公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-27 16:54 UTC

joinmeow / amazon-cognito-passwordless-auth

Passwordless authentication with Amazon Cognito: FIDO2 (WebAuthn, support for Passkeys), Totp MFA, Totp and Passkey Step Up

TypeScriptApache-2.0★ 0 星标⑂ 0 复刻始于 2025年4月复刻在 GitHub 上查看 ↗

joinmeow/amazon-cognito-passwordless-auth 的健康指数为 100 分中的 59 分,处于「中等」区间。 其得分最高的类别是Vitality(83/100),最低的是Community & Adoption(26/100)。 最近一次更新在 4 天前。 近期的大部分工作由 2 位贡献者完成。

59
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

59
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

Meow组织
4 关注者4 个公开仓库始于 2021年2月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布标签
npm@joinmeow/cognito-passwordless-auth1.0.1048,7131006 天前awscognitofido2passwordlesswebauthnpasskeys

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

83良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 4 天前
7.6/36提交节奏 — 52 周中有 11 周有提交
17.9/18提交量 — 最近一年 97 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year97
human_commit_share0.95
days_since_last_push4
active_weeks_last_year11

发布纪律

100优秀
评分方式
27/27有发布版本 — 已发布 96 个发布版本
36/36发布时效 — 最近一次发布版本于 6 天前
27/27发布节奏 — 约每 32 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count96
latest_release_tagv1.0.104
releases_from_tags
days_since_latest_release6
mean_days_between_releases32
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

26危急 · 占总体的 18%
评分方式
0/60星标 — 0 个星标
0/25复刻 — 0 个复刻
0/15关注者 — 0 位关注者
所用输入
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

25危急
评分方式
0/22.5README
22.5/22.5许可证 — 可识别的许可证(Apache-2.0)
0/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
52.5/80月度下载量 — npm 合计每月 8,713 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packages@joinmeow/cognito-passwordless-auth
dependents
ecosystemsnpm
total_downloads
monthly_downloads8,713
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

68中等 · 占总体的 24%
评分方式
25.2/54巴士系数 — 2 位贡献者贡献了半数提交
12.4/22.5提交分布 — 头号贡献者编写了 45% 的提交
13.5/13.5贡献者广度 — 20 位贡献者
10/10OpenSSF Scorecard:Contributors — project has 3 contributing companies or organizations -- score normalized to 10
所用输入
bus_factor2
contributors_sampled20
top_contributor_share0.448
评分方式
0/46.8议题解决 — 没有议题或无数据
36.5/38.3PR 接受 — 已裁定的 PR 中 105/110 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/29 approved changesets -- score normalized to 0
所用输入
merged_prs105
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs5
已排除计分(无数据或不适用):议题解决。 其余权重已重新归一化。
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
5/25所有者影响力 — joinmeow 有 4 位关注者
16/25既往记录 — 4 个公开仓库,账户约 5 年
所用输入
followers4
owner_typeOrganization
is_verified
owner_loginjoinmeow
public_repos4
account_age_days2,000
评分方式
25/25已发布且可解析 — npm 上有 1 个软件包
35/35发布时效 — 最近一次发布于 6 天前
20/20版本历史 — 100 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packages@joinmeow/cognito-passwordless-auth
ecosystemsnpm
any_deprecated
min_days_since_publish6

工程质量

基础的工程与文档实践是否到位?

53中等 · 占总体的 20%

工程实践

82良好
评分方式
24/24CI 工作流 — 2 个工作流
24/24存在测试
16/16Linter 配置 — .eslintrc.cjs
0/9.6Pre-commit 钩子
0/6.4.editorconfig
18/20OpenSSF Scorecard:CI-Tests — 24 out of 25 merged PRs checked by a CI test -- score normalized to 9
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

10危急
评分方式
0/30README
0/25文档目录
0/15文档 / 主页站点
0/10仓库描述
0/10主题标签
10/10Wiki
所用输入
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

55中等 · 占总体的 16%

安全态势

44存在风险
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.2/2.5CI-Tests — 24 out of 25 merged PRs checked by a CI test -- score normalized to 9
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/29 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 3 contributing companies or organizations -- score normalized to 10
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — 无数据
1.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 3
5/5SAST — SAST tool is run on all commits
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — 无数据
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 12 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate4.4
已排除计分(无数据或不适用):packaging, signed_releases。 其余权重已重新归一化。
评分方式
35/35直接依赖不含已知公告 — 没有直接依赖携带已知公告
25/25间接依赖不含已知公告 — 没有间接依赖携带已知公告
0/40没有长期未处理的公告 — 没有公告带有发布日期
所用输入
sourceosv
advisories0
affected_packages0
assessed_packages3
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
已排除计分(无数据或不适用):没有长期未处理的公告。 其余权重已重新归一化。 比对的是 npm:@joinmeow/cognito-passwordless-auth@1.0.104 的运行时依赖闭包——安装已发布的软件包时真正被拉取进来的内容——共 3 个软件包。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

64中等 · 占总体的 0%
评分方式
0/45代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 95 次人类提交中有 76 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.8
agent_instruction_files
agent_instruction_max_bytes
评分方式
0/18一条命令的引导启动
22/22自动化测试
11/11Lint / 格式化配置 — .eslintrc.cjs
11/11静态类型检查 — client/tsconfig.json
10/10可复现环境 — lockfile
4/10已体现的代理实践 — 最近 100 次提交中有 2 次由代理编写或署名代理
8/8自动化维护 — 最近 100 次提交中有 5 次为自动依赖更新
3/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 3
所用输入
has_nix
has_tests
lockfilespackage-lock.json
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configsclient/tsconfig.json
agent_commit_share0.02
toolchain_manifests
dependency_bot_commit_share0.05
评分方式
45/45可类型检查的代码 — TypeScript(静态类型)
53.2/55可控的文件大小 — 采样的 92 个源文件中有 3 个超过 60KB
所用输入
primary_languageTypeScript
largest_source_bytes96,149
source_files_sampled92
oversized_source_files3

关键数据

0GitHub 星标
20贡献者
97最近 12 个月提交数
4距最近推送天数
96发布版本数
2巴士系数(bus factor)
0开放议题
npm软件包生态系统数

数据采集警告

  • Community profile unavailable

更多细节

OpenSSF Scorecard 4.4 / 10
4.4综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-27 16:53 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
9CI-Tests24 out of 25 merged PRs checked by a CI test -- score normalized to 9
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/29 approved changesets -- score normalized to 0
10Contributorsproject has 3 contributing companies or organizations -- score normalized to 10
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
不适用Packagingpackaging workflow not detected
3Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 3
10SASTSAST tool is run on all commits
0Security-Policysecurity policy file not detected
不适用Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities12 existing vulnerabilities detected
直接依赖 2
注册表软件包版本约束清单文件
npmaws-jwt-verify^4.0.1package.json
npmcbor^9.0.2package.json
全部依赖 619

来自 GitHub 依赖图的完整解析依赖集合:2 个直接依赖与 617 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
npmaws-jwt-verify4.0.1直接
npmcbor9.0.2直接
npm@ampproject/remapping2.3.0间接
npm@asamuzakjp/css-color3.2.0间接
npm@babel/code-frame7.27.1间接
npm@babel/compat-data7.27.3间接
npm@babel/core7.27.3间接
npm@babel/generator7.27.3间接
npm@babel/helper-compilation-targets7.27.2间接
npm@babel/helper-module-imports7.27.1间接
npm@babel/helper-module-transforms7.27.3间接
npm@babel/helper-plugin-utils7.27.1间接
npm@babel/helper-string-parser7.27.1间接
npm@babel/helper-validator-identifier7.27.1间接
npm@babel/helper-validator-option7.27.1间接
npm@babel/helpers7.27.3间接
npm@babel/parser7.27.3间接
npm@babel/plugin-syntax-async-generators7.8.4间接
npm@babel/plugin-syntax-bigint7.8.3间接
npm@babel/plugin-syntax-class-properties7.12.13间接
npm@babel/plugin-syntax-class-static-block7.14.5间接
npm@babel/plugin-syntax-import-attributes7.27.1间接
npm@babel/plugin-syntax-import-meta7.10.4间接
npm@babel/plugin-syntax-json-strings7.8.3间接
npm@babel/plugin-syntax-jsx7.27.1间接
npm@babel/plugin-syntax-logical-assignment-operators7.10.4间接
npm@babel/plugin-syntax-nullish-coalescing-operator7.8.3间接
npm@babel/plugin-syntax-numeric-separator7.10.4间接
npm@babel/plugin-syntax-object-rest-spread7.8.3间接
npm@babel/plugin-syntax-optional-catch-binding7.8.3间接
npm@babel/plugin-syntax-optional-chaining7.8.3间接
npm@babel/plugin-syntax-private-property-in-object7.14.5间接
npm@babel/plugin-syntax-top-level-await7.14.5间接
npm@babel/plugin-syntax-typescript7.27.1间接
npm@babel/runtime7.27.6间接
npm@babel/template7.27.2间接
npm@babel/traverse7.27.3间接
npm@babel/types7.27.3间接
npm@bcoe/v8-coverage0.2.3间接
npm@cspotcode/source-map-support0.8.1间接
npm@csstools/color-helpers5.0.2间接
npm@csstools/css-calc2.1.4间接
npm@csstools/css-color-parser3.0.10间接
npm@csstools/css-parser-algorithms3.0.5间接
npm@csstools/css-tokenizer3.0.4间接
npm@esbuild/aix-ppc640.28.1间接
npm@esbuild/android-arm0.28.1间接
npm@esbuild/android-arm640.28.1间接
npm@esbuild/android-x640.28.1间接
npm@esbuild/darwin-arm640.28.1间接
npm@esbuild/darwin-x640.28.1间接
npm@esbuild/freebsd-arm640.28.1间接
npm@esbuild/freebsd-x640.28.1间接
npm@esbuild/linux-arm0.28.1间接
npm@esbuild/linux-arm640.28.1间接
npm@esbuild/linux-ia320.28.1间接
npm@esbuild/linux-loong640.28.1间接
npm@esbuild/linux-mips64el0.28.1间接
npm@esbuild/linux-ppc640.28.1间接
npm@esbuild/linux-riscv640.28.1间接
npm@esbuild/linux-s390x0.28.1间接
npm@esbuild/linux-x640.28.1间接
npm@esbuild/netbsd-arm640.28.1间接
npm@esbuild/netbsd-x640.28.1间接
npm@esbuild/openbsd-arm640.28.1间接
npm@esbuild/openbsd-x640.28.1间接
npm@esbuild/openharmony-arm640.28.1间接
npm@esbuild/sunos-x640.28.1间接
npm@esbuild/win32-arm640.28.1间接
npm@esbuild/win32-ia320.28.1间接
npm@esbuild/win32-x640.28.1间接
npm@eslint-community/eslint-utils4.4.0间接
npm@eslint-community/regexpp4.10.1间接
npm@eslint/eslintrc2.1.4间接
npm@eslint/js8.57.0间接
npm@humanwhocodes/config-array0.11.14间接
npm@humanwhocodes/module-importer1.0.1间接
npm@humanwhocodes/object-schema2.0.3间接
npm@istanbuljs/load-nyc-config1.1.0间接
npm@istanbuljs/schema0.1.3间接
npm@jest/console29.7.0间接
npm@jest/core29.7.0间接
npm@jest/environment29.7.0间接
npm@jest/environment30.0.0-beta.3间接
npm@jest/environment-jsdom-abstract30.0.0-beta.3间接
npm@jest/expect29.7.0间接
npm@jest/expect-utils29.7.0间接
npm@jest/fake-timers29.7.0间接
npm@jest/fake-timers30.0.0-beta.3间接
npm@jest/globals29.7.0间接
npm@jest/pattern30.0.0-beta.3间接
npm@jest/reporters29.7.0间接
npm@jest/schemas29.6.3间接
npm@jest/schemas30.0.0-beta.3间接
npm@jest/source-map29.6.3间接
npm@jest/test-result29.7.0间接
npm@jest/test-sequencer29.7.0间接
npm@jest/transform29.7.0间接
npm@jest/types29.6.3间接
npm@jest/types30.0.0-beta.3间接
npm@jridgewell/gen-mapping0.3.8间接
npm@jridgewell/resolve-uri3.1.2间接
npm@jridgewell/set-array1.2.1间接
npm@jridgewell/sourcemap-codec1.4.15间接
npm@jridgewell/trace-mapping0.3.25间接
npm@jridgewell/trace-mapping0.3.9间接
npm@nodelib/fs.scandir2.1.5间接
npm@nodelib/fs.stat2.0.5间接
npm@nodelib/fs.walk1.2.8间接
npm@sinclair/typebox0.27.8间接
npm@sinclair/typebox0.34.33间接
npm@sinonjs/commons3.0.1间接
npm@sinonjs/fake-timers10.3.0间接
npm@sinonjs/fake-timers13.0.5间接
npm@testing-library/dom10.4.0间接
npm@testing-library/react16.3.0间接
npm@tsconfig/node101.0.11间接
npm@tsconfig/node121.0.11间接
npm@tsconfig/node141.0.3间接
npm@tsconfig/node161.0.4间接
npm@types/aria-query5.0.4间接
npm@types/babel__core7.20.5间接
npm@types/babel__generator7.27.0间接
npm@types/babel__template7.4.4间接
npm@types/babel__traverse7.20.7间接
npm@types/graceful-fs4.1.9间接
npm@types/istanbul-lib-coverage2.0.6间接
npm@types/istanbul-lib-report3.0.3间接
npm@types/istanbul-reports3.0.4间接
npm@types/jest29.5.14间接
npm@types/jsdom21.1.7间接
npm@types/json50.0.29间接
npm@types/node20.14.5间接
npm@types/prop-types15.7.12间接
npm@types/react18.3.3间接
npm@types/stack-utils2.0.3间接
npm@types/tough-cookie4.0.5间接
npm@types/yargs17.0.33间接
npm@types/yargs-parser21.0.3间接
npm@typescript-eslint/eslint-plugin7.13.1间接
npm@typescript-eslint/parser7.13.1间接
npm@typescript-eslint/scope-manager7.13.1间接
npm@typescript-eslint/type-utils7.13.1间接
npm@typescript-eslint/types7.13.1间接
npm@typescript-eslint/typescript-estree7.13.1间接
npm@typescript-eslint/utils7.13.1间接
npm@typescript-eslint/visitor-keys7.13.1间接
npm@ungap/structured-clone1.2.0间接
npmacorn8.12.0间接
npmacorn-jsx5.3.2间接
npmacorn-walk8.3.3间接
npmagent-base7.1.3间接
npmajv6.12.6间接
npmansi-escapes4.3.2间接
npmansi-escapes7.0.0间接
npmansi-regex5.0.1间接
npmansi-regex6.1.0间接
npmansi-styles4.3.0间接
npmansi-styles5.2.0间接
npmansi-styles6.2.1间接
npmanymatch3.1.3间接
npmarg4.1.3间接
npmargparse1.0.10间接
npmargparse2.0.1间接
npmaria-query5.3.0间接
npmarray-buffer-byte-length1.0.1间接
npmarray-includes3.1.8间接
npmarray-union2.1.0间接
npmarray.prototype.findlast1.2.5间接
npmarray.prototype.findlastindex1.2.5间接
npmarray.prototype.flat1.3.2间接
npmarray.prototype.flatmap1.3.2间接
npmarray.prototype.toreversed1.1.2间接
npmarray.prototype.tosorted1.1.4间接
npmarraybuffer.prototype.slice1.0.3间接
npmasync3.2.6间接
npmavailable-typed-arrays1.0.7间接
npmbabel-jest29.7.0间接
npmbabel-plugin-istanbul6.1.1间接
npmbabel-plugin-jest-hoist29.6.3间接
npmbabel-preset-current-node-syntax1.1.0间接
npmbabel-preset-jest29.6.3间接
npmbalanced-match1.0.2间接
npmbrace-expansion1.1.11间接
npmbrace-expansion2.1.1间接
npmbraces3.0.3间接
npmbrowserslist4.25.0间接
npmbs-logger0.2.6间接
npmbser2.1.1间接
npmbuffer-from1.1.2间接
npmcall-bind1.0.7间接
npmcallsites3.1.0间接
npmcamelcase5.3.1间接
npmcamelcase6.3.0间接
npmcaniuse-lite1.0.30001720间接
npmchalk4.1.2间接
npmchalk5.4.1间接
npmchar-regex1.0.2间接
npmci-info3.9.0间接
npmci-info4.2.0间接
npmcjs-module-lexer1.4.3间接
npmcli-cursor5.0.0间接
npmcli-truncate4.0.0间接
npmcliui8.0.1间接
npmco4.6.0间接
npmcollect-v8-coverage1.0.2间接
npmcolor-convert2.0.1间接
npmcolor-name1.1.4间接
npmcolorette2.0.20间接
npmcommander14.0.0间接
npmconcat-map0.0.1间接
npmconvert-source-map2.0.0间接
npmcreate-jest29.7.0间接
npmcreate-require1.1.1间接
npmcross-spawn7.0.6间接
npmcssstyle4.3.1间接
npmcsstype3.1.3间接
npmdata-urls5.0.0间接
npmdata-view-buffer1.0.1间接
npmdata-view-byte-length1.0.1间接
npmdata-view-byte-offset1.0.0间接
npmdebug3.2.7间接
npmdebug4.4.1间接
npmdecimal.js10.5.0间接
npmdedent1.6.0间接
npmdeep-is0.1.4间接
npmdeepmerge4.3.1间接
npmdefine-data-property1.1.4间接
npmdefine-properties1.2.1间接
npmdequal2.0.3间接
npmdetect-newline3.1.0间接
npmdiff4.0.2间接
npmdiff-sequences29.6.3间接
npmdir-glob3.0.1间接
npmdoctrine2.1.0间接
npmdoctrine3.0.0间接
npmdom-accessibility-api0.5.16间接
npmejs3.1.10间接
npmelectron-to-chromium1.5.161间接
npmemittery0.13.1间接
npmemoji-regex10.4.0间接
npmemoji-regex8.0.0间接
npmentities6.0.0间接
npmenvironment1.1.0间接
npmerror-ex1.3.2间接
npmes-abstract1.23.3间接
npmes-define-property1.0.0间接
npmes-errors1.3.0间接
npmes-iterator-helpers1.0.19间接
npmes-object-atoms1.0.0间接
npmes-set-tostringtag2.0.3间接
npmes-shim-unscopables1.0.2间接
npmes-to-primitive1.2.1间接
npmesbuild0.28.1间接
npmescalade3.2.0间接
npmescape-string-regexp2.0.0间接
npmescape-string-regexp4.0.0间接
npmeslint8.57.0间接
npmeslint-import-resolver-node0.3.9间接
npmeslint-module-utils2.8.1间接
npmeslint-plugin-header3.1.1间接
npmeslint-plugin-import2.29.1间接
npmeslint-plugin-react7.34.2间接
npmeslint-plugin-react-hooks4.6.2间接
npmeslint-plugin-security3.0.1间接
npmeslint-scope7.2.2间接
npmeslint-visitor-keys3.4.3间接
npmespree9.6.1间接
npmesprima4.0.1间接
npmesquery1.5.0间接
npmesrecurse4.3.0间接
npmestraverse5.3.0间接
npmesutils2.0.3间接
npmeventemitter35.0.1间接
npmexeca5.1.1间接
npmexit0.1.2间接
npmexpect29.7.0间接
npmfast-deep-equal3.1.3间接
npmfast-glob3.3.2间接
npmfast-json-stable-stringify2.1.0间接
npmfast-levenshtein2.0.6间接
npmfastq1.17.1间接
npmfb-watchman2.0.2间接
npmfile-entry-cache6.0.1间接
npmfilelist1.0.4间接
npmfill-range7.1.1间接
npmfind-up4.1.0间接
npmfind-up5.0.0间接
npmflat-cache3.2.0间接
npmflatted3.4.2间接
npmfor-each0.3.3间接
npmfs.realpath1.0.0间接
npmfsevents2.3.3间接
npmfunction-bind1.1.2间接
npmfunction.prototype.name1.1.6间接
npmfunctions-have-names1.2.3间接
npmgensync1.0.0-beta.2间接
npmget-caller-file2.0.5间接
npmget-east-asian-width1.3.0间接
npmget-intrinsic1.2.4间接
npmget-package-type0.1.0间接
npmget-stream6.0.1间接
npmget-symbol-description1.0.2间接
npmglob7.2.3间接
npmglob-parent5.1.2间接
npmglob-parent6.0.2间接
npmglobals11.12.0间接
npmglobals13.24.0间接
npmglobalthis1.0.4间接
npmglobby11.1.0间接
npmgopd1.0.1间接
npmgraceful-fs4.2.11间接
npmgraphemer1.4.0间接
npmhas-bigints1.0.2间接
npmhas-flag4.0.0间接
npmhas-property-descriptors1.0.2间接
npmhas-proto1.0.3间接
npmhas-symbols1.0.3间接
npmhas-tostringtag1.0.2间接
npmhasown2.0.2间接
npmhtml-encoding-sniffer4.0.0间接
npmhtml-escaper2.0.2间接
npmhttp-proxy-agent7.0.2间接
npmhttps-proxy-agent7.0.6间接
npmhuman-signals2.1.0间接
npmhusky9.1.7间接
npmiconv-lite0.6.3间接
npmignore5.3.1间接
npmimport-fresh3.3.0间接
npmimport-local3.2.0间接
npmimurmurhash0.1.4间接
npminflight1.0.6间接
npminherits2.0.4间接
npminternal-slot1.0.7间接
npmis-array-buffer3.0.4间接
npmis-arrayish0.2.1间接
npmis-async-function2.0.0间接
npmis-bigint1.0.4间接
npmis-boolean-object1.1.2间接
npmis-callable1.2.7间接
npmis-core-module2.13.1间接
npmis-data-view1.0.1间接
npmis-date-object1.0.5间接
npmis-extglob2.1.1间接
npmis-finalizationregistry1.0.2间接
npmis-fullwidth-code-point3.0.0间接
npmis-fullwidth-code-point4.0.0间接
npmis-fullwidth-code-point5.0.0间接
npmis-generator-fn2.1.0间接
npmis-generator-function1.0.10间接
npmis-glob4.0.3间接
npmis-map2.0.3间接
npmis-negative-zero2.0.3间接
npmis-number7.0.0间接
npmis-number-object1.0.7间接
npmis-path-inside3.0.3间接
npmis-potential-custom-element-name1.0.1间接
npmis-regex1.1.4间接
npmis-set2.0.3间接
npmis-shared-array-buffer1.0.3间接
npmis-stream2.0.1间接
npmis-string1.0.7间接
npmis-symbol1.0.4间接
npmis-typed-array1.1.13间接
npmis-weakmap2.0.2间接
npmis-weakref1.0.2间接
npmis-weakset2.0.3间接
npmisarray2.0.5间接
npmisexe2.0.0间接
npmistanbul-lib-coverage3.2.2间接
npmistanbul-lib-instrument5.2.1间接
npmistanbul-lib-instrument6.0.3间接
npmistanbul-lib-report3.0.1间接
npmistanbul-lib-source-maps4.0.1间接
npmistanbul-reports3.1.7间接
npmiterator.prototype1.1.2间接
npmjake10.9.2间接
npmjest29.7.0间接
npmjest-changed-files29.7.0间接
npmjest-circus29.7.0间接
npmjest-cli29.7.0间接
npmjest-config29.7.0间接
npmjest-diff29.7.0间接
npmjest-docblock29.7.0间接
npmjest-each29.7.0间接
npmjest-environment-jsdom30.0.0-beta.3间接
npmjest-environment-node29.7.0间接
npmjest-get-type29.6.3间接
npmjest-haste-map29.7.0间接
npmjest-leak-detector29.7.0间接
npmjest-localstorage-mock2.4.26间接
npmjest-matcher-utils29.7.0间接
npmjest-message-util29.7.0间接
npmjest-message-util30.0.0-beta.3间接
npmjest-mock29.7.0间接
npmjest-mock30.0.0-beta.3间接
npmjest-pnp-resolver1.2.3间接
npmjest-regex-util29.6.3间接
npmjest-regex-util30.0.0-beta.3间接
npmjest-resolve29.7.0间接
npmjest-resolve-dependencies29.7.0间接
npmjest-runner29.7.0间接
npmjest-runtime29.7.0间接
npmjest-snapshot29.7.0间接
npmjest-util29.7.0间接
npmjest-util30.0.0-beta.3间接
npmjest-validate29.7.0间接
npmjest-watcher29.7.0间接
npmjest-worker29.7.0间接
npmjs-tokens4.0.0间接
npmjs-yaml3.14.2间接
npmjs-yaml4.1.1间接
npmjsdom26.1.0间接
npmjsesc3.1.0间接
npmjson-buffer3.0.1间接
npmjson-parse-even-better-errors2.3.1间接
npmjson-schema-traverse0.4.1间接
npmjson-stable-stringify-without-jsonify1.0.1间接
npmjson51.0.2间接
npmjson52.2.3间接
npmjsx-ast-utils3.3.5间接
npmkeyv4.5.4间接
npmkleur3.0.3间接
npmleven3.1.0间接
npmlevn0.4.1间接
npmlilconfig3.1.3间接
npmlines-and-columns1.2.4间接
npmlint-staged16.1.2间接
npmlistr28.3.3间接
npmlocate-path5.0.0间接
npmlocate-path6.0.0间接
npmlodash.memoize4.1.2间接
npmlodash.merge4.6.2间接
npmlog-update6.1.0间接
npmloose-envify1.4.0间接
npmlru-cache10.4.3间接
npmlru-cache5.1.1间接
npmlz-string1.5.0间接
npmmake-dir4.0.0间接
npmmake-error1.3.6间接
npmmakeerror1.0.12间接
npmmerge-stream2.0.0间接
npmmerge21.4.1间接
npmmicromatch4.0.8间接
npmmimic-fn2.1.0间接
npmmimic-function5.0.1间接
npmminimatch3.1.5间接
npmminimatch5.1.9间接
npmminimatch9.0.9间接
npmminimist1.2.8间接
npmms2.1.3间接
npmnano-spawn1.0.2间接
npmnatural-compare1.4.0间接
npmnode-int640.4.0间接
npmnode-releases2.0.19间接
npmnofilter3.1.0间接
npmnormalize-path3.0.0间接
npmnpm-run-path4.0.1间接
npmnwsapi2.2.20间接
npmobject-assign4.1.1间接
npmobject-inspect1.13.1间接
npmobject-keys1.1.1间接
npmobject.assign4.1.5间接
npmobject.entries1.1.8间接
npmobject.fromentries2.0.8间接
npmobject.groupby1.0.3间接
npmobject.hasown1.1.4间接
npmobject.values1.2.0间接
npmonce1.4.0间接
npmonetime5.1.2间接
npmonetime7.0.0间接
npmoptionator0.9.4间接
npmp-limit2.3.0间接
npmp-limit3.1.0间接
npmp-locate4.1.0间接
npmp-locate5.0.0间接
npmp-try2.2.0间接
npmparent-module1.0.1间接
npmparse-json5.2.0间接
npmparse57.3.0间接
npmpath-exists4.0.0间接
npmpath-is-absolute1.0.1间接
npmpath-key3.1.1间接
npmpath-parse1.0.7间接
npmpath-type4.0.0间接
npmpicocolors1.1.1间接
npmpicomatch2.3.2间接
npmpicomatch4.0.4间接
npmpidtree0.6.0间接
npmpirates4.0.7间接
npmpkg-dir4.2.0间接
npmpossible-typed-array-names1.0.0间接
npmprelude-ls1.2.1间接
npmprettier3.3.2间接
npmpretty-format27.5.1间接
npmpretty-format29.7.0间接
npmpretty-format30.0.0-beta.3间接
npmprompts2.4.2间接
npmprop-types15.8.1间接
npmpunycode2.3.1间接
npmpure-rand6.1.0间接
npmqueue-microtask1.2.3间接
npmreact18.3.1间接
npmreact-dom18.3.1间接
npmreact-is16.13.1间接
npmreact-is17.0.2间接
npmreact-is18.3.1间接
npmreflect.getprototypeof1.0.6间接
npmregexp-tree0.1.27间接
npmregexp.prototype.flags1.5.2间接
npmrequire-directory2.1.1间接
npmresolve1.22.8间接
npmresolve2.0.0-next.5间接
npmresolve-cwd3.0.0间接
npmresolve-from4.0.0间接
npmresolve-from5.0.0间接
npmresolve.exports2.0.3间接
npmrestore-cursor5.1.0间接
npmreusify1.0.4间接
npmrfdc1.4.1间接
npmrimraf3.0.2间接
npmrrweb-cssom0.8.0间接
npmrun-parallel1.2.0间接
npmsafe-array-concat1.1.2间接
npmsafe-regex2.1.1间接
npmsafe-regex-test1.0.3间接
npmsafer-buffer2.1.2间接
npmsaxes6.0.0间接
npmscheduler0.23.2间接
npmsemver6.3.1间接
npmsemver7.6.2间接
npmsemver7.7.2间接
npmset-function-length1.2.2间接
npmset-function-name2.0.2间接
npmshebang-command2.0.0间接
npmshebang-regex3.0.0间接
npmside-channel1.0.6间接
npmsignal-exit3.0.7间接
npmsignal-exit4.1.0间接
npmsisteransi1.0.5间接
npmslash3.0.0间接
npmslice-ansi5.0.0间接
npmslice-ansi7.1.0间接
npmsource-map0.6.1间接
npmsource-map-support0.5.13间接
npmsprintf-js1.0.3间接
npmstack-utils2.0.6间接
npmstring-argv0.3.2间接
npmstring-length4.0.2间接
npmstring-width4.2.3间接
npmstring-width7.2.0间接
npmstring.prototype.matchall4.0.11间接
npmstring.prototype.trim1.2.9间接
npmstring.prototype.trimend1.0.8间接
npmstring.prototype.trimstart1.0.8间接
npmstrip-ansi6.0.1间接
npmstrip-ansi7.1.0间接
npmstrip-bom3.0.0间接
npmstrip-bom4.0.0间接
npmstrip-final-newline2.0.0间接
npmstrip-json-comments3.1.1间接
npmsupports-color7.2.0间接
npmsupports-color8.1.1间接
npmsupports-preserve-symlinks-flag1.0.0间接
npmsymbol-tree3.2.4间接
npmtest-exclude6.0.0间接
npmtext-table0.2.0间接
npmtldts6.1.86间接
npmtldts-core6.1.86间接
npmtmpl1.0.5间接
npmto-regex-range5.0.1间接
npmtough-cookie5.1.2间接
npmtr465.1.1间接
npmts-api-utils1.3.0间接
npmts-jest29.3.4间接
npmts-node10.9.2间接
npmtsconfig-paths3.15.0间接
npmtype-check0.4.0间接
npmtype-detect4.0.8间接
npmtype-fest0.20.2间接
npmtype-fest0.21.3间接
npmtype-fest4.41.0间接
npmtyped-array-buffer1.0.2间接
npmtyped-array-byte-length1.0.1间接
npmtyped-array-byte-offset1.0.2间接
npmtyped-array-length1.0.6间接
npmtypescript5.4.5间接
npmunbox-primitive1.0.2间接
npmundici-types5.26.5间接
npmupdate-browserslist-db1.1.3间接
npmuri-js4.4.1间接
npmv8-compile-cache-lib3.0.1间接
npmv8-to-istanbul9.3.0间接
npmw3c-xmlserializer5.0.0间接
npmwalker1.0.8间接
npmwebidl-conversions7.0.0间接
npmwhatwg-encoding3.1.1间接
npmwhatwg-mimetype4.0.0间接
npmwhatwg-url14.2.0间接
npmwhich2.0.2间接
npmwhich-boxed-primitive1.0.2间接
npmwhich-builtin-type1.1.3间接
npmwhich-collection1.0.2间接
npmwhich-typed-array1.1.15间接
npmword-wrap1.2.5间接
npmwrap-ansi7.0.0间接
npmwrap-ansi9.0.0间接
npmwrappy1.0.2间接
npmwrite-file-atomic4.0.2间接
npmws8.18.2间接
npmxml-name-validator5.0.0间接
npmxmlchars2.2.0间接
npmy18n5.0.8间接
npmyallist3.1.1间接
npmyaml2.8.0间接
npmyargs17.7.2间接
npmyargs-parser21.1.1间接
npmyn3.1.1间接
npmyocto-queue0.1.0间接
依赖安全公告 0

安装 npm:@joinmeow/cognito-passwordless-auth@1.0.104 会引入 3 个包(直接与传递):其中 0 个存在已知公告,0 个为直接依赖。

没有已知公告影响已评估的依赖。

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": true,
      "size_kb": 23630,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "JavaScript": 4487,
        "TypeScript": 1136056
      },
      "pushed_at": "2026-07-23T16:22:55Z",
      "created_at": "2025-04-22T14:39:53Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-23T16:24:17Z",
      "description": "Passwordless authentication with Amazon Cognito: FIDO2 (WebAuthn, support for Passkeys), Totp MFA,  Totp and Passkey Step Up",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "www.meow.com",
      "name": "Meow",
      "type": "Organization",
      "login": "joinmeow",
      "company": null,
      "location": "United States of America",
      "followers": 4,
      "avatar_url": "https://avatars.githubusercontent.com/u/78460202?v=4",
      "created_at": "2021-02-03T03:32:11Z",
      "is_verified": null,
      "public_repos": 4,
      "account_age_days": 2000
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": false
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.0.104",
          "kind": "patch",
          "published_at": "2026-07-20T22:36:18Z"
        },
        {
          "tag": "v1.0.103",
          "kind": "patch",
          "published_at": "2026-07-17T18:24:38Z"
        },
        {
          "tag": "v1.0.102",
          "kind": "patch",
          "published_at": "2026-06-24T02:04:29Z"
        },
        {
          "tag": "v1.0.101",
          "kind": "patch",
          "published_at": "2026-06-23T20:34:07Z"
        },
        {
          "tag": "v1.0.100",
          "kind": "patch",
          "published_at": "2026-06-17T17:26:46Z"
        },
        {
          "tag": "v1.0.99",
          "kind": "patch",
          "published_at": "2026-05-31T15:49:03Z"
        },
        {
          "tag": "v1.0.98",
          "kind": "patch",
          "published_at": "2025-11-04T18:22:08Z"
        },
        {
          "tag": "v1.0.97",
          "kind": "patch",
          "published_at": "2025-10-06T20:02:32Z"
        },
        {
          "tag": "v1.0.96",
          "kind": "patch",
          "published_at": "2025-10-06T15:42:06Z"
        },
        {
          "tag": "v1.0.95",
          "kind": "patch",
          "published_at": "2025-10-05T19:50:05Z"
        },
        {
          "tag": "v1.0.94",
          "kind": "patch",
          "published_at": "2025-10-03T00:04:41Z"
        },
        {
          "tag": "v1.0.92",
          "kind": "patch",
          "published_at": "2025-10-02T22:13:38Z"
        },
        {
          "tag": "v1.0.91",
          "kind": "patch",
          "published_at": "2025-10-02T21:53:37Z"
        },
        {
          "tag": "v1.0.90",
          "kind": "patch",
          "published_at": "2025-09-09T20:17:24Z"
        },
        {
          "tag": "v1.0.88",
          "kind": "patch",
          "published_at": "2025-07-28T15:12:46Z"
        },
        {
          "tag": "v1.0.87",
          "kind": "patch",
          "published_at": "2025-07-23T13:32:39Z"
        },
        {
          "tag": "v1.0.86",
          "kind": "patch",
          "published_at": "2025-07-23T12:02:57Z"
        },
        {
          "tag": "v1.0.85",
          "kind": "patch",
          "published_at": "2025-07-22T19:16:58Z"
        },
        {
          "tag": "v1.0.84",
          "kind": "patch",
          "published_at": "2025-07-22T18:32:27Z"
        },
        {
          "tag": "v1.0.83",
          "kind": "patch",
          "published_at": "2025-07-20T22:05:13Z"
        },
        {
          "tag": "v1.0.82",
          "kind": "patch",
          "published_at": "2025-07-20T16:09:18Z"
        },
        {
          "tag": "v1.0.81",
          "kind": "patch",
          "published_at": "2025-07-08T18:20:39Z"
        },
        {
          "tag": "v1.0.80",
          "kind": "patch",
          "published_at": "2025-06-09T21:00:10Z"
        },
        {
          "tag": "v1.0.79",
          "kind": "patch",
          "published_at": "2025-06-09T01:33:45Z"
        },
        {
          "tag": "v1.0.78",
          "kind": "patch",
          "published_at": "2025-06-09T01:25:02Z"
        },
        {
          "tag": "v1.0.77",
          "kind": "patch",
          "published_at": "2025-06-09T00:28:16Z"
        },
        {
          "tag": "v1.0.76",
          "kind": "patch",
          "published_at": "2025-06-08T23:25:12Z"
        },
        {
          "tag": "v1.0.75",
          "kind": "patch",
          "published_at": "2025-06-08T22:49:40Z"
        },
        {
          "tag": "v1.0.74",
          "kind": "patch",
          "published_at": "2025-06-08T22:39:31Z"
        },
        {
          "tag": "v1.0.73",
          "kind": "patch",
          "published_at": "2025-06-08T22:32:48Z"
        },
        {
          "tag": "v1.0.72",
          "kind": "patch",
          "published_at": "2025-06-08T22:03:35Z"
        },
        {
          "tag": "v1.0.71",
          "kind": "patch",
          "published_at": "2025-05-30T02:03:25Z"
        },
        {
          "tag": "v1.0.70",
          "kind": "patch",
          "published_at": "2025-05-28T22:24:59Z"
        },
        {
          "tag": "v1.0.69",
          "kind": "patch",
          "published_at": "2025-05-18T17:25:59Z"
        },
        {
          "tag": "v1.0.68",
          "kind": "patch",
          "published_at": "2025-05-18T13:13:07Z"
        },
        {
          "tag": "v1.0.67",
          "kind": "patch",
          "published_at": "2025-05-17T20:31:59Z"
        },
        {
          "tag": "v1.0.66",
          "kind": "patch",
          "published_at": "2025-05-17T18:54:51Z"
        },
        {
          "tag": "v1.0.65",
          "kind": "patch",
          "published_at": "2025-05-17T15:08:16Z"
        },
        {
          "tag": "v1.0.64",
          "kind": "patch",
          "published_at": "2025-05-17T14:41:50Z"
        },
        {
          "tag": "v1.0.63",
          "kind": "patch",
          "published_at": "2025-05-16T21:54:47Z"
        },
        {
          "tag": "v1.0.62",
          "kind": "patch",
          "published_at": "2025-05-16T19:58:44Z"
        },
        {
          "tag": "v1.0.61",
          "kind": "patch",
          "published_at": "2025-05-16T19:31:04Z"
        },
        {
          "tag": "v1.0.60",
          "kind": "patch",
          "published_at": "2025-05-16T18:31:56Z"
        },
        {
          "tag": "v1.0.59",
          "kind": "patch",
          "published_at": "2025-05-16T17:51:25Z"
        },
        {
          "tag": "v1.0.58",
          "kind": "patch",
          "published_at": "2025-05-16T17:19:30Z"
        },
        {
          "tag": "v1.0.57",
          "kind": "patch",
          "published_at": "2025-05-16T02:27:24Z"
        },
        {
          "tag": "v1.0.56",
          "kind": "patch",
          "published_at": "2025-05-16T01:10:06Z"
        },
        {
          "tag": "v1.0.55",
          "kind": "patch",
          "published_at": "2025-05-15T15:57:07Z"
        },
        {
          "tag": "v1.0.54",
          "kind": "patch",
          "published_at": "2025-05-15T15:43:32Z"
        },
        {
          "tag": "v1.0.53",
          "kind": "patch",
          "published_at": "2025-05-15T01:15:08Z"
        },
        {
          "tag": "v1.0.52",
          "kind": "patch",
          "published_at": "2025-05-13T20:43:51Z"
        },
        {
          "tag": "v1.0.51",
          "kind": "patch",
          "published_at": "2025-05-13T12:34:24Z"
        },
        {
          "tag": "v1.0.50",
          "kind": "patch",
          "published_at": "2025-05-12T22:17:31Z"
        },
        {
          "tag": "v1.0.49",
          "kind": "patch",
          "published_at": "2025-05-10T18:47:14Z"
        },
        {
          "tag": "v1.0.48",
          "kind": "patch",
          "published_at": "2025-05-10T17:32:48Z"
        },
        {
          "tag": "v1.0.47",
          "kind": "patch",
          "published_at": "2025-05-09T23:17:15Z"
        },
        {
          "tag": "v1.0.46",
          "kind": "patch",
          "published_at": "2025-05-09T18:00:53Z"
        },
        {
          "tag": "v1.0.45",
          "kind": "patch",
          "published_at": "2025-05-09T16:15:05Z"
        },
        {
          "tag": "v1.0.44",
          "kind": "patch",
          "published_at": "2025-05-09T15:27:02Z"
        },
        {
          "tag": "v1.0.43",
          "kind": "patch",
          "published_at": "2025-05-09T13:46:53Z"
        },
        {
          "tag": "v1.0.42",
          "kind": "patch",
          "published_at": "2025-05-09T13:36:04Z"
        },
        {
          "tag": "v1.0.41",
          "kind": "patch",
          "published_at": "2025-05-09T12:42:14Z"
        },
        {
          "tag": "v1.0.40",
          "kind": "patch",
          "published_at": "2025-05-09T12:28:33Z"
        },
        {
          "tag": "v1.0.39",
          "kind": "patch",
          "published_at": "2025-05-09T02:08:42Z"
        },
        {
          "tag": "v1.0.38",
          "kind": "patch",
          "published_at": "2025-05-09T01:50:24Z"
        },
        {
          "tag": "v1.0.37",
          "kind": "patch",
          "published_at": "2025-05-09T01:28:47Z"
        },
        {
          "tag": "v1.0.36",
          "kind": "patch",
          "published_at": "2025-05-09T01:14:20Z"
        },
        {
          "tag": "v1.0.35",
          "kind": "patch",
          "published_at": "2025-05-09T00:43:19Z"
        },
        {
          "tag": "v1.0.34",
          "kind": "patch",
          "published_at": "2025-05-09T00:00:09Z"
        },
        {
          "tag": "v1.0.33",
          "kind": "patch",
          "published_at": "2025-05-08T23:05:08Z"
        },
        {
          "tag": "v1.0.32",
          "kind": "patch",
          "published_at": "2025-05-08T19:10:49Z"
        },
        {
          "tag": "v1.0.31",
          "kind": "patch",
          "published_at": "2025-05-08T18:15:39Z"
        },
        {
          "tag": "v1.0.30",
          "kind": "patch",
          "published_at": "2025-05-07T01:33:16Z"
        },
        {
          "tag": "v1.0.29",
          "kind": "patch",
          "published_at": "2025-05-06T23:37:16Z"
        },
        {
          "tag": "v1.0.28",
          "kind": "patch",
          "published_at": "2025-05-06T22:15:53Z"
        },
        {
          "tag": "v1.0.27",
          "kind": "patch",
          "published_at": "2025-05-06T21:03:22Z"
        },
        {
          "tag": "v1.0.26",
          "kind": "patch",
          "published_at": "2025-05-06T19:23:16Z"
        },
        {
          "tag": "v1.0.25",
          "kind": "patch",
          "published_at": "2025-05-06T18:59:43Z"
        },
        {
          "tag": "v1.0.24",
          "kind": "patch",
          "published_at": "2025-05-06T18:24:46Z"
        },
        {
          "tag": "v1.0.23",
          "kind": "patch",
          "published_at": "2025-05-06T17:40:15Z"
        },
        {
          "tag": "v1.0.22",
          "kind": "patch",
          "published_at": "2025-05-06T16:23:22Z"
        },
        {
          "tag": "v1.0.21",
          "kind": "patch",
          "published_at": "2025-05-06T13:38:10Z"
        },
        {
          "tag": "v1.0.20",
          "kind": "patch",
          "published_at": "2025-05-05T19:22:29Z"
        },
        {
          "tag": "v1.0.19",
          "kind": "patch",
          "published_at": "2025-05-05T16:29:37Z"
        },
        {
          "tag": "v1.0.18",
          "kind": "patch",
          "published_at": "2025-05-05T12:35:20Z"
        },
        {
          "tag": "v1.0.17",
          "kind": "patch",
          "published_at": "2025-05-04T20:03:20Z"
        },
        {
          "tag": "v1.0.16",
          "kind": "patch",
          "published_at": "2025-05-02T20:52:39Z"
        },
        {
          "tag": "v1.0.15",
          "kind": "patch",
          "published_at": "2025-05-02T20:19:30Z"
        },
        {
          "tag": "v1.0.14",
          "kind": "patch",
          "published_at": "2025-05-02T19:59:33Z"
        },
        {
          "tag": "v1.0.13",
          "kind": "patch",
          "published_at": "2025-05-01T16:19:53Z"
        },
        {
          "tag": "v1.0.12",
          "kind": "patch",
          "published_at": "2025-05-01T12:34:20Z"
        },
        {
          "tag": "v1.0.11",
          "kind": "patch",
          "published_at": "2025-04-24T23:51:58Z"
        },
        {
          "tag": "v1.0.10",
          "kind": "patch",
          "published_at": "2025-04-24T18:32:54Z"
        },
        {
          "tag": "v1.0.9",
          "kind": "patch",
          "published_at": "2025-04-24T18:07:35Z"
        },
        {
          "tag": "v1.0.8",
          "kind": "patch",
          "published_at": "2025-04-24T17:30:56Z"
        },
        {
          "tag": "v1.0.7",
          "kind": "patch",
          "published_at": "2025-04-24T16:40:20Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "2ddce40e8a2b8cce16f32bf03fd4b5051de26594",
          "body": "cognitoIdpEndpoint is the target for every cognito-idp API call\n(InitiateAuth, RespondToAuthChallenge, GetTokensFromRefreshToken,\nRevokeToken, GetUser, SignUp, ChangePassword, ...). Passwords\n(USER_PASSWORD_AUTH), SRP parameters, refresh/access tokens and any\noptional clientSecret are POSTed to it, \n[…]\ning hostedUi.domain http:// rejection. Bare AWS region shorthand\n(e.g. eu-west-1) is unaffected — it is handled by the auto-prefix path.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)",
          "is_bot": false,
          "headline": "fix(security): require https for cognitoIdpEndpoint (#110)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-07-23T16:22:55Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "72e1fd04e0be2667d7c69e2b563d5017fb215ab9",
          "body": "fido2.baseUrl is the base URL for every FIDO2 backend API call\n(register passkey, list/delete credentials). The user's ID token is sent\nas an `Authorization: Bearer <idToken>` header to that URL, so a\nplaintext http:// base would expose the token in transit.\n\nconfigure() validated hostedUi.domain ag\n[…]\n plaintext http:// fido2.baseUrl at\nconfigure() time, mirroring the existing hostedUi.domain http:// check\nin placement and error style.\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)",
          "is_bot": false,
          "headline": "fix(security): require https for fido2.baseUrl (#111)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-07-23T16:22:27Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ac145cc518b432d2b3d4b454baa2ae1ee6f9c64a",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.103 to 1.0.104",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2026-07-20T22:35:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e87dfdffd03ab314c231f3d9108af2a6a74e2374",
          "body": "… scope (#108)\n\nHosted-UI / OAuth access tokens only carry the OAuth scopes that were\nrequested at sign-in. Cognito GetUser requires\naws.cognito.signin.user.admin, so for redirect sessions the MFA-status\nfetch fails deterministically with NotAuthorizedException and the hook\nretries it per token (and\n[…]\nser; without\nthe scope, publish the default TOTP status (disabled) and mark\nmfaStatusReady immediately. Same guard in refreshTotpMfaStatus.\nUnparseable tokens fail open and keep the previous behavior.",
          "is_bot": false,
          "headline": "fix(react): skip GetUser MFA-status fetch when token lacks user.admin…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-07-20T22:34:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ab3efa53ec4aa9d9441702ccc580c6c8a111baba",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.102 to 1.0.103",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2026-07-17T18:24:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25fd5254cb20d30ce8403f74515ce3bb0da7826b",
          "body": "…t can't wedge auth (#107)\n\ncreateFetchWithRetry awaited fetch with no per-attempt timeout, so a black-holed\nconnection (TLS up, no response, no error) hung forever. Because auth requests\nrun on the critical sign-in/refresh path, one hung call — e.g. ConfirmDevice\nduring device confirmation, which r\n[…]\nast attempt). Default 25s; configurable via a\nnew createFetchWithRetry parameter. Applies to every Cognito call, so ConfirmDevice,\nRespondToAuthChallenge, and refresh all fail fast instead of hanging.",
          "is_bot": false,
          "headline": "fix(client): bound each fetch attempt with a timeout so a hung reques…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-07-17T18:20:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ccf3af1fca4bd1562ff01cd5bcabf7f46efc1dbe",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.101 to 1.0.102",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2026-06-24T02:04:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ba5e93fe4e0d3e407d94f5a7c99954acfd9a3f64",
          "body": "…ignal API (#106)\n\nWhen the relying party rejects a sign-in because it does not recognize the\npresented credential (a discoverable passkey revoked server-side but still\noffered at the login screen), Cognito returns a UserLambdaValidationException\ncarrying {\"reason\":\"unknown_credential\"}. authenticat\n[…]\n plus a produced assertion: cancels,\naborts, network/throttle failures, wrong signature, and generic NotAuthorized\nall keep the existing failure path, so a valid passkey is never signalled as\nunknown.",
          "is_bot": false,
          "headline": "feat(client): surface unknown-credential sign-in rejections for the S…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-24T02:03:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "de9d7afdbac03a3a37aa37aca8549faf3fb8c6ab",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.100 to 1.0.101",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2026-06-23T20:33:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "64ea8e32b66b70f06ab6289a942d7ffbfbcccbc5",
          "body": "* feat(client): add WebAuthn Signal API wrappers\n\nAdd signalAllAcceptedCredentials, signalUnknownCredential and\nsignalCurrentUserDetails over the W3C PublicKeyCredential.signal* static\nmethods. Each is feature-gated via getClientCapabilities() and no-ops where the\nbrowser lacks support. The WebAuthn\n[…]\nix rather than the current hostname.\nResolve the rpId from an explicit argument or the configured fido2.rp.id only,\nand no-op when neither is available rather than signalling against a guessed\ndomain.",
          "is_bot": false,
          "headline": "feat(client): add WebAuthn Signal API wrappers (#105)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-23T19:41:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e624ca2be4ba7ddcf578c378565a7a1f5eb13131",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.99 to 1.0.100",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2026-06-17T17:26:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ff0a56ccaafc689b2df73e068e2f4e65ba5ba58",
          "body": "When another tab signs out it removes the Cognito token keys from\nstorage, firing a storage event in this tab. The handler only called\nloadTokens (which nulls tokens) but never dispatched SIGN_OUT, so\nper-user React state (totpMfaStatus, mfaStatusReady, deviceKey,\nauthMethod, ...) survived until the\n[…]\n removal and a LastAuthUser removal each reset\ndeviceKey/totpMfaStatus/mfaStatusReady; a token change (refresh) keeps\nthe user signed in with state intact. The removal tests fail on the\nprevious code.",
          "is_bot": false,
          "headline": "Reset per-user state on a cross-tab sign-out (#103)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-17T17:09:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "77436c4968b14db832cebb897cbf0e1825a1bf2c",
          "body": "…in (#100)\n\nThree small hardening fixes from the re-review's core-cleanups bucket:\n\n- initiateAuth no longer mutates the caller's authParameters object\n  (it set authParameters.DEVICE_KEY = deviceKey, which stuck on an\n  object reused across retry attempts). The device key is merged into\n  the reque\n[…]\nh sends DEVICE_KEY without mutating the caller's\nobject (incl. reuse across two calls); http:// hostedUi.domain throws;\na bare domain is accepted. The behaviour-change tests fail on the\nprevious code.",
          "is_bot": false,
          "headline": "Misc safety: no authParameters mutation, reject http:// hostedUi.doma…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-17T17:08:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e17e4cf3b509a17eb9e0e1734a1aabecdb1b64dd",
          "body": "* Retry transient renewal initiate in conditional FIDO2 flow\n\nThe conditional-mediation renewal loop re-initiates a fresh Cognito\nCUSTOM_AUTH challenge at the top of each iteration. A transient network\nfailure of that initiateFido2Challenge() call threw and killed the whole\nconditional-autofill flow\n[…]\nker pointing at a dead, superseded flow rather\nthan returning to \"no live conditional flow\". Restore only a still-live\nprevious flow, else clear to undefined, so the invariant (non-null ⇒ live)\nholds.",
          "is_bot": false,
          "headline": "Retry transient renewal initiate in conditional FIDO2 flow (#102)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-17T17:08:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1162e23c608e6a6c6c1185c272e49f2094923d86",
          "body": "* Track refresh failures and backoff retry timer per user\n\nMove consecutiveRefreshFailures from a module global into per-user\nRefreshState, and track the failure-backoff retry timer so it can be\ncancelled on sign-out / abort / forced refresh instead of firing for a\ntorn-down session. One user's repe\n[…]\nMap) could arm a retry nothing could cancel.\n\nCancel retryTimer in clearExistingTimer too, and bail the failure catch when\nthere is no username. Regression test added for the re-schedule cancellation.",
          "is_bot": false,
          "headline": "Track refresh failures and backoff retry timer per user (#101)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-17T17:08:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "090cd82d89396c579600d07d6b2a45531982b0f3",
          "body": "…104)\n\n* Rehydrate deviceKey from storage in the SRP and plaintext tokensCb\n\nThe FIDO2 sign-in tokensCb rehydrates the device key from the\nremembered-device record when the tokens don't carry one (since #64),\nbut the SRP and plaintext tokensCb did not: SRP only set deviceKey when\npresent, and plaint\n[…]\ntical FIDO2/SRP/plaintext rehydrate blocks (which diverged once — the\nbug the previous commit fixed) collapse into one shared rehydrateDeviceKey()\nhelper. Add a regression test for the cross-tab case.",
          "is_bot": false,
          "headline": "Rehydrate deviceKey from storage in the SRP and plaintext tokensCb (#…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-17T17:07:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "32215579e7dc3a376d5ad9893a4051780c6995ec",
          "body": "processTokens is the only thing that arms the next refresh, and it runs\nonly on a fresh sign-in / refresh — never on a page reload, where the\ntokens are read back from storage. So after a reload nothing scheduled\nthe next refresh until the +5-minute watchdog tick. With short access\ntokens (Cognito a\n[…]\nt.\n\nTest: a session restored from storage schedules a refresh on mount; the\nsigned-out case still calls scheduleRefresh (which no-ops). Both fail on\nthe previous code, which never scheduled on reload.",
          "is_bot": false,
          "headline": "Schedule a token refresh on page reload (#99)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-15T17:20:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cda691f78d9ad1c0af387b5594d52b28e00d1ef0",
          "body": "…#97)\n\nThree related warts in the processTokens scheduling machinery:\n\n1. Identity-checked schedule deletion. A completed refresh runs its\n   nested processTokens (which registers the NEXT schedule for the new\n   tokens) BEFORE the old schedule's tokensCb fires. The tokensCb\n   deleted the user's ac\n[…]\n: newDeviceMetadata=undefined schedules immediately (no deferral);\na real new device key defers 2 minutes; sign-out cancels a pending\ndeferral. The two behavior-change tests fail on the previous code.",
          "is_bot": false,
          "headline": "Fix processTokens refresh-scheduling dedup and fresh-login deferral (…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-15T17:15:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "899d1d336df59fde027f19db7c507094f573a549",
          "body": "…sions (#98)\n\n* Resolve CodeQL alerts: two polynomial-ReDoS regexes and workflow permissions\n\nCodeQL code-scanning flagged three open alerts:\n\n- HIGH js/polynomial-redos in client/config.ts (trailing-slash trim\n  /\\/+$/): replace with a linear backward scan. Backtracking on a long\n  run of \"/\" was p\n[…]\nrightmost one\nwith a non-empty suffix (and non-empty prefix), which is what the regex\nresolves to — still O(n), no backtracking. Verified equivalent to the\nregex across single- and multi-marker cases.",
          "is_bot": false,
          "headline": "Resolve CodeQL alerts: two polynomial-ReDoS regexes + workflow permis…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-15T17:14:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "93c2e55fa9790379267c4b187e3b43df1fb5fe01",
          "body": "Bumps the npm_and_yarn group with 1 update in the / directory: [esbuild](https://github.com/evanw/esbuild).\n\n\nUpdates `esbuild` from 0.25.8 to 0.28.1\n- [Release notes](https://github.com/evanw/esbuild/releases)\n- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2025.md)\n- [Commits](h\n[…]\n dependency-type: indirect\n  dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump esbuild in the npm_and_yarn group across 1 directory (#90)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-15T17:07:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b02822e635fb47a9792008d018264d4a286fc8d9",
          "body": "…r (#96)\n\nOn a getUser error the hook retained the last-known MFA status, marked\nmfaStatusReady true, and scheduled a silent retry every ~7s by clearing\nthe token guard and nudging a re-run. There was no cap: a persistent\nfailure (network outage, or a backend that keeps erroring) retried\nforever.\n\nC\n[…]\nhile retries\nstop.\n\nTest: getUser failing every time yields exactly 1 initial + 3 retries =\n4 fetches then stops (the previous code kept polling); a token rotation\nresets the budget and fetches again.",
          "is_bot": false,
          "headline": "Cap the MFA-status fetch retry so a failing getUser can't poll foreve…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-15T16:52:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cc1c76821192f55d05a7bc341fa0f66109c9135c",
          "body": "* Honor an explicit advancedSecurity.region as an allowlist override\n\n#70 added a hardcoded allowlist of regions known to host the Advanced\nSecurity script and stopped defaulting unknown regions to us-east-1.\nBut it also gated an EXPLICITLY configured advancedSecurity.region\nbehind that allowlist, s\n[…]\n the allowlist. A malformed value is rejected outright rather than\nfalling through to the endpoint-derived region. Regression test loads a\nhost-injection region string and asserts nothing is injected.",
          "is_bot": false,
          "headline": "Honor an explicit advancedSecurity.region as an allowlist override (#95)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-15T16:38:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1482b75a02f0d181e6f0d6f32b03c4184723eadd",
          "body": "#92 widened the React OAuth-callback gate to also fire on an `error`\nparam so denied sign-ins surface instead of hanging silently. It checks\n`error` in both the query and the URL fragment, unconditionally.\n\nPer RFC 6749, response errors come back in the query for the code flow\n(§4.1.2.1) and in the \n[…]\n first — this just stops the spurious entry\nat the gate.\n\nTests: a code-flow fragment error no longer invokes the handler; an\nimplicit-flow fragment error still does and surfaces the provider message.",
          "is_bot": false,
          "headline": "Gate implicit-flow OAuth fragment errors to responseType \"token\" (#94)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-15T16:10:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "58c417acec1cd6d44d0fe9e09083a01f26b12b69",
          "body": "…dow (#93)\n\n* Close FIDO2 conditional renewal/takeover seam during the initiate window\n\nThe conditional-autofill renewal loop tracked takeovers only via\npendingConditionalGet, which exists solely while a navigator.credentials\n.get() is pending. Between renewal iterations — after the previous get()\ni\n[…]\nin once it has\nsuperseded the conditional one.\n\nTest: a conditional getter that performs a modal takeover and then\nresolves with a credential ends the flow with superseded=true rather\nthan completing.",
          "is_bot": false,
          "headline": "Close FIDO2 conditional renewal/takeover seam during the initiate win…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-15T16:08:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d49f2bf27b9ffa4b4548f269f419ba1f106b3abe",
          "body": "Two bugs in the hook's OAuth-callback effect:\n\n1. The gate only fired for code/access_token, so an error-only redirect\n   (user denied consent: ?error=access_denied with no code/token, in the\n   query for the code flow or the fragment for implicit) never invoked\n   handleCognitoOAuthCallback. The ha\n[…]\nGNED_IN; null result resolves to NOT_SIGNED_IN (not stuck at\nSIGNING_IN); tokens reach SIGNED_IN; a non-callback URL never invokes\nthe handler. The two behavior-change tests fail on the previous hook.",
          "is_bot": false,
          "headline": "Fix React OAuth callback gate for errors and stuck busy status (#92)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-15T15:37:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e227267b66592b2c50b3a8ac5d2831295e223b01",
          "body": "* Route forceRefreshTokens through the per-user refresh lock\n\nforceRefreshTokens (exposed by the React hook, called on a 401) passed\nforce:true, which conflated two concerns: skip the cross-tab dedup\ncheck AND bypass the per-user refresh lock. Bypassing the lock let a\nforced refresh race a concurren\n[…]\nes to a private\nperformRefresh that carries skipLock. Only the in-lock immediate-\nrefresh path calls performRefresh with skipLock:true. Verified the\ngenerated refresh.d.ts no longer mentions skipLock.",
          "is_bot": false,
          "headline": "Route forceRefreshTokens through the per-user refresh lock (#91)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-15T15:25:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e9b3b4ff7b5529a75303ede5eecd6fb990d22389",
          "body": "…an takeover (#89)\n\n* Fix sign-out and lock liveness: timeout fallback, heartbeat cap, orphan takeover\n\nThree liveness gaps around the cross-tab storage lock:\n\n1. signOut now catches LockTimeoutError and proceeds without the lock.\n   Previously another tab's heartbeat-renewed refresh lock made signO\n[…]\ned-token write) is\ncompensated; fresh sign-in clears a stale tombstone; the E2E\nhung-refresh race still passes. The signOut leftover-keys test now\nasserts the tombstone is the one deliberate survivor.",
          "is_bot": false,
          "headline": "Fix sign-out and lock liveness: timeout fallback, heartbeat cap, orph…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-15T14:32:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af5251cf768cd8ce16308e9d1ef104e51f0a5a51",
          "body": "…#88)\n\nThe stale-device hardening added to the plaintext flow (#67) never\nreached its SRP sibling, leaving the worst behavior in the most-used\nflow: srp.ts sent device keys from placeholder records (no device\npassword), and a device forgotten server-side PERMANENTLY bricked SRP\nsign-in - every attem\n[…]\n-api.ts and device.ts import each\nother, and a requireActual factory re-enters that cycle and splits the\nmodule identity (device.ts ends up calling a different confirmDevice\nthan the test configured).",
          "is_bot": false,
          "headline": "Bring SRP flow to device-key parity; never persist unconfirmed keys (…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-12T16:37:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3a8a950e464f487dafaaafb8487f8636ea645f25",
          "body": "* Make refresh-bugs suite deterministic under parallel load\n\nThe suite failed ~25% of runs on loaded machines. Root cause:\nprocessTokens launches fire-and-forget scheduleRefresh chains whose\nhops (storage-lock jitter sleeps, poll loops) outlive the test that\nstarted them; with static imports a strag\n[…]\nfor isolation (they belong to the\ndiscarded module graph) but the teardown comment claimed otherwise.\nCancel each suite username's timers via cleanupUserRefreshState\nbefore resetting the module graph.",
          "is_bot": false,
          "headline": "Make refresh-bugs suite deterministic under parallel load (#87)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-11T15:31:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fa16ca3af307056f882b6aa84e478745686de989",
          "body": "* Add opt-in Hosted UI sign-out via signOutWithRedirect\n\nLocal signOut only clears storage and revokes the refresh token; the\nCognito Hosted UI (managed login) session cookie survives, so on a\nshared device the next signInWithRedirect within the hour silently\nsigns in as the previous user. Add an op\n[…]\ndow\nshrinks from a network round-trip to microtasks. Regular signOut\nordering is unchanged (local-first, so a network failure can never\nkeep a user signed in). Ordering pinned by tests for both modes.",
          "is_bot": false,
          "headline": "Add opt-in Hosted UI sign-out via signOutWithRedirect (#68)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-11T13:42:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ea8744ee16be560e641efb4ef8f98aeb605fb3d6",
          "body": "* Send DEVICE_KEY in USER_PASSWORD_AUTH initiateAuth call\n\nThe plaintext password flow looked up the remembered device key only\nafter initiateAuth had already been sent, and never passed it along, so\nCognito could not recognize a remembered device: users were always\nprompted for MFA and the pre-buil\n[…]\ner browser\n   now fully self-heal in one sign-in).\n\n3. clearDeviceKey now awaits the storage removals before dispatching,\n   so a sign-in started right after it resolves cannot read the old\n   record.",
          "is_bot": false,
          "headline": "Send DEVICE_KEY in USER_PASSWORD_AUTH initiateAuth call (#67)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-11T13:06:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3163c2fe8041250aface58d2a7acac8a3d3d6905",
          "body": "…ow (#66)\n\n* Surface fragment-delivered OAuth errors and deprecate implicit flow\n\nPer RFC 6749 §4.2.2.1, implicit-flow error responses arrive in the URL\nfragment, but the callback handler only read url.searchParams, so real\nIdP errors were swallowed and surfaced as a misleading \"Access token\nmissing\n[…]\nattack stays blocked: the fallback never\nruns when the fragment holds valid tokens. Also rephrase the channel\ncomments to distinguish RFC-specified server behavior from this\nclient's hardening policy.",
          "is_bot": false,
          "headline": "Surface fragment-delivered OAuth errors and deprecate the implicit fl…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-11T13:05:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b49703bcacfdf6e14cd3e292c46f2f37253d063",
          "body": "…O2 request (#76)\n\n* Abort pending conditional credentials.get() before starting a new request\n\nPer the Credential Management API, only one credentials.get() request may\nbe pending at a time. With the documented usage pattern - a conditional\n(autofill) request kicked off at page load, followed by th\n[…]\nso the autofill flow would restart behind the modal request's\nback and keep renewing indefinitely. Rethrow superseded aborts so the\nflow ends cleanly; regression test covers the renewal-boundary race.",
          "is_bot": false,
          "headline": "Abort pending conditional credentials.get() before starting a new FID…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-11T00:59:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "762177be4dbe88d0f41e9ed7d382846852c0a5e4",
          "body": "* Reset per-user state on sign-out in React hook\n\nThe SIGN_OUT reducer action was defined but never dispatched, so the\nReact signOut method left deviceKey, totpMfaStatus, mfaStatusReady and\nactivity timestamps from the previous user in place. A subsequent user\non the same provider instance could the\n[…]\nin a session, and\nsign-out is a session boundary: reset it so the next user's fetch\nruns immediately. Regression test signs user B in within the cooldown\nand asserts an immediate fetch with B's token.",
          "is_bot": false,
          "headline": "Reset per-user state on sign-out in React hook (#64)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-11T00:59:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ddf4a3d8b8b10ca059c1bcc59b97c86d20bcfac0",
          "body": "…its (#62)\n\nThe post-exchange URL cleanup used history.pushState, which adds a new\nhistory entry and leaves the callback URL carrying ?code=...&state=...\n(or #access_token=... in the implicit flow) one step back in session\nhistory. Worse, no error path cleaned the URL at all: on state mismatch,\nmiss\n[…]\nes in the implicit flow, which previously threw without scrubbing.\nFalls back to pushState for custom MinimalHistory implementations\nwithout replaceState (replaceState is added as an optional member).",
          "is_bot": false,
          "headline": "Scrub OAuth code/tokens from URL with replaceState on all callback ex…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-11T00:58:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a225f9d40becb55236a9efdfc33af481193342cf",
          "body": "…bility listener (#60)\n\n* Keep global refresh listeners alive across sign-out\n\nsignOut called cleanupRefreshSystem(username), which tore down the\nglobal visibilitychange listener, refresh watchdog, and page-unload\nhandlers for the rest of the page lifetime. Since these are only\nregistered once at mo\n[…]\nther lookup in this file since #55) so the\nlock is honored whenever a refresh token still exists. With the lock\nhonored, the handler serializes behind signOut and then no-ops once\nthe tokens are gone.",
          "is_bot": false,
          "headline": "Fix signOut permanently tearing down global refresh watchdog and visi…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T23:15:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0d5792f526b14c6c213b6b91a863b183cf3715cd",
          "body": "…h cooldown (#61)\n\nWhen the access token changed within 5s of the previous getUser call\n(e.g. OAuth code exchange completing after stored tokens loaded, or a\nforced refresh right after sign-in), updateTokens reset mfaStatusReady\nto false but the MFA status effect early-returned on the cooldown\nwitho\n[…]\nw the cooldown branch schedules a setTimeout for the remaining\ncooldown that nudges the effect to re-run (INCREMENT_RECHECK_STATUS),\nwith cleanup on dependency change/unmount so timers cannot pile up.",
          "is_bot": false,
          "headline": "Fix mfaStatusReady deadlock when access token rotates within MFA fetc…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T23:15:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e5b2dc57ef7e31902784970450d3ec45e7dd825d",
          "body": "The plaintext (USER_PASSWORD_AUTH) flow looked up and stored remembered-\ndevice records under the username as entered, which may be an alias\n(e-mail / phone), while the SRP flow keys them by USER_ID_FOR_SRP. A\ndevice confirmed via one flow was then invisible to the other, silently\nlosing device reme\n[…]\ness token's username claim) and use it\nfor device record lookups and for the rest of the auth flow, with a\nbackward-compat fallback lookup under the username as entered so legacy\nrecords keep working.",
          "is_bot": false,
          "headline": "Key plaintext-flow device records by canonical user id (#71)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T23:14:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "04f2aa9ffb0a7c3cc05b009070c70eb5d6aff17b",
          "body": "…n-ASCII usernames (#75)\n\nRegistration encoded the server-sent user.id with Latin-1 byte-stuffing\n(charCodeAt mod 256) while usernameless sign-in decodes the returned\nuserHandle with TextDecoder (UTF-8). For non-ASCII usernames the bytes\nwere corrupted at registration, so the derived USERNAME never \n[…]\n\nare symmetric, and throw a clear Fido2ValidationError if the encoded\nhandle exceeds the 64-byte WebAuthn limit instead of failing opaquely.\nASCII user handles are byte-identical under both encodings.",
          "is_bot": false,
          "headline": "Fix userHandle encoding to UTF-8 so usernameless sign-in works for no…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T23:14:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1b6f2e03fecc7f9296913fc4e5681fcbe7b7b24e",
          "body": "handleCognitoOAuthCallback() overwrote the shared in-progress flag with\n\"processing\" before verifying the current URL matched the configured\nredirect URL. The URL-mismatch branch then returned null without\nrestoring the flag, so any invocation on a non-callback URL (e.g. the\nReact hook firing on an \n[…]\nthe redirect-URL comparison ahead of the flag transition so\nnon-callback invocations leave the flag untouched. All paths after the\n\"processing\" write either complete the flow or clear state and throw.",
          "is_bot": false,
          "headline": "Check redirect URL before marking OAuth callback as processing (#65)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T23:13:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c0df6f6c281fcfcfee03c1a6626e172d9a6a73e2",
          "body": "…y (#57)\n\n* Make setTimeoutWallClock resilient to device sleep for the whole delay\n\nPreviously, delays >= 30s used a plain setTimeout for all but the final\n30 seconds, and browsers don't reliably credit setTimeout time spent in\nsystem sleep. If the device slept during that phase (almost the entire\nd\n[…]\nresh() deadlocks. Add an\nawaitPumpingTimers helper that advances mock time in 100ms steps (settling\nmicrotasks between steps via real-timer waits) and use it for all\nscheduleRefresh calls in the file.",
          "is_bot": false,
          "headline": "Make setTimeoutWallClock resilient to device sleep for the whole dela…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T21:13:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c8621e1468bcec5b6cc36f6c2e85ca922c561f40",
          "body": "The CognitoSecurityProvider previously awaited script injection with a\n5-second timeout on every auth API call whenever the Amazon Cognito\nAdvanced Security script could not load (ad blockers, CSP, unsupported\nregions), and re-appended a fresh script tag on each attempt. An SRP\nsign-in flow could ac\n[…]\nire-and-forget, attempted at most once per page\nload, and skipped for custom proxy endpoints and regions where AWS does\nnot host the script (previously such endpoints silently defaulted to\nus-east-1).",
          "is_bot": false,
          "headline": "Never block auth calls on threat-protection script loading (#70)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T21:07:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9033903f9e328c377b4733dd3583248a081dc4c0",
          "body": "…okens (#69)\n\nThe 5-minute deduplication window in processTokens compared only\nwall-clock age of the previous schedule entry. After a successful\nrefresh, processTokens runs for the new tokens while the previous\nentry is still tracked (refresh.ts clears it via tokensCb only after\nprocessTokens return\n[…]\nently disabling retry backoff and abort propagation\nfor the replacement schedule). Add a regression test asserting a\nrefresh-driven processTokens arms the next refresh timer without\naborting anything.",
          "is_bot": false,
          "headline": "Fix refresh-schedule dedup suppressing next refresh for short-lived t…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T21:06:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f60ac1452eb2b9da33565a48dedfa1a92d9ecd2",
          "body": "The documented fallback pattern `error.name === 'NotAllowedError'` could\nnever match because fromDOMException wraps the DOMException in a\nFido2CredentialError whose name is \"Fido2CredentialError\", and both\nNotAllowedError and InvalidStateError mapped to the same CREDENTIAL_ERROR\ncode, leaving no pro\n[…]\nERROR fallback\n- Fix the JSDoc examples in fido2.ts and the docs in ERROR_HANDLING.md\n  and client/react/README.md to use the working pattern\n- Add regression tests for the new codes and the predicate",
          "is_bot": false,
          "headline": "Add discriminating error codes for WebAuthn credential failures (#63)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T21:05:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af2490b368037b73c28dedc2b82006365989d0e3",
          "body": "The Fido2ConfigError thrown when isConditionalMediationAvailable()\nresolves false was inside the same try block whose catch only\ndebug-logged and continued, so the guard never fired and the code\nproceeded to call navigator.credentials.get with conditional mediation\non browsers that explicitly report\n[…]\nt false propagates as\nFido2ConfigError, keep the lenient fallthrough when the capability\ncheck itself throws, and make the debug message truthful about\nproceeding. Add regression tests for both cases.",
          "is_bot": false,
          "headline": "Fix unreachable conditional-mediation guard in fido2getCredential (#59)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T21:04:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "58174921e5c1d978a08fa4fb3a781c73707e08a9",
          "body": "fido2getCredential unconditionally overrode userVerification to\n\"preferred\" when mediation was \"conditional\", silently downgrading a\nserver-requested \"required\". The WebAuthn spec has no such requirement;\n\"preferred\" is only passkeys.dev UX guidance. With the downgrade, an\nauthenticator may skip use\n[…]\n).\n\nNow the requested value is passed through unchanged and \"preferred\" is\napplied only as a default when no userVerification was requested. The\ntimeout removal for conditional mediation is unchanged.",
          "is_bot": false,
          "headline": "Respect requested userVerification for conditional mediation (#58)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T21:03:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8388acd84cedfa0b45af2d02aabe4eba1a820c70",
          "body": "…oIdpEndpoint fallback (#56)\n\ngetAuthorizeEndpoint()/getTokenEndpoint() fell back to cognitoIdpEndpoint\nwhen hostedUi.domain was omitted. With the documented region-only\nconfiguration (e.g. cognitoIdpEndpoint: \"eu-west-1\") this produced\nhttps://eu-west-1/oauth2/authorize, sending signInWithRedirect(\n[…]\nis not a bare AWS region), so https://eu-west-1 or other dotless\nhosts cannot slip through; plaintext http:// origins are rejected,\nbecause OAuth2 authorization codes and tokens travel to that origin.",
          "is_bot": false,
          "headline": "Require hostedUi.domain for OAuth2 endpoints instead of broken cognit…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T21:02:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "068f9fba5c3ba456ecfe10dab874ad492da31afa",
          "body": "…#86)\n\nPR #52 added the onTokensStored(cb) subscriber API to client/storage.ts;\nthe React hook calls the returned unsubscribe function in its mount\neffect cleanup. PR #74 added react-context-stability.test.tsx, which\nmocks ../storage without making onTokensStored return a function, so\nthe cleanup ca\n[…]\nact suites already use\n(mockOnTokensStored.mockReturnValue(() => {})), and harden the hook\ncleanup with a typeof check so a future mock omission degrades\ngracefully instead of throwing during unmount.",
          "is_bot": false,
          "headline": "Fix react-context-stability test suite broken by parallel PR merges (…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T20:21:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c8b7664193b23d5b953cab54bce2fda0560628d8",
          "body": "Debug output previously included full refresh/access/ID tokens, SRP\nsecret blocks, device keys and the OAuth state/PKCE challenge whenever\nan application wired the debug callback to console.log or a remote\nlogger. Add redactSecret and redactTokensFromObject helpers to\nclient/util.ts and apply them a\n[…]\nall, which still logged SECRET_BLOCK and DEVICE_KEY verbatim during\nremembered-device authentication, and the ConfirmDevice response log.\nA regression test covers the device challenge flow end to end.",
          "is_bot": false,
          "headline": "Redact tokens and device keys from debug logging (#78)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:57:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e561cdb5e4cddcecb76707907e8ea92b94a25c96",
          "body": "signOut's storage cleanup missed the per-user keys the library actually\nwrites: Passwordless.<clientId>.<username>.authMethod,\n.lastRefreshAttempt and .lastRefreshCompleted. A leftover\nlastRefreshAttempt written shortly before sign-out makes\nshouldAttemptRefresh veto the first refresh after an immed\n[…]\nthe .expireAt and\n.refreshingTokens removals as legacy-key migration hygiene, and add a\nregression test asserting no per-user residue remains after sign-out\n(while the remembered-device key persists).",
          "is_bot": false,
          "headline": "Remove leftover per-user storage keys on sign-out (#81)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:56:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2a4526a12cf96d9d802033285da6e84b0dcbcae2",
          "body": "… refresh (#55)\n\nrefreshTokens()/forceRefreshTokens() without an explicit tokens argument\nresolved the user and refresh token via retrieveTokens(), which returns\nundefined once the stored access token's exp is in the past. That made\nrefresh fail with \"Cannot determine user identity for refresh lock\"\n[…]\nen load, reuse-exception\nrecovery, cross-tab coordination helpers, forceRefreshTokens timer\nlookup) to retrieveTokensForRefresh(), which does not gate on\naccess-token expiry, and add regression tests.",
          "is_bot": false,
          "headline": "Use retrieveTokensForRefresh in refresh paths so expired sessions can…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:56:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "26a244a7b52c02b1bf39d1a20c8be26be40a6359",
          "body": "The storage lock could be double-acquired across tabs, causing\nconcurrent token refreshes and (with refresh-token rotation)\nRefreshTokenReuseException / session loss:\n\n- The storage event listener treated ANY foreign write to the lock key\n  as a release, including another waiter's acquisition, so a \n[…]\nownership verify\nthat acquisition uses, standing down if a competing write landed after\nours. Release already only removes the key when it still holds our id,\nso a takeover survives release untouched.",
          "is_bot": false,
          "headline": "Fix cross-tab storage lock to enforce mutual exclusion (#54)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:55:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dbf43b14757a2a26a5feea20180cd94996e5ecb0",
          "body": "The conditional-mediation fast path in prepareFido2SignIn called\ninitiateAuth (CUSTOM_AUTH) first and then awaited an indefinitely-pending\nautofill credentials.get(). Cognito invalidates the challenge session\nafter AuthSessionValidity minutes (3 by default), so any user picking an\nautofill passkey m\n[…]\nnvisible to the user. The loop stops when the credential resolves, on\nerror, or when the caller aborts. Also document the session-validity\nconstraint on PreparedFido2SignIn and the prepared parameter.",
          "is_bot": false,
          "headline": "Renew Cognito session while conditional passkey request is pending (#53)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:54:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9c1327655c25cadb5a2203c51d105b2b916754fd",
          "body": "…#52)\n\nBackground refreshes persist refreshed tokens via storeTokens, but the\nReact hook's only re-sync path was the \"storage\" event, which per the\nWHATWG HTML spec never fires in the document that performed the write.\nIn the active tab the hook therefore kept the stale access token until\nexpiry and\n[…]\nsubscribe in the React hook's\nmount effect to reload tokens from storage on same-context stores.\nThe subscription is removed on unmount and reloads are no-ops after\nabort. Public API is additive only.",
          "is_bot": false,
          "headline": "Propagate background token refresh into React state in the same tab (…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:54:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c863424b2bab73e1acaa4c93b2875f935be53799",
          "body": "… (#51)\n\nThe HKDF salt was derived from the raw SHA-256 digest hex of the\nscramble parameter u (leading zero bytes preserved), but Cognito's\nserver and the reference client (amazon-cognito-identity-js) encode u\nas a big integer: leading zero bytes stripped, with a '00' sign byte\nprepended only when \n[…]\n\narrayBufferToBigInt(uBuf).toString(16) passed through padHex, and add\nregression tests covering both the leading-zero-byte case and the\nsign-byte case against an independent reference implementation.",
          "is_bot": false,
          "headline": "Fix SRP HKDF salt to use big-integer encoding of scramble parameter u…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:52:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b903644934969b054bb16443b434d1a678550cdc",
          "body": "The unmount cleanup in useAwaitableState sets isMounted.current = false\nbut nothing ever set it back to true. Under React 18+ StrictMode's\nmount -> unmount -> remount cycle (default in dev), refs survive the\nsimulated remount, so resolve() and reject() — both guarded by\nisMounted.current — became pe\n[…]\naitable() returned a\npromise that never settled, hanging every MFA/new-password prompt flow\nin dev. Reset the flag in the effect body before returning the cleanup,\nand add StrictMode regression tests.",
          "is_bot": false,
          "headline": "Fix useAwaitableState hanging under React StrictMode (#72)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:52:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2ec99f9e9d22c20257cf06e3f8282dcb0ccaa9ce",
          "body": "Abort the SRP handshake when the server-supplied B is congruent to\n0 mod N (required by RFC 5054 section 2.5.3) or when the scramble\nparameter u is 0 (required by the SRP-6a design). Both checks live in\ncalculateSrpSignature so they cover the user-password and device-\npassword flows. Also make hexToArrayBuffer reject empty or non-hex\ninput with a descriptive error instead of throwing an opaque TypeError\nfrom a non-null assertion on a failed match.",
          "is_bot": false,
          "headline": "Add SRP-6a safety checks for B mod N and u, validate hex input (#73)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:51:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c4dd0f6013a2d6be4fd921d63fcac2ef0b1b4fd0",
          "body": "With tokenRefresh.useActivityTracking enabled, a 1s interval dispatched\nSET_NOW_TICK into the provider's reducer, and the derived\ntimeSinceLastActivityMs was a dep of the context useMemo — so the context\nvalue identity changed every second, re-rendering every usePasswordless()\nconsumer even if it ne\n[…]\n.\nAlso correct the inaccurate memo-deps comment claiming the API methods\nwere memoized with useCallback, and add render-count regression tests\ncovering the live fields and the config-flag propagation.",
          "is_bot": false,
          "headline": "Stop per-second context churn when activity tracking is enabled (#74)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:51:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "67a926af658549c3888bfc665166d64986d200e6",
          "body": "At device confirmation, x was hashed over the raw 16 random salt bytes\nand those raw bytes were uploaded in DeviceSecretVerifierConfig.Salt.\nCognito stores/echoes the salt as a big integer, so a salt with a\nleading zero byte (P ~ 1/128) came back stripped in the\nDEVICE_PASSWORD_VERIFIER SALT paramet\n[…]\nquals what the\nserver stores and echoes. The explicit top-bit masking is no longer\nneeded since padHex now provides the \"00\" sign prefix when the MSB is\nset, exactly like the reference implementation.",
          "is_bot": false,
          "headline": "Canonicalize device-verifier salt as big integer before hashing (#77)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:49:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "57ce5dedcb68ac88cef7affb56a2af247155c75e",
          "body": "The wait helper in createFetchWithRetry registered an \"abort\" listener\non the caller's AbortSignal for every backoff sleep, but { once: true }\nonly removes the listener when the signal actually aborts. When the\ntimer resolved normally, the listener stayed attached, so a long-lived\nsignal reused acro\n[…]\no the handler reference is shared by both\npaths: the timer callback now removes the abort listener before\nresolving, and the abort handler still clears the timer and rejects\nwith AbortError as before.",
          "is_bot": false,
          "headline": "Remove abort listener when retry backoff timer fires normally (#79)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:48:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ff8d61545aee65751dc603ceaef9445cfc2b2f78",
          "body": "…#80)\n\nThe catch-all in authenticateWithFido2 emitted FIDO2_SIGNIN_FAILED for\nevery error, including deliberate cancellations (Fido2AbortError from a\ncancelled WebAuthn ceremony, or an unwrapped DOMException AbortError\nescaping the Cognito fetch calls when the caller invokes the returned\nabort()). S\n[…]\nn-ins.\n\nNow the catch path detects abort errors and reverts the status to\nSIGNED_OUT (the idle state the flow started from) while still\nrethrowing, so callers' promise rejection behavior is unchanged.",
          "is_bot": false,
          "headline": "Report aborted FIDO2 sign-in as SIGNED_OUT, not FIDO2_SIGNIN_FAILED (…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:48:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b476aef2cf9166fc9804e9f59d09d9ae619c0fe0",
          "body": "The region regex /^[a-z]{2}-[a-z]+-\\d$/ in client/config.ts and\nclient/cognito-api.ts (AWS_REGION_REGEXP) only matched standard-partition\nregions. Multi-segment regions such as us-gov-west-1, us-gov-east-1\n(GovCloud) and eusc-de-east-1 (European Sovereign Cloud) were treated as\nhostnames instead: co\n[…]\nt-1 resolves to cognito-idp.eusc-de-east-1.amazonaws.eu\ninstead of the nonexistent .amazonaws.com host.\n\nAdds table-driven regression tests covering both code paths and the\nper-partition DNS suffixes.",
          "is_bot": false,
          "headline": "Broaden AWS region regex to support partitioned regions (#82)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:47:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dd6206ecc9351863db19d15581c8c4d101ed6069",
          "body": "…nput (#83)\n\nbufferFromBase64Url threw a raw TypeError (\"Cannot read properties of\nnull\") on an empty string because String.match returns null, and silently\ndecoded garbage for characters outside the base64url alphabet. Decoders\nnow return an empty buffer for empty input and throw a clear Error for\n\n[…]\nted in the decoder as an unclassified TypeError instead of a\nFido2ValidationError. Both checks now reject empty strings.\n\nAdds regression tests for the decoder edge cases and the tightened\nvalidation.",
          "is_bot": false,
          "headline": "Harden base64url decoding and FIDO2 option validation against empty i…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:46:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "416b979cf22bcb44007df0d438cdf103ca803046",
          "body": "btoa() throws InvalidCharacterError for any customState containing\nnon-Latin1 characters (e.g. emoji or accented UTF-8 app state), aborting\nsign-in. It also emits \"+\", \"/\" and \"=\" which are not URL-safe. Encode\nthe customState as base64url of its UTF-8 bytes using the existing\nbufferToBase64Url help\n[…]\nn succeeds, split the random hex prefix\nfrom the base64url suffix, decode it, and return it as the optional\ncustomState field on the resolved TokensFromSignIn. Flows without\ncustomState are unchanged.",
          "is_bot": false,
          "headline": "Make OAuth customState UTF-8 safe and surface it on the callback (#84)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:46:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "eb3a12b66630a5f8f4d220af1afe75fa7a9d1987",
          "body": "signOut() retrieved the session via retrieveTokens(), which drops tokens\nwhose access token has expired as a safety net and returns undefined. So\nwhen a user signed out after their access token expired, signOut logged\n\"No tokens in storage to delete\", reported SIGNED_OUT, but left\nrefreshToken, Last\n[…]\ntests covering an expired access token with a valid\nrefresh token (storage cleared + token revoked) and access-only sessions\nwith no refresh token, both valid and expired (storage cleared, no\nrevoke).",
          "is_bot": false,
          "headline": "Fix signOut no-op when access token is already expired (#85)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-06-10T18:45:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "43f19da4fa41954f658c6c5b3cf903e577fb5dda",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.98 to 1.0.99",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2026-05-31T15:48:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "155e8c1626900b1ce1efc0a1a64040afd53f7bda",
          "body": "The enterprise Actions policy requires every action — including GitHub-owned\nones — to be pinned to a full-length commit SHA. Tags (actions/checkout@v4,\nactions/setup-node@v4) are rejected and the run fails at startup\n(startup_failure) before any step ran. This is what was blocking every\nworkflow_dispatch.\n\nPin to the latest releases:\n- actions/checkout   -> de0fac2e4500dabe0009e67214ff5f5447ce83dd (v6.0.2)\n- actions/setup-node -> 48b55a011bda9f5d6aeb4c2d9c7362e8dae4041e (v6.4.0)",
          "is_bot": false,
          "headline": "publish: pin actions to full-length commit SHAs (#50)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-05-31T15:48:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3804d7efda2fe370c6ede669812ee5dc49fad8d1",
          "body": "The repo restricts Actions to an allowlist (allowed_actions=selected) that\ndoes not include softprops/action-gh-release, so the publish workflow failed\nat startup (startup_failure) the moment it was dispatched.\n\nReplace that third-party action with the pre-installed gh CLI\n(`gh release create`), whi\n[…]\no allowlist entry and removes a\nthird-party dependency from the release path. Release-notes input is passed\nvia env to avoid shell injection, preserving the prior body + auto-generated\nnotes behavior.",
          "is_bot": false,
          "headline": "publish: create GitHub Release via gh CLI (allowlist-safe) (#49)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-05-31T15:21:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2267d89cf502e2e15c5c39bf0d98d80f33119759",
          "body": "…#48)\n\n* publish: use npm Trusted Publishing (OIDC) instead of NPM_TOKEN\n\nSwitch the npm publish step to OIDC-based Trusted Publishing:\n- add `id-token: write` permission (kept `contents: write` for the\n  version commit/tag/push and GitHub release)\n- bump Node to 22.x and upgrade npm to >= 11.5.1 (T\n[…]\n\n  default registry lets OIDC handle authentication.\n- Pin `npm@11.5.1` instead of `npm@latest` to avoid a mutable supply-chain\n  dependency on the privileged (id-token + contents:write) release path.",
          "is_bot": false,
          "headline": "publish.yml: use npm Trusted Publishing (OIDC) instead of NPM_TOKEN (…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-05-30T21:06:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ba586b6504029e13316a6455c31f491e73d4c9e8",
          "body": "Bumps the npm_and_yarn group with 2 updates in the / directory: [minimatch](https://github.com/isaacs/minimatch) and [js-yaml](https://github.com/nodeca/js-yaml).\n\n\nUpdates `minimatch` from 3.1.2 to 3.1.5\n- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)\n- [Commits](https://g\n[…]\n dependency-type: indirect\n  dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump the npm_and_yarn group across 1 directory with 2 updates (#47)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-29T19:32:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3a0011993c935c7a39d129471ebad23954c17988",
          "body": "The library talks to Cognito entirely through its own fetch-based client\n(srp.ts, cognito-api.ts, hosted-oauth.ts). @aws-sdk/client-cognito-identity-provider\nis not imported anywhere in the source and is not re-exported from any\npackage entrypoint, so it is dead weight in the dependency tree.\n\nRemov\n[…]\nuntime behavior. This supersedes the lockfile-only bumps\nin #40/#39, which only churned versions of those same unused transitives.\n\nVerified: tsc (client/tsconfig) clean, full jest suite passes (182).",
          "is_bot": false,
          "headline": "Remove unused @aws-sdk/client-cognito-identity-provider dependency (#46)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-05-29T19:27:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "702536390d4dcc2afd60b82dde6ea7b00722fd0f",
          "body": "Bumps the npm_and_yarn group with 1 update in the / directory: [fast-xml-parser](https://github.com/NaturalIntelligence/fast-xml-parser).\n\n\nUpdates `fast-xml-parser` from 4.4.1 to 5.7.2\n- [Release notes](https://github.com/NaturalIntelligence/fast-xml-parser/releases)\n- [Changelog](https://github.co\n[…]\n dependency-type: indirect\n  dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump fast-xml-parser in the npm_and_yarn group across 1 directory (#40)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-29T18:49:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "71e68e902f72f7d7c7d29e7bc0645c2e4aa39c15",
          "body": "Bumps the npm_and_yarn group with 1 update in the / directory: [picomatch](https://github.com/micromatch/picomatch).\n\n\nUpdates `picomatch` from 2.3.1 to 2.3.2\n- [Release notes](https://github.com/micromatch/picomatch/releases)\n- [Changelog](https://github.com/micromatch/picomatch/blob/master/CHANGEL\n[…]\n dependency-type: indirect\n  dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump picomatch in the npm_and_yarn group across 1 directory (#41)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-29T18:49:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2c90089fefd74841a0ae9087a07c9155c55dfba8",
          "body": "Bumps the npm_and_yarn group with 1 update in the / directory: [flatted](https://github.com/WebReflection/flatted).\n\n\nUpdates `flatted` from 3.3.1 to 3.4.2\n- [Commits](https://github.com/WebReflection/flatted/compare/v3.3.1...v3.4.2)\n\n---\nupdated-dependencies:\n- dependency-name: flatted\n  dependency\n[…]\n dependency-type: indirect\n  dependency-group: npm_and_yarn\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "Bump flatted in the npm_and_yarn group across 1 directory (#42)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-05-29T18:48:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a6a0e37bfa680ffe8fd0fcdf57061bb6179413ac",
          "body": "…p login loop) (#43)\n\n* Tolerate client clock skew when validating token expiry\n\nA device whose clock is fast by more than the access token's lifetime\ntreated every freshly-issued token as already-expired: token validity\ncompared the server-issued `exp` claim against local `Date.now()` with no\nskew \n[…]\nCarry clockDriftMs over.\n- common.ts: signOut now removes the persisted clockDriftMs storage key\n  alongside the other per-user keys.\n- test/clock-skew.test.ts: add a sign-out cleanup regression test.",
          "is_bot": false,
          "headline": "Tolerate client clock skew when validating token expiry (fixes deskto…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2026-05-29T18:35:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9af1cbf6a0fe103ecc36288fc4c5b121609ec64a",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.97 to 1.0.98",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-11-04T18:21:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a57c18aabc3b9561e24ffa62e5e3c617fd54a14",
          "body": "* Ensure UI never hangs on MFA status loading failures\n\n* add silent retry for mfa status\n\n* run earlier",
          "is_bot": false,
          "headline": "Ensure UI never hangs on MFA status loading failures (#37)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-11-04T18:21:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d9b10157e45c70316905bc7d6876048cd2f83f75",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.96 to 1.0.97",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-10-06T20:02:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8a35c15c5c03ac3e01ebfaaa4e202f65dde0d384",
          "body": "* Add comprehensive debug logging for FIDO2 authentication flows\n\n* simpler flow\n\n* merge server and client credentials in auth flow",
          "is_bot": false,
          "headline": "Add comprehensive debug logging to FIDO2 authentication flows (#35)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-10-06T20:01:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c076c2e3927ffe8eca2c2b419e83c3e7245be1f8",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.95 to 1.0.96",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-10-06T15:41:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af05372cb331f705f18aea1b2164e0bd10244ca2",
          "body": "… autofill (#34)\n\n* Add prepareFido2SignIn for WebAuthn conditional mediation and passkey autofill\n\n* update tests\n\n* handle case when username is different",
          "is_bot": false,
          "headline": "Add prepareFido2SignIn for WebAuthn conditional mediation and passkey…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-10-06T15:40:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f73a826cdbfeb353fd2896f8df163267b29e6006",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.94 to 1.0.95",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-10-05T19:49:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "223c4a9afabc6d59845e02634cfb5f7d120f0fc0",
          "body": "* Add WebAuthn conditional mediation and passkey autofill support\n\n* rm create mediation",
          "is_bot": false,
          "headline": "Add WebAuthn conditional mediation and passkey autofill support (#33)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-10-05T19:49:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "61eab67deb8e3bfde3227879a19d676fafda481d",
          "body": "…cation flows (#32)\n\n* Add support for conditional mediation and automatic passkey creation\n\n* proper types and immediate mode\n\n* refactor tests",
          "is_bot": false,
          "headline": "Add WebAuthn mediation support for conditional and immediate authenti…",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-10-05T19:13:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "112c801a45c9b7c0e4e0461d7eba07c7e76cc326",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.93 to 1.0.94",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-10-03T00:04:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2db9179d0f520cddab113ddbb48b3a05472b34a3",
          "body": null,
          "is_bot": false,
          "headline": "fix build (#31)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-10-03T00:03:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d893ddca8f3d8d96c5fe4eae45da25d67865dc7b",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.92 to 1.0.93",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-10-02T23:53:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f261fb4b0f035bc34eb10eaa513c6c3c6895159a",
          "body": null,
          "is_bot": false,
          "headline": "user friendly error messages (#30)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-10-02T23:52:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "59cc1a0dd9a9b2bd4e1b998db6f6829b6a9e4462",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.91 to 1.0.92",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-10-02T22:13:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1b7bb64e506e1a73049452b48c1e43a9e5e85c25",
          "body": null,
          "is_bot": false,
          "headline": "export errors in package (#29)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-10-02T22:12:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eff8756a7a991f699f1bd2d70a506e67100314ff",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.90 to 1.0.91",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-10-02T21:53:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "01d5888f8e1efb51f8c9306b4e3cf70819088802",
          "body": "* Add typed error handling with custom error classes for FIDO2/WebAuthn operations\n\n* tests and better runtime checker\n\n* add more tests",
          "is_bot": false,
          "headline": "Add typed error handling for WebAuthn operations (#28)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-10-02T21:52:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8127dc061d49bbb7a9a8e63af927866db7588ada",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.89 to 1.0.90",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-09-09T20:17:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4b74532af98697a58a40daee40885681e4e5812",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.88 to 1.0.89",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-09-09T19:58:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4eb658593dfde16f721fe218ef0c88c288ebad63",
          "body": "* react: add reliable MFA readiness signal (mfaStatusReady)\n\n- Add mfaStatusReady to PasswordlessState and initialize to false\n- Extend action union with SET_MFA_STATUS_READY and reducer case\n- Include mfaStatusReady in context memo deps and hook state\n- Mark readiness true after successful getUser/\n[…]\nhat TOTP MFA status has been fetched and is current for the active access token.\n\n* test(react): increase hooks.tsx patch coverage (REDIRECT parsing, OAuth callback, error boundary, activity tracking)",
          "is_bot": false,
          "headline": "react: add reliable MFA readiness signal (mfaStatusReady) (#27)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-09-09T19:57:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "94e2ed9173c40ef18a81049741d754e22454e74a",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.87 to 1.0.88",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-07-28T15:12:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c8e57dac8821d98a05ca0692340e78a3311f8b8",
          "body": "* Add grace period during token refresh to prevent temporary logout\n\n* Add grace period during token refresh to prevent temporary logout\n\nThis fix addresses the \"30-minute lottery bug\" where users were temporarily\nlogged out when their tokens expired during page navigation while refresh\nwas in progr\n[…]\nsers remain signed in during the refresh process,\npreventing the temporary logout that occurred in 0.08% of sessions.\n\n* Update hooks.tsx\n\n* prettier\n\n* fix NaN check\n\n* fix test to match source logic",
          "is_bot": false,
          "headline": "Add grace period during token refresh to prevent temporary logout (#25)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-07-28T14:44:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "607fc3a657558e9b927d5ae8b0b90e328d85c47e",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.86 to 1.0.87",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-07-23T13:32:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "40dbb3794dd75dae31c306a54e55d4faf9d7bf03",
          "body": null,
          "is_bot": false,
          "headline": "add more tests (#24)",
          "author_name": "Amit Biswas",
          "author_login": "akbisw",
          "committed_at": "2025-07-23T13:31:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dcdf7e57c0cce438e354307b1586e55a654a87e6",
          "body": null,
          "is_bot": false,
          "headline": "Bump version from 1.0.85 to 1.0.86",
          "author_name": "GitHub Action",
          "author_login": "actions-user",
          "committed_at": "2025-07-23T12:02:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 96,
      "commits_last_year": 97,
      "latest_release_at": "2026-07-20T22:36:18Z",
      "latest_release_tag": "v1.0.104",
      "releases_from_tags": false,
      "days_since_last_push": 4,
      "active_weeks_last_year": 11,
      "days_since_latest_release": 6,
      "mean_days_between_releases": 32
    },
    "community": {
      "has_readme": false,
      "has_license": false,
      "has_description": false,
      "has_contributing": false,
      "health_percentage": null,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@joinmeow/cognito-passwordless-auth",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "AWS",
            "Cognito",
            "FIDO2",
            "Passwordless",
            "WebAuthn",
            "passkeys"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@joinmeow/cognito-passwordless-auth",
          "is_deprecated": false,
          "latest_version": "1.0.104",
          "repository_url": "https://github.com/joinmeow/amazon-cognito-passwordless-auth",
          "versions_count": 100,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 2,
          "monthly_downloads": 8713,
          "first_published_at": "2025-04-23T17:21:03.075000Z",
          "latest_published_at": "2026-07-20T22:36:16.595000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "client/tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 96149,
      "source_files_sampled": 92,
      "oversized_source_files": 3,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 3,
        "malicious_count": 0,
        "assessed_package": "npm:@joinmeow/cognito-passwordless-auth@1.0.104",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "aws-jwt-verify",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.0.1"
        },
        {
          "name": "cbor",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^9.0.2"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "aws-jwt-verify",
            "direct": true,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "cbor",
            "direct": true,
            "version": "9.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@ampproject/remapping",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@asamuzakjp/css-color",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/code-frame",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/compat-data",
            "direct": false,
            "version": "7.27.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/core",
            "direct": false,
            "version": "7.27.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/generator",
            "direct": false,
            "version": "7.27.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-compilation-targets",
            "direct": false,
            "version": "7.27.2",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-module-imports",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-module-transforms",
            "direct": false,
            "version": "7.27.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-plugin-utils",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-string-parser",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-identifier",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-option",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helpers",
            "direct": false,
            "version": "7.27.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/parser",
            "direct": false,
            "version": "7.27.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-async-generators",
            "direct": false,
            "version": "7.8.4",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-bigint",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-class-properties",
            "direct": false,
            "version": "7.12.13",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-class-static-block",
            "direct": false,
            "version": "7.14.5",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-import-attributes",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-import-meta",
            "direct": false,
            "version": "7.10.4",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-json-strings",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-jsx",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-logical-assignment-operators",
            "direct": false,
            "version": "7.10.4",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-nullish-coalescing-operator",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-numeric-separator",
            "direct": false,
            "version": "7.10.4",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-object-rest-spread",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-optional-catch-binding",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-optional-chaining",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-private-property-in-object",
            "direct": false,
            "version": "7.14.5",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-top-level-await",
            "direct": false,
            "version": "7.14.5",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-typescript",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/runtime",
            "direct": false,
            "version": "7.27.6",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/template",
            "direct": false,
            "version": "7.27.2",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/traverse",
            "direct": false,
            "version": "7.27.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/types",
            "direct": false,
            "version": "7.27.3",
            "ecosystem": "npm"
          },
          {
            "name": "@bcoe/v8-coverage",
            "direct": false,
            "version": "0.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "@cspotcode/source-map-support",
            "direct": false,
            "version": "0.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/color-helpers",
            "direct": false,
            "version": "5.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-calc",
            "direct": false,
            "version": "2.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-color-parser",
            "direct": false,
            "version": "3.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-parser-algorithms",
            "direct": false,
            "version": "3.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@csstools/css-tokenizer",
            "direct": false,
            "version": "3.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/aix-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/android-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/darwin-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/freebsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-loong64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-mips64el",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-ppc64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-riscv64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-s390x",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/linux-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/netbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openbsd-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/openharmony-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/sunos-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-arm64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-ia32",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@esbuild/win32-x64",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint-community/eslint-utils",
            "direct": false,
            "version": "4.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint-community/regexpp",
            "direct": false,
            "version": "4.10.1",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/eslintrc",
            "direct": false,
            "version": "2.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "@eslint/js",
            "direct": false,
            "version": "8.57.0",
            "ecosystem": "npm"
          },
          {
            "name": "@humanwhocodes/config-array",
            "direct": false,
            "version": "0.11.14",
            "ecosystem": "npm"
          },
          {
            "name": "@humanwhocodes/module-importer",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@humanwhocodes/object-schema",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@istanbuljs/load-nyc-config",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@istanbuljs/schema",
            "direct": false,
            "version": "0.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/console",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/core",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/environment",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/environment",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/environment-jsdom-abstract",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/expect",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/expect-utils",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/fake-timers",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/fake-timers",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/globals",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/pattern",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/reporters",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/schemas",
            "direct": false,
            "version": "29.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/schemas",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/source-map",
            "direct": false,
            "version": "29.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/test-result",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/test-sequencer",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/transform",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/types",
            "direct": false,
            "version": "29.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/types",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/gen-mapping",
            "direct": false,
            "version": "0.3.8",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/resolve-uri",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/set-array",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/sourcemap-codec",
            "direct": false,
            "version": "1.4.15",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/trace-mapping",
            "direct": false,
            "version": "0.3.25",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/trace-mapping",
            "direct": false,
            "version": "0.3.9",
            "ecosystem": "npm"
          },
          {
            "name": "@nodelib/fs.scandir",
            "direct": false,
            "version": "2.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "@nodelib/fs.stat",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@nodelib/fs.walk",
            "direct": false,
            "version": "1.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "@sinclair/typebox",
            "direct": false,
            "version": "0.27.8",
            "ecosystem": "npm"
          },
          {
            "name": "@sinclair/typebox",
            "direct": false,
            "version": "0.34.33",
            "ecosystem": "npm"
          },
          {
            "name": "@sinonjs/commons",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@sinonjs/fake-timers",
            "direct": false,
            "version": "10.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@sinonjs/fake-timers",
            "direct": false,
            "version": "13.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@testing-library/dom",
            "direct": false,
            "version": "10.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "@testing-library/react",
            "direct": false,
            "version": "16.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@tsconfig/node10",
            "direct": false,
            "version": "1.0.11",
            "ecosystem": "npm"
          },
          {
            "name": "@tsconfig/node12",
            "direct": false,
            "version": "1.0.11",
            "ecosystem": "npm"
          },
          {
            "name": "@tsconfig/node14",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@tsconfig/node16",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/aria-query",
            "direct": false,
            "version": "5.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__core",
            "direct": false,
            "version": "7.20.5",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__generator",
            "direct": false,
            "version": "7.27.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__template",
            "direct": false,
            "version": "7.4.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__traverse",
            "direct": false,
            "version": "7.20.7",
            "ecosystem": "npm"
          },
          {
            "name": "@types/graceful-fs",
            "direct": false,
            "version": "4.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "@types/istanbul-lib-coverage",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/istanbul-lib-report",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/istanbul-reports",
            "direct": false,
            "version": "3.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/jest",
            "direct": false,
            "version": "29.5.14",
            "ecosystem": "npm"
          },
          {
            "name": "@types/jsdom",
            "direct": false,
            "version": "21.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "@types/json5",
            "direct": false,
            "version": "0.0.29",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "20.14.5",
            "ecosystem": "npm"
          },
          {
            "name": "@types/prop-types",
            "direct": false,
            "version": "15.7.12",
            "ecosystem": "npm"
          },
          {
            "name": "@types/react",
            "direct": false,
            "version": "18.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/stack-utils",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/tough-cookie",
            "direct": false,
            "version": "4.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@types/yargs",
            "direct": false,
            "version": "17.0.33",
            "ecosystem": "npm"
          },
          {
            "name": "@types/yargs-parser",
            "direct": false,
            "version": "21.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/eslint-plugin",
            "direct": false,
            "version": "7.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/parser",
            "direct": false,
            "version": "7.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/scope-manager",
            "direct": false,
            "version": "7.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/type-utils",
            "direct": false,
            "version": "7.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/types",
            "direct": false,
            "version": "7.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/typescript-estree",
            "direct": false,
            "version": "7.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/utils",
            "direct": false,
            "version": "7.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "@typescript-eslint/visitor-keys",
            "direct": false,
            "version": "7.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "@ungap/structured-clone",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "acorn",
            "direct": false,
            "version": "8.12.0",
            "ecosystem": "npm"
          },
          {
            "name": "acorn-jsx",
            "direct": false,
            "version": "5.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "acorn-walk",
            "direct": false,
            "version": "8.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "agent-base",
            "direct": false,
            "version": "7.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "ajv",
            "direct": false,
            "version": "6.12.6",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-escapes",
            "direct": false,
            "version": "4.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-escapes",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "6.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "6.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "anymatch",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "arg",
            "direct": false,
            "version": "4.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "argparse",
            "direct": false,
            "version": "1.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "argparse",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "aria-query",
            "direct": false,
            "version": "5.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "array-buffer-byte-length",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "array-includes",
            "direct": false,
            "version": "3.1.8",
            "ecosystem": "npm"
          },
          {
            "name": "array-union",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "array.prototype.findlast",
            "direct": false,
            "version": "1.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "array.prototype.findlastindex",
            "direct": false,
            "version": "1.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "array.prototype.flat",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "array.prototype.flatmap",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "array.prototype.toreversed",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "array.prototype.tosorted",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "arraybuffer.prototype.slice",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "async",
            "direct": false,
            "version": "3.2.6",
            "ecosystem": "npm"
          },
          {
            "name": "available-typed-arrays",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "babel-jest",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "babel-plugin-istanbul",
            "direct": false,
            "version": "6.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "babel-plugin-jest-hoist",
            "direct": false,
            "version": "29.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "babel-preset-current-node-syntax",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "babel-preset-jest",
            "direct": false,
            "version": "29.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "1.1.11",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "braces",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "browserslist",
            "direct": false,
            "version": "4.25.0",
            "ecosystem": "npm"
          },
          {
            "name": "bs-logger",
            "direct": false,
            "version": "0.2.6",
            "ecosystem": "npm"
          },
          {
            "name": "bser",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "buffer-from",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "call-bind",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "callsites",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "camelcase",
            "direct": false,
            "version": "5.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "camelcase",
            "direct": false,
            "version": "6.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "caniuse-lite",
            "direct": false,
            "version": "1.0.30001720",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": false,
            "version": "4.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": false,
            "version": "5.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "char-regex",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "ci-info",
            "direct": false,
            "version": "3.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "ci-info",
            "direct": false,
            "version": "4.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "cjs-module-lexer",
            "direct": false,
            "version": "1.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "cli-cursor",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "cli-truncate",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "cliui",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "co",
            "direct": false,
            "version": "4.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "collect-v8-coverage",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "color-convert",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "color-name",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "colorette",
            "direct": false,
            "version": "2.0.20",
            "ecosystem": "npm"
          },
          {
            "name": "commander",
            "direct": false,
            "version": "14.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "concat-map",
            "direct": false,
            "version": "0.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "convert-source-map",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "create-jest",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "create-require",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "cssstyle",
            "direct": false,
            "version": "4.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "csstype",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "data-urls",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "data-view-buffer",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "data-view-byte-length",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "data-view-byte-offset",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "3.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "4.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "decimal.js",
            "direct": false,
            "version": "10.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "dedent",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "deep-is",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "deepmerge",
            "direct": false,
            "version": "4.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "define-data-property",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "define-properties",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "dequal",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "detect-newline",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "diff",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "diff-sequences",
            "direct": false,
            "version": "29.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "dir-glob",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "doctrine",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "doctrine",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "dom-accessibility-api",
            "direct": false,
            "version": "0.5.16",
            "ecosystem": "npm"
          },
          {
            "name": "ejs",
            "direct": false,
            "version": "3.1.10",
            "ecosystem": "npm"
          },
          {
            "name": "electron-to-chromium",
            "direct": false,
            "version": "1.5.161",
            "ecosystem": "npm"
          },
          {
            "name": "emittery",
            "direct": false,
            "version": "0.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "10.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "entities",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "environment",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "error-ex",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "es-abstract",
            "direct": false,
            "version": "1.23.3",
            "ecosystem": "npm"
          },
          {
            "name": "es-define-property",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-errors",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-iterator-helpers",
            "direct": false,
            "version": "1.0.19",
            "ecosystem": "npm"
          },
          {
            "name": "es-object-atoms",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-set-tostringtag",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "es-shim-unscopables",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "es-to-primitive",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "esbuild",
            "direct": false,
            "version": "0.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "escalade",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "escape-string-regexp",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "escape-string-regexp",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint",
            "direct": false,
            "version": "8.57.0",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-import-resolver-node",
            "direct": false,
            "version": "0.3.9",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-module-utils",
            "direct": false,
            "version": "2.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-plugin-header",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-plugin-import",
            "direct": false,
            "version": "2.29.1",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-plugin-react",
            "direct": false,
            "version": "7.34.2",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-plugin-react-hooks",
            "direct": false,
            "version": "4.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-plugin-security",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-scope",
            "direct": false,
            "version": "7.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "eslint-visitor-keys",
            "direct": false,
            "version": "3.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "espree",
            "direct": false,
            "version": "9.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "esprima",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "esquery",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "esrecurse",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "estraverse",
            "direct": false,
            "version": "5.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "esutils",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "eventemitter3",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "execa",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "exit",
            "direct": false,
            "version": "0.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "expect",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-deep-equal",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "fast-glob",
            "direct": false,
            "version": "3.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "fast-json-stable-stringify",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-levenshtein",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "fastq",
            "direct": false,
            "version": "1.17.1",
            "ecosystem": "npm"
          },
          {
            "name": "fb-watchman",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "file-entry-cache",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "filelist",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "fill-range",
            "direct": false,
            "version": "7.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "find-up",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "find-up",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "flat-cache",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "flatted",
            "direct": false,
            "version": "3.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "for-each",
            "direct": false,
            "version": "0.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "fs.realpath",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "function-bind",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "function.prototype.name",
            "direct": false,
            "version": "1.1.6",
            "ecosystem": "npm"
          },
          {
            "name": "functions-have-names",
            "direct": false,
            "version": "1.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "gensync",
            "direct": false,
            "version": "1.0.0-beta.2",
            "ecosystem": "npm"
          },
          {
            "name": "get-caller-file",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "get-east-asian-width",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-intrinsic",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "get-package-type",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-stream",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "get-symbol-description",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "glob",
            "direct": false,
            "version": "7.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "glob-parent",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "glob-parent",
            "direct": false,
            "version": "6.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "globals",
            "direct": false,
            "version": "11.12.0",
            "ecosystem": "npm"
          },
          {
            "name": "globals",
            "direct": false,
            "version": "13.24.0",
            "ecosystem": "npm"
          },
          {
            "name": "globalthis",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "globby",
            "direct": false,
            "version": "11.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "gopd",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "graceful-fs",
            "direct": false,
            "version": "4.2.11",
            "ecosystem": "npm"
          },
          {
            "name": "graphemer",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-bigints",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-property-descriptors",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "has-proto",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "has-symbols",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "has-tostringtag",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "hasown",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "html-encoding-sniffer",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "html-escaper",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "http-proxy-agent",
            "direct": false,
            "version": "7.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "https-proxy-agent",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "human-signals",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "husky",
            "direct": false,
            "version": "9.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "iconv-lite",
            "direct": false,
            "version": "0.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "ignore",
            "direct": false,
            "version": "5.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "import-fresh",
            "direct": false,
            "version": "3.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "import-local",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "imurmurhash",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "inflight",
            "direct": false,
            "version": "1.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "inherits",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "internal-slot",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "is-array-buffer",
            "direct": false,
            "version": "3.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "is-arrayish",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-async-function",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-bigint",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "is-boolean-object",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "is-callable",
            "direct": false,
            "version": "1.2.7",
            "ecosystem": "npm"
          },
          {
            "name": "is-core-module",
            "direct": false,
            "version": "2.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-data-view",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-date-object",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "is-extglob",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-finalizationregistry",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "is-fullwidth-code-point",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-fullwidth-code-point",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-fullwidth-code-point",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-generator-fn",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-generator-function",
            "direct": false,
            "version": "1.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "is-glob",
            "direct": false,
            "version": "4.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-map",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-negative-zero",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-number",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-number-object",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "is-path-inside",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-potential-custom-element-name",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-regex",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "is-set",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-shared-array-buffer",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "is-stream",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-string",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "is-symbol",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "is-typed-array",
            "direct": false,
            "version": "1.1.13",
            "ecosystem": "npm"
          },
          {
            "name": "is-weakmap",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "is-weakref",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "is-weakset",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "isarray",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-coverage",
            "direct": false,
            "version": "3.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-instrument",
            "direct": false,
            "version": "5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-instrument",
            "direct": false,
            "version": "6.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-report",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-source-maps",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-reports",
            "direct": false,
            "version": "3.1.7",
            "ecosystem": "npm"
          },
          {
            "name": "iterator.prototype",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "jake",
            "direct": false,
            "version": "10.9.2",
            "ecosystem": "npm"
          },
          {
            "name": "jest",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-changed-files",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-circus",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-cli",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-config",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-diff",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-docblock",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-each",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-environment-jsdom",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "jest-environment-node",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-get-type",
            "direct": false,
            "version": "29.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "jest-haste-map",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-leak-detector",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-localstorage-mock",
            "direct": false,
            "version": "2.4.26",
            "ecosystem": "npm"
          },
          {
            "name": "jest-matcher-utils",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-message-util",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-message-util",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "jest-mock",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-mock",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "jest-pnp-resolver",
            "direct": false,
            "version": "1.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "jest-regex-util",
            "direct": false,
            "version": "29.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "jest-regex-util",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "jest-resolve",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-resolve-dependencies",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-runner",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-runtime",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-snapshot",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-util",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-util",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "jest-validate",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-watcher",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-worker",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-tokens",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": false,
            "version": "3.14.2",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "jsdom",
            "direct": false,
            "version": "26.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "jsesc",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-buffer",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-parse-even-better-errors",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-schema-traverse",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "json-stable-stringify-without-jsonify",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "json5",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "json5",
            "direct": false,
            "version": "2.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "jsx-ast-utils",
            "direct": false,
            "version": "3.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "keyv",
            "direct": false,
            "version": "4.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "kleur",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "leven",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "levn",
            "direct": false,
            "version": "0.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "lilconfig",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "lines-and-columns",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "lint-staged",
            "direct": false,
            "version": "16.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "listr2",
            "direct": false,
            "version": "8.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "locate-path",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "locate-path",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "lodash.memoize",
            "direct": false,
            "version": "4.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "lodash.merge",
            "direct": false,
            "version": "4.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "log-update",
            "direct": false,
            "version": "6.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "loose-envify",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "10.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "lz-string",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "make-dir",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "make-error",
            "direct": false,
            "version": "1.3.6",
            "ecosystem": "npm"
          },
          {
            "name": "makeerror",
            "direct": false,
            "version": "1.0.12",
            "ecosystem": "npm"
          },
          {
            "name": "merge-stream",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "merge2",
            "direct": false,
            "version": "1.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "micromatch",
            "direct": false,
            "version": "4.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "mimic-fn",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "mimic-function",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "3.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "5.1.9",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "9.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "minimist",
            "direct": false,
            "version": "1.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "nano-spawn",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "natural-compare",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-int64",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-releases",
            "direct": false,
            "version": "2.0.19",
            "ecosystem": "npm"
          },
          {
            "name": "nofilter",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "normalize-path",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "npm-run-path",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "nwsapi",
            "direct": false,
            "version": "2.2.20",
            "ecosystem": "npm"
          },
          {
            "name": "object-assign",
            "direct": false,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "object-inspect",
            "direct": false,
            "version": "1.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "object-keys",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "object.assign",
            "direct": false,
            "version": "4.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "object.entries",
            "direct": false,
            "version": "1.1.8",
            "ecosystem": "npm"
          },
          {
            "name": "object.fromentries",
            "direct": false,
            "version": "2.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "object.groupby",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "object.hasown",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "object.values",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "once",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "onetime",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "onetime",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "optionator",
            "direct": false,
            "version": "0.9.4",
            "ecosystem": "npm"
          },
          {
            "name": "p-limit",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-limit",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-locate",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-locate",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-try",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "parent-module",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "parse-json",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "parse5",
            "direct": false,
            "version": "7.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-exists",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-is-absolute",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-parse",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "path-type",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "2.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "pidtree",
            "direct": false,
            "version": "0.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "pirates",
            "direct": false,
            "version": "4.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "pkg-dir",
            "direct": false,
            "version": "4.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "possible-typed-array-names",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "prelude-ls",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "prettier",
            "direct": false,
            "version": "3.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "pretty-format",
            "direct": false,
            "version": "27.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "pretty-format",
            "direct": false,
            "version": "29.7.0",
            "ecosystem": "npm"
          },
          {
            "name": "pretty-format",
            "direct": false,
            "version": "30.0.0-beta.3",
            "ecosystem": "npm"
          },
          {
            "name": "prompts",
            "direct": false,
            "version": "2.4.2",
            "ecosystem": "npm"
          },
          {
            "name": "prop-types",
            "direct": false,
            "version": "15.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "punycode",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "pure-rand",
            "direct": false,
            "version": "6.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "queue-microtask",
            "direct": false,
            "version": "1.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "react",
            "direct": false,
            "version": "18.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "react-dom",
            "direct": false,
            "version": "18.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "react-is",
            "direct": false,
            "version": "16.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "react-is",
            "direct": false,
            "version": "17.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "react-is",
            "direct": false,
            "version": "18.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "reflect.getprototypeof",
            "direct": false,
            "version": "1.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "regexp-tree",
            "direct": false,
            "version": "0.1.27",
            "ecosystem": "npm"
          },
          {
            "name": "regexp.prototype.flags",
            "direct": false,
            "version": "1.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "require-directory",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "resolve",
            "direct": false,
            "version": "1.22.8",
            "ecosystem": "npm"
          },
          {
            "name": "resolve",
            "direct": false,
            "version": "2.0.0-next.5",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-cwd",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-from",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-from",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "resolve.exports",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "restore-cursor",
            "direct": false,
            "version": "5.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "reusify",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "rfdc",
            "direct": false,
            "version": "1.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "rimraf",
            "direct": false,
            "version": "3.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "rrweb-cssom",
            "direct": false,
            "version": "0.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "run-parallel",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "safe-array-concat",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "safe-regex",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "safe-regex-test",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "safer-buffer",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "saxes",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "scheduler",
            "direct": false,
            "version": "0.23.2",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "6.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "set-function-length",
            "direct": false,
            "version": "1.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "set-function-name",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-command",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-regex",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel",
            "direct": false,
            "version": "1.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "signal-exit",
            "direct": false,
            "version": "3.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "signal-exit",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "sisteransi",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "slash",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "slice-ansi",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "slice-ansi",
            "direct": false,
            "version": "7.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "source-map",
            "direct": false,
            "version": "0.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "source-map-support",
            "direct": false,
            "version": "0.5.13",
            "ecosystem": "npm"
          },
          {
            "name": "sprintf-js",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "stack-utils",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "string-argv",
            "direct": false,
            "version": "0.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "string-length",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "4.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "string.prototype.matchall",
            "direct": false,
            "version": "4.0.11",
            "ecosystem": "npm"
          },
          {
            "name": "string.prototype.trim",
            "direct": false,
            "version": "1.2.9",
            "ecosystem": "npm"
          },
          {
            "name": "string.prototype.trimend",
            "direct": false,
            "version": "1.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "string.prototype.trimstart",
            "direct": false,
            "version": "1.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "7.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-bom",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-bom",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-final-newline",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-json-comments",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "8.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "supports-preserve-symlinks-flag",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "symbol-tree",
            "direct": false,
            "version": "3.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "test-exclude",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "text-table",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "tldts",
            "direct": false,
            "version": "6.1.86",
            "ecosystem": "npm"
          },
          {
            "name": "tldts-core",
            "direct": false,
            "version": "6.1.86",
            "ecosystem": "npm"
          },
          {
            "name": "tmpl",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "to-regex-range",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "tough-cookie",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "tr46",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "ts-api-utils",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "ts-jest",
            "direct": false,
            "version": "29.3.4",
            "ecosystem": "npm"
          },
          {
            "name": "ts-node",
            "direct": false,
            "version": "10.9.2",
            "ecosystem": "npm"
          },
          {
            "name": "tsconfig-paths",
            "direct": false,
            "version": "3.15.0",
            "ecosystem": "npm"
          },
          {
            "name": "type-check",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "type-detect",
            "direct": false,
            "version": "4.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "type-fest",
            "direct": false,
            "version": "0.20.2",
            "ecosystem": "npm"
          },
          {
            "name": "type-fest",
            "direct": false,
            "version": "0.21.3",
            "ecosystem": "npm"
          },
          {
            "name": "type-fest",
            "direct": false,
            "version": "4.41.0",
            "ecosystem": "npm"
          },
          {
            "name": "typed-array-buffer",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "typed-array-byte-length",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "typed-array-byte-offset",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "typed-array-length",
            "direct": false,
            "version": "1.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "typescript",
            "direct": false,
            "version": "5.4.5",
            "ecosystem": "npm"
          },
          {
            "name": "unbox-primitive",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "5.26.5",
            "ecosystem": "npm"
          },
          {
            "name": "update-browserslist-db",
            "direct": false,
            "version": "1.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "uri-js",
            "direct": false,
            "version": "4.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "v8-compile-cache-lib",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "v8-to-istanbul",
            "direct": false,
            "version": "9.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "w3c-xmlserializer",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "walker",
            "direct": false,
            "version": "1.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "webidl-conversions",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "whatwg-encoding",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "whatwg-mimetype",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "whatwg-url",
            "direct": false,
            "version": "14.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "which-boxed-primitive",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "which-builtin-type",
            "direct": false,
            "version": "1.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "which-collection",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "which-typed-array",
            "direct": false,
            "version": "1.1.15",
            "ecosystem": "npm"
          },
          {
            "name": "word-wrap",
            "direct": false,
            "version": "1.2.5",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "9.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrappy",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "write-file-atomic",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "ws",
            "direct": false,
            "version": "8.18.2",
            "ecosystem": "npm"
          },
          {
            "name": "xml-name-validator",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "xmlchars",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "y18n",
            "direct": false,
            "version": "5.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "yallist",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "yaml",
            "direct": false,
            "version": "2.8.0",
            "ecosystem": "npm"
          },
          {
            "name": "yargs",
            "direct": false,
            "version": "17.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "yargs-parser",
            "direct": false,
            "version": "21.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "yn",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "yocto-queue",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 619,
        "direct_count": 2,
        "indirect_count": 617
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 1,
        "merged_prs": 105,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 5
      },
      "bus_factor": 2,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "akbisw",
          "commits": 188,
          "avatar_url": "https://avatars.githubusercontent.com/u/8528636?v=4"
        },
        {
          "type": "User",
          "login": "actions-user",
          "commits": 102,
          "avatar_url": "https://avatars.githubusercontent.com/u/65916846?v=4"
        },
        {
          "type": "User",
          "login": "ottokruse",
          "commits": 96,
          "avatar_url": "https://avatars.githubusercontent.com/u/6275520?v=4"
        },
        {
          "type": "User",
          "login": "EricBorland",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/6512144?v=4"
        },
        {
          "type": "User",
          "login": "RobHarveyDev",
          "commits": 6,
          "avatar_url": "https://avatars.githubusercontent.com/u/87716995?v=4"
        },
        {
          "type": "User",
          "login": "martinpagelaws",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/128691727?v=4"
        },
        {
          "type": "User",
          "login": "fahadsadiq",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/18647350?v=4"
        },
        {
          "type": "User",
          "login": "tinti",
          "commits": 3,
          "avatar_url": "https://avatars.githubusercontent.com/u/31630?v=4"
        },
        {
          "type": "User",
          "login": "mikemeerschaert",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/2775912?v=4"
        },
        {
          "type": "User",
          "login": "Tameyer41",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/63265436?v=4"
        }
      ],
      "contributors_sampled": 20,
      "top_contributor_share": 0.448
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "main.yml",
        "publish.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        ".eslintrc.cjs"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 9,
            "reason": "24 out of 25 merged PRs checked by a CI test -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/29 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 3 contributing companies or organizations -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 3,
            "reason": "dependency not pinned by hash detected -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "12 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "2ddce40e8a2b8cce16f32bf03fd4b5051de26594",
        "ran_at": "2026-07-27T16:53:56Z",
        "aggregate_score": 4.4,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-24T06:37:05Z",
      "oldest_open_prs": [
        {
          "number": 109,
          "created_at": "2026-07-20T22:38:03Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-23T16:22:55Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/joinmeow/amazon-cognito-passwordless-auth",
    "host": "github.com",
    "name": "amazon-cognito-passwordless-auth",
    "owner": "joinmeow"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 59,
      "inputs": {
        "security": 55,
        "vitality": 83,
        "community": 26,
        "governance": 68,
        "engineering": 53
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 83,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 72,
            "inputs": {
              "commits_last_year": 97,
              "human_commit_share": 0.95,
              "days_since_last_push": 4,
              "active_weeks_last_year": 11
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "11/52 weeks with commits",
                "points": 7.6,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 11
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "97 commits in the last year",
                "points": 17.9,
                "status": "partial",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 97
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 96,
              "latest_release_tag": "v1.0.104",
              "releases_from_tags": false,
              "days_since_latest_release": 6,
              "mean_days_between_releases": 32
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "96 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 96
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~32 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 32
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 4,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 4 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "critical",
        "name": "Community & Adoption",
        "value": 26,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "critical",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 25,
            "inputs": {
              "has_readme": false,
              "has_license": false,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 66,
            "inputs": {
              "packages": [
                "@joinmeow/cognito-passwordless-auth"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 8713
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "8,713 downloads/month across npm",
                "points": 52.5,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 8713,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 68,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "moderate",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "bus_factor": 2,
              "contributors_sampled": 20,
              "top_contributor_share": 0.448
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "2 contributor(s) cover half of all commits",
                "points": 25.2,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 45% of commits",
                "points": 12.4,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 45
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "20 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 20
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "moderate",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 69,
            "inputs": {
              "merged_prs": 105,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 5
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "105/110 decided PRs merged",
                "points": 36.5,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 105,
                      "decided": 110
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/29 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 51,
            "inputs": {
              "followers": 4,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "joinmeow",
              "public_repos": 4,
              "account_age_days": 2000
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "4 followers of joinmeow",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 4,
                      "login": "joinmeow"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "4 public repos, account ~5 yr old",
                "points": 16,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 4
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 5
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@joinmeow/cognito-passwordless-auth"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "100 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 53,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".eslintrc.cjs",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".eslintrc.cjs"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "24 out of 25 merged PRs checked by a CI test -- score normalized to 9",
                "points": 18,
                "status": "partial",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "critical",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": false,
              "has_docs_dir": false,
              "has_description": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 55,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 44,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 4.4
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "24 out of 25 merged PRs checked by a CI test -- score normalized to 9",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/29 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 3",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "12 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@joinmeow/cognito-passwordless-auth@1.0.104 runtime dependency closure — what installing the published package pulls in — 3 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@joinmeow/cognito-passwordless-auth@1.0.104",
                  "assessed": 3
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 3,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 3,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 3
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 64,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.8,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "76 of 95 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 76,
                      "sampled": 95
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 69,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "client/tsconfig.json"
              ],
              "agent_commit_share": 0.02,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.05
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".eslintrc.cjs",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".eslintrc.cjs"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "client/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "client/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "2 of the last 100 commits agent-authored or agent-credited",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 2,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "5 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 5,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 96149,
              "source_files_sampled": 92,
              "oversized_source_files": 3
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "3/92 source files over 60KB",
                "points": 53.2,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 92,
                      "oversized": 3
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Community profile unavailable"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T16:54:22.870855Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/j/joinmeow/amazon-cognito-passwordless-auth.svg",
  "full_name": "joinmeow/amazon-cognito-passwordless-auth",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计npm.