原始 JSON 报告 机器可读
{
"data": {
"icon": {
"bytes": 3857,
"width": 256,
"height": 256,
"rejected": [],
"collected": true,
"media_type": "image/jpeg",
"source_url": "https://avatars.githubusercontent.com/u/267680661?v=4&s=256",
"source_type": "avatar",
"content_hash": "64935b9b6b98a48418622b7d56f2073d42f8341ba040446362e85e839e9e555f",
"candidates_considered": 1
},
"repo": {
"topics": [
"elixir",
"mix",
"no-nodejs",
"npm",
"package-manager"
],
"is_fork": false,
"size_kb": 1114,
"has_wiki": true,
"homepage": null,
"languages": {
"Elixir": 1303647
},
"pushed_at": "2026-07-20T18:49:03Z",
"created_at": "2026-03-11T08:22:29Z",
"owner_type": "Organization",
"updated_at": "2026-07-30T21:11:04Z",
"description": "npm package manager for Elixir",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "master",
"license_spdx_raw": "MIT",
"primary_language": "Elixir",
"significant_languages": [
"Elixir"
]
},
"owner": {
"blog": null,
"name": "Elixir Volt",
"type": "Organization",
"login": "elixir-volt",
"company": null,
"location": null,
"followers": 49,
"avatar_url": "https://avatars.githubusercontent.com/u/267680661?v=4",
"created_at": "2026-03-12T14:33:03Z",
"is_verified": null,
"public_repos": 18,
"account_age_days": 145
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.7.6",
"kind": "patch",
"published_at": "2026-07-20T18:49:04Z"
},
{
"tag": "v0.7.5",
"kind": "patch",
"published_at": "2026-07-07T16:06:56Z"
},
{
"tag": "v0.7.4",
"kind": "patch",
"published_at": "2026-05-17T18:04:49Z"
},
{
"tag": "v0.7.3",
"kind": "patch",
"published_at": "2026-05-16T18:52:34Z"
},
{
"tag": "v0.7.2",
"kind": "patch",
"published_at": "2026-05-16T15:28:28Z"
},
{
"tag": "v0.7.1",
"kind": "patch",
"published_at": "2026-05-12T18:10:27Z"
},
{
"tag": "v0.7.0",
"kind": "minor",
"published_at": "2026-05-12T14:51:12Z"
},
{
"tag": "v0.6.1",
"kind": "patch",
"published_at": "2026-05-12T11:35:58Z"
},
{
"tag": "v0.6.0",
"kind": "minor",
"published_at": "2026-04-24T12:08:11Z"
},
{
"tag": "v0.5.3",
"kind": "patch",
"published_at": "2026-04-14T17:48:24Z"
},
{
"tag": "v0.5.2",
"kind": "patch",
"published_at": "2026-04-14T14:25:25Z"
},
{
"tag": "v0.5.1",
"kind": "patch",
"published_at": "2026-03-24T10:55:03Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2026-03-24T10:36:17Z"
},
{
"tag": "v0.4.6",
"kind": "patch",
"published_at": "2026-03-24T10:19:30Z"
},
{
"tag": "v0.4.5",
"kind": "patch",
"published_at": "2026-03-24T07:19:09Z"
},
{
"tag": "v0.4.4",
"kind": "patch",
"published_at": "2026-03-23T12:24:49Z"
},
{
"tag": "v0.4.3",
"kind": "patch",
"published_at": "2026-03-23T11:01:28Z"
},
{
"tag": "v0.4.2",
"kind": "patch",
"published_at": "2026-03-14T15:44:34Z"
}
],
"recent_commits": [
{
"oid": "58b18bb4869ee42919a534a7c1338848d89076d3",
"body": null,
"is_bot": false,
"headline": "Prepare 0.7.6 release",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-07-20T14:33:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d850aaf89d48a6e0499f55497e8367dbf7aa7c25",
"body": null,
"is_bot": false,
"headline": "Fix Windows package root traversal",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-07-17T22:41:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "95ac3cff661fb8763754178c9af9360dfbd93469",
"body": null,
"is_bot": false,
"headline": "Prepare 0.7.5 release",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-07-07T15:48:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "adf97c3f91bdd1a3379b8eef88fe34eff8753ea4",
"body": null,
"is_bot": false,
"headline": "README: ecosystem footer linking org and Building Blocks standard",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-06-11T09:21:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d754c20e57922443899c12e0bd55dd899c68afc1",
"body": null,
"is_bot": false,
"headline": "Handle OTP 29 Dialyzer opacity warnings",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-06-06T19:08:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "330a640829224723063974f459d2c9cd1380f3cb",
"body": null,
"is_bot": false,
"headline": "Use shared Elixir CI workflow",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-06-06T18:48:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0352a92308a51bee6149cdcae59865a5bca9937b",
"body": null,
"is_bot": false,
"headline": "Support Elixir 1.20 type checks",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-06-06T13:59:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "39aab46057a8c4e031a3a650c2b98fd3d349b1f6",
"body": null,
"is_bot": false,
"headline": "Release v0.7.4",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-17T18:03:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f13e944298f1dc2dc9324ffb556d120c8daf0dc1",
"body": "…eps in frozen install",
"is_bot": false,
"headline": "Add tests for tarball permissions, native binary exec, and optional d…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-17T17:59:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "427e702b8973582da8d083c2b125215dbd6fdfd6",
"body": "…nstall\n\n- Preserve file permissions from tarball entries during extraction,\n fixing EACCES for native executables like tsgo\n- Run package scripts directly with node (not via loader wrapper) so\n package #imports resolve correctly\n- Detect native binaries and execute them directly instead of\n wrap\n[…]\n\n- Treat missing policy section in lockfile as valid for frozen\n install\n- Include optional_dependencies in lockfile consistency check so\n platform-specific packages don't appear orphaned\n\nCloses #3",
"is_bot": false,
"headline": "Fix tarball permissions, native binary exec, exit codes, and frozen i…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-17T17:51:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d421e7db96ebcc1c727eeca9f7d0d03a05af4143",
"body": null,
"is_bot": false,
"headline": "Fix browser field resolution for non-JS targets",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-16T18:49:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f4750bbff86ae71d561659e17ccef3a054b8f466",
"body": null,
"is_bot": false,
"headline": "Prepare 0.7.2 release",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-16T15:25:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "005ca4ea2cde7e7787d08f22f92784f9e1ee5cc1",
"body": null,
"is_bot": false,
"headline": "Add direct coverage for npm helpers",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-16T15:10:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d3056e27019a998d8a56153087798322d7a76612",
"body": null,
"is_bot": false,
"headline": "Align resolution tests with module paths",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-16T14:24:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6c16a9544be20349ae89a54a4be56a8a42210b98",
"body": null,
"is_bot": false,
"headline": "Fix tarball root extraction",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-16T14:23:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "db83f339b0e36e61808b40fcdb648615d2813a89",
"body": null,
"is_bot": false,
"headline": "Fix exotic candidate resolution",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T17:58:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8a70aeee455899bd61bd0c699e479b6d6a5bb163",
"body": null,
"is_bot": false,
"headline": "Link npm_ex docs from README",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T14:46:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7fac9c77f5134b5931e9124d86f582c9bb3e753d",
"body": null,
"is_bot": false,
"headline": "Add npm_ex user guides",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T14:45:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6a9b53e64d36c5129026b7d3e8200332a1617e99",
"body": null,
"is_bot": false,
"headline": "Refocus npm_ex README",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T14:38:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1e335cdedd87dd8445a9cbc6791e930b98010ec5",
"body": null,
"is_bot": false,
"headline": "Prepare npm_ex 0.7.0",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T14:33:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8a4bd5049e32e3366511f165ade595be1b2961fc",
"body": null,
"is_bot": false,
"headline": "Merge cached OSV advisory updates",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T14:28:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6ae4499305e985590d6f9dcf1f6ed6c5b7a2003e",
"body": null,
"is_bot": false,
"headline": "Cache compromised advisory data globally",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T14:22:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "65e06e7fd09e634196c51b0321c4f92af1c1818c",
"body": null,
"is_bot": false,
"headline": "Integrate compromised checks into npm audit",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T14:15:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7e818095988a89572b6df5c3b8e350d07137239a",
"body": null,
"is_bot": false,
"headline": "Add OSV compromised package checks",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T14:01:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "64d0014383cd0721af4d6b231bf1e796ac911933",
"body": null,
"is_bot": false,
"headline": "Fix static analysis warnings",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T13:39:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "99f04d4a6e3e1f4224360224acb29ddd9d23fe00",
"body": null,
"is_bot": false,
"headline": "Move registry config and install helpers",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T13:13:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0b68a183d87e71b242484dbd947f0129d8c50a0d",
"body": null,
"is_bot": false,
"headline": "Harden registry and dependency policies",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T13:09:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b87ee15cc4698331392e849424883f1bef7e15a0",
"body": null,
"is_bot": false,
"headline": "Document npm module organization",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T12:50:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "37a14526bb7a60974eaeb4ffe22da5030e11c4d2",
"body": null,
"is_bot": false,
"headline": "Move diagnostics checks under diagnostics namespace",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T12:48:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8301d26dbbcbb740dba3e95844908043ceba8649",
"body": null,
"is_bot": false,
"headline": "Use JSON helper for library decoding",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T12:47:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e5a2a8c088a46c429cb925079f1e0c9dc77ebe10",
"body": null,
"is_bot": false,
"headline": "Move package helpers under package namespace",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T12:46:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b520f4a377c8b834d75163df13c409ee4d4bdadf",
"body": null,
"is_bot": false,
"headline": "Move lockfile helpers under lockfile namespace",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T12:42:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bf722d7a8b0f05c859c0169ad4b86df865b090ce",
"body": null,
"is_bot": false,
"headline": "Move supply chain helpers under security",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T12:40:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "654853486ff634328707f340ea1dadc62447a89d",
"body": null,
"is_bot": false,
"headline": "Use JSON helper in dependency usage check",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T12:38:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f5c096273b6582cefb32ca2cc23e5be4802d703c",
"body": null,
"is_bot": false,
"headline": "Merge update analysis into outdated",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T12:37:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "24edf86ce7bbc74b8805e45055066d3a1b0dda66",
"body": null,
"is_bot": false,
"headline": "Merge duplicate analysis into dedupe",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T12:35:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d282336c9e07018723bc8b5f34eb824edd5dc479",
"body": null,
"is_bot": false,
"headline": "Merge graph operations into dependency graph",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T12:33:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b403ad9e5f0da1635a511a4d3224b379c3630833",
"body": null,
"is_bot": false,
"headline": "Reuse peer helpers in node modules scan",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T12:31:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e21326a358da6946590f7387c62a641180917faf",
"body": null,
"is_bot": false,
"headline": "Restructure dependency analysis modules",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T12:30:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5ddf522742dfb4418ab1fa39697ca936c991a25e",
"body": null,
"is_bot": false,
"headline": "Use Jason for npm JSON helpers",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T12:07:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5a8cf4b13fe6346caf9f01777c599b733cc8ac5f",
"body": null,
"is_bot": false,
"headline": "Document internal npm modules",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T12:01:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5b281f9d1f5b63f2cb151d95baa149d55fc4bd80",
"body": null,
"is_bot": false,
"headline": "Block exotic transitive npm dependencies",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T11:56:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "65db98c0fd4f1de9eabb3d9e0ab48f7113ffcb7b",
"body": null,
"is_bot": false,
"headline": "Release npm_ex 0.6.1",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-12T11:33:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3ca52922a2980b3a31a797fab6136616cc29b3fa",
"body": null,
"is_bot": false,
"headline": "Update ex_dna 1.5, ex_slop 0.4; fix new credo warnings",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-11T11:15:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4ba28c8e1884a5e89127a86c24462a5dc8b9a848",
"body": null,
"is_bot": false,
"headline": "Fix platform-dependent test for CI (Linux)",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-05-11T10:19:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "98c573335b62bd84d48d88640ae65e87cc17b599",
"body": null,
"is_bot": false,
"headline": "Update development dependencies",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-04-24T12:04:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "901300d5e9b9a3b08eabe7268833356ebbc8db18",
"body": null,
"is_bot": false,
"headline": "Fix completion task warnings",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-04-24T12:02:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "759e5a006a97e8cbc868b69b4a9052b3ec7f127a",
"body": null,
"is_bot": false,
"headline": "Restructure resolution modules",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-04-24T11:44:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b0c307b315e255afc6f268b034c5ab4b691076e8",
"body": null,
"is_bot": false,
"headline": "Fix optional tarball linker test",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-04-24T11:38:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "31f34d5521699c461b8bbabc75cd2f069e8b8f4b",
"body": null,
"is_bot": false,
"headline": "Release 0.5.4",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-04-24T11:35:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "db4bcd651c7fb11fd7dbeb5b85ddab1a1724899f",
"body": null,
"is_bot": false,
"headline": "Support nested exports and package imports",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-04-24T11:25:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4b476e6f09aa890fb119cfcf7ff68d960fb8aeeb",
"body": null,
"is_bot": false,
"headline": "Release 0.5.3",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-04-14T17:46:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ff24ac6d60be7df719e4cd98114c455f245919df",
"body": null,
"is_bot": false,
"headline": "Add PackageResolver.relative_import_path/3",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-04-14T17:46:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cd1cee335859f6d16d718fae3b103315d2436b1c",
"body": null,
"is_bot": false,
"headline": "Release 0.5.2",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-04-14T14:19:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8373d6b3fd298c6bff04845d4f7bec5556c285c8",
"body": null,
"is_bot": false,
"headline": "Add 0.5.2 changelog",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-04-14T14:17:38Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "17b53b5cb50588397ac57f7ca7888fa01e009c1f",
"body": "- Filter unparseable versions in Linker.resolve_nested_version before\n version_gt? to prevent Version.parse! crash on lenient npm versions\n- Restore rescue _ in Exec.find_in_packages with explanatory comment\n (ErlangError was nearly as broad and less honest about intent)\n- Update Cache.ensure/5 do\n[…]\nnsion (Path.extname returns\n \"\" not nil — the || \"(none)\" could never trigger)\n- Remove dead {:error, :cycle} branch in DepSort.install_order\n (sort/1 always returns {:ok, order} for acyclic graphs)",
"is_bot": false,
"headline": "Address follow-up review of 7ae97db",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-04-14T14:16:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4e615b9f5bfc3c9ec1c648d69330e3cb61fd4beb",
"body": null,
"is_bot": false,
"headline": "Bump ex_dna ~> 1.1 → ~> 1.3",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-04-14T12:45:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7ae97db01fbcdf11968a831d73e0697f48adaa3e",
"body": "Critical:\n- Fix Cache.ensure/5 spec to include {:ok, :missing_optional} return type\n- Fix ETS race condition in Resolver.ensure_cache (TOCTOU → try/rescue)\n- Remove dead code: redundant case in PeerDeps.version_satisfies?/2\n\nSignificant:\n- Replace blanket rescue _ with specific ArgumentError in vers\n[…]\ner_dependencies/4\n- Flatten expand_all_optional_deps nesting via maybe_add_optional_dep/2\n- Simplify DepsOutput.format_diff list building (no intermediate ++)\n- Remove extra blank lines in registry.ex",
"is_bot": false,
"headline": "Fix issues from GLM-5.1 code review",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-04-14T12:40:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "480e83c668846e2736ebe55f4bbf36ec1d388bd6",
"body": "Implements the file-system resolution algorithm that consumers (Volt,\nQuickBEAM, Tailwind) currently duplicate:\n\n- split_specifier/1 — parse @scope/package/subpath\n- find_node_modules/1 — walk up to find node_modules/\n- try_resolve/2 — probe extensions (.js, .mjs, .cjs, .json) and index files\n- reso\n[…]\nare, relative, builtin)\n\nDelegates to NPM.Exports for the exports field. Supports configurable\nconditions (import/require/browser/default) and extension lists.\n\n50 tests covering all resolution paths.",
"is_bot": false,
"headline": "Add NPM.PackageResolver for Node.js module resolution",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-04-14T12:27:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fd338964ec10fbf1f6944085297f09ea79393b1d",
"body": null,
"is_bot": false,
"headline": "Release 0.5.1",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-24T10:54:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d64a366fbef8dd6a43f5e883bc60a0498effde28",
"body": null,
"is_bot": false,
"headline": "Release 0.5.0",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-24T10:36:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "413af1ecfa42e334b67edf82167ffcdde2d005b0",
"body": null,
"is_bot": false,
"headline": "Release 0.4.6",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-24T10:19:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "21d28f348bc1304a2acdafbb7153567dedc7ee10",
"body": null,
"is_bot": false,
"headline": "Release 0.4.5",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-24T07:19:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "572fdd754d5f1e20bd967bb22eb21ee099632207",
"body": null,
"is_bot": false,
"headline": "Release 0.4.4",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-23T12:24:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8c2ea23d381e9b52436c5f203aa44c9a0d79cd8b",
"body": null,
"is_bot": false,
"headline": "Release 0.4.3",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-23T11:00:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7f6160da4d08b2be278dbc09300b44e82934354b",
"body": null,
"is_bot": false,
"headline": "Release 0.4.2",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-14T15:37:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c1fa6de462c7df5a2887e4b3e62e1bb390e97b33",
"body": null,
"is_bot": false,
"headline": "Extract NPM.FormatUtil to deduplicate format_size/format_bytes",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-14T15:35:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c99f30d8b2a415f9f65f6e994bf49d41bd4a2813",
"body": "Before running the solver, prefetch the entire dependency tree\nbreadth-first with 16 concurrent HTTP requests. Uses only the\nlatest stable version's deps to avoid fetching every version.",
"is_bot": false,
"headline": "Speculative parallel prefetch of transitive dependencies",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-14T15:35:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6cf041c260c3ef3898cbbd586e0f2447adfa2ff7",
"body": "Before running the solver, prefetch the entire dependency tree\nbreadth-first with 16 concurrent HTTP requests. Uses only the\nlatest stable version's deps to avoid fetching every version.",
"is_bot": false,
"headline": "Speculative parallel prefetch of transitive dependencies",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-14T14:08:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dadfc484acf9bfbce40c84ec0713f8b777437dab",
"body": "…nch'\n\nStart Req before running mix tasks instead of relying on app.config.",
"is_bot": false,
"headline": "Release 0.4.1 — fix mix tasks crashing with 'unknown registry: Req.Fi…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-14T10:22:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ae9dfd2e28129c055726843df3f9d053bbc8612a",
"body": "43 mix tasks, 141 library modules, 2697 tests.\n\nMajor additions: mix deps-style install output, dependency graph analysis,\npackage metadata introspection, security/supply chain tools, structured\nerror messages, progress reporting, .npmrc multi-layer resolution,\ntopological sorting, outdated report formatting, project scaffolding.",
"is_bot": false,
"headline": "Release 0.4.0",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T19:26:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a4640005d7389d68a79fc522a3d8997f423cb201",
"body": "…, orphaned_types) with 11 tests for @types/* companion package suggestions\\n\\nResult: {\"status\":\"keep\",\"test_count\":2697}",
"is_bot": false,
"headline": "Add NPM.TypesCompanion module (suggest, types_package, has_own_types?…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T16:47:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bb582035bed38b3b997c8d8b3fa858d33d5f54d5",
"body": "…, format, format_size) with 11 tests for cache usage statistics and metrics\\n\\nResult: {\"status\":\"keep\",\"test_count\":2686}",
"is_bot": false,
"headline": "Add NPM.CacheStats module (hit_miss, hit_rate, disk_size, list_cached…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T16:46:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fe47c8b70ec8366ef220aa0ac3a451506efb6b97",
"body": "…breakdown, format_time) with 10 tests for install progress output\\n\\nResult: {\"status\":\"keep\",\"test_count\":2675}",
"is_bot": false,
"headline": "Add NPM.ProgressReporter module (resolving, fetching, linking, done, …",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T16:45:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d70e0354ac595932852f7271c1afdc1ca2f660be",
"body": "…tests for structured error formatting with actionable suggestions\\n\\nResult: {\"status\":\"keep\",\"test_count\":2665}",
"is_bot": false,
"headline": "Add NPM.ErrorMessage module (format, suggestion, retryable?) with 12 …",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T16:44:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a549720629d929b832894a005b038e3c39b8c0b7",
"body": "…ist, ready?, format_checklist) with 9 tests for npm project scaffolding and setup verification\\n\\nResult: {\"status\":\"keep\",\"test_count\":2653}",
"is_bot": false,
"headline": "Add NPM.ProjectInit module (initialized?, create_package_json, checkl…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T16:43:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "df65c443afdf2b919883cfa4b124c1f7494e04f5",
"body": "…urity_risk) with 8 tests for npm outdated-style table formatting and severity categorization\\n\\nResult: {\"status\":\"keep\",\"test_count\":2644}",
"is_bot": false,
"headline": "Add NPM.OutdatedReport module (format_table, categorize, summary, sec…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T16:43:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "226fbc8d07d6853fd561495dbbea8dc36cf4b372",
"body": "…ith 8 tests for topological sorting and parallel install levels + NPM.PackageUpdate refactored to use VersionUtil\\n\\nResult: {\"status\":\"keep\",\"test_count\":2636}",
"is_bot": false,
"headline": "Add NPM.DepSort (sort, install_order, parallel_levels, level_count) w…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T16:42:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "37ab0ce77dafa49368f84f3b6bc8ac876a761f33",
"body": "…mpact, leaves, roots, reverse_graph) with 13 tests for advanced dependency graph analysis\\n\\nResult: {\"status\":\"keep\",\"test_count\":2628}",
"is_bot": false,
"headline": "Add NPM.GraphOps module (transitive_deps, shortest_path, max_depth, i…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T16:39:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7f5d597fe01b7335535f48bbd637b3d7c47818f3",
"body": "…, PackageUpdate, ReleaseNotes, IntegrityCheck, Gitignore, DepsOutput\\n\\nResult: {\"status\":\"keep\",\"test_count\":2615}",
"is_bot": false,
"headline": "Add 16 edge case tests across ManifestDiff, ScriptRunner, DepConflict…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T16:38:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4e279cfc6f354844a1fbee9e8a7e2facc0a34ae8",
"body": "…, trace) with 8 tests for multi-layer .npmrc resolution (project → user → global)\\n\\nResult: {\"status\":\"keep\",\"test_count\":2599}",
"is_bot": false,
"headline": "Add NPM.NpmrcMerge module (resolve, layers, read_layer, active_layers…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T16:38:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "688de9ef66462eff32a274b68886f2414785abc8",
"body": "…format_summary) with 12 tests, NPM.ReleaseNotes (10 tests), mix npm.deps task, integrate output into install flow — packages listed like * bunt 1.0.0 (Hex package) (mix)\n\n locked at 1.0.0 (bunt) dc5f86aa\n ok\n* credo 1.7.17 (Hex package) (mix)\n locked at 1.7.17 (credo) 1eb5645c\n ok\n* dialyxir 1.\n[…]\n package) (mix)\n locked at 0.5.17 (req) 0b8bc6ff\n ok\n* telemetry 1.4.1 (Hex package) (rebar3)\n locked at 1.4.1 (telemetry) 2172e05a\n ok after install\\n\\nResult: {\"status\":\"keep\",\"test_count\":2591}",
"is_bot": false,
"headline": "Add mix deps-style UX: NPM.DepsOutput (format_lockfile, format_diff, …",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T16:37:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e8540988b7bc170ec81f788c02c712e52a9fd2bd",
"body": "…mmary, format) with 10 tests for computing available major/minor/patch updates\\n\\nResult: {\"status\":\"keep\",\"test_count\":2569}",
"is_bot": false,
"headline": "Add NPM.PackageUpdate module (update_type, compute, group_by_type, su…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T16:02:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f4b07226569c403207a2828404c43c3814ddc67a",
"body": "…, group_failures, format_results) with 9 tests for verifying installed packages match lockfile\\n\\nResult: {\"status\":\"keep\",\"test_count\":2559}",
"is_bot": false,
"headline": "Add NPM.IntegrityCheck module (verify_package, verify_all, all_valid?…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T16:01:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f63b68c9f58cf8dfceca538953555dbc025d5ece",
"body": "…?, missing, generate, check) with 14 tests for .gitignore management\\n\\nResult: {\"status\":\"keep\",\"test_count\":2550}",
"is_bot": false,
"headline": "Add NPM.Gitignore module (essential, recommended, covers_node_modules…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T16:00:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e8bb9ba9608728161ef150ff750b9e92d72efff4",
"body": "…at) with 11 tests for detecting version conflicts between dependency groups\\n\\nResult: {\"status\":\"keep\",\"test_count\":2536}",
"is_bot": false,
"headline": "Add NPM.DepConflict module (find, conflicts?, count, duplicated, form…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T15:59:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f7847994ff15d1456f515c92ef4fe5ebbe9dc1dc",
"body": "… detect_patterns, names, count, missing_common) with 13 tests — delegates lifecycle list to NPM.Lifecycle.hook_names/0\\n\\nResult: {\"status\":\"keep\",\"test_count\":2525}",
"is_bot": false,
"headline": "Add NPM.ScriptRunner module (extract, lifecycle, custom, has_script?,…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T15:58:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5fee78f1fea6f1b1a0775b42e99af18ab4d890e9",
"body": "…th 12 tests for diffing two package.json files — detects added/removed/changed deps, scripts, version\\n\\nResult: {\"status\":\"keep\",\"test_count\":2512}",
"is_bot": false,
"headline": "Add NPM.ManifestDiff module (diff, diff_deps, equivalent?, format) wi…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T15:57:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a631295c14a621e2756659f793f96f453d94d162",
"body": "…ntegration/edge tests across DepFreshness+SnapshotDiff, Validate+PackageQuality, LockfileStats+Report, Diagnostics+NodeVersion, BundleAnalysis, InstallStrategy, Migration+Corepack, Workspaces+Monorepo, Bin+DepPath, Conditional+TypeField\\n\\nResult: {\"status\":\"keep\",\"test_count\":2500}",
"is_bot": false,
"headline": "🎯 2500 tests milestone! Add NPM.DepFreshness module (10 tests) + 15 i…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T15:54:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dbb5f1f8eca50e0cba9ebdf1df4633ba735fcf96",
"body": "… Diagnostics, PackageQuality, SupplyChain, ImportMap, Conditional, DepStats, PhantomDep, SnapshotDiff, Compat, PeerDep, Funding, Corepack, SideEffects, Npmrc\\n\\nResult: {\"status\":\"keep\",\"test_count\":2475}",
"is_bot": false,
"headline": "Add 17 cross-module edge case tests across BundleAnalysis, Migration,…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T15:53:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2cf1ce74d41c4fb9697e12be71c35612e8de1c6e",
"body": "… format_size) with 8 tests for lockfile metadata and content analysis\\n\\nResult: {\"status\":\"keep\",\"test_count\":2458}",
"is_bot": false,
"headline": "Add NPM.LockfileStats module (compute, content_stats, estimated_size,…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T15:52:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8c5ab7f0cda7e0aa5a1c464bb7a6973f0edaf084",
"body": "…erage) with 10 tests for package metadata quality scoring and grading\\n\\nResult: {\"status\":\"keep\",\"test_count\":2450}",
"is_bot": false,
"headline": "Add NPM.PackageQuality module (score, grade, missing_fields, rank, av…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T15:51:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "754689a3e1f11ca93880c5245acc232c85830351",
"body": "…ject health diagnostics — checks package.json, lockfile, node_modules, .npmrc auth\\n\\nResult: {\"status\":\"keep\",\"test_count\":2440}",
"is_bot": false,
"headline": "Add NPM.Diagnostics module (run, format, counts) with 8 tests for pro…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T15:51:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "93565691ca3286c82e4e78d8f3155e228db81ec8",
"body": "…g_changes, steps, format_guide) with 12 tests for npm version migration guidance\\n\\nResult: {\"status\":\"keep\",\"test_count\":2432}",
"is_bot": false,
"headline": "Add NPM.Migration module (lockfile_version, needs_migration?, breakin…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T15:49:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fe9092c0907fcc341b9b57b8af2ae5b2ca76272f",
"body": "…) with 13 tests for package bundle-friendliness scoring — ESM, tree-shaking, exports fields\\n\\nResult: {\"status\":\"keep\",\"test_count\":2420}",
"is_bot": false,
"headline": "Add NPM.BundleAnalysis module (score, grade, recommendations, analyze…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T15:48:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f83024bf022d6441c4a429f41c8c9b087b89ee30",
"body": "…erge, count) with 8 tests for browser import map generation from lockfile\\n\\nResult: {\"status\":\"keep\",\"test_count\":2407}",
"is_bot": false,
"headline": "Add NPM.ImportMap module (generate, generate_for, to_json, to_html, m…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T15:47:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6b10379e43c112957a293858c0ad7619a89a3ede",
"body": "…for supply chain security assessment — combines integrity, phantom deps, risk scoring\\n\\nResult: {\"status\":\"keep\",\"test_count\":2399}",
"is_bot": false,
"headline": "Add NPM.SupplyChain module (assess, risk_score, format) with 7 tests …",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T15:46:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "565458e616f356466d4a35535fddb79ed1f1c6b1",
"body": "…apshotDiff, PhantomDep, Conditional, Compat, DepPath, DepStats, PublishConfig, Corepack, LockfileCheck, PackageFiles\\n\\nResult: {\"status\":\"keep\",\"test_count\":2392}",
"is_bot": false,
"headline": "Add 21 edge case tests across Workspaces, Npmrc, HoistingConflict, Sn…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T15:45:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2855ffebea7e832c4d09270fb514219810b8172d",
"body": "…6 tests for aggregate dependency statistics — scope distribution, version breakdown, dep counts\\n\\nResult: {\"status\":\"keep\",\"test_count\":2371}",
"is_bot": false,
"headline": "Add NPM.DepStats module (compute, top_scopes, avg_deps, format) with …",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T15:45:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0548769c8cdf6313db47383faef124c7eb051f4e",
"body": "…nown_conditions, known_conditions) with 14 tests for conditional exports/imports resolution\\n\\nResult: {\"status\":\"keep\",\"test_count\":2365}",
"is_bot": false,
"headline": "Add NPM.Conditional module (resolve, conditions, uses_condition?, unk…",
"author_name": "Danila Poyarkov",
"author_login": "dannote",
"committed_at": "2026-03-13T15:44:17Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 18,
"commits_last_year": 334,
"latest_release_at": "2026-07-20T18:49:04Z",
"latest_release_tag": "v0.7.6",
"releases_from_tags": false,
"days_since_last_push": 15,
"active_weeks_last_year": 10,
"days_since_latest_release": 15,
"mean_days_between_releases": 10.8
},
"artifacts": {
"collected": true,
"structure": [],
"declarations": []
},
"community": {
"has_readme": true,
"has_license": true,
"readme_badges": {
"hosts": [
"github.com",
"shields.io"
],
"total": 2,
"header": 2,
"collected": true,
"has_inspect_badge": false
},
"has_description": true,
"has_contributing": false,
"health_percentage": 37,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "npm",
"exists": true,
"license": "MIT",
"keywords": [],
"ecosystem": "hex",
"categories": [],
"matches_repo": true,
"registry_url": "https://hex.pm/packages/npm",
"declared_type": null,
"is_deprecated": false,
"latest_version": "0.7.6",
"repository_url": "https://github.com/elixir-volt/npm_ex",
"versions_count": 24,
"total_downloads": 7348,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 2007,
"first_published_at": "2026-03-11T08:22:54.141810Z",
"latest_published_at": "2026-07-20T18:40:17.451067Z",
"latest_version_yanked": null,
"days_since_latest_publish": 15
}
]
},
"popularity": {
"forks": 0,
"stars": 21,
"watchers": 1,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": null,
"open_issues_and_prs": 1
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"mix.exs"
],
"largest_source_bytes": 39660,
"source_files_sampled": 373,
"oversized_source_files": 0,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"mix.exs"
],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"hex"
],
"dependencies": [
{
"name": "npm_semver",
"manifest": "mix.exs",
"ecosystem": "hex",
"version_constraint": "~> 0.1.0"
},
{
"name": "hex_solver",
"manifest": "mix.exs",
"ecosystem": "hex",
"version_constraint": "~> 0.2"
},
{
"name": "jason",
"manifest": "mix.exs",
"ecosystem": "hex",
"version_constraint": "~> 1.4"
},
{
"name": "req",
"manifest": "mix.exs",
"ecosystem": "hex",
"version_constraint": "~> 0.5"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 0,
"open_issues": 1,
"closed_ratio": 0.75,
"closed_issues": 3,
"closed_unmerged_prs": 0
},
"bus_factor": 1,
"bot_contributors": 0,
"top_contributors": [
{
"type": "User",
"login": "dannote",
"commits": 334,
"avatar_url": "https://avatars.githubusercontent.com/u/2206583?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml"
],
"has_docs_dir": false,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"mix.lock"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": null,
"reason": "no pull request found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/30 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 6,
"reason": "project has 2 contributing companies or organizations -- score normalized to 6",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 0,
"reason": "no update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "no SAST tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 10,
"reason": "GitHub workflow tokens follow principle of least privilege",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "11 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "58b18bb4869ee42919a534a7c1338848d89076d3",
"ran_at": "2026-08-05T09:27:22Z",
"aggregate_score": 4.1,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"recent_prs": {
"merged_7d": 0,
"decided_7d": 0,
"merged_30d": 0,
"authors_30d": 0,
"decided_30d": 0,
"sample_size": 0,
"window_days": 30,
"sample_exhausted": false,
"authors_probed_30d": 0,
"newcomer_merged_30d": 0,
"bot_prs_excluded_30d": 0,
"newcomer_authors_30d": 0,
"newcomer_decided_30d": 0
},
"ci_last_run_at": "2026-07-20T18:40:11Z",
"oldest_open_prs": [],
"last_merged_pr_at": null,
"ci_last_conclusion": "FAILURE",
"oldest_open_issues": [
{
"number": 4,
"created_at": "2026-05-20T18:27:41Z",
"last_comment_at": "2026-06-07T03:52:51Z",
"last_comment_author": "charlieaten"
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/elixir-volt/npm_ex",
"host": "github.com",
"name": "npm_ex",
"owner": "elixir-volt"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": "The weighted overall 55 is calibrated to 57 on the published index scale (record calibration 2026-08-02).",
"notes": [
{
"code": "overall_calibration",
"params": {
"raw": 55,
"calibrated": 57,
"calibration": "2026-08-02"
}
}
],
"value": 57,
"inputs": {
"security": 41,
"vitality": 78,
"community": 40,
"governance": 52,
"calibration": "2026-08-02",
"engineering": 60,
"ai_readiness": 38,
"weighted_overall_raw": 55
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 78,
"weight": 0.21,
"metrics": [
{
"key": "development_activity",
"band": "moderate",
"name": "Development activity",
"note": null,
"notes": [],
"value": 64,
"inputs": {
"commits_last_year": 334,
"human_commit_share": 1,
"days_since_last_push": 15,
"active_weeks_last_year": 10
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 15 days ago",
"points": 28.8,
"status": "partial",
"details": [
{
"code": "push_recency",
"params": {
"days": 15
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "10/52 weeks with commits",
"points": 6.9,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 10
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "334 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 334
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "exceptional",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 18,
"latest_release_tag": "v0.7.6",
"releases_from_tags": false,
"days_since_latest_release": 15,
"mean_days_between_releases": 10.8
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "18 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 18
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 15 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 15
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~10.8 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 10.8
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "exceptional",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "weak",
"name": "Community & Adoption",
"value": 40,
"weight": 0.17,
"metrics": [
{
"key": "popularity",
"band": "at_risk",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 21,
"inputs": {
"forks": 0,
"stars": 21,
"watchers": 1,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "21 stars",
"points": 21.1,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 21
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "1 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 1
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"readme_badges": 2,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"readme_badge_services": [
"github.com",
"shields.io"
],
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 55,
"inputs": {
"packages": [
"npm"
],
"dependents": null,
"ecosystems": "hex",
"total_downloads": 7348,
"monthly_downloads": 2007
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "2,007 downloads/month across hex",
"points": 44,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 2007,
"ecosystems": "hex"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 52,
"weight": 0.23,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 16,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 2 contributing companies or organizations -- score normalized to 6",
"points": 6,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "moderate",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): PR acceptance, Newcomer PR acceptance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"pr_acceptance",
"newcomer_pr_acceptance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 55,
"inputs": {
"merged_prs": 0,
"open_issues": 1,
"closed_issues": 3,
"prs_merged_7d": 0,
"prs_decided_7d": 0,
"prs_merged_30d": 0,
"prs_decided_30d": 0,
"issue_closed_ratio": 0.75,
"closed_unmerged_prs": 0,
"first_time_authors_30d": 0,
"first_time_prs_merged_30d": 0,
"first_time_prs_decided_30d": 0
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "75% of issues closed",
"points": 31.5,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 75
}
}
],
"max_points": 42
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "no decided pull requests or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_decided_prs_or_data",
"params": {}
}
],
"max_points": 30
},
{
"key": "newcomer_pr_acceptance",
"name": "Newcomer PR acceptance",
"detail": "no first-time contributor's PR decided in 30d",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_newcomer_prs",
"params": {
"days": 30
}
}
],
"max_points": 13
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "moderate",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 52,
"inputs": {
"followers": 49,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "elixir-volt",
"public_repos": 18,
"account_age_days": 145
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "49 followers of elixir-volt",
"points": 12.2,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 49,
"login": "elixir-volt"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "18 public repos, account ~0 yr old",
"points": 10.1,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 18
}
},
{
"code": "account_age_years",
"params": {
"years": 0
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "exceptional",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"npm"
],
"ecosystems": "hex",
"any_deprecated": false,
"min_days_since_publish": 15
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on hex",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "hex"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 15 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 15
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "24 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 24
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "moderate",
"name": "Engineering Quality",
"value": 60,
"weight": 0.19,
"metrics": [
{
"key": "engineering_practices",
"band": "moderate",
"name": "Engineering practices",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_ci_tests"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 60,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "1 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 1
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "moderate",
"name": "Documentation",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"topics": [
"elixir",
"mix",
"no-nodejs",
"npm",
"package-manager"
],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": false,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "5 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 5
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "weak",
"name": "Security",
"value": 41,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "weak",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"ci_tests",
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 41,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 15,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 3,
"scorecard_aggregate": 4.1
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "no pull request found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/30 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 2 contributing companies or organizations -- score normalized to 6",
"points": 1.5,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "no update tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "no SAST tool detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "GitHub workflow tokens follow principle of least privilege",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "11 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "weak",
"name": "AI Readiness",
"value": 38,
"weight": 0.04,
"metrics": [
{
"key": "ai_agent_context",
"band": "critical",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 19,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.36,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "36 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 19.2,
"status": "partial",
"details": [
{
"code": "legible_history",
"params": {
"legible": 36,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "weak",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 45,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"mix.lock"
],
"has_dockerfile": false,
"typed_language": false,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0,
"toolchain_manifests": [
"mix.exs"
],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "mix.exs (toolchain convention, no task runner)",
"points": 12.6,
"status": "partial",
"details": [
{
"code": "toolchain_convention",
"params": {
"files": "mix.exs"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "moderate",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"primary_language": "Elixir",
"largest_source_bytes": 39660,
"source_files_sampled": 373,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Elixir without a type-check config",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_typecheck_config_language",
"params": {
"language": "Elixir"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/373 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 373,
"oversized": 0
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
}
],
"classification": {
"top": [
"library"
],
"labels": [
"library"
],
"scores": {
"library": 6
},
"primary": "library",
"evidence": [
{
"tier": "distribution",
"label": "library",
"source": "registry:hex",
"weight": 6
}
],
"artifacts": [],
"confidence": "medium",
"host_extension": false,
"runs_as_process": false,
"consumed_by_code": true
},
"metrics_version": "2.5.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-08-05T09:27:27.064495Z",
"schema_version": "0.31.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/e/elixir-volt/npm_ex.svg",
"full_name": "elixir-volt/npm_ex",
"license_state": "standard",
"license_spdx": "MIT"
}