原始 JSON 报告 机器可读
{
"data": {
"repo": {
"topics": [
"laravel"
],
"is_fork": false,
"size_kb": 1431,
"has_wiki": true,
"homepage": "https://escalated.dev/framework/laravel",
"languages": {
"CSS": 59,
"PHP": 1712328,
"Vue": 1383,
"Blade": 14795,
"Shell": 1100,
"Dockerfile": 2143,
"JavaScript": 1931
},
"pushed_at": "2026-07-30T10:35:07Z",
"created_at": "2026-02-07T03:44:30Z",
"owner_type": "Organization",
"updated_at": "2026-07-30T10:33:59Z",
"description": "Escalated plugin for Laravel",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "PHP",
"significant_languages": [
"PHP"
]
},
"owner": {
"blog": "https://escalated.dev",
"name": "Escalated",
"type": "Organization",
"login": "escalated-dev",
"company": null,
"location": null,
"followers": 10,
"avatar_url": "https://avatars.githubusercontent.com/u/259997415?v=4",
"created_at": "2026-02-07T03:42:48Z",
"is_verified": null,
"public_repos": 31,
"account_age_days": 173
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v1.5.1",
"kind": "patch",
"published_at": "2026-06-04T05:29:13Z"
},
{
"tag": "v1.5.0",
"kind": "minor",
"published_at": "2026-06-04T05:10:51Z"
},
{
"tag": "v1.4.1",
"kind": "patch",
"published_at": "2026-05-29T11:53:46Z"
},
{
"tag": "v1.4.0",
"kind": "minor",
"published_at": "2026-05-29T02:46:28Z"
},
{
"tag": "v1.3.0",
"kind": "minor",
"published_at": "2026-05-10T21:51:42Z"
},
{
"tag": "v1.2.5",
"kind": "patch",
"published_at": "2026-05-07T14:22:06Z"
},
{
"tag": "v1.2.4",
"kind": "patch",
"published_at": "2026-05-07T03:42:56Z"
},
{
"tag": "v1.2.3",
"kind": "patch",
"published_at": "2026-05-07T01:48:06Z"
},
{
"tag": "v1.2.2",
"kind": "patch",
"published_at": "2026-04-20T15:23:50Z"
},
{
"tag": "v1.2.1",
"kind": "patch",
"published_at": "2026-04-19T00:17:40Z"
},
{
"tag": "v1.2.0",
"kind": "minor",
"published_at": "2026-04-18T04:21:05Z"
},
{
"tag": "v1.1.0",
"kind": "minor",
"published_at": "2026-04-06T17:18:23Z"
},
{
"tag": "v1.0.0",
"kind": "major",
"published_at": "2026-04-06T08:30:26Z"
}
],
"recent_commits": [
{
"oid": "db7d6832c2738a67fc294a59071d7fc757d90eae",
"body": "Bumps [@tailwindcss/postcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss) from 4.3.2 to 4.3.3.\n- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)\n- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)\n- [Commits]\n[…]\nrect:development\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump @tailwindcss/postcss in /docker/host-app (#164)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-30T10:32:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e6b17f2c54280af660f5637a28877ba5938c8749",
"body": "Bumps [@vitejs/plugin-vue](https://github.com/vitejs/vite-plugin-vue/tree/HEAD/packages/plugin-vue) from 6.0.7 to 6.0.8.\n- [Release notes](https://github.com/vitejs/vite-plugin-vue/releases)\n- [Changelog](https://github.com/vitejs/vite-plugin-vue/blob/main/packages/plugin-vue/CHANGELOG.md)\n- [Commit\n[…]\nrect:development\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump @vitejs/plugin-vue in /docker/host-app (#159)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-19T22:42:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c65694c85ce187e66240086100f266d583c63fbf",
"body": "Bumps [laravel-vite-plugin](https://github.com/laravel/vite-plugin) from 3.1.0 to 3.1.3.\n- [Release notes](https://github.com/laravel/vite-plugin/releases)\n- [Changelog](https://github.com/laravel/vite-plugin/blob/3.x/CHANGELOG.md)\n- [Commits](https://github.com/laravel/vite-plugin/compare/v3.1.0...\n[…]\nrect:development\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump laravel-vite-plugin in /docker/host-app (#160)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-19T22:42:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "37b341f72d991ac089ce4c38fa92432b81989c9b",
"body": "Bumps [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss) from 4.3.2 to 4.3.3.\n- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)\n- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)\n- [Commits](https://github.co\n[…]\nigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Matt Gros <3311227+mpge@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump tailwindcss in /docker/host-app (#161)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-19T22:42:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4f5a6cf41b84fb69abf77ad121413e7f6ccfcfc3",
"body": "…158)\n\nBumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.1.4 to 8.1.5.\n- [Release notes](https://github.com/vitejs/vite/releases)\n- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)\n- [Commits](https://github.com/vitejs/vite/commits/v8.1.5/pac\n[…]\nrect:development\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump vite from 8.1.4 to 8.1.5 in /docker/host-app (#…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-19T22:41:25Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "12634316ee1727434487d6fbc3a772c54570953c",
"body": "…#162)\n\nBumps [vue](https://github.com/vuejs/core) from 3.5.39 to 3.5.40.\n- [Release notes](https://github.com/vuejs/core/releases)\n- [Changelog](https://github.com/vuejs/core/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/vuejs/core/compare/v3.5.39...v3.5.40)\n\n---\nupdated-dependencies:\n- de\n[…]\nrect:development\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump vue from 3.5.39 to 3.5.40 in /docker/host-app (…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-19T21:21:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fb88980b9dd3a6f2daee28fd5e4a7491e75497f5",
"body": "Bumps [@inertiajs/vue3](https://github.com/inertiajs/inertia/tree/HEAD/packages/vue3) from 3.6.0 to 3.6.1.\n- [Release notes](https://github.com/inertiajs/inertia/releases)\n- [Changelog](https://github.com/inertiajs/inertia/blob/3.x/CHANGELOG.md)\n- [Commits](https://github.com/inertiajs/inertia/commi\n[…]\nrect:development\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump @inertiajs/vue3 in /docker/host-app (#157)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-14T23:08:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5dc62d0b38357e4cdfa09bd846b474ffdb53f211",
"body": "…156)\n\nBumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.1.3 to 8.1.4.\n- [Release notes](https://github.com/vitejs/vite/releases)\n- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)\n- [Commits](https://github.com/vitejs/vite/commits/v8.1.4/pac\n[…]\nrect:development\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump vite from 8.1.3 to 8.1.4 in /docker/host-app (#…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-14T23:08:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4d97d70746990e72e262bf25d15ffe42eeba43bd",
"body": "…pp (#151)\n\nBumps [postcss](https://github.com/postcss/postcss) from 8.5.15 to 8.5.16.\n- [Release notes](https://github.com/postcss/postcss/releases)\n- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/postcss/postcss/compare/8.5.15...8.5.16)\n\n---\n\n[…]\nrect:development\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump postcss from 8.5.15 to 8.5.16 in /docker/host-a…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-06T03:42:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "609e891b50b0a12e8250e592f8e5b6a3c145ed51",
"body": "Bumps [@inertiajs/vue3](https://github.com/inertiajs/inertia/tree/HEAD/packages/vue3) from 3.5.0 to 3.6.0.\n- [Release notes](https://github.com/inertiajs/inertia/releases)\n- [Changelog](https://github.com/inertiajs/inertia/blob/3.x/CHANGELOG.md)\n- [Commits](https://github.com/inertiajs/inertia/commi\n[…]\nigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Matt Gros <3311227+mpge@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump @inertiajs/vue3 in /docker/host-app (#152)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-06T03:41:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3bec86fb13a972cb463d1f6df67c2ace85eee986",
"body": "Bumps [@tailwindcss/postcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss) from 4.3.1 to 4.3.2.\n- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)\n- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)\n- [Commits]\n[…]\nrect:development\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump @tailwindcss/postcss in /docker/host-app (#154)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-06T03:40:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fa36bf0bbe1c4476de95626294396c5f26a6d94d",
"body": "…155)\n\nBumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.1.0 to 8.1.3.\n- [Release notes](https://github.com/vitejs/vite/releases)\n- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)\n- [Commits](https://github.com/vitejs/vite/commits/v8.1.3/pac\n[…]\nrect:development\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump vite from 8.1.0 to 8.1.3 in /docker/host-app (#…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-06T03:40:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "18c4111aa7cde8d6ea8e1ec3cab01b51e1b9807a",
"body": "Supersedes dependabot #147, which went stale (lockfile conflict after the\nother host-app dependabot PRs merged, and dependabot did not rebase it).\nApplied directly.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(deps-dev): bump vue to 3.5.39 in /docker/host-app (#150)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-06-27T10:41:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "58ae5d3410c9442afcac38667c82c64ee96ec820",
"body": "Bumps [@inertiajs/vue3](https://github.com/inertiajs/inertia/tree/HEAD/packages/vue3) from 3.4.0 to 3.5.0.\n- [Release notes](https://github.com/inertiajs/inertia/releases)\n- [Changelog](https://github.com/inertiajs/inertia/blob/3.x/CHANGELOG.md)\n- [Commits](https://github.com/inertiajs/inertia/commi\n[…]\nrect:development\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump @inertiajs/vue3 in /docker/host-app (#148)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-27T10:16:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "45238590981ca113f73d0208c99d0961214a937d",
"body": "…#149)\n\nBumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.0.16 to 8.1.0.\n- [Release notes](https://github.com/vitejs/vite/releases)\n- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)\n- [Commits](https://github.com/vitejs/vite/commits/create-v\n[…]\nrect:development\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump vite from 8.0.16 to 8.1.0 in /docker/host-app (…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-27T10:16:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e996bfb6feba35c81013e760c47f40f94bec72be",
"body": "… (#146)\n\nBumps [axios](https://github.com/axios/axios) from 1.18.0 to 1.18.1.\n- [Release notes](https://github.com/axios/axios/releases)\n- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)\n- [Commits](https://github.com/axios/axios/compare/v1.18.0...v1.18.1)\n\n---\nupdated-dependenci\n[…]\nrect:development\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump axios from 1.18.0 to 1.18.1 in /docker/host-app…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-27T10:13:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7a364a2ef6e454d3f06f470573c75854f26d5f54",
"body": null,
"is_bot": false,
"headline": "ci: remove unused FOSSA workflow and badge",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-06-20T18:52:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "44ce1241acb65a6a0bd0f3102430be3588f19cd0",
"body": "Bumps [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss) from 4.3.0 to 4.3.1.\n- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)\n- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)\n- [Commits](https://github.co\n[…]\nrect:development\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump tailwindcss in /docker/host-app (#141)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-20T13:13:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ae082881d8d600dd6f8d9594a858f3985b1fb11f",
"body": "… (#140)\n\nBumps [axios](https://github.com/axios/axios) from 1.17.0 to 1.18.0.\n- [Release notes](https://github.com/axios/axios/releases)\n- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)\n- [Commits](https://github.com/axios/axios/compare/v1.17.0...v1.18.0)\n\n---\nupdated-dependenci\n[…]\nrect:development\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump axios from 1.17.0 to 1.18.0 in /docker/host-app…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-20T13:13:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7fe351ba1ca6db752edcc8a62067c0adf5f5abf1",
"body": "Bumps [@tailwindcss/postcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss) from 4.3.0 to 4.3.1.\n- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)\n- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)\n- [Commits]\n[…]\nrect:development\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump @tailwindcss/postcss in /docker/host-app (#139)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-20T13:13:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9bd8b4b42bdcce5e3e5a2c11ba553131983c8dc5",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v6...v7)\n\n---\nupdated-dependenc\n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/checkout from 6 to 7 (#138)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-20T13:13:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "077b7000f0b37ec6b4fc20755dc5eaeb51bf6beb",
"body": "…ly (#144)\n\nescalated:install ran `npm install @escalated-dev/escalated` through\nLaravel's Process facade with the default 60s timeout. npm routinely\nexceeds that and throws ProcessTimedOutException, which bypassed the\nexisting \"show manual instructions\" fallback (it only handled a non-zero\nexit, no\n[…]\ncause.\n- Add regression tests: a faked npm timeout no longer aborts the\n installer, and a non-zero npm exit still shows manual instructions.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(install): raise npm/composer Process timeout and degrade graceful…",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-06-20T13:13:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "429cd1ebabdeab9a01d7994aad92db6b4cdd89f1",
"body": "…ix installs (#145)\n\nComposer 2.9+ refuses to install packages affected by security advisories.\nTwo newly-published laravel/framework 11.x advisories (PKSA-m5cs-t1y6-qpcs,\nPKSA-3r5d-mb8f-1qw9) are not yet in config.audit.ignore, so\n`composer require laravel/framework:^11.0` can no longer resolve and\n[…]\nting 11.x ignores (root CI config only; does not\npropagate to host apps). Unblocks the red L^11 legs on dependabot PRs\n#138-#141 and on main.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
"is_bot": false,
"headline": "ci: ignore two new laravel/framework 11.x advisories so the L^11 matr…",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-06-20T11:11:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "45da63245fc5f0e2e9db609f3616f43bf7f9bc1d",
"body": "…cker/host-app/vue-3.5.38\n\nchore(deps-dev): bump vue from 3.5.35 to 3.5.38 in /docker/host-app",
"is_bot": false,
"headline": "Merge pull request #136 from escalated-dev/dependabot/npm_and_yarn/do…",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-06-12T04:10:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "097091d04d8dc7a34c93a30e2dfb6bc083d59adf",
"body": "…3.5.38",
"is_bot": false,
"headline": "Merge branch 'main' into dependabot/npm_and_yarn/docker/host-app/vue-…",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-06-12T04:10:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "651cd7bf27312446d44da8f710e11d2acabfabd1",
"body": "…cker/host-app/inertiajs/vue3-3.4.0\n\nchore(deps-dev): bump @inertiajs/vue3 from 3.3.1 to 3.4.0 in /docker/host-app",
"is_bot": false,
"headline": "Merge pull request #137 from escalated-dev/dependabot/npm_and_yarn/do…",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-06-12T04:09:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "723906c6d40e3c60abefc06056139a8730c2c73d",
"body": "Bumps [@inertiajs/vue3](https://github.com/inertiajs/inertia/tree/HEAD/packages/vue3) from 3.3.1 to 3.4.0.\n- [Release notes](https://github.com/inertiajs/inertia/releases)\n- [Changelog](https://github.com/inertiajs/inertia/blob/3.x/CHANGELOG.md)\n- [Commits](https://github.com/inertiajs/inertia/commi\n[…]\ndependency-name: \"@inertiajs/vue3\"\n dependency-version: 3.4.0\n dependency-type: direct:development\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump @inertiajs/vue3 in /docker/host-app",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-12T03:24:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1620f8a44328f682017157269f3e3c4c1d510fc8",
"body": "Bumps [vue](https://github.com/vuejs/core) from 3.5.35 to 3.5.38.\n- [Release notes](https://github.com/vuejs/core/releases)\n- [Changelog](https://github.com/vuejs/core/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/vuejs/core/compare/v3.5.35...v3.5.38)\n\n---\nupdated-dependencies:\n- dependency-name: vue\n dependency-version: 3.5.38\n dependency-type: direct:development\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump vue from 3.5.35 to 3.5.38 in /docker/host-app",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-12T03:23:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b9f642f23af1f7539f242cd04aa280cf1c2dfb4b",
"body": "Add SECURITY.md security policy",
"is_bot": false,
"headline": "Merge pull request #135 from escalated-dev/chore/add-security-policy",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-06-10T00:43:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7d6f0e4c0293b90699571a2de6aedde30d1a58d4",
"body": null,
"is_bot": false,
"headline": "Add SECURITY.md pointing to main Escalated security policy",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-06-10T00:36:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2ef9417e2e69c0ab87c9b4351c58f64c691a62a7",
"body": "…cker/host-app (#134)\n\n* chore(deps-dev): bump @tailwindcss/postcss in /docker/host-app\n\nBumps [@tailwindcss/postcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-postcss) from 4.2.4 to 4.3.0.\n- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)\n- [C\n[…]\nigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Matt Gros <3311227+mpge@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump @tailwindcss/postcss from 4.2.4 to 4.3.0 in /do…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-06T14:11:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b7166574b613accf20a48fc71a5b7a3018885f69",
"body": "Bumps [@inertiajs/vue3](https://github.com/inertiajs/inertia/tree/HEAD/packages/vue3) from 3.3.0 to 3.3.1.\n- [Release notes](https://github.com/inertiajs/inertia/releases)\n- [Changelog](https://github.com/inertiajs/inertia/blob/3.x/CHANGELOG.md)\n- [Commits](https://github.com/inertiajs/inertia/commi\n[…]\nrect:development\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump @inertiajs/vue3 in /docker/host-app (#133)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-06T14:10:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7e553700c991f451a22e12b2467a893da443c0ec",
"body": "Bumps [tailwindcss](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/tailwindcss) from 4.2.4 to 4.3.0.\n- [Release notes](https://github.com/tailwindlabs/tailwindcss/releases)\n- [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md)\n- [Commits](https://github.co\n[…]\nrect:development\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump tailwindcss in /docker/host-app (#132)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-06T14:09:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a64ee25714b3a9a3c3867e960624ee647875858f",
"body": "… (#130)\n\nBumps [axios](https://github.com/axios/axios) from 1.15.2 to 1.17.0.\n- [Release notes](https://github.com/axios/axios/releases)\n- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)\n- [Commits](https://github.com/axios/axios/compare/v1.15.2...v1.17.0)\n\n---\nupdated-dependenci\n[…]\nrect:development\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump axios from 1.15.2 to 1.17.0 in /docker/host-app…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-06T14:09:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c7a95c06522fd05b77c429d61b6dd1da6c2a2213",
"body": "Bumps [@escalated-dev/escalated](https://github.com/escalated-dev/escalated) from 0.8.0 to 0.9.0.\n- [Release notes](https://github.com/escalated-dev/escalated/releases)\n- [Changelog](https://github.com/escalated-dev/escalated/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/escalated-dev/escal\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump @escalated-dev/escalated from 0.8.0 to 0.9.0 (#131)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-06T14:09:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "890c6bf893c2f33c109c19d5cc75b1363caa5a8b",
"body": "- enable ESCALATED_ENABLE_NEWSLETTERS via .env.docker (artisan serve does not\n forward OS-only env vars to its php -S worker, so it must live in .env)\n- apk add git in the assets stage: @escalated-dev/escalated pulls\n @escalated-dev/locale via a github: URL, which npm needs git to resolve\n- bump demo host-app frontend to @escalated-dev/escalated ^0.9.0",
"is_bot": false,
"headline": "chore(docker): showcase newsletters in the demo",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-06-04T06:43:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "66d8a7624a2e5f883eab5ab7d67bb84a7e03f18b",
"body": null,
"is_bot": false,
"headline": "chore(release): 1.5.1",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-06-04T05:28:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d1de53acce794716c4c061c2ef2f1f17945aecbe",
"body": "…lls (Composer 2.9 blocks advisory-affected packages)",
"is_bot": false,
"headline": "ci: ignore laravel/framework 11.x advisories so the L^11 matrix insta…",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-06-04T05:25:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dfd3637347cf7f14786f577dac8b073da15e23f2",
"body": null,
"is_bot": false,
"headline": "chore(release): 1.5.0",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-06-04T05:10:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8a2484bf77061360795c3ad3d8d0074c30f804a8",
"body": "…#129)\n\n* feat(newsletters): enforce newsletters.manage on admin route group + newsletters.send on send actions\n\n* feat(permissions): expose escalated.permissions in Inertia shared props for frontend gating\n\n---------\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(newsletters): enforce newsletters.manage/.send on admin routes (…",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-06-04T05:09:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cb6a62990c47571e867427f56942c8b20a839944",
"body": "…#128)\n\ncreated_by/added_by/sent_by used unsignedBigInteger, reintroducing the integer-only host-user-key assumption. Use Escalated::userForeignColumn (unsignedBigInteger by default -> identical schema for integer hosts; uuid/ulid/string for those hosts), like ticket_followers.user_id and tickets.assigned_to. FK columns (list_id/contact_id/template_id) stay bigint. 35 newsletter tests pass; Pint clean.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(newsletter): UUID-safe user-id columns in newsletter migrations (…",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-06-02T15:47:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "93856711150310efd088ca3cd25169a6217d5f72",
"body": "…ence) (#103)\n\n* feat(newsletters): add config keys (disabled by default)\n\n* feat(newsletters): create newsletter_lists table\n\n* feat(newsletters): create newsletter_list_members table\n\n* feat(newsletters): create newsletter_templates table\n\n* feat(newsletters): create newsletters table\n\n* feat(news\n[…]\ne\n backoff writes were silently dropped without it).\n\nAdds dispatcher tests for rate-limit, backoff-skip, and first-N auto-pause.\n\n---------\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(newsletters): admin-only broadcast system (Wave 1, Laravel refer…",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-06-02T03:34:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d71664ea1537602cfda8731935451117aa3cede9",
"body": "… (#127)\n\nPorts add_follower from the NestJS reference (escalated-nestjs#61). Laravel already has the ticket_followers pivot + Ticket::follow() (syncWithoutDetaching, idempotent), so this wires the executor case + validation allowlist only. Value is a host user key, trimmed and skipped when empty/0, mirroring assign_agent. Realizes discussion #88. Tests: follow + idempotent + empty-skip; 49 WorkflowEngine tests pass; Pint clean.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(workflow): add_follower action - auto-subscribe ticket followers…",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-06-02T02:14:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "973ef89b9b397f2aed2fd94e9e928f97ae75c23e",
"body": "CodeQL (actions/missing-workflow-permissions) flagged the run-tests\nworkflow for having no explicit `permissions` block, which leaves\nGITHUB_TOKEN at the repository default (often read/write). The test job\nonly checks out and runs Pest, so it needs nothing beyond `contents:\nread`. lint.yml (contents: write for auto-commit) and fossa.yml\n(contents: read) already declare explicit scopes.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
"is_bot": false,
"headline": "ci: set least-privilege permissions on run-tests workflow (#126)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-06-02T01:55:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b2bbc67e5b7add002d6d2119da533808d3017818",
"body": "…9) (#122)\n\nTickets can now reference one or more host-app entities they are *about*\n(Project, Customer, asset, …), distinct from the requester (the person).\n\n- New Contracts\\TicketSubject (title/subtitle/url/color/icon) + a\n PresentsAsTicketSubject trait with sane defaults.\n- escalated_ticket_subj\n[…]\na config allowlist\n (escalated.ticket_subjects.types) so request input can't resolve an\n arbitrary class.\n- Pest tests; README + CHANGELOG.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(tickets): attachable ticket subjects + presentation contract (#8…",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-31T05:55:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "07f6b3eee1adef79b17c04bd149edf4316dfd2fe",
"body": "…#124)\n\nbroadcastWith() read $reply->user_id / $reply->user, which don't exist on\nthe Reply model (it uses the polymorphic author_type/author_id + author()).\nEvery .reply.created payload therefore shipped author_id/author_name = null,\nrendering 'Unknown' for any consumer of the real-time event. Read\n[…]\nauthor relation (Ticketable display name, Users + Contacts) and add a\nnested author{id,name} mirroring ReplyResource. +Pest regression tests.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(replies): include real author in ReplyCreated broadcast payload (…",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-31T05:54:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a9ab0605de35c38b65998297f7c6b7d023dde85f",
"body": "- Add guarded migration to backfill skills routing columns that v1.4.0\n added by editing an already-run create migration (broke skill save on\n upgraded installs).\n- Restore agent existence validation in AssignTicketRequest (422 not 500),\n keeping int|string acceptance.\n- Make AssignmentService $s\n[…]\nk)\n to keep the v1.3.0 single-arg constructor working.\n- CHANGELOG: 1.4.1 + upgrade notes for the int|string TicketDriver/Ticket\n widening.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
"is_bot": false,
"headline": "fix: upgrade-safety regressions found in v1.4.0 audit (#120)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-29T11:51:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "acf98d9ca1d47fb1cfc7f5cc6702e3364e77a00d",
"body": "…#116)\n\nBumps [vue](https://github.com/vuejs/core) from 3.5.33 to 3.5.35.\n- [Release notes](https://github.com/vuejs/core/releases)\n- [Changelog](https://github.com/vuejs/core/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/vuejs/core/compare/v3.5.33...v3.5.35)\n\n---\nupdated-dependencies:\n- de\n[…]\nrect:development\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump vue from 3.5.33 to 3.5.35 in /docker/host-app (…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-29T03:48:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a80c1ff7d804402e8213f3786260df0d565187ef",
"body": "Co-authored-by: Matt Gros <mpge@users.noreply.github.com>",
"is_bot": false,
"headline": "docs: add Packagist version badge linking to the package page (#119)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-29T03:44:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "42edaf46ba48387a5c8470d6d5696872dc2a5421",
"body": "…pp (#118)\n\nBumps [postcss](https://github.com/postcss/postcss) from 8.5.13 to 8.5.15.\n- [Release notes](https://github.com/postcss/postcss/releases)\n- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/postcss/postcss/compare/8.5.13...8.5.15)\n\n---\n\n[…]\nrect:development\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump postcss from 8.5.13 to 8.5.15 in /docker/host-a…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-29T03:39:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0fd5fe9075550d69b15e87b55aa5ecdd3728544f",
"body": "Bumps [@escalated-dev/escalated](https://github.com/escalated-dev/escalated) from 0.7.1 to 0.8.0.\n- [Release notes](https://github.com/escalated-dev/escalated/releases)\n- [Changelog](https://github.com/escalated-dev/escalated/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/escalated-dev/escal\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump @escalated-dev/escalated in /docker/host-app (#117)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-29T03:39:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f368bf6a4465f508bb45854a35efff19cf02bbfb",
"body": "…(#115)\n\nBumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 8.0.10 to 8.0.14.\n- [Release notes](https://github.com/vitejs/vite/releases)\n- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)\n- [Commits](https://github.com/vitejs/vite/commits/v8.0.1\n[…]\nrect:development\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump vite from 8.0.10 to 8.0.14 in /docker/host-app …",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-29T03:39:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3cfc96ae28477a112d3bd178c4e742f281d43fcf",
"body": "Bumps [@vitejs/plugin-vue](https://github.com/vitejs/vite-plugin-vue/tree/HEAD/packages/plugin-vue) from 6.0.6 to 6.0.7.\n- [Release notes](https://github.com/vitejs/vite-plugin-vue/releases)\n- [Changelog](https://github.com/vitejs/vite-plugin-vue/blob/main/packages/plugin-vue/CHANGELOG.md)\n- [Commit\n[…]\nrect:development\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump @vitejs/plugin-vue in /docker/host-app (#114)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-29T03:39:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "525db5497cd5e0398c1f27854b47c7f731a19360",
"body": null,
"is_bot": false,
"headline": "chore(release): 1.4.0",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-29T02:46:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a05bcefbd34af6501c8f765567f224a41b23f530",
"body": "qs 6.15.1 (transitive via @inertiajs/core in the demo host-app) is\naffected by CVE-2026-8723 (NULL pointer dereference, medium 6.3). 6.15.2\nis a patch fix with identical dependencies (side-channel ^1.1.0), so this\nis a minimal lockfile-only bump.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(deps): bump qs 6.15.1 -> 6.15.2 (CVE-2026-8723) (#113)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-29T01:30:56Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ec8d65dc100bfd07c933d14742527afcac779403",
"body": "* feat(users): auto-detect host user key type for migration columns\n\nBuilds on the int|string fix (#109/#110): the package's user-referencing\ncolumns now match the host user model's key type automatically, so UUID/ULID/\nstring-keyed apps migrate with no manual edits.\n\n- Escalated::userKeyType() refl\n[…]\ndel uses HasUuids/HasUlids.\n\nAdds assign() regression tests (string id happy-path + clean\nInvalidArgumentException on unknown id).\n\n---------\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(users): auto-detect host user key type for migration columns (#112)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-29T01:14:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e091c670707423e77b0451c0abe5c22f9d523f9d",
"body": "Fixes a TypeError 500 (Argument #2 ($userId) must be of type int, string given)\nwhen host apps with UUID/string user primary keys open /support/admin/tickets.\n\n- SavedView::scopeForUser now takes (Builder $query, int|string $userId): Builder,\n mirroring Mention::scopeForUser (immediate bug).\n- Rela\n[…]\ncolumns (publish migrations + switch to uuid/string).\n- Regression test: SavedView::forUser() and Mention::forUser() with a UUID.\n\nRefs #109.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(users): support UUID/string host user keys throughout (#110)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-29T01:08:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fd9eaa57fb7d4c0b25628a454fa3e67ef4db5323",
"body": "Replace the hardcoded English \"Custom action dispatched.\" string in the\nagent and API ticket controllers with the\nescalated::messages.ticket.custom_action_dispatched lang key, matching the\ni18n convention used by every other ticket flash/response message\n(macro_applied, tags_updated, etc.). Adds the key to all 14 locales.\n\nFollow-up to #107.\n\nCo-authored-by: Matt Gros <mpge@users.noreply.github.com>",
"is_bot": false,
"headline": "fix(tickets): localize custom action dispatched message (#108)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-28T21:08:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0e4585fd11f0446a2cf83fc68c413109ebe7ad77",
"body": "* WIP Custom Actions\n\n* Custom Actions",
"is_bot": false,
"headline": "feat(tickets): custom ticket actions via events (#107)",
"author_name": "Matthew Weber",
"author_login": "matalaweb",
"committed_at": "2026-05-28T19:20:44Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4eb9be196428d09aaa43efd2674ce6f6ae8c99eb",
"body": "Co-authored-by: Matt Gros <mpge@users.noreply.github.com>",
"is_bot": false,
"headline": "Clarify final setup steps (#106)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-27T01:12:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dd460200bec043bd71ac1070d6d75bdaf21bcd76",
"body": "Co-authored-by: Matt Gros <mpge@users.noreply.github.com>",
"is_bot": false,
"headline": "feat(api): add mobile customer and guest support api (#104)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-26T02:41:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f3dd0f7572ca6fb5c5138edd8ebcde8bf09ded68",
"body": null,
"is_bot": false,
"headline": "style: pint binary_operator_spaces on plugin install test fixture",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-19T17:00:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "48704cbb926847e4ab534064ab00b1c579c83176",
"body": "…eypair\n\ntests/Fixtures/rsa.priv contained a real RSA-2048 private key, and\nescalated-laravel is a public repo (escalated-dev/escalated-laravel).\nThat made the keypair leaked from the moment the original commit\n(11846df, Phase 2.2f) hit GitHub. Treat both halves as compromised\n— never trust them as \n[…]\ns public key into\ntheir plugin trust-anchor config \"because the test fixture showed\nhow\", they should rotate immediately — the corresponding private\nkey is in public GitHub history and will remain so.",
"is_bot": false,
"headline": "fix(tests): rotate plugin-install RSA fixtures to runtime-generated k…",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-19T15:55:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "11846df5dfb63deeb7bf06a824b7225f9aefe6a7",
"body": "Phase 2.2e shipped the publish side (esc-plugin publish + cloud\nMarketplacePluginVersionController). This adds the consumer-side\ncounterpart for backend Laravel hosts:\n\n php artisan escalated:plugin:install <publisher>/<slug>\n\nThe command resolves the marketplace manifest envelope (defaults to\nth\n[…]\nha256 mismatch, marketplace 404,\nexisting-dir without --force, --force overwrite, valid RSA\nsignature, and signature mismatch — using an RSA fixture keypair\ncopied from the existing SSO test fixtures.",
"is_bot": false,
"headline": "feat(plugins): add verified marketplace install command (Phase 2.2f)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-19T03:03:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "94224f1d5fe559705bf37ee4e6133d22cf8f6c6b",
"body": "Bumps [@escalated-dev/escalated](https://github.com/escalated-dev/escalated) from 0.7.1 to 0.8.0.\n- [Release notes](https://github.com/escalated-dev/escalated/releases)\n- [Changelog](https://github.com/escalated-dev/escalated/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/escalated-dev/escal\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump @escalated-dev/escalated in /docker/host-app (#102)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-16T02:17:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f27f53b2c2441674003d83a3fe40e1ab9bdd83f0",
"body": "Bumps [@escalated-dev/escalated](https://github.com/escalated-dev/escalated) from 0.7.1 to 0.8.0.\n- [Release notes](https://github.com/escalated-dev/escalated/releases)\n- [Changelog](https://github.com/escalated-dev/escalated/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/escalated-dev/escal\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump @escalated-dev/escalated from 0.7.1 to 0.8.0 (#101)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-16T02:17:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a620b064b489692e4ec074fd3d19ad242dd2dfbb",
"body": "…le-bearing users (#100)\n\n- DB::transaction now wraps store() and update() so a syncAgents() failure\n rolls back the skill row's name + routing JSON changes. Previously a\n partial failure left the skill mutated but with stale agent_skill rows.\n- agents.*.user_id validation now rejects user IDs tha\n[…]\n\n (host hasn't adopted the convention) the check is skipped so behaviour\n is unchanged for those hosts.\n- New feature test covers the role-rejection branch.\n\nSurfaced by post-merge review of PR #95.",
"is_bot": false,
"headline": "fix(skills): wrap store/update in transactions; restrict agents to ro…",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-13T20:32:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d8804079ec81f6434427a52f78215d2a5e17be0f",
"body": null,
"is_bot": false,
"headline": "fix(2fa): show recovery codes after successful confirmation (#97)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-11T01:39:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "97ca3db485502b220612dee667566dfe44a10769",
"body": "* feat(skills): implement skills-based routing\n\n* style: apply Pint auto-fixes",
"is_bot": false,
"headline": "feat: implement skills-based routing (#95)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-11T01:39:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9ec32cd5af6d3da5eba4ad8815c135c99bd6c3a1",
"body": null,
"is_bot": false,
"headline": "feat(sso): expand provider configuration surface (#96)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-11T01:39:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1b2c5b3e16a68056f1f9f90a6df6c733393a4519",
"body": "* feat(admin): users-management page with admin/agent role toggles\n\nThe admin panel had no UI for granting or revoking admin/agent access on\nhost users — admins had to drop into tinker or run a seeder. New\nUserController surfaces the host User table (paged, searchable) and a\nPATCH endpoint flips is_\n[…]\nolumns the install command tells hosts to add). Hosts\nthat wire the gates differently (Spatie roles, custom pivots) should\noverride this controller in their own routes.\n\n* style: apply Pint auto-fixes",
"is_bot": false,
"headline": "feat(admin): users-management page with admin/agent role toggles (#94)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-10T21:49:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6c8ce2058388d94c3280d30495dc5d1198a15c11",
"body": "Bumps [@inertiajs/vue3](https://github.com/inertiajs/inertia/tree/HEAD/packages/vue3) from 2.3.23 to 3.1.1.\n- [Release notes](https://github.com/inertiajs/inertia/releases)\n- [Changelog](https://github.com/inertiajs/inertia/blob/3.x/CHANGELOG.md)\n- [Commits](https://github.com/inertiajs/inertia/comm\n[…]\nrect:development\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps-dev): bump @inertiajs/vue3 in /docker/host-app (#93)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-10T13:35:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0389bc5613122a0fd01588e005297f3afca68364",
"body": "Resolves #88 root cause. The reporter's `migrate -vvv` output showed:\n\n SQLSTATE[HY000]: General error: 1005 Can't create table\n `yog_stock`.`escalated_macros` (errno: 150 \"Foreign key constraint\n is incorrectly formed\")\n\nThis is the legacy MariaDB / MySQL 5.x error wording for FK column-type\ninc\n[…]\n— anyone with a successful prior\ninstall keeps their existing FK constraints (Laravel doesn't re-run\nmigrations once recorded). Anyone hit by #88 sees migrations 14+ run\ncleanly on their next attempt.",
"is_bot": false,
"headline": "fix(migrations): drop FK constraints to host `users` table (#92)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-07T14:21:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bdeb56e057491619a6934e587789728ed6ac6f80",
"body": "…m (#91)\n\nIssue #88 reported a \"table doesn't exist\" failure at the seeder step. The deeper cause was a migration earlier in the chain failing in the user's environment, but `runMigrations()` was using `callSilently('migrate')` and the `task` component, which together hide the actual SQL error — the\n[…]\nool — but the install flow now refuses to seed if migrate failed, which it already did, and shows step_seed in the printed instructions when seed didn't happen.\n\nNo translation key changes.\n\nRefs #88.",
"is_bot": false,
"headline": "fix(install): surface migrate / seed errors instead of swallowing the…",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-07T14:09:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1791741be1c829e31987c04608af43d4657a8988",
"body": "* feat(i18n): bridge install translations from escalated-dev/locale\n\nThe central `escalated-dev/locale` package was already declared as a composer dep and \"loaded\" by the service provider, but it wasn't actually serving any translations: its JSON files use camelCase keys (matching the Vue frontend c\n[…]\n `CentralLocaleBridgeTest` locks in the behavior: bridge populates the loaded array, resolved values match central JSON exactly, and placeholder syntax rewriting works.\n\n* style: apply Pint auto-fixes",
"is_bot": false,
"headline": "feat(i18n): bridge install translations from escalated-dev/locale (#90)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-07T03:42:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "94e5c44245e6b2a606e46451d67dd222cd33b022",
"body": "Resolves #88. The install command was publishing migration files but never running them, then immediately invoking `PermissionSeeder` which inserts into `escalated_permissions` — a table that didn't exist yet. Every clean install hit `SQLSTATE[42S02]: Base table or view not found` at the seeder step\n[…]\nage's `resources/lang/{locale}/commands.php` fallback files; the central JSON files are loaded but don't actually resolve any of the namespaced PHP-side keys. Aligning the two is a separate follow-up.",
"is_bot": false,
"headline": "fix(install): run migrations before seeding permissions (#89)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-07T01:47:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "34d747c540f987718621313e625442e057e33d99",
"body": "The auto-generated index name is escalated_delayed_actions_execute_at_executed_cancelled_index (61 chars). That fits MySQL's 64-char limit with the default `escalated_` prefix, but anyone configuring `escalated.table_prefix` to a value longer than 13 characters would hit the same \"Identifier name to\n[…]\nfix.\n\nBackwards compatible: the migration runs only once. Anyone for whom it already succeeded has the long auto-generated name in their schema; the new short name only takes effect on fresh installs.",
"is_bot": false,
"headline": "fix(migration): assign explicit name to delayed_actions index (#87)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-05T23:42:35Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "679f47f73f8e7f1fb5325d69b259c0cdcca9978f",
"body": "Resolve the following SQL error\r\n\r\nSyntax error or access violation: 1059 Identifier name 'escalated_ticket_links_parent_ticket_id_child_ticket_id_link_type_unique' is too long",
"is_bot": false,
"headline": "Resolve Unique Index name too long error (#86)",
"author_name": "Matthew Weber",
"author_login": "matalaweb",
"committed_at": "2026-05-05T23:39:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "16b8be56bb7e89decda1100a8c5ff884780a77b5",
"body": "* build(deps): require escalated-dev/locale ^0.1.0\n\nAdd central translations package as a dependency. Resolves to vendor/escalated-dev/locale/locales/{locale}/{group}.php after composer install.\n\nBlocked on escalated-dev/escalated-locale v0.1.0 publish — composer install will fail until then; that i\n[…]\ncalated-dev/escalated-locale via vcs repository. Once the\npackage is submitted to Packagist this block can be removed; until then\nthis lets composer install work today (verified: pest 606 tests pass).",
"is_bot": false,
"headline": "feat(i18n): consume central translations from escalated-dev/locale (#85)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-02T19:19:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "71e8e86f3a314d89f5f9e6e388bd896df2338517",
"body": "Bundles dependabot PRs #80, #81, #82, #83.\nTailwind 4 migration: @tailwind directives -> @import; @tailwindcss/postcss; remove redundant autoprefixer.",
"is_bot": false,
"headline": "chore(deps): modernize host-app frontend (Vite 8 + Tailwind 4) (#84)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-02T00:32:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "de9f3bc82c054ed9796d269a00c12e95ea6e2b9e",
"body": "Bumps [@escalated-dev/escalated](https://github.com/escalated-dev/escalated) from 0.6.0 to 0.7.1.\n- [Release notes](https://github.com/escalated-dev/escalated/releases)\n- [Changelog](https://github.com/escalated-dev/escalated/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/escalated-dev/escal\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump @escalated-dev/escalated in /docker/host-app (#79)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-01T18:28:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c31bf886f212f98bb0439afa840144fb06f30d10",
"body": "Bumps [stefanzweifel/git-auto-commit-action](https://github.com/stefanzweifel/git-auto-commit-action) from 5 to 7.\n- [Release notes](https://github.com/stefanzweifel/git-auto-commit-action/releases)\n- [Changelog](https://github.com/stefanzweifel/git-auto-commit-action/blob/master/CHANGELOG.md)\n- [Co\n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump stefanzweifel/git-auto-commit-action from 5 to 7 (#76)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-01T18:28:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0616f47b994e173ab27dd71be2cbb71ebb771ffc",
"body": "…alated-0.7.1",
"is_bot": false,
"headline": "Merge pull request #78 from dependabot/npm_and_yarn/escalated-dev/esc…",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-01T13:56:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9e815eeafdc8fd5f635d4776afb2ba5ab1fab401",
"body": null,
"is_bot": false,
"headline": "Merge pull request #77 from dependabot/github_actions/actions/checkout-6",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-01T13:52:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fb3903a056b01e7ae4fa1049d3366923b3b05b32",
"body": "Bumps [@escalated-dev/escalated](https://github.com/escalated-dev/escalated) from 0.6.0 to 0.7.1.\n- [Release notes](https://github.com/escalated-dev/escalated/releases)\n- [Changelog](https://github.com/escalated-dev/escalated/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/escalated-dev/escal\n[…]\ncy-name: \"@escalated-dev/escalated\"\n dependency-version: 0.7.1\n dependency-type: direct:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps): bump @escalated-dev/escalated from 0.6.0 to 0.7.1",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-01T13:27:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e82930eee6f95a79a5b6b654b6f63057159a8d1d",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 6.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v4...v6)\n\n---\nupdated-dependenc\n[…]\n:\n- dependency-name: actions/checkout\n dependency-version: '6'\n dependency-type: direct:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/checkout from 4 to 6",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-05-01T13:18:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "08be4742756c52f9a1cb9c56d3293203998e610a",
"body": null,
"is_bot": false,
"headline": "ci: add dependabot config",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-01T13:12:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4bbdbafa74cdd3a21678672d8eacdb454957b3e8",
"body": null,
"is_bot": false,
"headline": "ci(fossa): add FOSSA workflow + badges across READMEs",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-05-01T02:52:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4285e760e0f1526e2bcfd6efd1f9721b08e2b95b",
"body": "The admin settings page (PublicTicketsSettingsController) has been\npersisting guest_policy_mode / guest_policy_user_id /\nguest_policy_signup_url_template to EscalatedSettings, but\nWidgetController::createTicket wrote guest_name / guest_email /\nguest_token unconditionally regardless of mode — so the \n[…]\nver: unassigned mode (regression test for the\ndefault path), guest_user with valid user id, guest_user with missing\nuser id fallback, prompt_signup path. Full WidgetControllerTest suite\n13 → 13 green.",
"is_bot": false,
"headline": "fix(widget): honor guest_policy_mode on public ticket creation (#72)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-04-27T00:44:26Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0b1dda2768531bfed3b0cdbdaecdf3ce82df0320",
"body": "…To verification (#75)\n\nWires MessageIdUtil (#68) into InboundEmailService.findTicketByEmail\nso inbound mail routes to the correct ticket via four resolution\nstrategies, in priority order:\n\n 1. In-Reply-To header parsed via MessageIdUtil — the reply is\n threading off a Message-ID we issued (col\n[…]\ny-To rejection (wrong secret → no ticket match)\n\nThe signed Reply-To branch only activates when\nescalated.email.inbound_secret is configured — safe default of\nskipping when the admin hasn't set a key.",
"is_bot": false,
"headline": "feat(inbound): MessageIdUtil-based Message-ID parsing + signed Reply-…",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-04-27T00:36:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3dea62c0e6f1cf82ab711a8da11513758207f39f",
"body": "* feat(mail): wire MessageIdUtil into all 7 ticket notifications\n\nAdds NotificationThreading helper that centralizes the RFC 5322\nthreading headers + signed Reply-To so every outbound notification\ncarries consistent headers:\n\n- NewTicketNotification: applyAnchor (Message-ID = <ticket-id@domain>)\n- T\n[…]\n parametric test at the end iterates every notification class and\nasserts the signed Reply-To is present, catching regressions if a\nnew notification is added but forgets to call NotificationThreading.",
"is_bot": false,
"headline": "feat(mail): wire MessageIdUtil into all 7 ticket notifications (#74)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-04-26T01:40:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "209f05b861d31d99fffc0624f86b6b2f301f1297",
"body": "…s (#73)\n\nSecond wave of the widget/settings-disconnection sweep — same bug that\nwe just fixed across 6 frameworks for widget/guest submissions also\naffects inbound email. InboundEmailService::createNewTicket wrote\nguest_name / guest_email / guest_token unconditionally when the sender\nwasn't a regis\n[…]\n.\n\n3 new Pest cases added to InboundEmailServiceTest — guest_user routing,\nmisconfigured fallback, prompt_signup path. All 15 service tests still\ngreen.\n\nMirrors the NestJS fix in escalated-nestjs#28.",
"is_bot": false,
"headline": "fix(inbound): honor guest_policy_mode on inbound-email-created ticket…",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-04-26T01:39:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f8f00a199e929c60abe5731463939fce33e76d12",
"body": "* feat(admin): PublicTicketsSettingsController for guest policy\n\nAdds a controller + two routes that back the\nAdmin/Settings/PublicTickets.vue page in the shared escalated\nfrontend package. Persists `guest_policy_mode`,\n`guest_policy_user_id`, and `guest_policy_signup_url_template`\nvia the existing \n[…]\ns can switch\nthe public-ticket ownership mode at runtime without a redeploy.\n\nMatches the CsatSettings / SsoSettings / DataRetentionController\npattern already in place.\n\n* style: apply Pint auto-fixes",
"is_bot": false,
"headline": "feat(admin): PublicTicketsSettingsController for guest policy (#71)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-04-26T01:38:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0b5e333df4709f6b38ca8c735365541895b37d36",
"body": "Ports the NestJS email/message-id.ts helpers to Laravel. Mirrors the\nSpring / WordPress / .NET / Phoenix ports.\n\nAPI:\n buildMessageId(ticketId, replyId, domain)\n parseTicketIdFromMessageId(raw)\n buildReplyTo(ticketId, secret, domain)\n verifyReplyTo(address, secret)\n\nUses hash_hmac('sha256', ...)\n[…]\ntNotification / SlaBreachNotification\ninline Message-ID building to this util, wire signed Reply-To into the\noutbound headers, and extend the Mailgun / Postmark inbound adapters\nto call verifyReplyTo.",
"is_bot": false,
"headline": "feat(mail): add MessageIdUtil for RFC 5322 + signed Reply-To (#68)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-04-26T01:38:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6f1e0b63290bb232723f4c6e84c6d769e688b804",
"body": "* feat(contact): add Contact model for public-ticket dedupe (Pattern B convergence)\n\nBrings Laravel in line with the Pattern B design shipped in\nescalated-nestjs PR #17: a first-class Contact entity identifies\nguest requesters by email, enabling dedupe across tickets and a\nclean promote-to-user flow\n[…]\nat submissions (different casing, same email)\n onto a single Contact row with both tickets linked\n\nFull suite: 568 passed (+2 new), 1 pre-existing risky (unrelated).\n\n* style: apply Pint auto-fixes",
"is_bot": false,
"headline": "feat(contact): Contact model for public-ticket dedupe (Pattern B) (#67)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-04-26T01:31:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3e4494961b31db49bb487c33c1e8ab36f353c44b",
"body": "* fix(customer): pass priority (and other visible filters) through to the driver\n\nCloses #64\n\nThe Customer `TicketController@index` was dropping the `priority`\nURL param before it reached the driver:\n\n $request->only(['status', 'search', 'sort_by', 'sort_dir'])\n // ^^^ priority mi\n[…]\ny priority (the actual regression — fails\n on `main`, passes after this PR)\n\nAll 4 pass. The 7 existing `Feature/Customer/TicketControllerTest`\ncases continue to pass.\n\n* style: apply Pint auto-fixes",
"is_bot": false,
"headline": "fix(customer): pass priority filter through to the driver (#64) (#66)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-04-20T15:19:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "70ada066b351a9a7713781d797ec35637224157b",
"body": "…ured display column (#65)\n\nCloses #63\n\nEscalated's ticket search (agent + customer areas) assumed a `name`\ncolumn on the `users` table and would either raise\n\"column users.name does not exist\" against Postgres or silently\nreturn an empty result against sqlite when the column was absent.\nHosts that \n[…]\nlyUserSearch` no longer references the\n missing column\n- `Escalated::userOptions()` pivots to email when the display\n column is gone\n\nAll pass. Existing admin + agent ticket suites continue to pass.",
"is_bot": false,
"headline": "fix: fall back to email-only search when users table lacks the config…",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-04-20T14:41:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9cad531a54c96f079ccb3b5d40340aadef4d5ddf",
"body": "Laravel's publishesMigrations() stamps a fresh timestamp onto each file on\nevery invocation, so running escalated:install twice duplicated all 53\npackage migrations and caused migrate to fail with \"table already exists\".\nThe --force flag did not help because the duplicate filenames differ by\ntimesta\n[…]\n-force is set; with --force it first deletes the stale\ncopies so the new batch replaces the old. Adds 4 unit tests and a new\nmigrations_already_published translation key in all 14 locales.\n\nCloses #61",
"is_bot": false,
"headline": "fix(install): skip publishing migrations when already published (#62)",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-04-19T16:15:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5b521be94ad68f03abc1465c665fbac79b64a691",
"body": null,
"is_bot": false,
"headline": "chore: changelog for v1.2.1",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-04-19T00:17:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1d1de13ef372172c1eef90aa9a42ba84e5afc2e0",
"body": "fix(reporting): emit Postgres-compatible SQL for date/time helpers",
"is_bot": false,
"headline": "Merge pull request #60 from escalated-dev/fix/postgres-date-functions",
"author_name": "Matt Gros",
"author_login": "mpge",
"committed_at": "2026-04-18T17:49:54Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 13,
"commits_last_year": 292,
"latest_release_at": "2026-06-04T05:29:13Z",
"latest_release_tag": "v1.5.1",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 24,
"days_since_latest_release": 56,
"mean_days_between_releases": 5.1
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 62,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "escalated-dev/escalated-laravel",
"exists": true,
"license": "MIT",
"keywords": [
"support",
"laravel",
"tickets",
"helpdesk",
"customer-support"
],
"ecosystem": "packagist",
"matches_repo": true,
"registry_url": "https://packagist.org/packages/escalated-dev/escalated-laravel",
"is_deprecated": false,
"latest_version": "v1.5.1",
"repository_url": "https://github.com/escalated-dev/escalated-laravel",
"versions_count": 26,
"total_downloads": 5848,
"dependents_count": 1,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": 2063,
"first_published_at": null,
"latest_published_at": "2026-06-04T05:28:48Z",
"latest_version_yanked": null,
"days_since_latest_publish": 56
}
]
},
"popularity": {
"forks": 7,
"stars": 27,
"watchers": 3,
"fork_history": {
"days": [
{
"date": "2026-02-09",
"count": 1
},
{
"date": "2026-02-17",
"count": 1
},
{
"date": "2026-03-02",
"count": 1
},
{
"date": "2026-03-23",
"count": 1
},
{
"date": "2026-04-04",
"count": 1
},
{
"date": "2026-06-19",
"count": 1
},
{
"date": "2026-07-27",
"count": 1
}
],
"complete": true,
"collected": 7,
"total_forks": 7
},
"star_history": null,
"open_issues_and_prs": 1
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": true,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [],
"largest_source_bytes": 46189,
"source_files_sampled": 582,
"oversized_source_files": 0,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"dependencies": {
"manifests": [
"composer.json",
"package.json"
],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm",
"packagist"
],
"dependencies": [
{
"name": "escalated-dev/locale",
"manifest": "composer.json",
"ecosystem": "packagist",
"version_constraint": "^0.1.8"
},
{
"name": "illuminate/contracts",
"manifest": "composer.json",
"ecosystem": "packagist",
"version_constraint": "^11.0|^12.0|^13.0"
},
{
"name": "inertiajs/inertia-laravel",
"manifest": "composer.json",
"ecosystem": "packagist",
"version_constraint": "^2.0|^3.0"
},
{
"name": "league/commonmark",
"manifest": "composer.json",
"ecosystem": "packagist",
"version_constraint": "^2.0"
},
{
"name": "symfony/dom-crawler",
"manifest": "composer.json",
"ecosystem": "packagist",
"version_constraint": "^6.0|^7.0"
},
{
"name": "@escalated-dev/escalated",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.9.0"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 1,
"merged_prs": 133,
"open_issues": 0,
"closed_ratio": 1,
"closed_issues": 16,
"closed_unmerged_prs": 14
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "mpge",
"commits": 231,
"avatar_url": "https://avatars.githubusercontent.com/u/3311227?v=4"
},
{
"type": "User",
"login": "matalaweb",
"commits": 18,
"avatar_url": "https://avatars.githubusercontent.com/u/4079247?v=4"
},
{
"type": "User",
"login": "marufmax",
"commits": 4,
"avatar_url": "https://avatars.githubusercontent.com/u/7222229?v=4"
},
{
"type": "User",
"login": "codearachnid",
"commits": 2,
"avatar_url": "https://avatars.githubusercontent.com/u/755025?v=4"
}
],
"contributors_sampled": 4,
"top_contributor_share": 0.906
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"laravel.yml",
"lint.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"package-lock.json"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/5 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 10,
"reason": "project has 11 contributing companies or organizations",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 0,
"reason": "dependency not pinned by hash detected -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 9,
"reason": "1 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "db7d6832c2738a67fc294a59071d7fc757d90eae",
"ran_at": "2026-07-30T10:35:57Z",
"aggregate_score": 6.1,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-30T10:35:08Z",
"oldest_open_prs": [
{
"number": 163,
"created_at": "2026-07-24T03:24:22Z",
"last_comment_at": "2026-07-24T03:24:22Z",
"last_comment_author": "dependabot"
}
],
"last_merged_pr_at": "2026-07-30T10:33:00Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/escalated-dev/escalated-laravel",
"host": "github.com",
"name": "escalated-laravel",
"owner": "escalated-dev"
},
"metrics": {
"overall": {
"key": "overall",
"band": "good",
"name": "Overall health",
"note": "The weighted overall 66 is calibrated to 77 on the published index scale (record calibration 2026-08-02).",
"notes": [
{
"code": "overall_calibration",
"params": {
"raw": 66,
"calibrated": 77,
"calibration": "2026-08-02"
}
}
],
"value": 77,
"inputs": {
"security": 61,
"vitality": 89,
"community": 41,
"governance": 60,
"calibration": "2026-08-02",
"engineering": 81,
"ai_readiness": 43,
"weighted_overall_raw": 66
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "excellent",
"name": "Vitality",
"value": 89,
"weight": 0.21,
"metrics": [
{
"key": "development_activity",
"band": "excellent",
"name": "Development activity",
"note": null,
"notes": [],
"value": 81,
"inputs": {
"commits_last_year": 292,
"human_commit_share": 0.62,
"days_since_last_push": 0,
"active_weeks_last_year": 24
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "24/52 weeks with commits",
"points": 16.6,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 24
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "292 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 292
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "exceptional",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 13,
"latest_release_tag": "v1.5.1",
"releases_from_tags": false,
"days_since_latest_release": 56,
"mean_days_between_releases": 5.1
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "13 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 13
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 56 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 56
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~5.1 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 5.1
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "exceptional",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "weak",
"name": "Community & Adoption",
"value": 41,
"weight": 0.17,
"metrics": [
{
"key": "popularity",
"band": "at_risk",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 31,
"inputs": {
"forks": 7,
"stars": 27,
"watchers": 3,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "27 stars",
"points": 23,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 27
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "7 forks",
"points": 6.5,
"status": "partial",
"details": [
{
"code": "forks",
"params": {
"count": 7
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "3 watchers",
"points": 1.7,
"status": "partial",
"details": [
{
"code": "watchers",
"params": {
"count": 3
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"readme_badges": null,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"readme_badge_services": [],
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "weak",
"name": "Ecosystem adoption (downloads)",
"note": null,
"notes": [],
"value": 46,
"inputs": {
"packages": [
"escalated-dev/escalated-laravel"
],
"dependents": 1,
"ecosystems": "packagist",
"total_downloads": 5848,
"monthly_downloads": 2063
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "2,063 downloads/month across packagist",
"points": 44.2,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 2063,
"ecosystems": "packagist"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "1 packages depend on it",
"points": 2,
"status": "partial",
"details": [
{
"code": "registry_dependents",
"params": {
"count": 1
}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 60,
"weight": 0.23,
"metrics": [
{
"key": "maintainer_resilience",
"band": "at_risk",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 26,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 4,
"top_contributor_share": 0.906
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 91% of commits",
"points": 2.1,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 91
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "4 contributors",
"points": 5.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 4
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 11 contributing companies or organizations",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"newcomer_pr_acceptance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 79,
"inputs": {
"merged_prs": 133,
"open_issues": 0,
"closed_issues": 16,
"prs_merged_7d": null,
"prs_decided_7d": null,
"prs_merged_30d": null,
"prs_decided_30d": null,
"issue_closed_ratio": 1,
"closed_unmerged_prs": 14,
"first_time_authors_30d": null,
"first_time_prs_merged_30d": null,
"first_time_prs_decided_30d": null
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "100% of issues closed",
"points": 42,
"status": "met",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 100
}
}
],
"max_points": 42
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "133/147 decided PRs merged",
"points": 27.1,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 133,
"decided": 147
}
}
],
"max_points": 30
},
{
"key": "newcomer_pr_acceptance",
"name": "Newcomer PR acceptance",
"detail": "no first-time contributor's PR decided in 30d",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_newcomer_prs",
"params": {
"days": 30
}
}
],
"max_points": 13
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/5 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "weak",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 49,
"inputs": {
"followers": 10,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "escalated-dev",
"public_repos": 31,
"account_age_days": 173
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "10 followers of escalated-dev",
"points": 7.5,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 10,
"login": "escalated-dev"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "31 public repos, account ~0 yr old",
"points": 11.9,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 31
}
},
{
"code": "account_age_years",
"params": {
"years": 0
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "exceptional",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"escalated-dev/escalated-laravel"
],
"ecosystems": "packagist",
"any_deprecated": false,
"min_days_since_publish": 56
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on packagist",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "packagist"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 56 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 56
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "26 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 26
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "excellent",
"name": "Engineering Quality",
"value": 81,
"weight": 0.19,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 68,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "2 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 2
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "exceptional",
"name": "Documentation",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"topics": [
"laravel"
],
"has_wiki": true,
"homepage": "https://escalated.dev/framework/laravel",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://escalated.dev/framework/laravel",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "1 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 1
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 61,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 61,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 6.1
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "25 out of 25 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/5 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 11 contributing companies or organizations",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 7 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "1 existing vulnerabilities detected",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "exceptional",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"commit_weight_rule": {
"min_commits": 50,
"min_commit_share": 0.1
},
"review_only_matches": 0,
"below_threshold_exposures": [],
"assessed_self_published_locations": 6
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "weak",
"name": "AI Readiness",
"value": 43,
"weight": 0.04,
"metrics": [
{
"key": "ai_agent_context",
"band": "weak",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.968,
"agent_instruction_files": [],
"agent_instruction_max_bytes": null
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "no CLAUDE.md / AGENTS.md / editor rules",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_instructions",
"params": {}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "60 of 62 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 60,
"sampled": 62
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "weak",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"package-lock.json"
],
"has_dockerfile": true,
"typed_language": false,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [],
"agent_commit_share": 0,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0.38
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "Dockerfile, lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Dockerfile, lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "38 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 38,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "moderate",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 55,
"inputs": {
"primary_language": "PHP",
"largest_source_bytes": 46189,
"source_files_sampled": 582,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "PHP without a type-check config",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_typecheck_config_language",
"params": {
"language": "PHP"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/582 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 582,
"oversized": 0
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
}
],
"classification": {
"top": [
"library"
],
"labels": [
"library"
],
"scores": {
"plugin": 2,
"library": 6
},
"primary": "library",
"evidence": [
{
"tier": "distribution",
"label": "library",
"source": "registry:packagist",
"weight": 6
},
{
"tier": "description",
"label": "plugin",
"source": "description:plugin",
"weight": 2
}
],
"artifacts": [],
"confidence": "medium",
"host_extension": false,
"runs_as_process": false,
"consumed_by_code": true
},
"metrics_version": "2.5.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-30T10:36:13.132773Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/e/escalated-dev/escalated-laravel.svg",
"full_name": "escalated-dev/escalated-laravel",
"license_state": "standard",
"license_spdx": "MIT"
}