公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-27 22:43 UTC

cjohnstoniv / wardyn

Open-source governance control plane for coding agents — per-run identity, brokered credentials, layered egress, approvals, and an append-only audit. Apache-2.0, self-hosted.

Go · TypeScriptApache-2.0★ 2 星标⑂ 0 复刻始于 2026年7月在 GitHub 上查看 ↗

cjohnstoniv/wardyn 的健康指数为 100 分中的 58 分,处于「中等」区间。 其得分最高的类别是Engineering Quality(82/100),最低的是Sustainability & Governance(34/100)。 最近一次更新在 5 天前。 近期的大部分工作由 1 位贡献者完成。

58
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

58
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

Charlie Johnston个人账户
2 关注者9 个公开仓库始于 2011年8月blackrock

该仓库由个人账户拥有。相较于组织支持的项目,单一所有者项目的延续性风险更高。

软件包生态系统

注册表软件包版本月下载量版本数最近发布
Gogithub.com/cjohnstoniv/wardynv0.4.2-76 天前

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

74良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 5 天前
2.1/36提交节奏 — 52 周中有 3 周有提交
18/18提交量 — 最近一年 348 次提交
0/10OpenSSF Scorecard:Maintained — project was created within the last 90 days. Please review its contents carefully
所用输入
commits_last_year348
human_commit_share1
days_since_last_push5
active_weeks_last_year3

发布纪律

100优秀
评分方式
27/27有发布版本 — 已发布 7 个发布版本
36/36发布时效 — 最近一次发布版本于 6 天前
27/27发布节奏 — 约每 2.2 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count7
latest_release_tagv0.4.2
releases_from_tags
days_since_latest_release6
mean_days_between_releases2.2
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

43存在风险 · 占总体的 18%
评分方式
0/60星标 — 2 个星标
0/25复刻 — 0 个复刻
0/15关注者 — 0 位关注者
所用输入
forks0
stars2
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

92优秀
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(Apache-2.0)
18/18CONTRIBUTING 指南
13.5/13.5行为准则
0/7.2议题模板
6.3/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

34存在风险 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0/22.5提交分布 — 头号贡献者编写了 100% 的提交
1.4/13.5贡献者广度 — 1 位贡献者
3/10OpenSSF Scorecard:Contributors — project has 1 contributing companies or organizations -- score normalized to 3
所用输入
bus_factor1
contributors_sampled1
top_contributor_share1
评分方式
0/46.8议题解决 — 没有议题或无数据
0/38.3PR 接受 — 已裁定的 PR 中 0/37 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/30 approved changesets -- score normalized to 0
所用输入
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs37
已排除计分(无数据或不适用):议题解决。 其余权重已重新归一化。
评分方式
10/30所有权背书 — 个人(用户)账户
0/20已验证域名 — 不适用于个人账户
3.4/25所有者影响力 — cjohnstoniv 有 2 位关注者
19.3/25既往记录 — 9 个公开仓库,账户约 14 年
所用输入
followers2
owner_typeUser
is_verified
owner_logincjohnstoniv
public_repos9
account_age_days5,447
已排除计分(无数据或不适用):已验证域名。 其余权重已重新归一化。
评分方式
25/25已发布且可解析 — go 上有 1 个软件包
35/35发布时效 — 最近一次发布于 6 天前
20/20版本历史 — 7 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesgithub.com/cjohnstoniv/wardyn
ecosystemsgo
any_deprecated
min_days_since_publish6

工程质量

基础的工程与文档实践是否到位?

82良好 · 占总体的 20%

工程实践

80良好
评分方式
24/24CI 工作流 — 2 个工作流
24/24存在测试
16/16Linter 配置 — .golangci.yml
0/9.6Pre-commit 钩子
0/6.4.editorconfig
0/20OpenSSF Scorecard:CI-Tests — 无数据
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config
已排除计分(无数据或不适用):OpenSSF Scorecard:CI-Tests。 其余权重已重新归一化。

文档

85优秀
评分方式
30/30README
25/25文档目录
0/15文档 / 主页站点
10/10仓库描述
10/10主题标签 — 8 个主题标签
10/10Wiki
所用输入
topicsai-agents, egress-control, golang, gvisor, llm, sandbox, security, supply-chain
has_wiki
homepage
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

59中等 · 占总体的 16%

安全态势

51中等
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — 无数据
0/2.5CI-Tests — 无数据
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — 无数据
3.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 7
0/5SAST — no SAST tool detected
2/5Security-Policy — security policy file detected
0/7.5Signed-Releases — 无数据
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
0.8/7.5Vulnerabilities — 9 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated14
scorecard_versionv5.5.0
checks_inconclusive4
scorecard_aggregate5.1
已排除计分(无数据或不适用):branch_protection, ci_tests, packaging, signed_releases。 其余权重已重新归一化。
评分方式
26.6/35直接依赖不含已知公告 — 1 个受影响:github.com/go-chi/chi/v5 v5.2.4 (unknown)
0/25间接依赖不含已知公告 — 在此范围内,传递依赖集合无法与开发和测试依赖区分
40/40没有长期未处理的公告 — 没有公告公开超过 90 天
所用输入
sourceosv
advisories11
affected_packages7
assessed_packages686
unassessed_packages0
affected_by_severityhigh 4, low 1, unknown 2
direct_affected_packages1
已排除计分(无数据或不适用):间接依赖不含已知公告。 其余权重已重新归一化。 已将 686 个已解析依赖与 OSV 比对。 该仓库未发布任何索引可解析的软件包,因此改为评估仓库依赖图。该图将开发与测试版本固定同交付的依赖混在一起,因此仅对声明的运行时依赖计分;传递性发现仅作为背景信息列出,不计入评分。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

67中等 · 占总体的 0%
评分方式
0/45代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 100 次人类提交中有 95 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.95
agent_instruction_files
agent_instruction_max_bytes
评分方式
18/18一条命令的引导启动 — Makefile
22/22自动化测试
11/11Lint / 格式化配置 — .golangci.yml
11/11静态类型检查 — ui/tsconfig.json
10/10可复现环境 — devcontainer, Dockerfile, lockfile
0/10已体现的代理实践 — 最近 100 次提交中没有代理编写的提交
5/8自动化维护 — 已配置依赖自动化,但在抽样提交中未观察到
7/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 7
所用输入
has_nix
has_tests
lockfilesgo.sum, pnpm-lock.yaml
has_dockerfile
typed_language
bootstrap_filesMakefile
has_devcontainer
has_linter_config
typecheck_configsui/tsconfig.json
agent_commit_share0
toolchain_manifestsgo.mod
dependency_bot_commit_share0
评分方式
45/45可类型检查的代码 — Go(静态类型)
55/55可控的文件大小 — 采样的 655 个源文件中有 0 个超过 60KB
所用输入
primary_languageGo
largest_source_bytes54,725
source_files_sampled655
oversized_source_files0

机器可读接口

40存在风险
评分方式
0/40API 模式(OpenAPI/GraphQL/proto)
0/20MCP 服务器
40/40可运行示例 — demos, examples
所用输入
example_dirsdemos, examples
has_mcp_signal
api_schema_files

关键数据

2GitHub 星标
1贡献者
348最近 12 个月提交数
5距最近推送天数
7发布版本数
1巴士系数(bus factor)
0开放议题
Go, npm软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token

更多细节

OpenSSF Scorecard 5.1 / 10
5.1综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-27 22:43 UTC

10Binary-Artifactsno binaries found in the repo
不适用Branch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
不适用CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
不适用Packagingpackaging workflow not detected
7Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 7
0SASTno SAST tool detected
4Security-Policysecurity policy file detected
不适用Signed-Releasesno releases found
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
1Vulnerabilities9 existing vulnerabilities detected
直接依赖 49
注册表软件包版本约束清单文件
Gofilippo.io/agev1.2.1go.mod
Gogithub.com/Azure/azure-sdk-for-go/sdk/azidentityv1.14.0go.mod
Gogithub.com/anthropics/anthropic-sdk-gov1.56.0go.mod
Gogithub.com/aws/aws-sdk-go-v2/configv1.32.25go.mod
Gogithub.com/bradleyfalzon/ghinstallation/v2v2.19.0go.mod
Gogithub.com/coder/websocketv1.8.14go.mod
Gogithub.com/containerd/errdefsv1.0.0go.mod
Gogithub.com/coreos/go-oidc/v3v3.20.0go.mod
Gogithub.com/go-chi/chi/v5v5.2.4go.mod
Gogithub.com/go-jose/go-jose/v4v4.1.4go.mod
Gogithub.com/google/go-github/v88v88.0.0go.mod
Gogithub.com/google/uuidv1.6.0go.mod
Gogithub.com/jackc/pgx/v5v5.10.0go.mod
Gogithub.com/moby/docker-image-specv1.3.1go.mod
Gogithub.com/moby/moby/apiv1.55.0go.mod
Gogithub.com/moby/moby/clientv0.5.0go.mod
Gogithub.com/moby/profiles/seccompv0.2.3go.mod
Gogithub.com/openai/openai-go/v3v3.41.0go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogithub.com/spiffe/go-spiffe/v2v2.6.0go.mod
Gogolang.org/x/oauth2v0.36.0go.mod
Gogolang.org/x/termv0.45.0go.mod
Gogopkg.in/yaml.v3v3.0.1go.mod
npm@fontsource/inter^5.2.8ui/package.json
npm@fontsource/jetbrains-mono^5.2.8ui/package.json
npm@radix-ui/react-alert-dialog1.1.6ui/package.json
npm@radix-ui/react-checkbox1.1.4ui/package.json
npm@radix-ui/react-dialog1.1.6ui/package.json
npm@radix-ui/react-dropdown-menu2.1.6ui/package.json
npm@radix-ui/react-label2.1.11ui/package.json
npm@radix-ui/react-popover1.1.6ui/package.json
npm@radix-ui/react-radio-group1.2.3ui/package.json
npm@radix-ui/react-select2.1.6ui/package.json
npm@radix-ui/react-slot1.1.2ui/package.json
npm@radix-ui/react-switch1.1.3ui/package.json
npm@radix-ui/react-tabs1.1.3ui/package.json
npm@xterm/addon-fit^0.11.0ui/package.json
npm@xterm/xterm^6.0.0ui/package.json
npmasciinema-player^3.8.0ui/package.json
npmclass-variance-authority0.7.1ui/package.json
npmclsx2.1.1ui/package.json
npmcmdk1.1.1ui/package.json
npmlucide-react1.24.0ui/package.json
npmreact18.3.1ui/package.json
npmreact-dom18.3.1ui/package.json
npmreact-router-dom^7.18.1ui/package.json
npmsonner2.0.3ui/package.json
npmtailwind-merge3.2.0ui/package.json
npmtw-animate-css1.4.0ui/package.json
全部依赖 686

来自 GitHub 依赖图的完整解析依赖集合:53 个直接依赖与 633 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
Gofilippo.io/agev1.2.1直接
Gogithub.com/anthropics/anthropic-sdk-gov1.56.0直接
Gogithub.com/aws/aws-sdk-go-v2/configv1.32.25直接
Gogithub.com/azure/azure-sdk-for-go/sdk/azidentityv1.14.0直接
Gogithub.com/bradleyfalzon/ghinstallation/v2v2.19.0直接
Gogithub.com/coder/websocketv1.8.14直接
Gogithub.com/containerd/errdefsv1.0.0直接
Gogithub.com/coreos/go-oidc/v3v3.20.0直接
Gogithub.com/go-chi/chi/v5v5.2.4直接
Gogithub.com/go-jose/go-jose/v4v4.1.4直接
Gogithub.com/google/go-github/v88v88.0.0直接
Gogithub.com/google/uuidv1.6.0直接
Gogithub.com/jackc/pgx/v5v5.10.0直接
Gogithub.com/moby/docker-image-specv1.3.1直接
Gogithub.com/moby/moby/apiv1.55.0直接
Gogithub.com/moby/moby/clientv0.5.0直接
Gogithub.com/moby/profiles/seccompv0.2.3直接
Gogithub.com/openai/openai-go/v3v3.41.0直接
Gogithub.com/spf13/cobrav1.10.2直接
Gogithub.com/spiffe/go-spiffe/v2v2.6.0直接
Gogolang.org/x/oauth2v0.36.0直接
Gogolang.org/x/termv0.45.0直接
Gogopkg.in/yaml.v3v3.0.1直接
npm@fontsource/inter5.2.8直接
npm@fontsource/jetbrains-mono5.2.8直接
npm@radix-ui/react-alert-dialog1.1.6直接
npm@radix-ui/react-checkbox1.1.4直接
npm@radix-ui/react-dialog1.1.6直接
npm@radix-ui/react-dropdown-menu2.1.6直接
npm@radix-ui/react-label2.1.11直接
npm@radix-ui/react-popover1.1.6直接
npm@radix-ui/react-radio-group1.2.3直接
npm@radix-ui/react-select2.1.6直接
npm@radix-ui/react-slot1.1.2直接
npm@radix-ui/react-slot1.3.0直接
npm@radix-ui/react-switch1.1.3直接
npm@radix-ui/react-tabs1.1.3直接
npm@xterm/addon-fit0.11.0直接
npm@xterm/xterm6.0.0直接
npmasciinema-player3.16.0直接
npmclass-variance-authority0.7.1直接
npmclsx2.1.1直接
npmcmdk1.1.1直接
npmlucide-react1.24.0直接
npmreact18.3.1直接
npmreact19.2.7直接
npmreact-dom18.3.1直接
npmreact-dom19.2.7直接
npmreact-router-dom7.18.1直接
npmsonner2.0.3直接
npmtailwind-merge3.2.0直接
npmtailwind-merge3.6.0直接
npmtw-animate-css1.4.0直接
Gogithub.com/aws/aws-sdk-go-v2v1.42.0间接
Gogithub.com/aws/aws-sdk-go-v2/aws/protocol/eventstreamv1.7.8间接
Gogithub.com/aws/aws-sdk-go-v2/credentialsv1.19.24间接
Gogithub.com/aws/aws-sdk-go-v2/feature/ec2/imdsv1.18.29间接
Gogithub.com/aws/aws-sdk-go-v2/internal/configsourcesv1.4.29间接
Gogithub.com/aws/aws-sdk-go-v2/internal/endpoints/v2v2.7.29间接
Gogithub.com/aws/aws-sdk-go-v2/internal/v4av1.4.30间接
Gogithub.com/aws/aws-sdk-go-v2/service/internal/accept-encodingv1.13.12间接
Gogithub.com/aws/aws-sdk-go-v2/service/internal/presigned-urlv1.13.29间接
Gogithub.com/aws/aws-sdk-go-v2/service/signinv1.2.0间接
Gogithub.com/aws/aws-sdk-go-v2/service/ssov1.31.3间接
Gogithub.com/aws/aws-sdk-go-v2/service/ssooidcv1.36.6间接
Gogithub.com/aws/aws-sdk-go-v2/service/stsv1.43.3间接
Gogithub.com/aws/smithy-gov1.27.1间接
Gogithub.com/azure/azure-sdk-for-go/sdk/azcorev1.22.0间接
Gogithub.com/azure/azure-sdk-for-go/sdk/internalv1.12.0间接
Gogithub.com/azuread/microsoft-authentication-library-for-gov1.7.2间接
Gogithub.com/bahlo/generic-list-gov0.2.0间接
Gogithub.com/buger/jsonparserv1.1.2间接
Gogithub.com/cespare/xxhash/v2v2.3.0间接
Gogithub.com/containerd/errdefs/pkgv0.3.0间接
Gogithub.com/distribution/referencev0.6.0间接
Gogithub.com/docker/go-connectionsv0.7.0间接
Gogithub.com/docker/go-unitsv0.5.0间接
Gogithub.com/felixge/httpsnoopv1.0.4间接
Gogithub.com/go-logr/logrv1.4.3间接
Gogithub.com/go-logr/stdrv1.2.2间接
Gogithub.com/golang-jwt/jwt/v4v4.5.2间接
Gogithub.com/golang-jwt/jwt/v5v5.3.1间接
Gogithub.com/google/go-querystringv1.2.0间接
Gogithub.com/inconshreveable/mousetrapv1.1.0间接
Gogithub.com/invopop/jsonschemav0.14.0间接
Gogithub.com/jackc/pgpassfilev1.0.0间接
Gogithub.com/jackc/pgservicefilev0.0.0-20240606120523-5a60cdf6a761间接
Gogithub.com/jackc/puddle/v2v2.2.2间接
Gogithub.com/kylelemons/godebugv1.1.0间接
Gogithub.com/microsoft/go-winiov0.6.2间接
Gogithub.com/opencontainers/go-digestv1.0.0间接
Gogithub.com/opencontainers/image-specv1.1.1间接
Gogithub.com/opencontainers/runtime-specv1.3.0间接
Gogithub.com/pb33f/ordered-map/v2v2.3.1间接
Gogithub.com/pkg/browserv0.0.0-20240102092130-5ac0b6a4141c间接
Gogithub.com/spf13/pflagv1.0.9间接
Gogithub.com/standard-webhooks/standard-webhooks/librariesv0.0.1间接
Gogithub.com/tidwall/gjsonv1.18.0间接
Gogithub.com/tidwall/matchv1.1.1间接
Gogithub.com/tidwall/prettyv1.2.1间接
Gogithub.com/tidwall/sjsonv1.2.5间接
Gogo.opentelemetry.io/auto/sdkv1.2.1间接
Gogo.opentelemetry.io/contrib/instrumentation/net/http/otelhttpv0.69.0间接
Gogo.opentelemetry.io/otelv1.44.0间接
Gogo.opentelemetry.io/otel/metricv1.44.0间接
Gogo.opentelemetry.io/otel/tracev1.44.0间接
Gogo.yaml.in/yaml/v4v4.0.0-rc.2间接
Gogolang.org/x/cryptov0.54.0间接
Gogolang.org/x/netv0.56.0间接
Gogolang.org/x/syncv0.22.0间接
Gogolang.org/x/sysv0.47.0间接
Gogolang.org/x/textv0.40.0间接
npm@adobe/css-tools4.5.0间接
npm@ampproject/remapping2.3.0间接
npm@antfu/install-pkg1.1.0间接
npm@asamuzakjp/css-color5.1.11间接
npm@asamuzakjp/dom-selector7.1.1间接
npm@asamuzakjp/generational-cache1.0.1间接
npm@asamuzakjp/nwsapi2.3.9间接
npm@babel/code-frame7.29.7间接
npm@babel/compat-data7.29.7间接
npm@babel/core7.29.7间接
npm@babel/generator7.29.7间接
npm@babel/helper-compilation-targets7.29.7间接
npm@babel/helper-globals7.29.7间接
npm@babel/helper-module-imports7.29.7间接
npm@babel/helper-module-transforms7.29.7间接
npm@babel/helper-plugin-utils7.29.7间接
npm@babel/helper-string-parser7.29.7间接
npm@babel/helper-validator-identifier7.29.7间接
npm@babel/helper-validator-option7.29.7间接
npm@babel/helpers7.29.7间接
npm@babel/parser7.29.7间接
npm@babel/plugin-transform-react-jsx-self7.29.7间接
npm@babel/plugin-transform-react-jsx-source7.29.7间接
npm@babel/runtime7.29.7间接
npm@babel/template7.29.7间接
npm@babel/traverse7.29.7间接
npm@babel/types7.29.7间接
npm@bcoe/v8-coverage1.0.2间接
npm@braintree/sanitize-url7.1.2间接
npm@bramus/specificity2.4.2间接
npm@chevrotain/types11.1.2间接
npm@csstools/color-helpers6.1.0间接
npm@csstools/css-calc3.2.1间接
npm@csstools/css-color-parser4.1.9间接
npm@csstools/css-parser-algorithms4.0.0间接
npm@csstools/css-syntax-patches-for-csstree1.1.6间接
npm@csstools/css-tokenizer4.0.0间接
npm@esbuild/aix-ppc640.25.12间接
npm@esbuild/android-arm0.25.12间接
npm@esbuild/android-arm640.25.12间接
npm@esbuild/android-x640.25.12间接
npm@esbuild/darwin-arm640.25.12间接
npm@esbuild/darwin-x640.25.12间接
npm@esbuild/freebsd-arm640.25.12间接
npm@esbuild/freebsd-x640.25.12间接
npm@esbuild/linux-arm0.25.12间接
npm@esbuild/linux-arm640.25.12间接
npm@esbuild/linux-ia320.25.12间接
npm@esbuild/linux-loong640.25.12间接
npm@esbuild/linux-mips64el0.25.12间接
npm@esbuild/linux-ppc640.25.12间接
npm@esbuild/linux-riscv640.25.12间接
npm@esbuild/linux-s390x0.25.12间接
npm@esbuild/linux-x640.25.12间接
npm@esbuild/netbsd-arm640.25.12间接
npm@esbuild/netbsd-x640.25.12间接
npm@esbuild/openbsd-arm640.25.12间接
npm@esbuild/openbsd-x640.25.12间接
npm@esbuild/openharmony-arm640.25.12间接
npm@esbuild/sunos-x640.25.12间接
npm@esbuild/win32-arm640.25.12间接
npm@esbuild/win32-ia320.25.12间接
npm@esbuild/win32-x640.25.12间接
npm@exodus/bytes1.15.1间接
npm@floating-ui/core1.7.5间接
npm@floating-ui/dom1.7.6间接
npm@floating-ui/react0.26.28间接
npm@floating-ui/react0.27.19间接
npm@floating-ui/react-dom2.1.8间接
npm@floating-ui/utils0.2.11间接
npm@fortawesome/fontawesome-free7.3.0间接
npm@headlessui/react2.2.10间接
npm@headlessui/tailwindcss0.2.2间接
npm@iconify/types2.0.0间接
npm@iconify/utils3.1.4间接
npm@inquirer/ansi2.0.7间接
npm@inquirer/confirm6.1.1间接
npm@inquirer/core11.2.1间接
npm@inquirer/figures2.0.7间接
npm@inquirer/type4.0.7间接
npm@internationalized/date3.12.2间接
npm@internationalized/number3.6.7间接
npm@internationalized/string3.2.9间接
npm@isaacs/cliui8.0.2间接
npm@istanbuljs/schema0.1.6间接
npm@jridgewell/gen-mapping0.3.13间接
npm@jridgewell/remapping2.3.5间接
npm@jridgewell/resolve-uri3.1.2间接
npm@jridgewell/sourcemap-codec1.5.5间接
npm@jridgewell/trace-mapping0.3.31间接
npm@mermaid-js/layout-elk0.2.2间接
npm@mermaid-js/layout-tidy-tree0.2.2间接
npm@mermaid-js/mermaid-cli11.16.0间接
npm@mermaid-js/mermaid-zenuml0.2.3间接
npm@mermaid-js/parser1.2.0间接
npm@mswjs/interceptors0.41.9间接
npm@napi-rs/canvas0.1.100间接
npm@napi-rs/canvas-android-arm640.1.100间接
npm@napi-rs/canvas-darwin-arm640.1.100间接
npm@napi-rs/canvas-darwin-x640.1.100间接
npm@napi-rs/canvas-linux-arm-gnueabihf0.1.100间接
npm@napi-rs/canvas-linux-arm64-gnu0.1.100间接
npm@napi-rs/canvas-linux-arm64-musl0.1.100间接
npm@napi-rs/canvas-linux-riscv64-gnu0.1.100间接
npm@napi-rs/canvas-linux-x64-gnu0.1.100间接
npm@napi-rs/canvas-linux-x64-musl0.1.100间接
npm@napi-rs/canvas-win32-arm64-msvc0.1.100间接
npm@napi-rs/canvas-win32-x64-msvc0.1.100间接
npm@open-draft/deferred-promise2.2.0间接
npm@open-draft/deferred-promise3.0.0间接
npm@open-draft/logger0.3.0间接
npm@open-draft/until2.1.0间接
npm@pkgjs/parseargs0.11.0间接
npm@playwright/test1.61.1间接
npm@puppeteer/browsers3.0.6间接
npm@radix-ui/number1.1.0间接
npm@radix-ui/primitive1.1.1间接
npm@radix-ui/react-arrow1.1.2间接
npm@radix-ui/react-collection1.1.2间接
npm@radix-ui/react-compose-refs1.1.1间接
npm@radix-ui/react-compose-refs1.1.3间接
npm@radix-ui/react-context1.1.1间接
npm@radix-ui/react-direction1.1.0间接
npm@radix-ui/react-dismissable-layer1.1.5间接
npm@radix-ui/react-focus-guards1.1.1间接
npm@radix-ui/react-focus-scope1.1.2间接
npm@radix-ui/react-id1.1.0间接
npm@radix-ui/react-id1.1.2间接
npm@radix-ui/react-menu2.1.6间接
npm@radix-ui/react-popper1.2.2间接
npm@radix-ui/react-portal1.1.4间接
npm@radix-ui/react-presence1.1.2间接
npm@radix-ui/react-primitive2.0.2间接
npm@radix-ui/react-primitive2.1.6间接
npm@radix-ui/react-primitive2.1.7间接
npm@radix-ui/react-roving-focus1.1.2间接
npm@radix-ui/react-use-callback-ref1.1.0间接
npm@radix-ui/react-use-controllable-state1.1.0间接
npm@radix-ui/react-use-escape-keydown1.1.0间接
npm@radix-ui/react-use-layout-effect1.1.0间接
npm@radix-ui/react-use-layout-effect1.1.2间接
npm@radix-ui/react-use-previous1.1.0间接
npm@radix-ui/react-use-rect1.1.0间接
npm@radix-ui/react-use-size1.1.0间接
npm@radix-ui/react-visually-hidden1.1.2间接
npm@radix-ui/rect1.1.0间接
npm@react-aria/focus3.22.1间接
npm@react-aria/interactions3.28.1间接
npm@react-types/shared3.36.0间接
npm@rolldown/pluginutils1.0.0-beta.27间接
npm@rollup/rollup-android-arm-eabi4.62.2间接
npm@rollup/rollup-android-arm644.62.2间接
npm@rollup/rollup-darwin-arm644.62.2间接
npm@rollup/rollup-darwin-x644.62.2间接
npm@rollup/rollup-freebsd-arm644.62.2间接
npm@rollup/rollup-freebsd-x644.62.2间接
npm@rollup/rollup-linux-arm-gnueabihf4.62.2间接
npm@rollup/rollup-linux-arm-musleabihf4.62.2间接
npm@rollup/rollup-linux-arm64-gnu4.62.2间接
npm@rollup/rollup-linux-arm64-musl4.62.2间接
npm@rollup/rollup-linux-loong64-gnu4.62.2间接
npm@rollup/rollup-linux-loong64-musl4.62.2间接
npm@rollup/rollup-linux-ppc64-gnu4.62.2间接
npm@rollup/rollup-linux-ppc64-musl4.62.2间接
npm@rollup/rollup-linux-riscv64-gnu4.62.2间接
npm@rollup/rollup-linux-riscv64-musl4.62.2间接
npm@rollup/rollup-linux-s390x-gnu4.62.2间接
npm@rollup/rollup-linux-x64-gnu4.62.2间接
npm@rollup/rollup-linux-x64-musl4.62.2间接
npm@rollup/rollup-openbsd-x644.62.2间接
npm@rollup/rollup-openharmony-arm644.62.2间接
npm@rollup/rollup-win32-arm64-msvc4.62.2间接
npm@rollup/rollup-win32-ia32-msvc4.62.2间接
npm@rollup/rollup-win32-x64-gnu4.62.2间接
npm@rollup/rollup-win32-x64-msvc4.62.2间接
npm@solid-primitives/refs1.1.3间接
npm@solid-primitives/transition-group1.1.2间接
npm@solid-primitives/utils6.4.0间接
npm@swc/helpers0.5.23间接
npm@tailwindcss/node4.3.2间接
npm@tailwindcss/oxide4.3.2间接
npm@tailwindcss/oxide-android-arm644.3.2间接
npm@tailwindcss/oxide-darwin-arm644.3.2间接
npm@tailwindcss/oxide-darwin-x644.3.2间接
npm@tailwindcss/oxide-freebsd-x644.3.2间接
npm@tailwindcss/oxide-linux-arm-gnueabihf4.3.2间接
npm@tailwindcss/oxide-linux-arm64-gnu4.3.2间接
npm@tailwindcss/oxide-linux-arm64-musl4.3.2间接
npm@tailwindcss/oxide-linux-x64-gnu4.3.2间接
npm@tailwindcss/oxide-linux-x64-musl4.3.2间接
npm@tailwindcss/oxide-wasm32-wasi4.3.2间接
npm@tailwindcss/oxide-win32-arm64-msvc4.3.2间接
npm@tailwindcss/oxide-win32-x64-msvc4.3.2间接
npm@tailwindcss/vite4.3.2间接
npm@tanstack/react-virtual3.14.5间接
npm@tanstack/virtual-core3.17.3间接
npm@testing-library/dom10.4.1间接
npm@testing-library/jest-dom6.9.1间接
npm@testing-library/react16.3.2间接
npm@testing-library/user-event14.6.1间接
npm@types/aria-query5.0.4间接
npm@types/babel__core7.20.5间接
npm@types/babel__generator7.27.0间接
npm@types/babel__template7.4.4间接
npm@types/babel__traverse7.28.0间接
npm@types/chai5.2.3间接
npm@types/d37.4.3间接
npm@types/d3-array3.2.2间接
npm@types/d3-axis3.0.6间接
npm@types/d3-brush3.0.6间接
npm@types/d3-chord3.0.6间接
npm@types/d3-color3.1.3间接
npm@types/d3-contour3.0.6间接
npm@types/d3-delaunay6.0.4间接
npm@types/d3-dispatch3.0.7间接
npm@types/d3-drag3.0.7间接
npm@types/d3-dsv3.0.7间接
npm@types/d3-ease3.0.2间接
npm@types/d3-fetch3.0.7间接
npm@types/d3-force3.0.10间接
npm@types/d3-format3.0.4间接
npm@types/d3-geo3.1.0间接
npm@types/d3-hierarchy3.1.7间接
npm@types/d3-interpolate3.0.4间接
npm@types/d3-path3.1.1间接
npm@types/d3-polygon3.0.2间接
npm@types/d3-quadtree3.0.6间接
npm@types/d3-random3.0.4间接
npm@types/d3-scale4.0.9间接
npm@types/d3-scale-chromatic3.1.0间接
npm@types/d3-selection3.0.11间接
npm@types/d3-shape3.1.8间接
npm@types/d3-time3.0.4间接
npm@types/d3-time-format4.0.3间接
npm@types/d3-timer3.0.2间接
npm@types/d3-transition3.0.9间接
npm@types/d3-zoom3.0.8间接
npm@types/deep-eql4.0.2间接
npm@types/estree1.0.9间接
npm@types/geojson7946.0.16间接
npm@types/node22.20.0间接
npm@types/prop-types15.7.15间接
npm@types/react18.3.12间接
npm@types/react-dom18.3.1间接
npm@types/set-cookie-parser2.4.10间接
npm@types/statuses2.0.6间接
npm@types/trusted-types2.0.7间接
npm@upsetjs/venn.js2.0.0间接
npm@vitejs/plugin-react4.7.0间接
npm@vitest/coverage-v83.2.7间接
npm@vitest/expect3.2.7间接
npm@vitest/mocker3.2.7间接
npm@vitest/pretty-format3.2.7间接
npm@vitest/runner3.2.7间接
npm@vitest/snapshot3.2.7间接
npm@vitest/spy3.2.7间接
npm@vitest/utils3.2.7间接
npm@zenuml/core3.50.1间接
npmansi-regex5.0.1间接
npmansi-regex6.2.2间接
npmansi-styles4.3.0间接
npmansi-styles5.2.0间接
npmansi-styles6.2.3间接
npmantlr44.11.0间接
npmaria-hidden1.2.6间接
npmaria-query5.3.0间接
npmaria-query5.3.2间接
npmassertion-error2.0.1间接
npmast-v8-to-istanbul0.3.12间接
npmbalanced-match1.0.2间接
npmbalanced-match4.0.4间接
npmbaseline-browser-mapping2.10.40间接
npmbidi-js1.0.3间接
npmbrace-expansion2.1.1间接
npmbrace-expansion5.0.6间接
npmbrowserslist4.28.4间接
npmcac6.7.14间接
npmcaniuse-lite1.0.30001799间接
npmchai5.3.3间接
npmchalk5.6.2间接
npmcheck-error2.1.3间接
npmchromium-bidi16.0.1间接
npmcli-width4.1.0间接
npmcliui8.0.1间接
npmcliui9.0.1间接
npmcolor-convert2.0.1间接
npmcolor-name1.1.4间接
npmcolor-name2.1.0间接
npmcolor-string2.1.4间接
npmcommander13.1.0间接
npmcommander7.2.0间接
npmcommander8.3.0间接
npmconvert-source-map2.0.0间接
npmcookie1.1.1间接
npmcose-base1.0.3间接
npmcose-base2.2.0间接
npmcross-spawn7.0.6间接
npmcss-tree3.2.1间接
npmcss.escape1.5.1间接
npmcsstype3.2.3间接
npmcytoscape3.34.0间接
npmcytoscape-cose-bilkent4.1.0间接
npmcytoscape-fcose2.2.0间接
npmd37.9.0间接
npmd3-array2.12.1间接
npmd3-array3.2.4间接
npmd3-axis3.0.0间接
npmd3-brush3.0.0间接
npmd3-chord3.0.1间接
npmd3-color3.1.0间接
npmd3-contour4.0.2间接
npmd3-delaunay6.0.4间接
npmd3-dispatch3.0.1间接
npmd3-drag3.0.0间接
npmd3-dsv3.0.1间接
npmd3-ease3.0.1间接
npmd3-fetch3.0.1间接
npmd3-force3.0.0间接
npmd3-format3.1.2间接
npmd3-geo3.1.1间接
npmd3-hierarchy3.1.2间接
npmd3-interpolate3.0.1间接
npmd3-path1.0.9间接
npmd3-path3.1.0间接
npmd3-polygon3.0.1间接
npmd3-quadtree3.0.1间接
npmd3-random3.0.1间接
npmd3-sankey0.12.3间接
npmd3-scale4.0.2间接
npmd3-scale-chromatic3.1.0间接
npmd3-selection3.0.0间接
npmd3-shape1.3.7间接
npmd3-shape3.2.0间接
npmd3-time3.1.0间接
npmd3-time-format4.1.0间接
npmd3-timer3.0.1间接
npmd3-transition3.0.1间接
npmd3-zoom3.0.0间接
npmdagre-d3-es7.0.14间接
npmdata-urls7.0.0间接
npmdayjs1.11.21间接
npmdebug4.4.3间接
npmdecimal.js10.6.0间接
npmdeep-eql5.0.2间接
npmdelaunator5.1.0间接
npmdequal2.0.3间接
npmdetect-libc2.1.2间接
npmdetect-node-es1.1.0间接
npmdevtools-protocol0.0.1638949间接
npmdom-accessibility-api0.5.16间接
npmdom-accessibility-api0.6.3间接
npmdompurify3.4.11间接
npmeastasianwidth0.2.0间接
npmelectron-to-chromium1.5.380间接
npmelkjs0.9.3间接
npmemoji-regex10.6.0间接
npmemoji-regex8.0.0间接
npmemoji-regex9.2.2间接
npmenhanced-resolve5.21.6间接
npmentities8.0.0间接
npmes-module-lexer1.7.0间接
npmes-toolkit1.49.0间接
npmesbuild0.25.12间接
npmescalade3.2.0间接
npmestree-walker3.0.3间接
npmexpect-type1.4.0间接
npmfast-string-truncated-width3.0.3间接
npmfast-string-width3.0.2间接
npmfast-wrap-ansi0.2.2间接
npmfdir6.5.0间接
npmforeground-child3.3.1间接
npmfsevents2.3.2间接
npmfsevents2.3.3间接
npmgensync1.0.0-beta.2间接
npmget-caller-file2.0.5间接
npmget-east-asian-width1.6.0间接
npmget-nonce1.0.1间接
npmglob10.5.0间接
npmgraceful-fs4.2.11间接
npmgraphql16.14.2间接
npmhachure-fill0.5.2间接
npmhas-flag4.0.0间接
npmheaders-polyfill5.0.1间接
npmhighlight.js11.11.1间接
npmhtml-encoding-sniffer6.0.0间接
npmhtml-escaper2.0.2间接
npmhtml-to-image1.11.13间接
npmiconv-lite0.6.3间接
npmimport-meta-resolve4.2.0间接
npmindent-string4.0.0间接
npminternmap1.0.1间接
npminternmap2.0.3间接
npmis-fullwidth-code-point3.0.0间接
npmis-node-process1.2.0间接
npmis-potential-custom-element-name1.0.1间接
npmisexe2.0.0间接
npmistanbul-lib-coverage3.2.2间接
npmistanbul-lib-report3.0.1间接
npmistanbul-lib-source-maps5.0.6间接
npmistanbul-reports3.2.0间接
npmjackspeak3.4.3间接
npmjiti2.7.0间接
npmjotai2.20.1间接
npmjs-tokens10.0.0间接
npmjs-tokens4.0.0间接
npmjs-tokens9.0.1间接
npmjsdom29.1.1间接
npmjsesc3.1.0间接
npmjson52.2.3间接
npmkatex0.16.47间接
npmkhroma2.1.0间接
npmlayout-base1.0.2间接
npmlayout-base2.0.1间接
npmlightningcss1.32.0间接
npmlightningcss-android-arm641.32.0间接
npmlightningcss-darwin-arm641.32.0间接
npmlightningcss-darwin-x641.32.0间接
npmlightningcss-freebsd-x641.32.0间接
npmlightningcss-linux-arm-gnueabihf1.32.0间接
npmlightningcss-linux-arm64-gnu1.32.0间接
npmlightningcss-linux-arm64-musl1.32.0间接
npmlightningcss-linux-x64-gnu1.32.0间接
npmlightningcss-linux-x64-musl1.32.0间接
npmlightningcss-win32-arm64-msvc1.32.0间接
npmlightningcss-win32-x64-msvc1.32.0间接
npmlilconfig3.1.3间接
npmlodash-es4.18.1间接
npmloose-envify1.4.0间接
npmloupe3.2.1间接
npmlru-cache10.4.3间接
npmlru-cache11.5.2间接
npmlru-cache5.1.1间接
npmlz-string1.5.0间接
npmmagic-string0.30.21间接
npmmagicast0.3.5间接
npmmake-dir4.0.0间接
npmmarked16.4.2间接
npmmarked4.3.0间接
npmmdn-data2.27.1间接
npmmermaid11.16.0间接
npmmin-indent1.0.1间接
npmminimatch10.2.5间接
npmminimatch9.0.9间接
npmminipass7.1.3间接
npmmitt3.0.1间接
npmmodern-tar0.7.6间接
npmms2.1.3间接
npmmsw2.14.6间接
npmmute-stream3.0.0间接
npmnanoid3.3.15间接
npmnode-releases2.0.50间接
npmoutvariant1.4.3间接
npmp-limit6.2.0间接
npmpackage-json-from-dist1.0.1间接
npmpackage-manager-detector1.7.0间接
npmparse58.0.1间接
npmpath-data-parser0.1.0间接
npmpath-key3.1.1间接
npmpath-scurry1.11.1间接
npmpath-to-regexp6.3.0间接
npmpathe2.0.3间接
npmpathval2.0.1间接
npmpicocolors1.1.1间接
npmpicomatch4.0.4间接
npmplaywright1.61.1间接
npmplaywright-core1.61.1间接
npmpoints-on-curve0.2.0间接
npmpoints-on-path0.2.1间接
npmpostcss8.5.16间接
npmpretty-format27.5.1间接
npmpunycode2.3.1间接
npmpuppeteer25.3.0间接
npmpuppeteer-core25.3.0间接
npmreact-aria3.50.0间接
npmreact-is17.0.2间接
npmreact-refresh0.17.0间接
npmreact-remove-scroll2.7.2间接
npmreact-remove-scroll-bar2.3.8间接
npmreact-router7.18.1间接
npmreact-stately3.48.0间接
npmreact-style-singleton2.2.3间接
npmredent3.0.0间接
npmrequire-directory2.1.1间接
npmrequire-from-string2.0.2间接
npmrettime0.11.11间接
npmrobust-predicates3.0.3间接
npmrollup4.62.2间接
npmroughjs4.6.6间接
npmrw1.3.3间接
npmsafer-buffer2.1.2间接
npmsaxes6.0.0间接
npmscheduler0.23.2间接
npmscheduler0.27.0间接
npmsemver6.3.1间接
npmsemver7.8.5间接
npmseroval1.5.4间接
npmseroval-plugins1.5.4间接
npmset-cookie-parser2.7.2间接
npmset-cookie-parser3.1.1间接
npmshebang-command2.0.0间接
npmshebang-regex3.0.0间接
npmsiginfo2.0.0间接
npmsignal-exit4.1.0间接
npmsolid-js1.9.13间接
npmsolid-transition-group0.2.3间接
npmsource-map-js1.2.1间接
npmstackback0.0.2间接
npmstatuses2.0.2间接
npmstd-env3.10.0间接
npmstrict-event-emitter0.5.1间接
npmstring-width4.2.3间接
npmstring-width5.1.2间接
npmstring-width7.2.0间接
npmstrip-ansi6.0.1间接
npmstrip-ansi7.2.0间接
npmstrip-indent3.0.0间接
npmstrip-literal3.1.0间接
npmstylis4.4.0间接
npmsupports-color7.2.0间接
npmsymbol-tree3.2.4间接
npmtabbable6.5.0间接
npmtagged-tag1.0.0间接
npmtailwindcss4.1.12间接
npmtailwindcss4.3.2间接
npmtapable2.3.3间接
npmtest-exclude7.0.2间接
npmtinybench2.9.0间接
npmtinyexec0.3.2间接
npmtinyexec1.2.4间接
npmtinyglobby0.2.17间接
npmtinypool1.1.1间接
npmtinyrainbow2.0.0间接
npmtinyspy4.0.4间接
npmtldts7.4.5间接
npmtldts-core7.4.5间接
npmtough-cookie6.0.1间接
npmtr466.0.0间接
npmts-dedent2.3.0间接
npmtslib2.8.1间接
npmtype-fest5.7.0间接
npmtyped-query-selector2.12.2间接
npmtypescript5.9.3间接
npmundici7.28.0间接
npmundici-types6.21.0间接
npmuntil-async3.0.2间接
npmupdate-browserslist-db1.2.3间接
npmuse-callback-ref1.3.3间接
npmuse-sidecar1.1.3间接
npmuse-sync-external-store1.6.0间接
npmuuid14.0.1间接
npmvite6.4.3间接
npmvite-node3.2.4间接
npmvitest3.2.7间接
npmw3c-xmlserializer5.0.0间接
npmwebdriver-bidi-protocol0.4.2间接
npmwebidl-conversions8.0.1间接
npmwhatwg-mimetype5.0.0间接
npmwhatwg-url16.0.1间接
npmwhich2.0.2间接
npmwhy-is-node-running2.3.0间接
npmwrap-ansi7.0.0间接
npmwrap-ansi8.1.0间接
npmwrap-ansi9.0.2间接
npmws8.21.0间接
npmxml-name-validator5.0.0间接
npmxmlchars2.2.0间接
npmy18n5.0.8间接
npmyallist3.1.1间接
npmyargs17.7.3间接
npmyargs18.0.0间接
npmyargs-parser21.1.1间接
npmyargs-parser22.0.0间接
npmyocto-queue1.2.2间接
npmzod3.25.76间接
依赖安全公告 7

该仓库未发布可被索引解析的包,因此评估的是其自身的依赖图——共 686 个包,其中也包含从不交付的开发与测试版本固定:7 个存在已知公告,1 个为直接依赖。

软件包版本关系严重程度公告数修复版本
brace-expansion2.1.1间接25.0.8
brace-expansion5.0.6间接25.0.8
postcss8.5.16间接18.5.18
react-router7.18.1间接18.3.0
dompurify3.4.11间接13.4.12
github.com/go-chi/chi/v5v5.2.4直接未知35.3.0
golang.org/x/cryptov0.54.0间接未知1

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [
        "ai-agents",
        "egress-control",
        "golang",
        "gvisor",
        "llm",
        "sandbox",
        "security",
        "supply-chain"
      ],
      "is_fork": false,
      "size_kb": 6111,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Go": 4164934,
        "CSS": 10031,
        "HTML": 398,
        "Shell": 395961,
        "Python": 16400,
        "PLpgSQL": 4640,
        "Makefile": 31046,
        "Dockerfile": 47759,
        "JavaScript": 460,
        "TypeScript": 1686309,
        "Go Template": 2898
      },
      "pushed_at": "2026-07-22T03:29:55Z",
      "created_at": "2026-07-08T04:50:36Z",
      "owner_type": "User",
      "updated_at": "2026-07-21T03:20:22Z",
      "description": "Open-source governance control plane for coding agents — per-run identity, brokered credentials, layered egress, approvals, and an append-only audit. Apache-2.0, self-hosted.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go",
        "TypeScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Charlie Johnston",
      "type": "User",
      "login": "cjohnstoniv",
      "company": "blackrock",
      "location": null,
      "followers": 2,
      "avatar_url": "https://avatars.githubusercontent.com/u/1009163?v=4",
      "created_at": "2011-08-27T22:51:48Z",
      "is_verified": null,
      "public_repos": 9,
      "account_age_days": 5447
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.4.2",
          "kind": "patch",
          "published_at": "2026-07-21T03:26:00Z"
        },
        {
          "tag": "v0.4.1",
          "kind": "patch",
          "published_at": "2026-07-20T17:02:06Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-07-20T05:15:50Z"
        },
        {
          "tag": "v0.3.1",
          "kind": "patch",
          "published_at": "2026-07-18T17:37:46Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-07-15T02:19:58Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-07-13T05:58:19Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-07-08T05:07:57Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "61edf791031d627428b2c6cbc2c8e0f98f54d5f8",
          "body": "Follow-up findings from the same adopter, now running the containerized\nstack on a corporate laptop end to end. Full report (including what is\nstill open) in docs/adoption/corp-network-onboarding-findings.md.\n\nAn unreachable upstream proxy no longer hangs an approved request.\ndialThroughUpstream wro\n[…]\nfe.directory, so a\nhost/sandbox uid mismatch reads as itself instead of git refusing every\ncommand with \"detected dubious ownership\".\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "release: 0.4.2 — fix a hang, a regression, and two false claims",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-21T03:20:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b3f089582b92e42da99534d06cb1e134141d7f2f",
          "body": "Two adopter field reports, both on the containerized default path\n(`make setup`), both onboarding-trust bugs. The reports are kept\nde-identified in the new docs/adoption/.\n\n`make setup` no longer dies on a registry that can't serve pnpm. The\ndefault ui-build stage failed with a raw npm E404/403 behi\n[…]\nE workspace name, so the suite passed once and failed on every later\nrun against the same database — and release-check runs it twice.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "release: 0.4.1 — corporate-network onboarding fixes",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T16:56:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2d517ad7643a0bf026df25ca9dc9cf3d9e415a29",
          "body": "The ui-e2e lane had been red for a long time — 5 spec files on the 0.3.1 push,\n8 by the time this release's UI work landed — and it was never a product\nregression. Every failure was an assertion that had drifted from what the app\nactually renders. Because the lane is not a required check, the drift \n[…]\nh a\ndiagnostic naming the missing capability; every other failure still fails, so a\ngenuine build regression cannot hide behind this.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "test(e2e): bring the browser suite back in step with the shipped UI",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T05:07:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fa2564cbc1dc9dcbd00c9ce81f9e80c1b40a4b91",
          "body": "…se CI\n\nTwo tests intermittently failed the required build and ui jobs on a loaded CI\nrunner. Neither is a product defect; both are test-synchronization gaps.\n\nTestNewSessionRecorder_ConcurrentWriteAndFinishRaceFree (build, -tags docker)\ncalled finish() before the write pump was guaranteed to have p\n[…]\none test at a\ntime is whack-a-mole.\n\ngo build/vet, go test (incl -tags docker), make lint (0), and the full ui suite\n(549) are green.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "test: de-flake the two required-context tests that reddened the relea…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T03:56:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "610ebf962bb5ed254112d776754d203f16dd1068",
          "body": "Every entry is a commit:file:rule:line fingerprint, so rewriting history\ninvalidated all eleven and the full-history scan went red — a required CI\ncheck. The accepted findings themselves are unchanged: the same eleven\nfiles, rules and lines (dev age keys in main.go and the local scripts, and\nthe broker/workspacescan test fixtures), only at their new commit ids.\nRegenerated from the scan's own JSON output rather than hand-edited.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore(gitleaks): regenerate fingerprints after the history rewrite",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T02:42:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "55cd5e4b199fe5a5959d48f88b26f868ff1ae0e9",
          "body": "Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "docs(changelog): note the 110% default UI scale in [0.4.0]",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T02:36:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3abe793f0b150ba2fffb3e67b9642928c231aa22",
          "body": "Operators were reaching for browser zoom to make the console comfortable, so\nmake that the default. The root font token goes from 16px to 17.6px, and\nTailwind's rem-based text and spacing scales follow it, so the whole console\ngrows together.\n\nScaling only the root would have been the wrong half of \n[…]\no dependency change. tsc clean,\n549/549 UI tests green, no e2e spec needed changing (they assert on roles and\ntext, not coordinates).\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(ui): default sizing now matches 110% browser zoom",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T02:36:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "769e2e4848a4081f806be53f03a4145711eaaf34",
          "body": "…n pins\n\nThe CHANGELOG's [Unreleased] section covered five of the range's thirty-one\ncommits: only one commit ever touched it, so everything authored before and\nafter that point was missing — including the largest commit in the release.\n[0.4.0] now covers the whole range under Added / Changed / Fixe\n[…]\newise marked design-only, because it is.\n\nrelease-check PASSED. go test ./... green, make lint 0 issues, helm lint clean,\nui 549/549.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "docs: release prep for 0.4.0 — changelog, roadmap, gate truth, versio…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T02:25:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5080b9076cae3b844c262631658702edf2086a76",
          "body": "…ersisted\n\npersistRunGrants snapshots a run's grants, proxy injections and SCM egress from\nthe spec. applyWorkspaceCreds mutated that same by-value spec fifty-two lines\nlater, and nothing re-read it — so a per-workspace model credential never\nreached the persisted grants at all:\n\n  - api_key: the wo\n[…]\n workspace-bound api_key grant does not feed\nit. Moving that requires reordering the identity mint, which the audit event\ndepends on.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(runs): apply a workspace's credential binding before grants are p…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T02:07:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fa2705ee00460c696026a836e27d56b7c2114ab5",
          "body": "The login sandbox shipped with no ~/.aws at all, while the setup pane auto-typed\n`aws sso login --no-browser --use-device-code`. That command needs an\nsso_start_url and sso_region to already exist, so the flow could only work if\nthe operator noticed and ran `aws configure sso` by hand in the attach \n[…]\nand, under --network none,\nproceeds to dial exactly oidc.<region>.amazonaws.com — the first host the\nnarrowed egress list pre-allows.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(bedrock): make the containerized SSO login actually completable",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T01:51:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "71c377d272ced4d44726aeb891db147f5593a54a",
          "body": "…atch\n\nThe containerized `aws sso login` flow pre-allowed four egress entries, three of\nwhich the proxy compiles to unmatchable exact hostnames:\n\n    oidc.*.amazonaws.com\n    portal.sso.*.amazonaws.com\n    device.sso.*.amazonaws.com\n\nclassifyDomain (internal/egress/proxy/policy.go) supports a LEADIN\n[…]\n command the\npane auto-types has no sso_start_url to read until the operator runs\n`aws configure sso` by hand in the attach terminal.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(bedrock): the SSO login pre-allowed hosts the proxy could never m…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T01:32:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "90b0ec1e4db7fef91f15f085c8c4d18383c13219",
          "body": "…rets\n\nA review pass over this release's range flagged 32 candidates for removal;\nindependent verification refuted nine of them as deliberate seams and confirmed\nthe rest. This applies the confirmed set, plus three real defects the pass\nsurfaced on the way.\n\nDead code and duplication:\n\n  - awsssofak\n[…]\n and flaked here; the walk is the point of the test.\n\nmake lint: 0 issues. go test: green incl. -tags docker. ui: 547/547, tsc clean.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: cut verified-dead code, and stop under-disclosing resident sec…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T01:23:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0dcedd4b3b0f07c4316341d6bd8d4407db41a053",
          "body": "…e gate\n\nCI's required build job runs make lint (.github/workflows/ci.yml:38), and four\nfunctions this release touched had crossed the .golangci.yml thresholds. All\nfour are pure refactors — no behavior change, no threshold raised, no nolint,\nno exclusion added.\n\n  - policyCmd (174 > 150 funlen): li\n[…]\nverified against a synthetic unpinned Dockerfile).\n\nmake lint: 0 issues. go test ./cmd/... ./internal/...: green, incl. -tags docker.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(lint): bring the four complexity/length regressions back under th…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T01:03:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e415b18263a0855c74e0d51323c479c58fd62b67",
          "body": "Two repo gates had drifted out of truth with the tree and were failing before\nany of this release's work landed.\n\ncheck-diagrams.sh asserts that the labels drawn in the architecture diagrams\nstill name real symbols in the files it claims own them. UpdateRunStateIf and\nStopSandbox moved to runs_lifec\n[…]\nthem back.\n\nGates: check-file-size PASS, check-diagrams PASS (9 blocks), license-headers\nPASS (616 files), tsc clean, vitest 543/543.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(ci): re-green the file-size and diagram gates",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:55:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "be52d50e4f9ad659815a6152002a62ad5758357c",
          "body": "The public repo shipped a handful of identifiers that belong to the author's\nmachine rather than to the project:\n\n  - examples/policies/sandbox-workspace.yaml pinned a real home directory as\n    the example mount source, which is both a personal-path leak and dead\n    weight on any other machine (th\n[…]\nincipal fixtures used the author's real OS username; alice is\n    the convention everywhere else in these tests.\n\nNo behavior change.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore(privacy): scrub personal paths and usernames from the tree",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:49:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1cbc6f85a14b03346a27a5bbb7b15cc10a6c1a86",
          "body": "`run list` printed 8-char ids and `run kill <that id>` then rejected them with\n\"invalid run id: invalid UUID length: 8\". The same mismatch hit `approvals list`\n→ `approve`/`deny` and `policy list` → `run --policy`, so in all three the\nobvious list → copy → act flow was broken and the only way throug\n[…]\n the three lists and that the\ncontext-only RUN column stays short. Mutation-checked: restoring short() on the\nrun ID column fails it.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(cli): print actionable ids in full so list output can be acted on",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "106d1894c4d5519319273a0ba7525e64ca2b6275",
          "body": "…y downgrade\n\nWARDYN_DOCKER_SOCK decides which daemon wardynd drives, and wardyn_pick_docker_host\nderived it into the ENVIRONMENT only. So any `docker compose up -d wardynd` run\noutside up.sh fell back to compose's /var/run/docker.sock default. On a\ndual-daemon box (Docker Desktop alongside a native\n[…]\nd RELEASING.md now records branch protection as applied\nrather than pending, leaving only the pre-v0.3.1 prerelease re-flagging open.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(setup): persist the chosen docker socket so compose can't silentl…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0d709482bc23cd8d84532f3be853fb27580f6317",
          "body": "The model step opened a Claude subscription login the moment you chose\n\"container login\", with no way to say you were a Codex user, or a Claude user\nwith an API key, or on Bedrock. The choice it silently made for you was the\nonly one it offered.\n\nRestructured around the question the operator can act\n[…]\nd talked over whatever step was being configured.\nLaunching early still works from the Launch step, and that behavior keeps its\ntest.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(setup): harness-first model step, prerequisite-ordered funnel",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d798f801e39adfee017ce0c5fcd401d8f8e5436c",
          "body": "…S env\n\nAn SSO-only deployment had no first-class Bedrock path\non the containerized stack. The three existing paths each failed it — a\nbearer key many orgs don't issue, a host ~/.aws mount that exposes every\nprofile and needs a host-side login, or static keys that expire under SSO and\nmust be re-pas\n[…]\nbe dead in compose. A\nregion alone cannot enable Bedrock (that needs a model too), so this can't\nswitch the transport on by surprise.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(bedrock): containerized AWS SSO login, and honor the standard AW…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5555cb415bcce6187352b99df9436acff264930c",
          "body": "verifyCapsEnforced reads the ContainerCreate response warnings, which are\navailable before the container is started — but the gate ran after\nContainerStart. On a host that can't enforce resource caps (cgroup v1, or a\nrootless daemon without delegation) the untrusted agent container was therefore\nsta\n[…]\ninguishes \"never launched\" from \"launched,\nthen removed\". Mutation-checked: moving the gate back after ContainerStart\nfails the test.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(runner): refuse to LAUNCH an uncapped sandbox, not merely reap one",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "afca8f00a4d87b28d8ff3954f76e5626b4f3ecae",
          "body": "…fixing the Podman false-positive\n\nThe Phase-4 cap probe trusted docker info's MemoryLimit/PidsLimit/CPUCfsQuota\nbooleans pre-flight. Live testing on rootless Podman 4.9.3 showed those booleans\nare unreliable on Podman's Docker-compat API — it reports CpuCfsQuota=false even\nthough the CPU quota actu\n[…]\nngs so\nthe gate correctly passes (no false-positive); podman probe passes.\n\nAuthor: cjohnstoniv <cjohnstoniv@users.noreply.github.com>\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(runner): make the resource-cap gate authoritative (post-create), …",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c057734e3e53819a34403c8db3145c6eb12f628d",
          "body": "…d docker-info divergence\n\nRan scripts/test-podman.sh against a live rootless Podman 4.9.3 socket (cgroup v2,\nnon-root user) — the Gap-4 acceptance scenario. Findings:\n\n- Runner-critical primitives HOLD: --internal bridge networks block off-host egress\n  (the L0 no-default-route guarantee), the Runt\n[…]\n-MODEL\nrootless/Podman note updated from speculative to the tested result.\n\nAuthor: cjohnstoniv <cjohnstoniv@users.noreply.github.com>\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "test(podman): rootless Podman probed — compatible, with one documente…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "363323dbaaf39e62828294e743fced7be8fa0436",
          "body": "…m stays default)\n\nBehind a proxy that 403s public npm, installing the agent CLI via\n'npm install -g' fails and onboarding the package into the internal mirror is\nheavy. Add an opt-in native-binary path; the npm default is unchanged for OSS.\n\n- claude-code (CLAUDE_INSTALL=native): installs the nativ\n[…]\n_INSTALL=native without a\nstaged binary fails closed with a clear message.\n\nAuthor: cjohnstoniv <cjohnstoniv@users.noreply.github.com>\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "build(agents): opt-in native-binary CLI install for corp networks (np…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "93ebb333505db0518efa6aa49ca595b738fe7b23",
          "body": "…nswer, Podman probe, ADO broker design\n\nAnswer the CI-adoption egress and rootless questions:\n\n- THREAT-MODEL: document the supported ROOTLESS model — rootless Docker/Podman is\n  supported at CC1 (the full hardened-runc floor + all tier-independent egress/\n  credential controls hold), while CC2/CC3\n[…]\nhe credential path and needs\n  a real ADO PAT/repo to end-to-end validate.\n\nAuthor: cjohnstoniv <cjohnstoniv@users.noreply.github.com>\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "docs+ci(egress): rootless model, upstream-proxy lane, JVM/Deno MITM a…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0dedad75f276a48897a28bc0623a1ad0f2303efe",
          "body": "resourcesFromSpec pins NanoCPUs/Memory/PidsLimit, but on a cgroup-v1 host under\nrootless Docker (controllers not delegated) ContainerCreate SILENTLY accepts the\nlimits and the kernel ignores them — an untrusted sandbox then runs effectively\nuncapped (a fork bomb or memory hog can take out the host).\n[…]\nve isolation\nguardrails are unchanged — this only ADDS a fail-closed gate.\n\nAuthor: cjohnstoniv <cjohnstoniv@users.noreply.github.com>\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(runner): fail closed when the host can't enforce resource caps",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a82f617b008a849fc3b1963973eeddaf2e561567",
          "body": "…ontrol plane\n\nThe compose control plane was a single-tenant singleton: fixed container names, a\nfixed control-plane network, a fixed recordings volume, and fixed host ports, with\nci-run.sh using no compose project name and a global 'down --volumes'. Two CI jobs\non one shared build host collided and\n[…]\nll sandbox-isolation properties are\nunchanged (only object NAMES changed).\n\nAuthor: cjohnstoniv <cjohnstoniv@users.noreply.github.com>\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(compose): shared-host concurrency — per-job scoping for the CI c…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4e54b9edeec05eec7831336e8bef915413c12be6",
          "body": "…O & non-Docker-Desktop engines\n\nClose the gaps an SSO-only, non-Docker-Desktop enterprise user hits on the\ncontainerized stack:\n\n- UI: surface the Bedrock credentials the backend already reads but the wizard\n  never offered — the preferred never-resident bearer (bedrock-api-key) and the\n  SSO sessi\n[…]\norrect corp/socket/Bedrock\nlines and no false positive on a plain dev box.\n\nAuthor: cjohnstoniv <cjohnstoniv@users.noreply.github.com>\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(setup): enterprise onboarding + corp-aware doctor for Bedrock/SS…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "998ded4031dc07ba38f32bd5bbbb3d3e74beadc2",
          "body": "Behind a corporate TLS-intercepting proxy and internal package mirror, the\ncontainer build path failed where the agent images already had corp support but\nthe compose images did not. Make the corp-build convention uniform:\n\n- Dockerfile.wardynd: corp-CA in the ui (bookworm) and builder (alpine) stag\n[…]\nd corp CA is confirmed merged into the\nsystem trust bundle by fingerprint.\n\nAuthor: cjohnstoniv <cjohnstoniv@users.noreply.github.com>\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "build(corp): TLS-MITM proxy + mirror support across all image builds",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "416517b04a1a85dfe955ff63c11ae02f45d67d04",
          "body": "…e 5c)\n\nComplete the workspace-as-execution-environment model in the UI:\n\n- New Run wizard: an explicit \"Agent run\" vs \"Governed command\" run type\n  (task_mode=exec for governed commands, no agent/model), and bring-your-own\n  base image promoted from Advanced into a first-class Basics field. Fixes a\n[…]\n a base image, not a mount, in the picker and review.\n\nAlso logs the full welcome/setup/run-model campaign (Stages 1-5) in CHANGELOG.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(ui): workspace/container-driven run type + cred onboarding (Stag…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "84a3075b3fb174467091a6ea329df01adcf4188d",
          "body": "Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: gofmt comment normalization under go1.26.5",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b8146a4753ccb2947a83d8039aa14170f7dcfcd4",
          "body": "…ness creds (Stage 5 backend)\n\nA workspace is now the single \"execution environment\" entity that can carry its\nown model/harness credentials, so a run inherits the model access of the\nworkspace/container it picks — instead of every cred path being global.\n\n- Container as a WorkspaceKind: a bring-you\n[…]\npin all four modes (append/fallback/managed-drop/no-op); full\ninternal/api + store + types Go tests green; migration applies on boot.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(workspace): container as execution env + per-workspace model/har…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0acd7f96c722d4ef3b2ddc11446c53799cbe17a5",
          "body": "Stage 3 — a fifth, harness-aware demo (\"The agent in the box\") alongside the four\nkeyless egress demos. It's gated on a connected model (hidden on /demos until\nllmReady) and scoped to Anthropic egress; like every demo it comes up idle and\nthe operator runs `claude` in the ATTACHED TERMINAL — so \"wat\n[…]\nlaims in\nthe original autonomous-demo copy (now fixed via the interactive rework). Full UI\nsuite 532 green; typecheck + eslint clean.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(ui): harness-aware demo + platform-first reframe (Stages 3–4)",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "03734f42ca292f3534029d5d79abc3ec69295210",
          "body": "…t skip\n\nA model/harness provider is only needed to run an agent under Wardyn's own harness\nor to enable the AI Run Composer — a plain governed run (bring-your-own-container /\ntask_mode=exec) or an interactive run you drive needs no model. So it's now a\ndeliberate, non-blocking choice, not a soft-re\n[…]\npdated to the new invariant (barrier is the only hard requirement); 148\nsetup/onboarding UI tests + full internal/api Go tests green.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(setup): make the model/harness provider optional with an explici…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "331850e9494226affded2d37e300230eb76d1d67",
          "body": "Fresh local-mode consoles now guide the operator THROUGH Getting Started before\nthe app opens, instead of letting them skip into an unconfigured console.\n\n- Welcome hero: one \"Get started\" CTA. Removed the \"Try a 2-minute demo sandbox\"\n  side-door (demos live inside the funnel) and the \"Skip for now\n[…]\nhe completion flag restores full nav +\nNew-run. Unit + e2e specs updated (147 setup/onboarding tests green; full UI suite\n527 green).\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(ui): mandatory first-run setup gate + single Get-started CTA",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ccc7cde267f0420442a5cb79c8ef10c124552f10",
          "body": "The composer (Describe your task → propose → review) is newer and less battle-\ntested than the manual wizard. Flag it so expectations match: a teal \"Beta\" Chip\non the \"Describe your task\" entry card (with a title tooltip and a one-line note\nin the card hint) and on the \"AI Run Composer\" eyebrow in the Proposed-setup\nreview. The manual \"Configure manually\" path is unmarked.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(ui): mark the AI Run Composer as Beta",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "820a01102738b49355f23284f08ebab22fc1eca9",
          "body": "…plicate sentences\n\nThe review dialog answered \"why did it decide this\" (the model's prose) before\n\"can I launch / what's blocking me\", and rendered two sentences twice.\n\n- Collapse the model's rationale (result.summary) behind a \"Why this setup\"\n  disclosure — it is the wordiest block and answers a\n[…]\nch verified to fail without its fix) and updates the e2e +\ncomponent tests for the collapsed summary. Verified visually in a browser.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(ui): declutter the composer \"Proposed setup\" review + kill two du…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c6a5c4299248af8598a7ab92240dedd3e01e3f09",
          "body": "… local directory\n\nA YAML policy that mounts ONE onboarded local directory read-write into the\nsandbox so an agent can read and modify real code, while egress stays\ndefault-deny and the Claude subscription is injected proxy-side (no credential\nin the box).\n\nDocuments the two constraints that are eas\n[…]\nst.\n\nLive-verified: the agent added a /healthz handler + a matching unit test to a\nmounted Node service; both tests pass on the host.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "docs(examples): add sandbox-workspace.yaml — governed agent on a real…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ebc23c816deb767ed035ff86080bc83db353eb24",
          "body": "… runs and compose\n\nThree defects found by a live end-to-end run of the container-mode subscription\npath (real setup-token, real governed sandboxes).\n\n1. agent-run: detect_anthropic_mode only looked for credentials under ~/.claude,\n   but a MANAGED subscription materializes its inert sentinel into\n \n[…]\noser's sandbox\nwire produces a real proposal (compose.result uploaded, sandbox torn down) and\nnow reports model access as Configured.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(subscription): make managed Claude subscription actually work for…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f31c88b6e88ccd3906200509c204a910bd4b1901",
          "body": "… + YAML policies + subscription-billed composer\n\nConsolidate Wardyn setup around containerized mode and make model-access\nsetup first-class at the CLI (interactive + headless), so container mode no\nlonger defers everything to the UI.\n\nContainer-default setup (Stage 1 of the setup rethink):\n- make s\n[…]\ne stack: subscription connect lifecycle + idempotency,\nsetup status, headless seed, keyless exec runs; build + full test suite green.\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "feat(cli/setup): container-default setup + first-class credential CLI…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-20T00:48:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e76fc57a46bba62f4e582761766cd6fbc0a804ca",
          "body": "Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "release: 0.3.1",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-18T17:36:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4579da6da8647471008d10e5326550aacd2f2bd8",
          "body": "…der the complexity gate)\n\nSigned-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "refactor: extract promoteSkipHosts (keep handlePromoteRecordEgress un…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-18T17:36:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9406541ae14bf11028bb9fb0f1fb439ddf7e4c1e",
          "body": "Signed-off-by: cjohnstoniv <cjohnstoniv@users.noreply.github.com>",
          "is_bot": false,
          "headline": "chore: scrub internal tracking markers from docs and config",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-18T17:30:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d45691df4cc7dbc069573521ab9ce7a126299fc",
          "body": "…d internal markers\n\nUntrack (kept out of the repo) maintainer-local process/design artifacts: review notes, design-tool exports, contributor-campaign results, and the design-system-sync tooling. Genericize a company name in test fixtures. Strip internal review-tracking markers and stray development\n[…]\n from code comments. Rename the fat toolchain agent image to a neutral name. No behavior change; build/test/typecheck green.\n\nHistory is intentionally not rewritten; this cleans the current tree only.",
          "is_bot": false,
          "headline": "chore: pre-open-source cleanup — remove personal/process artifacts an…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-18T17:26:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fa6eaa265a64baacb9849ede37d2ac2020240223",
          "body": "A new wardyn-proxy local route (/wardyn/gh/<org>/<repo>) reverse-proxies git-smart-HTTP to github.com: it enforces a per-repo allowlist in cleartext, mints the repo-scoped GitHub App token proxy-side (never into the sandbox), and re-originates upstream. agent-run rewrites granted github URLs to the \n[…]\nerred.\n\n- Tests: handler (Basic x-access-token auth, sandbox-cred strip, path/service/Git-Protocol preserved, single-mint cache, traversal/ungranted 403s) + wiring helpers; CI/TRY-IT/sdk docs updated.",
          "is_bot": false,
          "headline": "git-broker: repo-scoped git egress — the sandbox never dials github.com",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-18T16:21:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "628fe67192a9110bd1d99839116c6f3ffdae7cd2",
          "body": "…dual-daemon socket fix\n\n- Demos become a funnel phase before Your Work: four demos as sidebar sub-steps, each with overview + policy YAML + UI-setup steps, an inline audit panel, and a launched-checkmark. Corporate phase moved earlier with one-click skip; SCM stays in Your Work.\n\n- Harness containe\n[…]\nendText handle; denied demo curls use -sSI so the 403 is visible.\n\n- scripts/lib/common.sh derives WARDYN_DOCKER_SOCK from DOCKER_HOST (dual-daemon tier fix); ci-run.sh drops its duplicate derivation.",
          "is_bot": false,
          "headline": "Getting Started: demos in the funnel + container-login auto-capture; …",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-18T16:21:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4e25629be2c4f0611355b0d4d355cc1dc87eeb05",
          "body": "… 18 blind re-assessments), residuals; Fable-audited (two prose corrections applied)",
          "is_bot": false,
          "headline": "docs: round-4 evidence — composite 92, method (reconciliation sweep +…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T22:13:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cbe0a551f471797e3935d1b03f359868d4a665cc",
          "body": "… tabindex + arrow keys), pinned by test",
          "is_bot": false,
          "headline": "a11y: run-mode radiogroups implement the APG keyboard pattern (roving…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T22:00:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4683b83b928adf746672f2f933c7f694218bd464",
          "body": "…label uses RUN_MODE copy, CLI 401 carries a token hint, OIDC discovery bounded by bootCtx, compose.go/store.go leave the size allowlist",
          "is_bot": false,
          "headline": "fix defects the R4 blind re-judge surfaced: banned 'Background' mode …",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T21:45:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a2b65917ee05450a8e7cb01942dbba2fe2b13f85",
          "body": "…mmands in RELEASING, R4 changelog entries",
          "is_bot": false,
          "headline": "docs: branch-protection honesty in CONTRIBUTING, one-time operator co…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T21:24:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c931210dcb0559caf7f45b77679f7ae781e7b16d",
          "body": "…rridable so it passes locally and on ubuntu-latest (U064)",
          "is_bot": false,
          "headline": "ci: envbuild real-daemon integration job lands — test network env-ove…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T21:24:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9f876952d1d3a759915c98a0b855ffef236cc674",
          "body": "…al mux+auth (U079)",
          "is_bot": false,
          "headline": "api: router-level tests for harness login/paste/disconnect through re…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T21:24:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c2b407703491f36f579ac9654cb7fff1142bbc99",
          "body": "…reads AND stale doc rows fail); typed helpers on remaining parseable reads (U084 + codequal)",
          "is_bot": false,
          "headline": "env: parity guard walks cmd/+internal/ both directions (undocumented …",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T21:24:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a8a4fefb4aa37e4f5f2ff0b2c83ef8b37843a9e",
          "body": "…objects) (U076)",
          "is_bot": false,
          "headline": "gitremote: scan skips .git internals — O(repo-roots) walk, not O(git-…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T21:24:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "110d72614d701a3eccbfb26f1f442666c5e31718",
          "body": "…ence; storage posture documented honestly (U098)",
          "is_bot": false,
          "headline": "ui+docs: console token defaults to sessionStorage with opt-in persist…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T21:24:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e26a27e58ae82f45bac9055c97da55d8300c2087",
          "body": null,
          "is_bot": false,
          "headline": "api: audit spool drains back to Postgres when the store recovers (U094)",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T21:24:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a1afd69c45e83aeafefb13ed005bc6f89b4e77b",
          "body": "…o llmcred.go — pure relocation (U051)",
          "is_bot": false,
          "headline": "api: LLM-credential/subscription-mount helpers move from compose.go t…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T21:24:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15c41d19e8497fb4dfc2f0ec19426e796255b438",
          "body": "…U053); one shared finalizeRunTail for watcher+reconciler (U145); terminal lifecycle split to runs_lifecycle.go",
          "is_bot": false,
          "headline": "api: dispatchParams struct replaces the 12-arg positional signature (…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T21:24:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c31e62704c6b9b6435eb8e5c25717f8e6613265e",
          "body": "… with honest package-doc claims (U047)",
          "is_bot": false,
          "headline": "sdk+cli+ui: pagination plumbed through; SDK covers every route family…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T21:24:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f315c3f17064f3a14beda7772b79c384240aad46",
          "body": "…tion disclosed, indexes for the run-scoped audit sort (U048/U049/U070/U071)",
          "is_bot": false,
          "headline": "api/store: explicit pagination on every list + audit endpoint, trunca…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T21:24:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c2967ef6724655177d4693fb8f0ef87f3d17dfb0",
          "body": "…owlist, justified in ARCHITECTURE.md",
          "is_bot": false,
          "headline": "arch: file-size ratchet extended to ui/src with a frozen two-file all…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T20:43:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "51f2111978d1e33657cdef4494ce304da0d36fe3",
          "body": "…shared unwrap (U097)",
          "is_bot": false,
          "headline": "ui-lib: write/delete endpoints surface the server error body via the …",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T20:43:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e36cc0b9d56dc8c932d1c0a48aa47c44ac69762e",
          "body": null,
          "is_bot": false,
          "headline": "envbuild: one canonical required-tools list, drift-guarded (U063)",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T20:43:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e90cf03eef949931ec6bfbb2736503ac81fb0e00",
          "body": "…s internal/setup (U111), demo PASS criteria achievable (U082), e2e BASE_URL derivation (U108), compose-config json preview (U109), license-header pipeline single-sourced (U110)",
          "is_bot": false,
          "headline": "dx: KVM detection names the containerized fix (U085), CLI setup reuse…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T20:43:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ad5130ae510589f49fbe8d8b43fd471025a24ae",
          "body": "…078), RBAC disclosures on site-config/harness routes (U080), github_token+cloud_sts scope validation (U081), syslog write deadline (U095), capabilities TTL cache (U055)",
          "is_bot": false,
          "headline": "api/audit/orchestrator: store-error vs not-connected distinguished (U…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T20:43:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "041a89a20f3d6b6958105f5f5a988daf469198aa",
          "body": "…nning / --url / WARDYN_URL)",
          "is_bot": false,
          "headline": "cli: connection-refused errors carry recovery guidance (is wardynd ru…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T20:42:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "36067e5af9dd89fa7d5bcdaa1a621cd09aa4fada",
          "body": "…alette-class source guard extends the contrast test",
          "is_bot": false,
          "headline": "ui: mobile nav drawer below md with focus/aria handling (U121); raw-p…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T20:42:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3085beb317845197d0598e9df67b26fe0cf7649c",
          "body": "…lib parse/fail-closed specs (U073), triaged test-gap inventory, honest rollup count",
          "is_bot": false,
          "headline": "test: kill-race covers dispatch seam + teardown half (X079/X093), ui-…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T20:42:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a318cfbcec69c03b79aca1b856a95501ed3419ba",
          "body": "…ns, action SHA pins, image-pin gate; envbuild-integration make target (job held: test pins bridge net)",
          "is_bot": false,
          "headline": "supply: both x/crypto paths named, tidy-check gate, compose digest pi…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T20:42:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0c9ddf3e95493ff7cd27ac7a412624b6992c9e79",
          "body": "…d task + env-var rows verified (U061 docs-truth)",
          "is_bot": false,
          "headline": "docs: PLUGGABILITY matches code (registry seams named exactly), recor…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T20:42:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ef7eed0129b0ccc85cafc1c77f1a1a1325b9292",
          "body": "… four waves)",
          "is_bot": false,
          "headline": "docs: count the Fable validation wave (30 blind re-assessments across…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T19:08:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bff07eba07a5fdd8171109ccc66f409d2d813ae1",
          "body": "…ands)\n\nFable came back online for the final validation pass and independently re-judged\nthe four recovery lanes. It was stricter than the Opus fallback: build/release/CI\nis held at 83, not 85 — two criteria stay partial (helm's v0.5 working-deploy gap\nand the pending non-prerelease release re-flag)\n[…]\n the\nmethod working. Composite is 85.6 -> 86 (cli-ux 100 buffers it). Fable also\nconfirmed all four S3 fix commits (live-Postgres-proved migration 0022) and\naudited this doc against the scorer (SHIP).",
          "is_bot": false,
          "headline": "docs: Fable's stricter re-judge holds build/CI at 83 (composite 86 st…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T19:06:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4713ccdba9f520368cdd81bfdfa97f238f34bc35",
          "body": "The CLI now takes the run id positionally (with --run kept as a hidden deprecated\nalias); update the docs and example TASK.md files to the positional form. Closes\nthe cheap doc residual the review flagged.",
          "is_bot": false,
          "headline": "docs: sweep audit --run to the positional 'audit <id>' form",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T18:55:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eb8f37d1f1479934dbbb6efc7589c863c04749ff",
          "body": "…review note\n\nRecords the final round-3 state: the three sub-80 dimensions (architecture 79,\nbuild/CI 75, maintainability 71) all closed to 85, security and reliability\nlifted 82->85, composite 83->86. Documents the honest middle of the round — a\nfull-coverage adversarial re-assessment drove CLI-UX \n[…]\nt Fable became\nunavailable mid-round (account switch) so Opus, the sanctioned reviewer tier,\nvalidated. One raw-bound miscount was caught by an independent Opus fact-check and\ncorrected before commit.",
          "is_bot": false,
          "headline": "docs: round-3 scorecard (composite 86) + honest arc, residuals, Opus-…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T18:50:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a3a895752b56c29272bb392a421c1b20e1a6e786",
          "body": "…ob comment\n\nThe 'make = CI reality' criterion was held partial by CI steps that still called\nscripts directly (diagrams, ui typecheck/test/build, ui-e2e, license-headers) —\nroute them through their make targets (each verified byte-equivalent or an\nidempotent no-op against install steps the job already runs), so a version/flag\nbump has one home. Also move the 'web UI' header comment off the diagrams job to\nhead the actual ui job it describes.",
          "is_bot": false,
          "headline": "ci: route remaining script-direct steps through make; fix misplaced j…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T18:37:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b5f56c1fae147c0243f15da37dc14b96454fac4",
          "body": "…fix popover contrast\n\nThe blind re-review found the CHANGELOG [Unreleased] omitted user-facing fixes\nfrom the release window and the threat model's MITM section lagged the code. Add\nthe missing entries (light-theme WCAG AA, keyboard/ARIA access, revoke-on-terminal\nC002/C003, finalize-over-live-run \n[…]\n off raw text-amber-600 (~3.4:1, below AA) to the guarded\ntext-warning token. (docs/ENV.md's loud-read claim is left as the accurate blanket\nstatement — the tetragon fix makes it true for every read.)",
          "is_bot": false,
          "headline": "docs+ui: complete [Unreleased], correct MITM threat-model residuals, …",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T18:37:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "de9d4f40e53422ae98ad35dee9d7de55432544c3",
          "body": "…guard kill, dedup approvals\n\nReal reliability defects the adversarial re-review surfaced. wardyn-tetragon-ingest\nparsed WARDYN_GROUNDTRUTH_{HEARTBEAT,REFRESH,STATS} through a local silent-default\nhelper — routed through cliutil.FlagDuration so a bad value now exits 2 (the loud\ncontract docs/ENV.md \n[…]\n\nthe unique-violation as a dedup signal (pg-gated concurrency test proves one row).\nTwo stale 'KNOWN GAP' comments (harness-token recording, interactive agent-run)\nrewritten to match the shipped code.",
          "is_bot": false,
          "headline": "fix(reliability): loud env-durations, un-swallow CAS/ref errors, nil-…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T18:37:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "99843be5a07cb3a2d5da207ea9de1938f1ab6d51",
          "body": "…sitional id\n\nThree CLI-UX defects the adversarial re-review surfaced. (1) A failing command\nprinted 'wardyn: wardyn: ...' — this round's SDK migration left pkg/client's own\nerror strings prefixed 'wardyn:', which cmd/wardyn/main.go then prefixes again.\nA public SDK shouldn't hardcode the consuming \n[…]\na required --run flag\nwhile every sibling takes a positional id; it now takes 'audit <run-id>' with\n--run kept as a hidden deprecated alias. Single-prefix and positional forms are\npinned by new tests.",
          "is_bot": false,
          "headline": "fix(cli): drop doubled error prefix, fix --interactive help, audit po…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T18:37:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8bc54db35ab5cecb72d4d65c7e88082dc7c7a7b4",
          "body": "…self-registration)\n\nThe [Unreleased] section was written before this round's last commits landed, so\nit missed user/operator-facing changes: the sandbox kill switch surviving a\ncontrol-plane restart (ref->substrate persistence), the self-registering\nrunner/substrate seam, structured control-plane/proxy logs, and the docs/ENV.md\nvariable registry. Add them so CHANGELOG is accurate to HEAD (the blind\nre-assessment flagged the drift).",
          "is_bot": false,
          "headline": "docs(changelog): bring [Unreleased] up to HEAD (durable kill switch, …",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T18:10:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d95c1fcd636f299652d0e83be130aa62ab933f9",
          "body": "…e RefStore\n\nThe substrate/runner seam was the one seam that did NOT self-register: a\nhardcoded -runner switch plus a components map, while PLUGGABILITY.md claimed a\nregistry + init() self-registration story it didn't have. Add\ninternal/runner/substrate/registry.go on internal/component.Registry (mi\n[…]\newPG(pool)), activating the kill-switch durability from the\nprior commit for any multi-substrate deployment. Registry resolution is a\ncounterfactual-proven test (removing register.go fails 'have []').",
          "is_bot": false,
          "headline": "arch(runner): make the substrate seam self-register + wire the durabl…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T18:01:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e0194a77d8a77dbc73e8576f696d74ea56a7fc9d",
          "body": "…e kill switch\n\nOrchestrator.byRef was process-memory-only: after a control-plane restart with\nmore than one substrate wired, subForRef could not resolve a pre-restart ref, so\nExec/Wait/Attach/Status/StopSandbox/KillSandbox all failed 'no substrate tracked\nfor ref' — the kill switch, a security-crit\n[…]\n. The restart-recovery test is a\nmutation-proven counterfactual: disable the rehydration and the kill switch\nfails to route. Dormant until a second substrate ships (single-substrate New\nis unchanged).",
          "is_bot": false,
          "headline": "fix(orchestrator): persist ref->substrate so a restart can't break th…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T17:46:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6e789f56689e432d6fa59652985932e250b792e3",
          "body": "Nothing held the line on function/file size: no golangci config, no gate. Add\n.golangci.yml (funlen 150/100, gocyclo 30, gocognit 60, scoped lll) + a\nscripts/check-file-size.sh allowlist gate (fails on a new .go file >1000 lines,\nor an allowlisted one that grows past its frozen cap), both wired into\n[…]\n:funlen (handleSetupStatus, runComposePipeline,\nCreateSandbox), and ARCHITECTURE.md gains a 'Large files' rationale for the 6\nallowlisted 1000+ files — the 'decomposed OR justified' bar, now enforced.",
          "is_bot": false,
          "headline": "lint+refactor: funlen/gocyclo gate + decompose the 3 worst god-functions",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T17:46:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "103e91962396dd31e17f31b93bbcb8132229f41d",
          "body": "…lane\n\nThe conformance-stub matrix leg ran ./test/conformance/... untagged, but\nnone_test.go carries no build tag, so cover-check already runs it under both tag\nsets and test-race a third time — pure duplication. Remove the CI leg (keep the\nmake target for local use); conformance is now a single doc\n[…]\n pkgs, 0 races) — real-daemon tests gate on\nWARDYN_TEST_DOCKER, unset here. Note: this renames the CI check 'conformance\n(docker)' -> 'conformance'; update branch-protection required checks if pinned.",
          "is_bot": false,
          "headline": "ci: drop the redundant conformance-stub leg, add a -tags docker race …",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T17:02:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0ac68f514089155ebd11ff1f1588f66d77499ab4",
          "body": "…guard\n\ninternal/api and internal/egress/proxy were the two shipped-binary packages\nstill emitting unstructured log.Printf (11 sites), so an operator shipping to a\nstructured sink silently lost those lines — including the panic-in-reconcile and\nthe 'run may be stranded' lines, the two most worth fil\n[…]\ne stdlib \"log\" import from every file,\nand add both packages to slog_guard_test.go's slogOnlyPackages so a regression\nnow fails the build. Counterfactual: an injected blank log import fails the guard.",
          "is_bot": false,
          "headline": "log(api,proxy): convert the last 11 log.Printf to slog + ratchet the …",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T17:02:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4e65a18eba231c1a49ad87851eceb08f47457a6e",
          "body": "…king\n\nlib/api.ts was one 704-line 'api' object with 47 methods across 11 domains, and\ntypes.ts held 86 exports — a single object defeats per-route dead-code\nelimination, so every React.lazy route dragged all 47 methods into the entry\nchunk. Split api.ts into per-domain modules with named exports (a\n[…]\n code-splits 9 route screens, so this now tree-shakes — pinned\nby a new bundle-split test asserting the terminal stack stays out of the entry\nchunk. Re-pointed the vi.mock paths the split invalidated.",
          "is_bot": false,
          "headline": "refactor(ui): split the api.ts/types.ts god-modules for real tree-sha…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T16:55:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1598966d74df623cfb89125a927352eb0eb69916",
          "body": "…v0.3.0\n\n62 commits landed since v0.3.0 with no changelog entry, and RELEASING.md step 1\npresumes an [Unreleased] heading that did not exist. Add it from the real\nv0.3.0..HEAD log (run-noun consolidation + exit-code taxonomy, run --json,\napprovals list, SDK devcontainer fields, NAT64 SSRF block, lou\n[…]\ny, no internal refactors. Dropped a claim about\n--wait distinguishing a missing complete-event from exit 0: that signal was\nremoved by a later commit and no longer describes HEAD (Fable-review catch).",
          "is_bot": false,
          "headline": "docs(changelog): add [Unreleased] with the user-facing changes since …",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T16:55:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "afd8c57c0dc1e6934b3c248a556d2243559a5f82",
          "body": "CI inlined build/vet/govulncheck/staticcheck/gitleaks/licenses/helm/compose/\ndco/sbom/npm-license, pinning every tool version in two places and leaving the\nnpm license gate with no make target. Add Makefile targets for each (versions\nsingle-sourced as vars), a 'make ci' aggregate (daemon-free merge \n[…]\npts/check-ui-licenses.sh. release-check now also\nguards that CHANGELOG has an [Unreleased] section. The dco target fails closed\nif git log errors on a bad range (Fable-review catch: it was fail-open).",
          "is_bot": false,
          "headline": "build(ci): make the Makefile the single source of truth for CI gates",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T16:55:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "97a970d447cf62bc673b53adb3ac38f6ad63168b",
          "body": "…try)\n\nAdd strict non-flag cliutil.EnvBool/EnvDuration (envFatal exit 2 naming var+\nvalue on garbage; unset/empty still defaults quietly). These do NOT register a\nflag — flag.Parse() runs before these env reads (main.go:173 vs :585; proxy\n27 vs 56; git-helper has no flag phase), so FlagBool/FlagDura\n[…]\nroxy): unknown values now fail loud instead of\n  silently skipping the kill-switch.\nAdd docs/ENV.md (every WARDYN_* var read in non-test Go) + an envdoc guard test\nthat fails if a var is undocumented.",
          "is_bot": false,
          "headline": "fix(cliutil): make env-var parse errors loud, not silent (+ ENV regis…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T16:55:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3e60aefc3f89ba2f02444fb230847fe974d4da22",
          "body": "cmd/wardyn carried a second HTTP client (apiClient: its own do() and ~15\nmethods duplicating pkg/client.Client, plus a policyBody twin of PolicyRequest).\nDelete it — the CLI now uses pkg/client directly, and the missing endpoints\n(SynthesizeProfile, RecordWorkspaceTask) are added to the SDK for pari\n[…]\nerver {\"error\":...} envelope unwrap the old\ntransport provided moves into pkg/client.APIError.Error(), so a failed call\nstill prints a human message rather than raw JSON (Fable-review regression fix).",
          "is_bot": false,
          "headline": "refactor(cli): consume pkg/client SDK, drop the duplicate CLI transport",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T16:54:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1831c79be480442aa5ef7b4524501fbb4a333967",
          "body": "Maintainability 67 -> 71 after the slog/env-validation/DTO work was credited.\nComposite holds at 83. Sharpens four residuals with what the reviewers actually\nmeasured rather than what the commits claimed:\n\n- the decomposition redistributed lines without breaking up the god functions —\n  7 funcs stil\n[…]\ngress/proxy, both fully\n  unstructured and both excluded from the guard test's ratchet.\n\nGate: build+vet both tags, full suite, -race, gitleaks (no leaks), union\ncoverage 66.3% (floor 65) — all green.",
          "is_bot": false,
          "headline": "docs: final scorecard (83) + the residuals the last blind pass surfaced",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T10:55:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5df2e9316ba6e02523fcc758e4f3bdaefc73beda",
          "body": "… the run DTO\n\nCloses the four criteria shared by both maintainability lanes.\n\nSTRUCTURED LOGGING: the remaining ~70 log.Printf sites in cmd/wardynd,\ncmd/wardyn-tetragon-ingest, cmd/wardyn-proxy, internal/approval and\ninternal/runner/docker now use log/slog with typed attrs; severity marker words\n(W\n[…]\nurth server field\nwould drift silently. Single-sourced, with a structural test that fails\nautomatically on the next divergence.\n\nGate: build + vet both tags, full suite, -race, ui typecheck all green.",
          "is_bot": false,
          "headline": "maintainability: finish slog, make bad env values loud, single-source…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T10:47:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c2763ec0d57d7725123e7cb7563d8d7cfab838e6",
          "body": "…nored)\n\nThe campaign's scoreboard, verdicts and findings live in a gitignored scratch\ntree and would have died with the branch. This is the durable record: the\nscorecard, how the score actually works (score=min(raw,ceiling); coverage never\nenters it), what makes a claim count (machine-verified reso\n[…]\n'. The true measurement is 704 -> 599\n(601 at HEAD). The commit repeated an unverified figure; a blind reviewer caught\nit. The decomposition is real and provably pure code motion — the number was not.",
          "is_bot": false,
          "headline": "docs: record the July 2026 repo-health review (the evidence was gitig…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T10:31:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "50e0a1c014b7c6a5edf24a2e533584b9b75ff007",
          "body": "…nment\n\nThe from-scratch path as actually walked on a WSL2 + dual-daemon box, with the\ntwo gotchas that cost an hour every time written up front rather than buried:\n(1) this machine runs TWO docker daemons — the scripts pick the tier-capable\nnative one automatically but a human's own docker commands\n[…]\nndbox's actual runtime (runsc/kata vs runc) and an\naudit trail showing BOTH an allow and a deny — a deny-everything box proves\nnothing. Every command verified against the current Makefile/scripts/CLI.",
          "is_bot": false,
          "headline": "docs: add FRESH-START — pristine local bring-up + how to prove contai…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T10:21:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b0875718ed9bdcb4aa067be09696b14c0130ef33",
          "body": "…s pass falsified\n\nTwo follow-ups the adversarial verifiers caught in the raw-lift work itself.\n\ngitleaks: adding the second published key to knownPublicAgeKeys made the secrets\ngate go RED (leaks found: 2) — a red secrets gate on a secrets-hardening commit.\nReproduced with the exact CI command, the\n[…]\nest/reports/README.md,\nrollup.md, CONTRIBUTING.md all still said 58 / 60.3%). Corrected to the verified\nnumbers: union 66.1%, floor 65 — confirmed by running make cover-check, not by\ncopying a report.",
          "is_bot": false,
          "headline": "ci+docs: keep the secrets gate green; correct the coverage claims thi…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T10:19:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a0a0de045f9c0fd5fde6aa2d523656c68e843bbb",
          "body": "…nest coverage/docs\n\nSix criteria-level fixes from the raw-lift pass. Each was verified against\ncurrent code first and adversarially reviewed for real-vs-cosmetic.\n\nsec-secrets (FAIL -> real): the boot guard was a single string-equality check\nagainst ONE published key, while a SECOND working key sat\n[…]\nilds\n(tagless + -tags docker) rather than the tagless subset that excluded the\ncontainer-hardening driver and envbuild. The honest number moved DOWN (67.2 ->\n66.1) while the floor moved UP (58 -> 65).",
          "is_bot": false,
          "headline": "security+honesty: deny every published age key, enforce wrap-only, ho…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T10:18:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "450ad4b99cc3dec1f40aa1de7f57321a078dd627",
          "body": "…rking\n\nThe per-run JWT-SVID had a fixed 1h TTL and no refresh producer. The token is\nheld solely by the per-run PROXY sidecar (never the sandbox — runs_dispatch.go\nis explicit), baked into its config at create time, so at ~1h EVERY consumer\ndied at once: decision logs, approvals, credential mints, \n[…]\n it could read revocations=0. Now waits for both.\n\nCounterfactuals: removing the route 404s all 5 API tests; restoring the\nsnapshot-at-startup sink reproduces the bug (proxy presents the stale token).",
          "is_bot": false,
          "headline": "fix(identity): renew the per-run token so a run outliving 1h keeps wo…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T09:33:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e40993edcb5adbb3e294d621a6af1de682b35f9d",
          "body": "…ce writer\n\nEvery caller did check-then-act (read the workspace, decide, write) against an\nUNFENCED update, so a verify/record run claiming the import step between the\nread and the write was silently clobbered. C001 added an active-run guard to\nhandleFinalizeWorkspace, but a guard is only a read: it\n[…]\nthrough the compiler rather than\nletting one silently keep the unfenced path.\n\nCounterfactual: unfencing the UPDATE makes a finalize decided from a stale\nempty-slot read apply over a live run's claim.",
          "is_bot": false,
          "headline": "fix(store): fence SetWorkspaceImportState — the last unfenced workspa…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T09:18:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a096dc7880286ae867fe9ad30654b810ac36036",
          "body": "…st teardown audits\n\nCrown-confirmed HIGHs in the record/verify + dispatch paths.\n\n- launchVerifyRun/launchRecordRun created credential_grants BEFORE the\n  agent_runs row, so the FK rejected them on Postgres and every private\n  workspace run silently lost its grants. The run row comes first now.\n- h\n[…]\nree compensating StopSandbox calls swallowed the teardown error\n  and audited \"sandbox torn down\" unconditionally — the audit log claimed\n  containment that had not happened. It reports the truth now.",
          "is_bot": false,
          "headline": "fix(api): FK-ordered grants, symlink escape, request-ctx builds, hone…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T09:13:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "39c43132963994ee89dcbf3c816a136bd04fa66d",
          "body": "… tier honesty, U009 boot guard\n\nCrown-confirmed HIGHs across the sandbox + ground-truth seams.\n\n- Kill during an in-flight Exec on the exec-less (krun/CC3) path reported 202\n  while the agent container was still created afterwards — a KILLED run whose\n  workload then started. The deferred create no\n[…]\noes.\n- U009 was incomplete: the tetragon-ingest boot guard rejected the very wiring\n  U009 made the documented default, so the eBPF ground-truth stream stayed\n  down on the shipped compose deployment.",
          "is_bot": false,
          "headline": "fix(runner,groundtruth): kill/exec race, transient-probe abandonment,…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T09:13:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "39e0ff269b01c1e2b5996a75556b4105f3bf6cca",
          "body": "…harness-login token\n\nThree crown-confirmed HIGHs, one root cause each.\n\n1. MaskingWriter.Close() closed a BORROWED dst. recording.go hands it an\n   *io.PipeWriter, and io.Pipe stores only the FIRST close reason — so Close()\n   winning with EOF made buildMaskingBody's CloseWithError(cpErr) a no-op a\n[…]\nr run's capture; the false comment is gone.\n\nCounterfactuals executed for each: reverting (1) yields 204-instead-of-413 and\na swallowed error; reverting (2) dumps the live token into a persisted cast.",
          "is_bot": false,
          "headline": "security(recording): stop swallowing upload errors; never record the …",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T09:13:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8fdc6be81dcf3a3313ad4967f2be439917b1876d",
          "body": "…ress allowlist\n\nresolvePolicy returned a SHALLOW copy of the process-global cfg.DefaultPolicy,\nso every run's spec aliased the global's slice backing arrays. Two concurrent\ncreate-runs appending run-specific egress (unionAllowedDomains, SCM/workspace\nunions) then wrote the SAME spare-capacity eleme\n[…]\npose_setup.go:479 was the one place that did).\n\nCounterfactual: reverting the clone makes both new tests fail (WARNING: DATA\nRACE + cross-run domain swap). Crown-confirmed by two independent refuters.",
          "is_bot": false,
          "headline": "fix(api): clone resolved policy specs — concurrent runs shared one eg…",
          "author_name": "cjohnstoniv",
          "author_login": "cjohnstoniv",
          "committed_at": "2026-07-17T08:30:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 7,
      "commits_last_year": 348,
      "latest_release_at": "2026-07-21T03:26:00Z",
      "latest_release_tag": "v0.4.2",
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 3,
      "days_since_latest_release": 6,
      "mean_days_between_releases": 2.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/cjohnstoniv/wardyn",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/cjohnstoniv/wardyn",
          "is_deprecated": false,
          "latest_version": "v0.4.2",
          "repository_url": "https://github.com/cjohnstoniv/wardyn",
          "versions_count": 7,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-21T03:20:05Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 2,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": null,
      "open_issues_and_prs": 6
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "demos",
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": true,
      "typecheck_configs": [
        "ui/tsconfig.json"
      ],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 54725,
      "source_files_sampled": 655,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod",
        "ui/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "2.1.1",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-3jxr-9vmj-r5cp",
              "GHSA-mh99-v99m-4gvg"
            ],
            "fixed_version": "5.0.8",
            "advisory_count": 2,
            "oldest_advisory_days": 7
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "5.0.6",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-3jxr-9vmj-r5cp",
              "GHSA-mh99-v99m-4gvg"
            ],
            "fixed_version": "5.0.8",
            "advisory_count": 2,
            "oldest_advisory_days": 7
          },
          {
            "name": "postcss",
            "direct": false,
            "version": "8.5.16",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-r28c-9q8g-f849"
            ],
            "fixed_version": "8.5.18",
            "advisory_count": 1,
            "oldest_advisory_days": 3
          },
          {
            "name": "react-router",
            "direct": false,
            "version": "7.18.1",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": null,
            "advisory_ids": [
              "GHSA-qwww-vcr4-c8h2"
            ],
            "fixed_version": "8.3.0",
            "advisory_count": 1,
            "oldest_advisory_days": 3
          },
          {
            "name": "dompurify",
            "direct": false,
            "version": "3.4.11",
            "severity": "low",
            "ecosystem": "npm",
            "cvss_score": 0,
            "advisory_ids": [
              "GHSA-c2j3-45gr-mqc4"
            ],
            "fixed_version": "3.4.12",
            "advisory_count": 1,
            "oldest_advisory_days": 6
          },
          {
            "name": "github.com/go-chi/chi/v5",
            "direct": true,
            "version": "v5.2.4",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5774",
              "GO-2026-5775",
              "GO-2026-5777"
            ],
            "fixed_version": "5.3.0",
            "advisory_count": 3,
            "oldest_advisory_days": 3
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.54.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5932"
            ],
            "fixed_version": null,
            "advisory_count": 1,
            "oldest_advisory_days": 20
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "low": 1,
          "high": 4,
          "unknown": 2
        },
        "advisory_count": 11,
        "affected_count": 7,
        "assessed_count": 686,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 1
      },
      "ecosystems": [
        "go",
        "npm"
      ],
      "dependencies": [
        {
          "name": "filippo.io/age",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.2.1"
        },
        {
          "name": "github.com/Azure/azure-sdk-for-go/sdk/azidentity",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.14.0"
        },
        {
          "name": "github.com/anthropics/anthropic-sdk-go",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.56.0"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/config",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.32.25"
        },
        {
          "name": "github.com/bradleyfalzon/ghinstallation/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.19.0"
        },
        {
          "name": "github.com/coder/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.14"
        },
        {
          "name": "github.com/containerd/errdefs",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.0"
        },
        {
          "name": "github.com/coreos/go-oidc/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.20.0"
        },
        {
          "name": "github.com/go-chi/chi/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.2.4"
        },
        {
          "name": "github.com/go-jose/go-jose/v4",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v4.1.4"
        },
        {
          "name": "github.com/google/go-github/v88",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v88.0.0"
        },
        {
          "name": "github.com/google/uuid",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/jackc/pgx/v5",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v5.10.0"
        },
        {
          "name": "github.com/moby/docker-image-spec",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.3.1"
        },
        {
          "name": "github.com/moby/moby/api",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.55.0"
        },
        {
          "name": "github.com/moby/moby/client",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.5.0"
        },
        {
          "name": "github.com/moby/profiles/seccomp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.3"
        },
        {
          "name": "github.com/openai/openai-go/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.41.0"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "github.com/spiffe/go-spiffe/v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v2.6.0"
        },
        {
          "name": "golang.org/x/oauth2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.36.0"
        },
        {
          "name": "golang.org/x/term",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.45.0"
        },
        {
          "name": "gopkg.in/yaml.v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "@fontsource/inter",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.2.8"
        },
        {
          "name": "@fontsource/jetbrains-mono",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.2.8"
        },
        {
          "name": "@radix-ui/react-alert-dialog",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.1.6"
        },
        {
          "name": "@radix-ui/react-checkbox",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.1.4"
        },
        {
          "name": "@radix-ui/react-dialog",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.1.6"
        },
        {
          "name": "@radix-ui/react-dropdown-menu",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "2.1.6"
        },
        {
          "name": "@radix-ui/react-label",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "2.1.11"
        },
        {
          "name": "@radix-ui/react-popover",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.1.6"
        },
        {
          "name": "@radix-ui/react-radio-group",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.2.3"
        },
        {
          "name": "@radix-ui/react-select",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "2.1.6"
        },
        {
          "name": "@radix-ui/react-slot",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.1.2"
        },
        {
          "name": "@radix-ui/react-switch",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.1.3"
        },
        {
          "name": "@radix-ui/react-tabs",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.1.3"
        },
        {
          "name": "@xterm/addon-fit",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.11.0"
        },
        {
          "name": "@xterm/xterm",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.0.0"
        },
        {
          "name": "asciinema-player",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.8.0"
        },
        {
          "name": "class-variance-authority",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "0.7.1"
        },
        {
          "name": "clsx",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "2.1.1"
        },
        {
          "name": "cmdk",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.1.1"
        },
        {
          "name": "lucide-react",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.24.0"
        },
        {
          "name": "react",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "18.3.1"
        },
        {
          "name": "react-dom",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "18.3.1"
        },
        {
          "name": "react-router-dom",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "^7.18.1"
        },
        {
          "name": "sonner",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "2.0.3"
        },
        {
          "name": "tailwind-merge",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "3.2.0"
        },
        {
          "name": "tw-animate-css",
          "manifest": "ui/package.json",
          "ecosystem": "npm",
          "version_constraint": "1.4.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "filippo.io/age",
            "direct": true,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/anthropics/anthropic-sdk-go",
            "direct": true,
            "version": "v1.56.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/config",
            "direct": true,
            "version": "v1.32.25",
            "ecosystem": "go"
          },
          {
            "name": "github.com/azure/azure-sdk-for-go/sdk/azidentity",
            "direct": true,
            "version": "v1.14.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bradleyfalzon/ghinstallation/v2",
            "direct": true,
            "version": "v2.19.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/coder/websocket",
            "direct": true,
            "version": "v1.8.14",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/errdefs",
            "direct": true,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/coreos/go-oidc/v3",
            "direct": true,
            "version": "v3.20.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-chi/chi/v5",
            "direct": true,
            "version": "v5.2.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-jose/go-jose/v4",
            "direct": true,
            "version": "v4.1.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-github/v88",
            "direct": true,
            "version": "v88.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/uuid",
            "direct": true,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jackc/pgx/v5",
            "direct": true,
            "version": "v5.10.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/docker-image-spec",
            "direct": true,
            "version": "v1.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/moby/api",
            "direct": true,
            "version": "v1.55.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/moby/client",
            "direct": true,
            "version": "v0.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/moby/profiles/seccomp",
            "direct": true,
            "version": "v0.2.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/openai/openai-go/v3",
            "direct": true,
            "version": "v3.41.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": true,
            "version": "v1.10.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spiffe/go-spiffe/v2",
            "direct": true,
            "version": "v2.6.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/oauth2",
            "direct": true,
            "version": "v0.36.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/term",
            "direct": true,
            "version": "v0.45.0",
            "ecosystem": "go"
          },
          {
            "name": "gopkg.in/yaml.v3",
            "direct": true,
            "version": "v3.0.1",
            "ecosystem": "go"
          },
          {
            "name": "@fontsource/inter",
            "direct": true,
            "version": "5.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "@fontsource/jetbrains-mono",
            "direct": true,
            "version": "5.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-alert-dialog",
            "direct": true,
            "version": "1.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-checkbox",
            "direct": true,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-dialog",
            "direct": true,
            "version": "1.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-dropdown-menu",
            "direct": true,
            "version": "2.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-label",
            "direct": true,
            "version": "2.1.11",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-popover",
            "direct": true,
            "version": "1.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-radio-group",
            "direct": true,
            "version": "1.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-select",
            "direct": true,
            "version": "2.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-slot",
            "direct": true,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-slot",
            "direct": true,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-switch",
            "direct": true,
            "version": "1.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-tabs",
            "direct": true,
            "version": "1.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "@xterm/addon-fit",
            "direct": true,
            "version": "0.11.0",
            "ecosystem": "npm"
          },
          {
            "name": "@xterm/xterm",
            "direct": true,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "asciinema-player",
            "direct": true,
            "version": "3.16.0",
            "ecosystem": "npm"
          },
          {
            "name": "class-variance-authority",
            "direct": true,
            "version": "0.7.1",
            "ecosystem": "npm"
          },
          {
            "name": "clsx",
            "direct": true,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "cmdk",
            "direct": true,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "lucide-react",
            "direct": true,
            "version": "1.24.0",
            "ecosystem": "npm"
          },
          {
            "name": "react",
            "direct": true,
            "version": "18.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "react",
            "direct": true,
            "version": "19.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "react-dom",
            "direct": true,
            "version": "18.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "react-dom",
            "direct": true,
            "version": "19.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "react-router-dom",
            "direct": true,
            "version": "7.18.1",
            "ecosystem": "npm"
          },
          {
            "name": "sonner",
            "direct": true,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "tailwind-merge",
            "direct": true,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "tailwind-merge",
            "direct": true,
            "version": "3.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "tw-animate-css",
            "direct": true,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2",
            "direct": false,
            "version": "v1.42.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream",
            "direct": false,
            "version": "v1.7.8",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/credentials",
            "direct": false,
            "version": "v1.19.24",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/feature/ec2/imds",
            "direct": false,
            "version": "v1.18.29",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/configsources",
            "direct": false,
            "version": "v1.4.29",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/endpoints/v2",
            "direct": false,
            "version": "v2.7.29",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/v4a",
            "direct": false,
            "version": "v1.4.30",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding",
            "direct": false,
            "version": "v1.13.12",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/internal/presigned-url",
            "direct": false,
            "version": "v1.13.29",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/signin",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/sso",
            "direct": false,
            "version": "v1.31.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/ssooidc",
            "direct": false,
            "version": "v1.36.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/sts",
            "direct": false,
            "version": "v1.43.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/smithy-go",
            "direct": false,
            "version": "v1.27.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/azure/azure-sdk-for-go/sdk/azcore",
            "direct": false,
            "version": "v1.22.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/azure/azure-sdk-for-go/sdk/internal",
            "direct": false,
            "version": "v1.12.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/azuread/microsoft-authentication-library-for-go",
            "direct": false,
            "version": "v1.7.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/bahlo/generic-list-go",
            "direct": false,
            "version": "v0.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/buger/jsonparser",
            "direct": false,
            "version": "v1.1.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/cespare/xxhash/v2",
            "direct": false,
            "version": "v2.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/containerd/errdefs/pkg",
            "direct": false,
            "version": "v0.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/distribution/reference",
            "direct": false,
            "version": "v0.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/docker/go-connections",
            "direct": false,
            "version": "v0.7.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/docker/go-units",
            "direct": false,
            "version": "v0.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/felixge/httpsnoop",
            "direct": false,
            "version": "v1.0.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/logr",
            "direct": false,
            "version": "v1.4.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/go-logr/stdr",
            "direct": false,
            "version": "v1.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang-jwt/jwt/v4",
            "direct": false,
            "version": "v4.5.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/golang-jwt/jwt/v5",
            "direct": false,
            "version": "v5.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-querystring",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/invopop/jsonschema",
            "direct": false,
            "version": "v0.14.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jackc/pgpassfile",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jackc/pgservicefile",
            "direct": false,
            "version": "v0.0.0-20240606120523-5a60cdf6a761",
            "ecosystem": "go"
          },
          {
            "name": "github.com/jackc/puddle/v2",
            "direct": false,
            "version": "v2.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/kylelemons/godebug",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/microsoft/go-winio",
            "direct": false,
            "version": "v0.6.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/opencontainers/go-digest",
            "direct": false,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/opencontainers/image-spec",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/opencontainers/runtime-spec",
            "direct": false,
            "version": "v1.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pb33f/ordered-map/v2",
            "direct": false,
            "version": "v2.3.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/pkg/browser",
            "direct": false,
            "version": "v0.0.0-20240102092130-5ac0b6a4141c",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": false,
            "version": "v1.0.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/standard-webhooks/standard-webhooks/libraries",
            "direct": false,
            "version": "v0.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tidwall/gjson",
            "direct": false,
            "version": "v1.18.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tidwall/match",
            "direct": false,
            "version": "v1.1.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tidwall/pretty",
            "direct": false,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/tidwall/sjson",
            "direct": false,
            "version": "v1.2.5",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/auto/sdk",
            "direct": false,
            "version": "v1.2.1",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp",
            "direct": false,
            "version": "v0.69.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/metric",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.opentelemetry.io/otel/trace",
            "direct": false,
            "version": "v1.44.0",
            "ecosystem": "go"
          },
          {
            "name": "go.yaml.in/yaml/v4",
            "direct": false,
            "version": "v4.0.0-rc.2",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/crypto",
            "direct": false,
            "version": "v0.54.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/net",
            "direct": false,
            "version": "v0.56.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": false,
            "version": "v0.22.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": false,
            "version": "v0.47.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.40.0",
            "ecosystem": "go"
          },
          {
            "name": "@adobe/css-tools",
            "direct": false,
            "version": "4.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "@ampproject/remapping",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@antfu/install-pkg",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@asamuzakjp/css-color",
            "direct": false,
            "version": "5.1.11",
            "ecosystem": "npm"
          },
          {
            "name": "@asamuzakjp/dom-selector",
            "direct": false,
            "version": "7.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@asamuzakjp/generational-cache",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@asamuzakjp/nwsapi",
            "direct": false,
            "version": "2.3.9",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/code-frame",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/compat-data",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/core",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/generator",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-compilation-targets",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-globals",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-module-imports",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-module-transforms",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-plugin-utils",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-string-parser",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-identifier",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-option",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helpers",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/parser",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-transform-react-jsx-self",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-transform-react-jsx-source",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/runtime",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/template",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/traverse",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/types",
            "direct": false,
            "version": "7.29.7",
            "ecosystem": "npm"
          },
          {
            "name": "@bcoe/v8-coverage",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@braintree/sanitize-url",
            "direct": false,
            "version": "7.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@bramus/specificity",
            "direct": false,
            "version": "2.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "@chevrotain/types",
            "direct": false,
            "version": "11.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/color-helpers",
            "direct": false,
            "version": "6.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-calc",
            "direct": false,
            "version": "3.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-color-parser",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-parser-algorithms",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-syntax-patches-for-csstree",
            "direct": false,
            "version": "1.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-tokenizer",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/aix-ppc64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-x64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-arm64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-x64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-arm64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-x64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ia32",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-loong64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-mips64el",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ppc64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-riscv64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-s390x",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-x64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-arm64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-x64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-arm64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-x64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openharmony-arm64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/sunos-x64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-arm64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-ia32",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-x64",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "@exodus/bytes",
            "direct": false,
            "version": "1.15.1",
            "ecosystem": "npm"
          },
          {
            "name": "@floating-ui/core",
            "direct": false,
            "version": "1.7.5",
            "ecosystem": "npm"
          },
          {
            "name": "@floating-ui/dom",
            "direct": false,
            "version": "1.7.6",
            "ecosystem": "npm"
          },
          {
            "name": "@floating-ui/react",
            "direct": false,
            "version": "0.26.28",
            "ecosystem": "npm"
          },
          {
            "name": "@floating-ui/react",
            "direct": false,
            "version": "0.27.19",
            "ecosystem": "npm"
          },
          {
            "name": "@floating-ui/react-dom",
            "direct": false,
            "version": "2.1.8",
            "ecosystem": "npm"
          },
          {
            "name": "@floating-ui/utils",
            "direct": false,
            "version": "0.2.11",
            "ecosystem": "npm"
          },
          {
            "name": "@fortawesome/fontawesome-free",
            "direct": false,
            "version": "7.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@headlessui/react",
            "direct": false,
            "version": "2.2.10",
            "ecosystem": "npm"
          },
          {
            "name": "@headlessui/tailwindcss",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "@iconify/types",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@iconify/utils",
            "direct": false,
            "version": "3.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/ansi",
            "direct": false,
            "version": "2.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/confirm",
            "direct": false,
            "version": "6.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/core",
            "direct": false,
            "version": "11.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/figures",
            "direct": false,
            "version": "2.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "@inquirer/type",
            "direct": false,
            "version": "4.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "@internationalized/date",
            "direct": false,
            "version": "3.12.2",
            "ecosystem": "npm"
          },
          {
            "name": "@internationalized/number",
            "direct": false,
            "version": "3.6.7",
            "ecosystem": "npm"
          },
          {
            "name": "@internationalized/string",
            "direct": false,
            "version": "3.2.9",
            "ecosystem": "npm"
          },
          {
            "name": "@isaacs/cliui",
            "direct": false,
            "version": "8.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@istanbuljs/schema",
            "direct": false,
            "version": "0.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/gen-mapping",
            "direct": false,
            "version": "0.3.13",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/remapping",
            "direct": false,
            "version": "2.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/resolve-uri",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/sourcemap-codec",
            "direct": false,
            "version": "1.5.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/trace-mapping",
            "direct": false,
            "version": "0.3.31",
            "ecosystem": "npm"
          },
          {
            "name": "@mermaid-js/layout-elk",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "@mermaid-js/layout-tidy-tree",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "@mermaid-js/mermaid-cli",
            "direct": false,
            "version": "11.16.0",
            "ecosystem": "npm"
          },
          {
            "name": "@mermaid-js/mermaid-zenuml",
            "direct": false,
            "version": "0.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "@mermaid-js/parser",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@mswjs/interceptors",
            "direct": false,
            "version": "0.41.9",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas",
            "direct": false,
            "version": "0.1.100",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-android-arm64",
            "direct": false,
            "version": "0.1.100",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-darwin-arm64",
            "direct": false,
            "version": "0.1.100",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-darwin-x64",
            "direct": false,
            "version": "0.1.100",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-linux-arm-gnueabihf",
            "direct": false,
            "version": "0.1.100",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-linux-arm64-gnu",
            "direct": false,
            "version": "0.1.100",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-linux-arm64-musl",
            "direct": false,
            "version": "0.1.100",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-linux-riscv64-gnu",
            "direct": false,
            "version": "0.1.100",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-linux-x64-gnu",
            "direct": false,
            "version": "0.1.100",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-linux-x64-musl",
            "direct": false,
            "version": "0.1.100",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-win32-arm64-msvc",
            "direct": false,
            "version": "0.1.100",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/canvas-win32-x64-msvc",
            "direct": false,
            "version": "0.1.100",
            "ecosystem": "npm"
          },
          {
            "name": "@open-draft/deferred-promise",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@open-draft/deferred-promise",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@open-draft/logger",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@open-draft/until",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@pkgjs/parseargs",
            "direct": false,
            "version": "0.11.0",
            "ecosystem": "npm"
          },
          {
            "name": "@playwright/test",
            "direct": false,
            "version": "1.61.1",
            "ecosystem": "npm"
          },
          {
            "name": "@puppeteer/browsers",
            "direct": false,
            "version": "3.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/number",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/primitive",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-arrow",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-collection",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-compose-refs",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-compose-refs",
            "direct": false,
            "version": "1.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-context",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-direction",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-dismissable-layer",
            "direct": false,
            "version": "1.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-focus-guards",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-focus-scope",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-id",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-id",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-menu",
            "direct": false,
            "version": "2.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-popper",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-portal",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-presence",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-primitive",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-primitive",
            "direct": false,
            "version": "2.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-primitive",
            "direct": false,
            "version": "2.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-roving-focus",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-use-callback-ref",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-use-controllable-state",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-use-escape-keydown",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-use-layout-effect",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-use-layout-effect",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-use-previous",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-use-rect",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-use-size",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/react-visually-hidden",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@radix-ui/rect",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@react-aria/focus",
            "direct": false,
            "version": "3.22.1",
            "ecosystem": "npm"
          },
          {
            "name": "@react-aria/interactions",
            "direct": false,
            "version": "3.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@react-types/shared",
            "direct": false,
            "version": "3.36.0",
            "ecosystem": "npm"
          },
          {
            "name": "@rolldown/pluginutils",
            "direct": false,
            "version": "1.0.0-beta.27",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-android-arm-eabi",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-android-arm64",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-darwin-arm64",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-darwin-x64",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-freebsd-arm64",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-freebsd-x64",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-arm-gnueabihf",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-arm-musleabihf",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-arm64-gnu",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-arm64-musl",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-loong64-gnu",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-loong64-musl",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-ppc64-gnu",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-ppc64-musl",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-riscv64-gnu",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-riscv64-musl",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-s390x-gnu",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-x64-gnu",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-linux-x64-musl",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-openbsd-x64",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-openharmony-arm64",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-win32-arm64-msvc",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-win32-ia32-msvc",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-win32-x64-gnu",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@rollup/rollup-win32-x64-msvc",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "@solid-primitives/refs",
            "direct": false,
            "version": "1.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "@solid-primitives/transition-group",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@solid-primitives/utils",
            "direct": false,
            "version": "6.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "@swc/helpers",
            "direct": false,
            "version": "0.5.23",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/node",
            "direct": false,
            "version": "4.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/oxide",
            "direct": false,
            "version": "4.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/oxide-android-arm64",
            "direct": false,
            "version": "4.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/oxide-darwin-arm64",
            "direct": false,
            "version": "4.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/oxide-darwin-x64",
            "direct": false,
            "version": "4.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/oxide-freebsd-x64",
            "direct": false,
            "version": "4.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/oxide-linux-arm-gnueabihf",
            "direct": false,
            "version": "4.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/oxide-linux-arm64-gnu",
            "direct": false,
            "version": "4.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/oxide-linux-arm64-musl",
            "direct": false,
            "version": "4.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/oxide-linux-x64-gnu",
            "direct": false,
            "version": "4.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/oxide-linux-x64-musl",
            "direct": false,
            "version": "4.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/oxide-wasm32-wasi",
            "direct": false,
            "version": "4.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/oxide-win32-arm64-msvc",
            "direct": false,
            "version": "4.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/oxide-win32-x64-msvc",
            "direct": false,
            "version": "4.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@tailwindcss/vite",
            "direct": false,
            "version": "4.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@tanstack/react-virtual",
            "direct": false,
            "version": "3.14.5",
            "ecosystem": "npm"
          },
          {
            "name": "@tanstack/virtual-core",
            "direct": false,
            "version": "3.17.3",
            "ecosystem": "npm"
          },
          {
            "name": "@testing-library/dom",
            "direct": false,
            "version": "10.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "@testing-library/jest-dom",
            "direct": false,
            "version": "6.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "@testing-library/react",
            "direct": false,
            "version": "16.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "@testing-library/user-event",
            "direct": false,
            "version": "14.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/aria-query",
            "direct": false,
            "version": "5.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__core",
            "direct": false,
            "version": "7.20.5",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__generator",
            "direct": false,
            "version": "7.27.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__template",
            "direct": false,
            "version": "7.4.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__traverse",
            "direct": false,
            "version": "7.28.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/chai",
            "direct": false,
            "version": "5.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3",
            "direct": false,
            "version": "7.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-array",
            "direct": false,
            "version": "3.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-axis",
            "direct": false,
            "version": "3.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-brush",
            "direct": false,
            "version": "3.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-chord",
            "direct": false,
            "version": "3.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-color",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-contour",
            "direct": false,
            "version": "3.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-delaunay",
            "direct": false,
            "version": "6.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-dispatch",
            "direct": false,
            "version": "3.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-drag",
            "direct": false,
            "version": "3.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-dsv",
            "direct": false,
            "version": "3.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-ease",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-fetch",
            "direct": false,
            "version": "3.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-force",
            "direct": false,
            "version": "3.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-format",
            "direct": false,
            "version": "3.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-geo",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-hierarchy",
            "direct": false,
            "version": "3.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-interpolate",
            "direct": false,
            "version": "3.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-path",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-polygon",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-quadtree",
            "direct": false,
            "version": "3.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-random",
            "direct": false,
            "version": "3.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-scale",
            "direct": false,
            "version": "4.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-scale-chromatic",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-selection",
            "direct": false,
            "version": "3.0.11",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-shape",
            "direct": false,
            "version": "3.1.8",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-time",
            "direct": false,
            "version": "3.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-time-format",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-timer",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-transition",
            "direct": false,
            "version": "3.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "@types/d3-zoom",
            "direct": false,
            "version": "3.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "@types/deep-eql",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@types/estree",
            "direct": false,
            "version": "1.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "@types/geojson",
            "direct": false,
            "version": "7946.0.16",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "22.20.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/prop-types",
            "direct": false,
            "version": "15.7.15",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react",
            "direct": false,
            "version": "18.3.12",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react-dom",
            "direct": false,
            "version": "18.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/set-cookie-parser",
            "direct": false,
            "version": "2.4.10",
            "ecosystem": "npm"
          },
          {
            "name": "@types/statuses",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/trusted-types",
            "direct": false,
            "version": "2.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "@upsetjs/venn.js",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "@vitejs/plugin-react",
            "direct": false,
            "version": "4.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/coverage-v8",
            "direct": false,
            "version": "3.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/expect",
            "direct": false,
            "version": "3.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/mocker",
            "direct": false,
            "version": "3.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/pretty-format",
            "direct": false,
            "version": "3.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/runner",
            "direct": false,
            "version": "3.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/snapshot",
            "direct": false,
            "version": "3.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/spy",
            "direct": false,
            "version": "3.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "@vitest/utils",
            "direct": false,
            "version": "3.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "@zenuml/core",
            "direct": false,
            "version": "3.50.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "6.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "6.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "antlr4",
            "direct": false,
            "version": "4.11.0",
            "ecosystem": "npm"
          },
          {
            "name": "aria-hidden",
            "direct": false,
            "version": "1.2.6",
            "ecosystem": "npm"
          },
          {
            "name": "aria-query",
            "direct": false,
            "version": "5.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "aria-query",
            "direct": false,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "assertion-error",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ast-v8-to-istanbul",
            "direct": false,
            "version": "0.3.12",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "baseline-browser-mapping",
            "direct": false,
            "version": "2.10.40",
            "ecosystem": "npm"
          },
          {
            "name": "bidi-js",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "5.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "browserslist",
            "direct": false,
            "version": "4.28.4",
            "ecosystem": "npm"
          },
          {
            "name": "cac",
            "direct": false,
            "version": "6.7.14",
            "ecosystem": "npm"
          },
          {
            "name": "caniuse-lite",
            "direct": false,
            "version": "1.0.30001799",
            "ecosystem": "npm"
          },
          {
            "name": "chai",
            "direct": false,
            "version": "5.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": false,
            "version": "5.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "check-error",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "chromium-bidi",
            "direct": false,
            "version": "16.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "cli-width",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "cliui",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "cliui",
            "direct": false,
            "version": "9.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "color-convert",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "color-name",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "color-name",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "color-string",
            "direct": false,
            "version": "2.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "commander",
            "direct": false,
            "version": "13.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "commander",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "commander",
            "direct": false,
            "version": "8.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "convert-source-map",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "cookie",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "cose-base",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "cose-base",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "css-tree",
            "direct": false,
            "version": "3.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "css.escape",
            "direct": false,
            "version": "1.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "csstype",
            "direct": false,
            "version": "3.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "cytoscape",
            "direct": false,
            "version": "3.34.0",
            "ecosystem": "npm"
          },
          {
            "name": "cytoscape-cose-bilkent",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "cytoscape-fcose",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "d3",
            "direct": false,
            "version": "7.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "d3-array",
            "direct": false,
            "version": "2.12.1",
            "ecosystem": "npm"
          },
          {
            "name": "d3-array",
            "direct": false,
            "version": "3.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "d3-axis",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "d3-brush",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "d3-chord",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "d3-color",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "d3-contour",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "d3-delaunay",
            "direct": false,
            "version": "6.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "d3-dispatch",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "d3-drag",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "d3-dsv",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "d3-ease",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "d3-fetch",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "d3-force",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "d3-format",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "d3-geo",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "d3-hierarchy",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "d3-interpolate",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "d3-path",
            "direct": false,
            "version": "1.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "d3-path",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "d3-polygon",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "d3-quadtree",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "d3-random",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "d3-sankey",
            "direct": false,
            "version": "0.12.3",
            "ecosystem": "npm"
          },
          {
            "name": "d3-scale",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "d3-scale-chromatic",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "d3-selection",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "d3-shape",
            "direct": false,
            "version": "1.3.7",
            "ecosystem": "npm"
          },
          {
            "name": "d3-shape",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "d3-time",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "d3-time-format",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "d3-timer",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "d3-transition",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "d3-zoom",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "dagre-d3-es",
            "direct": false,
            "version": "7.0.14",
            "ecosystem": "npm"
          },
          {
            "name": "data-urls",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "dayjs",
            "direct": false,
            "version": "1.11.21",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "decimal.js",
            "direct": false,
            "version": "10.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "deep-eql",
            "direct": false,
            "version": "5.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "delaunator",
            "direct": false,
            "version": "5.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "dequal",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "detect-libc",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "detect-node-es",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "devtools-protocol",
            "direct": false,
            "version": "0.0.1638949",
            "ecosystem": "npm"
          },
          {
            "name": "dom-accessibility-api",
            "direct": false,
            "version": "0.5.16",
            "ecosystem": "npm"
          },
          {
            "name": "dom-accessibility-api",
            "direct": false,
            "version": "0.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "dompurify",
            "direct": false,
            "version": "3.4.11",
            "ecosystem": "npm"
          },
          {
            "name": "eastasianwidth",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "electron-to-chromium",
            "direct": false,
            "version": "1.5.380",
            "ecosystem": "npm"
          },
          {
            "name": "elkjs",
            "direct": false,
            "version": "0.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "10.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "9.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "enhanced-resolve",
            "direct": false,
            "version": "5.21.6",
            "ecosystem": "npm"
          },
          {
            "name": "entities",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-module-lexer",
            "direct": false,
            "version": "1.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-toolkit",
            "direct": false,
            "version": "1.49.0",
            "ecosystem": "npm"
          },
          {
            "name": "esbuild",
            "direct": false,
            "version": "0.25.12",
            "ecosystem": "npm"
          },
          {
            "name": "escalade",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "estree-walker",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "expect-type",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-string-truncated-width",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-string-width",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-wrap-ansi",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "fdir",
            "direct": false,
            "version": "6.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "foreground-child",
            "direct": false,
            "version": "3.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "gensync",
            "direct": false,
            "version": "1.0.0-beta.2",
            "ecosystem": "npm"
          },
          {
            "name": "get-caller-file",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "get-east-asian-width",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-nonce",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "glob",
            "direct": false,
            "version": "10.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "graceful-fs",
            "direct": false,
            "version": "4.2.11",
            "ecosystem": "npm"
          },
          {
            "name": "graphql",
            "direct": false,
            "version": "16.14.2",
            "ecosystem": "npm"
          },
          {
            "name": "hachure-fill",
            "direct": false,
            "version": "0.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "headers-polyfill",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "highlight.js",
            "direct": false,
            "version": "11.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "html-encoding-sniffer",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "html-escaper",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "html-to-image",
            "direct": false,
            "version": "1.11.13",
            "ecosystem": "npm"
          },
          {
            "name": "iconv-lite",
            "direct": false,
            "version": "0.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "import-meta-resolve",
            "direct": false,
            "version": "4.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "indent-string",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "internmap",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "internmap",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-fullwidth-code-point",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-node-process",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-potential-custom-element-name",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-coverage",
            "direct": false,
            "version": "3.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-report",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-source-maps",
            "direct": false,
            "version": "5.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-reports",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "jackspeak",
            "direct": false,
            "version": "3.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "jiti",
            "direct": false,
            "version": "2.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jotai",
            "direct": false,
            "version": "2.20.1",
            "ecosystem": "npm"
          },
          {
            "name": "js-tokens",
            "direct": false,
            "version": "10.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-tokens",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-tokens",
            "direct": false,
            "version": "9.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "jsdom",
            "direct": false,
            "version": "29.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "jsesc",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "json5",
            "direct": false,
            "version": "2.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "katex",
            "direct": false,
            "version": "0.16.47",
            "ecosystem": "npm"
          },
          {
            "name": "khroma",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "layout-base",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "layout-base",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-android-arm64",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-darwin-arm64",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-darwin-x64",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-freebsd-x64",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-arm-gnueabihf",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-arm64-gnu",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-arm64-musl",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-x64-gnu",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-linux-x64-musl",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-win32-arm64-msvc",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lightningcss-win32-x64-msvc",
            "direct": false,
            "version": "1.32.0",
            "ecosystem": "npm"
          },
          {
            "name": "lilconfig",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "lodash-es",
            "direct": false,
            "version": "4.18.1",
            "ecosystem": "npm"
          },
          {
            "name": "loose-envify",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "loupe",
            "direct": false,
            "version": "3.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "10.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "11.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "lz-string",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "magic-string",
            "direct": false,
            "version": "0.30.21",
            "ecosystem": "npm"
          },
          {
            "name": "magicast",
            "direct": false,
            "version": "0.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "make-dir",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "marked",
            "direct": false,
            "version": "16.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "marked",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "mdn-data",
            "direct": false,
            "version": "2.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "mermaid",
            "direct": false,
            "version": "11.16.0",
            "ecosystem": "npm"
          },
          {
            "name": "min-indent",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "10.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "9.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "minipass",
            "direct": false,
            "version": "7.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "mitt",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "modern-tar",
            "direct": false,
            "version": "0.7.6",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "msw",
            "direct": false,
            "version": "2.14.6",
            "ecosystem": "npm"
          },
          {
            "name": "mute-stream",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "nanoid",
            "direct": false,
            "version": "3.3.15",
            "ecosystem": "npm"
          },
          {
            "name": "node-releases",
            "direct": false,
            "version": "2.0.50",
            "ecosystem": "npm"
          },
          {
            "name": "outvariant",
            "direct": false,
            "version": "1.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "p-limit",
            "direct": false,
            "version": "6.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "package-json-from-dist",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "package-manager-detector",
            "direct": false,
            "version": "1.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "parse5",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-data-parser",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-scurry",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-to-regexp",
            "direct": false,
            "version": "6.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "pathe",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "pathval",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "playwright",
            "direct": false,
            "version": "1.61.1",
            "ecosystem": "npm"
          },
          {
            "name": "playwright-core",
            "direct": false,
            "version": "1.61.1",
            "ecosystem": "npm"
          },
          {
            "name": "points-on-curve",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "points-on-path",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "postcss",
            "direct": false,
            "version": "8.5.16",
            "ecosystem": "npm"
          },
          {
            "name": "pretty-format",
            "direct": false,
            "version": "27.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "punycode",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "puppeteer",
            "direct": false,
            "version": "25.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "puppeteer-core",
            "direct": false,
            "version": "25.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "react-aria",
            "direct": false,
            "version": "3.50.0",
            "ecosystem": "npm"
          },
          {
            "name": "react-is",
            "direct": false,
            "version": "17.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "react-refresh",
            "direct": false,
            "version": "0.17.0",
            "ecosystem": "npm"
          },
          {
            "name": "react-remove-scroll",
            "direct": false,
            "version": "2.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "react-remove-scroll-bar",
            "direct": false,
            "version": "2.3.8",
            "ecosystem": "npm"
          },
          {
            "name": "react-router",
            "direct": false,
            "version": "7.18.1",
            "ecosystem": "npm"
          },
          {
            "name": "react-stately",
            "direct": false,
            "version": "3.48.0",
            "ecosystem": "npm"
          },
          {
            "name": "react-style-singleton",
            "direct": false,
            "version": "2.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "redent",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "require-directory",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "require-from-string",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "rettime",
            "direct": false,
            "version": "0.11.11",
            "ecosystem": "npm"
          },
          {
            "name": "robust-predicates",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "rollup",
            "direct": false,
            "version": "4.62.2",
            "ecosystem": "npm"
          },
          {
            "name": "roughjs",
            "direct": false,
            "version": "4.6.6",
            "ecosystem": "npm"
          },
          {
            "name": "rw",
            "direct": false,
            "version": "1.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "safer-buffer",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "saxes",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "scheduler",
            "direct": false,
            "version": "0.23.2",
            "ecosystem": "npm"
          },
          {
            "name": "scheduler",
            "direct": false,
            "version": "0.27.0",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "6.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.8.5",
            "ecosystem": "npm"
          },
          {
            "name": "seroval",
            "direct": false,
            "version": "1.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "seroval-plugins",
            "direct": false,
            "version": "1.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "set-cookie-parser",
            "direct": false,
            "version": "2.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "set-cookie-parser",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-command",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-regex",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "siginfo",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "signal-exit",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "solid-js",
            "direct": false,
            "version": "1.9.13",
            "ecosystem": "npm"
          },
          {
            "name": "solid-transition-group",
            "direct": false,
            "version": "0.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "source-map-js",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "stackback",
            "direct": false,
            "version": "0.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "statuses",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "std-env",
            "direct": false,
            "version": "3.10.0",
            "ecosystem": "npm"
          },
          {
            "name": "strict-event-emitter",
            "direct": false,
            "version": "0.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "4.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-indent",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-literal",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "stylis",
            "direct": false,
            "version": "4.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "symbol-tree",
            "direct": false,
            "version": "3.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "tabbable",
            "direct": false,
            "version": "6.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "tagged-tag",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "tailwindcss",
            "direct": false,
            "version": "4.1.12",
            "ecosystem": "npm"
          },
          {
            "name": "tailwindcss",
            "direct": false,
            "version": "4.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "tapable",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "test-exclude",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "tinybench",
            "direct": false,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinyexec",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "tinyexec",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "tinyglobby",
            "direct": false,
            "version": "0.2.17",
            "ecosystem": "npm"
          },
          {
            "name": "tinypool",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "tinyrainbow",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "tinyspy",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "tldts",
            "direct": false,
            "version": "7.4.5",
            "ecosystem": "npm"
          },
          {
            "name": "tldts-core",
            "direct": false,
            "version": "7.4.5",
            "ecosystem": "npm"
          },
          {
            "name": "tough-cookie",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "tr46",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "ts-dedent",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "tslib",
            "direct": false,
            "version": "2.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "type-fest",
            "direct": false,
            "version": "5.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "typed-query-selector",
            "direct": false,
            "version": "2.12.2",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "5.9.3",
            "ecosystem": "npm"
          },
          {
            "name": "undici",
            "direct": false,
            "version": "7.28.0",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "6.21.0",
            "ecosystem": "npm"
          },
          {
            "name": "until-async",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "update-browserslist-db",
            "direct": false,
            "version": "1.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "use-callback-ref",
            "direct": false,
            "version": "1.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "use-sidecar",
            "direct": false,
            "version": "1.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "use-sync-external-store",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "uuid",
            "direct": false,
            "version": "14.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "vite",
            "direct": false,
            "version": "6.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "vite-node",
            "direct": false,
            "version": "3.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "vitest",
            "direct": false,
            "version": "3.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "w3c-xmlserializer",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "webdriver-bidi-protocol",
            "direct": false,
            "version": "0.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "webidl-conversions",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "whatwg-mimetype",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "whatwg-url",
            "direct": false,
            "version": "16.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "why-is-node-running",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "8.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "9.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "ws",
            "direct": false,
            "version": "8.21.0",
            "ecosystem": "npm"
          },
          {
            "name": "xml-name-validator",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "xmlchars",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "y18n",
            "direct": false,
            "version": "5.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "yallist",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "yargs",
            "direct": false,
            "version": "17.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "yargs",
            "direct": false,
            "version": "18.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "yargs-parser",
            "direct": false,
            "version": "21.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "yargs-parser",
            "direct": false,
            "version": "22.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "yocto-queue",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "zod",
            "direct": false,
            "version": "3.25.76",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 686,
        "direct_count": 53,
        "indirect_count": 633
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 6,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 37
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "cjohnstoniv",
          "commits": 348,
          "avatar_url": "https://avatars.githubusercontent.com/u/1009163?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "nightly.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum",
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 7,
            "reason": "dependency not pinned by hash detected -- score normalized to 7",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 4,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 1,
            "reason": "9 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "61edf791031d627428b2c6cbc2c8e0f98f54d5f8",
        "ran_at": "2026-07-27T22:43:14Z",
        "aggregate_score": 5.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-27T10:52:15Z",
      "oldest_open_prs": [
        {
          "number": 38,
          "created_at": "2026-07-22T03:24:40Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 39,
          "created_at": "2026-07-22T03:24:52Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 40,
          "created_at": "2026-07-22T03:26:08Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 41,
          "created_at": "2026-07-22T03:28:24Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 42,
          "created_at": "2026-07-22T03:29:16Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 43,
          "created_at": "2026-07-22T03:29:55Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "FAILURE",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/cjohnstoniv/wardyn",
    "host": "github.com",
    "name": "wardyn",
    "owner": "cjohnstoniv"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 58,
      "inputs": {
        "security": 59,
        "vitality": 74,
        "community": 43,
        "governance": 34,
        "engineering": 82
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 74,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 56,
            "inputs": {
              "commits_last_year": 348,
              "human_commit_share": 1,
              "days_since_last_push": 5,
              "active_weeks_last_year": 3
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "3/52 weeks with commits",
                "points": 2.1,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "348 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 348
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 7,
              "latest_release_tag": "v0.4.2",
              "releases_from_tags": false,
              "days_since_latest_release": 6,
              "mean_days_between_releases": 2.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "7 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~2.2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 2.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 43,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 2,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "2 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 34,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 37
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "0/37 decided PRs merged",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 0,
                      "decided": 37
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 41,
            "inputs": {
              "followers": 2,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "cjohnstoniv",
              "public_repos": 9,
              "account_age_days": 5447
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "2 followers of cjohnstoniv",
                "points": 3.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 2,
                      "login": "cjohnstoniv"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "9 public repos, account ~14 yr old",
                "points": 19.3,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 9
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 14
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/cjohnstoniv/wardyn"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "7 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 82,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 80,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "topics": [
                "ai-agents",
                "egress-control",
                "golang",
                "gvisor",
                "llm",
                "sandbox",
                "security",
                "supply-chain"
              ],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "8 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 8
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 59,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, CI-Tests, Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "ci_tests",
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 51,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 14,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 4,
              "scorecard_aggregate": 5.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 7",
                "points": 3.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "9 existing vulnerabilities detected",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 686 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 686
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 89,
            "inputs": {
              "source": "osv",
              "advisories": 11,
              "affected_packages": 7,
              "assessed_packages": 686,
              "unassessed_packages": 0,
              "affected_by_severity": "high 4, low 1, unknown 2",
              "direct_affected_packages": 1
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "1 affected: github.com/go-chi/chi/v5 v5.2.4 (unknown)",
                "points": 26.6,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 1,
                      "packages": "github.com/go-chi/chi/v5 v5.2.4 (unknown)"
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 686,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 67,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.95,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "95 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 95,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum",
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": true,
              "has_linter_config": true,
              "typecheck_configs": [
                "ui/tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "ui/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "ui/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "devcontainer, Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "devcontainer, Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "dependency automation configured, none observed in the sampled commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "dependency_bot_config_only",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 7",
                "points": 7,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 54725,
              "source_files_sampled": 655,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/655 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 655,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "demos",
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "demos, examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "demos, examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T22:43:18.098593Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/c/cjohnstoniv/wardyn.svg",
  "full_name": "cjohnstoniv/wardyn",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计Go.