公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-23 11:15 UTC

drmoisan / drm-copilot

Python · TypeScript · PowerShellMIT★ 0 星标⑂ 0 复刻始于 2026年1月在 GitHub 上查看 ↗

drmoisan/drm-copilot 的健康指数为 100 分中的 59 分,处于「中等」区间。 其得分最高的类别是Vitality(81/100),最低的是Community & Adoption(32/100)。 最近一次更新在今天。 近期的大部分工作由 1 位贡献者完成。

59
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

59
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

drmoisan个人账户
5 关注者11 个公开仓库始于 2019年8月

该仓库由个人账户拥有。相较于组织支持的项目,单一所有者项目的延续性风险更高。

软件包生态系统

注册表软件包版本月下载量版本数最近发布标签
npm@danmoisan/drm-copilot-mcp1.0.172,218155 天前mcpcopilotclaudecodexautomationworkflowstdio

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

81良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 0 天前
13.2/36提交节奏 — 52 周中有 19 周有提交
18/18提交量 — 最近一年 896 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year896
human_commit_share0.99
days_since_last_push0
active_weeks_last_year19

发布纪律

88优秀
评分方式
16.2/27有发布版本 — 22 个版本标签(无 GitHub 发布版本)
36/36发布时效 — 最近一次发布版本于 5 天前
27/27发布节奏 — 约每 1.4 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count22
latest_release_tagv1.0.17
releases_from_tags
days_since_latest_release5
mean_days_between_releases1.4
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

32存在风险 · 占总体的 18%
评分方式
0/60星标 — 0 个星标
0/25复刻 — 0 个复刻
0/15关注者 — 0 位关注者
所用输入
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

50中等
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(MIT)
0/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
44.6/80月度下载量 — npm 合计每月 2,218 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packages@danmoisan/drm-copilot-mcp
dependents
ecosystemsnpm
total_downloads
monthly_downloads2,218
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

53中等 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0/22.5提交分布 — 头号贡献者编写了 100% 的提交
1.4/13.5贡献者广度 — 1 位贡献者
0/10OpenSSF Scorecard:Contributors — project has 0 contributing companies or organizations -- score normalized to 0
所用输入
bus_factor1
contributors_sampled1
top_contributor_share1
评分方式
38.2/46.8议题解决 — 82% 的议题已关闭
37.3/38.3PR 接受 — 已裁定的 PR 中 242/248 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/8 approved changesets -- score normalized to 0
所用输入
merged_prs242
open_issues28
closed_issues125
issue_closed_ratio0.817
closed_unmerged_prs6
评分方式
10/30所有权背书 — 个人(用户)账户
0/20已验证域名 — 不适用于个人账户
5.6/25所有者影响力 — drmoisan 有 5 位关注者
19.9/25既往记录 — 11 个公开仓库,账户约 6 年
所用输入
followers5
owner_typeUser
is_verified
owner_logindrmoisan
public_repos11
account_age_days2,532
已排除计分(无数据或不适用):已验证域名。 其余权重已重新归一化。
评分方式
25/25已发布且可解析 — npm 上有 1 个软件包
35/35发布时效 — 最近一次发布于 5 天前
20/20版本历史 — 15 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packages@danmoisan/drm-copilot-mcp
ecosystemsnpm
any_deprecated
min_days_since_publish5

工程质量

基础的工程与文档实践是否到位?

74良好 · 占总体的 20%

工程实践

80良好
评分方式
24/24CI 工作流 — 12 个工作流
24/24存在测试
16/16Linter 配置 — eslint.config.mjs
0/9.6Pre-commit 钩子
0/6.4.editorconfig
16/20OpenSSF Scorecard:CI-Tests — 8 out of 9 merged PRs checked by a CI test -- score normalized to 8
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

65中等
评分方式
30/30README
25/25文档目录
0/15文档 / 主页站点
0/10仓库描述
0/10主题标签
10/10Wiki
所用输入
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

47存在风险 · 占总体的 16%

安全态势

47存在风险
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
3/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2/2.5CI-Tests — 8 out of 9 merged PRs checked by a CI test -- score normalized to 8
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/8 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
1/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — 无数据
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 54 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate4.7
已排除计分(无数据或不适用):signed_releases。 其余权重已重新归一化。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

76良好 · 占总体的 0%
评分方式
45/45代理指令 — .github/copilot-instructions.md, .github/instructions/csharp-code-change.instructions.md, .github/instructions/csharp-unit-test.instructions.md, .github/instructions/general-code-change.instructions.md, .github/instructions/general-unit-test.instructions.md, .github/instructions/github-actions-ci-cd-best-practices.instructions.md, .github/instructions/github-actions.instructions.md, .github/instructions/powershell-code-change.instructions.md, .github/instructions/powershell-unit-test.instructions.md, .github/instructions/python-code-change.instructions.md, .github/instructions/python-suppressions.instructions.md, .github/instructions/python-unit-test.instructions.md, .github/instructions/self-explanatory-code-commenting.instructions.md, .github/instructions/tonality.instructions.md, .github/instructions/typescript-code-change.instructions.md, .github/instructions/typescript-suppressions.instructions.md, .github/instructions/typescript-unit-test.instructions.md, AGENTS.md, CLAUDE.md, docs/features/templates/policy_audit/AGENTS.md, extensions/drm-copilot/resources/codex-and-agents-customizations/AGENTS.md, extensions/drm-copilot/resources/templates/policy_audit/AGENTS.md, tests/fixtures/codex_native_converter/claude/CLAUDE.md, virtual/apply-artifacts-debug/proposed-tree/AGENTS.md, virtual/debug-artifacts-2/proposed-tree/AGENTS.md, virtual/debug-artifacts-3/proposed-tree/AGENTS.md, virtual/debug-artifacts/proposed-tree/AGENTS.md
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 99 次人类提交中有 98 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.99
agent_instruction_files.github/copilot-instructions.md, .github/instructions/csharp-code-change.instructions.md, .github/instructions/csharp-unit-test.instructions.md, .github/instructions/general-code-change.instructions.md, .github/instructions/general-unit-test.instructions.md, .github/instructions/github-actions-ci-cd-best-practices.instructions.md, .github/instructions/github-actions.instructions.md, .github/instructions/powershell-code-change.instructions.md, .github/instructions/powershell-unit-test.instructions.md, .github/instructions/python-code-change.instructions.md, .github/instructions/python-suppressions.instructions.md, .github/instructions/python-unit-test.instructions.md, .github/instructions/self-explanatory-code-commenting.instructions.md, .github/instructions/tonality.instructions.md, .github/instructions/typescript-code-change.instructions.md, .github/instructions/typescript-suppressions.instructions.md, .github/instructions/typescript-unit-test.instructions.md, AGENTS.md, CLAUDE.md, docs/features/templates/policy_audit/AGENTS.md, extensions/drm-copilot/resources/codex-and-agents-customizations/AGENTS.md, extensions/drm-copilot/resources/templates/policy_audit/AGENTS.md, tests/fixtures/codex_native_converter/claude/CLAUDE.md, virtual/apply-artifacts-debug/proposed-tree/AGENTS.md, virtual/debug-artifacts-2/proposed-tree/AGENTS.md, virtual/debug-artifacts-3/proposed-tree/AGENTS.md, virtual/debug-artifacts/proposed-tree/AGENTS.md
agent_instruction_max_bytes52,606
评分方式
0/18一条命令的引导启动
22/22自动化测试
11/11Lint / 格式化配置 — eslint.config.mjs
11/11静态类型检查 — extensions/drm-copilot/tsconfig.json, packages/mcp-server/tsconfig.json, tsconfig.json
10/10可复现环境 — devcontainer, Dockerfile, lockfile
10/10已体现的代理实践 — 最近 100 次提交中有 55 次由代理编写或署名代理
8/8自动化维护 — 最近 100 次提交中有 1 次为自动依赖更新
2/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
所用输入
has_nix
has_tests
lockfilespackage-lock.json, poetry.lock
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configsextensions/drm-copilot/tsconfig.json, packages/mcp-server/tsconfig.json, tsconfig.json
agent_commit_share0.55
toolchain_manifests
dependency_bot_commit_share0.01
评分方式
27/45可类型检查的代码 — Python,已配置类型检查(extensions/drm-copilot/tsconfig.json, packages/mcp-server/tsconfig.json, tsconfig.json)
55/55可控的文件大小 — 采样的 686 个源文件中有 0 个超过 60KB
所用输入
primary_languagePython
largest_source_bytes35,309
source_files_sampled686
oversized_source_files0
评分方式
0/40API 模式(OpenAPI/GraphQL/proto)
20/20MCP 服务器
40/40可运行示例 — examples
所用输入
example_dirsexamples
has_mcp_signal
api_schema_files

关键数据

0GitHub 星标
1贡献者
896最近 12 个月提交数
0距最近推送天数
22发布版本数
1巴士系数(bus factor)
28开放议题
npm, PyPI软件包生态系统数

数据采集警告

  • Could not fetch npm package 'drm-copilot' from its registry
  • Could not fetch pypi package 'drm-copilot' from its registry
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index npm:@danmoisan/drm-copilot-mcp@1.0.17; advisories assessed against the repository dependency graph instead

更多细节

OpenSSF Scorecard 4.7 / 10
4.7综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-23 11:14 UTC

10Binary-Artifactsno binaries found in the repo
4Branch-Protectionbranch protection is not maximal on development and all release branches
8CI-Tests8 out of 9 merged PRs checked by a CI test -- score normalized to 8
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/8 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
2Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 2
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
不适用Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities54 existing vulnerabilities detected
直接依赖 20
注册表软件包版本约束清单文件
npm@modelcontextprotocol/sdk^1.29.0package.json
PyPItyper>=0.9.0pyproject.toml
PyPIPyYAML>=6.0pyproject.toml
PyPInumpy>=1.23pyproject.toml
PyPIclick>=8.1pyproject.toml
PyPIpandas>=2.0pyproject.toml
PyPIscikit-learn>=1.3pyproject.toml
PyPIscipy>=1.10pyproject.toml
PyPIrequests>=2.31pyproject.toml
PyPIbeautifulsoup4>=4.12pyproject.toml
PyPIlxml>=5.3.0pyproject.toml
PyPIpyarrow>=15.0pyproject.toml
PyPIpdfplumber>=0.10.0pyproject.toml
PyPItensorflow>=2.10.0pyproject.toml
PyPIjoblib>=1.1.0pyproject.toml
PyPInltk>=3.8pyproject.toml
PyPIkeras-preprocessing>=1.1pyproject.toml
PyPIopenai>=1.40.0pyproject.toml
npm@modelcontextprotocol/sdk^1.29.0extensions/drm-copilot/package.json
npm@modelcontextprotocol/sdk^1.29.0packages/mcp-server/package.json
全部依赖 未采集

本报告未能采集到解析后的依赖集合:GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 14704,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Shell": 79272,
        "Python": 3041226,
        "Dockerfile": 8056,
        "JavaScript": 15878,
        "PowerShell": 2599583,
        "TypeScript": 2627159
      },
      "pushed_at": "2026-07-23T02:50:25Z",
      "created_at": "2026-01-28T20:17:27Z",
      "owner_type": "User",
      "updated_at": "2026-07-23T00:17:39Z",
      "description": null,
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Python",
      "significant_languages": [
        "Python",
        "TypeScript",
        "PowerShell"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "User",
      "login": "drmoisan",
      "company": null,
      "location": null,
      "followers": 5,
      "avatar_url": "https://avatars.githubusercontent.com/u/54180981?v=4",
      "created_at": "2019-08-16T14:30:52Z",
      "is_verified": null,
      "public_repos": 11,
      "account_age_days": 2532
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.0.17",
          "kind": "patch",
          "published_at": "2026-07-18T01:55:31Z"
        },
        {
          "tag": "v1.0.16",
          "kind": "patch",
          "published_at": "2026-07-16T03:55:23Z"
        },
        {
          "tag": "v1.0.15",
          "kind": "patch",
          "published_at": "2026-07-11T16:53:03Z"
        },
        {
          "tag": "v1.0.14",
          "kind": "patch",
          "published_at": "2026-07-10T21:59:13Z"
        },
        {
          "tag": "v1.0.13",
          "kind": "patch",
          "published_at": "2026-07-09T22:48:49Z"
        },
        {
          "tag": "v1.0.12",
          "kind": "patch",
          "published_at": "2026-07-09T12:46:29Z"
        },
        {
          "tag": "v1.0.11",
          "kind": "patch",
          "published_at": "2026-07-07T13:29:09Z"
        },
        {
          "tag": "v1.0.10",
          "kind": "patch",
          "published_at": "2026-07-06T22:38:39Z"
        },
        {
          "tag": "v1.0.9",
          "kind": "patch",
          "published_at": "2026-07-05T18:37:55Z"
        },
        {
          "tag": "v1.0.8",
          "kind": "patch",
          "published_at": "2026-07-05T01:49:57Z"
        },
        {
          "tag": "v1.0.7",
          "kind": "patch",
          "published_at": "2026-07-04T02:48:06Z"
        },
        {
          "tag": "v1.0.6",
          "kind": "patch",
          "published_at": "2026-07-03T21:15:37Z"
        },
        {
          "tag": "v1.0.5",
          "kind": "patch",
          "published_at": "2026-07-03T20:40:51Z"
        },
        {
          "tag": "v1.0.4",
          "kind": "patch",
          "published_at": "2026-07-03T04:05:40Z"
        },
        {
          "tag": "v1.0.3",
          "kind": "patch",
          "published_at": "2026-07-02T22:33:17Z"
        },
        {
          "tag": "v1.0.2",
          "kind": "patch",
          "published_at": "2026-06-30T12:12:31Z"
        },
        {
          "tag": "v1.0.1",
          "kind": "patch",
          "published_at": "2026-06-27T19:27:13Z"
        },
        {
          "tag": "v1.0.0",
          "kind": "major",
          "published_at": "2026-06-27T16:22:43Z"
        },
        {
          "tag": "v0.0.6",
          "kind": "patch",
          "published_at": "2026-06-26T02:07:45Z"
        },
        {
          "tag": "v0.0.5",
          "kind": "patch",
          "published_at": "2026-06-21T21:02:06Z"
        },
        {
          "tag": "v0.0.4",
          "kind": "patch",
          "published_at": "2026-06-21T20:39:56Z"
        },
        {
          "tag": "v0.0.3",
          "kind": "patch",
          "published_at": "2026-06-20T14:13:41Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "a9cea834fcf381d1d94a147dcb45fd101538105c",
          "body": "…n-type-gap-399\n\nfix(orchestration-routing): resolve promotion-entry MCP tool from checkpoint promotion type",
          "is_bot": false,
          "headline": "Merge pull request #402 from drmoisan:bug/large-route-matrix-promotio…",
          "author_name": "drmoisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-23T00:17:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a0dffff574354e34ed2c62d70880b3860034a15",
          "body": "Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(feature-review): record 0-blocking Go audit for #399",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-22T19:52:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fbfef347e819b9ea77c5fe4f3b6b60efdbc17163",
          "body": "…on-type\n\n- Remove dead required_skills entries (orchestrator-workflow, repo-automation-adapter) from large-route configuration\n- Add promotion-type-aware resolution logic to validate_routing_contract so bug-type promotions resolve to new_potential_bug_entry tool instead of feature-type new_potential_entry\n- Add unit tests for routing contract validation with promotion-type scenarios\n\nRefs: #399\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(orchestration-routing): resolve promotion-entry tool from promoti…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-22T19:27:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7bd788ce314fab41b8a32b6c78b55e59e8a30a41",
          "body": "…e gap (#399)\n\nDocuments two pre-existing orchestration-tooling defects discovered while\nfinalizing issue #397/PR #398: dead required_skills entries in the \"large\"\nroute (orchestrator-workflow, repo-automation-adapter) and a promotion-type-\nunaware required_mcp_tools entry (hardcoded new_potential_entry) that\ntogether block --require-complete from ever passing for large-route work.\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(potential): capture and promote large-route matrix promotion-typ…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-22T13:38:41Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a0b251d330525b8307467f4cf529c5cc3e947445",
          "body": "…i-gate-397\n\nfix(deps): resolve npm audit vulnerabilities in 3 manifests via @hono/node-server override (#397)",
          "is_bot": false,
          "headline": "Merge pull request #398 from drmoisan:bug/npm-audit-vulnerabilities-c…",
          "author_name": "drmoisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-22T13:25:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b716920ae91a86998697b086f96732b5f0c6cbc",
          "body": "PR #398 is open with all required checks green, not yet merged; spec.md\nnow reflects \"Ready for Merge\" rather than a premature \"Delivered\"/merged claim.\n\nRefs: #397",
          "is_bot": false,
          "headline": "docs(npm-audit): check off final AC and correct spec status for #397",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-22T12:56:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e11b9ee02a0f1c276981baf597593225af70ff6",
          "body": "Refs: #397",
          "is_bot": false,
          "headline": "docs(npm-audit): record feature-review audit (0 blocking) for #397",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-22T12:43:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "33a3380623de8e0aa3e158cad695b488a62c4cd9",
          "body": "- Add @hono/node-server override to all package manifests\n- Bump fast-uri, hono, and brace-expansion override versions\n- Regenerate package-lock.json files\n\nRefs: #397",
          "is_bot": false,
          "headline": "fix(npm-audit): add overrides to resolve npm audit vulnerabilities",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-22T12:35:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b2351cbc3fb3916f516d77567a1c9e40457c8981",
          "body": "refactor(shell): replace Python shell-qc with a native bash toolchain (no Poetry)",
          "is_bot": false,
          "headline": "Merge pull request #394 from drmoisan:drm-copilot-wt-2026-07-21T17-20",
          "author_name": "drmoisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-22T02:24:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0852b11633677b6fb87d98904a3fbd3fda22b079",
          "body": "…(#393)\n\nAdd the cycle-1 re-audit artifacts (policy-audit/code-review/feature-audit\n2026-07-21T20-09) confirming zero blocking findings and 9/9 acceptance\ncriteria, and update the orchestrator checkpoint (remediation loop exit,\ndelegation and model-routing receipts).\n\nRefs: #393\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(shell): record R4 re-audit (0 blocking) and orchestration state …",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-22T02:13:50Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3bf0b94f41ffb3a88312231949a5a0ebd3252c12",
          "body": "…ce (#393)\n\nAdd remediation-plan.2026-07-21T19-39.md and the post-fix bash coverage\nevidence (88.2% line coverage, summary line printing) verifying REM-1/REM-2\nresolution for issue #393.\n\nRefs: #393\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(shell): record cycle-1 remediation plan and bash-coverage eviden…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-22T02:13:50Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "36e7817c75f09623016f81d74165175880948d51",
          "body": "…al path\n\nRemediation for issue #393 feature review (REM-1 Blocking, REM-2 Major):\nthe per-run kcov invocation passed --cobertura-only, which suppresses the\ncoverage database that 'kcov --merge' consumes, producing an empty merged\nreport (lines-valid=0). Remove --cobertura-only from the per-run invo\n[…]\nline prints and Coverage Gutters resolves it.\nThis defect pre-existed in the removed shell_qc.py and is now corrected.\n\nRefs: #393\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(shell): make kcov coverage measurable and land cov.xml at canonic…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-22T02:13:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8402f8b1a894b0111f21d2e51b8ebbc1953f025d",
          "body": "- Implement shell QC (check/format/test) in native bash with no\n  Python or Poetry dependency\n- Add bats tests and fixtures with shell script discovery validation\n- Remove shell_qc.py and 5 Poetry console-script entries\n- Update CI workflows and fix_all_branches.py to use bash directly\n- Add .claude/rules/shell.md with shell toolchain standards\n\nRefs: #393\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(shell): replace Python shell-qc with native bash toolchain",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-22T02:13:50Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d465ca014eb4fdc01bc718ffeba62b50e4065308",
          "body": "fix(poshqc): host bundled Pester run in global session state to resolve Mock/InModuleScope failures (#392)",
          "is_bot": false,
          "headline": "Merge pull request #395 from drmoisan:drm-copilot-wt-2026-07-21T17-18",
          "author_name": "drmoisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-22T02:12:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f2fb870270b1f9cd83b313def84d72eff75441e3",
          "body": "Post-remediation reaudit (R4) artifacts confirm zero blocking findings remain\nand all 8 acceptance criteria verified passing. Branch confirmed ready for PR\ncreation.\n\nRefs: #392",
          "is_bot": false,
          "headline": "docs(poshqc): record remediation cycle 1 GO reaudit for issue #392",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-22T02:08:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e2f0b4e2bb6a39ac75130f6b9fd2fc92b187bbb8",
          "body": "- Implement process-lifetime cache for sub-module ScriptBlocks keyed by absolute path\n- Store in AppDomain data slot to preserve across Import-Module -Force reimports\n- Eliminate re-parse/re-compile churn that caused Pester to lose coverage hit credit\n- Preserve existing PS7.6+ isolation workaround \n[…]\nodule-collision guards\n- Add test coverage for Invoke-PoshQCTest $InvokePester and $EnsureModule defaults\n- Add test coverage for Convert-PoshQCCoverageToRelative missing-file early-return\n\nRefs: #392",
          "is_bot": false,
          "headline": "fix(poshqc): cache parsed ScriptBlocks to resolve coverage regression",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-22T02:08:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "33199f7280e55709d573e3be9da7b675608ba72f",
          "body": "- Create global-session-state trampoline function to host Invoke-Pester outside module scope\n- Import modules with -Global flag in default $EnsureModule seam\n- Add PoshQC.Testing.psm1 to Pester coverage paths for seam measurement\n- Add seam-default unit tests for $InvokePester and $EnsureModule\n- Fix Koverage-copy tests with explicit -InvokePester seam injection\n\nFixes #392",
          "is_bot": false,
          "headline": "fix(poshqc): run Pester in global scope to resolve bundled Mock tests",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-22T02:08:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "484e8a7a3fe868d614883bb453115dbf75a3bd73",
          "body": "docs(agent-memory): rescue #362 review artifacts; require commit/push of agent memory before PR open and merge",
          "is_bot": false,
          "headline": "Merge pull request #391 from drmoisan:chore/agent-memories",
          "author_name": "drmoisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-22T00:34:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "201e0357f8d69afd3fdb05a99a0ad50c6413a60d",
          "body": "…ories\n\nBoth new bundled feedback_commit_push_memory_before_pr.md files were missing\nmetadata.scope, which fails safe to \"repo\" and fails\ntest_bundled_agent_memory_scopes_are_well_formed (non-index bundled memories\nmust declare scope: general). Full pytest suite now passes (2069/2069).\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(agent-memory): declare metadata.scope: general on new bundled mem…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-21T20:51:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b52cdb96174d80dbdd1c967f253292fe64afcb9a",
          "body": "…and merge\n\nAdd a bundled agent-memory rule to orchestrator and epic-orchestrator: any\nmemory captured during a run must be committed and pushed before that run\nopens a PR, and any additional memory captured during the CI/remediation\ncycle must be committed and pushed again before the PR merges. Mot\n[…]\nture/legacy-discovery-documentation-371 worktree cleanup, which found\nreview-artifact files that were never committed and would have been lost.\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(agent-memory): require committing/pushing memory before PR open …",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-21T17:30:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e3570f68c4e43189779c58bc4491159e7e2ad952",
          "body": null,
          "is_bot": false,
          "headline": "(chore): update stranded agent memories",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-21T17:14:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "193864d87f3dfcc2e2a18987ec2ecc592dfea93b",
          "body": "…y-integration\n\ndocs(epic): finalize epic-status — all 14 features fanned in, integration PR #388 merged",
          "is_bot": false,
          "headline": "Merge pull request #390 from drmoisan:epic/legacy-discovery-and-parit…",
          "author_name": "drmoisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-20T10:37:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "56e3209e64733cada99d347377da16506349415c",
          "body": "…tion PR #388 merged\n\nEpic legacy-discovery-and-parity complete: all 14 child features merged into the integration\nbranch and worktrees removed (except #362, whose driving-session worktree removal is deferred);\nthe integration-to-main PR #388 merged as commit 33f8f6a2.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(epic): finalize epic-status — all 14 features fanned in, integra…",
          "author_name": "Dan Moisan",
          "author_login": null,
          "committed_at": "2026-07-20T10:29:41Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2f0080e60c05cdd8ba9d8aee839cdad8ba6acc4c",
          "body": "…b-actions-696b649f44\n\nchore(deps): bump actions/setup-python from 6 to 7 in the github-actions group",
          "is_bot": false,
          "headline": "Merge pull request #389 from drmoisan:dependabot/github_actions/githu…",
          "author_name": "drmoisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-20T10:27:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "93f859b38e8c392c6b2e7f4178a9a004b39d519b",
          "body": "Bumps the github-actions group with 1 update: [actions/setup-python](https://github.com/actions/setup-python).\n\n\nUpdates `actions/setup-python` from 6 to 7\n- [Release notes](https://github.com/actions/setup-python/releases)\n- [Commits](https://github.com/actions/setup-python/compare/v6...v7)\n\n---\nup\n[…]\non\n  dependency-version: '7'\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n  dependency-group: github-actions\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/setup-python in the github-actions group",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T07:13:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "33f8f6a23c720bc4b864e1e6570ac5289406593f",
          "body": "…y-integration\n\nepic(legacy-discovery-and-parity): merge integration branch to main",
          "is_bot": false,
          "headline": "Merge pull request #388 from drmoisan/epic/legacy-discovery-and-parit…",
          "author_name": "drmoisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T08:51:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c30b3d811e4749e334af33bea6ca4b12f4705072",
          "body": "Update integration branch with main (release 1.0.17, PR #373) to satisfy\nbranch-protection up-to-date requirement before the final epic merge.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "Merge branch 'main' into epic/legacy-discovery-and-parity-integration",
          "author_name": "Dan Moisan",
          "author_login": null,
          "committed_at": "2026-07-19T08:47:40Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "669c969ed11075fc777d93ee7c987081d102c06c",
          "body": "…ntation-371\n\ndocs(discovery): add capability documentation for legacy-discovery-and-parity epic (#371)",
          "is_bot": false,
          "headline": "Merge pull request #387 from drmoisan/feature/legacy-discovery-docume…",
          "author_name": "drmoisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T08:30:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0e44e091f2383d60875261b741d2da83543a7a1c",
          "body": "Independent reaudit confirms the consumer-onboarding.md distribution-claim\nfix holds: 11/11 spec.md and 5/5 user-story.md acceptance criteria\nindependently verified PASS. Closes remediation cycle 1 with\nblocking_count 0.\n\nRefs: #371",
          "is_bot": false,
          "headline": "docs(discovery): record remediation cycle 1 GO reaudit for issue #371",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T08:22:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f32c6d809088e583a45742f6a72d00718b84010",
          "body": "… #371 onboarding doc\n\n- Correct consumer-onboarding.md item 2 to state no consumer-facing\n  distribution mechanism exists for discovery schemas/init-templates,\n  replacing the false claim that they ship via @danmoisan/drm-copilot-mcp\n- Record remediation cycle 1 audit artifacts (policy-audit, code-review,\n  feature-audit, remediation-inputs, remediation-plan) and evidence under\n  evidence/{remediation-baseline,qa-gates,other}/\n\nRefs: #371",
          "is_bot": false,
          "headline": "docs(discovery): fix false schema/init-template distribution claim in…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T08:13:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de2cc7f9d5d1d7d1431db4db330c743f881927cd",
          "body": "…d-parity epic #371\n\n- Add README, workflow, domain-profile, artifacts-and-schemas, running-the-workflow, and consumer-onboarding docs under docs/engineering/legacy-discovery-and-parity/\n- Record phase0 baseline, integration reconciliation, and QA gate evidence artifacts for issue #371\n- Update plan, spec, and user-story AC checkboxes to reflect completed documentation work\n\nRefs: #371",
          "is_bot": false,
          "headline": "docs(discovery): add capability documentation for legacy-discovery-an…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T07:20:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b7be1a85d44f880e074e3d7a3ef160150297892f",
          "body": "Regenerated epic-status.md after launching the final child orchestrator run (documentation).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(epic): launch wave 4 (#371 documentation), mark worktree_created",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T06:55:41Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5c25bc45c02c796e352ecd2cfe4f1eebb07deb65",
          "body": "PR #386 (mcp-vscode) merged into the integration branch (merge commit f0446222); worktree\nremoved. Wave 3 complete; current wave advanced to 4.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(epic): fan in wave-3 #370 and advance to wave 4 in epic-status",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T06:54:49Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f0446222f1002e2a0febfd0e4071079b006bf4b2",
          "body": "…code-370\n\nfeat(discovery): expose seven dev.discovery.* CLI operations as MCP tools and VS Code commands",
          "is_bot": false,
          "headline": "Merge pull request #386 from drmoisan/feature/legacy-discovery-mcp-vs…",
          "author_name": "drmoisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T06:50:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "764d4a9c97797b6138ee4a6ce34dcc214816d3bb",
          "body": "Record the policy-audit, code-review, and feature-audit produced by\nthe feature-review workflow (REVIEW_STATUS: PASS, zero blocking\nfindings) for the legacy-discovery-mcp-vscode exposure feature.\n\nRefs: #370\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(discovery): add feature-review artifacts for issue #370",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T06:44:00Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9525dd0a529ff833f13c0c0bec8076794492d16e",
          "body": "- Add seven dev.discovery.* MCP tools (validate_discovery_artifacts,\n  run_discovery_init, run_discovery_repo_inventory,\n  run_discovery_dotnet_analyzer, run_discovery_vsto_analyzer,\n  run_discovery_scenario_generation, run_discovery_report) with input\n  definitions, handlers, and tool-name registra\n[…]\ntime detection, discovery execution, MCP tools, and commands\n\nRefs: #370\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "feat(discovery): expose discovery CLI as MCP tools and VS Code commands",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T06:27:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "edbb1429c419ee5b169e6eea990e602e2cd1e0c0",
          "body": "PR #385 merged into the integration branch (merge commit cba1038f); worktree removed.\nWave 3 remaining: #370 (mcp-vscode).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(epic): fan in wave-3 feature #372 (publishing) in epic-status",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T06:16:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cba1038fc47f34988d7fdd4ea2d399ce263bffde",
          "body": "…hing-372\n\ntest(discovery): verify epic-child mirror completeness and add pack-manifest coverage for issue #372",
          "is_bot": false,
          "headline": "Merge pull request #385 from drmoisan/feature/legacy-discovery-publis…",
          "author_name": "drmoisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T06:13:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aaf47c5f30165a5fe8f2c5d893ef2cad9ac84afc",
          "body": "- Code review: 0 Blocking findings, Go verdict; two new Python\n  manifest-completeness test modules verified and passing\n- Feature audit: all 18 acceptance criteria passing (spec 13/13,\n  user-story 5/5)\n- Policy audit: fully compliant; ready for merge\n\nRefs: #372\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(discovery): record feature-review GO audit artifacts for issue #372",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T06:06:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e64efcd136929f45febca53aec359e46e384f64e",
          "body": "- Add test_push_down_claude_pack_manifest_completeness.py to verify all\n  bundled .claude/ assets are registered in pack manifests\n- Add test_push_down_codex_and_agents_pack_manifest_completeness.py for\n  .codex/, .agents/, and hook registrations\n- Reconciliation result: all upstream legacy-discover\n[…]\nmplate placement (scripts-non-mirrored)\n- Record complete acceptance-criteria verification with evidence artifacts\n  per atomic plan\n\nRefs: #372\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(discovery): add manifest-completeness verification for Python side",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T05:47:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a6dd7d4591ef80f4d351cea4b0488ce08568286e",
          "body": "Regenerated epic-status.md after launching wave-3 child orchestrator runs (mcp-vscode, publishing).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(epic): launch wave 3 (#370, #372), mark worktree_created",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T05:01:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "050e541f5e8317dd16018ff2e473b4b46697535a",
          "body": "PR #384 (dotnet-vsto-analyzers) merged into the integration branch (merge commit 5ba4f9aa,\n4 remediation cycles); worktree removed. Wave 2 complete; current wave advanced to 3.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(epic): fan in wave-2 #369 and advance to wave 3 in epic-status",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T05:00:27Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5ba4f9aa60749632b1779e970fdfca21af34da68",
          "body": "…-vsto-analyzers-369\n\n.NET/C# and VSTO/Office legacy-discovery analyzers (#369)",
          "is_bot": false,
          "headline": "Merge pull request #384 from drmoisan/feature/legacy-discovery-dotnet…",
          "author_name": "drmoisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T04:54:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d60dafea031850421bd80e59cea8456f4b1c8df0",
          "body": "Add the feature-review cycle-4 re-audit outputs (policy-audit, code-review,\nfeature-audit) confirming the pack-manifest CI failure is resolved, all gates\npass, and all acceptance criteria remain satisfied. PR-ready.\n\nRefs: #369\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(discovery): record cycle 4 re-audit (manifest fix) for issue #369",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T04:51:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "937cfeb7fa9ea362454fa2d4834bed6f4416ca21",
          "body": "… check (#369)\n\nMark remediation cycle 4 plan tasks complete and add the r4c4 PR mergeable-check\nevidence (gh pr view 384 reports mergeable=MERGEABLE).\n\nIssue #369, remediation cycle 4.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(discovery): record cycle 4 plan completion and PR #384 mergeable…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T04:37:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d19c10ffb0ea58d05606422d5242818941c62996",
          "body": "…e pack manifest (#369 r4)\n\nRegister the two bundled discovery-artifact-gate hook paths in the core pack\nmanifest so the extension test claude-pack-manifest-completeness passes and the\nCI Extension Tests checks go green.\n\n- Append `.claude/hooks/enforce-discovery-artifact-gate.ps1` and\n  `.claude/ho\n[…]\ntest, or policy\nrule file is modified.\n\nIssue #369, remediation cycle 4.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "fix(bundled-resources): register discovery-artifact-gate hooks in cor…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T04:35:24Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a26a4abbf5fd2882c1c7c72e4b73dd7e3fe0a387",
          "body": "Add the feature-review cycle-3 re-audit outputs (policy-audit, code-review,\nfeature-audit) confirming the mandatory PowerShell coverage finding R-1 is\nresolved and all 22 acceptance criteria pass. GO for PR from review.\n\nRefs: #369\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(discovery): record cycle 3 re-audit (R-1 resolved) for issue #369",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T04:10:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "08b65760fdbcc61b4bff4db8a0d29921f4a201be",
          "body": "Add the feature-review cycle-2 re-audit outputs (policy-audit, code-review,\nfeature-audit) and the R-1 remediation-inputs (mandatory PowerShell coverage\nartifact for the pushed-down discovery-artifact-gate bundle mirrors).\n\nRefs: #369\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(discovery): record cycle 2 re-audit artifacts for issue #369",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T03:55:12Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "874bdaf9d3dfd51f261c1c56ce73c7a2afa3bf79",
          "body": "…ergeable evidence\n\nMark all Phase 0-3 tasks complete in the remediation-cycle-3 plan checklist and record\nthe PR #384 mergeable check (mergeable=MERGEABLE) for issue #369.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(discovery): finalize remediation cycle 3 checklist and PR #369 m…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T03:53:17Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "497a6166f99f51f0774a7a2b81088230a80bc500",
          "body": "…nce for issue #369\n\nProduce the mandatory PowerShell coverage evidence for the two discovery-artifact-gate\nhook bundle mirrors (enforce-discovery-artifact-gate.ps1 and validate-discovery-artifact-gate.ps1),\nresolving feature-review Blocking finding R-1 for PR #384.\n\nThe discovery-artifact-gate Pest\n[…]\n the r3c3- coverage summary under the feature evidence/qa-gates/ folder.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(discovery): record remediation cycle 3 PowerShell coverage evide…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T03:51:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "62662879766c9280015800634195a9582cb52041",
          "body": "…d mergeable evidence\n\nMark Phase 3 plan tasks complete and record the PR #384 mergeable check\n(mergeable: MERGEABLE) for the discovery-artifact-gate hook bundle push-down.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(discovery): finalize issue #369 remediation cycle 2 checklist an…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T03:09:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "5a3ea0fcf6b63062cd3b2924ec31b68313356c0e",
          "body": "…wn evidence\n\nAdd the remediation cycle 2 plan checklist, remediation inputs, Phase 0 baseline\nevidence, Phase 1 byte-identity and pass-after evidence, and Phase 2 final QC and\ncoverage-delta evidence for the discovery-artifact-gate hook bundle push-down\n(issue #369). Evidence uses the r2c2- prefix \n[…]\ne canonical\nevidence/ tree and does not overwrite prior-cycle artifacts.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(discovery): record issue #369 remediation cycle 2 bundle push-do…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T03:07:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "245e537e1f985a07f608e0560ddbf0df6935adf5",
          "body": "…tension bundle\n\nIssue #369 remediation cycle 2. The bundled extension payload was missing\nbyte-identical copies of two repo .claude hooks\n(enforce-discovery-artifact-gate.ps1 and validate-discovery-artifact-gate.ps1)\nand the bundle .claude/settings.json omitted the corresponding PreToolUse and\nPost\n[…]\nle so repo bytes equal bundle bytes. Repo-root originals are unmodified.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "fix(bundled-resources): push-down discovery-artifact-gate hooks to ex…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T03:07:21Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "008e59e91ff8473792da98ba656653a146c31165",
          "body": "…ble confirmation\n\nAdd the PR #384 mergeability confirmation artifact (mergeable: MERGEABLE) and\nfinalize the remediation cycle 1 plan checklist for issue #369.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(discovery): record issue #369 remediation cycle 1 PR #384 mergea…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T02:47:21Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "420914110592dd4128fb9e80d472b2fb7ba02a8e",
          "body": "…e-conflict resolution\n\nResolve the PR #384 pyproject.toml [tool.poetry.scripts] merge conflict by\nmerging origin/epic/legacy-discovery-and-parity-integration into the feature\nbranch and retaining all three dev.discovery console-script entries\n(dotnet, parity-report, vsto) in alias-suffix order. Rec\n[…]\n, and Phase 2 post-merge QA evidence for issue #369\nremediation cycle 1.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(discovery): record issue #369 remediation cycle 1 pyproject merg…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T02:45:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "02df65089327939057611afdf80883f8c2b994c2",
          "body": "…-integration' into feature/legacy-discovery-dotnet-vsto-analyzers-369\n\n# Conflicts:\n#\tpyproject.toml",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/epic/legacy-discovery-and-parity…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T02:45:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01fb34a8468090db01db471bb339a0dd6391a9d7",
          "body": "PR #383 merged into the integration branch (merge commit 63da9ce3); worktree removed.\nWave 2 remaining: #369 (dotnet-vsto-analyzers).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(epic): fan in wave-2 feature #366 (hooks) in epic-status",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T02:23:23Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "63da9ce3cbe1a182befc3b6fd12c19848d7aa32d",
          "body": "feat(hooks): add discovery-artifact completion-gate hooks (#366)",
          "is_bot": false,
          "headline": "Merge pull request #383 from drmoisan/feature/legacy-discovery-hooks-366",
          "author_name": "drmoisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T02:20:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c51608ddee92eb5aa503c581c5862f8a6739372a",
          "body": "Policy-audit, code-review, and feature-audit artifacts for the\nlegacy-discovery-hooks feature: GO verdict, 0 blocking findings.\n\nRefs: #366",
          "is_bot": false,
          "headline": "docs(discovery): record feature-review artifacts for issue #366",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T02:14:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2215ebf992ebfb46ab10674188c48d5a3a15cf3a",
          "body": "PR #381 merged into the integration branch (merge commit 1329b6f8, 1 remediation cycle);\nworktree removed.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(epic): fan in wave-2 feature #367 (skills) in epic-status",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T02:11:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e5b890024824d258987f7d1350cfe93f7317c92f",
          "body": "… for #369\n\n- Add policy-audit, code-review, and feature-audit artifacts (all PASS, zero\n  blocking findings) for the .NET/VSTO analyzers feature\n- Record orchestrator-state checkpoint through S6_feature_review with model\n  routing receipts and routing-contract receipts\n- Reflect acceptance-criteria check-off validation in spec.md and user-story.md\n\nRefs: #369\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(discovery): record feature-review audits and orchestration state…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T02:10:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "1329b6f80949a22bcd4bc2e3437c5fb0f93c2d89",
          "body": "…-367\n\nfeat(discovery): add seven domain-neutral discovery workflow-mechanics skills (#367)",
          "is_bot": false,
          "headline": "Merge pull request #381 from drmoisan/feature/legacy-discovery-skills…",
          "author_name": "drmoisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T02:09:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6fe61ffd560cd6e1392bd666171a4ea2d4148272",
          "body": "…pack-manifest fix\n\nAdd the cycle-1 remediation inputs, plan, baseline/QC evidence, and the three\ncycle-exit reaudit artifacts (code-review, feature-audit, policy-audit) for the\npack-manifest completeness remediation. Reaudit blocking-findings count is zero;\nall spec and user-story acceptance criteria remain satisfied.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(discovery): record remediation cycle 1 artifacts for issue #367 …",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T02:06:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fa1501451109fb2e4556c610330452126f9a8ae0",
          "body": "PR #382 merged into the integration branch (merge commit 26c24f86); worktree removed.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(epic): fan in wave-2 feature #368 (reports) in epic-status",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T02:02:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bb8f8b794b9073194d7494b6566b6ace09c94cf6",
          "body": "… for issue #367\n\nAdd the seven bundled `.claude/skills/discovery-*/SKILL.md` paths to the core\npack manifest (extensions/drm-copilot/resources/claude-customizations/pack-manifests/core.json)\nin existing alphabetical order. The bundled skills were present on disk but\nabsent from every pack manifest,\n[…]\nifest\ncompleteness while the Python push-down parity gate remains green.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "fix(discovery): register seven discovery skills in core pack manifest…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T01:59:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "31965bd00a703cc90c173f0f6de7b308b6be9df8",
          "body": "- Delivers .NET/C# inventory analyzer (dotnet_inventory.py) and VSTO/Office\n  analyzer (vsto_office.py) modules plugged into the #363 analyzer framework\n- Introduces shared TextParseResult frozen ParseResult subtype (source_text.py)\n  and supporting pattern matching module (vsto_patterns.py)\n- Adds \n[…]\nrk-level banned list to #363 language-neutral\n  modules only\n\nRefs: #369\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "feat(discovery): add .NET and VSTO analyzers for legacy discovery",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T01:59:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "26c24f861594922902b43fd8e04637304f210690",
          "body": "…s-368\n\nfeat(discovery): add coverage, parity, and completion report CLIs",
          "is_bot": false,
          "headline": "Merge pull request #382 from drmoisan/feature/legacy-discovery-report…",
          "author_name": "drmoisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T01:59:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "024cf6290c1a7666eac74aa41e8db99de1036e51",
          "body": "- Add enforce-discovery-artifact-gate.ps1 PreToolUse hook for Write operation validation\n- Add validate-discovery-artifact-gate.ps1 SubagentStop hook for subagent output validation\n- Register both hooks in .claude/settings.json\n- Add comprehensive Pester test files\n- Update coverage allowlist in pester.runsettings.psd1\n\nRefs: #366",
          "is_bot": false,
          "headline": "feat(hooks): add discovery-artifact completion-gate hooks",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T01:56:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5e83fe888917506071aab47469214e9660d59066",
          "body": "Audit verdict: PASS WITH FINDINGS, no Blocking findings.\n\nRefs: #368",
          "is_bot": false,
          "headline": "docs(feature-review): record audit for legacy-discovery-reports (#368)",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T01:52:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "20c26abd85dd2a58b28d77578edd7bc2fc403f8c",
          "body": "- Add coverage_report.py, parity_report.py, and completion_report.py modules\n- Add shared io.py and rendering.py helper modules with full isolation of I/O boundaries\n- Add comprehensive unit tests for all new modules (coverage >= 85%, branch >= 75%)\n- Register three new dev.discovery.* Poetry console-script entry points\n- Mark all acceptance criteria complete in spec and user-story\n\nRefs: #368",
          "is_bot": false,
          "headline": "feat(discovery): add coverage, parity, and completion report CLIs",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T01:36:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bff412d1b91864662fcbd142ca743b2ff5a58ba3",
          "body": "Add the policy-audit, code-review, and feature-audit artifacts produced by the\nfeature-review pass for the legacy-discovery-skills feature. All nine spec\nacceptance criteria and all seven user-story acceptance criteria evaluated PASS;\nblocking findings count is zero.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(discovery): record feature-review audit artifacts for issue #367",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T01:28:52Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "13234ea088cb074d0e5e89c183c7d11900abf048",
          "body": "…or issue #367\n\nAuthor the reusable workflow-mechanics layer for the legacy-discovery-and-parity\nepic: seven `.claude/skills/discovery-*/SKILL.md` skills that sequence the\ndiscovery and parity-definition workflow (profile load, inventory, coverage\nledger, runtime characterization, parity matrix, beh\n[…]\ns, domain-neutrality, plugin-name non-collision,\nand bundle byte-parity.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "feat(discovery): add seven domain-neutral discovery workflow skills f…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T01:22:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3a4985fa904da7b5925091b393f9551c874ab006",
          "body": "Regenerated epic-status.md projection from the epic-orchestrator checkpoint after\nlaunching wave-2 child orchestrator runs (hooks, skills, reports, dotnet-vsto-analyzers)\nin isolated worktrees.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(epic): advance to wave 2, mark #366/#367/#368/#369 worktree_created",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T01:06:44Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e395efb7cf55953a93088964f10edc4d9dede404",
          "body": "Regenerated epic-status.md projection from the reconstructed epic-orchestrator\ncheckpoint. Feature #362 is merged into the integration branch via PR #380\n(merge commit c9c4af8c); current wave advanced to 2.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(epic): fan in wave-1 feature #362 (init-templates) in epic-status",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T01:02:50Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c9c4af8c53af850f4dd5cd6cda62c06b50753965",
          "body": "…emplates-362\n\nfeat(discovery): add dev.discovery.init command and workspace templates",
          "is_bot": false,
          "headline": "Merge pull request #380 from drmoisan/feature/legacy-discovery-init-t…",
          "author_name": "drmoisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T00:49:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da573298b182a22bb9fd3fc1b68e030e5fe6f6c2",
          "body": "…check for issue #362\n\n- Mark P3-T4 (branch push) and P3-T5 (PR mergeable check) complete in remediation plan\n- Add QA gate evidence confirming PR #380 now reports mergeable status\n\nRefs: #362\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\nClaude-Session: https://claude.ai/code/session_014yaSJ5v4AUiuhaAQHPPDk9",
          "is_bot": false,
          "headline": "docs(discovery): record cycle 4 Phase 3 final tasks and PR mergeable …",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-19T00:42:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "6a9a9e34c291427b7c818dec971b6a651c20ad15",
          "body": "…pyproject.toml merge conflict",
          "is_bot": false,
          "headline": "docs(discovery): record remediation cycle 4 checklist for issue #362 …",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T18:58:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "307678815fac727abfe54aca78df0ff59242dd1d",
          "body": "…-integration' into feature/legacy-discovery-init-templates-362\n\n# Conflicts:\n#\tpyproject.toml",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/epic/legacy-discovery-and-parity…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T18:57:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f17f1af08c67568fbc14140a25882c068a50d2b0",
          "body": "…nsion bundle\n\n- Copy legacy-parity-analyst.md into bundled extension\n- Copy migration-coverage-reviewer.md into bundled extension\n- Copy requirements-reconciler.md into bundled extension\n- Copy runtime-characterization-analyst.md into bundled extension\n\nThese files were added to the repo root by si\n[…]\ns the bundle to be a byte-identical mirror of the repo .claude/\ntree (excluding .claude/agent-memory/** and .claude/settings.local.json).\n\nThis fix restores that invariant and allows the test to pass.",
          "is_bot": false,
          "headline": "fix(bundled-resources): push-down four missing agent personas to exte…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T18:20:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c4ec9a2bb46d68689d1ae095d1ecb1f409fecda3",
          "body": "…tatus\n\nlegacy-discovery-analyzer-framework (#363, PR #378) merged into the\nintegration branch; worktree removed. Wave 1 remains open: #362 in flight\n(PR #380 open).\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(epic): fan in wave-1 feature #363 (analyzer-framework) in epic-s…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T17:51:05Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a13adb8ba12bc1b8e06d1a81c42e992bec8a0a47",
          "body": "…er-framework-363\n\nfeat(discovery): add domain-neutral analyzer framework and inventory analyzer (#363)",
          "is_bot": false,
          "headline": "Merge pull request #378 from drmoisan/feature/legacy-discovery-analyz…",
          "author_name": "drmoisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T17:45:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a6cfe1608ad2e3fc337edda6cc1438953490b8e",
          "body": "Reaudit after the pack-manifest registration fix: policy-audit, code-review,\nand feature-audit all PASS with zero blocking findings; 20/20 acceptance\ncriteria verified; both bundle-contract tests (Python + TypeScript) pass;\nPR #378 CI green and mergeable.\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(discovery): add cycle-3 exit reaudit for #363 (READY TO MERGE)",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T17:42:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "48939e3e3f551dcf45465aa9be06560f86db65b5",
          "body": "…ble evidence for issue #362\n\nChecks off Phase 3 tasks and records the post-push PR #380 mergeable\nconfirmation evidence (MERGEABLE) for the pyproject.toml merge-conflict\nremediation.",
          "is_bot": false,
          "headline": "docs(discovery): finalize remediation cycle 2 checklist and PR mergea…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T17:40:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "88707a3320370b0b074b51652ae28f29b8e6cbe4",
          "body": "…erge conflict\n\nAdds Phase 0-2 baseline and QA-gate evidence, prior cycle-1 audit\nartifacts, and the updated remediation-plan checklist for the\npyproject.toml dev.discovery.* merge-conflict resolution against\norigin/epic/legacy-discovery-and-parity-integration (PR #380).",
          "is_bot": false,
          "headline": "docs(discovery): record remediation cycle 2 evidence for issue #362 m…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T17:39:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "afab4468201df8b4bceb89155cc232da6e228298",
          "body": "…-integration' into feature/legacy-discovery-init-templates-362\n\n# Conflicts:\n#\tpyproject.toml",
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/epic/legacy-discovery-and-parity…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T17:38:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f22b09e810dc97f66f888fed599dc67bd4577f42",
          "body": "Add the remediation cycle 3 finalization artifacts (commit, push, and PR #378\nmergeable verification) and check off the corresponding plan tasks. Evidence-only\nchange; no production code, test, or manifest changes.\n\nRefs #363\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(evidence): record cycle 3 commit, push, and PR-mergeable evidence",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T17:29:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "99e4772d73547e6d42fa8e2d62896f764a2fdeab",
          "body": "…nifest\n\nAdd the four #365 agent files to the core.json pack-manifest `paths` array so the\nbundled `.claude/agents` payload is fully covered by a manifest, preserving the\nexisting alphabetical ordering:\n\n- .claude/agents/legacy-parity-analyst.md\n- .claude/agents/migration-coverage-reviewer.md\n- .cla\n[…]\nmissing from every manifest and that the codex-and-agents parallel contract\npasses. Includes remediation cycle 3 evidence artifacts.\n\nRefs #363\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(claude-customizations): register #365 agent paths in core pack ma…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T17:28:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "64a94ad2212d323387152a65c31688bc43d46669",
          "body": "…e (#363)\n\nS9 CI surfaced a failed required check (Extension Tests: claude pack-manifest\ncompleteness) not covered by the local Python suite. The four #365 agent files\nmirrored into the bundle in cycle 2 are absent from every pack manifest. Cycle 3\nregisters them in core.json.\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(discovery): open cycle-3 remediation for CI pack-manifest failur…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T17:02:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3d2544ec3dba82d343f93ac6d844ed303643af57",
          "body": "Reaudit after the integration merge and bundled-payload drift repair:\npolicy-audit, code-review, and feature-audit all PASS with zero blocking\nfindings; 20/20 acceptance criteria verified; PR #378 mergeable.\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(discovery): add cycle-2 exit reaudit for #363 (READY TO MERGE)",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T16:57:11Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "85e7bea2bd2695114c9feffb2a4963da9f37c9ad",
          "body": "legacy-discovery-validators (#361, PR #379) merged into the integration\nbranch; worktree removed. Wave 1 remains open: #362, #363 in flight\n(#363 PR #378 open).\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(epic): fan in wave-1 feature #361 (validators) in epic-status",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T16:53:06Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d1530986e01d1a1293f4cb55510acc62e3a83725",
          "body": "feat(discovery): add deterministic validators for domain-profile config and seven discovery schemas (#361)",
          "is_bot": false,
          "headline": "merge(epic): fan in prepared feature legacy-discovery-validators (#379)",
          "author_name": "drmoisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T16:50:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7610bf2539f62bba5e4489f559ed486fb368043a",
          "body": "- Fix .gitignore anchor to track discovery template artifacts\n- Rewrite domain-profile.yaml to match v1 contract from #360\n- Correct 7 JSON template files to validate against schemas (#359)\n- Restore public re-exports in discovery.__init__.py\n- Add package-export regression test\n- Un-skip schema-conformance gate test\n- Update acceptance criteria in spec.md and user-story.md\n\nRefs: #362",
          "is_bot": false,
          "headline": "fix(discovery): resolve blocking review findings for init templates",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T16:43:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6126b4f5d1df1b0a1e95681763e4d759fc5e2d70",
          "body": "…eck-offs\n\nAdd the commit, push, and PR-mergeable evidence artifacts for remediation\ncycle 2 of the legacy-discovery-analyzer-framework feature (issue #363) and\nmark the corresponding plan tasks complete. Documentation only; no change to\nthe bundle fix in the preceding commit.\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(remediation): record cycle 2 commit/push/PR evidence and plan ch…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T16:43:23Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "527a5677b8bda5f514de4cc28176d200611dc7c8",
          "body": "…cycle-1 reaudit)\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(review): add feature-review audit artifacts for #361 (initial + …",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T16:41:45Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e0c68418c000b6ea50655c3cd2de35c9dee1eecc",
          "body": "Copy the four repo .claude/agents source files added by sibling #365\n(legacy-parity-analyst, migration-coverage-reviewer, requirements-reconciler,\nruntime-characterization-analyst) byte-for-byte into the bundled payload at\nextensions/drm-copilot/resources/claude-customizations/.claude/agents/.\n\nThis\n[…]\nct\n(line 88.62% >= 85%, branch 79.25% >= 75%, no regression).\n\nIncludes remediation cycle 2 evidence artifacts under the feature evidence tree.\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(bundle): mirror four .claude/agents contracts into bundled payload",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T16:40:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3742216347ff92ca9fd6c0c9a59e6e349ff9f449",
          "body": "…ght/Pytest)\n\nShortens one overlong docstring flagged by Ruff (E501) in\ntest_schema_loading.py and restarts the toolchain loop per policy; Black,\nRuff, and Pyright all pass clean. Full-suite pytest run (1720 passed)\nconfirms aggregate line coverage 88.26% and branch coverage 79.11%, both\nat or above the pre-remediation baseline (88.21%/79.02%), with no\nregression. All 12 remediation-plan tasks are checked off.",
          "is_bot": false,
          "headline": "remediation(361): Phase 5 final QA loop passes clean (Black/Ruff/Pyri…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T16:28:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f780ae3db10b1263d93c15b248d37f30b643494a",
          "body": "… (#363)\n\nCycle 1 resolved the pyproject.toml [tool.poetry.scripts] merge conflict\n(union) against the integration branch. Final-QC surfaced a separate\npre-existing bundled-payload drift finding (#365 agent personas not mirrored\ninto the extension bundle), handed to cycle 2 per the scope-change rule.\n\nCo-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(discovery): record cycle-1 remediation evidence and open cycle 2…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T16:26:47Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bce0339d5f44d242dea33d99599bea57ddbcbacf",
          "body": "Checks off the Definition-of-Done and Acceptance Criteria items flagged\nGap (feature-review 2026-07-18T16-04) now that schema_loading.py's branch\ncoverage is verified at 92.86% (>= 75% threshold).",
          "is_bot": false,
          "headline": "remediation(361): check off spec.md/user-story.md coverage AC after fix",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T16:25:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a382489d668a4cf1046d5204458219f859319d11",
          "body": "…g 1)\n\nAdds three targeted test functions to test_schema_loading.py covering the\nfile:// success path, file:// not-found branch, and scheme-less relative\nnot-found branch (no production code change). Branch coverage for\nschema_loading.py rises from 64.29% to 92.86% in the test-file-scoped run.\nAlso adds a corrected evidence artifact restating line and branch coverage\nseparately, replacing the prior mislabeled blended-metric reference\n(Finding 2).",
          "is_bot": false,
          "headline": "remediation(361): close schema_loading.py branch-coverage gap (Findin…",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T16:24:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc12c8636c3c04ec0030bc897daf690a034f5995",
          "body": "Adds Phase 0 evidence artifacts for the legacy-discovery-validators-361\nremediation cycle: policy-read record and pre-remediation baseline\ncoverage for schema_loading.py (branch coverage 64.29% test-file-scoped,\nconfirming Finding 1 before the Phase 1 test additions).",
          "is_bot": false,
          "headline": "remediation(361): Phase 0 policy read + baseline coverage evidence",
          "author_name": "Dan Moisan",
          "author_login": "drmoisan",
          "committed_at": "2026-07-18T16:21:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 22,
      "commits_last_year": 896,
      "latest_release_at": "2026-07-18T01:55:31Z",
      "latest_release_tag": "v1.0.17",
      "releases_from_tags": true,
      "days_since_last_push": 0,
      "active_weeks_last_year": 19,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 1.4
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": false,
      "has_contributing": false,
      "health_percentage": 28,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@danmoisan/drm-copilot-mcp",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "mcp",
            "copilot",
            "claude",
            "codex",
            "automation",
            "workflow",
            "stdio"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@danmoisan/drm-copilot-mcp",
          "is_deprecated": false,
          "latest_version": "1.0.17",
          "repository_url": "https://github.com/drmoisan/drm-copilot",
          "versions_count": 15,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2218,
          "first_published_at": "2026-05-09T02:01:15.789000Z",
          "latest_published_at": "2026-07-18T01:57:04.585000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 30
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": true,
      "typecheck_configs": [
        "extensions/drm-copilot/tsconfig.json",
        "packages/mcp-server/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 35309,
      "source_files_sampled": 686,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        ".github/copilot-instructions.md",
        ".github/instructions/csharp-code-change.instructions.md",
        ".github/instructions/csharp-unit-test.instructions.md",
        ".github/instructions/general-code-change.instructions.md",
        ".github/instructions/general-unit-test.instructions.md",
        ".github/instructions/github-actions-ci-cd-best-practices.instructions.md",
        ".github/instructions/github-actions.instructions.md",
        ".github/instructions/powershell-code-change.instructions.md",
        ".github/instructions/powershell-unit-test.instructions.md",
        ".github/instructions/python-code-change.instructions.md",
        ".github/instructions/python-suppressions.instructions.md",
        ".github/instructions/python-unit-test.instructions.md",
        ".github/instructions/self-explanatory-code-commenting.instructions.md",
        ".github/instructions/tonality.instructions.md",
        ".github/instructions/typescript-code-change.instructions.md",
        ".github/instructions/typescript-suppressions.instructions.md",
        ".github/instructions/typescript-unit-test.instructions.md",
        "AGENTS.md",
        "CLAUDE.md",
        "docs/features/templates/policy_audit/AGENTS.md",
        "extensions/drm-copilot/resources/codex-and-agents-customizations/AGENTS.md",
        "extensions/drm-copilot/resources/templates/policy_audit/AGENTS.md",
        "tests/fixtures/codex_native_converter/claude/CLAUDE.md",
        "virtual/apply-artifacts-debug/proposed-tree/AGENTS.md",
        "virtual/debug-artifacts-2/proposed-tree/AGENTS.md",
        "virtual/debug-artifacts-3/proposed-tree/AGENTS.md",
        "virtual/debug-artifacts/proposed-tree/AGENTS.md"
      ],
      "agent_instruction_max_bytes": 52606
    },
    "dependencies": {
      "manifests": [
        "package.json",
        "pyproject.toml"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm",
        "pypi"
      ],
      "dependencies": [
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.29.0"
        },
        {
          "name": "typer",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.9.0"
        },
        {
          "name": "PyYAML",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=6.0"
        },
        {
          "name": "numpy",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.23"
        },
        {
          "name": "click",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=8.1"
        },
        {
          "name": "pandas",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.0"
        },
        {
          "name": "scikit-learn",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.3"
        },
        {
          "name": "scipy",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.10"
        },
        {
          "name": "requests",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.31"
        },
        {
          "name": "beautifulsoup4",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=4.12"
        },
        {
          "name": "lxml",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=5.3.0"
        },
        {
          "name": "pyarrow",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=15.0"
        },
        {
          "name": "pdfplumber",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.10.0"
        },
        {
          "name": "tensorflow",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.10.0"
        },
        {
          "name": "joblib",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.1.0"
        },
        {
          "name": "nltk",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=3.8"
        },
        {
          "name": "keras-preprocessing",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.1"
        },
        {
          "name": "openai",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.40.0"
        },
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "extensions/drm-copilot/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.29.0"
        },
        {
          "name": "@modelcontextprotocol/sdk",
          "manifest": "packages/mcp-server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.29.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 2,
        "merged_prs": 242,
        "open_issues": 28,
        "closed_ratio": 0.817,
        "closed_issues": 125,
        "closed_unmerged_prs": 6
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "drmoisan",
          "commits": 873,
          "avatar_url": "https://avatars.githubusercontent.com/u/54180981?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "_build-check.yml",
        "_docs-validation.yml",
        "_drm-copilot-extension-tests.yml",
        "_npm-audit-gate.yml",
        "_poshqc.yml",
        "_quality-checks.yml",
        "_security-scan.yml",
        "_shell-coverage.yml",
        "ci.yml",
        "npm-audit-gate.yml",
        "publish-extension.yml",
        "publish-mcp-npm.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        "eslint.config.mjs"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json",
        "poetry.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 4,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 8,
            "reason": "8 out of 9 merged PRs checked by a CI test -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/8 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 2,
            "reason": "dependency not pinned by hash detected -- score normalized to 2",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "54 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "a9cea834fcf381d1d94a147dcb45fd101538105c",
        "ran_at": "2026-07-23T11:14:41Z",
        "aggregate_score": 4.7,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T00:20:02Z",
      "oldest_open_prs": [
        {
          "number": 400,
          "created_at": "2026-07-22T13:38:51Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 403,
          "created_at": "2026-07-23T02:31:38Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-23T00:17:34Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 3,
          "created_at": "2026-02-02T14:36:47Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 5,
          "created_at": "2026-02-02T14:38:40Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 7,
          "created_at": "2026-02-04T17:06:19Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 182,
          "created_at": "2026-06-13T23:59:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 183,
          "created_at": "2026-06-13T23:59:46Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 184,
          "created_at": "2026-06-13T23:59:47Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 303,
          "created_at": "2026-07-04T16:44:48Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 335,
          "created_at": "2026-07-09T13:45:18Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 336,
          "created_at": "2026-07-09T13:45:20Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 337,
          "created_at": "2026-07-09T13:45:22Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 338,
          "created_at": "2026-07-09T13:46:26Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 343,
          "created_at": "2026-07-10T20:54:20Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 359,
          "created_at": "2026-07-17T18:02:39Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 360,
          "created_at": "2026-07-17T18:03:09Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 361,
          "created_at": "2026-07-17T18:03:16Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 362,
          "created_at": "2026-07-17T18:05:31Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 363,
          "created_at": "2026-07-17T18:34:36Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 364,
          "created_at": "2026-07-17T18:36:51Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 365,
          "created_at": "2026-07-17T18:37:50Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 366,
          "created_at": "2026-07-17T18:38:12Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/drmoisan/drm-copilot",
    "host": "github.com",
    "name": "drm-copilot",
    "owner": "drmoisan"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 59,
      "inputs": {
        "security": 47,
        "vitality": 81,
        "community": 32,
        "governance": 53,
        "engineering": 74
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 81,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "commits_last_year": 896,
              "human_commit_share": 0.99,
              "days_since_last_push": 0,
              "active_weeks_last_year": 19
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "19/52 weeks with commits",
                "points": 13.2,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 19
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "896 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 896
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "releases_count": 22,
              "latest_release_tag": "v1.0.17",
              "releases_from_tags": true,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 1.4
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "22 version tags (no GitHub releases)",
                "points": 16.2,
                "status": "partial",
                "details": [
                  {
                    "code": "version_tags_no_releases",
                    "params": {
                      "count": 22
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~1.4 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 1.4
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 32,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 56,
            "inputs": {
              "packages": [
                "@danmoisan/drm-copilot-mcp"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 2218
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,218 downloads/month across npm",
                "points": 44.6,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2218,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 53,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "merged_prs": 242,
              "open_issues": 28,
              "closed_issues": 125,
              "issue_closed_ratio": 0.817,
              "closed_unmerged_prs": 6
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "82% of issues closed",
                "points": 38.2,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 82
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "242/248 decided PRs merged",
                "points": 37.3,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 242,
                      "decided": 248
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/8 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 44,
            "inputs": {
              "followers": 5,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "drmoisan",
              "public_repos": 11,
              "account_age_days": 2532
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "5 followers of drmoisan",
                "points": 5.6,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 5,
                      "login": "drmoisan"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "11 public repos, account ~6 yr old",
                "points": 19.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 11
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 6
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@danmoisan/drm-copilot-mcp"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "15 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 15
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 74,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "12 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 12
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.mjs",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "8 out of 9 merged PRs checked by a CI test -- score normalized to 8",
                "points": 16,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 65,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 47,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 47,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 4.7
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "8 out of 9 merged PRs checked by a CI test -- score normalized to 8",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/8 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 30 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 1,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "54 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 76,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.99,
              "agent_instruction_files": [
                ".github/copilot-instructions.md",
                ".github/instructions/csharp-code-change.instructions.md",
                ".github/instructions/csharp-unit-test.instructions.md",
                ".github/instructions/general-code-change.instructions.md",
                ".github/instructions/general-unit-test.instructions.md",
                ".github/instructions/github-actions-ci-cd-best-practices.instructions.md",
                ".github/instructions/github-actions.instructions.md",
                ".github/instructions/powershell-code-change.instructions.md",
                ".github/instructions/powershell-unit-test.instructions.md",
                ".github/instructions/python-code-change.instructions.md",
                ".github/instructions/python-suppressions.instructions.md",
                ".github/instructions/python-unit-test.instructions.md",
                ".github/instructions/self-explanatory-code-commenting.instructions.md",
                ".github/instructions/tonality.instructions.md",
                ".github/instructions/typescript-code-change.instructions.md",
                ".github/instructions/typescript-suppressions.instructions.md",
                ".github/instructions/typescript-unit-test.instructions.md",
                "AGENTS.md",
                "CLAUDE.md",
                "docs/features/templates/policy_audit/AGENTS.md",
                "extensions/drm-copilot/resources/codex-and-agents-customizations/AGENTS.md",
                "extensions/drm-copilot/resources/templates/policy_audit/AGENTS.md",
                "tests/fixtures/codex_native_converter/claude/CLAUDE.md",
                "virtual/apply-artifacts-debug/proposed-tree/AGENTS.md",
                "virtual/debug-artifacts-2/proposed-tree/AGENTS.md",
                "virtual/debug-artifacts-3/proposed-tree/AGENTS.md",
                "virtual/debug-artifacts/proposed-tree/AGENTS.md"
              ],
              "agent_instruction_max_bytes": 52606
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": ".github/copilot-instructions.md, .github/instructions/csharp-code-change.instructions.md, .github/instructions/csharp-unit-test.instructions.md, .github/instructions/general-code-change.instructions.md, .github/instructions/general-unit-test.instructions.md, .github/instructions/github-actions-ci-cd-best-practices.instructions.md, .github/instructions/github-actions.instructions.md, .github/instructions/powershell-code-change.instructions.md, .github/instructions/powershell-unit-test.instructions.md, .github/instructions/python-code-change.instructions.md, .github/instructions/python-suppressions.instructions.md, .github/instructions/python-unit-test.instructions.md, .github/instructions/self-explanatory-code-commenting.instructions.md, .github/instructions/tonality.instructions.md, .github/instructions/typescript-code-change.instructions.md, .github/instructions/typescript-suppressions.instructions.md, .github/instructions/typescript-unit-test.instructions.md, AGENTS.md, CLAUDE.md, docs/features/templates/policy_audit/AGENTS.md, extensions/drm-copilot/resources/codex-and-agents-customizations/AGENTS.md, extensions/drm-copilot/resources/templates/policy_audit/AGENTS.md, tests/fixtures/codex_native_converter/claude/CLAUDE.md, virtual/apply-artifacts-debug/proposed-tree/AGENTS.md, virtual/debug-artifacts-2/proposed-tree/AGENTS.md, virtual/debug-artifacts-3/proposed-tree/AGENTS.md, virtual/debug-artifacts/proposed-tree/AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".github/copilot-instructions.md, .github/instructions/csharp-code-change.instructions.md, .github/instructions/csharp-unit-test.instructions.md, .github/instructions/general-code-change.instructions.md, .github/instructions/general-unit-test.instructions.md, .github/instructions/github-actions-ci-cd-best-practices.instructions.md, .github/instructions/github-actions.instructions.md, .github/instructions/powershell-code-change.instructions.md, .github/instructions/powershell-unit-test.instructions.md, .github/instructions/python-code-change.instructions.md, .github/instructions/python-suppressions.instructions.md, .github/instructions/python-unit-test.instructions.md, .github/instructions/self-explanatory-code-commenting.instructions.md, .github/instructions/tonality.instructions.md, .github/instructions/typescript-code-change.instructions.md, .github/instructions/typescript-suppressions.instructions.md, .github/instructions/typescript-unit-test.instructions.md, AGENTS.md, CLAUDE.md, docs/features/templates/policy_audit/AGENTS.md, extensions/drm-copilot/resources/codex-and-agents-customizations/AGENTS.md, extensions/drm-copilot/resources/templates/policy_audit/AGENTS.md, tests/fixtures/codex_native_converter/claude/CLAUDE.md, virtual/apply-artifacts-debug/proposed-tree/AGENTS.md, virtual/debug-artifacts-2/proposed-tree/AGENTS.md, virtual/debug-artifacts-3/proposed-tree/AGENTS.md, virtual/debug-artifacts/proposed-tree/AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "98 of 99 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 98,
                      "sampled": 99
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 74,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json",
                "poetry.lock"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": true,
              "has_linter_config": true,
              "typecheck_configs": [
                "extensions/drm-copilot/tsconfig.json",
                "packages/mcp-server/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0.55,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.01
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.mjs",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.mjs"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "extensions/drm-copilot/tsconfig.json, packages/mcp-server/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "extensions/drm-copilot/tsconfig.json, packages/mcp-server/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "devcontainer, Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "devcontainer, Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "55 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 55,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "1 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 1,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "good",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "primary_language": "Python",
              "largest_source_bytes": 35309,
              "source_files_sampled": 686,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Python with type-check config (extensions/drm-copilot/tsconfig.json, packages/mcp-server/tsconfig.json, tsconfig.json)",
                "points": 27,
                "status": "partial",
                "details": [
                  {
                    "code": "typecheck_config_language",
                    "params": {
                      "files": "extensions/drm-copilot/tsconfig.json, packages/mcp-server/tsconfig.json, tsconfig.json",
                      "language": "Python"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/686 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 686,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "moderate",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Could not fetch npm package 'drm-copilot' from its registry",
    "Could not fetch pypi package 'drm-copilot' from its registry",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index npm:@danmoisan/drm-copilot-mcp@1.0.17; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T11:15:00.483561Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/d/drmoisan/drm-copilot.svg",
  "full_name": "drmoisan/drm-copilot",
  "license_state": "standard",
  "license_spdx": "MIT"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计npm.