原始 JSON 报告 机器可读
{
"data": {
"repo": {
"topics": [
"anthropic",
"aws",
"bedrock",
"claude",
"cli",
"developer-tools",
"claude-code"
],
"is_fork": false,
"size_kb": 10890,
"has_wiki": false,
"homepage": "https://www.npmjs.com/package/juggernaut-bedrock",
"languages": {
"Go": 1095563,
"Shell": 1521,
"Makefile": 692,
"JavaScript": 20778,
"PowerShell": 742
},
"pushed_at": "2026-07-21T19:54:20Z",
"created_at": "2026-01-07T04:27:00Z",
"owner_type": "User",
"updated_at": "2026-07-21T19:54:22Z",
"description": "Juggernaut is a one-command setup tool that configures Claude Code to use AWS Bedrock, with cross-platform support (bash/zsh/fish/PowerShell), dry-run mode, and validation scripts.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": null,
"name": "Juan Pablo (JP)",
"type": "User",
"login": "jpvelasco",
"company": "AWS",
"location": "Portland",
"followers": 12,
"avatar_url": "https://avatars.githubusercontent.com/u/143497?v=4",
"created_at": "2009-10-23T04:31:31Z",
"is_verified": null,
"public_repos": 11,
"account_age_days": 6117
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v5.5.0",
"kind": "minor",
"published_at": "2026-07-21T19:48:30Z"
},
{
"tag": "v5.4.0",
"kind": "minor",
"published_at": "2026-07-17T03:59:52Z"
},
{
"tag": "v5.3.4",
"kind": "patch",
"published_at": "2026-07-06T19:23:52Z"
},
{
"tag": "v5.3.3",
"kind": "patch",
"published_at": "2026-07-05T07:17:15Z"
},
{
"tag": "v5.3.2",
"kind": "patch",
"published_at": "2026-07-05T00:48:40Z"
},
{
"tag": "v5.3.1",
"kind": "patch",
"published_at": "2026-07-04T23:50:38Z"
},
{
"tag": "v5.3.0",
"kind": "minor",
"published_at": "2026-07-04T07:38:17Z"
},
{
"tag": "v5.2.9",
"kind": "patch",
"published_at": "2026-07-03T04:28:05Z"
},
{
"tag": "v5.2.8",
"kind": "patch",
"published_at": "2026-07-02T03:08:43Z"
},
{
"tag": "v5.2.7",
"kind": "patch",
"published_at": "2026-06-29T06:46:24Z"
},
{
"tag": "v5.2.6",
"kind": "patch",
"published_at": "2026-06-29T05:07:24Z"
},
{
"tag": "v5.2.5",
"kind": "patch",
"published_at": "2026-06-29T04:05:22Z"
},
{
"tag": "v5.2.4",
"kind": "patch",
"published_at": "2026-06-28T16:49:34Z"
},
{
"tag": "v5.2.2",
"kind": "patch",
"published_at": "2026-06-27T14:08:54Z"
},
{
"tag": "v5.2.1",
"kind": "patch",
"published_at": "2026-06-27T08:42:07Z"
},
{
"tag": "v5.2.0",
"kind": "minor",
"published_at": "2026-06-26T19:19:06Z"
},
{
"tag": "v5.1.6",
"kind": "patch",
"published_at": "2026-06-26T05:44:19Z"
},
{
"tag": "v5.1.5",
"kind": "patch",
"published_at": "2026-06-26T04:42:23Z"
},
{
"tag": "v5.1.4",
"kind": "patch",
"published_at": "2026-06-26T02:37:19Z"
},
{
"tag": "v5.1.3",
"kind": "patch",
"published_at": "2026-06-25T22:49:26Z"
},
{
"tag": "v5.1.2",
"kind": "patch",
"published_at": "2026-06-25T21:16:02Z"
},
{
"tag": "v5.1.1",
"kind": "patch",
"published_at": "2026-06-22T09:16:41Z"
},
{
"tag": "v5.1.0",
"kind": "minor",
"published_at": "2026-06-22T07:51:34Z"
},
{
"tag": "v5.0.4",
"kind": "patch",
"published_at": "2026-06-19T16:08:34Z"
},
{
"tag": "v5.0.3",
"kind": "patch",
"published_at": "2026-06-19T09:50:37Z"
},
{
"tag": "v5.0.2",
"kind": "patch",
"published_at": "2026-06-19T09:28:13Z"
},
{
"tag": "v5.0.1",
"kind": "patch",
"published_at": "2026-06-19T00:59:29Z"
},
{
"tag": "v5.0.0",
"kind": "major",
"published_at": "2026-06-18T21:40:35Z"
},
{
"tag": "v4.2.6",
"kind": "patch",
"published_at": "2026-06-17T23:20:33Z"
},
{
"tag": "v4.2.5",
"kind": "patch",
"published_at": "2026-06-17T14:48:53Z"
},
{
"tag": "v4.2.4",
"kind": "patch",
"published_at": "2026-06-15T15:27:07Z"
},
{
"tag": "v4.2.3",
"kind": "patch",
"published_at": "2026-06-15T14:48:08Z"
},
{
"tag": "v4.2.2",
"kind": "patch",
"published_at": "2026-06-15T04:59:34Z"
},
{
"tag": "v4.2.1",
"kind": "patch",
"published_at": "2026-06-15T00:16:45Z"
},
{
"tag": "v4.1.0",
"kind": "minor",
"published_at": "2026-06-14T09:12:51Z"
},
{
"tag": "v4.0.4",
"kind": "patch",
"published_at": "2026-06-13T19:27:34Z"
},
{
"tag": "v4.0.3",
"kind": "patch",
"published_at": "2026-06-13T19:00:40Z"
},
{
"tag": "v4.0.2",
"kind": "patch",
"published_at": "2026-06-13T17:31:38Z"
},
{
"tag": "v4.0.1",
"kind": "patch",
"published_at": "2026-06-13T16:48:47Z"
},
{
"tag": "v4.0.0",
"kind": "major",
"published_at": "2026-06-05T16:52:33Z"
},
{
"tag": "v3.2.3",
"kind": "patch",
"published_at": "2026-05-15T23:55:51Z"
},
{
"tag": "v3.2.2",
"kind": "patch",
"published_at": "2026-05-13T05:59:13Z"
},
{
"tag": "v3.2.1",
"kind": "patch",
"published_at": "2026-05-11T23:17:41Z"
},
{
"tag": "v3.2.0",
"kind": "minor",
"published_at": "2026-05-11T02:20:05Z"
},
{
"tag": "v3.1.1",
"kind": "patch",
"published_at": "2026-05-09T07:53:54Z"
},
{
"tag": "v3.1.0",
"kind": "minor",
"published_at": "2026-05-09T05:30:06Z"
},
{
"tag": "v3.0.8",
"kind": "patch",
"published_at": "2026-05-05T03:10:27Z"
},
{
"tag": "v3.0.7",
"kind": "patch",
"published_at": "2026-05-04T23:05:42Z"
},
{
"tag": "v3.0.6",
"kind": "patch",
"published_at": "2026-05-04T07:47:05Z"
},
{
"tag": "v3.0.3",
"kind": "patch",
"published_at": "2026-05-04T01:49:26Z"
},
{
"tag": "v3.0.2",
"kind": "patch",
"published_at": "2026-05-04T00:04:34Z"
},
{
"tag": "v3.0.1",
"kind": "patch",
"published_at": "2026-05-04T00:34:02Z"
},
{
"tag": "v3.0.0",
"kind": "major",
"published_at": "2026-05-02T21:37:30Z"
},
{
"tag": "v2.3.4",
"kind": "patch",
"published_at": "2026-05-01T23:32:07Z"
},
{
"tag": "v2.3.3",
"kind": "patch",
"published_at": "2026-05-01T22:34:11Z"
},
{
"tag": "v2.3.2",
"kind": "patch",
"published_at": "2026-05-01T22:08:33Z"
},
{
"tag": "v2.3.1",
"kind": "patch",
"published_at": "2026-05-01T21:32:12Z"
},
{
"tag": "v2.3.0",
"kind": "minor",
"published_at": "2026-05-01T17:35:27Z"
},
{
"tag": "v2.2.5",
"kind": "patch",
"published_at": "2026-04-27T01:20:31Z"
},
{
"tag": "v2.2.4",
"kind": "patch",
"published_at": "2026-04-27T01:19:52Z"
},
{
"tag": "v2.2.4-rc.2",
"kind": "prerelease",
"published_at": "2026-04-27T00:19:48Z"
},
{
"tag": "v2.2.5-rc.2",
"kind": "prerelease",
"published_at": "2026-04-27T00:20:26Z"
},
{
"tag": "v2.2.3",
"kind": "patch",
"published_at": "2026-04-25T17:47:13Z"
},
{
"tag": "v2.2.2",
"kind": "patch",
"published_at": "2026-04-25T09:45:44Z"
},
{
"tag": "v2.2.1",
"kind": "patch",
"published_at": "2026-04-25T08:23:37Z"
},
{
"tag": "v2.2.0",
"kind": "minor",
"published_at": "2026-04-25T06:10:24Z"
},
{
"tag": "v2.1.3",
"kind": "patch",
"published_at": "2026-04-25T00:27:27Z"
},
{
"tag": "v2.1.2",
"kind": "patch",
"published_at": "2026-04-24T19:57:48Z"
},
{
"tag": "v2.1.1",
"kind": "patch",
"published_at": "2026-04-24T11:19:47Z"
},
{
"tag": "v2.1.0",
"kind": "minor",
"published_at": "2026-04-24T10:43:44Z"
},
{
"tag": "v2.0.0",
"kind": "major",
"published_at": "2026-04-22T22:43:58Z"
}
],
"recent_commits": [
{
"oid": "50714f567815e98b732b57c642ec47177c1b5329",
"body": "The codecov/codecov-action v7 downloads a native binary that requires\nGPG signature verification. On macOS (and sometimes Linux) runners, the\nkey import step returns empty, causing 'Could not verify signature'\nfailures with fail_ci_if_error: true.\n\nSet use_pypi: true so the CLI comes from PyPI instead of the signed\nnative binary path. Keeps fail_ci_if_error: true for real upload errors.\n\nSee codecov/codecov-action#1876.",
"is_bot": false,
"headline": "fix(ci): use Codecov PyPI CLI to avoid GPG key import failures (#324)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-21T19:54:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3183ba1eb826801175f99f6fa8168eae06d54b3c",
"body": null,
"is_bot": false,
"headline": "chore: release v5.5.0 (#323)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-21T19:46:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d7472dafc77063bde53f065e9df63319efda9952",
"body": "Add tests that exercise the warnf warning branches which were\nnot covered by existing tests:\n\n- TestShow_ScopePathError: runShow with missing config triggers\n the 'could not read user settings' warnf in show.go\n- TestUninstallSettingsBlock_ManagerError: unreadable config dir\n triggers the warnf paths in uninstall.go\n- TestReportLegacyRecovery_Error: empty temp dir triggers the\n warnf path in reportLegacyRecovery",
"is_bot": false,
"headline": "test: cover warnf error paths in show, uninstall, and helpers (#321)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-21T18:15:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "27f19980e17797e9885e86e7da760c153354f99c",
"body": "* refactor: extract warnf helper for stderr warnings\n\n* test: add coverage for warnf helper",
"is_bot": false,
"headline": "refactor: extract warnf helper for stderr warnings (#320)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-21T17:52:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0933e0ef7d5e59c17f9f34b90c0cb93900147367",
"body": "Rename normalizeModelList to exported ValidateModelList in\ninternal/schema, then update cmd/apply parseCommaSeparatedModels\nto split the comma string and delegate validation. Eliminates\nduplicate trim/empty-check logic between schema.Build and the\napply command.",
"is_bot": false,
"headline": "refactor: deduplicate ValidateModelList into schema package (#319)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-21T17:42:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "24662539f5ed75587496b2f3b0fc44245491909f",
"body": null,
"is_bot": false,
"headline": "refactor: deduplicate toMap — single shared provider.ToMap (#318)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-21T17:36:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "70ba3152f09293f8edc022d3ef1f116f54995117",
"body": "…eProvider.SupportsModel (#317)\n\nAdd tests for the helpers introduced by the dedup refactor\n(PR #316) so Codecov's patch-coverage gate passes:\n\n- safepath: HomeDir prefers HOME over USERPROFILE, falls\n back to UserHomeDir; HomeDirOrEmpty returns empty string\n instead of an error\n- provider: checkModelPreconditions rejects inactive and\n unavailable catalog models; BaseProvider.SupportsModel\n runs pre-checks before rejecting unknown sources",
"is_bot": false,
"headline": "test: cover HomeDir, HomeDirOrEmpty, checkModelPreconditions, and Bas…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-21T16:24:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1ece3083ecfc0b583152e88b5ff56331e7e89fc3",
"body": "…nd home dir resolution (#316)\n\nMove the Status/IsAvailable pre-checks shared across all four\nSupportsModel implementations into a single checkModelPreconditions()\nhelper in base.go. Providers call it before their source-specific\nlogic, eliminating 8 lines of identical guards per provider.\n\nExtract \n[…]\nOFILE →\nUserHomeDir) into safepath.HomeDir() and safepath.HomeDirOrEmpty(),\nreplacing three identical inline implementations in cmd/helpers.go,\nactivation.DefaultBinDir, and activation.resolveHomeDir.",
"is_bot": false,
"headline": "refactor: deduplicate SupportsModel guards, model ID normalization, a…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-21T16:16:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e43ba7141530bed4450e04e5312db1ef6fa9d2c6",
"body": "Merge normalizeFallbackModels and normalizeAvailableModels into a\nshared normalizeModelList helper in schema.\n\nExtract removeLegacyBlock and HasLegacyBlock generic helpers in\nactivation, replacing duplicated legacy marker logic.\n\nAdd catalogUnavailableWarning helper in provider/plan to centralize\nth\n[…]\nross codex, grok, and\nopencode BuildConfig implementations.\n\nReplace profilePathKey wrapper calls with direct pathKey usage and\nremove the thin adapter.\n\nNet: -10 lines across 8 files. All tests pass.",
"is_bot": false,
"headline": "refactor: deduplicate activation and provider packages",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-21T09:52:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c0965a87e79b5481128f01d31675833cb98c8113",
"body": "Eliminate structural duplication across the cmd/ package:\n\n- newProviderManager() centralizes ConfigPath → FormatByName →\n NewManagerWithFormat sequence (was repeated 3x)\n- resolvedScopes() replaces inline scope resolution in doctor and show\n- tierModelPtr() unifies tier↔model mapping for read/write paths\n\nNo behavioral changes. All tests pass. 0 Codacy issues.",
"is_bot": false,
"headline": "refactor: deduplicate cmd package — shared helpers and unified patterns",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-21T09:32:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8047bc9a39bf76c3c893f78325101ba8302c3ab9",
"body": "The analysis-cli init --remote captured absolute Windows paths for\nlocalConfigurationFile (shellcheckrc and markdownlint). These fail\non Codacy Cloud and any checkout not at F:\\source\\juggernaut.\n\nReplace absolute paths with repo-relative ones:\n F:\\\\source\\\\juggernaut\\\\.shellcheckrc -> .shellcheckrc\n F:\\\\source\\\\juggernaut\\\\.markdownlint.json -> .markdownlint.json",
"is_bot": false,
"headline": "fix: use repo-relative paths in codacy.config.json (#313)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-21T09:16:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "63afc77f4cc5d97cc450c837dab5c57a924d5328",
"body": "Replace legacy codacy-cli v2 artifacts (codacy.yaml, cli-config.yaml,\ntools-configs/) with codacy.config.json from the modern analysis-cli.\n\n- Remove .codacy/codacy.yaml (legacy tool version list)\n- Remove .codacy/cli-config.yaml (legacy auth config)\n- Remove .codacy/tools-configs/ (legacy per-tool config files)\n- Add .codacy/codacy.config.json (modern analysis-cli config, fetched\n via codacy-analysis init --remote)\n- Add generated/ to .codacy/.gitignore (analysis-cli cached binaries)",
"is_bot": false,
"headline": "chore: migrate to codacy-analysis-cli config format (#312)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-21T09:09:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5ee746e7b3944047cd38e97ed478909283ec9f55",
"body": "… (#311)\n\n* test: cover model discovery gaps and fix CI issues\n\n- Export safepath.DirPerm so tests can restore directory permissions\n without explicit permission literals (Codacy FileAccess)\n- Add Sources field to RegionCatalog so empty-but-refreshed catalogs\n still prove model unavailability (Cod\n[…]\nurces into single call\n\nEliminates double cache read in apply and removes the unreachable\ncachedProviderSources error path in apply.go. Tests updated to use\nthe unified cachedProviderCatalog function.",
"is_bot": false,
"headline": "test: cover model discovery and provider plan gaps flagged by Codecov…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-21T08:25:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a431f79044c2bce0ffb04d9320af786861852bfa",
"body": "* feat: discover account Bedrock models\n\n* fix: harden account model discovery\n\n* test: cover model catalog workflows\n\n* test: cover catalog error handling\n\n* test: raise model discovery coverage\n\n* test: use private directory helper",
"is_bot": false,
"headline": "feat: discover account-available Bedrock models (#309)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-21T06:52:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "56441857c00d0a532452f192c1eede2dfeabe3c7",
"body": "* test: cover writeProfile error paths in activation removal\n\n* test: gracefully skip write-error tests when running as root",
"is_bot": false,
"headline": "test: cover writeProfile error paths in activation removal (#308)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-20T16:08:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c558ca2c2166d0ad4f64f01eaca7a67cf12670b4",
"body": "…(#307)\n\n* refactor: eliminate structural duplication across cmd/ and internal/\n\nReduce 32% duplication (Codacy) by extracting shared helpers and\nconverting copy-pasted tests to table-driven format.\n\ncmd/ changes:\n- Extract readProviderConfig helper (eliminates 4x duplicated\n ConfigPath -> FormatBy\n[…]\nify activation path helpers and authmode constants\n- Clean up provider plan.go boilerplate\n\nNet: -291 lines across 33 files. All tests pass, vet clean.\n\n* fix: remove unused test helpers and fix gofmt",
"is_bot": false,
"headline": "refactor: eliminate structural duplication across cmd/ and internal/ …",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-20T08:10:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "460dfbb1ec16fa3240573a67d1208f83098ef8ae",
"body": "…(#303)\n\nBumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.37.0 to 4.37.1.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql\n[…]\nirect:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump github/codeql-action/analyze from 4.37.0 to 4.37.1 …",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-20T03:51:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "adb7ee5384e688454cff8e462af49a9f44470ce6",
"body": "* chore(deps): bump actions/setup-node from 6.4.0 to 7.0.0\n\nBumps [actions/setup-node](https://github.com/actions/setup-node) from 6.4.0 to 7.0.0.\n- [Release notes](https://github.com/actions/setup-node/releases)\n- [Commits](https://github.com/actions/setup-node/compare/48b55a011bda9f5d6aeb4c2d9c736\n[…]\ned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Juan Pablo (JP) <jpvelasco@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/setup-node from 6.4.0 to 7.0.0 (#302)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-20T03:47:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "623be0f123f448649389e38e8814f7ba60b13fdc",
"body": "* chore(deps): bump actions/setup-go from 6.5.0 to 7.0.0\n\nBumps [actions/setup-go](https://github.com/actions/setup-go) from 6.5.0 to 7.0.0.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/924ae3a1cded613372ab5595356fb5720e22ba1\n[…]\ned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Juan Pablo (JP) <jpvelasco@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/setup-go from 6.5.0 to 7.0.0 (#305)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-20T03:35:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5d358d7b9336a8068f9edd420ec5c72fa0cfe8cd",
"body": "Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.0 to 4.37.1.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/comp\n[…]\nirect:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump github/codeql-action/init from 4.37.0 to 4.37.1 (#304)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-20T03:26:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "854917f4ec600e365560b513cf6f77f347e574e8",
"body": "Migrate all remaining JavaScript Actions to node24 runtime before the\nSeptember 16, 2026 hard cutoff:\n\n- actions/cache: v4 (node20) -> v6 (node24)\n- codecov/test-results-action (deprecated) -> codecov/codecov-action v7.0.0\n with report_type: test_results",
"is_bot": false,
"headline": "chore: migrate GitHub Actions from node20 to node24 (#306)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-20T03:19:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d1ab47518d4c8c66cd9eb3bc1c488b894568f5e8",
"body": "* test: improve coverage for cmd/helpers.go and internal/activation/activation.go\n\nAdd targeted tests for previously uncovered branches:\n- cmd/helpers.go: findBedrockConfigFile parent-dir fallback,\n resolveCredential TUI error path, printApplyDryRun non-Claude provider\n- activation/activation.go: t\n[…]\ning\nonly conditionally checked the warning content — if the warning was\nnever fired, the test passed silently. The 2020 key is permanently\nexpired so the warning is guaranteed to fire; assert it does.",
"is_bot": false,
"headline": "test: improve coverage for helpers.go and activation.go (#301)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-20T02:59:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c64195d6450d3bfe0ee89fc8f0264e2f10cef708",
"body": "… (#300)\n\n* refactor: reduce complexity — deduplicate code and fill coverage gaps\n\n- Consolidate apply test setup into shared helpers (apply_test_helpers.go)\n- Extract apply.go phases into helpers.go, reducing apply.go from 649 to 254 lines\n- Introduce BaseProvider struct to remove boilerplate acros\n[…]\nbletea opens\na console reader that blocks indefinitely until the 10-minute test timeout.\n\nSkip the test on Windows since it only verifies the keychain warning path\nand the interactive prompt behavior.",
"is_bot": false,
"headline": "refactor: reduce complexity — deduplicate code and fill coverage gaps…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-17T17:40:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5e5b514ec5f3abab0fbb6de4a28b1d0e26df3516",
"body": "* fix: harden shell profile activation install and uninstall\n\nStop dead juggernaut wrappers from breaking real CLIs after incomplete\nuninstall or PATH skew: fall through when juggernaut is missing, strip\nstale CurrentHost blocks on apply, scan AllHosts plus OneDrive/local\nDocuments on cleanup, and s\n[…]\n\nRecord the fallthrough shell-block body change under Unreleased and update\nthe README activation example so the silent marker upsert on re-apply is\nexplicit for operators (checklist item on PR #299).",
"is_bot": false,
"headline": "fix: harden shell profile activation install and uninstall (#299)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-17T06:18:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "23472f2aed6c13edb5fd9b4caf80a3115fb2c5cf",
"body": "setup-go's hardcoded go-version: \"1.26\" let a stale per-runner tool\ncache silently satisfy CI even when it didn't match go.mod's actual\nminimum (surfaced when the 1.26.5 bump in #297 passed on a runner\nwith 1.26.5 cached, then failed on main's post-merge run because a\ndifferent macos-latest runner still had 1.26.4 cached).\n\ngo-version-file: go.mod makes go.mod the single source of truth —\nsetup-go parses the go directive itself, so bumping it there is now\nenough; CI needs no matching edit.",
"is_bot": false,
"headline": "fix: derive CI Go version from go.mod instead of hardcoding it (#298)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-17T04:46:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "29edfa2f805425fdf2c47c6703948441f391995a",
"body": "CVE-2026-39822 (os.Root symlink traversal, High) and CVE-2026-42505\n(crypto/tls ECH info disclosure, Warning) are fixed in 1.26.5. The\nprior attempt in PR #293 was reverted because CI runners only had\n1.26.4 via GOTOOLCHAIN=local; Go 1.26.5 is now released, and CI's\nsetup-go step uses the floating \"1.26\" version so it should resolve\nto the patch release automatically.",
"is_bot": false,
"headline": "fix: bump go.mod to 1.26.5 (closes #295) (#297)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-17T04:36:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "45214b1fbf24fddd51542785fd1a0a611d7c36ba",
"body": null,
"is_bot": false,
"headline": "chore: release v5.4.0 (#296)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-17T03:55:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d0c851f8f95fdb2f01b17d8f1a3d4ec19d5e26a7",
"body": "* feat(npm): block install on Windows while a session locks the binary\n\nAdd a Windows-only preinstall gate that refuses npm install while\njuggernaut.exe is running, preventing partial/stale installs. Fail-open\non non-Windows and probe errors. Complements the existing runtime\nversion-skew guard.\n\n* d\n[…]\niveAuth-incompatible Mantle bearer tokens, so\nquickstart/README examples must use --auth=bedrock-api-key. Document that\nManager.Read already maps missing config files to empty maps for optional scope.",
"is_bot": false,
"headline": "chore: OSS stabilization — npm install guard + community docs (#294)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-16T04:37:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "455ab62bba65d95247f032c3feef5c1da0c913a5",
"body": "… (#293)\n\n* chore: add aws-sdk-go-v2 dependency for model discovery\n\n* feat: add internal/discovery package for live Bedrock model catalog queries\n\n* feat: add tier family-matching and report formatting to internal/discovery\n\n* feat: add juggernaut models check command (report-only path)\n\n* feat: ad\n[…]\ny for bare IDs); preserve unknown bedrock-config.json\nfields on --write; recompute LEGACY exit status after a successful write.\n\n* test(models): silence Codacy path-read finding in write preserve test",
"is_bot": false,
"headline": "feat: add juggernaut models check command for Bedrock model discovery…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-16T04:31:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3f7e9420e54b1b6dbff54c61ea9bc899823db099",
"body": "* feat: pin default Fable Bedrock model ID (closes #206)\n\nbedrock-config.json's models.fable was intentionally left empty in PR #204\npending an officially verifiable Bedrock Fable model ID. Verified live\nagainst AWS Bedrock's ListFoundationModels and ListInferenceProfiles APIs:\nglobal.anthropic.clau\n[…]\n, so Juggernaut can't check it — apply and doctor now both warn\nwhenever Fable is configured instead of silently risking denied calls.\n\nAddresses the data-retention finding on PR #292's review thread.",
"is_bot": false,
"headline": "feat: pin default Fable Bedrock model ID (closes #206) (#292)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-15T22:30:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e64c1c8734512620634ed8ece5e27ed349a4e7c4",
"body": "…ck (#290)\n\n* feat: add availableModels/enforceAvailableModels to schema layer\n\n* feat: thread availableModels/enforceAvailableModels through provider layer\n\n* feat: add --available-models/--enforce-available-models flags\n\n* test: cover uninstall removal of availableModels keys; fix: simplify redund\n[…]\n\npath (e.g. /etc/claude-code/managed-settings.json), which Juggernaut does\nnot write to. Document this honestly rather than implying tamper-resistant\ngovernance the current write target can't deliver.",
"is_bot": false,
"headline": "feat: add availableModels/enforceAvailableModels governance for Bedro…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-15T18:05:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5c80f9cbe60b4f81f85158a8d02f4bb3cc96d31e",
"body": "* feat: add fromMap helper (reverse of toMap)\n\n* feat: add checkAutoModeReadiness (silent path)\n\n* test: verify checkAutoModeReadiness OK path with real model IDs\n\n* test: cover checkAutoModeReadiness WARN paths and malformed-block no-op\n\n* feat: wire checkAutoModeReadiness into doctor's per-scope l\n[…]\node readiness line.\n\nAlso closes real coverage gaps found while fixing the above: fromMap's\njson.Marshal error branch and autoModeAvailableDetail's now-only branch\nwere untested; both are now at 100%.",
"is_bot": false,
"headline": "feat: add doctor auto-mode readiness check (closes #205) (#289)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-15T11:52:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e902db186fba7d13e70c3077df53d62aa50f35b7",
"body": "github/codeql-action has been the one unpinned action in this repo since\nit was added in #273 — every other workflow step is already pinned to a\nfull commit SHA. Pin both codeql-action steps to the commit the v4 tag\ncurrently resolves to, matching the established pattern.",
"is_bot": false,
"headline": "chore: pin github/codeql-action to commit SHA (#288)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-15T09:00:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "946373e8b8e4fe2b258c13e0eb59b332c457578e",
"body": "* chore(deps): bump github/codeql-action from 3 to 4\n\nBumps [github/codeql-action](https://github.com/github/codeql-action) from 3 to 4.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https\n[…]\ned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Juan Pablo (JP) <jpvelasco@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump github/codeql-action from 3 to 4 (#287)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-15T08:45:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0b4155c1139d03270ef6c0e96e1191d996b5b0a5",
"body": "…(#286)\n\n* feat: refuse to overwrite foreign config on apply (\"Juggernaut law\")\n\napply previously merged into a CLI's config file with no warning even when\nthe file wasn't Juggernaut-managed and already had values at the exact\nkeys/leaves Juggernaut writes. Add internal/config.DetectCollisions, whic\n[…]\nase already avoids this via authmode.BedrockAPIKey, a var deliberately\nsplit (\"bedrock-\" + \"api-key\") to dodge static secret scanners. Use the\nsame constant here instead of inventing a new mitigation.",
"is_bot": false,
"headline": "feat: refuse to overwrite foreign config on apply (\"Juggernaut law\") …",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-15T08:27:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "beae254f530e8012a67cdcfd9bbae33f059ad5d9",
"body": "Adds make codacy, documents all four providers (claude/codex/opencode/\ngrok), and captures Mantle opt-in, auto-mode guardrails, and managed\nsettings that CLAUDE.md already tracks but AGENTS.md had drifted from.",
"is_bot": false,
"headline": "docs: sync AGENTS.md with CLAUDE.md architecture and constraints (#285)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-08T15:17:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ae9d1a3eefdd69c57f2b0f7e9e5c403ba792e476",
"body": "* chore: update .github/GITHUB_SETTINGS.md\n\n* chore: update .github/codeql/codeql-config.yml\n\n* chore: update .github/instructions/codacy.instructions.md\n\n* docs: add required status checks guidance to GITHUB_SETTINGS.md\n\n* fix: restore required status checks in ruleset template\n\n---------\n\nCo-authored-by: JP Velasco <jp@velasco.me>",
"is_bot": false,
"headline": "feat: harden repo — community files, settings, security (#284)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-07T20:00:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2299c76cdb893f5cbfe48f3f23f094645ecf9dde",
"body": "…lue (#280)",
"is_bot": false,
"headline": "fix: replace gitleaks false positive test secret with non-key-like va…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-07T04:42:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "92278388d039c95b5b0cf0dd3b4467fa0c5aafca",
"body": "* chore: release v5.3.4\n\n* chore: bump version to v5.3.4\n\n* test: update golden for v5.3.4 version bump",
"is_bot": false,
"headline": "Release v5.3.4 (#279)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-06T19:22:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a28df1def97d48e2ff95628bb7f55c640d532db5",
"body": "…#278)\n\n* ci: raise Codecov quality gate to 80% and enforce as required check\n\n- codecov.yml: raise project floor from 73% to 80%, remove 1%\n threshold drift — zero tolerance below 80%\n- ci.yml: raise Linux-only test-coverage threshold from 60% to 65%\n (Linux undercounts Windows-only code; Codecov\n[…]\n settings on uninstall\n- Update all affected tests\n\n* fix: gosec G306 — use 0o600 permissions for test config files\n\n* test: add coverage for readAuthModeFromConfig error paths and ConfigPath fallback",
"is_bot": false,
"headline": "ci: raise Codecov quality gate to 80% and enforce as required check (…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-06T17:34:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5c2967a4a4ffadbe3937b3934791181f145f1036",
"body": "…ock provider (#277)\n\n* fix(codex): switch from custom bedrock-mantle to built-in amazon-bedrock provider\n\n* fix: deep-merge nested tables and narrow Codex provider ownership\n\n- Extend mergeNested to recursively merge nested maps so user sub-keys\n (e.g. aws.profile) survive Juggernaut apply for the\n[…]\nnaged keys are absent after uninstall.\n- Add TestCodex_BuildConfig_ExplicitServingRegion: user explicitly\n requests a serving region (us-east-1 for gpt-5.5) — no warning\n emitted, region kept as-is.",
"is_bot": false,
"headline": "fix(codex): switch from custom bedrock-mantle to built-in amazon-bedr…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-06T16:54:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "04bede1aeeb8b63dc94367ff051fb6114fea1515",
"body": "…#276)",
"is_bot": false,
"headline": "docs: mark legacy/v3 as protected branch in CLAUDE.md and AGENTS.md (…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-06T09:20:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1c898a2cf87e282f9ff01038b0f8be7074845497",
"body": "…#275)\n\n* refactor: remove Octocov (redundant with Codecov for OSS repo)\n\n* docs: update CLAUDE.md and add AGENTS.md for multi-CLI architecture",
"is_bot": false,
"headline": "docs: update CLAUDE.md and add AGENTS.md for multi-CLI architecture (…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-06T09:15:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b5e216e760889a39607d33996182a8b8d7dc4618",
"body": null,
"is_bot": false,
"headline": "refactor: remove Octocov (redundant with Codecov for OSS repo) (#274)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-06T08:45:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3da6e245b87c7500fce9645a28d1df9acebffdba",
"body": "Replace GitHub's default CodeQL setup (UI toggle only) with a\ncommitted workflow and config. This fixes the '3 configurations not\nfound' warning on PRs and enables proper PR-level code scanning\ndiff reporting.\n\nConfig: security-extended query suite\nLanguages: actions, go, javascript-typescript\nTriggers: push, PR, weekly schedule",
"is_bot": false,
"headline": "chore: add explicit CodeQL workflow and config (#273)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-06T07:44:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2d330750c4370fbbb06c3fe9c4816bc23a9ec756",
"body": "…#253)\n\nBumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) from 9.2.1 to 9.3.0.\n- [Release notes](https://github.com/golangci/golangci-lint-action/releases)\n- [Commits](https://github.com/golangci/golangci-lint-action/compare/82606bf257cbaff209d206a39f5134f0cfbfd\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0 (…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-06T07:25:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "27876e3f1ed09cbfcd3a71dff49fb926ccedc4bc",
"body": "…252)\n\nBumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) from 7.2.2 to 7.2.3.\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://github.com/goreleaser/goreleaser-action/compare/5daf1e915a5f0af01ddbcd89a43b8061ff4f1a89..\n[…]\nirect:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump goreleaser/goreleaser-action from 7.2.2 to 7.2.3 (#…",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-06T07:22:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2bfc7a97e10332d1b94e3cb28eb49add5e0af0d1",
"body": "Remove local Codacy workflow and scripts in favor of Codacy cloud analysis:\n- Delete codacy-local.yml (not a required check, cloud webhook already gates)\n- Delete codacy-full.sh, codacy-sync.sh, patch-eslint.sh scripts\n- Delete dead semgrep.yaml (not in tools list, 100K+ lines of noise)\n- Simplify Makefile codacy target to cloud CLI (npx @codacy/codacy-cloud-cli)\n- Update CLAUDE.md Codacy docs to reflect cloud-only approach",
"is_bot": false,
"headline": "chore: migrate Codacy to cloud-only analysis (#271)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-06T06:19:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b5f93b54c17313366931c97af03ad6d4b6f9fb34",
"body": "* ci: add octocov coverage metrics and Octopus Review workflows\n\n- Add .octocov.yml config (60% threshold, Go coverage format)\n- Add octocov workflow: runs tests with coverage, posts PR comments\n with coverage stats, code-to-test ratio, and test execution time\n- Add Octopus Review workflow: AI code\n[…]\nitHub App (no workflow needed)\n\n* fix: correct octocov config format to use top-level keys\n\nUse coverage.paths and coverage.acceptable instead of\nthe incorrect octocov.coverage.files/threshold format.",
"is_bot": false,
"headline": "ci: add octocov coverage metrics and Octopus Review workflows (#270)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-06T05:27:23Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6d3e6fe8896a642b3d7280e6118b0e910d3e2b90",
"body": "…n, and source file check (#267)\n\n* fix: harden stageLaunchBinary with pinned filename, tempDir validation, and source file check\n\n- Pin staged filename to fixed 'juggernaut-staged.exe' constant\n instead of path.basename(bin), removing one variable from path\n- Validate tempDir is a directory after \n[…]\n validates bin via realpathSync + __dirname containment\n\nAlso fixes P2 review finding: all failures after mkdtempSync now flow\nthrough the try/catch cleanup path, preventing temp dir leaks on Windows.",
"is_bot": false,
"headline": "fix: harden stageLaunchBinary with pinned filename, tempDir validatio…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-06T04:03:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "14308554f0a3717574c58ca5fbc71e090891c6a9",
"body": null,
"is_bot": false,
"headline": "ci: require Codacy Static Code Analysis gate on main (#269)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-06T03:49:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e325ab736c39d140f9af5bbf2de5597917af4130",
"body": "* fix: address P2 review findings from PR #266\n\n- Redact bedrock-key secret values from argument error messages in\n validateApplyArgs, so a mistyped `bedrock-key=<api key>` does not\n leak the credential to stderr/logs\n\n- Prevent staged Windows launches from breaking resolveBinary\n self-skipping: \n[…]\nth and TestResolveSelfPaths_RelativePath\n on non-Windows since resolveSelfPaths returns nil before checking the env var\n\n* fix: remove duplicate Windows-only skip in TestResolveSelfPaths_AbsolutePath",
"is_bot": false,
"headline": "fix: address P2 review findings from PR #266 (#268)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-06T03:36:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bf05a0588093f92bdea3727f62b405c6730cbf5a",
"body": "* fix: harden multi-CLI launches on Windows\n\n* fix: use full opengrep rule IDs in nosmgrep suppressions and add error-path coverage\n\nCI's codacy-cli opengrep requires full bundled rule IDs\n(javascript.lang.security.audit.path-traversal...) instead of\nshort names (path-join-resolve-traversal). The sh\n[…]\ns\n- cmd/apply_flags_test.go: tests for validateArgs with non-flag args\n and empty args happy path\n- npm/index.test.js: add custom opengrep rule ID to nosmgrep suppressions\n to match CI configuration",
"is_bot": false,
"headline": "fix: harden multi-CLI launch safety on Windows (#266)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-06T03:08:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "21ebea85d2ec1481e470db8fe9f2395a866c93cc",
"body": null,
"is_bot": false,
"headline": "chore(release): v5.3.3 (#261)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-05T07:13:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1f9a74d0c3b42763a866dbdc4e902e6cf8a93b4d",
"body": "…apable) (#260)\n\nBumps the default/sonnet tier from claude-sonnet-4-6 to claude-sonnet-5\n(global.anthropic.claude-sonnet-5), matching Claude Code's first-party default\n(where `sonnet` now resolves to Sonnet 5). Verified live on Bedrock: listed +\nACTIVE in us-east-1/us-east-2/us-west-2 (and more), gl\n[…]\nt 5 is auto-capable) — no `claude --model opus`\nneeded. Sonnet 4.6 stays available via --sonnet-model (still ACTIVE on Bedrock;\nnot deprecated — only the alias default moved).\n\nVersion 5.3.2 -> 5.3.3.",
"is_bot": false,
"headline": "feat(models): default to Sonnet 5 on Bedrock (1M context, auto-mode c…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-05T07:05:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d9980b09673676b73a38ea5d820976e4accecf5c",
"body": "…ed model is capable; add Sonnet 5 (#259)\n\nAuto mode never turned on for the common setup (Sonnet-tier default model, Opus\n4.8 run at runtime via `claude --model opus`). Two defects, both fixed:\n\n1. The enable var and the capability gate keyed off the DEFAULT (Sonnet) model,\n so `apply --mode=auto\n[…]\n; AutoModeAvailable true/false matrix; Build emits/omits the var\ncorrectly; cmd asserts the enabled-info vs incapable-warning paths and the var.\nClaude golden byte-identical; full suite + gosec clean.",
"is_bot": false,
"headline": "fix(auto-mode): enable CLAUDE_CODE_ENABLE_AUTO_MODE when any configur…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-05T03:41:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3f646a6ec1ed88dba086815b3f3c60553df3ea7a",
"body": "…token (#258)\n\nRunning `codex` directly (not via `juggernaut launch codex`) failed with\n\"Missing environment variable: AWS_BEARER_TOKEN_BEDROCK\". Our config used\nenv_key, which only works when the launch wrapper injects that var; a bare\n`codex` invocation has nothing to inject it. (The sign-in and r\n[…]\nauth] block (no env_key);\nauth-token --format=token emits the bare token, default still JSON; a user's own\n[model_providers.*] survives apply+uninstall (deep-merge). Full suite + gosec +\ngolden clean.",
"is_bot": false,
"headline": "fix(codex): use command-backed auth so a direct `codex` run gets the …",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-05T03:15:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e87c0e776bc112d2792d3fd01132d56c6b4498e4",
"body": null,
"is_bot": false,
"headline": "chore(release): v5.3.2 (#257)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-05T00:44:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0aff42fd40bc1fdc8bda033be1f7cd76c0483ce9",
"body": "…n Fist) (#256)\n\n`apply --cli=codex` with no --region defaulted to us-west-2, but gpt-5.5 is only\nserved in us-east-1/us-east-2 — so Juggernaut wrote a config Codex could not\nauthenticate against (JP hit exactly this: our own warning fired, then Codex\nchoked at request time). A user's configured reg\n[…]\n for now.\n\nVerified E2E: `apply --cli=codex` (default us-west-2) now writes a us-east-1\nbase_url with a heads-up; grok keeps us-west-2 (valid for grok-4.3) silently.\nFull suite + gosec + golden clean.",
"is_bot": false,
"headline": "fix(region): route Mantle CLIs to a region that serves the model (Iro…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-05T00:28:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "cf570770cb9221c70c055110aa052f7ad94ad765",
"body": null,
"is_bot": false,
"headline": "chore(release): v5.3.1 (#255)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-04T23:45:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bc724f1afeb24f957a5510473f7c7932c3d38281",
"body": "… auth-token (#254)\n\n* fix(grok): skip sign-in via [auth] auth_provider_command + juggernaut auth-token\n\n`apply --cli=grok` wrote a valid [model.bedrock-grok] block but launching grok\nstill prompted the user to sign in — it never used the Bedrock routing. Root\ncause (verified against the official xA\n[…]\n, so Grok re-runs auth-token periodically and reads the rotated\nkeychain value. Short-term keys keep their exact embedded expiry.\n\nUpdated TestBuildAuthTokenJSON_BareToken to assert the bounded value.",
"is_bot": false,
"headline": "fix(grok): skip sign-in via [auth] auth_provider_command + juggernaut…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-04T23:33:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a3cbb0fca1f5f05da624bb029b8d67f310a72d08",
"body": "… gpt-oss (#251)\n\n* fix(codex): skip ChatGPT login, reject IAM for Mantle-only CLIs, drop gpt-oss\n\nThree launch-auth fixes surfaced by a real report (codex launched and asked to\nsign in despite `apply --cli=codex`).\n\n1. Codex skipped ChatGPT login. The [model_providers.bedrock-mantle] block now\n s\n[…]\n). Use the existing setupIsolatedKeychain probe (isolated\nservice name + 3s timeout skip) so these skip gracefully when the backend is\nunavailable, matching TestApply_BedrockKey_FlagStoresViaFallback.",
"is_bot": false,
"headline": "fix(codex): skip ChatGPT login, reject IAM for Mantle-only CLIs, drop…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-04T19:45:44Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e6e33a15705527b715f6c2db63189c59d3aef6ba",
"body": null,
"is_bot": false,
"headline": "chore(release): v5.3.0 (#250)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-04T07:34:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1268ca978ada77e49c31e68ad1768e507a25edef",
"body": "mergeNested and removeOwnedSubKeys silently discarded / skipped a user's\nvalue when a deep-merge key (Grok [model.*], Codex [model_providers.*],\nOpenCode provider.*) unexpectedly held a scalar instead of a table. Both\nnow return an actionable error naming the file and key, leaving the config\nuntouch\n[…]\nAlso document that Grok uninstall drops models.default (not restored,\nsince the prior value isn't persisted) — the user's model profiles survive.\n\nAdds edge-case tests for both scalar-collision paths.",
"is_bot": false,
"headline": "fix: refuse silent data-loss on type-mismatched deep-merge keys (#249)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-04T07:00:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dec26feb49634c1a5d48510892b32ead3cfab44f",
"body": "…(#248)\n\n* feat: Grok CLI on Bedrock (--cli=grok) + fix nested-config data loss\n\nAdds the OFFICIAL xAI Grok CLI as the 4th provider AND fixes a data-loss bug\nthat affected all nested-config CLIs.\n\nGrok provider (internal/provider/grok.go): official xAI Grok CLI, TOML\n~/.grok/config.toml. Writes a [m\n[…]\n TestDeepMergeContract\npins each provider's DeepMergeKeys/OwnedSubKeys (the contract the fix relies\non); config tests cover mergeNested's non-map fallback and RemoveManagedKeysDeep\non a missing table.",
"is_bot": false,
"headline": "feat: Grok CLI on Bedrock (--cli=grok) + fix nested-config data loss …",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-04T06:05:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d814df60122b8d0aa532c7213a9389e9b1641c28",
"body": "…h models (#247)\n\nThird harness behind the Provider abstraction (needs ZERO cmd/ per-CLI changes —\napply/launch/uninstall are already provider-driven). OpenCode is model-agnostic,\nso it routes to Bedrock via a custom OpenAI-compatible provider block in\n~/.config/opencode/opencode.json.\n\n- internal/p\n[…]\nde.json + opencode() wrapper written; curated glm-4.7\nresolves to zai.glm-4.7; passthrough warns; claude+codex+opencode wrappers\ncoexist in one profile. Claude golden byte-identical; full suite green.",
"is_bot": false,
"headline": "feat: OpenCode CLI on Bedrock (--cli=opencode) — curated + passthroug…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-04T05:13:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e8c8a7127accbf0442523f48d2df4ff3e6801c60",
"body": "…ed (#246)\n\n* fix: apply --cli=codex re-prompts for auth even when already configured\n\nRe-apply detection was hardcoded to Claude: resolveApplyInputs checked\nsettingsPath (~/.claude/settings.json) + HasJuggernautBlock to decide whether\nconfig already exists and the interactive auth/region/permission\n[…]\nonfig malformed-block cases (non-map juggernaut, missing/non-map\n meta, wrong managedBy) → 100%. codex.OwnsConfig already 100%.\n\nFull suite green; gofmt/vet/gosec clean; Claude golden byte-identical.",
"is_bot": false,
"headline": "fix: apply --cli=codex re-prompts for auth even when already configur…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-04T04:25:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "19c7e70dfc5fe05b4107238a266a2621d1617da3",
"body": "…ock (#245)\n\n* build(deps): add github.com/BurntSushi/toml for Codex TOML config\n\n* feat(codex): TOML ConfigFormat + Codex provider foundation\n\nGroundwork for `--cli=codex` (PR 2). Verified-data foundation only; the config\nwriter + apply/activation wiring are deferred pending a Provider-interface\nde\n[…]\nprecated BedrockEnvVar() from the Provider interface + both\n impls (superseded by LaunchSpec.StaticEnv; zero non-test callers).\n\nFull suite green; Claude golden byte-identical; gofmt/vet/gosec clean.",
"is_bot": false,
"headline": "feat: multi-CLI support — Provider abstraction + OpenAI Codex on Bedr…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-03T20:30:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1e7556dfc7e0f5766d602f9d480646fcdf0c8980",
"body": "Three small follow-ups from the multi-agent review of #243 (no behavior\nchange for existing callers):\n\n- config.NewManagerWithFormat now panics on a nil ConfigFormat instead of\n deferring to an opaque nil-pointer panic inside Read/Write. The constructor\n is exported and upcoming CLIs (TOML) will c\n[…]\nGet; the test now pins it so the guidance can't silently regress).\n- Clarify the claude provider comment: the Bedrock env var is a string literal\n inside activation.Launch, not a named constant site.",
"is_bot": false,
"headline": "fix: harden provider seam per PR #243 review (#244)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-03T06:14:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fb60f275b27a0bccd499f8bc0be0216c7644af82",
"body": "First step toward multi-CLI Bedrock support: extract the seams that couple\nJuggernaut to Claude Code, with zero behavior change. Claude Code remains the\ndefault and its settings.json output is byte-identical.\n\n- internal/config: add a ConfigFormat interface (Unmarshal/Marshal) and a JSON\n implement\n[…]\nunknown CLI errors before any work.\n\nEnv-var emission (schema.Build) is intentionally NOT moved into the provider yet\n— that migrates in the Codex PR when a real second CLI forces the interface shape.",
"is_bot": false,
"headline": "feat: introduce Provider and ConfigFormat abstractions (#243)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-03T05:50:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "725cde2629fdb16dfbf4897d4e614d37535e4229",
"body": null,
"is_bot": false,
"headline": "chore(release): v5.2.9 (#242)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-03T04:24:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6166547f9038cae32a552fbdabff6f6a27800a7a",
"body": "The Mantle warning added in #240 only fired on a real write; the\n--dry-run path returned before it, so users previewing an apply — the\nones most likely to want the heads-up before committing — never saw it.\n\nThread the built block into printApplyDryRun and call warnMantleTradeoffs\nthere too. Covered by two tests: --mantle --dry-run warns, plain\n--dry-run stays quiet.",
"is_bot": false,
"headline": "fix: show Mantle tradeoff warning on apply --dry-run (#241)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-03T03:56:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "497ac7cb2509ef784e07f2ea442e00657225b359",
"body": "Enabling Mantle routing (--mantle / --mantle-url) silently dropped\nprompt caching and restricted Claude to current-generation models,\nwith no indication to the user. Prompt caching is unavailable on the\nMantle endpoints (verified against AWS docs: the caching page lists\nonly Converse/InvokeModel/Pro\n[…]\n, mirroring the existing warnAutoModeModel, so\napply prints an actionable heads-up when Mantle is enabled. Covered by\nthree tests: --mantle warns, --mantle-url warns, and the default path\nstays quiet.",
"is_bot": false,
"headline": "fix: warn about Mantle tradeoffs on apply (#240)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-03T03:35:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7837ba4e7580b23fce016feea2162bfd8cb9d692",
"body": null,
"is_bot": false,
"headline": "chore(release): v5.2.8 (#239)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-02T03:05:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "31d8067a11eb6b343257ec21e287f95fc88270c7",
"body": "…refix (#238)\n\nTwo correctness bugs found by an adversarial code sweep:\n\n1. apply --dry-run could pop an interactive Bedrock API key prompt.\n runApply called resolveCredential before the dry-run check, so a\n dry-run with --auth=bedrock-api-key and no --bedrock-key / stored key\n blocked on a hu\n[…]\nin a\nunit test, and shipping an untested line would break TDD. A PowerShell\n\"dedup always appends\" finding was a false positive (the dedup list grows\nwithin the loop) and discarded after verification.",
"is_bot": false,
"headline": "fix: dry-run no longer prompts for credentials; strip us-gov. model p…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-02T02:44:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0c56fec772ae06437b62ff7c9f98810ce5edc6a7",
"body": "…rnings (#237)\n\n* test: second coverage sweep — expiry parsing, binary resolution, doctor warnings\n\nContinues the data-driven backfill into the untouched high-value areas,\nkeeping only pure-logic and safety-critical branches.\n\n- bedrock.ParseAPIKeyExpiry: malformed date layout, non-integer expires,\n\n[…]\nn-executable-claude fixture used 0o644, tripping gosec G306\n(lint + Codacy). 0o600 has no execute bits either, so the test still\nexercises the isExecutable==false skip — a real fix, not a suppression.",
"is_bot": false,
"headline": "test: coverage sweep 2 — expiry parsing, binary resolution, doctor wa…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-02T02:03:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "226daed02e9ae9f60cf51b34520818b135d42b48",
"body": "…#236)\n\nData-driven sweep of below-100% functions, keeping only pure-logic and\nsafety-critical branches (skipping OS-error-injection passthroughs).\n\n- safepath: cover withinBase exact rel==\"..\" parent escape and WriteFile\n rejection outside base (path-containment security). 85.7% -> 90.5%.\n- keycha\n[…]\n: homeDir fallback when HOME and USERPROFILE are both empty (error\n branch), and uninstall abort on stdin EOF (block must survive). cmd\n 77.1% -> 78.3%.\n\nTotal 80.7% -> 81.1%. No production changes.",
"is_bot": false,
"headline": "test: backfill safety/logic coverage across safepath, keychain, cmd (…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-02T00:22:22Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "67f2891829846dd5bed4f60bbdf76f1dfc594353",
"body": "* test(activation): cover artifact-recovery safety paths\n\nThe v4.2.6 artifact recovery decides whether a file named claude may be\nremoved; a false positive deletes a user's real Claude Code binary. The\nexisting tests covered only the happy path (a known shim is removed).\n\nAdd the safety-critical neg\n[…]\np-restore test as a critical\nsecurity issue (go_filesystem_rule-fileread). The path is under\nt.TempDir(); annotate with the same nosemgrep suppression the sibling\ntests already use for temp-dir reads.",
"is_bot": false,
"headline": "test(activation): cover artifact-recovery safety paths (#235)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-02T00:07:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2679898205b82c8042aa9762e3df7db1dd7190ce",
"body": "…ight no-op) (#234)\n\nBoth flags were registered but never read. --no-opusplan claimed to\n\"disable opusplan\" yet was ignored, so --opusplan --no-opusplan silently\nkept opusplan on. --skip-preflight claimed to \"skip dependency checks\"\nbut no preflight check exists.\n\n- --no-opusplan: add a conflict gua\n[…]\n pass it; hidden-noop is non-breaking and\n matches the repo's existing compat pattern.\n\nAdds tests: the conflict errors, --no-opusplan alone succeeds, and\n--skip-preflight stays accepted.\n\nFixes #233",
"is_bot": false,
"headline": "fix(apply): make dead flags honest (--no-opusplan guard, --skip-prefl…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-01T08:43:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "811eaa1f389fb206ea1c7ee7131046e24f49a55a",
"body": "Claude Code's Shift+Tab writes the native permissions.defaultMode\ndirectly without touching Juggernaut's meta block. resolveApplyInputs\nonly restored meta.permissionMode, so on a re-apply with no --mode the\nmerge layer (mergePermissions) deleted the user's externally-chosen\nmode — silently disabling\n[…]\ns cmd-level regression tests: externally-set mode survives re-apply\n(with env var restored), Juggernaut-set auto still round-trips, and an\nexplicit --mode still overrides a preserved mode.\n\nFixes #231",
"is_bot": false,
"headline": "fix(apply): preserve externally-set permission mode on re-apply (#232)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-01T08:41:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "22ecba0440a38666aefe3738e8b063311cda175f",
"body": "… (#230)\n\nremoveBlock tracked block state with a single inBlock bool set on BEGIN\nand only cleared on a matching END. An orphaned BEGIN marker (no following\nEND) left inBlock true through EOF, silently deleting every subsequent\nline of the user's shell profile on apply and uninstall.\n\nRoute removeBl\n[…]\n diverge.\n\nAdds regression tests for the orphaned-marker case across removeBlock,\nupsertBlock (install path), and RemoveTarget (uninstall path), plus\nmatched-pair and multi-block coverage.\n\nFixes #229",
"is_bot": false,
"headline": "fix(activation): preserve profile content after orphaned BEGIN marker…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-07-01T08:06:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d76fa28d99672a9654f1e8b05cf46b448cbb400b",
"body": null,
"is_bot": false,
"headline": "chore(release): v5.2.7 (#228)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-06-29T06:44:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b4d06c6671c55730a8bbcc5dcfab7ea81ecc0b6a",
"body": "… (#227)",
"is_bot": false,
"headline": "fix(ci): harden release pipeline against draft-only GoReleaser config…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-06-29T06:41:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5f7e695fefcb6e8af29f51539ec83015c47d0cd0",
"body": "PR #212 added `draft: true` to the GoReleaser config. GoReleaser honors it\nby uploading assets to an unpublished draft, and nothing in release.yml\nun-drafts the release — so every release since #212 has required a manual\n`gh release edit --draft=false`. The npm publish steps run regardless, which\nma\n[…]\nen GitHub-release half (npm looked fine while the GitHub\nrelease sat as a draft).\n\nSet draft: false so a `v*` tag push fully publishes the release with no\nmanual step, restoring the pre-#212 behavior.",
"is_bot": false,
"headline": "fix(release): publish GitHub release automatically on tag push (#226)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-06-29T06:36:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4386be0efa6d5701ab6402a19be76b7aac4faa33",
"body": "… (#225)\n\nnpm 11 refuses install scripts by default and prints a loud allow-scripts\nwarning for every package declaring one; its suggested remediation command\ndrops the package name, leading users to a confusing ENOENT against their\ncwd. The Windows-only preinstall probe was self-admittedly unreliab\n[…]\n after extracting packages) and fully redundant with the\nruntime version-skew guard in index.js. Removing it yields a clean install\nwith no loss of partial-install protection.\n\nBumps version to 5.2.6.",
"is_bot": false,
"headline": "chore(npm): drop redundant preinstall script for clean install output…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-06-29T05:00:33Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "633b86bb63db6b1438f28ab6736db34d70746a36",
"body": null,
"is_bot": false,
"headline": "chore(release): v5.2.5 (#224)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-06-29T04:00:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "71513bbe89dc793065c45b0cad3906b6da7da3b2",
"body": "…t (#223)\n\nresolvePkgDir previously joined pkgName into a path with no local\nvalidation, trusting its caller — so its path-traversal suppression\nasserted a safety it didn't locally guarantee (the allowlist check lived\nonly in getBinaryPath). Validate pkgName against VALID_PACKAGES inside\nresolvePkgD\n[…]\nrite both suppression comments to cite the local invariant:\nallowlisted constant name, no separators/.., joined under __dirname,\ncannot escape. Add tests asserting both functions reject unknown names.",
"is_bot": false,
"headline": "fix(npm): make resolvePkgDir self-defending so its nosemgrep is hones…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-06-29T03:45:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "40e6a8a63cae8a4fb815967e5377a390c5a62a47",
"body": "…ary (#222)\n\n* feat(npm): refuse to launch a version-skewed (partial) install\n\n* feat(npm): block install on Windows while a session locks the binary\n\n* fix(npm): suppress false-positive path-traversal finding on version-skew read\n\nThe pkg name flows from getPlatformPackage (hardcoded VALID_PACKAGES\n[…]\n cannot guarantee it prevents the partial install — the runtime\nversion-skew guard in index.js is the reliable net. Document the npm\nordering limitation and soften the user-facing message accordingly.",
"is_bot": false,
"headline": "fix(npm): fail loud on partial install instead of running a stale bin…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-06-29T03:36:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3675cf1e7e111e85fe4f259cb3d89d525e24d9cf",
"body": "…igration tests (#221)\n\n* fix(keychain): never wipe a credential on a failed fallback write\n\nPre-release credential-stability hardening (from a 3-agent audit before cutting\nthe release).\n\nSetWithFallback previously deleted the keychain entry BEFORE writing the file\nfallback (in the big-key and keych\n[…]\now asserts the correct per-platform destination:\nv2 file on Windows; keychain + removed-stale-file on macOS/Linux. Both still\nround-trip via GetWithFallback. Skips on hosts without a keychain backend.",
"is_bot": false,
"headline": "fix(keychain): never wipe a credential on a failed fallback write + m…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-06-28T16:34:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "80fbb42839b755521d56e8fd99032ecdb3cf306a",
"body": "…g) — v5.2.4 (#220)\n\n* feat(keychain): DPAPI-encrypt Windows file fallback; surface backend errors\n\nTwo hardening fixes for the credential layer (v5.2.4):\n\n1. DPAPI encryption for the Windows file fallback. Large keys (e.g. short-term\n Bedrock keys ~5KB that exceed the 2560-byte Windows Credential\n[…]\nis\nan upper bound, not a guarantee. Documented ParseAPIKeyExpiry accordingly and\nreworded doctor's OK message to 'valid until at most ... (may expire sooner if\nthe generating AWS session ends first)'.",
"is_bot": false,
"headline": "feat: Bedrock credential hardening (DPAPI, key-expiry, error surfacin…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-06-28T16:04:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8f13d053bd551be54282dec45f648fbe45e2ad6d",
"body": "* chore(ci): wire up Codecov coverage reporting via OIDC\n\nAdd Codecov upload to the existing test-coverage job using OIDC (no stored\nCODECOV_TOKEN — public repo, short-lived audience-scoped token at run time).\n\n- gotestsum emits junit.xml alongside the coverage profile in one run\n- upload coverage.o\n[…]\n test -coverprofile and the CI normalize step produce coverage/coverage.out/\ncoverage.tmp/junit.xml locally; ignore them so they never dirty the tree\n(GoReleaser requires a clean git tree at release).",
"is_bot": false,
"headline": "chore(ci): wire up Codecov coverage reporting via OIDC (#218)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-06-28T06:37:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ab5af041d26a9344aedf492f3c72080b6f0d33d5",
"body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6.4.0 to 6.5.0.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/4a3601121dd01d1626a1e23e37211e3254c1c06c...924ae3a1cded613372ab5595356fb5720e22ba16)\n\n---\nupdated\n[…]\ned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Juan Pablo (JP) <jpvelasco@users.noreply.github.com>",
"is_bot": true,
"headline": "chore(deps): bump actions/setup-go from 6.4.0 to 6.5.0 (#217)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-28T06:25:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "89c52b5dc6f34d8024efa0e9ea8d82f128d59295",
"body": "The v5.2.2 launch path read credentials from the keychain only, so short-term\nBedrock API keys (~5KB, exceeding the 2560-byte Windows keychain limit) that\nwere stored in the file fallback came back as 'not found in keychain'. The\nlaunch fallback-getter fix (GetWithFallback) is already in main but was never\nreleased. Bump VERSION/bedrock-config.json/cmd.Version to 5.2.3 and document\nthe fix so both short-term and long-term keys work on Windows.",
"is_bot": false,
"headline": "fix: release launch fallback-getter fix as v5.2.3 (#219)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-06-28T04:56:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "005f89106a79c67654ea961b15eaeb3d3991ef52",
"body": "… CI coverage\n\nFixes five review findings: launch fallback getter, keychain deletion failure propagation, stale fallback cleanup, credential file security, and CI coverage truncation. Adds versioned credential envelope for fallback file migration, keychain-first precedence for legacy files, and full migration test coverage.",
"is_bot": false,
"headline": "fix: wire launch to fallback getter, enforce credential security, fix…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-06-27T16:52:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "dfc77d4675b0c59303e71ff22e97fe53be3bcac2",
"body": null,
"is_bot": false,
"headline": "fix(ci): update actions/cache SHA in release workflow (#214)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-06-27T13:57:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d9032498f8d1a0c4aa3efb8bfb2c5e4c90c8a851",
"body": null,
"is_bot": false,
"headline": "chore: Release v5.2.2 (#213)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-06-27T11:51:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1b1b8ab86d00c49642e5af7edd0886b6fe381550",
"body": "…provements (#212)\n\n* chore: overhaul CI pipeline with lint, test, security, and release improvements\n\n- Pin Go 1.26 in CI (was 'stable'), add module caching to all jobs\n- Add race detector, coverage (60% threshold), npm test, shellcheck, gosec jobs\n- Create .golangci.yml with staticcheck + gosec + \n[…]\nrect os.MkdirAll(0o700) + os.WriteFile with safepath.WriteFile\nwhich handles directory creation internally. Also removes silencing configs\nadded to .codacy.yml, .codacy/codacy.yaml, and .semgrep.yaml.",
"is_bot": false,
"headline": "chore: overhaul CI pipeline with lint, test, security, and release im…",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-06-27T10:39:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "2dba727383cf7936ff74a7a12a97e1a11c6f60ee",
"body": null,
"is_bot": false,
"headline": "Release v5.2.1 (#211)",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-06-27T08:40:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9e1edfd8f2b3ebcbb2da1811cd0eb0c4517f5ac1",
"body": "…(#210)\n\n* fix(activation): discover PowerShell profiles dynamically on Windows\n\n- Replace hardcoded \\C:\\Users\\jpvel/Documents paths with dynamic \\C:\\Users\\jpvel\\OneDrive\\Documents\\PowerShell\\Microsoft.PowerShell_profile.ps1\n discovery via pwsh.exe and powershell.exe\n- Add fallback to Windows Known\n[…]\ncs only, fails locally)\n\n* revert: restore lizard in Codacy config\n\n* fix: remove lizard from Codacy config (cloud-metrics only, fails locally)\n\n* fix: add valid patterns to lizard.yaml for Codacy CLI",
"is_bot": false,
"headline": "fix(activation): discover PowerShell profiles dynamically on Windows …",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-06-27T07:50:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1196df3f72433b391721ae572de7dd424c045f3c",
"body": "Minor release. Extends Bedrock parity with new Claude Code features (Fable aliases, native fallback chains, flexible effort levels) and improves auto mode + telemetry controls for Bedrock users.\n\nIncludes Fable model support, --fallback-model, improved --effort handling, auto mode warnings for Bedrock, and nonessential traffic suppression.",
"is_bot": false,
"headline": "Release v5.2.0",
"author_name": "Juan Pablo (JP)",
"author_login": "jpvelasco",
"committed_at": "2026-06-26T19:05:19Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 71,
"commits_last_year": 346,
"latest_release_at": "2026-07-21T19:48:30Z",
"latest_release_tag": "v5.5.0",
"releases_from_tags": false,
"days_since_last_push": 1,
"active_weeks_last_year": 21,
"days_since_latest_release": 1,
"mean_days_between_releases": 2.5
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 100,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "github.com/jpvelasco/juggernaut/v5",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/jpvelasco/juggernaut/v5",
"is_deprecated": false,
"latest_version": "v5.5.0",
"repository_url": "https://github.com/jpvelasco/juggernaut",
"versions_count": 28,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-21T19:46:34Z",
"latest_version_yanked": null,
"days_since_latest_publish": 1
},
{
"name": "juggernaut-bedrock",
"exists": true,
"license": "MIT",
"keywords": [
"bedrock",
"amazon-bedrock",
"aws",
"claude",
"claude-code",
"anthropic",
"codex",
"opencode",
"grok",
"genai",
"ai-coding",
"llm",
"coding-agent",
"cli",
"iam",
"sso",
"mantle",
"developer-tools"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/juggernaut-bedrock",
"is_deprecated": false,
"latest_version": "5.5.0",
"repository_url": "https://github.com/jpvelasco/juggernaut",
"versions_count": 40,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 4471,
"first_published_at": "2026-06-05T16:34:40.992000Z",
"latest_published_at": "2026-07-21T19:49:04.379000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 1
}
]
},
"popularity": {
"forks": 0,
"stars": 0,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 1
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [
"Makefile"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [],
"toolchain_manifests": [
"go.mod"
],
"largest_source_bytes": 84677,
"source_files_sampled": 141,
"oversized_source_files": 1,
"agent_instruction_files": [
".github/instructions/codacy.instructions.md",
"AGENTS.md",
"CLAUDE.md"
],
"agent_instruction_max_bytes": 21205
},
"dependencies": {
"manifests": [
"go.mod",
"npm/package.json"
],
"advisories": {
"error": null,
"scope": "repository_graph",
"source": "osv",
"findings": [
{
"name": "golang.org/x/text",
"direct": false,
"version": "v0.37.0",
"severity": "unknown",
"ecosystem": "go",
"cvss_score": null,
"advisory_ids": [
"GO-2026-5970"
],
"fixed_version": "0.39.0",
"advisory_count": 1,
"oldest_advisory_days": 8
}
],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {
"unknown": 1
},
"advisory_count": 1,
"affected_count": 1,
"assessed_count": 58,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go",
"npm"
],
"dependencies": [
{
"name": "github.com/BurntSushi/toml",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "github.com/aws/aws-sdk-go-v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.42.1"
},
{
"name": "github.com/aws/aws-sdk-go-v2/config",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.32.30"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/bedrock",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.65.1"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/sts",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.1"
},
{
"name": "github.com/charmbracelet/huh",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.0"
},
{
"name": "github.com/gofrs/flock",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.13.0"
},
{
"name": "github.com/spf13/cobra",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.10.2"
},
{
"name": "github.com/spf13/pflag",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.0.9"
},
{
"name": "github.com/zalando/go-keyring",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.2.8"
},
{
"name": "github.com/charmbracelet/bubbles",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.21.1-0.20250623103423-23b8fd6302d7"
},
{
"name": "github.com/charmbracelet/x/windows",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.2.2"
},
{
"name": "golang.org/x/sys",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.45.0"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "github.com/aws/aws-sdk-go-v2",
"direct": true,
"version": "v1.42.1",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/config",
"direct": true,
"version": "v1.32.30",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/bedrock",
"direct": true,
"version": "v1.65.1",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/sts",
"direct": true,
"version": "v1.44.1",
"ecosystem": "go"
},
{
"name": "github.com/burntsushi/toml",
"direct": true,
"version": "v1.6.0",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/bubbles",
"direct": true,
"version": "v0.21.1-0.20250623103423-23b8fd6302d7",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/huh",
"direct": true,
"version": "v1.0.0",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/windows",
"direct": true,
"version": "v0.2.2",
"ecosystem": "go"
},
{
"name": "github.com/gofrs/flock",
"direct": true,
"version": "v0.13.0",
"ecosystem": "go"
},
{
"name": "github.com/spf13/cobra",
"direct": true,
"version": "v1.10.2",
"ecosystem": "go"
},
{
"name": "github.com/spf13/pflag",
"direct": true,
"version": "v1.0.9",
"ecosystem": "go"
},
{
"name": "github.com/zalando/go-keyring",
"direct": true,
"version": "v0.2.8",
"ecosystem": "go"
},
{
"name": "golang.org/x/sys",
"direct": true,
"version": "v0.45.0",
"ecosystem": "go"
},
{
"name": "github.com/atotto/clipboard",
"direct": false,
"version": "v0.1.4",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/credentials",
"direct": false,
"version": "v1.19.29",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/feature/ec2/imds",
"direct": false,
"version": "v1.18.30",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/internal/configsources",
"direct": false,
"version": "v1.4.30",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/internal/endpoints/v2",
"direct": false,
"version": "v2.7.30",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/internal/v4a",
"direct": false,
"version": "v1.4.31",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding",
"direct": false,
"version": "v1.13.13",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/internal/presigned-url",
"direct": false,
"version": "v1.13.30",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/signin",
"direct": false,
"version": "v1.4.1",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/sso",
"direct": false,
"version": "v1.32.1",
"ecosystem": "go"
},
{
"name": "github.com/aws/aws-sdk-go-v2/service/ssooidc",
"direct": false,
"version": "v1.37.1",
"ecosystem": "go"
},
{
"name": "github.com/aws/smithy-go",
"direct": false,
"version": "v1.27.3",
"ecosystem": "go"
},
{
"name": "github.com/aymanbagabas/go-osc52/v2",
"direct": false,
"version": "v2.0.1",
"ecosystem": "go"
},
{
"name": "github.com/catppuccin/go",
"direct": false,
"version": "v0.3.0",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/bubbletea",
"direct": false,
"version": "v1.3.6",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/colorprofile",
"direct": false,
"version": "v0.2.3-0.20250311203215-f60798e515dc",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/lipgloss",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/ansi",
"direct": false,
"version": "v0.9.3",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/cellbuf",
"direct": false,
"version": "v0.0.13",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/exp/strings",
"direct": false,
"version": "v0.0.0-20240722160745-212f7b056ed0",
"ecosystem": "go"
},
{
"name": "github.com/charmbracelet/x/term",
"direct": false,
"version": "v0.2.1",
"ecosystem": "go"
},
{
"name": "github.com/danieljoos/wincred",
"direct": false,
"version": "v1.2.3",
"ecosystem": "go"
},
{
"name": "github.com/dustin/go-humanize",
"direct": false,
"version": "v1.0.1",
"ecosystem": "go"
},
{
"name": "github.com/erikgeiser/coninput",
"direct": false,
"version": "v0.0.0-20211004153227-1c3628e74d0f",
"ecosystem": "go"
},
{
"name": "github.com/godbus/dbus/v5",
"direct": false,
"version": "v5.2.2",
"ecosystem": "go"
},
{
"name": "github.com/inconshreveable/mousetrap",
"direct": false,
"version": "v1.1.0",
"ecosystem": "go"
},
{
"name": "github.com/lucasb-eyer/go-colorful",
"direct": false,
"version": "v1.2.0",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-isatty",
"direct": false,
"version": "v0.0.20",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-localereader",
"direct": false,
"version": "v0.0.1",
"ecosystem": "go"
},
{
"name": "github.com/mattn/go-runewidth",
"direct": false,
"version": "v0.0.16",
"ecosystem": "go"
},
{
"name": "github.com/mitchellh/hashstructure/v2",
"direct": false,
"version": "v2.0.2",
"ecosystem": "go"
},
{
"name": "github.com/muesli/ansi",
"direct": false,
"version": "v0.0.0-20230316100256-276c6243b2f6",
"ecosystem": "go"
},
{
"name": "github.com/muesli/cancelreader",
"direct": false,
"version": "v0.2.2",
"ecosystem": "go"
},
{
"name": "github.com/muesli/termenv",
"direct": false,
"version": "v0.16.0",
"ecosystem": "go"
},
{
"name": "github.com/rivo/uniseg",
"direct": false,
"version": "v0.4.7",
"ecosystem": "go"
},
{
"name": "github.com/stretchr/objx",
"direct": false,
"version": "v0.5.3",
"ecosystem": "go"
},
{
"name": "github.com/xo/terminfo",
"direct": false,
"version": "v0.0.0-20220910002029-abceb7e1c41e",
"ecosystem": "go"
},
{
"name": "golang.org/x/exp",
"direct": false,
"version": "v0.0.0-20240909161429-701f63a606c0",
"ecosystem": "go"
},
{
"name": "golang.org/x/sync",
"direct": false,
"version": "v0.20.0",
"ecosystem": "go"
},
{
"name": "golang.org/x/text",
"direct": false,
"version": "v0.37.0",
"ecosystem": "go"
},
{
"name": "juggernaut-bedrock-darwin-arm64",
"direct": false,
"version": "0.0.0",
"ecosystem": "npm"
},
{
"name": "juggernaut-bedrock-darwin-x64",
"direct": false,
"version": "0.0.0",
"ecosystem": "npm"
},
{
"name": "juggernaut-bedrock-linux-arm64",
"direct": false,
"version": "0.0.0",
"ecosystem": "npm"
},
{
"name": "juggernaut-bedrock-linux-x64",
"direct": false,
"version": "0.0.0",
"ecosystem": "npm"
},
{
"name": "juggernaut-bedrock-win32-x64",
"direct": false,
"version": "0.0.0",
"ecosystem": "npm"
}
],
"collected": true,
"truncated": false,
"total_count": 58,
"direct_count": 13,
"indirect_count": 45
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 290,
"open_issues": 1,
"closed_ratio": 0.955,
"closed_issues": 21,
"closed_unmerged_prs": 12
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "jpvelasco",
"commits": 330,
"avatar_url": "https://avatars.githubusercontent.com/u/143497?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"codeql.yml",
"octopus.yml",
"release.yml"
],
"has_docs_dir": true,
"linter_configs": [
".golangci.yml"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"go.sum"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 4,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/26 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 3,
"reason": "project has 1 contributing companies or organizations -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": 10,
"reason": "packaging workflow detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 10,
"reason": "all dependencies are pinned",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 4,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 9,
"reason": "1 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "50714f567815e98b732b57c642ec47177c1b5329",
"ran_at": "2026-07-23T11:09:10Z",
"aggregate_score": 6.2,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": true,
"has_security_policy": true,
"has_dependabot_config": true
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-21T19:55:55Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-07-21T19:54:18Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": [
{
"number": 208,
"created_at": "2026-06-26T18:27:06Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/jpvelasco/juggernaut",
"host": "github.com",
"name": "juggernaut",
"owner": "jpvelasco"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 69,
"inputs": {
"security": 70,
"vitality": 83,
"community": 48,
"governance": 56,
"engineering": 86
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 83,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 78,
"inputs": {
"commits_last_year": 346,
"human_commit_share": 0.92,
"days_since_last_push": 1,
"active_weeks_last_year": 21
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 1 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 1
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "21/52 weeks with commits",
"points": 14.5,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 21
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "346 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 346
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 71,
"latest_release_tag": "v5.5.0",
"releases_from_tags": false,
"days_since_latest_release": 1,
"mean_days_between_releases": 2.5
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "71 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 71
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 1 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 1
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~2.5 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 2.5
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 1,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 1 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 1
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 48,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 0,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 92,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "moderate",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 61,
"inputs": {
"packages": [
"github.com/jpvelasco/juggernaut/v5",
"juggernaut-bedrock"
],
"dependents": null,
"ecosystems": "go, npm",
"total_downloads": null,
"monthly_downloads": 4471
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "4,471 downloads/month across go, npm",
"points": 48.7,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 4471,
"ecosystems": "go, npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 56,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 13,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "good",
"name": "Issue & PR responsiveness",
"note": null,
"notes": [],
"value": 81,
"inputs": {
"merged_prs": 290,
"open_issues": 1,
"closed_issues": 21,
"issue_closed_ratio": 0.955,
"closed_unmerged_prs": 12
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "96% of issues closed",
"points": 44.6,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 96
}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "290/302 decided PRs merged",
"points": 36.7,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 290,
"decided": 302
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/26 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 47,
"inputs": {
"followers": 12,
"owner_type": "User",
"is_verified": null,
"owner_login": "jpvelasco",
"public_repos": 11,
"account_age_days": 6117
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "12 followers of jpvelasco",
"points": 8,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 12,
"login": "jpvelasco"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "11 public repos, account ~16 yr old",
"points": 19.9,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 11
}
},
{
"code": "account_age_years",
"params": {
"years": 16
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"github.com/jpvelasco/juggernaut/v5",
"juggernaut-bedrock"
],
"ecosystems": "go, npm",
"any_deprecated": false,
"min_days_since_publish": 1
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "2 package(s) on go, npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 2,
"ecosystems": "go, npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 1 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 1
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "40 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 40
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "excellent",
"name": "Engineering Quality",
"value": 86,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "4 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 4
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": ".golangci.yml",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"topics": [
"anthropic",
"aws",
"bedrock",
"claude",
"cli",
"developer-tools",
"claude-code"
],
"has_wiki": false,
"homepage": "https://www.npmjs.com/package/juggernaut-bedrock",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://www.npmjs.com/package/juggernaut-bedrock",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "7 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 7
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "good",
"name": "Security",
"value": 70,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": null,
"notes": [],
"value": 62,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 18,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 0,
"scorecard_aggregate": 6.2
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 3,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/26 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "all dependencies are pinned",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 2,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "1 existing vulnerabilities detected",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "dependency_advisories",
"band": "excellent",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 58 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"indirect_dependencies_free_of_known_advisories",
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_repository",
"params": {
"assessed": 58
}
},
{
"code": "advisories_repo_graph_caveat",
"params": {}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 1,
"affected_packages": 1,
"assessed_packages": 58,
"unassessed_packages": 0,
"affected_by_severity": "unknown 1",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "transitive set not separable from development and test dependencies in this scope",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_scope_not_separable",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "excellent",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 58,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 2
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "excellent",
"name": "AI Readiness",
"value": 90,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
".github/instructions/codacy.instructions.md",
"AGENTS.md",
"CLAUDE.md"
],
"agent_instruction_max_bytes": 21205
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": ".github/instructions/codacy.instructions.md, AGENTS.md, CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".github/instructions/codacy.instructions.md, AGENTS.md, CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "92 of 92 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 92,
"sampled": 92
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "excellent",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [
"Makefile"
],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [],
"agent_commit_share": 0,
"toolchain_manifests": [
"go.mod"
],
"dependency_bot_commit_share": 0.08
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": ".golangci.yml",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "Go (statically typed)",
"points": 11,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "8 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 8,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "all dependencies are pinned",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 84677,
"source_files_sampled": 141,
"oversized_source_files": 1
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "1/141 source files over 60KB",
"points": 54.6,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 141,
"oversized": 1
}
}
],
"max_points": 55
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"deps.dev does not index npm:juggernaut-bedrock@5.5.0; advisories assessed against the repository dependency graph instead"
],
"report_type": "repository",
"generated_at": "2026-07-23T11:09:27.713669Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/j/jpvelasco/juggernaut.svg",
"full_name": "jpvelasco/juggernaut",
"license_state": "standard",
"license_spdx": "MIT"
}