公开记录
软件健康报告模式 0.23.0 · 指标 1.13.0 · 2026-07-21 16:42 UTC

edge-base / edgebase

TypeScriptMIT★ 7 星标⑂ 2 复刻始于 2026年3月在 GitHub 上查看 ↗

edge-base/edgebase 的健康指数为 100 分中的 66 分,处于「中等」区间。 其得分最高的类别是AI Readiness(93/100),最低的是Sustainability & Governance(53/100)。 最近一次更新在 2 天前。 近期的大部分工作由 1 位贡献者完成。

66
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

66
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

edge-base组织
2 关注者8 个公开仓库始于 2026年3月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布标签
npm@edge-base/cli0.4.92,620314 天前edgebaseclibaasbackendcloudflare-workers
npm@edge-base/server0.4.92,699314 天前edgebaseruntimeservercloudflare-workers
npm@edge-base/shared0.4.93,819314 天前edgebasesharedconfigfunctions
npmcreate-edgebase0.4.92,283324 天前edgebasecreate-edgebasescaffoldcli

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

81良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 2 天前
4.8/36提交节奏 — 52 周中有 7 周有提交
18/18提交量 — 最近一年 397 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year397
human_commit_share0.93
days_since_last_push2
active_weeks_last_year7

发布纪律

100优秀
评分方式
27/27有发布版本 — 已发布 16 个发布版本
36/36发布时效 — 最近一次发布版本于 4 天前
27/27发布节奏 — 约每 11 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count16
latest_release_tagv0.4.9
releases_from_tags
days_since_latest_release4
mean_days_between_releases11
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

54中等 · 占总体的 18%
评分方式
12.6/60星标 — 7 个星标
0/25复刻 — 2 个复刻
0/15关注者 — 0 位关注者
所用输入
forks2
stars7
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonbelow_threshold

社区健康

92优秀
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(MIT)
18/18CONTRIBUTING 指南
13.5/13.5行为准则
0/7.2议题模板
6.3/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
54.1/80月度下载量 — npm 合计每月 11,421 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packages@edge-base/cli, @edge-base/server, @edge-base/shared, create-edgebase
dependents
ecosystemsnpm
total_downloads
monthly_downloads11,421
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

53中等 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
1.8/22.5提交分布 — 头号贡献者编写了 92% 的提交
2.7/13.5贡献者广度 — 2 位贡献者
0/10OpenSSF Scorecard:Contributors — project has 0 contributing companies or organizations -- score normalized to 0
所用输入
bus_factor1
contributors_sampled2
top_contributor_share0.92
评分方式
42.5/46.8议题解决 — 91% 的议题已关闭
32.2/38.3PR 接受 — 已裁定的 PR 中 53/63 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/24 approved changesets -- score normalized to 0
所用输入
merged_prs53
open_issues1
closed_issues10
issue_closed_ratio0.909
closed_unmerged_prs10
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
3.4/25所有者影响力 — edge-base 有 2 位关注者
7.6/25既往记录 — 8 个公开仓库,账户约 0 年
所用输入
followers2
owner_typeOrganization
is_verified
owner_loginedge-base
public_repos8
account_age_days128
评分方式
25/25已发布且可解析 — npm 上有 4 个软件包
35/35发布时效 — 最近一次发布于 4 天前
20/20版本历史 — 32 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packages@edge-base/cli, @edge-base/server, @edge-base/shared, create-edgebase
ecosystemsnpm
any_deprecated
min_days_since_publish4

工程质量

基础的工程与文档实践是否到位?

72良好 · 占总体的 20%

工程实践

84良好
评分方式
24/24CI 工作流 — 11 个工作流
24/24存在测试
16/16Linter 配置 — eslint.config.js
0/9.6Pre-commit 钩子
0/6.4.editorconfig
20/20OpenSSF Scorecard:CI-Tests — 1 out of 1 merged PRs checked by a CI test -- score normalized to 10
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

55中等
评分方式
30/30README
25/25文档目录
0/15文档 / 主页站点
0/10仓库描述
0/10主题标签
0/10Wiki
所用输入
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

73良好 · 占总体的 16%

安全态势

73良好
评分方式
6.8/7.5Binary-Artifacts — binaries present in source code
0/7.5Branch-Protection — 无数据
2.5/2.5CI-Tests — 1 out of 1 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/24 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — 无数据
4/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — 无数据
6/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 30 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated15
scorecard_versionv5.5.0
checks_inconclusive3
scorecard_aggregate7.3
已排除计分(无数据或不适用):branch_protection, packaging, signed_releases。 其余权重已重新归一化。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

93优秀 · 占总体的 0%
评分方式
45/45代理指令 — AGENT.md, AGENTS.md, CLAUDE.md
15/15机器可读文档(llms.txt) — 存在 llms.txt
40/40可读的提交历史 — 93 次人类提交中有 78 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.839
agent_instruction_filesAGENT.md, AGENTS.md, CLAUDE.md
agent_instruction_max_bytes5,111
评分方式
12.6/18一条命令的引导启动 — packages/sdk/csharp/packages/admin/EdgeBase.Admin.csproj, packages/sdk/csharp/packages/admin/tests/EdgeBase.Admin.Tests.csproj, packages/sdk/csharp/packages/core/EdgeBase.Core.csproj(工具链约定,无任务运行器)
22/22自动化测试
11/11Lint / 格式化配置 — eslint.config.js
11/11静态类型检查 — docs/tsconfig.json, packages/admin/tsconfig.json, packages/cli/tsconfig.json, packages/plugins/core/tsconfig.json, packages/sdk/js/packages/admin/tsconfig.json, packages/sdk/js/packages/auth-ui-react/tsconfig.json, packages/sdk/js/packages/core/tsconfig.json, packages/sdk/js/packages/ssr/tsconfig.json, packages/sdk/js/packages/web/tsconfig.json, packages/sdk/js/tsconfig.json, packages/sdk/react-native/tsconfig.json, packages/server/tsconfig.json, packages/shared/tsconfig.json
10/10可复现环境 — Dockerfile, lockfile
10/10已体现的代理实践 — 最近 100 次提交中有 37 次由代理编写或署名代理
5/8自动化维护 — 已配置依赖自动化,但在抽样提交中未观察到
8/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 8
所用输入
has_nix
has_tests
lockfilesmix.lock, pnpm-lock.yaml, yarn.lock
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configsdocs/tsconfig.json, packages/admin/tsconfig.json, packages/cli/tsconfig.json, packages/plugins/core/tsconfig.json, packages/sdk/js/packages/admin/tsconfig.json, packages/sdk/js/packages/auth-ui-react/tsconfig.json, packages/sdk/js/packages/core/tsconfig.json, packages/sdk/js/packages/ssr/tsconfig.json, packages/sdk/js/packages/web/tsconfig.json, packages/sdk/js/tsconfig.json, packages/sdk/react-native/tsconfig.json, packages/server/tsconfig.json, packages/shared/tsconfig.json
agent_commit_share0.37
toolchain_manifestspackages/sdk/csharp/packages/admin/EdgeBase.Admin.csproj, packages/sdk/csharp/packages/admin/tests/EdgeBase.Admin.Tests.csproj, packages/sdk/csharp/packages/core/EdgeBase.Core.csproj, packages/sdk/csharp/packages/unity/EdgeBase.Unity.csproj, packages/sdk/csharp/packages/unity/tests/EdgeBase.Unity.Tests.csproj, packages/sdk/csharp/src/EdgeBase.csproj, packages/sdk/csharp/tests/EdgeBase.Tests.csproj, packages/sdk/elixir/packages/admin/mix.exs, packages/sdk/elixir/packages/core/mix.exs, packages/sdk/go/go.mod, packages/sdk/java/build.gradle, packages/sdk/java/packages/admin/build.gradle, packages/sdk/java/packages/android/build.gradle, packages/sdk/java/packages/core/build.gradle, packages/sdk/kotlin/admin/build.gradle.kts, packages/sdk/kotlin/build.gradle.kts, packages/sdk/kotlin/client/build.gradle.kts, packages/sdk/kotlin/core/build.gradle.kts, packages/sdk/rust/Cargo.toml, packages/sdk/rust/packages/admin/Cargo.toml, packages/sdk/rust/packages/core/Cargo.toml, packages/sdk/scala/build.gradle.kts, packages/sdk/scala/packages/admin/build.gradle.kts, packages/sdk/scala/packages/core/build.gradle.kts
dependency_bot_commit_share0
评分方式
45/45可类型检查的代码 — TypeScript(静态类型)
53.7/55可控的文件大小 — 采样的 1,183 个源文件中有 28 个超过 60KB
所用输入
primary_languageTypeScript
largest_source_bytes205,754
source_files_sampled1,183
oversized_source_files28
评分方式
40/40API 模式(OpenAPI/GraphQL/proto) — packages/server/openapi.json
0/20MCP 服务器
40/40可运行示例 — example
所用输入
example_dirsexample
has_mcp_signal
api_schema_filespackages/server/openapi.json

关键数据

7GitHub 星标
2贡献者
397最近 12 个月提交数
2距最近推送天数
16发布版本数
1巴士系数(bus factor)
1开放议题
npm软件包生态系统数

数据采集警告

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index npm:@edge-base/cli@0.4.9; advisories assessed against the repository dependency graph instead

更多细节

Star 与 Fork 历史 7 ★ / 2 ⇿
7Star
2Fork
7发布

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

12345677242026-032026-042026-05
主版本 0次版本 0修订 7
OpenSSF Scorecard 7.3 / 10
7.3综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-21 16:42 UTC

9Binary-Artifactsbinaries present in source code
不适用Branch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests1 out of 1 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/24 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
不适用Packagingpackaging workflow not detected
8Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 8
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
不适用Signed-Releasesno releases found
8Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities30 existing vulnerabilities detected
直接依赖 23
注册表软件包版本约束清单文件
npm@edge-base/serverworkspace:*packages/cli/package.json
npm@edge-base/sharedworkspace:*packages/cli/package.json
npmchalk^5.4.0packages/cli/package.json
npmcommander^13.1.0packages/cli/package.json
npmesbuild^0.28.1packages/cli/package.json
npmjose^6.0.0packages/cli/package.json
npmora^9.3.0packages/cli/package.json
npmpg^8.16.3packages/cli/package.json
npmtsx^4.20.6packages/cli/package.json
npmts-morph^27.0.2packages/cli/package.json
npmwrangler4.103.0packages/cli/package.json
npm@edge-base/cliworkspace:*packages/create-edgebase/package.json
npm@edge-base/coreworkspace:*packages/server/package.json
npm@edge-base/sharedworkspace:*packages/server/package.json
npm@hono/zod-openapi^1.2.2packages/server/package.json
npm@simplewebauthn/server^10packages/server/package.json
npmbcryptjs^3.0.3packages/server/package.json
npmhono4.12.25packages/server/package.json
npmjose^6.0.0packages/server/package.json
npmpg^8.16.3packages/server/package.json
npmzod^4.3.6packages/server/package.json
npmtsx^4.0.0tools/sdk-codegen/package.json
npmtsx^4.0.0tools/smoke-gen/package.json
全部依赖 未采集

本报告未能采集到解析后的依赖集合:GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 8540,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "C": 6659,
        "C#": 626931,
        "Go": 292523,
        "C++": 538403,
        "CSS": 13727,
        "PHP": 350929,
        "Dart": 517797,
        "HTML": 447,
        "Java": 622348,
        "Ruby": 165470,
        "Rust": 338271,
        "CMake": 21561,
        "Scala": 37091,
        "Shell": 41210,
        "Swift": 468704,
        "Elixir": 60889,
        "Kotlin": 604989,
        "Python": 318948,
        "Svelte": 629149,
        "Dockerfile": 3587,
        "JavaScript": 417077,
        "PowerShell": 3298,
        "TypeScript": 9170822,
        "Go Template": 4771,
        "Objective-C++": 15873
      },
      "pushed_at": "2026-07-19T13:48:31Z",
      "created_at": "2026-03-15T08:14:59Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-17T00:14:29Z",
      "description": null,
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "Organization",
      "login": "edge-base",
      "company": null,
      "location": null,
      "followers": 2,
      "avatar_url": "https://avatars.githubusercontent.com/u/268324515?v=4",
      "created_at": "2026-03-15T08:07:20Z",
      "is_verified": null,
      "public_repos": 8,
      "account_age_days": 128
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.4.9",
          "kind": "patch",
          "published_at": "2026-07-17T00:15:22Z"
        },
        {
          "tag": "v0.4.8",
          "kind": "patch",
          "published_at": "2026-07-16T00:21:10Z"
        },
        {
          "tag": "v0.4.7",
          "kind": "patch",
          "published_at": "2026-07-15T15:24:35Z"
        },
        {
          "tag": "v0.4.6",
          "kind": "patch",
          "published_at": "2026-07-14T12:39:06Z"
        },
        {
          "tag": "v0.4.5",
          "kind": "patch",
          "published_at": "2026-07-14T05:28:07Z"
        },
        {
          "tag": "v0.3.5",
          "kind": "patch",
          "published_at": "2026-07-08T20:49:35Z"
        },
        {
          "tag": "v0.3.3",
          "kind": "patch",
          "published_at": "2026-07-08T02:43:59Z"
        },
        {
          "tag": "v0.3.2",
          "kind": "patch",
          "published_at": "2026-07-07T12:17:28Z"
        },
        {
          "tag": "v0.3.1",
          "kind": "patch",
          "published_at": "2026-07-03T09:05:06Z"
        },
        {
          "tag": "v0.2.9",
          "kind": "patch",
          "published_at": "2026-04-08T23:06:18Z"
        },
        {
          "tag": "v0.2.8",
          "kind": "patch",
          "published_at": "2026-04-04T06:52:31Z"
        },
        {
          "tag": "v0.2.7",
          "kind": "patch",
          "published_at": "2026-03-29T13:52:34Z"
        },
        {
          "tag": "v0.2.4",
          "kind": "patch",
          "published_at": "2026-03-24T23:27:33Z"
        },
        {
          "tag": "v0.2.3",
          "kind": "patch",
          "published_at": "2026-03-24T01:52:17Z"
        },
        {
          "tag": "v0.2.2",
          "kind": "patch",
          "published_at": "2026-03-23T09:15:57Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2026-03-23T07:10:37Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "38e0ba236bb395a079f0fc42ff1a513a710263a7",
          "body": null,
          "is_bot": false,
          "headline": "release: prepare 0.4.9",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-17T00:07:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f27bc14e65fdde54b002e138cd0639757bece16",
          "body": null,
          "is_bot": false,
          "headline": "release: prepare 0.4.8",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-15T23:48:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ca773bbc89a13b04a07783e0541ecee97e263a78",
          "body": null,
          "is_bot": false,
          "headline": "Merge 0.4.7 server fixes",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-15T15:21:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f5a4cf661d2425eb674fbd942d7c0b2163d87f0",
          "body": null,
          "is_bot": false,
          "headline": "fix(server): reconcile SQLite uniqueness and signed HEAD",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-15T15:21:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9528017dccde3a0bb5d5a41ffdedf1a65658b354",
          "body": null,
          "is_bot": false,
          "headline": "test: make local CI opt-in and responsive",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-15T15:17:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "05877bdfe8cefc91a930e12b682166e902a59b4c",
          "body": null,
          "is_bot": false,
          "headline": "test: keep app bundle checks responsive",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-15T13:15:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "afb5a7ba6cd554a1d16484ab41a186ef57c7272d",
          "body": null,
          "is_bot": false,
          "headline": "ci: add focused npm release gate",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-15T11:45:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4e726a82e6d62d06fb90d399defe2a919e70811a",
          "body": null,
          "is_bot": false,
          "headline": "test: keep CLI telemetry checks nonblocking",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-15T11:29:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c515aaa50d70156bdccbb50af0d3128d42c3a581",
          "body": null,
          "is_bot": false,
          "headline": "test: keep CLI workers responsive during packaging",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-15T10:38:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "90320e7d2c5d8cf15c163cc84fb0d1dbcbd34650",
          "body": null,
          "is_bot": false,
          "headline": "test: extend local CLI packaging timeout",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-15T09:50:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1a3af133cc7fa4f8b6dd6f913f4a45e5a0921e51",
          "body": null,
          "is_bot": false,
          "headline": "test: allow slow local CLI packaging",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-15T09:48:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3ac68298b2e8e47efa417f3a5a2074e8853b159",
          "body": null,
          "is_bot": false,
          "headline": "test: extend isolated local CI timeouts",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-15T09:44:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "70745ef7ecee67372bca546c4e03bfd9e3a914ee",
          "body": null,
          "is_bot": false,
          "headline": "perf(ci): cache pnpm stores in Docker volumes",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-15T08:59:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a18f318761c51608a9044b7ef4332e6f7243e08",
          "body": null,
          "is_bot": false,
          "headline": "fix(ci): keep release gates operational",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-15T08:46:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "509b98b4250ab7669676d264735a975722a3481d",
          "body": null,
          "is_bot": false,
          "headline": "test: tolerate slow isolated Linux checks",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-15T06:44:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ce47b0ea56b7d0d7666b6e3ff2a77a2d3429c5f7",
          "body": null,
          "is_bot": false,
          "headline": "Release EdgeBase 0.4.7",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-15T04:23:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8ab5607e84d5937b03ffd774e1a2fd50de36127d",
          "body": null,
          "is_bot": false,
          "headline": "docs(functions): document background work context",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-15T04:20:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bd4d204ddef56649803c0a52b7916f0d53097daf",
          "body": null,
          "is_bot": false,
          "headline": "feat(server): enrich function runtime contracts",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-15T04:19:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f2f2026596a832798f0d83abeb411b473dea7aa",
          "body": null,
          "is_bot": false,
          "headline": "fix(web): coalesce same-tab session refreshes",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-15T04:19:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de41c621944de8b3289a65e197e776cd9ee96449",
          "body": null,
          "is_bot": false,
          "headline": "fix(cli): harden live refresh and slow startup",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-15T04:19:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "97cffd805b74d769e7c68f8c256ca45a923f6b2b",
          "body": null,
          "is_bot": false,
          "headline": "refactor(web): model room connection lifecycle",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-14T23:47:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "71344a672fee186acc638d7acee7c093ad543a76",
          "body": null,
          "is_bot": false,
          "headline": "fix(web): preserve room reconnect backoff until sync",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-14T20:54:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0367ca2091d2b055e461c85f9ce0865afcdbb62",
          "body": null,
          "is_bot": false,
          "headline": "Release EdgeBase 0.4.6",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-14T12:37:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24dd2e6f4c03d497548f492634f68618f4810563",
          "body": "Release EdgeBase 0.4.5",
          "is_bot": false,
          "headline": "Merge pull request #81 from edge-base/codex/edgebase-0.4.5-release-ci",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-14T05:26:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e811f8d8bc70f4292f6d31e889b5eda7202383d9",
          "body": null,
          "is_bot": false,
          "headline": "Align mutation checks with configured targets",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-14T03:56:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fba85707fdb3f3e9cb83c7ea12355e27f4e0ece1",
          "body": null,
          "is_bot": false,
          "headline": "Preserve mutation coverage in the local gate",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-14T03:46:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ccdac6af128f41124ac81807f7f41b3bd6ffdfe",
          "body": null,
          "is_bot": false,
          "headline": "Keep the local Linux gate sequential",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-14T03:27:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7643fb798ba3e2ca79f36b0d0fe7f9c9179684c2",
          "body": null,
          "is_bot": false,
          "headline": "Scale server test deadlines under local emulation",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-14T03:08:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "94e8a536321a6d9cb2c0389e3fddba57d4f3d515",
          "body": null,
          "is_bot": false,
          "headline": "Use native Trivy under local emulation",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-14T02:59:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0aad074b88c5c3698e7e31e510dbb8f06d2c122f",
          "body": null,
          "is_bot": false,
          "headline": "Make local Trivy scans tokenless",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-14T02:46:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad171072de3e8be503e5d49318601045477ddbd2",
          "body": null,
          "is_bot": false,
          "headline": "Document additional EdgeBase 0.4.5 changes",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-14T02:29:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8da3f19d1455e520784787e208eefd13e6434413",
          "body": null,
          "is_bot": false,
          "headline": "Add request deadlines and live fan-out safeguards",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-14T02:29:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "feadb110c9c214a1e7863e99cd94cc1ca518bdc3",
          "body": null,
          "is_bot": false,
          "headline": "Fix local release gate isolation",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-14T02:08:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "984a908cdef45ba228567f26783ff5b875339efe",
          "body": null,
          "is_bot": false,
          "headline": "Prepare EdgeBase 0.4.5 release",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-14T01:45:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7014cf2912cb419230483c97df83de487497bed0",
          "body": "* Release EdgeBase 0.4.4 Docker self-hosting\n\nAdd context-only Docker packaging, project docker-context support, public CA and automatic data volume defaults, and an explicit self-hosted localhost cookie opt-in. Synchronize the 0.4.4 release graph and changelogs.\n\n* Harden Dependabot update cooldown\n[…]\n\n\n* Drop Windows runners from hosted CI\n\n* Remove stale Win64 CI dependencies\n\n* Fix cookie refresh lock takeover\n\n---------\n\nCo-authored-by: june lee <21379657+melodysdreamj@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Release EdgeBase 0.4.4 Docker self-hosting (#79)",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-13T13:40:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4ca5b50af2ec6a19d12b564a33a600561d17abf6",
          "body": "The only shipped-code change: the C++ SDK's AuthClient::adoptAuthTokens rejected\nany auth response carrying an accessToken without a refreshToken as an\n\"incomplete replacement token pair\" (ok=false). But the server legitimately\nreturns access-token-only on a displayName change — the name is embedded\n[…]\nRemaining red CI is Windows-only (Node/JS/Python e2e on Windows,\npack smoke, C++ Unreal Win64) plus the two contract gates that aggregate them.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Version 0.4.3: fix C++ SDK updateProfile access-token-only adoption",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-12T22:37:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4af7338dabbed0c9a46cf591d1d64dc1f1c3339f",
          "body": "…sessions\n\nThe test revoked sessionsAfterSecondSignIn.last(), which can be this client's own\nsession (changePassword had re-issued exactly one session for it) — revoking it\ninvalidates the caller's token, so the follow-up listSessions threw EdgeBaseError.\nCapture the client's own session id and revoke a different one, matching the JS\nand Flutter SDK fixes. (Verified via CI — local Gradle reproduction was blocked.)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(sdk-kotlin): revoke a non-current session in changePassword_and_…",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-12T14:52:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "c5e39840fc0c10f977ccfe79edae9a1fc48eacb0",
          "body": "IosUnitTests.swift used `XCTAssertEqual(await ...)` etc. in 13 places, but Swift\nautoclosures (which XCTAssert* take) cannot contain `await`, so the ios test\ntarget failed to compile (\"await in an autoclosure that does not support\nconcurrency\"). Bind each awaited value to a `let` first, then assert. Mechanical\nfix; verified no XCTAssert-with-await lines remain. (Verified via CI — full Xcode\nis unavailable locally.)\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(sdk-swift): extract awaited values before XCTAssert (compile fix)",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-12T14:52:30Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b742103e6ed380434a889b956f973b3b84456a2a",
          "body": "…storage\n\nThe anonymous → link-with-email e2e used MemoryTokenStorage, but anonymous\naccount upgrades require a DurableTokenStorage (0.4.0: replacement tokens must\nsurvive a lost response), so linkWithEmail threw \"Anonymous account upgrades\nrequire durable ... storage\" — correct SDK behavior, wrong \n[…]\nhat the server accepts an anon token on /auth/link/email, confirming this is a\ntest-config issue, not an SDK/server bug. Flutter e2e now 62/62.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(sdk-flutter): back the anonymous-upgrade e2e with durable token …",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-12T14:46:36Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "84b346c58667743466e48260dfcfb8f53f98dc01",
          "body": "The Flutter revokeSession e2e revoked sessions.last, which can be this client's\nown session — revoking it invalidates the caller's token, so the follow-up\nlistSessions failed with TOKEN_INVALID. Capture the client's own session id up\nfront and revoke a different one, matching the JS SDK fix. Also document the\nverified flutter test:e2e command in dev/testing/sdk-e2e.md.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(sdk-flutter): revoke a non-current session in the revokeSession e2e",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-12T14:34:27Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4e2df6708092a16e059c7fc36924c08a76fe9f15",
          "body": "Document the per-language SDK E2E harness — run-with-services commands, the\ntoolchain matrix, the EDGEBASE_E2E_REQUIRED / gradle-daemon / localhost-vs-\n127.0.0.1 gotchas, and the Windows-only jobs that cannot be reproduced off a\nWindows runner. Allowlist dev/testing/ in .gitignore (like dev/release/) and\nlink the doc from AGENT.md (Testing) and CONTRIBUTING.md (Development).\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: add dev/testing/sdk-e2e.md for local SDK E2E reproduction",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-12T14:21:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2eeabe259cada06dd01293df9b608cd7d60be3eb",
          "body": "…ting them\n\nAuthClient::adoptAuthTokens rejected any response that carried an accessToken\nwithout a refreshToken as an \"incomplete replacement token pair\", setting\nok=false. But the server legitimately returns access-token-only on a displayName\nchange (the name is embedded in the JWT, so it re-issue\n[…]\nefresh token for access-only responses; still reject a refresh-only response.\n\nVerified: C++ core e2e 64/64 pass (was 63/1), unit 132/132 pass.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(sdk-cpp): adopt access-token-only auth refreshes instead of rejec…",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-12T14:20:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d6ad4731740ef9fe74731496658e536cb3aa657c",
          "body": "The AsyncStorage restore E2E persisted the refresh token under the legacy\n'edgebase:refresh-token' key, but 0.4.0 namespaced storage keys as\n'edgebase:<encoded baseUrl>:refresh-token' and deliberately does not migrate\npre-namespace keys. TokenManager.restore() therefore found nothing and left the\nuser null. Persist under the namespaced key the manager actually reads.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(sdk-rn): restore session from the namespaced refresh-token key",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-12T13:31:54Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "26171db2de3f4ecc46c2fcf61cc6684340e4210f",
          "body": "…h callback\n\nTwo cookie-auth-transport unit tests captured the refresh resolver inside a\ngetAccessToken callback, then relied on a fixed setTimeout(45ms) before calling\nit. On slow CI runners (Windows) the callback had not run yet, so resolveRefresh\nwas undefined (\"resolveRefresh is not a function\") — a flaky failure. Await a\nsignal fired from inside the callback instead of guessing a delay.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(sdk-js): make in-flight-refresh cookie tests wait for the refres…",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-12T13:26:37Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9008ba16aa507663cccab6054872326a2f2cbb3d",
          "body": "Two web.e2e.test.ts cases asserted pre-0.4.0 semantics (dead since the file's\ntransform error) and failed once revived:\n- revokeSession revoked the caller's own only session and expected to stay\n  authenticated; revoke a second account session instead.\n- handleOAuthCallback fed a hand-crafted JWT an\n[…]\n and exchanges the refresh\n  token server-side; drive the real flow with a genuine session's tokens.\nAlso drop the now-unused fake-JWT helpers.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(sdk-js): rewrite stale web e2e auth tests for current behavior",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-12T13:05:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2d4a50b0cd40d5eb6c8647d036c20be51a9389da",
          "body": "The E2E config runs in release mode, where auth redirect flows (magic link,\npassword reset, email verify/change) require an explicit\nauth.allowedRedirectUrls allowlist since 0.4.0. The config never set one, so the\nweb auth-verify-loop E2E tests hit \"redirect_url requires auth.allowedRedirectUrls\nin release mode\". Add a same-origin localhost:4173 wildcard covering the test\napp's callback routes.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(server): allow localhost redirect URLs in the E2E config",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-12T13:05:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b61ccfc577d026a6bad2e5fa86e5068054072fe6",
          "body": "resolve-options.test.ts asserted the secrets-file spy was called with a\nhardcoded POSIX path, but resolveOptionalServiceKey builds it via\njoin(projectDir, '.edgebase', 'secrets.json'), which yields backslashes on\nWindows — failing the spy assertion on windows-latest. Build the expected path\nwith join() so it matches on every platform.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli-test): compare resolved secrets path with join() for Windows",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-12T12:40:27Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2e6ed7dc8839fec2274870cf7356837f8b526f74",
          "body": "Two `it(...)` blocks in web.e2e.test.ts used `await client.auth.signInWithOAuth`\ninside a non-async arrow, so esbuild failed the whole suite transform with\n\"await can only be used inside an async function\" (pre-existing since 0.4.0).\nAdd the missing `async`.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(sdk-js-test): mark web OAuth e2e cases async so await is valid",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-12T12:29:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2a52c6133f06681331dbe03cdd4e06742de531ca",
          "body": "The version-bound managed-deploy-secrets tests asserted\n`statSync(path).mode & 0o777 === 0o600`, but NTFS cannot represent POSIX\npermissions and Node reports 0o666 (438) there, failing 5 tests on\nwindows-latest. Skip the owner-only mode assertion on win32, matching the\nexisting guard used for the deploy-manifest permission check.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli-test): guard POSIX 0600 secret-file mode assertions on Windows",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-12T12:29:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "20bc4669a7b2116d3f2f708a562beadb3afde7ff",
          "body": "…ures\n\nThe 0.4.2 release commit added a version-bound managed-deploy-secrets CLI test\nwhose SERVICE_KEY/JWT_USER_SECRET/JWT_ADMIN_SECRET fixtures are synthetic\n\"<16-hex>\".repeat(4) values. Gitleaks flags them as generic-api-key. Add their\nexact fingerprints per the file's fingerprint-specific policy so a genuinely new\ncredential in the same file still fails CI.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(secret-scan): allowlist deterministic hex deploy-secret test fixt…",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-12T12:10:25Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "695c5be0051fe8ed58fd170dfa88214e091c30f8",
          "body": "…e integrity hardening\n\nSecurity hardening release across auth, config export, and the release runtime\nboundary. No public HTTP or SDK API break; language SDKs are metadata-synced to\n0.4.2 only.\n\n- Password sign-in no longer leaks account existence: absent, passwordless, and\n  wrong-password users s\n[…]\nd Content-Length\n  and while streaming.\n\nVerified locally: server unit 2666 passed, CLI 943 passed, release:preflight\n32/32 with no advisories.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Version 0.4.2: auth enumeration, backup redaction, and release runtim…",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-12T11:33:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "af1d32826d0ae58e375d2ab51f274e531c2b36da",
          "body": "The secret-scan workflow and .gitleaksignore added in 0.4.0 missed a fixture in\ntheir own commit: a hand-crafted \"header.<base64 test payload>.signature\" JWT in\npackages/sdk/swift/packages/ios/Tests/IosUnitTests.swift (token-restore unit\ntest). It is a deterministic test value, not a real credential. Add its exact\nfingerprint per the file's fingerprint-specific policy so a genuinely new\ncredential in the same file still fails CI.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(secret-scan): allowlist deterministic fake-JWT iOS test fixture",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-12T06:03:41Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4e9196007d4e88c6262050d4fb8876353f76da0d",
          "body": "Realtime rooms rewrote Durable Object storage on every socket heartbeat: the\nper-room ephemeral-timer blob was persisted unconditionally several times per\nalarm, and the socket liveness check re-armed itself every ~5s while persisting\nan ever-advancing socketHeartbeatCheckAt. An active room therefor\n[…]\ntate\nchanges; a dead socket is still reaped within roughly one stale window. No\npublic API / SDK change. Guarded by room-auth-state-loss tests.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Version 0.4.1: fix RoomsDO per-heartbeat storage write storm",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-12T05:40:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b93d1781d29f1b6ef77ce447d79840e17dab60a0",
          "body": "Bump EdgeBase 0.3.8 -> 0.4.0. A minor (not patch) bump because this release\ncarries backward-incompatible behavior; a patch number would understate the\nupgrade risk for downstream SDK consumers.\n\nBreaking changes:\n- React Native signInWithOAuth() is now async; callers using its { url } must await it\n[…]\n).\n\nVersion stamped across all file-backed SDK targets and doc references; per-SDK\nCHANGELOG headings relabeled to 0.4.0. release:check passes.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Version 0.4.0: security hardening with breaking SDK auth/storage changes",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-12T04:42:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d7c094206190e1998e1a662662a4a5129d91c8d3",
          "body": null,
          "is_bot": false,
          "headline": "docs: codify the fast verification loop",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-10T05:38:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cd15fc4910aa35e10066e9cbfdef121912744bb7",
          "body": null,
          "is_bot": false,
          "headline": "fix: align release assets with the CLI server graph",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-10T05:13:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "64c854c8062eac2e922eaf1fcc9fb86e78c79004",
          "body": null,
          "is_bot": false,
          "headline": "release: harden packaged runtimes for EdgeBase 0.3.8",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-10T05:04:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98d963867d908caf1c0bd71374d39cfaef9c8d4b",
          "body": null,
          "is_bot": false,
          "headline": "release: fix packaged runtimes for EdgeBase 0.3.7",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-10T03:47:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9bd79dd4acc9941bdafe8b6ef1d84d5f547ecf8",
          "body": null,
          "is_bot": false,
          "headline": "ci: install dependencies for release contract checks",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-10T02:05:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c55b13e8d407dd7f078db82065e0ca2ebeaaae39",
          "body": null,
          "is_bot": false,
          "headline": "release: prepare EdgeBase 0.3.6",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-10T02:03:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1efbdbc8bc6f35245b1bed9d88cb5ba2e5d762bf",
          "body": "Full-repo review remediation across server, SDKs, admin, CLI, and infra, plus release 0.3.5.\n\n- Server: room anonymous-auth hardening, schemaless SQL identifier escaping, OAuth redirect wildcard fix + warning, admin login rate-limit + timing, CORS credentials only on exact-origin match, validated Se\n[…]\ns, non-root Docker.\n- CI: pinned all GitHub Actions to SHAs, explicit workflow secrets, shell-injection fix, pnpm supply-chain settings.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)",
          "is_bot": false,
          "headline": "Security & correctness hardening + release 0.3.5 (#69)",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-08T20:47:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d076aea8fa35df947ee80b0171db03fc6f88dd5c",
          "body": "…ky crash)\n\ntest_room_unified_surface_sends_signal_member_and_admin_frames used a fixed\n`Task.sleep(20ms)` and then read `fakeSocket.messages[0/1/2]` by index. The\nsend is async and appends on a different executor, so on a slow/loaded CI runner\nthe append had not landed within 20ms and the index rea\n[…]\nthe message exists (2s cap)\n  and replace the three sleep-then-index reads with it, making the test\n  deterministic regardless of runner speed.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(sdk-swift): make room send-frame test wait deterministically (fla…",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-08T04:41:43Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d5844cc5f94ac2a05db637a5cd6fd8e98162ca4b",
          "body": "…e it\n\nThese modules were previously untested (listed in UNTESTED_LIBS and excluded\nfrom the coverage gate). Add hermetic unit tests (all network/bindings mocked):\n- totp.ts: verifyTOTP window tolerance + invalid/expired codes, recovery codes,\n  encrypt/decrypt round-trips\n- email-provider.ts: facto\n[…]\n/email/sms\nfrom the coverage exclude so the gate now enforces them: branch coverage is\n99% / 100% / 90.6% respectively, global stays at 85.87%.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(server): cover auth-critical TOTP/email/SMS providers and enforc…",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-08T04:08:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "11e7785ec629d85e7e71bb67190ec747f4f60fbf",
          "body": "…tles\n\nThe clamp in _scheduleNextAlarm() stops a past-due setAlarm from wedging the DO,\nbut it does not make the loop terminate: alarm steps 5 (_stateSaveAt, not-dirty\nbranch) and 7 (_socketHeartbeatCheckAt) cleared their ephemeral scalar in memory\nWITHOUT calling syncEphemeralTimersToStorage() — un\n[…]\n a past-due scalar and\nthe room settles to idle.\n\nVerified: all 10 room integration files pass (127 tests) with zero \"Alarm\nexceeded\" warnings.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(room): persist cleared ephemeral timers so the past-due alarm set…",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-08T04:08:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "accb730c160f63d4d955d814352c4db0c3d0e7d9",
          "body": "Bundles the create-edgebase bin restore, the room DO alarm fix, and the\nCI integration-runner timeout. Bumps version to 0.3.3 across all packages,\nSDKs, and versioned references.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: release 0.3.3",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-08T02:43:33Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b028ea4b729635df7fde9aeba3d9271ed2a5a94e",
          "body": "_scheduleNextAlarm() called ctx.storage.setAlarm(earliest) with no lower\nbound. When earliest <= now (a timer restored from storage after hibernation,\nor re-armed during alarm() processing), workerd re-fires the alarm immediately\nwithout yielding the DO input gate. That spins into a tight loop — sur\n[…]\ns pass (127 tests), zero \"Alarm exceeded\"\nwarnings (was 26 on room-hooks alone), and session.onReconnect passes 5/5\nconsecutively with no hang.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(room): never schedule a Durable Object alarm in the past",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-08T02:07:50Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2a69b8776ae40f3821b7d67c3589af60ea8e9171",
          "body": "…d test\n\nA flaky pre-existing hang in room-hooks.test.ts (a Room Durable Object alarm\nthat breaks the workerd runtime so vitest can never exit) left a shard's\nprocess idle forever. The runner's `wait` loops had no timeout, so one wedged\nshard blocked the whole job until GitHub's 6h cap — which is ex\n[…]\n: happy path still 43s/PASS; a forced low timeout fails with exit 1\n(no false pass); ❯ extraction pinpoints the hung file on a real wedged log.\n\nCo-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(ci): stop integration shard runner from hanging for 6h on a wedge…",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-08T00:32:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3a92ab1717d11cf9e4be9fd0bf85ca6f67c9d901",
          "body": "The bin entrypoint (./bin/create-edgebase.js) was caught by the blanket\n`bin/` rule in .gitignore, so it was never committed. It happened to exist\non disk through 0.2.9 but was absent from 0.3.0 onward — every release since\nshipped with no bin, breaking `npm create edgebase@latest`.\n\n- Restore the l\n[…]\n-to-end against the current CLI.\n- Add a .gitignore exception so this hand-written file stays tracked and can\n  never be silently dropped again.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(create-edgebase): restore missing bin entrypoint and track it in git",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-07T23:22:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3b7a5235d18e71cb6c1ca38f903a502ad731b24b",
          "body": "The regenerated smoke report now counts the two transact endpoints;\nupdate the inline snapshot to match (skippedRouteCount stays 0).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: update smoke skip-report snapshot for transact routes (191→193)",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-07T07:13:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "43cd91dff288c428c686975834932d982c934fe8",
          "body": "The openapi.json list operations gained an includeTotal query parameter;\nregenerate the checked-in smoke tests to match (SDK codegen output is\nunchanged — the param does not alter the generated wrappers).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: regenerate smoke tests for includeTotal list param",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-07T06:53:59Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ed43f3d47c817bd18620c9ee861112f377db6d51",
          "body": "…ted provider handlers from the unit coverage gate\n\nAdds mocked-executor unit tests for the PostgreSQL list/get/insert/count/search\nand batch-by-filter update/delete paths.\n\nExcludes d1-handler.ts and postgres-handler.ts from the vitest.unit coverage\ninclude set. Both are provider request handlers v\n[…]\ndo.ts handler already sits outside src/lib/. This aligns the unit\ncoverage gate with genuinely unit-tested code without weakening the threshold.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(server): cover PostgreSQL handler paths; exclude integration-tes…",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-07T06:50:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "faf2619326f33082add6b83d13fd8beeffb52fff",
          "body": "Bump version to 0.3.2 across all packages, SDKs, and versioned references.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: release 0.3.2",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-07T06:25:27Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "4565a77bf31b88644855e3711b28d8b00a217f96",
          "body": "Document which of the 15 SDKs are fully supported (Tier 1), maintained\nbest-effort (Tier 2), or experimental, with a tier table on a new docs page,\nsidebar entry, and a Support column in the README SDK table.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: add SDK support tiers",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-07T06:25:05Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "069011e64fa076223d5b70702e22e68a3075e741",
          "body": "…ontracts\n\nSecurity: the D1 batch endpoints skipped access-rule evaluation entirely —\nbatch updates ran no update rule, batch deletes evaluated the delete rule once\nagainst an empty row, and batch-by-filter ignored auth/service-key context —\nallowing authenticated clients to bypass row-level authori\n[…]\nook rejection no longer\nleaves a stale pending email/phone registration.\n\nAdds focused unit and integration coverage for every aligned behavior.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(server): enforce batch access rules and align D1/PG/DO provider c…",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-07T06:25:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a108d37b5e772a3d3b31291483f6cc3535d88323",
          "body": "…tion registry\n\nFiles exporting only named defineFunction consts (e.g. DB trigger maintainers)\nwere silently dropped by the registry codegen, so their triggers never fired.\ndetectExports now collects such exports and generateFunctionRegistry registers\neach as '<route>#<exportName>'; HTTP-method and default exports are unchanged.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cli): register named defineFunction exports in the generated func…",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-05T23:24:35Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "060a92b2d1ad9ba3787d736101df501c5b348860",
          "body": "…ace)\n\nFirst dynamic-block integration coverage: needsCreate 2-RTT bootstrap on\nfirst transact, per-instance isolation, expect-based 409 rollback, and\nper-row rule enforcement without a Service Key, all through the worker\n/{ns}/{instanceId}/transact route.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: dynamic per-instance transact integration coverage (txws namesp…",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-05T20:55:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "f857fe07f24438840170c421de90f33813c17a0b",
          "body": "- handlePgRequest routes POST /transact before table validation; ops run\n  on the request's single connection inside BEGIN/COMMIT with ROLLBACK on\n  any failure\n- expect assertions run real SELECTs inside the transaction (409 when\n  unmet); per-row update/delete rules and expect read rules evaluated\n[…]\nc); core dist\n  rebuilt\n- unit tests: postgres-transact.test.ts (BEGIN/COMMIT ordering, 409\n  rollback, sidecar 501, pre-transaction validation)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: PostgreSQL transact support via session-scoped BEGIN/COMMIT",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-05T05:04:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "027877d25a83e4dda819f97e1401603ccbffb184",
          "body": "- POST /api/db/{ns}[/{instanceId}]/transact: ordered insert/update/delete\n  ops across tables applied all-or-nothing, plus expect assertions that\n  verify row state at commit time and abort with 409 when unmet\n- DO provider: single transactionSync with batch-parity rule evaluation,\n  database-live e\n[…]\nw, FAQ update\n- Tests: transact integration suite (14) across D1 shared and new\n  provider-pinned txdo DO namespace; batch/crud regression green\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: add multi-table atomic transact API (DO + D1 providers)",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-05T04:44:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "21a9115072d4741275e714dba487e914a06b907f",
          "body": null,
          "is_bot": false,
          "headline": "fix: include metadata in signed storage URLs",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-03T08:32:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "228b115d7b64ff2ec194dadfabe49d14b08bab0b",
          "body": null,
          "is_bot": false,
          "headline": "fix: use wrangler boolean env for ci watcher",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-03T08:05:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be4b0d52b7c46fddc00109b5e4948164aef02747",
          "body": null,
          "is_bot": false,
          "headline": "fix: stabilize windows portable pack smoke",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-03T07:59:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "12b52f057aea17a4096e9ed13e9ce320ae14c47f",
          "body": null,
          "is_bot": false,
          "headline": "ci: install elixir hex from github",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-03T07:47:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8325856049285cfb75eaeced96422527fd246fd0",
          "body": null,
          "is_bot": false,
          "headline": "ci: skip unused elixir rebar setup",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-03T07:40:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c1c0c856971b292d7ff16afb7754a57d1cad4de",
          "body": null,
          "is_bot": false,
          "headline": "fix: pass storage query map in rust sdk",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-03T07:32:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a1ce27d4b63f6b5517c3412db595dc157a1b8d18",
          "body": null,
          "is_bot": false,
          "headline": "fix: pass storage query map in go sdk",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-03T07:20:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "45f4574e96ec4df64f902973c097dcf3897273f2",
          "body": null,
          "is_bot": false,
          "headline": "fix: align storage wrappers with query-aware core",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-03T07:17:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a237d2dfd7318c6d09325b4824496b547c0a2cda",
          "body": null,
          "is_bot": false,
          "headline": "fix: stabilize auth smoke ci",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-03T07:14:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ed6ead93dd28b65aec93e65740fee4d798333d1",
          "body": null,
          "is_bot": false,
          "headline": "chore: release 0.3.1 with storage updates",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-03T06:58:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3af07afda808c594b3eb255a06a6a0f04fce88f5",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump release version to 0.3.0",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-03T06:46:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f66a8d8d6493aadcbbf51283953e063f8700d03f",
          "body": null,
          "is_bot": false,
          "headline": "Fix cross-tab auth refresh coordination",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-03T06:42:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "148df2bcfba54fdfa44bb9ef020ccf4885ecc075",
          "body": null,
          "is_bot": false,
          "headline": "Harden auth tokens and sync SDK contracts",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-07-03T00:49:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5429683ae6266748b1cf3ca50cfce7d9d98ca36f",
          "body": null,
          "is_bot": true,
          "headline": "chore: bump release version to 0.2.9",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-08T22:58:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5cb6bdf8e910d1d495e3f60155d64900f0c02fcc",
          "body": "[codex] Add server-blind room.collab Yjs surface",
          "is_bot": false,
          "headline": "Merge pull request #68 from edge-base/codex/room-collab-yjs-surface",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-04-08T22:41:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8942288267c38bc40042c3ac8b95233a406aa3a7",
          "body": null,
          "is_bot": true,
          "headline": "add anonymous room auth integration coverage",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-08T22:11:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ccda34cd210103d99ab95dd639fff2424005ac31",
          "body": null,
          "is_bot": true,
          "headline": "add room.collab yjs surface",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-08T21:26:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "20524d8cf7d8e3b2f4384c2a49ff22795060c5bf",
          "body": "Fix CodeQL PR summary category matching",
          "is_bot": false,
          "headline": "Merge pull request #67 from edge-base/codex/codeql-summary-check",
          "author_name": "june lee",
          "author_login": "melodysdreamj",
          "committed_at": "2026-04-04T08:38:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a2653579a38531c9097f2459d3f6709c970579c0",
          "body": null,
          "is_bot": true,
          "headline": "ci: align codeql categories with pipeline workflow",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-04T08:09:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bbe0560b7ab46290fe3552be4b5552198c6114ab",
          "body": null,
          "is_bot": true,
          "headline": "ci: stabilize codeql analysis categories",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-04T08:05:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc704ae938dbed0c20330fe2c9366220509f06c6",
          "body": null,
          "is_bot": true,
          "headline": "docs: remove meta separation wording",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-04T07:38:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3605ca1044902d3bf6de8500a84e36da01d3b4f9",
          "body": null,
          "is_bot": true,
          "headline": "docs: simplify static frontend docs wording",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-04T07:36:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 16,
      "commits_last_year": 397,
      "latest_release_at": "2026-07-17T00:15:22Z",
      "latest_release_tag": "v0.4.9",
      "releases_from_tags": false,
      "days_since_last_push": 2,
      "active_weeks_last_year": 7,
      "days_since_latest_release": 4,
      "mean_days_between_releases": 11
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": false,
      "has_contributing": true,
      "health_percentage": 75,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@edge-base/cli",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "edgebase",
            "cli",
            "baas",
            "backend",
            "cloudflare-workers"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@edge-base/cli",
          "is_deprecated": false,
          "latest_version": "0.4.9",
          "repository_url": "https://github.com/edge-base/edgebase",
          "versions_count": 31,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 2,
          "monthly_downloads": 2620,
          "first_published_at": "2026-03-18T10:50:05.468000Z",
          "latest_published_at": "2026-07-17T00:20:50.176000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        },
        {
          "name": "@edge-base/server",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "edgebase",
            "runtime",
            "server",
            "cloudflare-workers"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@edge-base/server",
          "is_deprecated": false,
          "latest_version": "0.4.9",
          "repository_url": "https://github.com/edge-base/edgebase",
          "versions_count": 31,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 2,
          "monthly_downloads": 2699,
          "first_published_at": "2026-03-18T10:49:25.609000Z",
          "latest_published_at": "2026-07-17T00:20:07.754000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        },
        {
          "name": "@edge-base/shared",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "edgebase",
            "shared",
            "config",
            "functions"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@edge-base/shared",
          "is_deprecated": false,
          "latest_version": "0.4.9",
          "repository_url": "https://github.com/edge-base/edgebase",
          "versions_count": 31,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 2,
          "monthly_downloads": 3819,
          "first_published_at": "2026-03-18T10:49:05.882000Z",
          "latest_published_at": "2026-07-17T00:19:30.752000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        },
        {
          "name": "create-edgebase",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "edgebase",
            "create-edgebase",
            "scaffold",
            "cli"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/create-edgebase",
          "is_deprecated": false,
          "latest_version": "0.4.9",
          "repository_url": "https://github.com/edge-base/edgebase",
          "versions_count": 32,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 2,
          "monthly_downloads": 2283,
          "first_published_at": "2026-03-18T08:18:03.941000Z",
          "latest_published_at": "2026-07-17T00:20:54.478000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        }
      ]
    },
    "popularity": {
      "forks": 2,
      "stars": 7,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-03-18",
            "count": 1
          },
          {
            "date": "2026-03-20",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 2,
        "total_forks": 2
      },
      "star_history": {
        "days": [
          {
            "date": "2026-03-18",
            "count": 4
          },
          {
            "date": "2026-03-19",
            "count": 1
          },
          {
            "date": "2026-03-30",
            "count": 1
          },
          {
            "date": "2026-05-19",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 7,
        "total_stars": 7
      },
      "open_issues_and_prs": 9
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "example"
      ],
      "has_llms_txt": true,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [
        "packages/server/openapi.json"
      ],
      "has_devcontainer": false,
      "typecheck_configs": [
        "docs/tsconfig.json",
        "packages/admin/tsconfig.json",
        "packages/cli/tsconfig.json",
        "packages/plugins/core/tsconfig.json",
        "packages/sdk/js/packages/admin/tsconfig.json",
        "packages/sdk/js/packages/auth-ui-react/tsconfig.json",
        "packages/sdk/js/packages/core/tsconfig.json",
        "packages/sdk/js/packages/ssr/tsconfig.json",
        "packages/sdk/js/packages/web/tsconfig.json",
        "packages/sdk/js/tsconfig.json",
        "packages/sdk/react-native/tsconfig.json",
        "packages/server/tsconfig.json",
        "packages/shared/tsconfig.json"
      ],
      "toolchain_manifests": [
        "packages/sdk/csharp/packages/admin/EdgeBase.Admin.csproj",
        "packages/sdk/csharp/packages/admin/tests/EdgeBase.Admin.Tests.csproj",
        "packages/sdk/csharp/packages/core/EdgeBase.Core.csproj",
        "packages/sdk/csharp/packages/unity/EdgeBase.Unity.csproj",
        "packages/sdk/csharp/packages/unity/tests/EdgeBase.Unity.Tests.csproj",
        "packages/sdk/csharp/src/EdgeBase.csproj",
        "packages/sdk/csharp/tests/EdgeBase.Tests.csproj",
        "packages/sdk/elixir/packages/admin/mix.exs",
        "packages/sdk/elixir/packages/core/mix.exs",
        "packages/sdk/go/go.mod",
        "packages/sdk/java/build.gradle",
        "packages/sdk/java/packages/admin/build.gradle",
        "packages/sdk/java/packages/android/build.gradle",
        "packages/sdk/java/packages/core/build.gradle",
        "packages/sdk/kotlin/admin/build.gradle.kts",
        "packages/sdk/kotlin/build.gradle.kts",
        "packages/sdk/kotlin/client/build.gradle.kts",
        "packages/sdk/kotlin/core/build.gradle.kts",
        "packages/sdk/rust/Cargo.toml",
        "packages/sdk/rust/packages/admin/Cargo.toml",
        "packages/sdk/rust/packages/core/Cargo.toml",
        "packages/sdk/scala/build.gradle.kts",
        "packages/sdk/scala/packages/admin/build.gradle.kts",
        "packages/sdk/scala/packages/core/build.gradle.kts"
      ],
      "largest_source_bytes": 205754,
      "source_files_sampled": 1183,
      "oversized_source_files": 28,
      "agent_instruction_files": [
        "AGENT.md",
        "AGENTS.md",
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 5111
    },
    "dependencies": {
      "manifests": [
        "docs/package.json",
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@edge-base/server",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@edge-base/shared",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "chalk",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.4.0"
        },
        {
          "name": "commander",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^13.1.0"
        },
        {
          "name": "esbuild",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.28.1"
        },
        {
          "name": "jose",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.0.0"
        },
        {
          "name": "ora",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^9.3.0"
        },
        {
          "name": "pg",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.16.3"
        },
        {
          "name": "tsx",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.20.6"
        },
        {
          "name": "ts-morph",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^27.0.2"
        },
        {
          "name": "wrangler",
          "manifest": "packages/cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "4.103.0"
        },
        {
          "name": "@edge-base/cli",
          "manifest": "packages/create-edgebase/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@edge-base/core",
          "manifest": "packages/server/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@edge-base/shared",
          "manifest": "packages/server/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@hono/zod-openapi",
          "manifest": "packages/server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.2.2"
        },
        {
          "name": "@simplewebauthn/server",
          "manifest": "packages/server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^10"
        },
        {
          "name": "bcryptjs",
          "manifest": "packages/server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.3"
        },
        {
          "name": "hono",
          "manifest": "packages/server/package.json",
          "ecosystem": "npm",
          "version_constraint": "4.12.25"
        },
        {
          "name": "jose",
          "manifest": "packages/server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.0.0"
        },
        {
          "name": "pg",
          "manifest": "packages/server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.16.3"
        },
        {
          "name": "zod",
          "manifest": "packages/server/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.3.6"
        },
        {
          "name": "tsx",
          "manifest": "tools/sdk-codegen/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.0"
        },
        {
          "name": "tsx",
          "manifest": "tools/smoke-gen/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 8,
        "merged_prs": 53,
        "open_issues": 1,
        "closed_ratio": 0.909,
        "closed_issues": 10,
        "closed_unmerged_prs": 10
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "melodysdreamj",
          "commits": 243,
          "avatar_url": "https://avatars.githubusercontent.com/u/21379657?v=4"
        },
        {
          "type": "User",
          "login": "edgebase1952",
          "commits": 21,
          "avatar_url": "https://avatars.githubusercontent.com/u/269032722?v=4"
        }
      ],
      "contributors_sampled": 2,
      "top_contributor_share": 0.92
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "agent-skills-sync.yml",
        "ci.yml",
        "codeql.yml",
        "go-split-sync.yml",
        "npm-publish.yml",
        "php-split-sync.yml",
        "pipeline.yml",
        "secret-scan.yml",
        "semgrep.yml",
        "swift-split-sync.yml",
        "test.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        "eslint.config.js"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "mix.lock",
        "pnpm-lock.yaml",
        "yarn.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 9,
            "reason": "binaries present in source code",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/24 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 8,
            "reason": "dependency not pinned by hash detected -- score normalized to 8",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 8,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "30 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "38e0ba236bb395a079f0fc42ff1a513a710263a7",
        "ran_at": "2026-07-21T16:42:00Z",
        "aggregate_score": 7.3,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": true,
      "has_dependabot_config": true
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/edge-base/edgebase",
    "host": "github.com",
    "name": "edgebase",
    "owner": "edge-base"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 66,
      "inputs": {
        "security": 73,
        "vitality": 81,
        "community": 54,
        "governance": 53,
        "engineering": 72
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 81,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 69,
            "inputs": {
              "commits_last_year": 397,
              "human_commit_share": 0.93,
              "days_since_last_push": 2,
              "active_weeks_last_year": 7
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 2 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "7/52 weeks with commits",
                "points": 4.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 7
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "397 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 397
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 16,
              "latest_release_tag": "v0.4.9",
              "releases_from_tags": false,
              "days_since_latest_release": 4,
              "mean_days_between_releases": 11
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "16 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 16
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~11 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 11
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 54,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "forks": 2,
              "stars": 7,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "below_threshold"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "7 stars",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "2 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 68,
            "inputs": {
              "packages": [
                "@edge-base/cli",
                "@edge-base/server",
                "@edge-base/shared",
                "create-edgebase"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 11421
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "11,421 downloads/month across npm",
                "points": 54.1,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 11421,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 53,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 14,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 2,
              "top_contributor_share": 0.92
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 92% of commits",
                "points": 1.8,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 92
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "2 contributors",
                "points": 2.7,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "merged_prs": 53,
              "open_issues": 1,
              "closed_issues": 10,
              "issue_closed_ratio": 0.909,
              "closed_unmerged_prs": 10
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "91% of issues closed",
                "points": 42.5,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 91
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "53/63 decided PRs merged",
                "points": 32.2,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 53,
                      "decided": 63
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/24 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 41,
            "inputs": {
              "followers": 2,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "edge-base",
              "public_repos": 8,
              "account_age_days": 128
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "2 followers of edge-base",
                "points": 3.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 2,
                      "login": "edge-base"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "8 public repos, account ~0 yr old",
                "points": 7.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 8
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@edge-base/cli",
                "@edge-base/server",
                "@edge-base/shared",
                "create-edgebase"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 4
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "4 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 4,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 4 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "32 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 32
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 72,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "11 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 11
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.js",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 55,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 73,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "good",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection, Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection",
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 73,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 15,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 3,
              "scorecard_aggregate": 7.3
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "binaries present in source code",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "1 out of 1 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/24 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 4,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "30 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "excellent",
        "name": "AI Readiness",
        "value": 93,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "has_llms_txt": true,
              "legible_history_share": 0.839,
              "agent_instruction_files": [
                "AGENT.md",
                "AGENTS.md",
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 5111
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENT.md, AGENTS.md, CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENT.md, AGENTS.md, CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": "llms.txt present",
                "points": 15,
                "status": "met",
                "details": [
                  {
                    "code": "llms_txt_present",
                    "params": {}
                  }
                ],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "78 of 93 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 78,
                      "sampled": 93
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "mix.lock",
                "pnpm-lock.yaml",
                "yarn.lock"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "docs/tsconfig.json",
                "packages/admin/tsconfig.json",
                "packages/cli/tsconfig.json",
                "packages/plugins/core/tsconfig.json",
                "packages/sdk/js/packages/admin/tsconfig.json",
                "packages/sdk/js/packages/auth-ui-react/tsconfig.json",
                "packages/sdk/js/packages/core/tsconfig.json",
                "packages/sdk/js/packages/ssr/tsconfig.json",
                "packages/sdk/js/packages/web/tsconfig.json",
                "packages/sdk/js/tsconfig.json",
                "packages/sdk/react-native/tsconfig.json",
                "packages/server/tsconfig.json",
                "packages/shared/tsconfig.json"
              ],
              "agent_commit_share": 0.37,
              "toolchain_manifests": [
                "packages/sdk/csharp/packages/admin/EdgeBase.Admin.csproj",
                "packages/sdk/csharp/packages/admin/tests/EdgeBase.Admin.Tests.csproj",
                "packages/sdk/csharp/packages/core/EdgeBase.Core.csproj",
                "packages/sdk/csharp/packages/unity/EdgeBase.Unity.csproj",
                "packages/sdk/csharp/packages/unity/tests/EdgeBase.Unity.Tests.csproj",
                "packages/sdk/csharp/src/EdgeBase.csproj",
                "packages/sdk/csharp/tests/EdgeBase.Tests.csproj",
                "packages/sdk/elixir/packages/admin/mix.exs",
                "packages/sdk/elixir/packages/core/mix.exs",
                "packages/sdk/go/go.mod",
                "packages/sdk/java/build.gradle",
                "packages/sdk/java/packages/admin/build.gradle",
                "packages/sdk/java/packages/android/build.gradle",
                "packages/sdk/java/packages/core/build.gradle",
                "packages/sdk/kotlin/admin/build.gradle.kts",
                "packages/sdk/kotlin/build.gradle.kts",
                "packages/sdk/kotlin/client/build.gradle.kts",
                "packages/sdk/kotlin/core/build.gradle.kts",
                "packages/sdk/rust/Cargo.toml",
                "packages/sdk/rust/packages/admin/Cargo.toml",
                "packages/sdk/rust/packages/core/Cargo.toml",
                "packages/sdk/scala/build.gradle.kts",
                "packages/sdk/scala/packages/admin/build.gradle.kts",
                "packages/sdk/scala/packages/core/build.gradle.kts"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "packages/sdk/csharp/packages/admin/EdgeBase.Admin.csproj, packages/sdk/csharp/packages/admin/tests/EdgeBase.Admin.Tests.csproj, packages/sdk/csharp/packages/core/EdgeBase.Core.csproj (toolchain convention, no task runner)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "toolchain_convention",
                    "params": {
                      "files": "packages/sdk/csharp/packages/admin/EdgeBase.Admin.csproj, packages/sdk/csharp/packages/admin/tests/EdgeBase.Admin.Tests.csproj, packages/sdk/csharp/packages/core/EdgeBase.Core.csproj"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.js",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "docs/tsconfig.json, packages/admin/tsconfig.json, packages/cli/tsconfig.json, packages/plugins/core/tsconfig.json, packages/sdk/js/packages/admin/tsconfig.json, packages/sdk/js/packages/auth-ui-react/tsconfig.json, packages/sdk/js/packages/core/tsconfig.json, packages/sdk/js/packages/ssr/tsconfig.json, packages/sdk/js/packages/web/tsconfig.json, packages/sdk/js/tsconfig.json, packages/sdk/react-native/tsconfig.json, packages/server/tsconfig.json, packages/shared/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "docs/tsconfig.json, packages/admin/tsconfig.json, packages/cli/tsconfig.json, packages/plugins/core/tsconfig.json, packages/sdk/js/packages/admin/tsconfig.json, packages/sdk/js/packages/auth-ui-react/tsconfig.json, packages/sdk/js/packages/core/tsconfig.json, packages/sdk/js/packages/ssr/tsconfig.json, packages/sdk/js/packages/web/tsconfig.json, packages/sdk/js/tsconfig.json, packages/sdk/react-native/tsconfig.json, packages/server/tsconfig.json, packages/shared/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "37 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 37,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "dependency automation configured, none observed in the sampled commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "dependency_bot_config_only",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 8",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 205754,
              "source_files_sampled": 1183,
              "oversized_source_files": 28
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "28/1183 source files over 60KB",
                "points": 53.7,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 1183,
                      "oversized": 28
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "good",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "example_dirs": [
                "example"
              ],
              "has_mcp_signal": false,
              "api_schema_files": [
                "packages/server/openapi.json"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "packages/server/openapi.json",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "packages/server/openapi.json"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "example",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "example"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index npm:@edge-base/cli@0.4.9; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-21T16:42:10.255297Z",
  "schema_version": "0.23.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/e/edge-base/edgebase.svg",
  "full_name": "edge-base/edgebase",
  "license_state": "standard",
  "license_spdx": "MIT"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.23.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计npm.