公开记录
软件健康报告模式 0.26.0 · 指标 1.13.0 · 2026-07-22 15:32 UTC

iterate / capnweb

JavaScript/TypeScript-native, low-boilerplate, object-capability RPC system

TypeScriptMIT★ 0 星标⑂ 0 复刻始于 2026年6月复刻在 GitHub 上查看 ↗

iterate/capnweb 的健康指数为 100 分中的 48 分,处于「存在风险」区间。 其得分最高的类别是Vitality(77/100),最低的是Engineering Quality(29/100)。 最近一次更新在 5 天前。 近期的大部分工作由 1 位贡献者完成。

48
总分 / 100
存在风险

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

48
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

27 关注者20 个公开仓库始于 2010年8月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布
npm@iterate-com/capnweb0.10.069,25925 天前

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

77良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 5 天前
22.8/36提交节奏 — 52 周中有 33 周有提交
18/18提交量 — 最近一年 175 次提交
0/10OpenSSF Scorecard:Maintained — project was created within the last 90 days. Please review its contents carefully
所用输入
commits_last_year175
human_commit_share0.83
days_since_last_push5
active_weeks_last_year33

发布纪律

76良好
评分方式
27/27有发布版本 — 已发布 1 个发布版本
36/36发布时效 — 最近一次发布版本于 41 天前
12.6/27发布节奏 — 节奏未知(仅一次发布)
0/10OpenSSF Scorecard:Signed-Releases — Project has not signed or included provenance with any releases.
所用输入
releases_count1
latest_release_tagv0.8.0-websocket.1
releases_from_tags
days_since_latest_release41
mean_days_between_releases

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

29危急 · 占总体的 18%
评分方式
0/60星标 — 0 个星标
0/25复刻 — 0 个复刻
0/15关注者 — 0 位关注者
所用输入
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

25危急
评分方式
0/22.5README
22.5/22.5许可证 — 可识别的许可证(MIT)
0/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
64.5/80月度下载量 — npm 合计每月 69,259 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packages@iterate-com/capnweb
dependents
ecosystemsnpm
total_downloads
monthly_downloads69,259
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

60中等 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
8.1/22.5提交分布 — 头号贡献者编写了 64% 的提交
13.5/13.5贡献者广度 — 28 位贡献者
10/10OpenSSF Scorecard:Contributors — project has 5 contributing companies or organizations
所用输入
bus_factor1
contributors_sampled28
top_contributor_share0.638
评分方式
0/46.8议题解决 — 没有议题或无数据
30.6/38.3PR 接受 — 已裁定的 PR 中 4/5 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/30 approved changesets -- score normalized to 0
所用输入
merged_prs4
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs1
已排除计分(无数据或不适用):议题解决。 其余权重已重新归一化。
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
10.4/25所有者影响力 — iterate 有 27 位关注者
21.6/25既往记录 — 20 个公开仓库,账户约 15 年
所用输入
followers27
owner_typeOrganization
is_verified
owner_loginiterate
public_repos20
account_age_days5,820
评分方式
25/25已发布且可解析 — npm 上有 1 个软件包
35/35发布时效 — 最近一次发布于 5 天前
12/20版本历史 — 2 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packages@iterate-com/capnweb
ecosystemsnpm
any_deprecated
min_days_since_publish5

工程质量

基础的工程与文档实践是否到位?

29危急 · 占总体的 20%

工程实践

48存在风险
评分方式
24/24CI 工作流 — 4 个工作流
24/24存在测试
0/16Linter 配置
0/9.6Pre-commit 钩子
0/6.4.editorconfig
0/20OpenSSF Scorecard:CI-Tests — 0 out of 1 merged PRs checked by a CI test -- score normalized to 0
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

1危急
评分方式
0/30README
0/25文档目录
0/15文档 / 主页站点
0/10仓库描述
0/10主题标签
0/10Wiki
所用输入
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

35存在风险 · 占总体的 16%

安全态势

35存在风险
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — 0 out of 1 merged PRs checked by a CI test -- score normalized to 0
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 5 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — 无数据
1/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
6.8/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 15 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate3.5
已排除计分(无数据或不适用):packaging。 其余权重已重新归一化。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

57中等 · 占总体的 0%
评分方式
0/45代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 83 次人类提交中有 80 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.964
agent_instruction_files
agent_instruction_max_bytes
评分方式
0/18一条命令的引导启动
22/22自动化测试
0/11Lint / 格式化配置
11/11静态类型检查 — __tests__/tsconfig.json, __type-tests__/tsconfig.json, examples/worker-react/client/tsconfig.json, examples/worker-react/server/tsconfig.json, packages/capnweb-validate/tsconfig.json, tsconfig.json
10/10可复现环境 — lockfile
8/10已体现的代理实践 — 最近 100 次提交中有 4 次由代理编写或署名代理
8/8自动化维护 — 最近 100 次提交中有 3 次为自动依赖更新
2/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 2
所用输入
has_nix
has_tests
lockfilespackage-lock.json
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configs__tests__/tsconfig.json, __type-tests__/tsconfig.json, examples/worker-react/client/tsconfig.json, examples/worker-react/server/tsconfig.json, packages/capnweb-validate/tsconfig.json, tsconfig.json
agent_commit_share0.04
toolchain_manifests
dependency_bot_commit_share0.03
评分方式
45/45可类型检查的代码 — TypeScript(静态类型)
53.9/55可控的文件大小 — 采样的 97 个源文件中有 2 个超过 60KB
所用输入
primary_languageTypeScript
largest_source_bytes130,907
source_files_sampled97
oversized_source_files2

机器可读接口

40存在风险
评分方式
0/40API 模式(OpenAPI/GraphQL/proto)
0/20MCP 服务器
40/40可运行示例 — examples
所用输入
example_dirsexamples
has_mcp_signal
api_schema_files

关键数据

0GitHub 星标
28贡献者
175最近 12 个月提交数
5距最近推送天数
1发布版本数
1巴士系数(bus factor)
0开放议题
npm软件包生态系统数

数据采集警告

  • Community profile unavailable
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index npm:@iterate-com/capnweb@0.10.0; advisories assessed against the repository dependency graph instead

更多细节

OpenSSF Scorecard 3.5 / 10
3.5综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-22 15:32 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
0CI-Tests0 out of 1 merged PRs checked by a CI test -- score normalized to 0
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
10Contributorsproject has 5 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
不适用Packagingpackaging workflow not detected
2Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 2
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
9Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities15 existing vulnerabilities detected
全部依赖 未采集

本报告未能采集到解析后的依赖集合:GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": true,
      "size_kb": 955,
      "has_wiki": false,
      "homepage": null,
      "languages": {
        "JavaScript": 5587,
        "TypeScript": 847165
      },
      "pushed_at": "2026-07-17T13:31:47Z",
      "created_at": "2026-06-03T15:45:16Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-17T13:32:22Z",
      "description": "JavaScript/TypeScript-native, low-boilerplate, object-capability RPC system",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://iterate.com",
      "name": "iterate.com",
      "type": "Organization",
      "login": "iterate",
      "company": null,
      "location": "United Kingdom",
      "followers": 27,
      "avatar_url": "https://avatars.githubusercontent.com/u/364663?v=4",
      "created_at": "2010-08-14T23:00:46Z",
      "is_verified": null,
      "public_repos": 20,
      "account_age_days": 5820
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.8.0-websocket.1",
          "kind": "prerelease",
          "published_at": "2026-06-10T19:56:22Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "6cd9dc89f53ee8420be0c69fe6c5d1be563954f4",
          "body": "Bonk (Cloudflare's AI PR reviewer) requires Cloudflare AI Gateway secrets\nthis repo doesn't have, and its PR-opened trigger is not gated on the\ncloudflare org, so every iterate PR would get a failing check. The CLA\nassistant runs on pull_request_target and would demand Cloudflare CLA\nsignatures from iterate contributors. Both are upstream-internal; drop\nthem. semgrep.yml and test.yml are kept — they run without secrets.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Remove Cloudflare-internal CI workflows from the fork",
          "author_name": "Jonas Templestein",
          "author_login": "jonastemplestein",
          "committed_at": "2026-07-17T13:19:02Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "fdf04f5e14ad22b249162219223732aad225dae3",
          "body": null,
          "is_bot": false,
          "headline": "Sync package-lock name to @iterate-com/capnweb",
          "author_name": "Jonas Templestein",
          "author_login": "jonastemplestein",
          "committed_at": "2026-07-17T13:11:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "291c19170a8d2d976a2a47ac5e54fc9eaff45538",
          "body": "Rename the package so Iterate can ship the fork (WebSocket-over-RPC +\nonCall + Provider type fix) on npm without colliding with upstream\ncapnweb. Wire pkg.pr.new for main/PR previews and a tag-based npm\nrelease workflow for real registry publishes.",
          "is_bot": false,
          "headline": "Publish as @iterate-com/capnweb with pkg.pr.new and npm release CI",
          "author_name": "Jonas Templestein",
          "author_login": "jonastemplestein",
          "committed_at": "2026-07-17T13:11:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "11b103c38e0c6e35a3f9f1961ae59e57b049b468",
          "body": null,
          "is_bot": false,
          "headline": "Add a server-side per-call RPC hook",
          "author_name": "Jonas Templestein",
          "author_login": "jonastemplestein",
          "committed_at": "2026-07-17T12:57:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "37740d3858a5604a4310443d9efd61a033642b92",
          "body": "Installing capnweb directly from git (e.g. \"capnweb\": \"github:...\")\notherwise produces a package without dist/, since only prepublishOnly\ntriggers the build and package managers don't run it for git deps.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add a prepare script so git dependencies get a build",
          "author_name": "Jonas Templestein",
          "author_login": "jonastemplestein",
          "committed_at": "2026-07-17T12:57:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "dd78944e223584029e91e66094b27ec8a5e19602",
          "body": "…de Response.\n\nWhen a Response has a webSocket property -- the Cloudflare Workers\nextension, as produced by a fetch() that performs a WebSocket upgrade --\nit can now be passed over RPC, in arguments or return values, with the\nsocket's messages tunneled over the RPC session. Bare WebSockets remain\nno\n[…]\nfor now; and on\nplatforms whose sockets don't buffer pre-accept (e.g. Node ws), messages\narriving before the Response is serialized are dropped.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Add support for sending WebSockets over RPC, as part of a fetch upgra…",
          "author_name": "Jonas Templestein",
          "author_login": "jonastemplestein",
          "committed_at": "2026-07-17T12:57:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bc4bc45a6f54b6a4ea211e746c4d545df0d8c1b3",
          "body": "Bump vitest, @vitest/browser, vite, and ws to clear critical/high\ndev-server advisories, and refresh patched transitives in range.",
          "is_bot": false,
          "headline": "chore: patch relevant audit vulnerabilities (#218)",
          "author_name": "Nathan Disidore",
          "author_login": "ndisidore",
          "committed_at": "2026-07-16T15:31:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1cca1a212da1e8bc4f807725d96702f0b78207e1",
          "body": "…RPC payloads (#212)\n\n* test: add tests for streaming RpcTarget over RPC\n\n* feat: support streaming WritableStream writes with lifecycle-managed RPC payloads\n\n* chore: add changeset for RpcTarget streaming support\n\n* fix: dispose capability-free stream chunks immediately after write\n\n- Only defer payload disposal when the chunk owns hooks or promises\n- Avoid attaching disposers to pure data object chunks",
          "is_bot": false,
          "headline": "feat: support streaming WritableStream writes with lifecycle-managed …",
          "author_name": "Neko Hz",
          "author_login": "codehz",
          "committed_at": "2026-07-16T12:17:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f790b59d5e6692d93ff382c2acabe5eacb64d54",
          "body": null,
          "is_bot": false,
          "headline": "ci: prevent Bonk from pushing (#217)",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-07-16T01:16:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7325f9d5c80dd57fea896bb4696d22a102cf10a8",
          "body": "* feat: Support buffer views serialization\n\n* docs: list bytes type markers\n\n* Always serialize in little endian, check length multiples.\n\n* feat: Enhance byte container support and error handling in serialization",
          "is_bot": false,
          "headline": "feat: Support ArrayBuffer and Buffer Views serialization (#201)",
          "author_name": "ttmx",
          "author_login": "ttmx",
          "committed_at": "2026-07-16T00:10:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2a02db961460c222b0643a92483255613c7f78d5",
          "body": "The BaseType union types readable streams as ReadableStream<any>, mirroring WritableStream<any>, so an RpcTarget signature can carry a readable stream of any RPC-compatible chunk type. The runtime pipes each chunk through the generic RPC serializer, so the type surface matches runtime behavior; the \n[…]\nrough the Stubify/Unstubify mapped types unchanged.\n\nType-tests cover string and object chunk streams, assert the chunk type is preserved rather than collapsed to any, and retain byte-stream coverage.",
          "is_bot": false,
          "headline": "Widen ReadableStream RPC chunk type to any RPC-compatible value (#214)",
          "author_name": "Nathan Disidore",
          "author_login": "ndisidore",
          "committed_at": "2026-07-15T15:24:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ee7ca6f5f15dfc238c8d877e23ad396de67d68ab",
          "body": "* Tidy the error-type map and WebSocket close-reason limit\n\n- serialize.ts: use a null-prototype object literal for ERROR_TYPES instead of\n  Object.assign(Object.create(null), ...).\n- websocket.ts: derive the close-reason cap from the RFC 6455 Close-frame size\n  (125 - 2) rather than a bare 123, and\n[…]\nn the\n\"import not found\" path and never calls resolve() a second time. Its test also\npassed with the guard removed. Remove both, and drop the changeset since this\nis a cleanup with no behavior change.",
          "is_bot": false,
          "headline": "Tidy the error-type map and WebSocket close-reason limit (#209)",
          "author_name": "Nathan Disidore",
          "author_login": "ndisidore",
          "committed_at": "2026-07-09T17:27:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "92baaed467e2cefb7f89916516ebdb7b88d043c6",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Version Packages (#208)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-07T01:21:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6e5c5622a326540e14602304da84fccf00b2d62d",
          "body": "…port handling (#190)\n\n* Fix four correctness issues in serialization and transport handling\n\n- serialize.ts: filter inherited Object.prototype keys (and toJSON) out of an\n  error's own-property bag during deserialization, matching the plain-object\n  path. Prevents keys like __proto__/toString/value\n[…]\n--\n\nCo-authored-by: taylorodell <172618523+taylorodell@users.noreply.github.com>\nCo-authored-by: Kenton Varda <kenton@cloudflare.com>\nCo-authored-by: Dimitri Mitropoulos <dimitrimitropoulos@gmail.com>",
          "is_bot": false,
          "headline": "Fix five correctness and robustness issues in serialization and trans…",
          "author_name": "taylorodell",
          "author_login": "taylorodell",
          "committed_at": "2026-07-07T01:16:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0b20ec655bc244072f78382b22ef295228b1d259",
          "body": "Deserializing messages from an untrusted peer could exhaust CPU, memory,\nor the stack:\n\n- A long [bigint,...] digit string fed straight to BigInt() blocks the\n  event loop, because BigInt()'s decimal parse is superlinear.\n- A deeply nested message could overflow the stack during evaluation.\n- An arb\n[…]\nandalone\ndeserialize() path stays protected by the defaults. Limits are purely local\n(the protocol has no negotiation step); exceeding one throws, which aborts\nthe session via the existing abort path.",
          "is_bot": false,
          "headline": "Add receiver-side resource limits for untrusted peers (#184) (#185)",
          "author_name": "Nathan Disidore",
          "author_login": "ndisidore",
          "committed_at": "2026-07-06T22:54:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "47df6970ed155868e40504a171374ff8b50f46b9",
          "body": "* ci: bump checkout/setup-node to v5 for Node 20 deprecation\n\nGitHub Actions warns that Node.js 20 is deprecated and actions/checkout@v4 + actions/setup-node@v4 are forced onto Node.js 24 (actions run 28813638276, PR #185). Upgrade these workflows to v5 to align with the new runtime.\n\n* ci: move wor\n[…]\nsteps from v5 to v7 for consistency.\n\n* ci: upgrade setup-node action to v6\n\nBump actions/setup-node from v5 to v6 across workflows to stay on the latest major while keeping node-version pinned to 24.",
          "is_bot": false,
          "headline": "ci: upgrade GitHub Actions to Node 24-compatible versions (#207)",
          "author_name": "Dimitri Mitropoulos",
          "author_login": "dimitropoulos",
          "committed_at": "2026-07-06T21:52:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "610ab3ab6c187a5bafc24f321c27ae957d7206e5",
          "body": null,
          "is_bot": false,
          "headline": "ci(cla): report dispatched CLA pass via commit status (#206)",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-07-06T16:24:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7fcc52a3e69861f0b36b52911aed9e2ad3a8fb65",
          "body": "* Version Packages\n\n* docs(changelog): credit @ashkalor for #186",
          "is_bot": true,
          "headline": "Version Packages (#205)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-04T14:10:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "78744ca99df8c93443556351b5849329765a930c",
          "body": "…sponse (#195)\n\nWithout response.end() and return, non-POST requests fell through into the\nRPC pipeline and crashed with ERR_HTTP_HEADERS_SENT. Forward options.headers\non the 405 path so cross-origin browser clients receive CORS headers.",
          "is_bot": false,
          "headline": "fix(batch): return 405 immediately for non-POST in nodeHttpBatchRpcRe…",
          "author_name": "Lê Minh Quân",
          "author_login": "aleister1102",
          "committed_at": "2026-07-04T13:51:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a9f19d1c957215c0cc84058c64324feea8ff9c5",
          "body": "The global test server called `httpServer.listen(0)` with no host, so on\ndual-stack hosts Node binds the IPv6 wildcard `::`. That address is then\nprovided to clients verbatim as `testServerHost`, so tests connect to\n`http://[::]:PORT` / `ws://[::]:PORT`.\n\nChromium tolerates connecting to the wildcar\n[…]\n synchronous).\n\nVerified on macOS: Firefox and WebKit go from failing those two tests to\npassing; node and workerd are unaffected.\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Bind test server to loopback so Firefox/WebKit can connect (#200)",
          "author_name": "SamJB123",
          "author_login": "SamJB123",
          "committed_at": "2026-07-03T19:29:35Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "79bc29639f2fb73882d119987c5bc97a9f3cb933",
          "body": null,
          "is_bot": false,
          "headline": "ci(cla): dispatch CLA check for generated release PRs (#204)",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-07-02T16:44:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5161d97cfd9a6374d6bd0485e9ce1851495c5e18",
          "body": "* Version Packages\n\n* chore: empty commit to trigger required CLAssistant check",
          "is_bot": true,
          "headline": "Version Packages (#203)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-02T14:06:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5bf633f81972cb6cb1d9bf6d1c8be711d9ec9878",
          "body": "Add \".\" to workspaces so the root package is treated as a workspace\nmember (releasable), and set onlyUpdatePeerDependentsWhenOutOfRange so\nbumping capnweb does not force a major bump of capnweb-validate.\n\nFixes the Release workflow failing on the first changeset that targets\nthe root capnweb package (regression from #169).",
          "is_bot": false,
          "headline": "fix: allow changesets to release root capnweb package (#202)",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-07-01T14:27:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c70bbb77ee5b25672f77d7befef7e711f4a98836",
          "body": "Add transport encoding levels so custom RPC transports can work with `jsonCompatible` values, `jsonCompatibleWithBytes` values, or `structuredClonable` messages instead of always receiving JSON strings.\n\nNote: `MessagePort` sessions now post structured-clonable objects over the port instead of JSON \n[…]\n This changes the wire format between the two ends of the port, so both ends of a `MessagePort` session must upgrade to this version together.\n\nOriginal design and implementation by @ashkalor in #144.",
          "is_bot": false,
          "headline": "Finish RPC transport encoding levels from #144 (#186)",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-07-01T03:24:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "952a541afbfb7c051b8b1f17fb84d3587300cb4c",
          "body": "…call (#198)\n\nBoth Bonk workflows previously authorized the triggering user with a\ndedicated step that called the GitHub API at\n/orgs/cloudflare/members/{user}. That required provisioning and storing a\nREAD_ONLY_ORG_GITHUB_TOKEN secret and cost an extra API round-trip on\nevery invocation.\n\nThe webho\n[…]\nout, since these jobs run with contents/issues/\npull-requests write and the Cloudflare AI Gateway secrets.\n\nREAD_ONLY_ORG_GITHUB_TOKEN is no longer referenced by any workflow and\ncan be deprovisioned.",
          "is_bot": false,
          "headline": "ci: gate Bonk on author_association instead of an org-membership API …",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-06-19T22:09:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9c9ef01e028185e4feadea552978d43205a6af68",
          "body": null,
          "is_bot": true,
          "headline": "Version Packages (#199)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-16T16:38:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "040982108c4c35820f61292819a276a495aa982d",
          "body": "…ypoint and DurableObject. (#197)\n\nThese are invoked by the Workers runtime, not over RPC, so they pass\nthrough unvalidated instead of being treated as RPC methods. The same\nplatform-passthrough filtering now runs on the server-marker path\n(newWorkersRpcResponse) as well as the @validateRpc decorator, so both\nagree on which members are validated.",
          "is_bot": false,
          "headline": "Skip validation for fetch and connect lifecycle methods on WorkerEntr…",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-06-16T14:57:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc8601e0cd430627ab1f5708a42e2a3c6275e7c0",
          "body": "* Version Packages",
          "is_bot": true,
          "headline": "Version Packages (#196)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-12T20:25:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4093556c84ab7193a289c62bce6fd75996840cda",
          "body": "…(#194)\n\n- Replace constructor-returns-Proxy in __validateRpcClass with in-place\n  prototype method wrapping, idempotent via a WRAPPED_METHOD symbol\n- Decorated classes extending decorated classes now resolve subclass-only\n  methods against the subclass validator instead of refusing them\n- Instances\n[…]\nl branded RpcTargets, removing the Proxy-serialization\n  hazard over native workerd RPC\n- Reword refusal errors to distinguish instance-property access from\n  methods not declared on the RPC interface",
          "is_bot": false,
          "headline": "fix(validate): support decorated classes extending decorated classes …",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-06-12T20:00:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0d6b2ff40ea4138c4487b94e196bbe4bb087e1c8",
          "body": "Adds the same Bonk (ask-bonk/OpenCode) setup used in cloudflare/workers-sdk:\n\n- bonk-pr-review.yml: auto-reviews newly opened PRs from Cloudflare org\n  members using the prompt in .github/bonk_reviewer.md\n- bonk.yml: interactive agent triggered by /bonk or @ask-bonk comments,\n  using the agent defin\n[…]\nss-runtime support.\n\nRequires repo access to secrets: CF_AI_GATEWAY_ACCOUNT_ID,\nCF_AI_GATEWAY_NAME, CF_AI_GATEWAY_TOKEN, READ_ONLY_ORG_GITHUB_TOKEN,\nplus the ask-bonk GitHub App installed on the repo.",
          "is_bot": false,
          "headline": "ci: add Bonk AI code review workflows (#193)",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-06-12T09:46:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bd220554cb2fa401feca7e533679e511cbfed5ec",
          "body": null,
          "is_bot": true,
          "headline": "Version Packages (#191)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-06-09T01:58:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d5a0478c3a6d283c66182f8031214906a5ad36a",
          "body": "Changesets 'Version Packages' PRs are authored by github-actions[bot], which isn't in the CLA allowlist, so the required CLAssistant check can never pass on them: the bot can't sign, and recheck reports against main rather than the PR head. Add it alongside dependabot[bot]/workers-devprod.",
          "is_bot": false,
          "headline": "ci(cla): allowlist github-actions[bot] for changesets release PRs (#192)",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-06-09T01:48:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2cb51eb4c6424ef38132daa0e473f48ec7e14271",
          "body": "* Add capnweb-typecheck RPC validators\n\nAdd the capnweb-typecheck package, marker transform, plugin adapters, CLI, runtime validators, tests, and Worker React debug example.\n\n* rename capnweb-typecheck to capnweb-validate\n\n* Add decorator-based RPC validation\n\n* Stabilize capnweb-validate fast bailo\n[…]\nexercises a server-side validation failure.\n\n* fix(validate): require TypeScript >=5.7 (SharedArrayBuffer view typing)\n\n* Add changeset\n\n---------\n\nCo-authored-by: Kenton Varda <kenton@cloudflare.com>",
          "is_bot": false,
          "headline": "Add capnweb-validate RPC validators (#169)",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-06-09T00:58:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3d17ba1afc3613cb02a832c5c88eda338dd32dfe",
          "body": "Use tsdown's explicit tsx config loader so older Node 22 builds can still load tsdown.config.ts.\n\nReplace deprecated external config with deps.neverBundle and update the config type to UserConfig.",
          "is_bot": false,
          "headline": "Update tsdown to latest version (#183)",
          "author_name": "Steven",
          "author_login": "teamchong",
          "committed_at": "2026-05-22T17:55:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5eb7701f74ee7783455e3ea17ea65d5200ded496",
          "body": null,
          "is_bot": false,
          "headline": "Switch build tool from tsup to tsdown (#50)",
          "author_name": "Kingsword",
          "author_login": "kingsword09",
          "committed_at": "2026-05-20T16:53:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b9f85997fe554cd986bb02ab16afb3375e515b6",
          "body": null,
          "is_bot": false,
          "headline": "docs: add info about Blob serialization to protocol.md (#171)",
          "author_name": "Zachary Dremann",
          "author_login": "Dr-Emann",
          "committed_at": "2026-05-15T01:01:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "31adae850abdba0e0735aa60cd5fa31f2814c09c",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Version Packages (#167)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-05-11T18:20:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7413e43b251a0db79e9c59e67d37f01c725818fe",
          "body": "…ialization (#166)\n\nCloses #87.\n\nToday the wire format for `Error` only carries `name`, `message`, and (optionally) `stack`. Anything a user attaches to the error — `code`, `details`, a `cause`, the inner errors of an `AggregateError` — is lost the moment the error crosses an RPC boundary.\n\nThis PR \n[…]\ne any if needed.\n\nThe `error` expression in protocol.md now documents the optional `props` element, the lossy-fallback semantics.\n\n---------\n\nCo-authored-by: aron-cf <aron-cf@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Preserve own properties of Error instances across serialization/deser…",
          "author_name": "Aron",
          "author_login": "aron-cf",
          "committed_at": "2026-05-08T15:21:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "25baebf7facfcdafb8cd46ea20b982cbc05557a4",
          "body": "_This fix is actually #154 from @VastBlast, but I removed the middle commit and squashed the other two. (The middle commit of #154 was addressing an unrelated problem and is more controversial -- see my comments there.)_\n\nThis fixes a memory leak in long sessions. It turns out that due to the implem\n[…]\nsh to fix it, at least in V8: https://chromium-review.googlesource.com/c/v8/v8/+/7646250\n\nBut this won't fix the `Promise.race` leak (first point above), so we should still land this fix to Cap'n WEb.",
          "is_bot": false,
          "headline": "Fix memory leak from long-lived cancellation promise (#168)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2026-05-07T17:27:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9e499e2ac38dd4b57403d7e3d3294412bfbace14",
          "body": "* fix serialization of Invalid Date values and handle NaN/null timestamps\n\n* Create proud-melons-stare.md\n\n---------\n\nCo-authored-by: Kenton Varda <kenton@cloudflare.com>",
          "is_bot": false,
          "headline": "Fix serialization for Invalid/NaN dates (#152)",
          "author_name": "VastBlast",
          "author_login": "VastBlast",
          "committed_at": "2026-05-07T16:25:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "48f4d495ef66e947612e80f36f4f9570b439e407",
          "body": "* feat: add Blob serialization support over RPC\n\nBlobs can now be passed as RPC call arguments and return values, with\nMIME type preserved across the wire.\n\nWire format: [\"blob\", type, [\"readable\", pipeId]]. Bytes always stream\nthrough a pipe — reading a Blob's bytes is inherently async, so there's\n\n[…]\nequires a session).\n\n* Apply suggestions from code review\n\nCo-authored-by: Kenton Varda <kenton@cloudflare.com>\n\n* Inline blob constant\n\n---------\n\nCo-authored-by: Kenton Varda <kenton@cloudflare.com>",
          "is_bot": false,
          "headline": "feat: add Blob serialization support over RPC (#155)",
          "author_name": "Gabriel Massadas",
          "author_login": "G4brym",
          "committed_at": "2026-05-07T16:05:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e4b0aab6e6a59562188a6ac59f68b79804434526",
          "body": "## Summary\n\nAdds Semgrep Community Edition (OSS) scanning to this repository as part of the App&ProdSec team's migration from Semgrep Pro to Semgrep CE.\n\n## What it does\n\n- Runs on every PR, on `push` to the main/master branch, and monthly on a staggered schedule.\n- Uses `actions/cache@v5` so `pip i\n[…]\nrmational; the job does not block on findings.\n- First PR after merge installs Semgrep; subsequent PRs skip that step.\n\nSee the internal App&ProdSec email for migration context, or ping us internally.",
          "is_bot": false,
          "headline": "ci: add Semgrep OSS scanning workflow (#164)",
          "author_name": "Hrushikesh Deshpande",
          "author_login": "hrushikeshdeshpande",
          "committed_at": "2026-05-06T19:29:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b4a17cf1695837e2238cffffa07b5761fa7dd149",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Version Packages (#163)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-04-27T22:37:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7cb91326387bea52a4dab889ed01a46f30ce4af0",
          "body": "* Add Bun ServerWebSocket support\n\nBun uses callback-based WebSocket handlers registered on `Bun.serve()`\nrather than the standard `addEventListener` interface. Passing a Bun\nServerWebSocket to `newWebSocketRpcSession()` errors because the\n`addEventListener` method does not exist (#61).\n\nA new BunWe\n[…]\nREADME.md\n\nRemove example of custom Bun websocket transport\n\n* Add changeset\n\n---------\n\nCo-authored-by: aron-cf <aron-cf@users.noreply.github.com>\nCo-authored-by: Kenton Varda <kenton@cloudflare.com>",
          "is_bot": false,
          "headline": "Add bun support (#159)",
          "author_name": "Aron",
          "author_login": "aron-cf",
          "committed_at": "2026-04-20T16:40:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cfa1b959ebf4cf24c3ea8277f424118306ffff2e",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Version Packages (#149)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-03-09T23:03:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "189fa799f6ef26d0704b355c1e11a9ed9a362247",
          "body": "…nto capnweb's public interface. (#148)\n\nThese type overrides were meant for type-checking Cap'n Web's own code, but the TS compiler \"helpfully\" shlepped them into the public `index.d.ts` for the capnweb package, affecting dependent builds. Oops!",
          "is_bot": false,
          "headline": "Fix type overrides for Uint8Array's toBase64 and fromBase64 leaking i…",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2026-03-09T21:48:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "03c82e877efcd1cfed1bee91d20140870bd07a27",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Version Packages (#147)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-03-09T20:19:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60be60d504f6d6984e88a6ef558b91dee5afb97b",
          "body": "…ore accurate. (#142)\n\nThis PR rewrites type definitions to fix a ton of issues. I believe this closes all the open & confirmed type issues/bugs reported. Based on my testing, I did not find any new issues, but please let me know if anything slipped.\n\nMy motivation for this stemmed from the current \n[…]\n different base/edge cases. I then tested it against the current types, before using AI to both rewrite the types. After many hours, feedback loops, and handwritten rewrites, I finally landed on this.",
          "is_bot": false,
          "headline": "Major improvements to type definitions, fixing bugs and making them m…",
          "author_name": "VastBlast",
          "author_login": "VastBlast",
          "committed_at": "2026-03-09T20:08:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5667226688fad4e28508f7779d49c1c89e53f102",
          "body": "* Fix base64 handling and also support Buffer.\n\n* base64 encoding of large arrays no longer throws on any platform.\n* When toBase64 is unavailable, but Buffer is, this uses Buffer.\n* Also, we now accept Buffer for serialization and treat it like Uint8Array.\n* Also, when decoding, if Buffer is availa\n[…]\nencode.cloudflare.dev/share/VwnZjojz\n\n* Add changesets for base64 and Buffer changes.\n\n* Don't strip padding in the toBase64() case that already omits it.\n\nAlso add a test verifying padding-stripping.",
          "is_bot": false,
          "headline": "Fix base64 handling and also support Buffer. (#145)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2026-03-09T19:19:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "686da4465b0f42b4f2a30ba93c2b52424a67ba0b",
          "body": "…ing in commands (#138)",
          "is_bot": false,
          "headline": "refactor: move build format config to tsup config rather than hardcod…",
          "author_name": "VastBlast",
          "author_login": "VastBlast",
          "committed_at": "2026-03-07T23:13:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "844e2ece215712e8e0f0537f3655eef2152fe331",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Version Packages (#130)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-02-18T23:07:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0d2f1ddf188cf2f3633c58a9c7141b1e5fa8392",
          "body": "There are some ugly hacks to work around Firefox not supporting `request.body`. Ugh.\n\n(I started out asking Claude to do this but it actually failed in a bunch of ways and I ended up rewriting most of it.)",
          "is_bot": false,
          "headline": "Implement support for serializing Headers, Request, and Response. (#135)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2026-02-18T21:27:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b42835387ba6053d70351a2bea6bb5dc3e6ec5c8",
          "body": "* docs: add info about transport/framing to protocol.md\n\n* Apply suggestions from code review\n\n---------\n\nCo-authored-by: Kenton Varda <kenton@cloudflare.com>",
          "is_bot": false,
          "headline": "docs: add info about transport/framing to protocol.md (#137)",
          "author_name": "Zachary Dremann",
          "author_login": "Dr-Emann",
          "committed_at": "2026-02-18T21:18:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c2bb17b940b23eb8ab89be1e85538493cb4552ad",
          "body": "…ith automatic flow control. (#132)\n\n* Refactor: RpcPayload.stubs -> hooks\n\nInstead of storing an array of RpcStub, we now store an array of the underlying StubHooks.\n\nThis will make it easier to add support for new types like streams, which aren't RpcStubs, but they will wrap / be wrapped in StubHo\n[…]\npletes. This makes sense and solves the case seen in the tests.\n2. I also just made it skip the cancel() call if the stream is locked. Throwing the exception and ignoring it is just a waste of cycles.",
          "is_bot": false,
          "headline": "Add support for sending ReadableStream and WritableStream over RPC, w…",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2026-02-13T01:42:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e3fa09394c0c50c0901c98782936f4ef3df963fc",
          "body": "* Update dependencies.\n\n* Test proxying an RPC stub all the way to Durable Objects.\n\nIn particular, the DO keeps a dup() of the stub and uses it later, after the original subscription call has returned. This requires the `rpc_params_dup_stubs` compat flag, which became default as of 2026-01-20, hence the compat flag update.\n\nFixes #110.",
          "is_bot": false,
          "headline": "Test proxying an RPC stub all the way to Durable Objects. (#122)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2026-02-05T22:40:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10abaf35dbf4de32ad1d91d4c3482dcba72f3e30",
          "body": "Use key remapping to filter out symbol keys instead of mapping to never.\nFixes Disposable compatibility issue with RPC types.\n\nRef: cloudflare/workerd#5804",
          "is_bot": false,
          "headline": "fix(types): filter symbol keys in RpcCompatible mapped type (#129)",
          "author_name": "Dillon Mulroy",
          "author_login": "dmmulroy",
          "committed_at": "2026-01-21T17:52:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a64e42529987d4ace65ed752bcca5ff074b9b63d",
          "body": "* updates dependencies\n\n* adds a tsconfig to fix type error\nExecutionContext was missing in worker.ts.  it's actually unused, but I was thinking that it was probably here (since this is an example) to show it, so instead of deleting it to remove the type error I fixed the problem by adding a tsconfi\n[…]\nale both)\n\n* comparison bar\nin the summary, it would be nice to have a side-by-side horizontal histogram\n\n* spell out initialism\n\n---------\n\nCo-authored-by: dimitropoulos <dmitropoulos@cloudflare.com>",
          "is_bot": false,
          "headline": "refresh `worker-react` example (#127)",
          "author_name": "Dimitri Mitropoulos",
          "author_login": "dimitropoulos",
          "committed_at": "2026-01-12T16:41:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "34ce42c915737374e5d8c760fe157e4ec6fd18e8",
          "body": null,
          "is_bot": false,
          "headline": "fix type error in tests stub (#124)",
          "author_name": "Dimitri Mitropoulos",
          "author_login": "dimitropoulos",
          "committed_at": "2026-01-05T18:17:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "db952ec5aefe49f4235e83f064d6f37d013262ef",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Version Packages (#123)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2025-12-24T14:57:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32e362fd1ee465d3adfe810ba135bbea224ce32b",
          "body": "This matches behavior introduced in workerd in: https://github.com/cloudflare/workerd/pull/5733\n\nThis plus the workerd change together should allow full end-to-end proxying between Cap'n Web and native workerd RPC to work correctly (provided workerd has enabled the `rpc_params_dup_stubs` compat flag, at least).",
          "is_bot": false,
          "headline": "If an RpcTarget passed in params has a dup() method, use it. (#121)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-12-23T17:11:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "76fdff109d561b66025ee693920a34b23e74f317",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Version Packages (#109)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2025-12-16T21:33:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c87560efe1b042f133e978f7a60ecd52f69a549",
          "body": "* Mention @hono/capnweb in readme.\n\nFixes #60\n\n* Support serializing async functions.\n\nThere's a hidden `AsyncFunction` type which they implement.\n\nFixes #115.\n\n* Update dependencies.\n\n... Except for playwright because Firefox starts giving opaque NetworkErrors on some tests that connect to localhost and I don't want to debug it right now.",
          "is_bot": false,
          "headline": "Three small updates, in particular fixing async functions (#120)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-12-16T21:29:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "89a706f1a1c484eb199f09b01688a30433d7a441",
          "body": "* fix(worker-react): jsrpc -> capnweb\n\n* fix(worker-react): import server type\n\n* fix: last remnants of jsrpc",
          "is_bot": false,
          "headline": "fix(worker-react): jsrpc -> capnweb (#35)",
          "author_name": "Aries",
          "author_login": "ariesclark",
          "committed_at": "2025-12-16T20:40:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d21e4cacfa1305e271e89657f8167bc688ade438",
          "body": "* Enhance Stubify and Unstubify for tuple types\nfixes #116\n\n* Add changeset for \"Enhance Stubify and Unstubify for tuple types\"",
          "is_bot": false,
          "headline": "Enhance Stubify and Unstubify for tuple types (#117)",
          "author_name": "Neko Hz",
          "author_login": "codehz",
          "committed_at": "2025-12-16T20:36:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a470458dd152a66d473be638626f668f8be47d9",
          "body": "* Changes the name of the type `Serializable` to the more correct\n`RpcCompatible` and exports it.\n\nThis is needed to aide integration with other libraries. For instance,\nif you want to make a generic function that will make use of an RpcStub,\nyou will need to declare a constraint of `RpcCompatible<T\n[…]\ncopy the entire type definition and declare it\nlocally, which works, but this is much simpler.\n\n* Add changeset for `RpcCompatible<T>`.\n\n---------\n\nCo-authored-by: Kenton Varda <kenton@cloudflare.com>",
          "is_bot": false,
          "headline": "Export the `Serializable` type from the package. (#78)",
          "author_name": "Ian Taylor",
          "author_login": "itaylor",
          "committed_at": "2025-11-06T15:19:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "85fde1b90f25956ac0a820fa3e5be41a321fc34f",
          "body": null,
          "is_bot": false,
          "headline": "Add explicit build step to release workflow (#108)",
          "author_name": "Sunil Pai",
          "author_login": "threepointone",
          "committed_at": "2025-11-05T14:45:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6d805d4b6c60fa3e182bcbc7ce169b428cb92d7a",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Version Packages (#104)",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2025-11-05T14:28:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa4fe305f8037219bce822f9e9095303ff374c4f",
          "body": "- generate both ESM and CommonJS outputs and adjust package exports\n- upgraded some devDependencies\n- removeds the sample changeset I'd added\n- update workflow to not explicitly call build (since we do that with prepublish anyway)",
          "is_bot": false,
          "headline": "Add CommonJS build output and update dependencies (#107)",
          "author_name": "Sunil Pai",
          "author_login": "threepointone",
          "committed_at": "2025-11-05T14:15:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6e38f80505f5024e20d9eead0b0a45d8d0688b76",
          "body": "Sorry, the lawyers insist.\n\n(This is the same bot we use on the workerd repo.)",
          "is_bot": false,
          "headline": "Add CLA signature enforcement bot. (#106)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-11-05T14:14:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f4275f5531472003fa8264e6434929c03eb54448",
          "body": "* Add changeset for past PR #82.\n\n* Throw an error when attempting to access RpcTarget instance properties.\n\nThis helps people learn why instance properties are not accessible over RPC, whereas returning `undefined` leaves them confused.\n\nFixes #55\n\n* Implement toString() for RpcStub and RpcPromise.\n[…]\n, so I didn't want to install it.\n\nMight help with #91, though I won't declare that one \"fixed\" until we actually have tests proving it.\n\n* Document missing expression types in protocol.md.\n\nFixes #48",
          "is_bot": false,
          "headline": "Grab bag of issue fixes! (#105)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-11-05T14:12:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b2fcb34ba17f2d9e979fa9d3ac3e12a61c384870",
          "body": null,
          "is_bot": false,
          "headline": "Release automation take 4. (#103)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-11-04T20:21:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "99ecb6ba6b12580e7de168e2ed591d050a3811db",
          "body": "* Fix changeset version command, attempt 2.\n\nSince this isn't parsed by a shell, the quotes don't work. 🤦\n\n* Add missing version-script.ts file.\n\nThis was referenced from the prerelease job but didn't make it into the original PR.",
          "is_bot": false,
          "headline": "Release automation, take 3. (#102)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-11-04T20:12:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46180b9922ef447d721e2ebe1661d2a4e2fa996f",
          "body": "Apparently it's not run through a shell by default, so my `&&` was misinterpreted.",
          "is_bot": false,
          "headline": "Fix changeset version command. (#101)",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-11-04T19:49:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "032de6b17d86098619d5e09e5ec4895aaa031d97",
          "body": "This sets up some stuff for release automation, built around github actions, changesets, and pkg.pr.new. \n- pkg-pr-new.yml: For every pull request, we publish a version to their registry, and a comment will popup in the PR comments showing how to use it (eg: https://github.com/cloudflare/workers-oau\n[…]\ncluded (or if they're not). This will also have a link to generate and add a changeset to the PR directly (example https://github.com/cloudflare/workers-oauth-provider/pull/99#issuecomment-3454786218)",
          "is_bot": false,
          "headline": "setup some release stuff (#100)",
          "author_name": "Sunil Pai",
          "author_login": "threepointone",
          "committed_at": "2025-11-04T19:34:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6404359e08c432ad6253ae0d886a013106c449f1",
          "body": null,
          "is_bot": false,
          "headline": "Update package-lock.json",
          "author_name": "Sunil Pai",
          "author_login": "threepointone",
          "committed_at": "2025-11-03T15:31:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0547ce1b85a55ccd5f2223ff8566139217510bfd",
          "body": "…es/worker-react/web/vite-7.1.11\n\nBump vite from 7.1.6 to 7.1.11 in /examples/worker-react/web",
          "is_bot": false,
          "headline": "Merge pull request #95 from cloudflare/dependabot/npm_and_yarn/exampl…",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-10-30T19:39:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4b5027580ca53d1c84bcca70e57793d7f02e6e2b",
          "body": "…ight-1.56.1\n\nBump playwright from 1.55.0 to 1.56.1",
          "is_bot": false,
          "headline": "Merge pull request #88 from cloudflare/dependabot/npm_and_yarn/playwr…",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-10-30T19:39:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ead4f337e4dd614d7f5835f60aad28d42b7811e2",
          "body": "Bumps [playwright](https://github.com/microsoft/playwright) from 1.55.0 to 1.56.1.\n- [Release notes](https://github.com/microsoft/playwright/releases)\n- [Commits](https://github.com/microsoft/playwright/compare/v1.55.0...v1.56.1)\n\n---\nupdated-dependencies:\n- dependency-name: playwright\n  dependency-version: 1.56.1\n  dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump playwright from 1.55.0 to 1.56.1",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-10-30T19:19:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4bba0cfe732cdff294ec32170c3ea8581a5a1e3c",
          "body": "Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 7.1.6 to 7.1.11.\n- [Release notes](https://github.com/vitejs/vite/releases)\n- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)\n- [Commits](https://github.com/vitejs/vite/commits/v7.1.11/packages/vite)\n\n---\nupdated-dependencies:\n- dependency-name: vite\n  dependency-version: 7.1.11\n  dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump vite from 7.1.6 to 7.1.11 in /examples/worker-react/web",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-10-30T19:17:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9680ba09da0b627138872df294ece69b970c2761",
          "body": "….1.11\n\nBump vite from 7.1.5 to 7.1.11",
          "is_bot": false,
          "headline": "Merge pull request #89 from cloudflare/dependabot/npm_and_yarn/vite-7…",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-10-30T19:16:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fcc4e8c8e56b0f493474ed1eaad46e27c988946d",
          "body": "Spelling",
          "is_bot": false,
          "headline": "Merge pull request #75 from jsoref/spelling",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-10-30T15:31:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7e8cd97ae76100173716e470234148c23b2b8ad2",
          "body": "Fixes for protocol definition",
          "is_bot": false,
          "headline": "Merge pull request #74 from Dr-Emann/push-pwsnvsymkmzx",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-10-30T15:25:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4b1018a5ffa885117d854b078e9b67b9ef1d3a24",
          "body": "Fix types in React example",
          "is_bot": false,
          "headline": "Merge pull request #22 from third774/fix-types-in-react-example",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-10-30T15:16:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c499a1e5c9c577ab49fe2f1b57e118441c73caf",
          "body": "Try a different approach to importing \"cloudflare:workers\".",
          "is_bot": false,
          "headline": "Merge pull request #82 from cloudflare/kenton/fix-bundlers",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-10-30T14:22:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2bb855ecb098a3d422d13ae899a2894104e00d2f",
          "body": "Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 7.1.5 to 7.1.11.\n- [Release notes](https://github.com/vitejs/vite/releases)\n- [Changelog](https://github.com/vitejs/vite/blob/main/packages/vite/CHANGELOG.md)\n- [Commits](https://github.com/vitejs/vite/commits/v7.1.11/packages/vite)\n\n---\nupdated-dependencies:\n- dependency-name: vite\n  dependency-version: 7.1.11\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>",
          "is_bot": true,
          "headline": "Bump vite from 7.1.5 to 7.1.11",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2025-10-20T23:55:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f540551c3405654087176bbb5f20575002052f2",
          "body": "Fixes #23\n\nPer #23, many bundlers do not like our dynamic import of \"cloudflare:workers\". This PR takes a different approach, using the \"exports\" feature of \"package.json\" to point workerd at a different version of the code. That version imports \"cloudflare:workers\" and sticks it in the global scope before importing the rest of the library, thus allowing it to conditionally probe.",
          "is_bot": false,
          "headline": "Try a different approach to importing \"cloudflare:workers\".",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-10-11T20:57:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c3409357b1c84dd515b4e739786addbdd135c244",
          "body": "This fixes two syntactical errors in code examples in the main README.md",
          "is_bot": false,
          "headline": "docs: Fix syntax errors (#79)",
          "author_name": "Timo Stamm",
          "author_login": "timostamm",
          "committed_at": "2025-10-10T19:26:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57143f5f2dccd765b776fa3609083558c3a16a55",
          "body": "Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>",
          "is_bot": false,
          "headline": "spelling: the",
          "author_name": "Josh Soref",
          "author_login": "jsoref",
          "committed_at": "2025-10-08T03:30:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0b1877fdf121a9baa9c5872d23728828b33fce1b",
          "body": "Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>",
          "is_bot": false,
          "headline": "spelling: service",
          "author_name": "Josh Soref",
          "author_login": "jsoref",
          "committed_at": "2025-10-08T03:30:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "adee13ab1b823391923eea825c717c648852c8f5",
          "body": "Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>",
          "is_bot": false,
          "headline": "spelling: nonexistent",
          "author_name": "Josh Soref",
          "author_login": "jsoref",
          "committed_at": "2025-10-08T03:30:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "655484e27d948f59bcd83cdd9b5edca2bd151d96",
          "body": "Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>",
          "is_bot": false,
          "headline": "spelling: brokenness",
          "author_name": "Josh Soref",
          "author_login": "jsoref",
          "committed_at": "2025-10-08T02:06:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6993e69e316acaef56d30916234e6ea82abc842c",
          "body": "callArguments is an array of expressions, not an expression that evaluates to an array",
          "is_bot": false,
          "headline": "docs: fix protocol docs type of callArguments",
          "author_name": "Zachary Dremann",
          "author_login": "Dr-Emann",
          "committed_at": "2025-10-07T22:24:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9ad1b15947af320c3ae6d61b009a78da05a486c5",
          "body": null,
          "is_bot": false,
          "headline": "docs: fix protocol docs description of array escaping",
          "author_name": "Zachary Dremann",
          "author_login": "Dr-Emann",
          "committed_at": "2025-10-07T22:24:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7c4207a4830c5cb50d1c1590cfd4fa22cf50b129",
          "body": null,
          "is_bot": false,
          "headline": "docs: add deno server example to the README (#57)",
          "author_name": "Bedis Nbiba",
          "author_login": "sigmaSd",
          "committed_at": "2025-09-27T01:11:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5397427cd046994b62b15be0978a363cadca2dfe",
          "body": "docs: fix typo",
          "is_bot": false,
          "headline": "Merge pull request #49 from fukouda/main",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-09-25T23:30:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0dc4cbff7c9de85284fdce38b6d64161eef00bd3",
          "body": null,
          "is_bot": false,
          "headline": "docs: fix typo",
          "author_name": "nas",
          "author_login": "fukouda",
          "committed_at": "2025-09-24T23:56:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "051358482556d577651ec8e893f4d4f007196851",
          "body": "chore: fix typos",
          "is_bot": false,
          "headline": "Merge pull request #25 from dynamic-calm/fix-typos",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-09-24T13:53:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e1459279278226bae4eb021af7cd68c4ae78a1d0",
          "body": "spelling: typo in the README.md's example code",
          "is_bot": false,
          "headline": "Merge pull request #46 from sifatulrabbi/patch-1",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-09-24T12:55:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96495fd809814967a820974eaa98749acf8d72de",
          "body": "The example code of the `### HTTP server on Node.js` section has a typo in the import statement of capnweb.\r\n\r\n- Current: `capnpweb`\r\n- Correct spelling `capnweb`",
          "is_bot": false,
          "headline": "The example code has a typo in the imports",
          "author_name": "Sifatul Rabbi",
          "author_login": "sifatulrabbi",
          "committed_at": "2025-09-24T12:43:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49c3543e185231a98fef7782977006bcece46dbd",
          "body": "Add missing await in node.js example code",
          "is_bot": false,
          "headline": "Merge pull request #37 from cloudflare/kenton/missing-await",
          "author_name": "Kenton Varda",
          "author_login": "kentonv",
          "committed_at": "2025-09-23T15:53:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 1,
      "commits_last_year": 175,
      "latest_release_at": "2026-06-10T19:56:22Z",
      "latest_release_tag": "v0.8.0-websocket.1",
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 33,
      "days_since_latest_release": 41,
      "mean_days_between_releases": null
    },
    "community": {
      "has_readme": false,
      "has_license": false,
      "has_description": false,
      "has_contributing": false,
      "health_percentage": null,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@iterate-com/capnweb",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@iterate-com/capnweb",
          "is_deprecated": false,
          "latest_version": "0.10.0",
          "repository_url": "https://github.com/iterate/capnweb",
          "versions_count": 2,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 4,
          "monthly_downloads": 69259,
          "first_published_at": "2026-07-17T12:44:46.116000Z",
          "latest_published_at": "2026-07-17T13:33:35.282000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "__tests__/tsconfig.json",
        "__type-tests__/tsconfig.json",
        "examples/worker-react/client/tsconfig.json",
        "examples/worker-react/server/tsconfig.json",
        "packages/capnweb-validate/tsconfig.json",
        "tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 130907,
      "source_files_sampled": 97,
      "oversized_source_files": 2,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 4,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 1
      },
      "bus_factor": 1,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "kentonv",
          "commits": 113,
          "avatar_url": "https://avatars.githubusercontent.com/u/4001805?v=4"
        },
        {
          "type": "User",
          "login": "teamchong",
          "commits": 12,
          "avatar_url": "https://avatars.githubusercontent.com/u/25894545?v=4"
        },
        {
          "type": "User",
          "login": "jonastemplestein",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/242550?v=4"
        },
        {
          "type": "User",
          "login": "jsoref",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/2119212?v=4"
        },
        {
          "type": "User",
          "login": "ndisidore",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/1103087?v=4"
        },
        {
          "type": "User",
          "login": "threepointone",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/18808?v=4"
        },
        {
          "type": "User",
          "login": "Dr-Emann",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/1153779?v=4"
        },
        {
          "type": "User",
          "login": "dynamic-calm",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/96750403?v=4"
        },
        {
          "type": "User",
          "login": "VastBlast",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/48421698?v=4"
        },
        {
          "type": "User",
          "login": "dimitropoulos",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/15232461?v=4"
        }
      ],
      "contributors_sampled": 28,
      "top_contributor_share": 0.638
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "pkg-pr-new.yml",
        "release.yml",
        "semgrep.yml",
        "test.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 0,
            "reason": "0 out of 1 merged PRs checked by a CI test -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 5 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 2,
            "reason": "dependency not pinned by hash detected -- score normalized to 2",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 9,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "15 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "6cd9dc89f53ee8420be0c69fe6c5d1be563954f4",
        "ran_at": "2026-07-22T15:32:27Z",
        "aggregate_score": 3.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-18T00:39:26Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-17T13:31:26Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/iterate/capnweb",
    "host": "github.com",
    "name": "capnweb",
    "owner": "iterate"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "at_risk",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 48,
      "inputs": {
        "security": 35,
        "vitality": 77,
        "community": 29,
        "governance": 60,
        "engineering": 29
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 77,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "commits_last_year": 175,
              "human_commit_share": 0.83,
              "days_since_last_push": 5,
              "active_weeks_last_year": 33
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "33/52 weeks with commits",
                "points": 22.8,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 33
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "175 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 175
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "good",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "releases_count": 1,
              "latest_release_tag": "v0.8.0-websocket.1",
              "releases_from_tags": false,
              "days_since_latest_release": 41,
              "mean_days_between_releases": null
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "1 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 41 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 41
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "cadence unknown (single release)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence_unknown",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 29,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": false,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "good",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 81,
            "inputs": {
              "packages": [
                "@iterate-com/capnweb"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 69259
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "69,259 downloads/month across npm",
                "points": 64.5,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 69259,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 60,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 41,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 28,
              "top_contributor_share": 0.638
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 64% of commits",
                "points": 8.1,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 64
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "28 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 28
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 5 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 57,
            "inputs": {
              "merged_prs": 4,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 1
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "4/5 decided PRs merged",
                "points": 30.6,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 4,
                      "decided": 5
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 62,
            "inputs": {
              "followers": 27,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "iterate",
              "public_repos": 20,
              "account_age_days": 5820
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "27 followers of iterate",
                "points": 10.4,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 27,
                      "login": "iterate"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "20 public repos, account ~15 yr old",
                "points": 21.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 20
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 15
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "packages": [
                "@iterate-com/capnweb"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "2 published versions",
                "points": 12,
                "status": "partial",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "critical",
        "name": "Engineering Quality",
        "value": 29,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 48,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "0 out of 1 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "critical",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": null,
              "has_readme": false,
              "has_docs_dir": false,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 35,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 35,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 3.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "0 out of 1 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 5 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 1,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "15 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 11
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 57,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.964,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "80 of 83 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 80,
                      "sampled": 83
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "__tests__/tsconfig.json",
                "__type-tests__/tsconfig.json",
                "examples/worker-react/client/tsconfig.json",
                "examples/worker-react/server/tsconfig.json",
                "packages/capnweb-validate/tsconfig.json",
                "tsconfig.json"
              ],
              "agent_commit_share": 0.04,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.03
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "__tests__/tsconfig.json, __type-tests__/tsconfig.json, examples/worker-react/client/tsconfig.json, examples/worker-react/server/tsconfig.json, packages/capnweb-validate/tsconfig.json, tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "__tests__/tsconfig.json, __type-tests__/tsconfig.json, examples/worker-react/client/tsconfig.json, examples/worker-react/server/tsconfig.json, packages/capnweb-validate/tsconfig.json, tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "4 of the last 100 commits agent-authored or agent-credited",
                "points": 8,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 4,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "3 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 3,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 2",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 99,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 130907,
              "source_files_sampled": 97,
              "oversized_source_files": 2
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "2/97 source files over 60KB",
                "points": 53.9,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 97,
                      "oversized": 2
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Community profile unavailable",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index npm:@iterate-com/capnweb@0.10.0; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T15:32:50.393415Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/i/iterate/capnweb.svg",
  "full_name": "iterate/capnweb",
  "license_state": "standard",
  "license_spdx": "MIT"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.26.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计npm.