公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-29 16:43 UTC

gonest-dev / gonest

A NestJS-inspired dependency-injection and HTTP framework for Go

GoMIT★ 4 星标⑂ 1 复刻始于 2026年7月在 GitHub 上查看 ↗

gonest-dev/gonest 的健康指数为 100 分中的 45 分,处于「存在风险」区间。 其得分最高的类别是Vitality(74/100),最低的是Community & Adoption(28/100)。 最近一次更新在 4 天前。 近期的大部分工作由 1 位贡献者完成。

45
总分 / 100
存在风险

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

45
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

0 关注者3 个公开仓库始于 2026年3月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布
Gogonest.dev/gonestv0.31.0-314 天前

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

74良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 4 天前
2.1/36提交节奏 — 52 周中有 3 周有提交
18/18提交量 — 最近一年 343 次提交
0/10OpenSSF Scorecard:Maintained — project was created within the last 90 days. Please review its contents carefully
所用输入
commits_last_year343
human_commit_share1
days_since_last_push4
active_weeks_last_year3

发布纪律

100优秀
评分方式
27/27有发布版本 — 已发布 31 个发布版本
36/36发布时效 — 最近一次发布版本于 4 天前
27/27发布节奏 — 约每 0.2 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count31
latest_release_tagv0.31.0
releases_from_tags
days_since_latest_release4
mean_days_between_releases0.2
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

28危急 · 占总体的 18%
评分方式
7.7/60星标 — 4 个星标
0/25复刻 — 1 个复刻
0/15关注者 — 0 位关注者
所用输入
forks1
stars4
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

50中等
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(MIT)
0/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

32存在风险 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0/22.5提交分布 — 头号贡献者编写了 100% 的提交
1.4/13.5贡献者广度 — 1 位贡献者
0/10OpenSSF Scorecard:Contributors — project has 0 contributing companies or organizations -- score normalized to 0
所用输入
bus_factor1
contributors_sampled1
top_contributor_share1
评分方式
0/46.8议题解决 — 没有议题或无数据
0/38.3PR 接受 — 没有已裁定的拉取请求或无数据
0/15OpenSSF Scorecard:Code-Review — Found 0/30 approved changesets -- score normalized to 0
所用输入
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
已排除计分(无数据或不适用):议题解决, PR 接受。 其余权重已重新归一化。
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
0/25所有者影响力 — gonest-dev 有 0 位关注者
5.2/25既往记录 — 3 个公开仓库,账户约 0 年
所用输入
followers0
owner_typeOrganization
is_verified
owner_logingonest-dev
public_repos3
account_age_days145
评分方式
25/25已发布且可解析 — go 上有 1 个软件包
35/35发布时效 — 最近一次发布于 4 天前
20/20版本历史 — 31 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesgonest.dev/gonest
ecosystemsgo
any_deprecated
min_days_since_publish4

工程质量

基础的工程与文档实践是否到位?

56中等 · 占总体的 20%

工程实践

60中等
评分方式
24/24CI 工作流 — 1 个工作流
24/24存在测试
0/16Linter 配置
0/9.6Pre-commit 钩子
0/6.4.editorconfig
0/20OpenSSF Scorecard:CI-Tests — 无数据
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config
已排除计分(无数据或不适用):OpenSSF Scorecard:CI-Tests。 其余权重已重新归一化。

文档

50中等
评分方式
30/30README
0/25文档目录
0/15文档 / 主页站点
10/10仓库描述
0/10主题标签
10/10Wiki
所用输入
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

29危急 · 占总体的 16%

安全态势

29危急
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — 无数据
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — 无数据
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — 无数据
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6/7.5Vulnerabilities — 2 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated15
scorecard_versionv5.5.0
checks_inconclusive3
scorecard_aggregate2.9
已排除计分(无数据或不适用):ci_tests, packaging, signed_releases。 其余权重已重新归一化。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

60中等 · 占总体的 0%
评分方式
0/45代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 100 次人类提交中有 100 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
评分方式
18/18一条命令的引导启动 — Taskfile.yml
22/22自动化测试
0/11Lint / 格式化配置
11/11静态类型检查 — Go(静态类型)
10/10可复现环境 — lockfile
0/10已体现的代理实践 — 最近 100 次提交中没有代理编写的提交
0/8自动化维护 — 未观察到自动依赖更新
0/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
所用输入
has_nix
has_tests
lockfilesgo.sum
has_dockerfile
typed_language
bootstrap_filesTaskfile.yml
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0
toolchain_manifests.examples/blog-api/go.mod, .examples/blog-graphql/go.mod, .examples/config-dotenv/go.mod, .examples/full-text-search/go.mod, .examples/lifecycle-hooks/go.mod, .examples/notification-driver/go.mod, .examples/simple-todo/go.mod, go.mod
dependency_bot_commit_share0
评分方式
45/45可类型检查的代码 — Go(静态类型)
54.2/55可控的文件大小 — 采样的 219 个源文件中有 3 个超过 60KB
所用输入
primary_languageGo
largest_source_bytes147,910
source_files_sampled219
oversized_source_files3

关键数据

4GitHub 星标
1贡献者
343最近 12 个月提交数
4距最近推送天数
31发布版本数
1巴士系数(bus factor)
0开放议题
Go软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

更多细节

OpenSSF Scorecard 2.9 / 10
2.9综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-29 16:43 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
不适用CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
不适用Packagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
不适用Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
8Vulnerabilities2 existing vulnerabilities detected
直接依赖 7
注册表软件包版本约束清单文件
Gogithub.com/fasthttp/websocketv1.5.12go.mod
Gogithub.com/gofiber/contrib/v3/websocketv1.2.1go.mod
Gogithub.com/gofiber/fiber/v3v3.4.0go.mod
Gogithub.com/google/uuidv1.6.0go.mod
Gogithub.com/graphql-go/graphqlv0.8.1go.mod
Gogithub.com/robfig/cron/v3v3.0.1go.mod
Gogolang.org/x/syncv0.22.0go.mod
全部依赖 未采集

本报告未能采集到解析后的依赖集合:GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 2981,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Go": 1756512
      },
      "pushed_at": "2026-07-25T15:10:27Z",
      "created_at": "2026-07-16T13:49:05Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-26T13:33:12Z",
      "description": "A NestJS-inspired dependency-injection and HTTP framework for Go",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": "https://gonest.dev",
      "name": "gonest.dev",
      "type": "Organization",
      "login": "gonest-dev",
      "company": null,
      "location": "Brazil",
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/265890641?v=4",
      "created_at": "2026-03-05T19:13:28Z",
      "is_verified": null,
      "public_repos": 3,
      "account_age_days": 145
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.31.0",
          "kind": "minor",
          "published_at": "2026-07-25T15:10:35Z"
        },
        {
          "tag": "v0.30.0",
          "kind": "minor",
          "published_at": "2026-07-25T03:18:28Z"
        },
        {
          "tag": "v0.29.4",
          "kind": "patch",
          "published_at": "2026-07-25T02:12:13Z"
        },
        {
          "tag": "v0.29.3",
          "kind": "patch",
          "published_at": "2026-07-25T02:05:40Z"
        },
        {
          "tag": "v0.29.2",
          "kind": "patch",
          "published_at": "2026-07-24T19:43:10Z"
        },
        {
          "tag": "v0.29.1",
          "kind": "patch",
          "published_at": "2026-07-24T19:33:50Z"
        },
        {
          "tag": "v0.29.0",
          "kind": "minor",
          "published_at": "2026-07-24T18:57:24Z"
        },
        {
          "tag": "v0.28.0",
          "kind": "minor",
          "published_at": "2026-07-24T14:16:56Z"
        },
        {
          "tag": "v0.27.0",
          "kind": "minor",
          "published_at": "2026-07-23T17:41:23Z"
        },
        {
          "tag": "v0.26.0",
          "kind": "minor",
          "published_at": "2026-07-23T17:41:20Z"
        },
        {
          "tag": "v0.25.0",
          "kind": "minor",
          "published_at": "2026-07-23T17:41:20Z"
        },
        {
          "tag": "v0.24.0",
          "kind": "minor",
          "published_at": "2026-07-22T19:59:20Z"
        },
        {
          "tag": "v0.23.0",
          "kind": "minor",
          "published_at": "2026-07-21T22:27:15Z"
        },
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2026-07-21T21:03:06Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2026-07-21T16:41:44Z"
        },
        {
          "tag": "v0.20.0",
          "kind": "minor",
          "published_at": "2026-07-21T02:15:07Z"
        },
        {
          "tag": "v0.19.0",
          "kind": "minor",
          "published_at": "2026-07-20T20:35:09Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2026-07-20T18:29:42Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2026-07-20T17:55:21Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2026-07-20T02:56:28Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2026-07-20T02:56:29Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2026-07-19T22:30:17Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-07-19T20:20:06Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-07-18T21:54:32Z"
        },
        {
          "tag": "v0.11.0",
          "kind": "minor",
          "published_at": "2026-07-18T03:02:18Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-07-18T02:38:12Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-07-18T00:57:35Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-07-17T19:09:02Z"
        },
        {
          "tag": "v0.7.1",
          "kind": "patch",
          "published_at": "2026-07-16T21:53:26Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-07-16T20:54:29Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-07-16T20:44:04Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "ea4e03179f40f7cc14adcaa9812343e8cfaf126b",
          "body": "Route gains an owner reference (set by Controller.Route) and implements\nResolveDirect/ResolveDirectAll by delegating to it, so MustInject[T](route)\nresolves from the same module scope MustInject[T](controller) does -- no\nmore forcing every per-route dependency up into the Controller's outer fn.\nroute.New takes owner as its new first param; existing internal callers pass\nnil (unchanged no-resolution behavior).",
          "is_bot": false,
          "headline": "feat(route): Route can MustInject inside its own callback",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-25T15:09:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f610fba1815857563c137d0a800fc479ed2b433f",
          "body": null,
          "is_bot": false,
          "headline": "docs(specs): mark http-context-unify traceability Verified (site done)",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-25T03:27:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4bb6739802fdaae07e5c8bb126c852df69ff6cec",
          "body": "Response (write-side) renamed to Reply (Fastify's own (request, reply)\nnaming for this exact role); RouteResponse (the OpenAPI per-status\ndocumentation builder) reclaims the Response name, matching OpenAPI 3.x's\nown vocabulary. New HttpContext type wraps Request/Reply behind exactly 2\nmethods, Reque\n[…]\nre changes from (req, res[, next/exc]) to (c, [next/exc]);\ngonest.Response is now the OpenAPI documentation builder (was\nRouteResponse); the HTTP write-side type is gonest.Reply (was\ngonest.Response).",
          "is_bot": false,
          "headline": "feat(execution)!: HttpContext unifies (req, res) into one parameter",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-25T03:17:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "72160012f06b82e2d10e724a63c174ebcd914060",
          "body": "SetupSwagger was the last \"final\" bootstrap builder still returning a raw\nerror, forcing every call site to write its own\n`if err := ...; err != nil { panic(err) }` -- exactly the boilerplate\nevery other Must-prefixed API in the package already avoids. Migrates\nREADME's bootstrap example and .examples/{full-text-search,blog-api}.",
          "is_bot": false,
          "headline": "feat(openapi): add MustSetupSwagger, panic-on-error convenience wrapper",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-25T02:11:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db1f551298fd8758e740d913ea026984ad970193",
          "body": "… addr\n\ndisplayAddr rewrote \":3000\" into \"0.0.0.0:3000\" for the \"Listening on\"\nbanner line. The actual bind is unaffected, but 0.0.0.0 is a wildcard\nbind address, not a real destination a browser can connect to on most\nOSes -- printing it produces a URL that fails to connect unless the dev\nalready knows to substitute localhost/127.0.0.1 themselves.\n\nFound via a real session: banner showed http://0.0.0.0:3000, only\n127.0.0.1/localhost actually worked.",
          "is_bot": false,
          "headline": "fix(app): startup banner prints localhost, not 0.0.0.0, for bare-port…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-25T02:04:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fbbcbabae7662a9a6d83e71bd5e8c78960296039",
          "body": "NewBadRequestException/NewNotFoundException/etc (internal/exception/\nbuiltin.go) never call SetMessage, only SetDetails -- so Error() always\nreturned \"\" for every validation failure across internal/validate (env,\nquery, params, headers, form, body). A wrapped panic like \"gonest:\nprovider for type X \n[…]\ntails) when message was\nnever explicitly set; message still wins whenever it was set. MarshalJSON\n(the actual HTTP response body) is unchanged -- this only fixes the Go\nerror text used by panics/logs.",
          "is_bot": false,
          "headline": "fix(exception): Error() falls back to JSON of Details() when unset",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-24T19:42:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1e09edc1ab331c3625d535217573f8c526d85dc8",
          "body": "OnModuleInit/OnApplicationBootstrap/OnModuleDestroy/BeforeApplicationShutdown/\nOnApplicationShutdown panicked with just \"gonest: invalid <Hook> signature\"\non a bad shape -- no hint of which provider, what was actually passed, or\nwhat shapes are accepted. Message now includes all three, e.g.:\n\n  gone\n[…]\none of: func(T, string), func(T,\n  string) error, func(T, context.Context, string), func(T, context.Context,\n  string) error\n\nFound debugging a real erc panic with no actionable detail in the message.",
          "is_bot": false,
          "headline": "fix(provider): name provider type + signature in lifecycle hook panics",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-24T19:33:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1e4f27d2c75e564806221e169b208b8421129723",
          "body": "ExportableRef (AD-052) replaced by a broader TokenRef marker embedded by\nevery existing XxxRef interface. Imports/Providers/Controllers/Resolvers/\nUse/Filters/Listeners/Schedulers/Exports now all accept ...TokenRef,\nrouting internally via type-switch with a fail-fast panic on the wrong\nconcrete kind\n[…]\n be\ntype-asserted or spread into []gonest.ExportableRef (Go slices of\ninterface types are not covariant), panicking at runtime in erc's module\nfiles. See .specs/features/unified-token-ref/ and AD-056.",
          "is_bot": false,
          "headline": "feat(module): add TokenRef unifying all 9 Module builder methods",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-24T18:56:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6ff3acc0f08070ca253be79bc7c1ee92b82a23cd",
          "body": "…truct field syncing",
          "is_bot": false,
          "headline": "feat(accessor): add SyncAccessorFields for automatic dirty Accessor s…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-24T14:14:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7723249804897b48b65307624ecbeb09ba45417d",
          "body": "…s, subagents)\n\nCodifies 6 process rules the user stated explicitly, previously followed\nonly informally this session: agent speech in pt-br (code/commits/README\nstay English); work always split by milestone with its own commit+push;\neach closed milestone gets its own version tag on its exact commit\n[…]\nthe version tags for v0.25.0-v0.27.0 only getting cut after\nthe user asked \"subiu as novas versões?\" -- makes the practice durable in\nPROJECT.md (base load every session) instead of relying on memory.",
          "is_bot": false,
          "headline": "docs(project): formalize workflow conventions (pt-br, milestones, tag…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-23T17:44:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "635ca0b4e0fe7a8a6299201d6de1a0de10ba411a",
          "body": "…xports\n\nMilestone 24 (module-lazy-loading). Replaces .examples/notification-driver's\nModuleForRoot free-function workaround (config picked outside the DI graph,\nin main()) with gonest.LazyModule: Module.Lazy(func(l *LazyModule) {...})\nruns synchronously during Stage 1 assembly, before Imports/Expor\n[…]\n now flows\nthrough a real Schema-validated notifier.Config_ provider instead of an\nad hoc env read in main.go. Verified live via curl for both drivers.\ngo test ./... -race -count=1 green, 24 packages.",
          "is_bot": false,
          "headline": "feat(module): add Module.Lazy for config-driven conditional Imports/E…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-23T17:19:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "328561cb1996a314c185d8a650a8265c0c57f1c7",
          "body": "Milestone 23 (provider-interface-export, P2). Every exported package-level\nvar produced by a gonest builder now carries a trailing underscore\nunconditionally (Provider_, Module_, Controller_) -- documented in README,\napplied across .examples/notification-driver (every builder var there was\nmissing i\n[…]\nmd\nremoved, PROVIDER.md status marked shipped). ROADMAP.md/STATE.md closed out\nfor Milestones 22-23 (AD-053). go test ./... -race -count=1 green, 25\npackages, zero regression from the example renames.",
          "is_bot": false,
          "headline": "docs(project): formalize Thing_ naming convention, close Milestone 22/23",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-23T16:35:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d58f4a3200d3985045057bffa6f1c0358790e782",
          "body": "Milestone 22 (provider-interface-export, P1). MustInject[T]/MustInjectAll[T]\nnow resolve an interface ONLY via an explicit gonest.ProviderAs[T](ref)\nregistration -- the implicit reflect.Type.Implements() structural fallback\nis removed entirely. Closes 3 real gaps from INSIGHT-PROVIDER.md: no\nmodule-\n[…]\ning another ProviderAs) is rejected outright.\n\n.examples/notification-driver migrated to ProviderAs[port.Notifier],\nverified live against both drivers. go test ./... -race -count=1 green,\n25 packages.",
          "is_bot": false,
          "headline": "feat(module): add ProviderAs[T] for explicit interface-export resolution",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-23T16:27:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a70cbee0241c8138f6cbc1870971625bb3ba551d",
          "body": "…leRef)\n\nReverses AD-051's separate ExportModules method: Exports(refs ...ExportableRef)\nnow takes both individual providers and whole modules to re-export in the same\ncall, mirroring NestJS's exports: [...] array. Nest-API-parity now documented\nas a fundamental project premise (PROJECT.md) that wins over Go-purity when\nthey conflict -- ExportModules removed, no deprecated alias.",
          "is_bot": false,
          "headline": "feat(module): unify Exports to accept providers and *Module (Exportab…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-22T19:58:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8c8fac680f509c4673e5044abd5609ab694a8437",
          "body": "New example demonstrating gonest.Module's core value: injection across a\ndiffuse scope decided by config, not source code. NOTIFICATION_DRIVER\n(loaded via Dotenv, validated+defaulted via Schema.Enum+Default) picks,\nonce at bootstrap, whether notifier/impl/email or notifier/impl/sms wires\ninto AppMod\n[…]\n the notifier picker package\nitself, avoiding an import cycle -- their Providers return the concrete\n*Service type and gonest's resolver matches it against the interface via\nreflect.Type.Implements().",
          "is_bot": false,
          "headline": "docs(examples): add notification-driver -- env-driven Module swap",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-22T00:33:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ddb112fe2b0b5ab912ed1e9f8c21b22ac7b2f385",
          "body": "…ld, runtime blocked by unrelated pre-existing bug)",
          "is_bot": false,
          "headline": "docs(specs): close module-reexport T3 (real consumer verified via bui…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T22:30:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f9532de81bed49cdd7a2c047f17c58485ea80693",
          "body": "… (NestJS-style)\n\nModule.Exports only ever accepted individual providers -- NestJS's own\nexports: [...] also accepts a whole imported Module, re-exposing that\nmodule's own exports transitively to whoever imports the re-exporting\nmodule. gonest had no equivalent, confirmed by a real compile error in \n[…]\nntly gate-verified (go test ./... -race -count=1, no cache) before\napproval. Purely additive -- Exports/ExportedProviders unchanged, zero\nbehavior change for any module that never calls ExportModules.",
          "is_bot": false,
          "headline": "feat(module): add ExportModules for transitive whole-module re-export…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T22:26:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2abffe16fee2dd8978eabb23696e15d69d974251",
          "body": "…f/MiddlewareRef/FilterRef/ListenerRef/SchedulerRef\n\nModule.Providers/Controllers/Resolvers/Use/Filters/Listeners/Schedulers\nalready took these marker interfaces as their variadic parameter type\ninternally; without a root alias, hovering those methods from outside this\npackage showed the internal mo\n[…]\nf issue AD-046 already fixed elsewhere). Purely additive -- these methods\nalready accepted the same concrete values (*Provider, *Controller, etc.)\nbefore, only the visible parameter type name changes.",
          "is_bot": false,
          "headline": "feat(gonest): re-export Module's ProviderRef/ControllerRef/ResolverRe…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T21:02:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d0582feedcf77e32123b6e7c0dd6698bdc328961",
          "body": "…gistered schema\n\nWraps internal/schema.Lookup (the registry NewSchema[T] already populates,\npreviously only consumed internally by the MustJsonBody family) so a\nProvider/Controller declared in a different file/package than an entity's\nown NewSchema[T] call can reach that schema without needing an e\n[…]\nal type->provider registry that conflicts with the DI graph's existing\nmodule-scoped semantics (2 unrelated modules can legitimately provide the\nsame concrete type today) -- deferred, not implemented.",
          "is_bot": false,
          "headline": "feat(gonest): add SchemaFor[T], a reflection lookup for an already-re…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T20:06:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4cf8599f28bcf3009998c52cfd1fab5a93bfd44e",
          "body": "…sitive regex\n\nMatchString's LIKE/NLIKE operators did a case-SENSITIVE strings.Contains,\ninconsistent with query.text's own separate manual-lowercase substring\nsearch -- neither was a real regex match. Both now share one\nsearch.LikeMatch(value, pattern string) helper: compiles \"(?i)\" +\nregexp.QuoteM\n[…]\noth wrong matches and a\nReDoS-shaped footgun from compiling raw user input as a live pattern).\nVerified live: mixed-case search, and a name containing literal\nparentheses/period, both match correctly.",
          "is_bot": false,
          "headline": "fix(full-text-search): like/nlike and text search use real case-insen…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T17:02:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ce7097cd385c4621b025e7d05856374353d87b6a",
          "body": "…heir parent, avoid OpenAPI title collisions\n\ninternal/openapi's registerSchema keys components.schemas purely by\nSchema.TitleText(), not by Go type -- search.QuerySchemaFor/FieldsSchemaFor/\nSortFieldSchemaFor/ResultSchemaFor were using a fixed \"search.Fields\"/\n\"search.SortField\"/\"search.Result\" tit\n[…]\nsSchemaFor/SortFieldSchemaFor fall back\nto a T-derived title (T's own type name + \"Fields\"/\"Sort\") the same way when\ncalled standalone, so nothing generated is ever left with an empty (invalid)\ntitle.",
          "is_bot": false,
          "headline": "docs(full-text-search): derive Fields/Sort/Where/Result titles from t…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T16:53:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f67ae3a8f1a6e4c5d38745d4b07d1dc895564685",
          "body": null,
          "is_bot": false,
          "headline": "chore: reorder routes",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T16:40:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8461a38ff7828e1f49c50100f1fc37368fb1ea93",
          "body": null,
          "is_bot": false,
          "headline": "docs(examples): reorder person.Controller routes (POST before _search)",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T16:40:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4de2117330e7758ca27984254b72ddea000154f9",
          "body": "New standalone example (.examples/full-text-search, own go.mod) modeled after\na Search.ts gist: CRUD for Person plus POST /person/_search (text/where/\nfields/sort/offset/limit). Exercises gonest.Schema nested Object()/Array()\nrefs, gonest.Accessor dirty-tracking on both write DTOs and the Where filt\n[…]\nST /person/_search rather than the HTTP QUERY method: OpenAPI's Path\nItem Object has no representation for QUERY (still an IETF draft RFC), so a\nroute registered under it never surfaces in Swagger UI.",
          "is_bot": false,
          "headline": "docs(examples): add full-text-search (Person CRUD + generic search API)",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T16:39:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "29fe7d5458eb400c8761e8b3483029c11f0bf205",
          "body": "…set for nested embeds\n\nStringSchema.Enum(items ...string)/NumericSchema.Enum(items ...int64), chainable\nlike Min/Max/Pattern. internal/validate rejects out-of-list values (collected\nalongside other violations, never short-circuits); internal/openapi emits\n\"enum\":[...] when set. Motivated by a real \n[…]\n -- lets a long summary/description split across several Go string\nliterals without manual \"...\" + \"...\" concatenation, while still requiring at\nleast one word so an empty call can't compile silently.",
          "is_bot": false,
          "headline": "feat(schema): add Enum to String/Numeric branches; fix findFieldByOff…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T16:39:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4a8fa1189c4ad177f4b4ac274f420c64323157e6",
          "body": "…OpenapiGenerate; root wrappers stop leaking internal types in autocomplete\n\nEvery root New*/etc that was a bare var-aliased func value (var NewX =\npkg.New) is now a real func with the signature spelled out using root\naliases -- var-aliasing copies pkg.New's literal signature verbatim, so\nIDE hover/\n[…]\nvel) and got renamed to\nLoggerLevel/LoggerLevel* alongside; GenerateOpenApiSchema renamed to\nOpenapiGenerate on request. Both are breaking, no deprecation path.\n\nSee AD-046 in .specs/project/STATE.md.",
          "is_bot": false,
          "headline": "refactor(gonest)!: LogLevel -> LoggerLevel, GenerateOpenApiSchema -> …",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-21T02:12:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9b5c2851f7f7c08886e939586937fe3ae3cf4c9a",
          "body": "…ruct\n\nParse[*Config]/MustParse[*Config] now allocates the pointee and returns\nthe populated pointer, instead of requiring the caller to Parse the\nstruct value and take its own address. Motivated by a real consumer\ncall site needing *T straight out of a DI provider constructor.\n\nSee AD-045 in .specs/project/STATE.md.",
          "is_bot": false,
          "headline": "feat(parse): Parse/MustParse accept T as a pointer to the schema's st…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-20T20:34:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee200f76b37f214577ebf393cb10126161b4a449",
          "body": "…or; drop ToDirtyMap/AccessorsToDirtyMap\n\nPackage name now matches the Accessor[T] type it defines. ToDirtyMap and its\npublic wrapper AccessorsToDirtyMap are removed -- unused, no known callers.\n\nBREAKING CHANGE: gonest.AccessorsToDirtyMap no longer exists.",
          "is_bot": false,
          "headline": "refactor(accessor)!: rename internal/value package to internal/access…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-20T18:28:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "046ac2b6a85ceb08ccdf677f6cc05211b9701d84",
          "body": "…Accessor\n\nApply writes into a raw *T target. Sync covers the DTO -> entity case where\nthe target is itself an Accessor[T], so the dirty flag propagates via Set\ninstead of being silently lost.",
          "is_bot": false,
          "headline": "feat(value): add Accessor.Sync to propagate dirty value into another …",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-20T17:54:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3ae95c81bf4bd0ec2592eb4233b417ef419d528",
          "body": "…O.md\n\nManual dependency lookup already covered by MustInject. Module-level\nlazy loading has no Go equivalent (documented explicitly on the site,\nnot just silently absent) -- JS dynamic import() solves a runtime\nproblem Go's compiled binary doesn't have. Cycle detection already\nexists (DetectCycle); a real escape hatch for legitimate cycles\n(LazyInject[T]) and deferred-instantiation \"Lazy Providers\" are both\ngrounded in real NestJS examples but left speculative, no concrete use\ncase yet.",
          "is_bot": false,
          "headline": "docs: add INSIGHT-LAZY.md, split Module Reference/Lazy Loading in TOD…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-20T03:13:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "14e80d40e5e008b8cb12444e69a20bb05f5b7186",
          "body": "No framework code needed -- Module is a plain Go value built by a\nbuilder function, so a dynamic module is just a function closing over\noptions and returning *Module. Documented on the site instead.",
          "is_bot": false,
          "headline": "docs: add INSIGHT-DYNAMIC.md, mark Dynamic Modules resolved in TODO.md",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-20T03:02:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ff9fb9dac9474da6b81e1e7cfa984683155a205a",
          "body": "…no-error convenience form\n\nListener[EventType].On(func(ctx, event) error) -- a non-nil return is\nlogged by Emit the same way a recovered panic already is, never\npropagated to Emit's own caller. MustOn(func(ctx, event)) wraps a\nhandler that never fails, so simple listeners don't need \"return nil\".\nMustOn does not panic on anything despite the name -- deliberate choice\nto read naturally alongside On, confirmed with the user, a documented\nexception to this framework's usual Must=panics convention.",
          "is_bot": false,
          "headline": "feat(emitter): On returns error (logged like a panic); MustOn is the …",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-20T00:31:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a59f509b0fa6254e7b3a4c7a28bf74664f7483d2",
          "body": "…places the return-a-handler builder\n\nNewListener(func(l *Listener[EventType]) { l.On(handler) }) -- Listener\nis now a genuinely generic struct (Go 1.24+ parameterized type alias),\nso On is a real method (uses the receiver's own type parameter, doesn't\nintroduce a new one, so L-001 doesn't block it)\n[…]\n\nuses, without the func-returning-func shape the previous iteration had.\n\nBreaking: Listener is now Listener[EventType] everywhere (call sites\ninferring it from NewListener's argument are unaffected).",
          "is_bot": false,
          "headline": "refactor(emitter)!: Listener[EventType] is a real generic type; On re…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-20T00:08:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6da8792244a0940b26173b43ab319dbaea29ddf6",
          "body": "Listener is now bound to its event type via NewListener's own generic\nparameter -- the builder receives *Listener (for MustInject) and returns\nthe per-event handler, resolving dependencies once instead of via a\nseparate MustOn call:\n\n  NewListener(func(l *Listener) func(context.Context, UserCreatedE\n[…]\nis removed -- the only real usage in the repo was always exactly\none event per Listener, so the split never bought anything. Breaking\nchange: internal/emitter.MustOn and gonest.MustOn no longer exist.",
          "is_bot": false,
          "headline": "refactor(emitter)!: NewListener[EventType] replaces NewListener+MustOn",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T22:29:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f2ceff25fcce278294472f886c2dd4665456a042",
          "body": "…otstrap/OnModuleDestroy/BeforeApplicationShutdown/OnApplicationShutdown)\n\nProvider gains 5 lifecycle hooks matching NestJS's real hook set 1:1\n(confirmed via Context7, not assumed -- INSIGHT-ON.md's original sketch\nwas missing BeforeApplicationShutdown). OnModuleInit/OnApplicationBootstrap\nrun auto\n[…]\nire for scope.Singleton providers. HttpAdapter gains Shutdown(ctx),\nFiberApp implements it via Fiber v3's real ShutdownWithContext.\n\n.examples/lifecycle-hooks demonstrates the flow live. Milestone 20.",
          "is_bot": false,
          "headline": "feat(provider,app): add lifecycle hooks (OnModuleInit/OnApplicationBo…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T20:19:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3a3d0fa9e78a0c8a33a18fc82a2520e8378399c5",
          "body": null,
          "is_bot": false,
          "headline": "chore: add config-dotenv to Taskfile's EXAMPLES list (missed in T12)",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:32:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a63332cdd2ac9ff05ba2c180210453cb0c441d6",
          "body": "Update both spec.md's traceability tables (all DOTENV-0x/ENVCFG-0x ->\nVerified), ROADMAP.md (Milestone 19 -> COMPLETE), and STATE.md (AD-043\ndocumenting the T1-T12 execution: hand-rolled .env parser in distinct\npasses, PropertyBuilder.Default mirroring Custom exactly, envSource\nreusing the REST validation pipeline unchanged, real end-to-end evidence\nfrom .examples/config-dotenv).",
          "is_bot": false,
          "headline": "docs(specs): close Config Loading — Milestone 19 COMPLETE",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:31:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd8b96ddcdd5fbc8a971df1d4774f1b038ea509c",
          "body": "…se end-to-end",
          "is_bot": false,
          "headline": "docs(examples): add config-dotenv demonstrating Dotenv.Load + MustPar…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:28:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c24c8df3ad9508b42ab4248a15ca13eb17b34327",
          "body": "…se work end-to-end",
          "is_bot": false,
          "headline": "feat(dotenv): ParseInto satisfies execution.Parseable -- Load+MustPar…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:24:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0dadd89a8be4e8535efb3f822558e6b0a9a0e477",
          "body": "…lidateValue/populate unchanged",
          "is_bot": false,
          "headline": "feat(validate): envSource/ParseEnvInto -- reuses coerceParamString/va…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:21:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "47fa731bf81760d0abc571896066b92ee41cbce3",
          "body": "…sent source data",
          "is_bot": false,
          "headline": "feat(schema): PropertyBuilder.Default/DefaultValue -- fallback for ab…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:18:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1129a4adc3ed7c38c27d143898f2c308dec8da8a",
          "body": "…bootstrap",
          "is_bot": false,
          "headline": "feat(gonest): export Dotenv() -- root re-export, callable before any …",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:16:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a1f877d9fb4b0ec094940d3d2668f91f749e828",
          "body": "…ways wins",
          "is_bot": false,
          "headline": "feat(dotenv): first-path-wins precedence, pre-existing process env al…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:13:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "23ceedb0b1db163b4ff8b382c99562b053077cb0",
          "body": "Extend the backtick branch so an unclosed backtick on the opening line\nfalls back to extractBacktickBlock, folding subsequent real file lines\ninto the value (joined with real \\n) until the closing backtick is\nfound. parseFile's line loop is now index-based (was range-based) so\nit can skip past all lines consumed by a multi-line backtick block.",
          "is_bot": false,
          "headline": "feat(dotenv): backtick multiline values preserve real newlines",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:10:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c61250bafdee0addd9be0152f81e031708f71951",
          "body": "…-close-rule)\n\nStrips inline \"# comment\" text per spec's 4 literal rules: bare values\nonly treat \" #\" (space then hash) as a comment start (glued \"#\" stays\npart of the value); quoted values (single/double) never treat a \"#\"\ninside the quotes as a comment (a natural consequence of the existing\nextrac\n[…]\nfault/alternate text is never mistaken for a real trailing comment.\n\nextractDelimited now also returns the text remaining after the closing\ndelimiter (rest) so callers can detect a post-quote comment.",
          "is_bot": false,
          "headline": "feat(dotenv): inline comment stripping (bare space-rule, quoted after…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:07:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2d8903e018e93c6edd5f611dca71868b6b6487df",
          "body": "…me-type quotes\n\nextractDelimited now unescapes \\<delim> into a literal delimiter character\nwhile extracting (single/double/backtick), instead of leaving the backslash\nin the raw content. A new applyEscapes converts \\n/\\r/\\t/\\ to their real\nbyte values, wired only into parseValue's double-quote branch, running\nbefore resolveInterpolation on the escape-resolved content.",
          "is_bot": false,
          "headline": "feat(dotenv): double-quote escape sequences (\\n \\r \\t \\) + escaped sa…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:03:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "28c8d30d6e42432b87b2599279557a052582d63f",
          "body": "…ors)",
          "is_bot": false,
          "headline": "feat(dotenv): interpolation (${VAR}/$VAR + 4 default/alternate operat…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T01:00:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eaaa2be34147bfd655ec611fe30775d62b4e2b7c",
          "body": "…o interpolation yet)",
          "is_bot": false,
          "headline": "feat(dotenv): parseFile line classification + quote-style dispatch (n…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T00:56:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "842459eb3b1ff44f94d980008b2ec408708ed06a",
          "body": "…arser",
          "is_bot": false,
          "headline": "feat(dotenv): Dotenv singleton, Load/MustLoad skeleton over stubbed p…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T00:53:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6789dc3833b380ce4fb323c94be0f3e323ae685a",
          "body": "…racks",
          "is_bot": false,
          "headline": "docs(specs): tasks.md for Milestone 19 (Config Loading) — T1-T12, 2 t…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T00:51:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "305fadd5a7b660f4f4f969f01be53c30d541374b",
          "body": "Both features designed, mirroring existing internal/validate sources\nclosely (paramsSource.ParseInto's exact shape) rather than inventing new\npatterns.\n\ndotenv-loading: internal/dotenv (new leaf package), Dotenv.Load/MustLoad,\na hand-rolled line-by-line parser (classify -> dequote -> escape ->\ninter\n[…]\ne skips coercion entirely (assumed to already be the right Go\ntype). Dotenv.ParseInto is a one-line delegation to envSource, satisfying\nexecution.Parseable on the same singleton Load/MustLoad live on.",
          "is_bot": false,
          "headline": "docs(specs): design Milestone 19 (Config Loading)",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T00:46:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "11e270a2ede8d879ba49c8b378aea05cc46a0f80",
          "body": "… Env→Schema Binding\n\nTwo features, spec+context each, evolving INSIGHT-CONFIG.md's brainstorm\n(motivated by @nestjs/config's ConfigModule and the user's own gox/env\nmodel, which itself targets real dotenvx behavior — read live from\nhttps://dotenvx.com/docs/env-file via WebFetch, not assumed).\n\nKey \n[…]\ndefault/alternate operators, backtick\nmultiline, escapes) targeted for v1, not a smaller core first — explicit\nuser choice via AskUserQuestion.\n\nDesign/Tasks/Execute not started — no code written yet.",
          "is_bot": false,
          "headline": "docs(specs): specify Milestone 19 (Config Loading) — Dotenv Loading +…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-19T00:40:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "66e8f30298290286bd78a09643ff07fd63f5faf9",
          "body": "Both still described the Milestone 17 ad-hoc SSE/WS transports\n(/graphql/stream/:name, /graphql/ws/:name) as current and, in\nINSIGHT-GRAPHQL.md's case, listed the real-protocol replacement as\n\"Design/Tasks/Execute ainda pendentes\" -- stale since Milestone 18\ncompleted. README.md's milestone checklis\n[…]\npen-items sections rewritten\nto match (Execute, WSProtocolHandler/SSEDistinctHandler/SSESingleXxxHandler,\nRequest.IsWebSocketUpgrade/Response.UpgradeWebSocket replacing\nHttpAdapter.RegisterWebSocket).",
          "is_bot": false,
          "headline": "docs: update README.md and INSIGHT-GRAPHQL.md for Milestone 18",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T21:52:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "95119371c3c1c4ee4745b12ed06a85e817bd75d9",
          "body": "…L tests\n\nlistenOnEphemeralPort's cleanup called fiber.App.Shutdown(), which waits\nfor every still-open connection to close gracefully -- an abandoned SSE\nstream (Distinct or Single connection mode) only notices its client is\ngone on the next heartbeat write attempt (sseHeartbeatInterval, 15s), so\nT\n[…]\non this test deliberately\nleft open), not asserted on.\n\ninternal/app package time: 31s -> ~1.9s. Full `task gate` (build, vet,\nrace test, examples) now completes in seconds instead of tens of seconds.",
          "is_bot": false,
          "headline": "fix(app): ShutdownWithTimeout instead of Shutdown in real-dial GraphQ…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T21:39:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "abdaee02197b8a1bfb5187e45d53d8f324b46902",
          "body": null,
          "is_bot": false,
          "headline": "docs(specs): record AD-041 (internal/appoptions removal, test-cycle fix)",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T21:31:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ebab8928cad9ba98e6b13cdb66a00113c5c858ce",
          "body": "…-cycle it caused\n\ninternal/appoptions existed only to avoid an import cycle: FiberApp.Init\nneeded the config type, but internal/app already imported\ninternal/adapter/fiber (test_app.go's MustNewTestApp hardcoded\nfiber.FiberApp). internal/appoptions.AppOptions is now internal/app.Options\ndirectly --\n[…]\n}.go -> {ws_protocol,sse_distinct,sse_single}\n{,_test}.go.\n\ngo test ./... -race (25 packages) and .examples/* all green; test function\ncount in the migrated files verified identical before/after (66).",
          "is_bot": false,
          "headline": "refactor(app)!: move Options struct into internal/app, break the test…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T21:30:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fdd9ff77196d76e012bba3aa89877691f3c2d6dc",
          "body": "Update spec.md's traceability table (all GQLRT-0x -> Verified),\nROADMAP.md (Milestone 18 SPECIFIED -> COMPLETE), and STATE.md (AD-040\ndocumenting the T1-T18 execution, the Planner/Implementer/Evaluator\nsubagent run, and the 2 real bugs found running .examples/blog-graphql\nend-to-end).",
          "is_bot": false,
          "headline": "docs(specs): close graphql-realtime-protocols — Milestone 18 COMPLETE",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T18:17:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7432623d39ad3b7bef801d9d999620af28ccac8",
          "body": "…st stubs\n\napp_test.go's recordingFakeAdapter/listenSpyAdapter kept a RegisterWebSocket\nmethod after HttpAdapter dropped it (T4) -- dead code that still compiled\nsince Go allows extra methods on a type, cleaned up as part of the final\ngate pass. appoptions.go's GraphqlPath doc comment still described the\nremoved ad-hoc /graphql/stream/:name and /graphql/ws/:name paths -- updated\nto describe the real-protocol transports that replaced them.",
          "is_bot": false,
          "headline": "chore(graphql-realtime-protocols): drop orphaned RegisterWebSocket te…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T18:15:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0c19d807a350931fc2ca4cea0ab5012d7224fc54",
          "body": "…otocol echoed back)\n\nfiberResponder.Upgrade called websocket.New(fn) with no Config, so\nSec-WebSocket-Protocol was never echoed back during the handshake even\nwhen a client offered graphql-transport-ws -- a spec-compliant IDE\n(Apollo Sandbox/GraphiQL) checks that response header and refuses the\ncon\n[…]\nket now\ntake a variadic subprotocols argument, forwarded to\nwebsocket.Config{Subprotocols: subprotocols} on the fiber adapter side;\nthe GraphQL GET dispatcher passes \"graphql-transport-ws\" explicitly.",
          "is_bot": false,
          "headline": "fix(adapter/fiber): negotiate WebSocket subprotocol (Sec-WebSocket-Pr…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T18:11:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aed1930f03f1f2f56524e293692863f03c9d8629",
          "body": "…aphql-sse (both modes)\n\nReplaces the removed ad-hoc /graphql/stream/:name and /graphql/ws/:name\nmentions in main.go's doc comment with a new README.md documenting the 3\nreal-protocol transports registerGraphql now exposes on /graphql\n(WebSocket graphql-transport-ws, SSE Distinct connections, SSE Si\n[…]\nand a streaming Subscription, a real curl -N SSE\nDistinct request for both a Query and a Subscription, and a full\nPUT->GET->POST->DELETE SSE Single connection flow -- captured output is\nin the README.",
          "is_bot": false,
          "headline": "docs(examples): blog-graphql demonstrates graphql-transport-ws and gr…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T18:04:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bc4994288a81bdbe26d9f50d31ffea9681e4fcf1",
          "body": "…y real protocols)\n\nws.go/sse.go (Milestone 17's hand-rolled Subscription transports) had no\nconsumers left after registerGraphql was rewritten to use\nWSProtocolHandler/SSEDistinctHandler/SSESingleXxxHandler (real\ngraphql-transport-ws / graphql-sse protocols). Deletes ws.go, sse.go,\nws_test.go, sse_\n[…]\nnt through graphql-sse's Distinct\nconnections mode (SSEDistinctHandler), both subscribed to the same\nSubscription and fed by the same Emitter.Emit, proving disconnecting one\ndoes not affect the other.",
          "is_bot": false,
          "headline": "refactor(graphql)!: remove ad-hoc ws.go/sse.go transports (replaced b…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T17:58:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2d90769e4fd5b335eda7f1714b07aa449741fb68",
          "body": "…ame /graphql path\n\nRewrites registerGraphql (internal/app/graphql.go) to register exactly 4\nRegisterRoute calls -- POST/PUT/GET/DELETE -- all on the same graphqlPath,\nreplacing the previous POST-only + ad-hoc WS/SSE-path registration:\n\n- POST dispatches to SSESingleOperationHandler when a graphql-s\n[…]\ndshake and\nreceives connection_ack, a real TCP dial reads an SSE Distinct next/complete\npair for a plain GET, and a PUT+GET+POST flow proves the Single connection\nmode token-based dispatch end to end.",
          "is_bot": false,
          "headline": "refactor(app)!: registerGraphql wires 4 real-protocol routes on the s…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T17:52:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1df9ac46180afaf9f62191efde83ec3dfbe6b2d0",
          "body": "SSESingleCancelHandler serves DELETE /graphql?operationId=X (token via\nheader or query) and delegates to ReservationRegistry.StopOperation,\nstopping only that operationId's Subscription without touching any other\noperation active on the same token. Unknown token/operationId responds\n404, never panics.",
          "is_bot": false,
          "headline": "feat(graphql): ssesingle DELETE cancels one streaming operation by id",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T17:35:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5b567a8b0f796dc8578bdbd0353bd5a053ac1cff",
          "body": "…served token\n\nAdds SSESingleOperationHandler implementing graphql-sse's Single\nconnection mode operation start: POST /graphql decodes the standard\nGraphQL-over-HTTP body plus extensions.operationId, resolves the\nreservation token's write func via ReservationRegistry.Route (409 if\nno GET has attache\n[…]\nre\nDELETE handler (T14) can cancel one operationId's stream without\ntouching others on the same token; Release now also cancels any\noperations still registered under a token when its connection drops.",
          "is_bot": false,
          "headline": "feat(graphql): ssesingle POST executes operation, routes result to re…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T17:31:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ce2f9175c7845ed735e1645393e77a8cadffb790",
          "body": null,
          "is_bot": false,
          "headline": "feat(graphql): ssesingle PUT (reservation) + GET (single SSE connection)",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T17:23:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "162a7f8ddc1bd22ce792cf7e07419c641b365a65",
          "body": "Adds ReservationRegistry (Reserve/Attach/Route/Release), a thread-safe\ntoken -> connection registry used by graphql-sse's Single connection\nmode: PUT reserves a token, GET attaches the one SSE connection, and\nsubsequent POST/DELETE route by token via Route. Reuses google/uuid\n(already a direct dependency) for token generation.",
          "is_bot": false,
          "headline": "feat(graphql): reservation registry for SSE Single connection mode",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T17:09:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75bcf2fce3f702376762e8ad4a0f58f89fc148a9",
          "body": "…ections",
          "is_bot": false,
          "headline": "feat(graphql): ssedistinct handles Subscription via SSE Distinct conn…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T17:07:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "94fcc60edde243f7ad2c3dcfa754fd3c2ad0a1d2",
          "body": "…r graphql-sse PROTOCOL.md\n\nPROTOCOL.md (github.com/enisdenjo/graphql-sse, line 52) requires an\nexplicit, empty `data: ` field on the complete event: EventSource never\nfires its listener for an event with no `data:` line at all. The\nprevious commit's SPEC_DEVIATION #1 omitted it, which was a real bug,\nnot a neutral protocol choice. writeSSEDistinctResult now writes\n`event: complete\\ndata: \\n\\n`.",
          "is_bot": false,
          "headline": "fix(graphql): ssedistinct complete event includes empty data field pe…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T17:03:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "16ae41f1c8852d4574f8b75d7aa7fc5badd9154e",
          "body": "…TP SSE\n\nAdds SSEDistinctHandler (GET /graphql, graphql-sse Distinct connections\nmode): reads query/variables/operationName from the query string, reuses\nwsRootFieldName to resolve the root field and Execute to dispatch\nQuery/Mutation, then streams exactly one `event: next` frame (the\n{data,errors} \n[…]\never a bare HTTP\nerror status (EventSource can't read a non-2xx body). A root field that\nresolves to a registered Subscription gets a placeholder error frame --\nreal streaming dispatch is T10's scope.",
          "is_bot": false,
          "headline": "feat(graphql): ssedistinct handles Query/Mutation via GraphQL-over-HT…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T17:02:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b62c74c0ca89ee91b97f6710400cf6a7d2510047",
          "body": "T8: add a duplicate-id guard to handleSubscribe (checked via a new\nisOpActive closure over activeOps) that closes the connection with 4409\n(graphql-transport-ws's SubscriberAlreadyExists) when a Subscribe arrives\nfor an id whose earlier streaming Subscription hasn't completed yet. The\nQuery/Mutation\n[…]\nhere; documented inline.\n\nNew tests prove real multiplexing (a Query dispatched and fully answered\nwhile a Subscription is parked mid-stream on a different id, same\nconnection) and the new 4409 close.",
          "is_bot": false,
          "headline": "feat(graphql): wsprotocol multiplexing + 4409 on duplicate id",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T16:58:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bc94d099e3064b39485ca8729c1808095576e962",
          "body": "Design phase (routing collision at /graphql resolved via a new\nResponse.UpgradeWebSocket capability instead of adapter-level\nRegisterWebSocket+app.Use) and Planner-generated task breakdown (T1-T18),\nboth already implemented up through T7 in prior commits this session.",
          "is_bot": false,
          "headline": "docs(specs): add design.md and tasks.md for graphql-realtime-protocols",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T16:54:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "de2c24ce037ec7c3e029293d1b3ac7ef823fa785",
          "body": "…ing operation\n\nExtend WSProtocolHandler so a Subscribe whose root field matches a\nregistered Subscription runs HandlerFunc() in its own goroutine, emitting\none Next per emit(value) call instead of the T7-scope placeholder Error.\nWrites onto the connection are serialized through one writeMu (handsha\n[…]\nms are emitting share the same conn). A per-id\nid->done-channel registry lets a client's Complete for one id cancel only\nthat id's stream, and the connection dropping tears down every id still\nactive.",
          "is_bot": false,
          "headline": "feat(graphql): wsprotocol Subscribe dispatches Subscription as stream…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T16:53:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "86cb094104ec2fd6fe6128b33694b5433e5fce2f",
          "body": "…le-result operation\n\nExtends WSProtocolHandler's post-ack loop to handle graphql-transport-ws\nSubscribe messages: the root selection field is resolved via the\ngraphql-go parser (same AST parser Execute/gql.Do already uses) and\nlooked up in subs. When it isn't a registered Subscription (i.e. it's a\n\n[…]\nubscribe whose root field DOES match a registered\nSubscription gets a minimal Error response (\"not implemented yet\")\nrather than real streaming dispatch -- that's T7's scope, extending\nthis same loop.",
          "is_bot": false,
          "headline": "feat(graphql): wsprotocol Subscribe dispatches Query/Mutation as sing…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T16:48:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e296a8b49811170017cb834cc34c0949a980f4b",
          "body": "…00/4429)",
          "is_bot": false,
          "headline": "feat(graphql): wsprotocol handshake (ConnectionInit/Ack, timeouts, 44…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T16:40:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8fa8ece27379000b3a9dbf48d3d7c6a6a8c74ed0",
          "body": "…terWebSocket\n\nReplace fiberResponder.IsUpgradeRequest/Upgrade stubs with real\nwebsocket.IsWebSocketUpgrade/websocket.New wiring, and give\nfiberWSConn.CloseWithCode a real close-frame implementation\n(WriteControl(CloseMessage, FormatCloseMessage(code, reason)) + Close),\nboth confirmed against github\n[…]\nRegisterWebSocket -- required so `go build ./...` (this repo's\npre-commit build gate builds the whole module) keeps passing; this is\nNOT the GraphQL WS path reorganization, that lands in a later task.",
          "is_bot": false,
          "headline": "refactor(adapter/fiber)!: real WS upgrade via Responder, remove Regis…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T16:37:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1bc06514da189db63349645ad5ccde28e0cd87d1",
          "body": "…, extend Responder\n\nAdds IsUpgradeRequest()/Upgrade(handler func(conn WSConn)) to the\nResponder contract so Request/Response can expose thin delegating\nwrappers (IsWebSocketUpgrade/UpgradeWebSocket) for the upcoming\nWebSocket transport (graphql-realtime-protocols, Milestone 18).\n\nEvery existing Responder fake across the repo gets minimal no-op\nimplementations to keep compiling. fiberResponder gets a temporary\npanicking stub -- the real Fiber-backed WS implementation lands in a\nlater task (T4).",
          "is_bot": false,
          "headline": "feat(execution): Request.IsWebSocketUpgrade/Response.UpgradeWebSocket…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T16:29:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cae5d81aa4d3dc3d9ce5d6d503086eb3ec0bb8a1",
          "body": "…Code\n\nMoves the WSConn interface to internal/execution/wsconn.go so it can be\nshared beyond internal/graphql, and adds CloseWithCode(code, reason) for\ngraphql-transport-ws's well-known close codes (4400/4401/4408/4409/4429).\ngraphql.WSConn becomes a type alias back to execution.WSConn so ws.go's\nWSHandler is unaffected. fakeWSConn (ws_test.go) and fiberWSConn\n(internal/adapter/fiber) get minimal CloseWithCode stubs that delegate to\nClose() -- real close-code behavior lands in a later task.",
          "is_bot": false,
          "headline": "refactor(execution): move WSConn from internal/graphql, add CloseWith…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T16:23:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f7a50502f3779ae304359275c293e4a8a2fc632f",
          "body": "Move the gql.Do(gql.Params{...}) call plus the result.Errors ->\n[]map[string]any{\"message\": ...} mapping out of graphqlHandler into a\nnew internal/graphql.Execute(sch, query, variables, operationName)\nfunction, so upcoming WS/SSE transports can reuse the identical\ndispatch instead of copying it.",
          "is_bot": false,
          "headline": "refactor(graphql): extract Execute helper from POST /graphql handler",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T16:20:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a928cf3d42fbac091c92ed41447019920b9bb8ef",
          "body": null,
          "is_bot": false,
          "headline": "chore: change argument name on files",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T16:01:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d6fd98da79fbb2b2350f0d7086c9cfcfbf5bd2c",
          "body": null,
          "is_bot": false,
          "headline": "chore: change argument name on files",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T15:59:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae458408f42466aee3c581cdbd4446aaae823691",
          "body": "…ols, Design/Tasks/Execute pending\n\nMotivated by a real bug: a GraphQL IDE tried WebSocket directly on /graphql\nexpecting the graphql-transport-ws subprotocol and failed. The ad-hoc\nSubscription transports from Milestone 17 (/graphql/stream/:name,\n/graphql/ws/:name) never had a real consumer and don\n[…]\nely; WS modern subprotocol only (no legacy graphql-ws); multiplexing\nsupported from v1; full coverage of both graphql-sse modes.\n\nStopping here per explicit request — Design/Tasks/Execute not started.",
          "is_bot": false,
          "headline": "docs: specify graphql-realtime-protocols (Milestone 18) — real protoc…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T03:26:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "91585f5b524e0f22f19b8ef7046828c579e08713",
          "body": null,
          "is_bot": false,
          "headline": "docs: mention AppOptions.GraphqlPath in README",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T03:15:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e26305239fda0fb34688be4c6c5d04cc57e06e2a",
          "body": null,
          "is_bot": false,
          "headline": "chore: untrack image.png (debug screenshot, not project content)",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T03:15:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6f30121c82ffaefa8e540ee83cb348c7b7ccff3",
          "body": "…l endpoint\n\nSubscription's SSE/WS endpoints derive from the same path (<path>/stream/:name,\n<path>/ws/:name), so overriding it moves all three consistently.",
          "is_bot": false,
          "headline": "feat(app): add AppOptions.GraphqlPath to override the default /graphq…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T03:14:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd224e423240056fe3e15caa510190c3619515fa",
          "body": null,
          "is_bot": false,
          "headline": "docs: mention .examples/blog-graphql in README and Taskfile",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T03:01:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "916c86a1249c06e33db158e66a3e1e29d61efc36",
          "body": "… Returns\n\nThree real bugs found by actually running a GraphQL example end-to-end\n(not caught by any existing unit test, all of which used map[string]any\nHandler results and never a Query returning a list):\n\n1. Object fields never resolved when a Handler returned a real Go struct\n   (only a map[stri\n[…]\n Query/Mutation/Subscription\nend-to-end (verified via real dispatch: HTTP POST /graphql and a live SSE\nconnection actually receiving an emitted event), which is how all three\nbugs were actually found.",
          "is_bot": false,
          "headline": "fix(graphql): resolve struct fields, native int/float args, and array…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T02:57:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c50b995626fed42ebe9f9d462e9a0d2ed442377b",
          "body": null,
          "is_bot": false,
          "headline": "docs: update README for M16-M17 (Sanitize/Refine, GraphQL Support)",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T02:37:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0898f8d98de615a2b3d5f1e9ca6e97178439f76e",
          "body": "…GHT-GRAPHQL, verify gate",
          "is_bot": false,
          "headline": "chore: finalize graphql-support feature — update STATE, ROADMAP, INSI…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T02:36:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4002ad68857863608baf098075349f04e81d8a17",
          "body": "…on/Subscription/Context, Subscribe[T])\n\nTasks.md's T1-T11 built the full internal/graphql plumbing (Resolver/\nQuery/Mutation/Subscription, Schema->SDL generation, real HTTP dispatch,\nSSE/WebSocket Subscription transports) but never exposed it through\ngonest.go -- a real gap: without this, the feature had no way to actually\nbe used. Verified end-to-end via a real scratch build + gonest_test.go's\nown dispatch test.",
          "is_bot": false,
          "headline": "feat(gonest): expose public GraphQL API (GraphqlResolver/Query/Mutati…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T02:32:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5ffb8988e366e7ace363f38c46b2dfafa900285e",
          "body": "…gle internal/graphql package\n\nUser's call: 3 flat internal/* packages were unnecessary — the builder API,\nthe Schema->SDL generator, and the SSE/WS transports all belong to one\ncohesive concept. Package named 'graphql' (not nested under\ninternal/graphql/resolver, which would recreate the internal/r\n[…]\non AD-033 was written to avoid). Every reference to the\nEXTERNAL graphql-go/graphql package is import-aliased (gql \"github.com/\ngraphql-go/graphql\") wherever both packages are needed in the same file.",
          "is_bot": false,
          "headline": "refactor(graphql): merge gqlresolver/graphqlgen/gqltransport into sin…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T02:29:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1beb09910f60a3ca1cba80d8bbfca0d49c25ba3e",
          "body": "New HttpAdapter.RegisterWebSocket capability (confirmed real API via\nContext7: github.com/gofiber/contrib/v3/websocket's IsWebSocketUpgrade +\nwebsocket.New) -- a genuinely different connection shape than\nRegisterRoute's execution.Request/Response, so it gets its own method.\ngqltransport.WSConn keeps\n[…]\ns the spec's own P2 Independent Test: the same\nEmitter.Emit reaches an SSE client and a WebSocket client subscribed to\nthe same Subscription simultaneously; disconnecting one doesn't affect\nthe other.",
          "is_bot": false,
          "headline": "feat(gqltransport): add WebSocket transport for GraphQL Subscription",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T02:18:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c0623354e119663da3ec474fb32e54586fe969b2",
          "body": "SPEC_DEVIATION (Args format not decided by design.md): GET has no body,\nso Args come from a single ?args=<JSON object> query param, reusing\nvalidate.NewGraphqlArgsSource unchanged rather than inventing a new\nper-field query tag/coercion path.\n\nDisconnect detection is write-failure-based (a closed connection only\nsurfaces on an actual write attempt) -- a periodic heartbeat frame\n(': ping') covers Subscriptions whose Handler doesn't emit often enough\non its own to notice quickly.",
          "is_bot": false,
          "headline": "feat(gqltransport): add SSE transport for GraphQL Subscription",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T02:10:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01773b93c663a706f1905133c908549d4c4dbc1c",
          "body": "…treaming responses\n\nPrerequisite for graphql-support's SSE transport (T9) -- neither Json/Html/\nText nor a single Response value can express \"keep this connection open,\nwrite more later\". Backed by fasthttp's real SetBodyStreamWriter (confirmed\nvia fasthttp@v1.72.0 source, stream.go/server.go).",
          "is_bot": false,
          "headline": "feat(execution): add Response.Stream/Responder.WriteStream for body-s…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T02:05:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab209ebea7308bb583d76e70fe0fd09a0dec3773",
          "body": null,
          "is_bot": false,
          "headline": "feat(emitter): add Subscribe[T] dynamic channel subscription",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T01:55:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "227f2879ce94946dd1a96c9803902fd5ab167091",
          "body": "SPEC_DEVIATION: graphql-go's own execution engine (graphql.Do) is what\ninvokes Resolve per field -- dispatch could not be wired from internal/app\nalone as tasks.md originally sketched. Resolve callbacks are built inside\ninternal/graphqlgen.Build itself (wrapping each Query/Mutation's own\nHandlerFunc\n[…]\nh jsonBodySource.ParseInto) so GraphqlContext.Args()\nreuses the exact same validate/populate/Refine pipeline REST already has,\nover graphql-go's own already-decoded args map instead of raw JSON bytes.",
          "is_bot": false,
          "headline": "feat(app): wire real GraphQL Query/Mutation dispatch over POST /graphql",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T01:52:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3cbbf6239416bcbf53f6fd8faffc04af0c86e9e9",
          "body": "Dispatch (Resolve/Subscribe) intentionally left nil -- Query/Mutation\ndispatch is wired directly against gqlresolver's own HandlerFunc by\ninternal/app (T7), Subscription transport bypasses graphql-go's execution\nengine entirely (T9/T10), per design.md's Architecture Overview.\n\nSPEC_DEVIATION: no Pri\n[…]\nper found in graphql-go/graphql\n(confirmed via Context7 docs search) -- tests assert against the built\n*graphql.Schema's own structure (QueryType().Fields(), TypeMap()) instead\nof a golden SDL string.",
          "is_bot": false,
          "headline": "feat(graphqlgen): build graphql.Schema from gonest Schema declarations",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T01:44:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "55a5c73034e506b3963f6c1777946126e44f9025",
          "body": null,
          "is_bot": false,
          "headline": "feat(schema): add GraphqlScalar(name) modifier for Custom(fn) fields",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T01:40:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "036743457e9ed6ef9dc52e6c037572711785cb1a",
          "body": "…apping",
          "is_bot": false,
          "headline": "feat(graphqlgen): add graphql-go/graphql dependency + native scalar m…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T01:38:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c0e81fb90eae8ab3e28c84ed4769d76802bbdc51",
          "body": "…eclaration API\n\nAdds internal/gqlresolver (T1, T3) mirroring Controller/Route's builder\nshape, plus Module.Resolvers/OwnResolvers (T2) mirroring Controllers.\nGraphqlContext is stubbed for now (real Args()/Done() wiring lands in T7).",
          "is_bot": false,
          "headline": "feat(gqlresolver): add Resolver shell + Query/Mutation/Subscription d…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T01:36:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d0e8da2399dfcf945382e07b20b975923b3109c7",
          "body": "…Refine)",
          "is_bot": false,
          "headline": "docs: update README for M13-M16 (Accessor rename, NewValue, Sanitize/…",
          "author_name": "Leandro Santiago Gomes",
          "author_login": "leandroluk",
          "committed_at": "2026-07-18T00:57:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 31,
      "commits_last_year": 343,
      "latest_release_at": "2026-07-25T15:10:35Z",
      "latest_release_tag": "v0.31.0",
      "releases_from_tags": false,
      "days_since_last_push": 4,
      "active_weeks_last_year": 3,
      "days_since_latest_release": 4,
      "mean_days_between_releases": 0.2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "gonest.dev/gonest",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": null,
          "registry_url": "https://pkg.go.dev/gonest.dev/gonest",
          "is_deprecated": false,
          "latest_version": "v0.31.0",
          "repository_url": null,
          "versions_count": 31,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-25T15:09:39Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 4
        }
      ]
    },
    "popularity": {
      "forks": 1,
      "stars": 4,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-07-21",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 1,
        "total_forks": 1
      },
      "star_history": null,
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Taskfile.yml"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        ".examples/blog-api/go.mod",
        ".examples/blog-graphql/go.mod",
        ".examples/config-dotenv/go.mod",
        ".examples/full-text-search/go.mod",
        ".examples/lifecycle-hooks/go.mod",
        ".examples/notification-driver/go.mod",
        ".examples/simple-todo/go.mod",
        "go.mod"
      ],
      "largest_source_bytes": 147910,
      "source_files_sampled": 219,
      "oversized_source_files": 3,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/fasthttp/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.12"
        },
        {
          "name": "github.com/gofiber/contrib/v3/websocket",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.2.1"
        },
        {
          "name": "github.com/gofiber/fiber/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.4.0"
        },
        {
          "name": "github.com/google/uuid",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/graphql-go/graphql",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.8.1"
        },
        {
          "name": "github.com/robfig/cron/v3",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v3.0.1"
        },
        {
          "name": "golang.org/x/sync",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.22.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "leandroluk",
          "commits": 343,
          "avatar_url": "https://avatars.githubusercontent.com/u/8602982?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "release.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 8,
            "reason": "2 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "ea4e03179f40f7cc14adcaa9812343e8cfaf126b",
        "ran_at": "2026-07-29T16:43:24Z",
        "aggregate_score": 2.9,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-25T15:10:38Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/gonest-dev/gonest",
    "host": "github.com",
    "name": "gonest",
    "owner": "gonest-dev"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 45,
      "inputs": {
        "security": 29,
        "vitality": 74,
        "community": 28,
        "governance": 32,
        "engineering": 56
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 74,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 56,
            "inputs": {
              "commits_last_year": 343,
              "human_commit_share": 1,
              "days_since_last_push": 4,
              "active_weeks_last_year": 3
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "3/52 weeks with commits",
                "points": 2.1,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "343 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 343
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 31,
              "latest_release_tag": "v0.31.0",
              "releases_from_tags": false,
              "days_since_latest_release": 4,
              "mean_days_between_releases": 0.2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "31 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 31
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 28,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 8,
            "inputs": {
              "forks": 1,
              "stars": 4,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "4 stars",
                "points": 7.7,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "1 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 32,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution, PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution",
                    "pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "no decided pull requests or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_decided_prs_or_data",
                    "params": {}
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 35,
            "inputs": {
              "followers": 0,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "gonest-dev",
              "public_repos": 3,
              "account_age_days": 145
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of gonest-dev",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "gonest-dev"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "3 public repos, account ~0 yr old",
                "points": 5.2,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 3
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "gonest.dev/gonest"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 4
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 4 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "31 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 31
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 56,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "critical",
        "name": "Security",
        "value": 29,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 29,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 15,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 3,
              "scorecard_aggregate": 2.9
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "2 existing vulnerabilities detected",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 60,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "Taskfile.yml"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                ".examples/blog-api/go.mod",
                ".examples/blog-graphql/go.mod",
                ".examples/config-dotenv/go.mod",
                ".examples/full-text-search/go.mod",
                ".examples/lifecycle-hooks/go.mod",
                ".examples/notification-driver/go.mod",
                ".examples/simple-todo/go.mod",
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Taskfile.yml",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Taskfile.yml"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 147910,
              "source_files_sampled": 219,
              "oversized_source_files": 3
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "3/219 source files over 60KB",
                "points": 54.2,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 219,
                      "oversized": 3
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-29T16:43:29.647887Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/g/gonest-dev/gonest.svg",
  "full_name": "gonest-dev/gonest",
  "license_state": "standard",
  "license_spdx": "MIT"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计Go.