkeley re-gate round 7 — close the primary-arg type-confusion …",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T07:01:45Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "009765faca7efb036fab8bd6b53292b80942ea70",
"body": "… pre-decode DoS, convergence 11->3->2->1->0\n\nThe round-6 re-gate returned DOES_NOT_WITHSTAND with a SINGLE confirmed escape (down from 2), and the\ncompleteness critic (350 hostile cases across 30+ verify surfaces) confirmed it is the ONLY reachable\nin-contract raw-escape left. All fixed; full suite\n[…]\n proofbundle[anchors]+FIPS-204 build to fuzz):\nanchors_ots / anchors_rfc3161 deserialize+verify internals and the real PQ signature-parse path.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: Berkeley re-gate round 6 — last in-contract RecursionError + JWT…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T06:21:59Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e2ccc2934acfb5cea7ffab8c1096b58caab7d860",
"body": "… (dsse/anchor/pqsig), convergence 11->3->2->0\n\nThe round-5 re-gate returned DOES_NOT_WITHSTAND with only 2 confirmed escapes (down from 3) + a completeness\nfinding — all the same sibling-escape / non-JCS-value classes at the last few surfaces the earlier rounds had\nnot reached. All repro-confirmed;\n[…]\nz; the pqsig public exports raising\nPQUnavailable on a non-PQ build is by-design (returning False would be a No-Fake violation) and left as-is.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: Berkeley re-gate round 5 — the last public-surface sibling leaks…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T05:26:58Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4898809fc213b5baced45424c9eb63e15b2c61aa",
"body": "…ted mktemp, in a regression test\n\nCodeQL flagged 1 high-severity alert on PR #106: the round-4 regression helper `_node_heavy_file` used\n`tempfile.mktemp()` (deprecated: it returns a name without creating the file, a name-then-open TOCTOU race).\nSwitched to `tempfile.mkstemp()`, which creates the f\n[…]\nrrence; the test's intent (a >200k-node JSON file to exercise the node-budget verify path) is unchanged.\n\n28 regression tests pass, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: CodeQL py/insecure-temporary-file — use mkstemp, not the depreca…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T04:42:21Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e5e7a54b632e9ec029d5e088d1309759287a7fc7",
"body": "…llide with the earlier relations SET\n\nCI `mypy src` (the `test` job runs mypy before pytest) failed with 2 errors in outcome.py: the automation\nfail-open clamp (commit e103b89) reused the local name `_codes`, which verify_outcome_receipt already binds\nas a SET at line 798 (`{v[\"code\"] for v in _vio\n[…]\nno other type errors from the round-3/4/5 never-raise work.\n\nBehaviour-preserving (variable rename only); outcome tests 110 passed, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: mypy — rename the automation-blocker code list so it does not co…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T04:37:57Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0f87d2959f6f78c00fb3bdfe31fd2dbf63251ecf",
"body": "…could not reach (convergence 11->3->0)\n\nA fresh Berkeley DEEP re-gate against the round-4 HEAD returned DOES_NOT_WITHSTAND with only 3 confirmed\nescapes (down from 11) + 2 completeness-critic escapes — all the SAME two classes (structural-budget bypass on\na direct object, and file-read/PQ-sibling D\n[…]\nlable input rather than raise a ProofBundleError\nsibling. 6 new round-5 regression tests (PQ-robust: assert 'returns a verdict, never raises').\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: Berkeley re-gate round 4 — same classes at the surfaces round-3 …",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T04:32:05Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "231c32e85988c2b856fbacab2cc08b393b9ad3bc",
"body": "…intoto ValueError family + file DoS\n\nA fresh Berkeley DEEP re-gate (6 lenses x 3 skeptics + completeness critic, 44 agents) against the round-3\nHEAD returned DOES_NOT_WITHSTAND with 11 confirmed escapes + 2 from the completeness critic. The round-3\nwidening had fixed the INNER loads_strict except s\n[…]\nleError, honoring the test's own stated intent) instead of the raw subclass.\n7 new round-4 regression tests in test_bughunt_361_never_raise.py.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: Berkeley re-gate round 3 — close the FLAGSHIP verify surfaces + …",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T03:33:45Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "550a8556832eee04db3491289e45cc5fa1dd8129",
"body": "…ass (repro-confirmed)\n\nA deterministic pre-sweep + executable repro proved the never-raise-BASE class was still open at the\nLIBRARY level (the CLI class was already closed by main()'s catch-all in the prior commit). Several PUBLIC\nverify surfaces funnel an embedded SD-JWT / claim payload through lo\n[…]\natch base).\n\nRegression tests: 4 new library-surface cases in test_bughunt_361_never_raise.py.\nFull suite 1832 passed, 158 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix: Berkeley re-gate round 3 — close the library never-raise-base cl…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T02:28:55Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f380e3bfc161f61e1c01c27a2a996d41803cabc1",
"body": "… P1 siblings\n\nThe round-2 re-gate proved the never-raise contract was incomplete as a CLASS, not point bugs: fixes\nRAISED BundleFormatError but the CONSUMING handlers caught only subclasses, so siblings (BudgetExceeded,\nPQUnavailable) escaped — the exact never_raise_fix_must_wrap_all_and_catch_base\n[…]\ninstead of read_bytes() — a large card is\n legitimate (not capped) but /dev/zero no longer grows to a raw MemoryError out of the never-raise surface.\n\nFull suite 1826 passed, 158 skipped, ruff clean.",
"is_bot": false,
"headline": "fix: Berkeley re-gate round 2 — systematic never-raise-base close + 2…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T02:08:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e103b89bef536c99dcacef380b8783b40e80a9dc",
"body": "…missed + version 3.6.2\n\nThe Berkeley DEEP release-gate (verify-before-release) refused the first 3.6.2 fix pass and named two\nP1 siblings + an incomplete sweep — generator-hardening, not point-fixtures:\n\n- outcome.py (P1 fail-open sibling of the first outcome fix): the clamp fired ONLY on\n relatio\n[…]\nely exceed the verify budget) is hashed in 1 MiB chunks instead.\n\nVersion bumped to 3.6.2 (pyproject + __init__ + CITATION + CHANGELOG). Regression tests extended;\nfull suite 1826 passed, 158 skipped.",
"is_bot": false,
"headline": "fix: Berkeley re-gate remediation — 2 P1 siblings the first fix pass …",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T01:35:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "423678548732d5da06bb2492c9573e566a38f0f3",
"body": "…g-hunt 3.6.2)\n\nThe 3.6.1 never-raise hardening wrapped some public entrypoints (load_bundle, checkpoint) but the\nadversarial re-audit found unwrapped siblings + two unbounded-read DoS holes. Each surface must map\nhostile untrusted input to a typed fail-closed result, never a raw exception (crash/Do\n[…]\nM\n the process; new _read_capped() bounds the read at the input_bytes budget (15 call sites hardened).\n\nRegression tests in tests/test_bughunt_361_never_raise.py; full suite 1823 passed, 158 skipped.",
"is_bot": false,
"headline": "fix: eight never-raise / DoS sibling holes the 3.6.1 sweep missed (bu…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T01:08:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b8385b3025506f7c02651e986cbe05b87796a655",
"body": "…bug-hunt 3.6.2)\n\nAn adversarial re-audit of 3.6.1 found the never-raise fix did not cover all siblings AND two\ngenuine trust-policy fail-opens on the automation-verdict surface (the surface the docs recommend\nfor automation gating; .ok was already False, so an ok-only caller was safe, but a caller \n[…]\nirections:\nfail-closed on violation, no over-fire on the safe case) in tests/test_bughunt_361_automation_failopen.py;\n59 decision + 119 outcome/relation tests still pass. No crypto verdict is touched.",
"is_bot": false,
"headline": "fix: two P1 fail-opens on the .automation.safeForAutomation surface (…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-19T00:56:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "76c096efc95028629b4b8a68907e45d7583f669f",
"body": "Names the cross-implementation acceptance gate. The independent Rust second-verifier\n(tools/pb_verify_rs) must AGREE with Python over the verifier core via the existing\ncrosscheck.py harness: content root (RFC 8785), DSSE/Ed25519 verify (real + tampered),\nduplicate-key reject, RFC 6962 Merkle head, \n[…]\nocal + acceptance gate, closing the #55 S2 accept criterion with existing code.\nCI/test-only, no package change. Verified: make conformance-crossimpl exits 0.\n\nCo-authored-by: kraxo <kraxo@b7n0de.com>",
"is_bot": false,
"headline": "feat: make conformance-crossimpl acceptance target (#55 S2) (#105)",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-19T00:41:02Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "17e59e1972d827e8793bd623ee6cf15f56c2b7d4",
"body": "…#104)\n\n6-lens/Berkeley-gated readability rewrite (README-audit verdict was TEILWEISE SOTA).\nCompresses the 65-line 'What's in the box' wall-of-text to scannable one-line bullets\n(exact flags/exit-codes/version history now live in the already-linked docs + CHANGELOG),\nslims '60-second try' to the tw\n[…]\naveats move into the linked docs (nothing lost, zero dead links — all 24\ninternal doc links verified to exist). Length now within the SOTA 500-1500-word band.\n\nCo-authored-by: kraxo <kraxo@b7n0de.com>",
"is_bot": false,
"headline": "docs: README SOTA readability pass — 317->205 lines, no claims lost (…",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-19T00:11:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8c9877413d605532f4a8477564e258c79f7f5ef3",
"body": "proofbundle 3.6.1 — security patch: close all 8 Teil-1/Teil-2 audit findings (Python + Rust), Berkeley-Gate green",
"is_bot": false,
"headline": "Merge pull request #103 from b7n0de/fix/subject-pin-361-P0",
"author_name": "kraxo",
"author_login": "b7n0de",
"committed_at": "2026-07-18T23:39:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "54729dee019dae09369f63b0cf3ffba89cf1fac1",
"body": "…rewrites (CI mutation gap fix)\n\nThe mutation CI job failed: FAILED (76 operators, 3 gaps) — three line/pattern-pinned mutation operators\nno longer matched the source because the very fixes they guard were rewritten (the known re-stale-on-\nrewrite class). NOT a real test-suite weakness: the guards a\n[…]\nhe SAME semantic guard-disable/invert as before (killed by the same tests), just on the\nmoved code. Patterns grep-unique in the current source.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(mutation): retarget 3 stale operators after the Teil-2/DEEP-gate …",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T21:20:55Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "374edde943668a11e0bfbc2301957fe66fda9a30",
"body": "…s (DEEP gate RT-04 closure)\n\nThe release-grade DEEP gate re-confirmed RT-01/RT-02/RT-03 fail-closed and narrowed RT-04 to one root\nclass: a public verify_/load_ export leaking a RAW exception on a wrong-TYPE (not wrong-value) untrusted\nargument. Three one-line guards, mirroring the existing witness\n[…]\nrror, zero raw leaks. Regression tests CheckpointNonStrNoteTyped\n+ load_bundle wrong-type-path. Full suite 1963 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(never-raise): typed guards on 3 public exports for wrong-TYPE arg…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T19:23:38Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a9aa322b3fb9b25cf279fa8366f82433a170ef5b",
"body": "… + FIFO hang (DEEP gate RT-04 file/path)\n\nThe release-grade DEEP Berkeley-Gate (RT-01..RT-04 pre-registered) confirmed 3.6.1 fixes the two v3.6.0\nescapes — RT-01 (subject absent -> RELATION_TARGET_SUBJECT_MISSING) and RT-02 (JCS/rfc8785 absent minimal-\ninstall -> fail-closed) both hold — but caught\n[…]\n\na normal bundle still loads. Regression tests LoadBundleFilePathClass (device/FIFO/oversized). Full suite\n1960 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(never-raise): bound load_bundle file read — /dev/zero MemoryError…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T18:58:26Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "7404068d4753b1eb1b749eefb37d67d264c8b166",
"body": "…ed_tree_size DoS, tlog witnesses shape, sdist test)\n\nThe 6-lens Berkeley gate on ca392f8 confirmed exactly 3 P2 defects (and re-cleared L1 canonicality \\A..\\Z,\nL2 RT-09 direct-dict budgets, L4 relation subject-pin, L5 register deny-by-default — no crypto false-accept,\nno fail-open). All three are n\n[…]\nailed), the L6-01 test SKIPs; CLI verify-proof on a malformed proof prints a\nclean fail-closed verdict (exit 1) in text and json, no traceback.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(never-raise+packaging): 3 real 6-lens findings on ca392f8 (expect…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T16:13:01Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ca392f8f43b3974f6ae02f05db4bfe0acf701563",
"body": "…invisible/confusable severity)\n\nThe 6-lens gate confirmed 1 P2 (and re-confirmed A1-A8/A10/A12 + crypto/budget/relation/packaging all\nhold): verify_and_count's severity fold was ALLOW-by-default (anything not exactly {P0,P1} after\n.strip().upper() was silently non-gating) while status is DENY-by-de\n[…]\nTrue, 17 evaluated).\n\nRegression tests added (hidden-open-P0 wiring + known/unknown allowlist). Full suite 1955 passed /\n7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(register): severity deny-by-default + Unicode fold (6-lens L5-01 …",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T15:23:32Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a9269f6510edff905b1a501864f77ebab01fc933",
"body": "…ns L1-01 trailing-newline)\n\nThe 6-lens gate confirmed 1 P2 canonicality false-PASS (and re-confirmed RT-09/RT-10/relation/\npackaging/malformed-type all hold): decision/outcome `_SHA256_HEX` used `re.compile(r\"^[0-9a-f]{64}$\")`,\nbut `$` matches BEFORE a trailing newline in Python, so a sha256 digest\n[…]\ned / 7 skipped, ruff clean. Not a signature forgery (the receipt\nmust be authentically signed); a strictness/canonicality gap, no One-Way-Door.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(canonicality): anchor every validator with \\A..\\Z, not ^..$ (6-le…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T14:48:06Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f8e76cd5cee86f63d4945860953c829b46ae4141",
"body": "…BDOS-01, int<->str cap parity)\n\nThe 6-lens gate confirmed 1 remaining P2 (and re-confirmed RT-09/RT-10/crypto/relation/packaging and\nverify_evidence_pack/verify_sample_opening/recompute all hold): verify_bundle(dict) leaked a raw\nValueError on a huge merkle.tree_size / leaf_index (e.g. 10**5000). R\n[…]\n raw ValueError; a legit small tree_size is\nunaffected.\n\nRegression test added (bidirectional). Full suite 1952 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(never-raise): bound integer magnitude in _require_int (6-lens L2-…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T14:23:18Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "74c882aaad67673fae6d1a3b16bd39d486f38f1c",
"body": "…ree (release-vorlauf)\n\nAdded \"Addendum 2 — reconciled to the shipped v3.6.1 release tree\" to the pre-tag adversarial audit\nrecord. Every number carries its command source (No-Fake, vorlauf P5), and figures that changed vs the\nv3.6.0 addendum are called out so nothing contradicts the shipped state:\n\n[…]\nl branch-base snapshot, not the shipped count.\n- 0 open P0/P1 holds (signed register). Status boundary unchanged (BETA, EXPERIMENTAL relation).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(pre-tag): P5 reconcile the audit addendum to the shipped 3.6.1 t…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T13:49:59Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "8fe8b629d40c2fd1bf8dd68731156cef739e4fda",
"body": "…attest-dryrun startup failure\n\nThe published-artifact-gate's reusable-attest-dryrun job called reusable-build-attest.yml whose\nbuild-attest job declares id-token:write + attestations:write, but the workflow-wide contents:read\ncannot be exceeded by a called workflow -> the run was refused at startup\n[…]\n from PR #102 per Owner-GO, so 3.6.1 carries the fix without a separate merge). The\nreusable workflow is unchanged; CI-only, no package change.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "ci(pag): integrate PR #102 permission fix into 3.6.1 (P3) — reusable-…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T13:46:30Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "710357a8ad9ca36a554385422f49cf51f98a3f0f",
"body": "…typed errors (6-lens L2/L3)\n\nThe 6-lens gate confirmed 2 P2 fail-closed defects on SECONDARY exported surfaces (it also\nre-confirmed RT-09/RT-10/crypto/relation and every primary verify_* surface hold):\n\n- L2-BDOS-01: recompute_merkle_root_b64(dict) walked merkle.inclusion_proof_b64 with an INERT\n \n[…]\n\n\nRegression tests added (load_bundle malformed matrix; recompute 100k-proof fast fail-closed).\nFull suite 1951 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(never-raise+dos): recompute_merkle_root_b64 budget + load_bundle …",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T13:37:57Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5d35b6a371ef1c63561ba8c6304a3a4b270143d7",
"body": "…enewal_policy (6-lens L2-01/L3-02)\n\nThe 6-lens gate confirmed 2 P2 never-raise leaks, both the recurring class \"an exported\nverify_*/evaluate_* surface missing a guard its sibling already has\". (My earlier claim that\nverify_prereg was clean was wrong — I tested with an empty claim, which short-circ\n[…]\nnd shape\nsurfaces are the three now-guarded ones plus verify_sequence.\n\nRegression tests added. Full suite 1949 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(never-raise): sibling-guard parity for verify_prereg + evaluate_r…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T13:04:17Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4737356ee318af768a60b7c2b236871ef250f219",
"body": "…e never-raise + bare-eval clean-skips)\n\nThe 6-lens gate confirmed 4 findings; after per-finding live re-verification against the\neditable HEAD (No-Fake), 3 were real and 1 (L2-01 verify_prereg) was a FALSE finding — the\ngate's own probe env had a stale build; verify_prereg already returns a fail-cl\n[…]\nession tests added (verify_evaluation_card bad paths; verify_sample_opening non-ASCII).\nFull in-repo suite 1947 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(never-raise+packaging): 3 real 6-lens findings (evalcard/persampl…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T12:35:59Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "a1d1d71d80e747ebeca6112d17b99c090c53ebf2",
"body": "…widen pre_tag negation\n\nThe single-round 6-lens Berkeley gate confirmed 1 P0 (and confirmed every other RT-10\nguard HELD live: absent/empty/foreign-key/tamper/dangling/self-supersede/non-string-id/\nlist-typed severity-status/dup-id downgrade/lowercase p0/status!='closed').\n\n- L5-01 (P0, fail-open):\n[…]\nion tests added (rings -> anomaly, linear chain -> legit; the concession\nwords -> not counted). Full suite 1945 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(register): P0 supersession-cycle fail-open (6-lens gate L5-01) + …",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T11:52:20Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "5bf162451046cc4dc6e5196690dfc5c70e43b357",
"body": "…rify_dual_hash guard (P2 L3-02)\n\nThe single-round 6-lens Berkeley gate confirmed 2 findings (and confirmed the crypto/\ncanonicality, RT-09 direct-dict budgets incl. string_len, relation subject-pin, and RT-10\nregister/pre_tag surfaces all WITHSTOOD). Both fixed:\n\n- L6-01 (P1) from-sdist \"pip instal\n[…]\ndded (verify_dual_hash non-bytes; the 5 module-skip guards exercised by the\ncleanroom). Full in-repo suite 1943 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(packaging+never-raise): from-sdist test invariant (P1 L6-01) + ve…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T11:19:34Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "bfae68b63bb4cb1ac21b2babc4990cec03fc2281",
"body": "…ound gate L3-01/L3-02)\n\nThe corrected single-round 6-lens Berkeley gate (PUBLIC-contract scoped, no more\ninternal-helper over-confirmation) confirmed 2 P2 never-raise leaks on exported\nrelying-party surfaces; both fixed with zero behavioural change on valid input:\n\n- L3-01 verify_bundle(str) / reco\n[…]\nf-element; first==second None-roots) is now typed-error\nor fail-closed False, 0 raw exceptions. Full suite 1943 passed / 7 skipped, ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(never-raise): close 2 public raw-exception leaks (6-lens single-r…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T10:39:37Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "aa502badaaccd1a5cc0b8e563bcdc063f6afe7a8",
"body": "…ster severity type-confusion P1)\n\nA 6-lens Berkeley re-gate (Owner-tuned agent budget) surfaced further findings; after\nrigorous per-finding verification (PUBLIC never-raise contract applies to exported\nverify_*/evaluate_* only — internal helpers may raise, their public callers wrap them) 3\nwere re\n[…]\n, and\nthe strict public sweep confirms no public caller leaks their TypeError. Not over-fixed.\n\nFull suite 1941 passed / 7 skipped. ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(teil5): remediate 6-lens Berkeley re-gate — 3 real findings (regi…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T10:07:17Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "297a9a61818563065a4dfff9c483ba725fb6527a",
"body": "…5 fixes\n\nA faithful Berkeley re-gate (10 attack classes incl. RT-09 direct-dict + RT-10\nassertion-by-absence, 3-juror refute-to-kill) found 6 real defects in this session's\nown Teil-5 work. All fixed with bidirectional regression tests:\n\n- RT10-REG-01 (P1, fail-open): findings_register.verify_and_c\n[…]\nsstehend/... The genuine 3.6.0 record\n still passes.\n\nFull suite 1938 passed / 7 skipped. ruff clean. CHANGELOG updated to the hardened state.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(teil5): remediate 6 Berkeley-gate FIX_FIRST findings on the Teil-…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T09:15:18Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "93c1dbbc2267c8e2d329f776a76aecba6dac0dcc",
"body": "…toolchain\n\ncargo fmt --check disagreed with the runner's rustfmt on line breaks at\nmain.rs:1132/1496 because the toolchain was unpinned (rustfmt/clippy output is\nversion-dependent). Pin the exact toolchain in tools/pb_verify_rs/rust-toolchain.toml\n(1.95.0 + rustfmt + clippy), reformat main.rs with \n[…]\ne pinned toolchain.\n\nFindings register: PB-2026-0718-15 open -> closed (regenerated + re-signed, pinned\npubkey stable). 0 open P0/P1 unchanged.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(rust): PB-2026-0718-15 deterministic cargo fmt/clippy via pinned …",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T08:22:14Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "e1bb2f37a41738b36b62f1bbdd4d4d0999801e9a",
"body": "…ces stale-substring C12.2 (PB-2026-0718-14)\n\nThe audit_candidate_matrix C12.2 \"0 open P0/P1\" check derived PASS from a lexical\n\"0 open P0/P1\" substring in a version-scoped .md, with NO freshness / supersession /\nsignature / contradiction check. A STALE record that still said \"0 open\" granted PASS\nw\n[…]\n\nsubstring semantics to the register (absent -> FAIL, not PENDING; a fake .md grants nothing).\n\nFull suite 1932 passed / 7 skipped. ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(audit-candidate): RT-10 signed structured findings register repla…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T08:17:01Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "01ab3805c0907d8ffef0e3fa27f2cb557ad766ac",
"body": "…y path (PB-2026-0718-16)\n\nThe input_bytes + json_nodes + json_depth budget lives in loads_strict, which a STR\nbundle path funnels through (load_bundle -> loads_strict). A caller that hands an\nALREADY-PARSED dict to verify_bundle(dict) bypassed that chokepoint, so the structural\nbudget was INERT on \n[…]\n Shallow bundles unaffected.\n\nRegression: tests/test_sibling_never_raise_361.py::CallerPathTypedErrors::test_rt09_direct_dict_structural_budget\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(budget): RT-09 enforce structural budget on the direct-dict verif…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T07:45:41Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "805d68e1e861cc0b85d87ac08cc7411f82e6df87",
"body": "…-0718 thorough-sweep closure)\n\nevaluate_public_transparency built a named-status dict verdict but a non-str\nsigned_note (123/None/list) hit an early string op → raw AttributeError before\nthe fail-closed path. Coerce a non-str note to \"\" so every checkpoint parse\nfails gracefully (all statuses FAIL)\n[…]\nrdict).\n\nRegression: tests/test_sibling_never_raise_361.py::CallerPathTypedErrors\n ::test_evaluate_public_transparency_non_str_note_is_verdict\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(public_transparency): never-raise on non-str signed_note (PB-2026…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T07:33:08Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "1f939d5d2783aa5ec0fca6841d11def185cc8a35",
"body": "…athTypedErrors regression\n\nThe new CallerPathTypedErrors regression test (pinning the bc0028a caller-path fixes) exposed a second\nvkey parser: verify_cosignature routes through _parse_witness_vkey (NOT _parse_vkey), which still raised a\nraw AttributeError on a non-str vkey. Added the same isinstanc\n[…]\ney was a valid str, not None/int.)\n\nFull suite 1924 passed; ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
"is_bot": false,
"headline": "fix(never-raise): _parse_witness_vkey typed on non-str vkey + CallerP…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T07:27:14Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "bc0028a98f7d6d78a0bffb166feefc60140c9a67",
"body": "… checkpoint non-str vkey (final sweep)\n\nA comprehensive gate-substitute sweep (every public verify surface x budget/malformed-JSON/type-confusion,\n74 surface-attack combinations across 50 functions) confirmed the whole surface is never-raise for untrusted\nWIRE input, and closed the last two raw-exc\n[…]\nff clean; sweep CLEAN (no raw non-typed exception on any probed input).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
"is_bot": false,
"headline": "fix(never-raise): typed caller-path errors — verify_bundle bad-path +…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T07:23:20Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "b9b8aeb5b5e1de481b6a979f5adf37292fec07c3",
"body": "…al sweep)\n\nThe comprehensive verify_* sweep found verify_sdjwt_vc raised a raw AttributeError on a non-dict policy\n(policy.get(...)) — the same type-confusion class as decision/outcome/relation_statement. Now a fail-closed\nverdict (ok=False). (bundle.verify_bundle(<huge str>) -> OSError is the docu\n[…]\n wire input; left for the gate to adjudicate.) Suite green; ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
"is_bot": false,
"headline": "fix(never-raise): verify_sdjwt_vc fail-closed on non-dict policy (fin…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T06:25:53Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "d191e844a15142e2ff63525de4c5b8f98dae2994",
"body": "…rs never-raise, HF token budget-consistent\n\nTo break the round-by-round pattern (each Berkeley RE-GATE found the budget-leak class on one more verify\nsurface), a full sweep of every loads_strict call site closed the remaining ones in one batch:\n\n- intoto verify_intoto_dsse / verify_eval_result_dsse\n[…]\nFalse + duplicate named in detail). Full suite 1922 passed; ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
"is_bot": false,
"headline": "fix(never-raise): proactive loads_strict-sweep — in-toto DSSE verifie…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T06:23:04Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "6a3dec77bfb2daa7540c09fc9ef8dcbeb1c33a0e",
"body": "…get family + relstmt policy + CLI inspect)\n\nThe Berkeley gate on ee923a4 found the never-raise budget class STILL LIVE on the SD-JWT family (which I had\nonly fixed for TYPE-confusion, not budget) plus two more:\n\nBUDGET (P1 x5) verify_status_snapshot / verify_key_binding / verify_sd_jwt (header+payl\n[…]\nicyGuard, CliInspectLoneSurrogate).\nFull suite 1922 passed; ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
"is_bot": false,
"headline": "fix(never-raise): close 9 final Berkeley RE-GATE findings (SD-JWT bud…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T06:10:35Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ee923a48923806c0a233d90a6daa2bd83f6818ce",
"body": "…part deferred to 3.6.2)\n\nThe CI fmt/clippy gate I added turned the previously-green advisory rust-parity check RED: the runner's\nrustfmt formats differently than the local toolchain (rust 1.95.0) — Diff at main.rs:1132/1496 — a classic\nrustfmt version drift. The code stays cargo-fmt + clippy-clean \n[…]\n a red advisory check (No-Fake: a red check must be a real regression).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
"is_bot": false,
"headline": "ci(rust): revert version-fragile fmt/clippy gate (PB-2026-0718-15 CI …",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T05:33:32Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "29bbbbc38db87e41caa205376fb54992609c6fd0",
"body": "…gate to the rust job\n\nCatches a fmt/clippy regression in the Rust second-verifier going forward (advisory rust job, annotates).\nPlus the CHANGELOG entry for the fmt/clippy code fix.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
"is_bot": false,
"headline": "ci(rust): PB-2026-0718-15 add cargo fmt --check + clippy -D warnings …",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T05:29:22Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "4e9dbc7f4c20f77bbabf849811de2a1d0224dae3",
"body": "…rity preserved)\n\nTeil-5 finding: the Rust second-verifier tree was not fmt-clean and clippy -D warnings failed\n(collapsible-match in the same-key fail-closed branch, a redundant closure). Applied `cargo fmt` and the\ntwo machine-applicable clippy fixes.\n\nNo behavior change: the fixes are cosmetic (f\n[…]\nn vectors and the same-key branch clippy touched). Release build\nclean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
"is_bot": false,
"headline": "style(rust): PB-2026-0718-15 cargo fmt + clippy -D warnings green (pa…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T05:28:03Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "7f6a6dc323225f329ab306c18d27bbbe3f2d09c3",
"body": "…erification core (direct dict path)\n\nTeil-5 finding (Berkeley GATE-T5-02): the merkle_path budget (256) was defined but enforced NOWHERE.\nverify_inclusion / verify_consistency ran a per-step hash loop over an unbounded proof list, and the 8 MiB\ninput_bytes byte-proxy never applies when a bundle is \n[…]\nfails, legit small proof verifies).\nFull suite 1919 passed; ruff clean.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
"is_bot": false,
"headline": "fix(budget): PB-2026-0718-16 enforce merkle-path step budget in the v…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T05:25:06Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "c13159130dc6e13cd2ac1064a25b9cb4c93eb5c8",
"body": "…asses vacuously on singletons\n\nTeil-4 finding: the corpus-integrity comparator grouped cases by crossFormatId and SKIPPED any group with\n< 2 members. All six xfmt-* groups had exactly one member, so the \"same scenario agrees across formats\"\ncheck was vacuously true and reported ok=true while verify\n[…]\ntic contradictory pair fails; an agreeing pair passes. Full suite 1916.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
"is_bot": false,
"headline": "fix(conformance): PB-2026-0718-11 cross-format comparator no longer p…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T05:14:45Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "cb52ca062489eb0ec158092da483b2cbcbaa3c87",
"body": "…pe-confused input\n\nExtends the breadth sweep: verify_sd_jwt (dict-returning, untrusted SD-JWT compact from a holder) raised a\nraw AttributeError on a non-str compact (.split(\"~\")); verify_commitment raised a raw AttributeError on a\nnon-str PRESENTED identifier (identifier.encode() inside salted_com\n[…]\nff clean. Regression cases added to tests/test_sibling_never_raise_361.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_016U4g5SFB1DzS8RXVETDycS",
"is_bot": false,
"headline": "fix(never-raise): verify_sd_jwt + verify_commitment fail-closed on ty…",
"author_name": "kraxo",
"author_login": null,
"committed_at": "2026-07-18T05:04:43Z",
"body_truncated": true,
"is_coding_agent": true
}
],
"releases_count": 47,
"commits_last_year": 560,
"latest_release_at": "2026-07-23T11:34:27Z",
"latest_release_tag": "v3.7.0",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 4,
"days_since_latest_release": 0,
"mean_days_between_releases": 0.8
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 100,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "proofbundle",
"exists": true,
"license": "MIT",
"keywords": [
"cryptography",
"merkle",
"transparency-log",
"ed25519",
"sd-jwt",
"verifiable-credentials",
"attestation",
"provenance",
"rfc6962",
"Development Status :: 4 - Beta",
"Intended Audience :: Developers",
"License :: OSI Approved :: MIT License",
"Programming Language :: Python :: 3",
"Programming Language :: Python :: 3.10",
"Programming Language :: Python :: 3.11",
"Programming Language :: Python :: 3.12",
"Programming Language :: Python :: 3.13",
"Programming Language :: Python :: 3.14",
"Topic :: Security :: Cryptography"
],
"ecosystem": "pypi",
"matches_repo": true,
"registry_url": "https://pypi.org/project/proofbundle/",
"is_deprecated": false,
"latest_version": "3.7.0",
"repository_url": "https://github.com/b7n0de/proofbundle",
"versions_count": 41,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 6574,
"first_published_at": "2026-07-01T15:10:44.562607Z",
"latest_published_at": "2026-07-23T11:48:28.208813Z",
"latest_version_yanked": null,
"days_since_latest_publish": 0
}
]
},
"popularity": {
"forks": 2,
"stars": 2,
"watchers": 0,
"fork_history": {
"days": [
{
"date": "2026-07-06",
"count": 1
},
{
"date": "2026-07-20",
"count": 1
}
],
"complete": true,
"collected": 2,
"total_forks": 2
},
"star_history": null,
"open_issues_and_prs": 5
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": false,
"bootstrap_files": [
"Makefile"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"src/proofbundle/py.typed"
],
"toolchain_manifests": [
"tools/pb_verify_rs/Cargo.toml"
],
"largest_source_bytes": 171563,
"source_files_sampled": 257,
"oversized_source_files": 3,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"pyproject.toml"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 46,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 16,
"direct_affected_count": 0
},
"ecosystems": [
"pypi"
],
"dependencies": [
{
"name": "cryptography",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=42"
},
{
"name": "rfc8785",
"manifest": "pyproject.toml",
"ecosystem": "pypi",
"version_constraint": ">=0.1.4"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "cryptography",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "rfc8785",
"direct": true,
"version": null,
"ecosystem": "pypi"
},
{
"name": "base64",
"direct": false,
"version": "0.22.1",
"ecosystem": "crates"
},
{
"name": "base64ct",
"direct": false,
"version": "1.8.3",
"ecosystem": "crates"
},
{
"name": "block-buffer",
"direct": false,
"version": "0.10.4",
"ecosystem": "crates"
},
{
"name": "cfg-if",
"direct": false,
"version": "1.0.4",
"ecosystem": "crates"
},
{
"name": "const-oid",
"direct": false,
"version": "0.9.6",
"ecosystem": "crates"
},
{
"name": "cpufeatures",
"direct": false,
"version": "0.2.17",
"ecosystem": "crates"
},
{
"name": "crypto-common",
"direct": false,
"version": "0.1.7",
"ecosystem": "crates"
},
{
"name": "curve25519-dalek",
"direct": false,
"version": "4.1.3",
"ecosystem": "crates"
},
{
"name": "curve25519-dalek-derive",
"direct": false,
"version": "0.1.1",
"ecosystem": "crates"
},
{
"name": "der",
"direct": false,
"version": "0.7.10",
"ecosystem": "crates"
},
{
"name": "digest",
"direct": false,
"version": "0.10.7",
"ecosystem": "crates"
},
{
"name": "ed25519",
"direct": false,
"version": "2.2.3",
"ecosystem": "crates"
},
{
"name": "ed25519-dalek",
"direct": false,
"version": "2.2.0",
"ecosystem": "crates"
},
{
"name": "equivalent",
"direct": false,
"version": "1.0.2",
"ecosystem": "crates"
},
{
"name": "fiat-crypto",
"direct": false,
"version": "0.2.9",
"ecosystem": "crates"
},
{
"name": "generic-array",
"direct": false,
"version": "0.14.7",
"ecosystem": "crates"
},
{
"name": "getrandom",
"direct": false,
"version": "0.2.17",
"ecosystem": "crates"
},
{
"name": "hashbrown",
"direct": false,
"version": "0.17.1",
"ecosystem": "crates"
},
{
"name": "hex",
"direct": false,
"version": "0.4.3",
"ecosystem": "crates"
},
{
"name": "indexmap",
"direct": false,
"version": "2.14.0",
"ecosystem": "crates"
},
{
"name": "itoa",
"direct": false,
"version": "1.0.18",
"ecosystem": "crates"
},
{
"name": "libc",
"direct": false,
"version": "0.2.186",
"ecosystem": "crates"
},
{
"name": "memchr",
"direct": false,
"version": "2.8.3",
"ecosystem": "crates"
},
{
"name": "pkcs8",
"direct": false,
"version": "0.10.2",
"ecosystem": "crates"
},
{
"name": "proc-macro2",
"direct": false,
"version": "1.0.106",
"ecosystem": "crates"
},
{
"name": "quote",
"direct": false,
"version": "1.0.46",
"ecosystem": "crates"
},
{
"name": "rand_core",
"direct": false,
"version": "0.6.4",
"ecosystem": "crates"
},
{
"name": "rustc_version",
"direct": false,
"version": "0.4.1",
"ecosystem": "crates"
},
{
"name": "ryu-js",
"direct": false,
"version": "0.2.2",
"ecosystem": "crates"
},
{
"name": "semver",
"direct": false,
"version": "1.0.28",
"ecosystem": "crates"
},
{
"name": "serde",
"direct": false,
"version": "1.0.228",
"ecosystem": "crates"
},
{
"name": "serde_core",
"direct": false,
"version": "1.0.228",
"ecosystem": "crates"
},
{
"name": "serde_derive",
"direct": false,
"version": "1.0.228",
"ecosystem": "crates"
},
{
"name": "serde_jcs",
"direct": false,
"version": "0.1.0",
"ecosystem": "crates"
},
{
"name": "serde_json",
"direct": false,
"version": "1.0.150",
"ecosystem": "crates"
},
{
"name": "sha2",
"direct": false,
"version": "0.10.9",
"ecosystem": "crates"
},
{
"name": "signature",
"direct": false,
"version": "2.2.0",
"ecosystem": "crates"
},
{
"name": "spki",
"direct": false,
"version": "0.7.3",
"ecosystem": "crates"
},
{
"name": "subtle",
"direct": false,
"version": "2.6.1",
"ecosystem": "crates"
},
{
"name": "syn",
"direct": false,
"version": "2.0.118",
"ecosystem": "crates"
},
{
"name": "typenum",
"direct": false,
"version": "1.20.1",
"ecosystem": "crates"
},
{
"name": "unicode-ident",
"direct": false,
"version": "1.0.24",
"ecosystem": "crates"
},
{
"name": "version_check",
"direct": false,
"version": "0.9.5",
"ecosystem": "crates"
},
{
"name": "wasi",
"direct": false,
"version": "0.11.1+wasi-snapshot-preview1",
"ecosystem": "crates"
},
{
"name": "zeroize",
"direct": false,
"version": "1.9.0",
"ecosystem": "crates"
},
{
"name": "zmij",
"direct": false,
"version": "1.0.23",
"ecosystem": "crates"
},
{
"name": "build",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "ecdsa",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "hypothesis",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "inspect-ai",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "jsonschema",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "mypy",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "opentimestamps",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pytest",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "pyyaml",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "rfc3161-client",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "ruff",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "sd-jwt",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "setuptools",
"direct": false,
"version": null,
"ecosystem": "pypi"
},
{
"name": "z3-solver",
"direct": false,
"version": null,
"ecosystem": "pypi"
}
],
"collected": true,
"truncated": false,
"total_count": 62,
"direct_count": 2,
"indirect_count": 60
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 109,
"open_issues": 5,
"closed_ratio": 0.444,
"closed_issues": 4,
"closed_unmerged_prs": 9
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "b7n0de",
"commits": 130,
"avatar_url": "https://avatars.githubusercontent.com/u/45888075?v=4"
},
{
"type": "User",
"login": "tuodijihua",
"commits": 3,
"avatar_url": "https://avatars.githubusercontent.com/u/158809980?v=4"
},
{
"type": "User",
"login": "MarkovianProtocol",
"commits": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/292588966?v=4"
}
],
"contributors_sampled": 3,
"top_contributor_share": 0.97
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"codeql.yml",
"demo-reproducible.yml",
"fork-pr-isolation.yml",
"published-artifact-gate.yml",
"release-integrity.yml",
"release.yml",
"reusable-build-attest.yml",
"scorecard.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"Cargo.lock"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 9,
"reason": "binaries present in source code",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 3,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "15 out of 15 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 2,
"reason": "Found 2/10 approved changesets -- score normalized to 2",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 10,
"reason": "project is fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 0,
"reason": "project was created within the last 90 days. Please review its contents carefully",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 3,
"reason": "dependency not pinned by hash detected -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 10,
"reason": "GitHub workflow tokens follow principle of least privilege",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "defc3ee24cc2ef5e07d41b29bf271890d447846e",
"ran_at": "2026-07-23T12:24:22Z",
"aggregate_score": 6.6,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": true,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-23T11:48:31Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-07-23T11:08:29Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 7,
"created_at": "2026-07-05T00:44:01Z",
"last_comment_at": "2026-07-21T14:26:40Z",
"last_comment_author": "b7n0de"
},
{
"number": 24,
"created_at": "2026-07-07T18:00:37Z",
"last_comment_at": "2026-07-07T18:16:38Z",
"last_comment_author": "b7n0de"
},
{
"number": 26,
"created_at": "2026-07-07T19:31:43Z",
"last_comment_at": "2026-07-09T23:34:54Z",
"last_comment_author": "b7n0de"
},
{
"number": 27,
"created_at": "2026-07-07T19:31:45Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 55,
"created_at": "2026-07-11T08:01:46Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/b7n0de/proofbundle",
"host": "github.com",
"name": "proofbundle",
"owner": "b7n0de"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 64,
"inputs": {
"security": 73,
"vitality": 70,
"community": 49,
"governance": 48,
"engineering": 81
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 70,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 57,
"inputs": {
"commits_last_year": 560,
"human_commit_share": 0.95,
"days_since_last_push": 0,
"active_weeks_last_year": 4
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "4/52 weeks with commits",
"points": 2.8,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 4
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "560 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 560
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 47,
"latest_release_tag": "v3.7.0",
"releases_from_tags": false,
"days_since_latest_release": 0,
"mean_days_between_releases": 0.8
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "47 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 47
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~0.8 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 0.8
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 49,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 2,
"stars": 2,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "2 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 2
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "2 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 2
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 92,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 64,
"inputs": {
"packages": [
"proofbundle"
],
"dependents": null,
"ecosystems": "pypi",
"total_downloads": null,
"monthly_downloads": 6574
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "6,574 downloads/month across pypi",
"points": 50.9,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 6574,
"ecosystems": "pypi"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "at_risk",
"name": "Sustainability & Governance",
"value": 48,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 14,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 3,
"top_contributor_share": 0.97
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 97% of commits",
"points": 0.7,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 97
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "3 contributors",
"points": 4.1,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 3
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "moderate",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 59,
"inputs": {
"merged_prs": 109,
"open_issues": 5,
"closed_issues": 4,
"issue_closed_ratio": 0.444,
"closed_unmerged_prs": 9
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "44% of issues closed",
"points": 20.8,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 44
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "109/118 decided PRs merged",
"points": 35.3,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 109,
"decided": 118
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 2/10 approved changesets -- score normalized to 2",
"points": 3,
"status": "partial",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 37,
"inputs": {
"followers": 2,
"owner_type": "User",
"is_verified": null,
"owner_login": "b7n0de",
"public_repos": 3,
"account_age_days": 2777
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "2 followers of b7n0de",
"points": 3.4,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 2,
"login": "b7n0de"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "3 public repos, account ~7 yr old",
"points": 16.4,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 3
}
},
{
"code": "account_age_years",
"params": {
"years": 7
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"proofbundle"
],
"ecosystems": "pypi",
"any_deprecated": false,
"min_days_since_publish": 0
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on pypi",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "pypi"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 0 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 0
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "41 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 41
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 81,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 68,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "9 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 9
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "15 out of 15 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"topics": [
"attestation",
"cryptography",
"ed25519",
"merkle",
"provenance",
"python",
"rfc6962",
"sd-jwt",
"transparency-log",
"verifiable-credentials",
"merkle-tree",
"sigstore",
"supply-chain-security",
"ai-evaluation",
"ai-safety",
"llm-evaluation",
"receipts",
"attestations",
"evidence"
],
"has_wiki": true,
"homepage": "https://b7n0de.com/proofbundle",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://b7n0de.com/proofbundle",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "19 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 19
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "good",
"name": "Security",
"value": 73,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": null,
"notes": [],
"value": 66,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 18,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 0,
"scorecard_aggregate": 6.6
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "binaries present in source code",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "15 out of 15 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 2/10 approved changesets -- score normalized to 2",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is fuzzed",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "project was created within the last 90 days. Please review its contents carefully",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 3",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "GitHub workflow tokens follow principle of least privilege",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 46 resolved dependencies against OSV; 16 could not be assessed (no resolved version, an unsupported ecosystem, or beyond the reported package list). This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories",
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 46
}
},
{
"code": "advisories_unassessed",
"params": {
"count": 16
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 46,
"unassessed_packages": 16,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 46,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 63,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "at_risk",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.979,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "93 of 95 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 93,
"sampled": 95
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 82,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"Cargo.lock"
],
"has_dockerfile": true,
"typed_language": false,
"bootstrap_files": [
"Makefile"
],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [
"src/proofbundle/py.typed"
],
"agent_commit_share": 0.59,
"toolchain_manifests": [
"tools/pb_verify_rs/Cargo.toml"
],
"dependency_bot_commit_share": 0.05
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "src/proofbundle/py.typed",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "src/proofbundle/py.typed"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "59 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 59,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "5 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 5,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "good",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 81,
"inputs": {
"primary_language": "Python",
"largest_source_bytes": 171563,
"source_files_sampled": 257,
"oversized_source_files": 3
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Python with type-check config (src/proofbundle/py.typed)",
"points": 27,
"status": "partial",
"details": [
{
"code": "typecheck_config_language",
"params": {
"files": "src/proofbundle/py.typed",
"language": "Python"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "3/257 source files over 60KB",
"points": 54.4,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 257,
"oversized": 3
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "at_risk",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": false,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"deps.dev does not index pypi:proofbundle@3.7.0; advisories assessed against the repository dependency graph instead"
],
"report_type": "repository",
"generated_at": "2026-07-23T12:24:39.941015Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/b/b7n0de/proofbundle.svg",
"full_name": "b7n0de/proofbundle",
"license_state": "standard",
"license_spdx": "MIT"
}