公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-23 11:09 UTC

jpvelasco / juggernaut

Juggernaut is a one-command setup tool that configures Claude Code to use AWS Bedrock, with cross-platform support (bash/zsh/fish/PowerShell), dry-run mode, and validation scripts.

GoMIT★ 0 星标⑂ 0 复刻始于 2026年1月在 GitHub 上查看 ↗

jpvelasco/juggernaut 的健康指数为 100 分中的 69 分,处于「中等」区间。 其得分最高的类别是AI Readiness(90/100),最低的是Community & Adoption(48/100)。 最近一次更新在 1 天前。 近期的大部分工作由 1 位贡献者完成。

69
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

69
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

Juan Pablo (JP)个人账户
12 关注者11 个公开仓库始于 2009年10月AWS

该仓库由个人账户拥有。相较于组织支持的项目,单一所有者项目的延续性风险更高。

软件包生态系统

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

83良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 1 天前
14.5/36提交节奏 — 52 周中有 21 周有提交
18/18提交量 — 最近一年 346 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year346
human_commit_share0.92
days_since_last_push1
active_weeks_last_year21

发布纪律

90优秀
评分方式
27/27有发布版本 — 已发布 71 个发布版本
36/36发布时效 — 最近一次发布版本于 1 天前
27/27发布节奏 — 约每 2.5 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — Project has not signed or included provenance with any releases.
所用输入
releases_count71
latest_release_tagv5.5.0
releases_from_tags
days_since_latest_release1
mean_days_between_releases2.5

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

48存在风险 · 占总体的 18%
评分方式
0/60星标 — 0 个星标
0/25复刻 — 0 个复刻
0/15关注者 — 0 位关注者
所用输入
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

92优秀
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(MIT)
18/18CONTRIBUTING 指南
13.5/13.5行为准则
0/7.2议题模板
6.3/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
48.7/80月度下载量 — go, npm 合计每月 4,471 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packagesgithub.com/jpvelasco/juggernaut/v5, juggernaut-bedrock
dependents
ecosystemsgo, npm
total_downloads
monthly_downloads4,471
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

56中等 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0/22.5提交分布 — 头号贡献者编写了 100% 的提交
1.4/13.5贡献者广度 — 1 位贡献者
3/10OpenSSF Scorecard:Contributors — project has 1 contributing companies or organizations -- score normalized to 3
所用输入
bus_factor1
contributors_sampled1
top_contributor_share1
评分方式
44.6/46.8议题解决 — 96% 的议题已关闭
36.7/38.3PR 接受 — 已裁定的 PR 中 290/302 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/26 approved changesets -- score normalized to 0
所用输入
merged_prs290
open_issues1
closed_issues21
issue_closed_ratio0.955
closed_unmerged_prs12
评分方式
10/30所有权背书 — 个人(用户)账户
0/20已验证域名 — 不适用于个人账户
8/25所有者影响力 — jpvelasco 有 12 位关注者
19.9/25既往记录 — 11 个公开仓库,账户约 16 年
所用输入
followers12
owner_typeUser
is_verified
owner_loginjpvelasco
public_repos11
account_age_days6,117
已排除计分(无数据或不适用):已验证域名。 其余权重已重新归一化。
评分方式
25/25已发布且可解析 — go, npm 上有 2 个软件包
35/35发布时效 — 最近一次发布于 1 天前
20/20版本历史 — 40 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesgithub.com/jpvelasco/juggernaut/v5, juggernaut-bedrock
ecosystemsgo, npm
any_deprecated
min_days_since_publish1

工程质量

基础的工程与文档实践是否到位?

86优秀 · 占总体的 20%

工程实践

84良好
评分方式
24/24CI 工作流 — 4 个工作流
24/24存在测试
16/16Linter 配置 — .golangci.yml
0/9.6Pre-commit 钩子
0/6.4.editorconfig
20/20OpenSSF Scorecard:CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

90优秀
评分方式
30/30README
25/25文档目录
15/15文档 / 主页站点 — https://www.npmjs.com/package/juggernaut-bedrock
10/10仓库描述
10/10主题标签 — 7 个主题标签
0/10Wiki
所用输入
topicsanthropic, aws, bedrock, claude, cli, developer-tools, claude-code
has_wiki
homepagehttps://www.npmjs.com/package/juggernaut-bedrock
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

70良好 · 占总体的 16%

安全态势

62中等
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
3/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/26 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
5/5Pinned-Dependencies — all dependencies are pinned
5/5SAST — SAST tool is run on all commits
2/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
6.8/7.5Vulnerabilities — 1 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated18
scorecard_versionv5.5.0
checks_inconclusive0
scorecard_aggregate6.2
评分方式
35/35直接依赖不含已知公告 — 没有直接依赖携带已知公告
0/25间接依赖不含已知公告 — 在此范围内,传递依赖集合无法与开发和测试依赖区分
0/40没有长期未处理的公告 — 没有公告带有发布日期
所用输入
sourceosv
advisories1
affected_packages1
assessed_packages58
unassessed_packages0
affected_by_severityunknown 1
direct_affected_packages0
已排除计分(无数据或不适用):间接依赖不含已知公告, 没有长期未处理的公告。 其余权重已重新归一化。 已将 58 个已解析依赖与 OSV 比对。 该仓库未发布任何索引可解析的软件包,因此改为评估仓库依赖图。该图将开发与测试版本固定同交付的依赖混在一起,因此仅对声明的运行时依赖计分;传递性发现仅作为背景信息列出,不计入评分。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

90优秀 · 占总体的 0%
评分方式
45/45代理指令 — .github/instructions/codacy.instructions.md, AGENTS.md, CLAUDE.md
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 92 次人类提交中有 92 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share1
agent_instruction_files.github/instructions/codacy.instructions.md, AGENTS.md, CLAUDE.md
agent_instruction_max_bytes21,205
评分方式
18/18一条命令的引导启动 — Makefile
22/22自动化测试
11/11Lint / 格式化配置 — .golangci.yml
11/11静态类型检查 — Go(静态类型)
10/10可复现环境 — lockfile
0/10已体现的代理实践 — 最近 100 次提交中没有代理编写的提交
8/8自动化维护 — 最近 100 次提交中有 8 次为自动依赖更新
10/10OpenSSF Scorecard:Pinned-Dependencies — all dependencies are pinned
所用输入
has_nix
has_tests
lockfilesgo.sum
has_dockerfile
typed_language
bootstrap_filesMakefile
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0
toolchain_manifestsgo.mod
dependency_bot_commit_share0.08
评分方式
45/45可类型检查的代码 — Go(静态类型)
54.6/55可控的文件大小 — 采样的 141 个源文件中有 1 个超过 60KB
所用输入
primary_languageGo
largest_source_bytes84,677
source_files_sampled141
oversized_source_files1

关键数据

0GitHub 星标
1贡献者
346最近 12 个月提交数
1距最近推送天数
71发布版本数
1巴士系数(bus factor)
1开放议题
Go, npm软件包生态系统数

数据采集警告

  • deps.dev does not index npm:juggernaut-bedrock@5.5.0; advisories assessed against the repository dependency graph instead

更多细节

OpenSSF Scorecard 6.2 / 10
6.2综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-23 11:09 UTC

10Binary-Artifactsno binaries found in the repo
4Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/26 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
10Pinned-Dependenciesall dependencies are pinned
10SASTSAST tool is run on all commits
4Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
9Vulnerabilities1 existing vulnerabilities detected
直接依赖 13
注册表软件包版本约束清单文件
Gogithub.com/BurntSushi/tomlv1.6.0go.mod
Gogithub.com/aws/aws-sdk-go-v2v1.42.1go.mod
Gogithub.com/aws/aws-sdk-go-v2/configv1.32.30go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/bedrockv1.65.1go.mod
Gogithub.com/aws/aws-sdk-go-v2/service/stsv1.44.1go.mod
Gogithub.com/charmbracelet/huhv1.0.0go.mod
Gogithub.com/gofrs/flockv0.13.0go.mod
Gogithub.com/spf13/cobrav1.10.2go.mod
Gogithub.com/spf13/pflagv1.0.9go.mod
Gogithub.com/zalando/go-keyringv0.2.8go.mod
Gogithub.com/charmbracelet/bubblesv0.21.1-0.20250623103423-23b8fd6302d7go.mod
Gogithub.com/charmbracelet/x/windowsv0.2.2go.mod
Gogolang.org/x/sysv0.45.0go.mod
全部依赖 58

来自 GitHub 依赖图的完整解析依赖集合:13 个直接依赖与 45 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
Gogithub.com/aws/aws-sdk-go-v2v1.42.1直接
Gogithub.com/aws/aws-sdk-go-v2/configv1.32.30直接
Gogithub.com/aws/aws-sdk-go-v2/service/bedrockv1.65.1直接
Gogithub.com/aws/aws-sdk-go-v2/service/stsv1.44.1直接
Gogithub.com/burntsushi/tomlv1.6.0直接
Gogithub.com/charmbracelet/bubblesv0.21.1-0.20250623103423-23b8fd6302d7直接
Gogithub.com/charmbracelet/huhv1.0.0直接
Gogithub.com/charmbracelet/x/windowsv0.2.2直接
Gogithub.com/gofrs/flockv0.13.0直接
Gogithub.com/spf13/cobrav1.10.2直接
Gogithub.com/spf13/pflagv1.0.9直接
Gogithub.com/zalando/go-keyringv0.2.8直接
Gogolang.org/x/sysv0.45.0直接
Gogithub.com/atotto/clipboardv0.1.4间接
Gogithub.com/aws/aws-sdk-go-v2/credentialsv1.19.29间接
Gogithub.com/aws/aws-sdk-go-v2/feature/ec2/imdsv1.18.30间接
Gogithub.com/aws/aws-sdk-go-v2/internal/configsourcesv1.4.30间接
Gogithub.com/aws/aws-sdk-go-v2/internal/endpoints/v2v2.7.30间接
Gogithub.com/aws/aws-sdk-go-v2/internal/v4av1.4.31间接
Gogithub.com/aws/aws-sdk-go-v2/service/internal/accept-encodingv1.13.13间接
Gogithub.com/aws/aws-sdk-go-v2/service/internal/presigned-urlv1.13.30间接
Gogithub.com/aws/aws-sdk-go-v2/service/signinv1.4.1间接
Gogithub.com/aws/aws-sdk-go-v2/service/ssov1.32.1间接
Gogithub.com/aws/aws-sdk-go-v2/service/ssooidcv1.37.1间接
Gogithub.com/aws/smithy-gov1.27.3间接
Gogithub.com/aymanbagabas/go-osc52/v2v2.0.1间接
Gogithub.com/catppuccin/gov0.3.0间接
Gogithub.com/charmbracelet/bubbleteav1.3.6间接
Gogithub.com/charmbracelet/colorprofilev0.2.3-0.20250311203215-f60798e515dc间接
Gogithub.com/charmbracelet/lipglossv1.1.0间接
Gogithub.com/charmbracelet/x/ansiv0.9.3间接
Gogithub.com/charmbracelet/x/cellbufv0.0.13间接
Gogithub.com/charmbracelet/x/exp/stringsv0.0.0-20240722160745-212f7b056ed0间接
Gogithub.com/charmbracelet/x/termv0.2.1间接
Gogithub.com/danieljoos/wincredv1.2.3间接
Gogithub.com/dustin/go-humanizev1.0.1间接
Gogithub.com/erikgeiser/coninputv0.0.0-20211004153227-1c3628e74d0f间接
Gogithub.com/godbus/dbus/v5v5.2.2间接
Gogithub.com/inconshreveable/mousetrapv1.1.0间接
Gogithub.com/lucasb-eyer/go-colorfulv1.2.0间接
Gogithub.com/mattn/go-isattyv0.0.20间接
Gogithub.com/mattn/go-localereaderv0.0.1间接
Gogithub.com/mattn/go-runewidthv0.0.16间接
Gogithub.com/mitchellh/hashstructure/v2v2.0.2间接
Gogithub.com/muesli/ansiv0.0.0-20230316100256-276c6243b2f6间接
Gogithub.com/muesli/cancelreaderv0.2.2间接
Gogithub.com/muesli/termenvv0.16.0间接
Gogithub.com/rivo/unisegv0.4.7间接
Gogithub.com/stretchr/objxv0.5.3间接
Gogithub.com/xo/terminfov0.0.0-20220910002029-abceb7e1c41e间接
Gogolang.org/x/expv0.0.0-20240909161429-701f63a606c0间接
Gogolang.org/x/syncv0.20.0间接
Gogolang.org/x/textv0.37.0间接
npmjuggernaut-bedrock-darwin-arm640.0.0间接
npmjuggernaut-bedrock-darwin-x640.0.0间接
npmjuggernaut-bedrock-linux-arm640.0.0间接
npmjuggernaut-bedrock-linux-x640.0.0间接
npmjuggernaut-bedrock-win32-x640.0.0间接
依赖安全公告 1

该仓库未发布可被索引解析的包,因此评估的是其自身的依赖图——共 58 个包,其中也包含从不交付的开发与测试版本固定:1 个存在已知公告,0 个为直接依赖。

软件包版本关系严重程度公告数修复版本
golang.org/x/textv0.37.0间接未知10.39.0

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [
        "anthropic",
        "aws",
        "bedrock",
        "claude",
        "cli",
        "developer-tools",
        "claude-code"
      ],
      "is_fork": false,
      "size_kb": 10890,
      "has_wiki": false,
      "homepage": "https://www.npmjs.com/package/juggernaut-bedrock",
      "languages": {
        "Go": 1095563,
        "Shell": 1521,
        "Makefile": 692,
        "JavaScript": 20778,
        "PowerShell": 742
      },
      "pushed_at": "2026-07-21T19:54:20Z",
      "created_at": "2026-01-07T04:27:00Z",
      "owner_type": "User",
      "updated_at": "2026-07-21T19:54:22Z",
      "description": "Juggernaut is a one-command setup tool that configures Claude Code to use AWS Bedrock, with cross-platform support (bash/zsh/fish/PowerShell), dry-run mode, and validation scripts.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": null,
      "name": "Juan Pablo (JP)",
      "type": "User",
      "login": "jpvelasco",
      "company": "AWS",
      "location": "Portland",
      "followers": 12,
      "avatar_url": "https://avatars.githubusercontent.com/u/143497?v=4",
      "created_at": "2009-10-23T04:31:31Z",
      "is_verified": null,
      "public_repos": 11,
      "account_age_days": 6117
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v5.5.0",
          "kind": "minor",
          "published_at": "2026-07-21T19:48:30Z"
        },
        {
          "tag": "v5.4.0",
          "kind": "minor",
          "published_at": "2026-07-17T03:59:52Z"
        },
        {
          "tag": "v5.3.4",
          "kind": "patch",
          "published_at": "2026-07-06T19:23:52Z"
        },
        {
          "tag": "v5.3.3",
          "kind": "patch",
          "published_at": "2026-07-05T07:17:15Z"
        },
        {
          "tag": "v5.3.2",
          "kind": "patch",
          "published_at": "2026-07-05T00:48:40Z"
        },
        {
          "tag": "v5.3.1",
          "kind": "patch",
          "published_at": "2026-07-04T23:50:38Z"
        },
        {
          "tag": "v5.3.0",
          "kind": "minor",
          "published_at": "2026-07-04T07:38:17Z"
        },
        {
          "tag": "v5.2.9",
          "kind": "patch",
          "published_at": "2026-07-03T04:28:05Z"
        },
        {
          "tag": "v5.2.8",
          "kind": "patch",
          "published_at": "2026-07-02T03:08:43Z"
        },
        {
          "tag": "v5.2.7",
          "kind": "patch",
          "published_at": "2026-06-29T06:46:24Z"
        },
        {
          "tag": "v5.2.6",
          "kind": "patch",
          "published_at": "2026-06-29T05:07:24Z"
        },
        {
          "tag": "v5.2.5",
          "kind": "patch",
          "published_at": "2026-06-29T04:05:22Z"
        },
        {
          "tag": "v5.2.4",
          "kind": "patch",
          "published_at": "2026-06-28T16:49:34Z"
        },
        {
          "tag": "v5.2.2",
          "kind": "patch",
          "published_at": "2026-06-27T14:08:54Z"
        },
        {
          "tag": "v5.2.1",
          "kind": "patch",
          "published_at": "2026-06-27T08:42:07Z"
        },
        {
          "tag": "v5.2.0",
          "kind": "minor",
          "published_at": "2026-06-26T19:19:06Z"
        },
        {
          "tag": "v5.1.6",
          "kind": "patch",
          "published_at": "2026-06-26T05:44:19Z"
        },
        {
          "tag": "v5.1.5",
          "kind": "patch",
          "published_at": "2026-06-26T04:42:23Z"
        },
        {
          "tag": "v5.1.4",
          "kind": "patch",
          "published_at": "2026-06-26T02:37:19Z"
        },
        {
          "tag": "v5.1.3",
          "kind": "patch",
          "published_at": "2026-06-25T22:49:26Z"
        },
        {
          "tag": "v5.1.2",
          "kind": "patch",
          "published_at": "2026-06-25T21:16:02Z"
        },
        {
          "tag": "v5.1.1",
          "kind": "patch",
          "published_at": "2026-06-22T09:16:41Z"
        },
        {
          "tag": "v5.1.0",
          "kind": "minor",
          "published_at": "2026-06-22T07:51:34Z"
        },
        {
          "tag": "v5.0.4",
          "kind": "patch",
          "published_at": "2026-06-19T16:08:34Z"
        },
        {
          "tag": "v5.0.3",
          "kind": "patch",
          "published_at": "2026-06-19T09:50:37Z"
        },
        {
          "tag": "v5.0.2",
          "kind": "patch",
          "published_at": "2026-06-19T09:28:13Z"
        },
        {
          "tag": "v5.0.1",
          "kind": "patch",
          "published_at": "2026-06-19T00:59:29Z"
        },
        {
          "tag": "v5.0.0",
          "kind": "major",
          "published_at": "2026-06-18T21:40:35Z"
        },
        {
          "tag": "v4.2.6",
          "kind": "patch",
          "published_at": "2026-06-17T23:20:33Z"
        },
        {
          "tag": "v4.2.5",
          "kind": "patch",
          "published_at": "2026-06-17T14:48:53Z"
        },
        {
          "tag": "v4.2.4",
          "kind": "patch",
          "published_at": "2026-06-15T15:27:07Z"
        },
        {
          "tag": "v4.2.3",
          "kind": "patch",
          "published_at": "2026-06-15T14:48:08Z"
        },
        {
          "tag": "v4.2.2",
          "kind": "patch",
          "published_at": "2026-06-15T04:59:34Z"
        },
        {
          "tag": "v4.2.1",
          "kind": "patch",
          "published_at": "2026-06-15T00:16:45Z"
        },
        {
          "tag": "v4.1.0",
          "kind": "minor",
          "published_at": "2026-06-14T09:12:51Z"
        },
        {
          "tag": "v4.0.4",
          "kind": "patch",
          "published_at": "2026-06-13T19:27:34Z"
        },
        {
          "tag": "v4.0.3",
          "kind": "patch",
          "published_at": "2026-06-13T19:00:40Z"
        },
        {
          "tag": "v4.0.2",
          "kind": "patch",
          "published_at": "2026-06-13T17:31:38Z"
        },
        {
          "tag": "v4.0.1",
          "kind": "patch",
          "published_at": "2026-06-13T16:48:47Z"
        },
        {
          "tag": "v4.0.0",
          "kind": "major",
          "published_at": "2026-06-05T16:52:33Z"
        },
        {
          "tag": "v3.2.3",
          "kind": "patch",
          "published_at": "2026-05-15T23:55:51Z"
        },
        {
          "tag": "v3.2.2",
          "kind": "patch",
          "published_at": "2026-05-13T05:59:13Z"
        },
        {
          "tag": "v3.2.1",
          "kind": "patch",
          "published_at": "2026-05-11T23:17:41Z"
        },
        {
          "tag": "v3.2.0",
          "kind": "minor",
          "published_at": "2026-05-11T02:20:05Z"
        },
        {
          "tag": "v3.1.1",
          "kind": "patch",
          "published_at": "2026-05-09T07:53:54Z"
        },
        {
          "tag": "v3.1.0",
          "kind": "minor",
          "published_at": "2026-05-09T05:30:06Z"
        },
        {
          "tag": "v3.0.8",
          "kind": "patch",
          "published_at": "2026-05-05T03:10:27Z"
        },
        {
          "tag": "v3.0.7",
          "kind": "patch",
          "published_at": "2026-05-04T23:05:42Z"
        },
        {
          "tag": "v3.0.6",
          "kind": "patch",
          "published_at": "2026-05-04T07:47:05Z"
        },
        {
          "tag": "v3.0.3",
          "kind": "patch",
          "published_at": "2026-05-04T01:49:26Z"
        },
        {
          "tag": "v3.0.2",
          "kind": "patch",
          "published_at": "2026-05-04T00:04:34Z"
        },
        {
          "tag": "v3.0.1",
          "kind": "patch",
          "published_at": "2026-05-04T00:34:02Z"
        },
        {
          "tag": "v3.0.0",
          "kind": "major",
          "published_at": "2026-05-02T21:37:30Z"
        },
        {
          "tag": "v2.3.4",
          "kind": "patch",
          "published_at": "2026-05-01T23:32:07Z"
        },
        {
          "tag": "v2.3.3",
          "kind": "patch",
          "published_at": "2026-05-01T22:34:11Z"
        },
        {
          "tag": "v2.3.2",
          "kind": "patch",
          "published_at": "2026-05-01T22:08:33Z"
        },
        {
          "tag": "v2.3.1",
          "kind": "patch",
          "published_at": "2026-05-01T21:32:12Z"
        },
        {
          "tag": "v2.3.0",
          "kind": "minor",
          "published_at": "2026-05-01T17:35:27Z"
        },
        {
          "tag": "v2.2.5",
          "kind": "patch",
          "published_at": "2026-04-27T01:20:31Z"
        },
        {
          "tag": "v2.2.4",
          "kind": "patch",
          "published_at": "2026-04-27T01:19:52Z"
        },
        {
          "tag": "v2.2.4-rc.2",
          "kind": "prerelease",
          "published_at": "2026-04-27T00:19:48Z"
        },
        {
          "tag": "v2.2.5-rc.2",
          "kind": "prerelease",
          "published_at": "2026-04-27T00:20:26Z"
        },
        {
          "tag": "v2.2.3",
          "kind": "patch",
          "published_at": "2026-04-25T17:47:13Z"
        },
        {
          "tag": "v2.2.2",
          "kind": "patch",
          "published_at": "2026-04-25T09:45:44Z"
        },
        {
          "tag": "v2.2.1",
          "kind": "patch",
          "published_at": "2026-04-25T08:23:37Z"
        },
        {
          "tag": "v2.2.0",
          "kind": "minor",
          "published_at": "2026-04-25T06:10:24Z"
        },
        {
          "tag": "v2.1.3",
          "kind": "patch",
          "published_at": "2026-04-25T00:27:27Z"
        },
        {
          "tag": "v2.1.2",
          "kind": "patch",
          "published_at": "2026-04-24T19:57:48Z"
        },
        {
          "tag": "v2.1.1",
          "kind": "patch",
          "published_at": "2026-04-24T11:19:47Z"
        },
        {
          "tag": "v2.1.0",
          "kind": "minor",
          "published_at": "2026-04-24T10:43:44Z"
        },
        {
          "tag": "v2.0.0",
          "kind": "major",
          "published_at": "2026-04-22T22:43:58Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "50714f567815e98b732b57c642ec47177c1b5329",
          "body": "The codecov/codecov-action v7 downloads a native binary that requires\nGPG signature verification. On macOS (and sometimes Linux) runners, the\nkey import step returns empty, causing 'Could not verify signature'\nfailures with fail_ci_if_error: true.\n\nSet use_pypi: true so the CLI comes from PyPI instead of the signed\nnative binary path. Keeps fail_ci_if_error: true for real upload errors.\n\nSee codecov/codecov-action#1876.",
          "is_bot": false,
          "headline": "fix(ci): use Codecov PyPI CLI to avoid GPG key import failures (#324)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-21T19:54:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3183ba1eb826801175f99f6fa8168eae06d54b3c",
          "body": null,
          "is_bot": false,
          "headline": "chore: release v5.5.0 (#323)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-21T19:46:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7472dafc77063bde53f065e9df63319efda9952",
          "body": "Add tests that exercise the warnf warning branches which were\nnot covered by existing tests:\n\n- TestShow_ScopePathError: runShow with missing config triggers\n  the 'could not read user settings' warnf in show.go\n- TestUninstallSettingsBlock_ManagerError: unreadable config dir\n  triggers the warnf paths in uninstall.go\n- TestReportLegacyRecovery_Error: empty temp dir triggers the\n  warnf path in reportLegacyRecovery",
          "is_bot": false,
          "headline": "test: cover warnf error paths in show, uninstall, and helpers (#321)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-21T18:15:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "27f19980e17797e9885e86e7da760c153354f99c",
          "body": "* refactor: extract warnf helper for stderr warnings\n\n* test: add coverage for warnf helper",
          "is_bot": false,
          "headline": "refactor: extract warnf helper for stderr warnings (#320)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-21T17:52:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0933e0ef7d5e59c17f9f34b90c0cb93900147367",
          "body": "Rename normalizeModelList to exported ValidateModelList in\ninternal/schema, then update cmd/apply parseCommaSeparatedModels\nto split the comma string and delegate validation. Eliminates\nduplicate trim/empty-check logic between schema.Build and the\napply command.",
          "is_bot": false,
          "headline": "refactor: deduplicate ValidateModelList into schema package (#319)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-21T17:42:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24662539f5ed75587496b2f3b0fc44245491909f",
          "body": null,
          "is_bot": false,
          "headline": "refactor: deduplicate toMap — single shared provider.ToMap (#318)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-21T17:36:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "70ba3152f09293f8edc022d3ef1f116f54995117",
          "body": "…eProvider.SupportsModel (#317)\n\nAdd tests for the helpers introduced by the dedup refactor\n(PR #316) so Codecov's patch-coverage gate passes:\n\n- safepath: HomeDir prefers HOME over USERPROFILE, falls\n  back to UserHomeDir; HomeDirOrEmpty returns empty string\n  instead of an error\n- provider: checkModelPreconditions rejects inactive and\n  unavailable catalog models; BaseProvider.SupportsModel\n  runs pre-checks before rejecting unknown sources",
          "is_bot": false,
          "headline": "test: cover HomeDir, HomeDirOrEmpty, checkModelPreconditions, and Bas…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-21T16:24:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ece3083ecfc0b583152e88b5ff56331e7e89fc3",
          "body": "…nd home dir resolution (#316)\n\nMove the Status/IsAvailable pre-checks shared across all four\nSupportsModel implementations into a single checkModelPreconditions()\nhelper in base.go. Providers call it before their source-specific\nlogic, eliminating 8 lines of identical guards per provider.\n\nExtract \n[…]\nOFILE →\nUserHomeDir) into safepath.HomeDir() and safepath.HomeDirOrEmpty(),\nreplacing three identical inline implementations in cmd/helpers.go,\nactivation.DefaultBinDir, and activation.resolveHomeDir.",
          "is_bot": false,
          "headline": "refactor: deduplicate SupportsModel guards, model ID normalization, a…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-21T16:16:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e43ba7141530bed4450e04e5312db1ef6fa9d2c6",
          "body": "Merge normalizeFallbackModels and normalizeAvailableModels into a\nshared normalizeModelList helper in schema.\n\nExtract removeLegacyBlock and HasLegacyBlock generic helpers in\nactivation, replacing duplicated legacy marker logic.\n\nAdd catalogUnavailableWarning helper in provider/plan to centralize\nth\n[…]\nross codex, grok, and\nopencode BuildConfig implementations.\n\nReplace profilePathKey wrapper calls with direct pathKey usage and\nremove the thin adapter.\n\nNet: -10 lines across 8 files. All tests pass.",
          "is_bot": false,
          "headline": "refactor: deduplicate activation and provider packages",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-21T09:52:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c0965a87e79b5481128f01d31675833cb98c8113",
          "body": "Eliminate structural duplication across the cmd/ package:\n\n- newProviderManager() centralizes ConfigPath → FormatByName →\n  NewManagerWithFormat sequence (was repeated 3x)\n- resolvedScopes() replaces inline scope resolution in doctor and show\n- tierModelPtr() unifies tier↔model mapping for read/write paths\n\nNo behavioral changes. All tests pass. 0 Codacy issues.",
          "is_bot": false,
          "headline": "refactor: deduplicate cmd package — shared helpers and unified patterns",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-21T09:32:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8047bc9a39bf76c3c893f78325101ba8302c3ab9",
          "body": "The analysis-cli init --remote captured absolute Windows paths for\nlocalConfigurationFile (shellcheckrc and markdownlint). These fail\non Codacy Cloud and any checkout not at F:\\source\\juggernaut.\n\nReplace absolute paths with repo-relative ones:\n  F:\\\\source\\\\juggernaut\\\\.shellcheckrc -> .shellcheckrc\n  F:\\\\source\\\\juggernaut\\\\.markdownlint.json -> .markdownlint.json",
          "is_bot": false,
          "headline": "fix: use repo-relative paths in codacy.config.json (#313)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-21T09:16:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "63afc77f4cc5d97cc450c837dab5c57a924d5328",
          "body": "Replace legacy codacy-cli v2 artifacts (codacy.yaml, cli-config.yaml,\ntools-configs/) with codacy.config.json from the modern analysis-cli.\n\n- Remove .codacy/codacy.yaml (legacy tool version list)\n- Remove .codacy/cli-config.yaml (legacy auth config)\n- Remove .codacy/tools-configs/ (legacy per-tool config files)\n- Add .codacy/codacy.config.json (modern analysis-cli config, fetched\n  via codacy-analysis init --remote)\n- Add generated/ to .codacy/.gitignore (analysis-cli cached binaries)",
          "is_bot": false,
          "headline": "chore: migrate to codacy-analysis-cli config format (#312)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-21T09:09:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5ee746e7b3944047cd38e97ed478909283ec9f55",
          "body": "… (#311)\n\n* test: cover model discovery gaps and fix CI issues\n\n- Export safepath.DirPerm so tests can restore directory permissions\n  without explicit permission literals (Codacy FileAccess)\n- Add Sources field to RegionCatalog so empty-but-refreshed catalogs\n  still prove model unavailability (Cod\n[…]\nurces into single call\n\nEliminates double cache read in apply and removes the unreachable\ncachedProviderSources error path in apply.go. Tests updated to use\nthe unified cachedProviderCatalog function.",
          "is_bot": false,
          "headline": "test: cover model discovery and provider plan gaps flagged by Codecov…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-21T08:25:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a431f79044c2bce0ffb04d9320af786861852bfa",
          "body": "* feat: discover account Bedrock models\n\n* fix: harden account model discovery\n\n* test: cover model catalog workflows\n\n* test: cover catalog error handling\n\n* test: raise model discovery coverage\n\n* test: use private directory helper",
          "is_bot": false,
          "headline": "feat: discover account-available Bedrock models (#309)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-21T06:52:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "56441857c00d0a532452f192c1eede2dfeabe3c7",
          "body": "* test: cover writeProfile error paths in activation removal\n\n* test: gracefully skip write-error tests when running as root",
          "is_bot": false,
          "headline": "test: cover writeProfile error paths in activation removal (#308)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-20T16:08:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c558ca2c2166d0ad4f64f01eaca7a67cf12670b4",
          "body": "…(#307)\n\n* refactor: eliminate structural duplication across cmd/ and internal/\n\nReduce 32% duplication (Codacy) by extracting shared helpers and\nconverting copy-pasted tests to table-driven format.\n\ncmd/ changes:\n- Extract readProviderConfig helper (eliminates 4x duplicated\n  ConfigPath -> FormatBy\n[…]\nify activation path helpers and authmode constants\n- Clean up provider plan.go boilerplate\n\nNet: -291 lines across 33 files. All tests pass, vet clean.\n\n* fix: remove unused test helpers and fix gofmt",
          "is_bot": false,
          "headline": "refactor: eliminate structural duplication across cmd/ and internal/ …",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-20T08:10:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "460dfbb1ec16fa3240573a67d1208f83098ef8ae",
          "body": "…(#303)\n\nBumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.37.0 to 4.37.1.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump github/codeql-action/analyze from 4.37.0 to 4.37.1 …",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T03:51:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "adb7ee5384e688454cff8e462af49a9f44470ce6",
          "body": "* chore(deps): bump actions/setup-node from 6.4.0 to 7.0.0\n\nBumps [actions/setup-node](https://github.com/actions/setup-node) from 6.4.0 to 7.0.0.\n- [Release notes](https://github.com/actions/setup-node/releases)\n- [Commits](https://github.com/actions/setup-node/compare/48b55a011bda9f5d6aeb4c2d9c736\n[…]\ned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Juan Pablo (JP) <jpvelasco@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/setup-node from 6.4.0 to 7.0.0 (#302)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T03:47:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "623be0f123f448649389e38e8814f7ba60b13fdc",
          "body": "* chore(deps): bump actions/setup-go from 6.5.0 to 7.0.0\n\nBumps [actions/setup-go](https://github.com/actions/setup-go) from 6.5.0 to 7.0.0.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/924ae3a1cded613372ab5595356fb5720e22ba1\n[…]\ned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Juan Pablo (JP) <jpvelasco@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/setup-go from 6.5.0 to 7.0.0 (#305)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T03:35:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5d358d7b9336a8068f9edd420ec5c72fa0cfe8cd",
          "body": "Bumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.0 to 4.37.1.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/comp\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump github/codeql-action/init from 4.37.0 to 4.37.1 (#304)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-20T03:26:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "854917f4ec600e365560b513cf6f77f347e574e8",
          "body": "Migrate all remaining JavaScript Actions to node24 runtime before the\nSeptember 16, 2026 hard cutoff:\n\n- actions/cache: v4 (node20) -> v6 (node24)\n- codecov/test-results-action (deprecated) -> codecov/codecov-action v7.0.0\n  with report_type: test_results",
          "is_bot": false,
          "headline": "chore: migrate GitHub Actions from node20 to node24 (#306)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-20T03:19:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d1ab47518d4c8c66cd9eb3bc1c488b894568f5e8",
          "body": "* test: improve coverage for cmd/helpers.go and internal/activation/activation.go\n\nAdd targeted tests for previously uncovered branches:\n- cmd/helpers.go: findBedrockConfigFile parent-dir fallback,\n  resolveCredential TUI error path, printApplyDryRun non-Claude provider\n- activation/activation.go: t\n[…]\ning\nonly conditionally checked the warning content — if the warning was\nnever fired, the test passed silently. The 2020 key is permanently\nexpired so the warning is guaranteed to fire; assert it does.",
          "is_bot": false,
          "headline": "test: improve coverage for helpers.go and activation.go (#301)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-20T02:59:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c64195d6450d3bfe0ee89fc8f0264e2f10cef708",
          "body": "… (#300)\n\n* refactor: reduce complexity — deduplicate code and fill coverage gaps\n\n- Consolidate apply test setup into shared helpers (apply_test_helpers.go)\n- Extract apply.go phases into helpers.go, reducing apply.go from 649 to 254 lines\n- Introduce BaseProvider struct to remove boilerplate acros\n[…]\nbletea opens\na console reader that blocks indefinitely until the 10-minute test timeout.\n\nSkip the test on Windows since it only verifies the keychain warning path\nand the interactive prompt behavior.",
          "is_bot": false,
          "headline": "refactor: reduce complexity — deduplicate code and fill coverage gaps…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-17T17:40:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5e5b514ec5f3abab0fbb6de4a28b1d0e26df3516",
          "body": "* fix: harden shell profile activation install and uninstall\n\nStop dead juggernaut wrappers from breaking real CLIs after incomplete\nuninstall or PATH skew: fall through when juggernaut is missing, strip\nstale CurrentHost blocks on apply, scan AllHosts plus OneDrive/local\nDocuments on cleanup, and s\n[…]\n\nRecord the fallthrough shell-block body change under Unreleased and update\nthe README activation example so the silent marker upsert on re-apply is\nexplicit for operators (checklist item on PR #299).",
          "is_bot": false,
          "headline": "fix: harden shell profile activation install and uninstall (#299)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-17T06:18:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "23472f2aed6c13edb5fd9b4caf80a3115fb2c5cf",
          "body": "setup-go's hardcoded go-version: \"1.26\" let a stale per-runner tool\ncache silently satisfy CI even when it didn't match go.mod's actual\nminimum (surfaced when the 1.26.5 bump in #297 passed on a runner\nwith 1.26.5 cached, then failed on main's post-merge run because a\ndifferent macos-latest runner still had 1.26.4 cached).\n\ngo-version-file: go.mod makes go.mod the single source of truth —\nsetup-go parses the go directive itself, so bumping it there is now\nenough; CI needs no matching edit.",
          "is_bot": false,
          "headline": "fix: derive CI Go version from go.mod instead of hardcoding it (#298)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-17T04:46:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "29edfa2f805425fdf2c47c6703948441f391995a",
          "body": "CVE-2026-39822 (os.Root symlink traversal, High) and CVE-2026-42505\n(crypto/tls ECH info disclosure, Warning) are fixed in 1.26.5. The\nprior attempt in PR #293 was reverted because CI runners only had\n1.26.4 via GOTOOLCHAIN=local; Go 1.26.5 is now released, and CI's\nsetup-go step uses the floating \"1.26\" version so it should resolve\nto the patch release automatically.",
          "is_bot": false,
          "headline": "fix: bump go.mod to 1.26.5 (closes #295) (#297)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-17T04:36:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "45214b1fbf24fddd51542785fd1a0a611d7c36ba",
          "body": null,
          "is_bot": false,
          "headline": "chore: release v5.4.0 (#296)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-17T03:55:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d0c851f8f95fdb2f01b17d8f1a3d4ec19d5e26a7",
          "body": "* feat(npm): block install on Windows while a session locks the binary\n\nAdd a Windows-only preinstall gate that refuses npm install while\njuggernaut.exe is running, preventing partial/stale installs. Fail-open\non non-Windows and probe errors. Complements the existing runtime\nversion-skew guard.\n\n* d\n[…]\niveAuth-incompatible Mantle bearer tokens, so\nquickstart/README examples must use --auth=bedrock-api-key. Document that\nManager.Read already maps missing config files to empty maps for optional scope.",
          "is_bot": false,
          "headline": "chore: OSS stabilization — npm install guard + community docs (#294)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-16T04:37:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "455ab62bba65d95247f032c3feef5c1da0c913a5",
          "body": "… (#293)\n\n* chore: add aws-sdk-go-v2 dependency for model discovery\n\n* feat: add internal/discovery package for live Bedrock model catalog queries\n\n* feat: add tier family-matching and report formatting to internal/discovery\n\n* feat: add juggernaut models check command (report-only path)\n\n* feat: ad\n[…]\ny for bare IDs); preserve unknown bedrock-config.json\nfields on --write; recompute LEGACY exit status after a successful write.\n\n* test(models): silence Codacy path-read finding in write preserve test",
          "is_bot": false,
          "headline": "feat: add juggernaut models check command for Bedrock model discovery…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-16T04:31:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3f7e9420e54b1b6dbff54c61ea9bc899823db099",
          "body": "* feat: pin default Fable Bedrock model ID (closes #206)\n\nbedrock-config.json's models.fable was intentionally left empty in PR #204\npending an officially verifiable Bedrock Fable model ID. Verified live\nagainst AWS Bedrock's ListFoundationModels and ListInferenceProfiles APIs:\nglobal.anthropic.clau\n[…]\n, so Juggernaut can't check it — apply and doctor now both warn\nwhenever Fable is configured instead of silently risking denied calls.\n\nAddresses the data-retention finding on PR #292's review thread.",
          "is_bot": false,
          "headline": "feat: pin default Fable Bedrock model ID (closes #206) (#292)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-15T22:30:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e64c1c8734512620634ed8ece5e27ed349a4e7c4",
          "body": "…ck (#290)\n\n* feat: add availableModels/enforceAvailableModels to schema layer\n\n* feat: thread availableModels/enforceAvailableModels through provider layer\n\n* feat: add --available-models/--enforce-available-models flags\n\n* test: cover uninstall removal of availableModels keys; fix: simplify redund\n[…]\n\npath (e.g. /etc/claude-code/managed-settings.json), which Juggernaut does\nnot write to. Document this honestly rather than implying tamper-resistant\ngovernance the current write target can't deliver.",
          "is_bot": false,
          "headline": "feat: add availableModels/enforceAvailableModels governance for Bedro…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-15T18:05:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5c80f9cbe60b4f81f85158a8d02f4bb3cc96d31e",
          "body": "* feat: add fromMap helper (reverse of toMap)\n\n* feat: add checkAutoModeReadiness (silent path)\n\n* test: verify checkAutoModeReadiness OK path with real model IDs\n\n* test: cover checkAutoModeReadiness WARN paths and malformed-block no-op\n\n* feat: wire checkAutoModeReadiness into doctor's per-scope l\n[…]\node readiness line.\n\nAlso closes real coverage gaps found while fixing the above: fromMap's\njson.Marshal error branch and autoModeAvailableDetail's now-only branch\nwere untested; both are now at 100%.",
          "is_bot": false,
          "headline": "feat: add doctor auto-mode readiness check (closes #205) (#289)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-15T11:52:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e902db186fba7d13e70c3077df53d62aa50f35b7",
          "body": "github/codeql-action has been the one unpinned action in this repo since\nit was added in #273 — every other workflow step is already pinned to a\nfull commit SHA. Pin both codeql-action steps to the commit the v4 tag\ncurrently resolves to, matching the established pattern.",
          "is_bot": false,
          "headline": "chore: pin github/codeql-action to commit SHA (#288)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-15T09:00:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "946373e8b8e4fe2b258c13e0eb59b332c457578e",
          "body": "* chore(deps): bump github/codeql-action from 3 to 4\n\nBumps [github/codeql-action](https://github.com/github/codeql-action) from 3 to 4.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https\n[…]\ned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Juan Pablo (JP) <jpvelasco@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump github/codeql-action from 3 to 4 (#287)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-15T08:45:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0b4155c1139d03270ef6c0e96e1191d996b5b0a5",
          "body": "…(#286)\n\n* feat: refuse to overwrite foreign config on apply (\"Juggernaut law\")\n\napply previously merged into a CLI's config file with no warning even when\nthe file wasn't Juggernaut-managed and already had values at the exact\nkeys/leaves Juggernaut writes. Add internal/config.DetectCollisions, whic\n[…]\nase already avoids this via authmode.BedrockAPIKey, a var deliberately\nsplit (\"bedrock-\" + \"api-key\") to dodge static secret scanners. Use the\nsame constant here instead of inventing a new mitigation.",
          "is_bot": false,
          "headline": "feat: refuse to overwrite foreign config on apply (\"Juggernaut law\") …",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-15T08:27:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "beae254f530e8012a67cdcfd9bbae33f059ad5d9",
          "body": "Adds make codacy, documents all four providers (claude/codex/opencode/\ngrok), and captures Mantle opt-in, auto-mode guardrails, and managed\nsettings that CLAUDE.md already tracks but AGENTS.md had drifted from.",
          "is_bot": false,
          "headline": "docs: sync AGENTS.md with CLAUDE.md architecture and constraints (#285)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-08T15:17:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae9d1a3eefdd69c57f2b0f7e9e5c403ba792e476",
          "body": "* chore: update .github/GITHUB_SETTINGS.md\n\n* chore: update .github/codeql/codeql-config.yml\n\n* chore: update .github/instructions/codacy.instructions.md\n\n* docs: add required status checks guidance to GITHUB_SETTINGS.md\n\n* fix: restore required status checks in ruleset template\n\n---------\n\nCo-authored-by: JP Velasco <jp@velasco.me>",
          "is_bot": false,
          "headline": "feat: harden repo — community files, settings, security (#284)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-07T20:00:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2299c76cdb893f5cbfe48f3f23f094645ecf9dde",
          "body": "…lue (#280)",
          "is_bot": false,
          "headline": "fix: replace gitleaks false positive test secret with non-key-like va…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-07T04:42:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "92278388d039c95b5b0cf0dd3b4467fa0c5aafca",
          "body": "* chore: release v5.3.4\n\n* chore: bump version to v5.3.4\n\n* test: update golden for v5.3.4 version bump",
          "is_bot": false,
          "headline": "Release v5.3.4 (#279)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-06T19:22:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a28df1def97d48e2ff95628bb7f55c640d532db5",
          "body": "…#278)\n\n* ci: raise Codecov quality gate to 80% and enforce as required check\n\n- codecov.yml: raise project floor from 73% to 80%, remove 1%\n  threshold drift — zero tolerance below 80%\n- ci.yml: raise Linux-only test-coverage threshold from 60% to 65%\n  (Linux undercounts Windows-only code; Codecov\n[…]\n settings on uninstall\n- Update all affected tests\n\n* fix: gosec G306 — use 0o600 permissions for test config files\n\n* test: add coverage for readAuthModeFromConfig error paths and ConfigPath fallback",
          "is_bot": false,
          "headline": "ci: raise Codecov quality gate to 80% and enforce as required check (…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-06T17:34:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5c2967a4a4ffadbe3937b3934791181f145f1036",
          "body": "…ock provider (#277)\n\n* fix(codex): switch from custom bedrock-mantle to built-in amazon-bedrock provider\n\n* fix: deep-merge nested tables and narrow Codex provider ownership\n\n- Extend mergeNested to recursively merge nested maps so user sub-keys\n  (e.g. aws.profile) survive Juggernaut apply for the\n[…]\nnaged keys are absent after uninstall.\n- Add TestCodex_BuildConfig_ExplicitServingRegion: user explicitly\n  requests a serving region (us-east-1 for gpt-5.5) — no warning\n  emitted, region kept as-is.",
          "is_bot": false,
          "headline": "fix(codex): switch from custom bedrock-mantle to built-in amazon-bedr…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-06T16:54:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "04bede1aeeb8b63dc94367ff051fb6114fea1515",
          "body": "…#276)",
          "is_bot": false,
          "headline": "docs: mark legacy/v3 as protected branch in CLAUDE.md and AGENTS.md (…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-06T09:20:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1c898a2cf87e282f9ff01038b0f8be7074845497",
          "body": "…#275)\n\n* refactor: remove Octocov (redundant with Codecov for OSS repo)\n\n* docs: update CLAUDE.md and add AGENTS.md for multi-CLI architecture",
          "is_bot": false,
          "headline": "docs: update CLAUDE.md and add AGENTS.md for multi-CLI architecture (…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-06T09:15:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b5e216e760889a39607d33996182a8b8d7dc4618",
          "body": null,
          "is_bot": false,
          "headline": "refactor: remove Octocov (redundant with Codecov for OSS repo) (#274)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-06T08:45:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3da6e245b87c7500fce9645a28d1df9acebffdba",
          "body": "Replace GitHub's default CodeQL setup (UI toggle only) with a\ncommitted workflow and config. This fixes the '3 configurations not\nfound' warning on PRs and enables proper PR-level code scanning\ndiff reporting.\n\nConfig: security-extended query suite\nLanguages: actions, go, javascript-typescript\nTriggers: push, PR, weekly schedule",
          "is_bot": false,
          "headline": "chore: add explicit CodeQL workflow and config (#273)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-06T07:44:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2d330750c4370fbbb06c3fe9c4816bc23a9ec756",
          "body": "…#253)\n\nBumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) from 9.2.1 to 9.3.0.\n- [Release notes](https://github.com/golangci/golangci-lint-action/releases)\n- [Commits](https://github.com/golangci/golangci-lint-action/compare/82606bf257cbaff209d206a39f5134f0cfbfd\n[…]\nirect:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump golangci/golangci-lint-action from 9.2.1 to 9.3.0 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-06T07:25:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "27876e3f1ed09cbfcd3a71dff49fb926ccedc4bc",
          "body": "…252)\n\nBumps [goreleaser/goreleaser-action](https://github.com/goreleaser/goreleaser-action) from 7.2.2 to 7.2.3.\n- [Release notes](https://github.com/goreleaser/goreleaser-action/releases)\n- [Commits](https://github.com/goreleaser/goreleaser-action/compare/5daf1e915a5f0af01ddbcd89a43b8061ff4f1a89..\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump goreleaser/goreleaser-action from 7.2.2 to 7.2.3 (#…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-06T07:22:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2bfc7a97e10332d1b94e3cb28eb49add5e0af0d1",
          "body": "Remove local Codacy workflow and scripts in favor of Codacy cloud analysis:\n- Delete codacy-local.yml (not a required check, cloud webhook already gates)\n- Delete codacy-full.sh, codacy-sync.sh, patch-eslint.sh scripts\n- Delete dead semgrep.yaml (not in tools list, 100K+ lines of noise)\n- Simplify Makefile codacy target to cloud CLI (npx @codacy/codacy-cloud-cli)\n- Update CLAUDE.md Codacy docs to reflect cloud-only approach",
          "is_bot": false,
          "headline": "chore: migrate Codacy to cloud-only analysis (#271)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-06T06:19:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b5f93b54c17313366931c97af03ad6d4b6f9fb34",
          "body": "* ci: add octocov coverage metrics and Octopus Review workflows\n\n- Add .octocov.yml config (60% threshold, Go coverage format)\n- Add octocov workflow: runs tests with coverage, posts PR comments\n  with coverage stats, code-to-test ratio, and test execution time\n- Add Octopus Review workflow: AI code\n[…]\nitHub App (no workflow needed)\n\n* fix: correct octocov config format to use top-level keys\n\nUse coverage.paths and coverage.acceptable instead of\nthe incorrect octocov.coverage.files/threshold format.",
          "is_bot": false,
          "headline": "ci: add octocov coverage metrics and Octopus Review workflows (#270)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-06T05:27:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6d3e6fe8896a642b3d7280e6118b0e910d3e2b90",
          "body": "…n, and source file check (#267)\n\n* fix: harden stageLaunchBinary with pinned filename, tempDir validation, and source file check\n\n- Pin staged filename to fixed 'juggernaut-staged.exe' constant\n  instead of path.basename(bin), removing one variable from path\n- Validate tempDir is a directory after \n[…]\n validates bin via realpathSync + __dirname containment\n\nAlso fixes P2 review finding: all failures after mkdtempSync now flow\nthrough the try/catch cleanup path, preventing temp dir leaks on Windows.",
          "is_bot": false,
          "headline": "fix: harden stageLaunchBinary with pinned filename, tempDir validatio…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-06T04:03:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "14308554f0a3717574c58ca5fbc71e090891c6a9",
          "body": null,
          "is_bot": false,
          "headline": "ci: require Codacy Static Code Analysis gate on main (#269)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-06T03:49:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e325ab736c39d140f9af5bbf2de5597917af4130",
          "body": "* fix: address P2 review findings from PR #266\n\n- Redact bedrock-key secret values from argument error messages in\n  validateApplyArgs, so a mistyped `bedrock-key=<api key>` does not\n  leak the credential to stderr/logs\n\n- Prevent staged Windows launches from breaking resolveBinary\n  self-skipping: \n[…]\nth and TestResolveSelfPaths_RelativePath\n  on non-Windows since resolveSelfPaths returns nil before checking the env var\n\n* fix: remove duplicate Windows-only skip in TestResolveSelfPaths_AbsolutePath",
          "is_bot": false,
          "headline": "fix: address P2 review findings from PR #266 (#268)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-06T03:36:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bf05a0588093f92bdea3727f62b405c6730cbf5a",
          "body": "* fix: harden multi-CLI launches on Windows\n\n* fix: use full opengrep rule IDs in nosmgrep suppressions and add error-path coverage\n\nCI's codacy-cli opengrep requires full bundled rule IDs\n(javascript.lang.security.audit.path-traversal...) instead of\nshort names (path-join-resolve-traversal). The sh\n[…]\ns\n- cmd/apply_flags_test.go: tests for validateArgs with non-flag args\n  and empty args happy path\n- npm/index.test.js: add custom opengrep rule ID to nosmgrep suppressions\n  to match CI configuration",
          "is_bot": false,
          "headline": "fix: harden multi-CLI launch safety on Windows (#266)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-06T03:08:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "21ebea85d2ec1481e470db8fe9f2395a866c93cc",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v5.3.3 (#261)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-05T07:13:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f9a74d0c3b42763a866dbdc4e902e6cf8a93b4d",
          "body": "…apable) (#260)\n\nBumps the default/sonnet tier from claude-sonnet-4-6 to claude-sonnet-5\n(global.anthropic.claude-sonnet-5), matching Claude Code's first-party default\n(where `sonnet` now resolves to Sonnet 5). Verified live on Bedrock: listed +\nACTIVE in us-east-1/us-east-2/us-west-2 (and more), gl\n[…]\nt 5 is auto-capable) — no `claude --model opus`\nneeded. Sonnet 4.6 stays available via --sonnet-model (still ACTIVE on Bedrock;\nnot deprecated — only the alias default moved).\n\nVersion 5.3.2 -> 5.3.3.",
          "is_bot": false,
          "headline": "feat(models): default to Sonnet 5 on Bedrock (1M context, auto-mode c…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-05T07:05:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d9980b09673676b73a38ea5d820976e4accecf5c",
          "body": "…ed model is capable; add Sonnet 5 (#259)\n\nAuto mode never turned on for the common setup (Sonnet-tier default model, Opus\n4.8 run at runtime via `claude --model opus`). Two defects, both fixed:\n\n1. The enable var and the capability gate keyed off the DEFAULT (Sonnet) model,\n   so `apply --mode=auto\n[…]\n; AutoModeAvailable true/false matrix; Build emits/omits the var\ncorrectly; cmd asserts the enabled-info vs incapable-warning paths and the var.\nClaude golden byte-identical; full suite + gosec clean.",
          "is_bot": false,
          "headline": "fix(auto-mode): enable CLAUDE_CODE_ENABLE_AUTO_MODE when any configur…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-05T03:41:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3f646a6ec1ed88dba086815b3f3c60553df3ea7a",
          "body": "…token (#258)\n\nRunning `codex` directly (not via `juggernaut launch codex`) failed with\n\"Missing environment variable: AWS_BEARER_TOKEN_BEDROCK\". Our config used\nenv_key, which only works when the launch wrapper injects that var; a bare\n`codex` invocation has nothing to inject it. (The sign-in and r\n[…]\nauth] block (no env_key);\nauth-token --format=token emits the bare token, default still JSON; a user's own\n[model_providers.*] survives apply+uninstall (deep-merge). Full suite + gosec +\ngolden clean.",
          "is_bot": false,
          "headline": "fix(codex): use command-backed auth so a direct `codex` run gets the …",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-05T03:15:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e87c0e776bc112d2792d3fd01132d56c6b4498e4",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v5.3.2 (#257)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-05T00:44:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0aff42fd40bc1fdc8bda033be1f7cd76c0483ce9",
          "body": "…n Fist) (#256)\n\n`apply --cli=codex` with no --region defaulted to us-west-2, but gpt-5.5 is only\nserved in us-east-1/us-east-2 — so Juggernaut wrote a config Codex could not\nauthenticate against (JP hit exactly this: our own warning fired, then Codex\nchoked at request time). A user's configured reg\n[…]\n for now.\n\nVerified E2E: `apply --cli=codex` (default us-west-2) now writes a us-east-1\nbase_url with a heads-up; grok keeps us-west-2 (valid for grok-4.3) silently.\nFull suite + gosec + golden clean.",
          "is_bot": false,
          "headline": "fix(region): route Mantle CLIs to a region that serves the model (Iro…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-05T00:28:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cf570770cb9221c70c055110aa052f7ad94ad765",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v5.3.1 (#255)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-04T23:45:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bc724f1afeb24f957a5510473f7c7932c3d38281",
          "body": "… auth-token (#254)\n\n* fix(grok): skip sign-in via [auth] auth_provider_command + juggernaut auth-token\n\n`apply --cli=grok` wrote a valid [model.bedrock-grok] block but launching grok\nstill prompted the user to sign in — it never used the Bedrock routing. Root\ncause (verified against the official xA\n[…]\n, so Grok re-runs auth-token periodically and reads the rotated\nkeychain value. Short-term keys keep their exact embedded expiry.\n\nUpdated TestBuildAuthTokenJSON_BareToken to assert the bounded value.",
          "is_bot": false,
          "headline": "fix(grok): skip sign-in via [auth] auth_provider_command + juggernaut…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-04T23:33:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a3cbb0fca1f5f05da624bb029b8d67f310a72d08",
          "body": "… gpt-oss (#251)\n\n* fix(codex): skip ChatGPT login, reject IAM for Mantle-only CLIs, drop gpt-oss\n\nThree launch-auth fixes surfaced by a real report (codex launched and asked to\nsign in despite `apply --cli=codex`).\n\n1. Codex skipped ChatGPT login. The [model_providers.bedrock-mantle] block now\n   s\n[…]\n). Use the existing setupIsolatedKeychain probe (isolated\nservice name + 3s timeout skip) so these skip gracefully when the backend is\nunavailable, matching TestApply_BedrockKey_FlagStoresViaFallback.",
          "is_bot": false,
          "headline": "fix(codex): skip ChatGPT login, reject IAM for Mantle-only CLIs, drop…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-04T19:45:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e6e33a15705527b715f6c2db63189c59d3aef6ba",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v5.3.0 (#250)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-04T07:34:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1268ca978ada77e49c31e68ad1768e507a25edef",
          "body": "mergeNested and removeOwnedSubKeys silently discarded / skipped a user's\nvalue when a deep-merge key (Grok [model.*], Codex [model_providers.*],\nOpenCode provider.*) unexpectedly held a scalar instead of a table. Both\nnow return an actionable error naming the file and key, leaving the config\nuntouch\n[…]\nAlso document that Grok uninstall drops models.default (not restored,\nsince the prior value isn't persisted) — the user's model profiles survive.\n\nAdds edge-case tests for both scalar-collision paths.",
          "is_bot": false,
          "headline": "fix: refuse silent data-loss on type-mismatched deep-merge keys (#249)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-04T07:00:03Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dec26feb49634c1a5d48510892b32ead3cfab44f",
          "body": "…(#248)\n\n* feat: Grok CLI on Bedrock (--cli=grok) + fix nested-config data loss\n\nAdds the OFFICIAL xAI Grok CLI as the 4th provider AND fixes a data-loss bug\nthat affected all nested-config CLIs.\n\nGrok provider (internal/provider/grok.go): official xAI Grok CLI, TOML\n~/.grok/config.toml. Writes a [m\n[…]\n TestDeepMergeContract\npins each provider's DeepMergeKeys/OwnedSubKeys (the contract the fix relies\non); config tests cover mergeNested's non-map fallback and RemoveManagedKeysDeep\non a missing table.",
          "is_bot": false,
          "headline": "feat: Grok CLI on Bedrock (--cli=grok) + fix nested-config data loss …",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-04T06:05:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d814df60122b8d0aa532c7213a9389e9b1641c28",
          "body": "…h models (#247)\n\nThird harness behind the Provider abstraction (needs ZERO cmd/ per-CLI changes —\napply/launch/uninstall are already provider-driven). OpenCode is model-agnostic,\nso it routes to Bedrock via a custom OpenAI-compatible provider block in\n~/.config/opencode/opencode.json.\n\n- internal/p\n[…]\nde.json + opencode() wrapper written; curated glm-4.7\nresolves to zai.glm-4.7; passthrough warns; claude+codex+opencode wrappers\ncoexist in one profile. Claude golden byte-identical; full suite green.",
          "is_bot": false,
          "headline": "feat: OpenCode CLI on Bedrock (--cli=opencode) — curated + passthroug…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-04T05:13:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e8c8a7127accbf0442523f48d2df4ff3e6801c60",
          "body": "…ed (#246)\n\n* fix: apply --cli=codex re-prompts for auth even when already configured\n\nRe-apply detection was hardcoded to Claude: resolveApplyInputs checked\nsettingsPath (~/.claude/settings.json) + HasJuggernautBlock to decide whether\nconfig already exists and the interactive auth/region/permission\n[…]\nonfig malformed-block cases (non-map juggernaut, missing/non-map\n  meta, wrong managedBy) → 100%. codex.OwnsConfig already 100%.\n\nFull suite green; gofmt/vet/gosec clean; Claude golden byte-identical.",
          "is_bot": false,
          "headline": "fix: apply --cli=codex re-prompts for auth even when already configur…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-04T04:25:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "19c7e70dfc5fe05b4107238a266a2621d1617da3",
          "body": "…ock (#245)\n\n* build(deps): add github.com/BurntSushi/toml for Codex TOML config\n\n* feat(codex): TOML ConfigFormat + Codex provider foundation\n\nGroundwork for `--cli=codex` (PR 2). Verified-data foundation only; the config\nwriter + apply/activation wiring are deferred pending a Provider-interface\nde\n[…]\nprecated BedrockEnvVar() from the Provider interface + both\n  impls (superseded by LaunchSpec.StaticEnv; zero non-test callers).\n\nFull suite green; Claude golden byte-identical; gofmt/vet/gosec clean.",
          "is_bot": false,
          "headline": "feat: multi-CLI support — Provider abstraction + OpenAI Codex on Bedr…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-03T20:30:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1e7556dfc7e0f5766d602f9d480646fcdf0c8980",
          "body": "Three small follow-ups from the multi-agent review of #243 (no behavior\nchange for existing callers):\n\n- config.NewManagerWithFormat now panics on a nil ConfigFormat instead of\n  deferring to an opaque nil-pointer panic inside Read/Write. The constructor\n  is exported and upcoming CLIs (TOML) will c\n[…]\nGet; the test now pins it so the guidance can't silently regress).\n- Clarify the claude provider comment: the Bedrock env var is a string literal\n  inside activation.Launch, not a named constant site.",
          "is_bot": false,
          "headline": "fix: harden provider seam per PR #243 review (#244)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-03T06:14:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fb60f275b27a0bccd499f8bc0be0216c7644af82",
          "body": "First step toward multi-CLI Bedrock support: extract the seams that couple\nJuggernaut to Claude Code, with zero behavior change. Claude Code remains the\ndefault and its settings.json output is byte-identical.\n\n- internal/config: add a ConfigFormat interface (Unmarshal/Marshal) and a JSON\n  implement\n[…]\nunknown CLI errors before any work.\n\nEnv-var emission (schema.Build) is intentionally NOT moved into the provider yet\n— that migrates in the Codex PR when a real second CLI forces the interface shape.",
          "is_bot": false,
          "headline": "feat: introduce Provider and ConfigFormat abstractions (#243)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-03T05:50:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "725cde2629fdb16dfbf4897d4e614d37535e4229",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v5.2.9 (#242)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-03T04:24:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6166547f9038cae32a552fbdabff6f6a27800a7a",
          "body": "The Mantle warning added in #240 only fired on a real write; the\n--dry-run path returned before it, so users previewing an apply — the\nones most likely to want the heads-up before committing — never saw it.\n\nThread the built block into printApplyDryRun and call warnMantleTradeoffs\nthere too. Covered by two tests: --mantle --dry-run warns, plain\n--dry-run stays quiet.",
          "is_bot": false,
          "headline": "fix: show Mantle tradeoff warning on apply --dry-run (#241)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-03T03:56:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "497ac7cb2509ef784e07f2ea442e00657225b359",
          "body": "Enabling Mantle routing (--mantle / --mantle-url) silently dropped\nprompt caching and restricted Claude to current-generation models,\nwith no indication to the user. Prompt caching is unavailable on the\nMantle endpoints (verified against AWS docs: the caching page lists\nonly Converse/InvokeModel/Pro\n[…]\n, mirroring the existing warnAutoModeModel, so\napply prints an actionable heads-up when Mantle is enabled. Covered by\nthree tests: --mantle warns, --mantle-url warns, and the default path\nstays quiet.",
          "is_bot": false,
          "headline": "fix: warn about Mantle tradeoffs on apply (#240)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-03T03:35:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7837ba4e7580b23fce016feea2162bfd8cb9d692",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v5.2.8 (#239)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-02T03:05:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "31d8067a11eb6b343257ec21e287f95fc88270c7",
          "body": "…refix (#238)\n\nTwo correctness bugs found by an adversarial code sweep:\n\n1. apply --dry-run could pop an interactive Bedrock API key prompt.\n   runApply called resolveCredential before the dry-run check, so a\n   dry-run with --auth=bedrock-api-key and no --bedrock-key / stored key\n   blocked on a hu\n[…]\nin a\nunit test, and shipping an untested line would break TDD. A PowerShell\n\"dedup always appends\" finding was a false positive (the dedup list grows\nwithin the loop) and discarded after verification.",
          "is_bot": false,
          "headline": "fix: dry-run no longer prompts for credentials; strip us-gov. model p…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-02T02:44:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0c56fec772ae06437b62ff7c9f98810ce5edc6a7",
          "body": "…rnings (#237)\n\n* test: second coverage sweep — expiry parsing, binary resolution, doctor warnings\n\nContinues the data-driven backfill into the untouched high-value areas,\nkeeping only pure-logic and safety-critical branches.\n\n- bedrock.ParseAPIKeyExpiry: malformed date layout, non-integer expires,\n\n[…]\nn-executable-claude fixture used 0o644, tripping gosec G306\n(lint + Codacy). 0o600 has no execute bits either, so the test still\nexercises the isExecutable==false skip — a real fix, not a suppression.",
          "is_bot": false,
          "headline": "test: coverage sweep 2 — expiry parsing, binary resolution, doctor wa…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-02T02:03:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "226daed02e9ae9f60cf51b34520818b135d42b48",
          "body": "…#236)\n\nData-driven sweep of below-100% functions, keeping only pure-logic and\nsafety-critical branches (skipping OS-error-injection passthroughs).\n\n- safepath: cover withinBase exact rel==\"..\" parent escape and WriteFile\n  rejection outside base (path-containment security). 85.7% -> 90.5%.\n- keycha\n[…]\n: homeDir fallback when HOME and USERPROFILE are both empty (error\n  branch), and uninstall abort on stdin EOF (block must survive). cmd\n  77.1% -> 78.3%.\n\nTotal 80.7% -> 81.1%. No production changes.",
          "is_bot": false,
          "headline": "test: backfill safety/logic coverage across safepath, keychain, cmd (…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-02T00:22:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "67f2891829846dd5bed4f60bbdf76f1dfc594353",
          "body": "* test(activation): cover artifact-recovery safety paths\n\nThe v4.2.6 artifact recovery decides whether a file named claude may be\nremoved; a false positive deletes a user's real Claude Code binary. The\nexisting tests covered only the happy path (a known shim is removed).\n\nAdd the safety-critical neg\n[…]\np-restore test as a critical\nsecurity issue (go_filesystem_rule-fileread). The path is under\nt.TempDir(); annotate with the same nosemgrep suppression the sibling\ntests already use for temp-dir reads.",
          "is_bot": false,
          "headline": "test(activation): cover artifact-recovery safety paths (#235)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-02T00:07:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2679898205b82c8042aa9762e3df7db1dd7190ce",
          "body": "…ight no-op) (#234)\n\nBoth flags were registered but never read. --no-opusplan claimed to\n\"disable opusplan\" yet was ignored, so --opusplan --no-opusplan silently\nkept opusplan on. --skip-preflight claimed to \"skip dependency checks\"\nbut no preflight check exists.\n\n- --no-opusplan: add a conflict gua\n[…]\n pass it; hidden-noop is non-breaking and\n  matches the repo's existing compat pattern.\n\nAdds tests: the conflict errors, --no-opusplan alone succeeds, and\n--skip-preflight stays accepted.\n\nFixes #233",
          "is_bot": false,
          "headline": "fix(apply): make dead flags honest (--no-opusplan guard, --skip-prefl…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-01T08:43:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "811eaa1f389fb206ea1c7ee7131046e24f49a55a",
          "body": "Claude Code's Shift+Tab writes the native permissions.defaultMode\ndirectly without touching Juggernaut's meta block. resolveApplyInputs\nonly restored meta.permissionMode, so on a re-apply with no --mode the\nmerge layer (mergePermissions) deleted the user's externally-chosen\nmode — silently disabling\n[…]\ns cmd-level regression tests: externally-set mode survives re-apply\n(with env var restored), Juggernaut-set auto still round-trips, and an\nexplicit --mode still overrides a preserved mode.\n\nFixes #231",
          "is_bot": false,
          "headline": "fix(apply): preserve externally-set permission mode on re-apply (#232)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-01T08:41:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "22ecba0440a38666aefe3738e8b063311cda175f",
          "body": "… (#230)\n\nremoveBlock tracked block state with a single inBlock bool set on BEGIN\nand only cleared on a matching END. An orphaned BEGIN marker (no following\nEND) left inBlock true through EOF, silently deleting every subsequent\nline of the user's shell profile on apply and uninstall.\n\nRoute removeBl\n[…]\n diverge.\n\nAdds regression tests for the orphaned-marker case across removeBlock,\nupsertBlock (install path), and RemoveTarget (uninstall path), plus\nmatched-pair and multi-block coverage.\n\nFixes #229",
          "is_bot": false,
          "headline": "fix(activation): preserve profile content after orphaned BEGIN marker…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-07-01T08:06:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d76fa28d99672a9654f1e8b05cf46b448cbb400b",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v5.2.7 (#228)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-06-29T06:44:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4d06c6671c55730a8bbcc5dcfab7ea81ecc0b6a",
          "body": "… (#227)",
          "is_bot": false,
          "headline": "fix(ci): harden release pipeline against draft-only GoReleaser config…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-06-29T06:41:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f7e695fefcb6e8af29f51539ec83015c47d0cd0",
          "body": "PR #212 added `draft: true` to the GoReleaser config. GoReleaser honors it\nby uploading assets to an unpublished draft, and nothing in release.yml\nun-drafts the release — so every release since #212 has required a manual\n`gh release edit --draft=false`. The npm publish steps run regardless, which\nma\n[…]\nen GitHub-release half (npm looked fine while the GitHub\nrelease sat as a draft).\n\nSet draft: false so a `v*` tag push fully publishes the release with no\nmanual step, restoring the pre-#212 behavior.",
          "is_bot": false,
          "headline": "fix(release): publish GitHub release automatically on tag push (#226)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-06-29T06:36:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4386be0efa6d5701ab6402a19be76b7aac4faa33",
          "body": "… (#225)\n\nnpm 11 refuses install scripts by default and prints a loud allow-scripts\nwarning for every package declaring one; its suggested remediation command\ndrops the package name, leading users to a confusing ENOENT against their\ncwd. The Windows-only preinstall probe was self-admittedly unreliab\n[…]\n after extracting packages) and fully redundant with the\nruntime version-skew guard in index.js. Removing it yields a clean install\nwith no loss of partial-install protection.\n\nBumps version to 5.2.6.",
          "is_bot": false,
          "headline": "chore(npm): drop redundant preinstall script for clean install output…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-06-29T05:00:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "633b86bb63db6b1438f28ab6736db34d70746a36",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v5.2.5 (#224)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-06-29T04:00:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "71513bbe89dc793065c45b0cad3906b6da7da3b2",
          "body": "…t (#223)\n\nresolvePkgDir previously joined pkgName into a path with no local\nvalidation, trusting its caller — so its path-traversal suppression\nasserted a safety it didn't locally guarantee (the allowlist check lived\nonly in getBinaryPath). Validate pkgName against VALID_PACKAGES inside\nresolvePkgD\n[…]\nrite both suppression comments to cite the local invariant:\nallowlisted constant name, no separators/.., joined under __dirname,\ncannot escape. Add tests asserting both functions reject unknown names.",
          "is_bot": false,
          "headline": "fix(npm): make resolvePkgDir self-defending so its nosemgrep is hones…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-06-29T03:45:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "40e6a8a63cae8a4fb815967e5377a390c5a62a47",
          "body": "…ary (#222)\n\n* feat(npm): refuse to launch a version-skewed (partial) install\n\n* feat(npm): block install on Windows while a session locks the binary\n\n* fix(npm): suppress false-positive path-traversal finding on version-skew read\n\nThe pkg name flows from getPlatformPackage (hardcoded VALID_PACKAGES\n[…]\n cannot guarantee it prevents the partial install — the runtime\nversion-skew guard in index.js is the reliable net. Document the npm\nordering limitation and soften the user-facing message accordingly.",
          "is_bot": false,
          "headline": "fix(npm): fail loud on partial install instead of running a stale bin…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-06-29T03:36:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3675cf1e7e111e85fe4f259cb3d89d525e24d9cf",
          "body": "…igration tests (#221)\n\n* fix(keychain): never wipe a credential on a failed fallback write\n\nPre-release credential-stability hardening (from a 3-agent audit before cutting\nthe release).\n\nSetWithFallback previously deleted the keychain entry BEFORE writing the file\nfallback (in the big-key and keych\n[…]\now asserts the correct per-platform destination:\nv2 file on Windows; keychain + removed-stale-file on macOS/Linux. Both still\nround-trip via GetWithFallback. Skips on hosts without a keychain backend.",
          "is_bot": false,
          "headline": "fix(keychain): never wipe a credential on a failed fallback write + m…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-06-28T16:34:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "80fbb42839b755521d56e8fd99032ecdb3cf306a",
          "body": "…g) — v5.2.4 (#220)\n\n* feat(keychain): DPAPI-encrypt Windows file fallback; surface backend errors\n\nTwo hardening fixes for the credential layer (v5.2.4):\n\n1. DPAPI encryption for the Windows file fallback. Large keys (e.g. short-term\n   Bedrock keys ~5KB that exceed the 2560-byte Windows Credential\n[…]\nis\nan upper bound, not a guarantee. Documented ParseAPIKeyExpiry accordingly and\nreworded doctor's OK message to 'valid until at most ... (may expire sooner if\nthe generating AWS session ends first)'.",
          "is_bot": false,
          "headline": "feat: Bedrock credential hardening (DPAPI, key-expiry, error surfacin…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-06-28T16:04:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8f13d053bd551be54282dec45f648fbe45e2ad6d",
          "body": "* chore(ci): wire up Codecov coverage reporting via OIDC\n\nAdd Codecov upload to the existing test-coverage job using OIDC (no stored\nCODECOV_TOKEN — public repo, short-lived audience-scoped token at run time).\n\n- gotestsum emits junit.xml alongside the coverage profile in one run\n- upload coverage.o\n[…]\n test -coverprofile and the CI normalize step produce coverage/coverage.out/\ncoverage.tmp/junit.xml locally; ignore them so they never dirty the tree\n(GoReleaser requires a clean git tree at release).",
          "is_bot": false,
          "headline": "chore(ci): wire up Codecov coverage reporting via OIDC (#218)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-06-28T06:37:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ab5af041d26a9344aedf492f3c72080b6f0d33d5",
          "body": "Bumps [actions/setup-go](https://github.com/actions/setup-go) from 6.4.0 to 6.5.0.\n- [Release notes](https://github.com/actions/setup-go/releases)\n- [Commits](https://github.com/actions/setup-go/compare/4a3601121dd01d1626a1e23e37211e3254c1c06c...924ae3a1cded613372ab5595356fb5720e22ba16)\n\n---\nupdated\n[…]\ned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Juan Pablo (JP) <jpvelasco@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/setup-go from 6.4.0 to 6.5.0 (#217)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-06-28T06:25:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "89c52b5dc6f34d8024efa0e9ea8d82f128d59295",
          "body": "The v5.2.2 launch path read credentials from the keychain only, so short-term\nBedrock API keys (~5KB, exceeding the 2560-byte Windows keychain limit) that\nwere stored in the file fallback came back as 'not found in keychain'. The\nlaunch fallback-getter fix (GetWithFallback) is already in main but was never\nreleased. Bump VERSION/bedrock-config.json/cmd.Version to 5.2.3 and document\nthe fix so both short-term and long-term keys work on Windows.",
          "is_bot": false,
          "headline": "fix: release launch fallback-getter fix as v5.2.3 (#219)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-06-28T04:56:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "005f89106a79c67654ea961b15eaeb3d3991ef52",
          "body": "… CI coverage\n\nFixes five review findings: launch fallback getter, keychain deletion failure propagation, stale fallback cleanup, credential file security, and CI coverage truncation. Adds versioned credential envelope for fallback file migration, keychain-first precedence for legacy files, and full migration test coverage.",
          "is_bot": false,
          "headline": "fix: wire launch to fallback getter, enforce credential security, fix…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-06-27T16:52:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dfc77d4675b0c59303e71ff22e97fe53be3bcac2",
          "body": null,
          "is_bot": false,
          "headline": "fix(ci): update actions/cache SHA in release workflow (#214)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-06-27T13:57:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d9032498f8d1a0c4aa3efb8bfb2c5e4c90c8a851",
          "body": null,
          "is_bot": false,
          "headline": "chore: Release v5.2.2 (#213)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-06-27T11:51:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1b1b8ab86d00c49642e5af7edd0886b6fe381550",
          "body": "…provements (#212)\n\n* chore: overhaul CI pipeline with lint, test, security, and release improvements\n\n- Pin Go 1.26 in CI (was 'stable'), add module caching to all jobs\n- Add race detector, coverage (60% threshold), npm test, shellcheck, gosec jobs\n- Create .golangci.yml with staticcheck + gosec + \n[…]\nrect os.MkdirAll(0o700) + os.WriteFile with safepath.WriteFile\nwhich handles directory creation internally. Also removes silencing configs\nadded to .codacy.yml, .codacy/codacy.yaml, and .semgrep.yaml.",
          "is_bot": false,
          "headline": "chore: overhaul CI pipeline with lint, test, security, and release im…",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-06-27T10:39:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2dba727383cf7936ff74a7a12a97e1a11c6f60ee",
          "body": null,
          "is_bot": false,
          "headline": "Release v5.2.1 (#211)",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-06-27T08:40:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9e1edfd8f2b3ebcbb2da1811cd0eb0c4517f5ac1",
          "body": "…(#210)\n\n* fix(activation): discover PowerShell profiles dynamically on Windows\n\n- Replace hardcoded \\C:\\Users\\jpvel/Documents paths with dynamic \\C:\\Users\\jpvel\\OneDrive\\Documents\\PowerShell\\Microsoft.PowerShell_profile.ps1\n  discovery via pwsh.exe and powershell.exe\n- Add fallback to Windows Known\n[…]\ncs only, fails locally)\n\n* revert: restore lizard in Codacy config\n\n* fix: remove lizard from Codacy config (cloud-metrics only, fails locally)\n\n* fix: add valid patterns to lizard.yaml for Codacy CLI",
          "is_bot": false,
          "headline": "fix(activation): discover PowerShell profiles dynamically on Windows …",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-06-27T07:50:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1196df3f72433b391721ae572de7dd424c045f3c",
          "body": "Minor release. Extends Bedrock parity with new Claude Code features (Fable aliases, native fallback chains, flexible effort levels) and improves auto mode + telemetry controls for Bedrock users.\n\nIncludes Fable model support, --fallback-model, improved --effort handling, auto mode warnings for Bedrock, and nonessential traffic suppression.",
          "is_bot": false,
          "headline": "Release v5.2.0",
          "author_name": "Juan Pablo (JP)",
          "author_login": "jpvelasco",
          "committed_at": "2026-06-26T19:05:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 71,
      "commits_last_year": 346,
      "latest_release_at": "2026-07-21T19:48:30Z",
      "latest_release_tag": "v5.5.0",
      "releases_from_tags": false,
      "days_since_last_push": 1,
      "active_weeks_last_year": 21,
      "days_since_latest_release": 1,
      "mean_days_between_releases": 2.5
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 100,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/jpvelasco/juggernaut/v5",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/jpvelasco/juggernaut/v5",
          "is_deprecated": false,
          "latest_version": "v5.5.0",
          "repository_url": "https://github.com/jpvelasco/juggernaut",
          "versions_count": 28,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-21T19:46:34Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 1
        },
        {
          "name": "juggernaut-bedrock",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "bedrock",
            "amazon-bedrock",
            "aws",
            "claude",
            "claude-code",
            "anthropic",
            "codex",
            "opencode",
            "grok",
            "genai",
            "ai-coding",
            "llm",
            "coding-agent",
            "cli",
            "iam",
            "sso",
            "mantle",
            "developer-tools"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/juggernaut-bedrock",
          "is_deprecated": false,
          "latest_version": "5.5.0",
          "repository_url": "https://github.com/jpvelasco/juggernaut",
          "versions_count": 40,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 4471,
          "first_published_at": "2026-06-05T16:34:40.992000Z",
          "latest_published_at": "2026-07-21T19:49:04.379000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 1
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 1
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 84677,
      "source_files_sampled": 141,
      "oversized_source_files": 1,
      "agent_instruction_files": [
        ".github/instructions/codacy.instructions.md",
        "AGENTS.md",
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 21205
    },
    "dependencies": {
      "manifests": [
        "go.mod",
        "npm/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.37.0",
            "severity": "unknown",
            "ecosystem": "go",
            "cvss_score": null,
            "advisory_ids": [
              "GO-2026-5970"
            ],
            "fixed_version": "0.39.0",
            "advisory_count": 1,
            "oldest_advisory_days": 8
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "unknown": 1
        },
        "advisory_count": 1,
        "affected_count": 1,
        "assessed_count": 58,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go",
        "npm"
      ],
      "dependencies": [
        {
          "name": "github.com/BurntSushi/toml",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.6.0"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.42.1"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/config",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.32.30"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/bedrock",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.65.1"
        },
        {
          "name": "github.com/aws/aws-sdk-go-v2/service/sts",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.44.1"
        },
        {
          "name": "github.com/charmbracelet/huh",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.0"
        },
        {
          "name": "github.com/gofrs/flock",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.13.0"
        },
        {
          "name": "github.com/spf13/cobra",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.10.2"
        },
        {
          "name": "github.com/spf13/pflag",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.0.9"
        },
        {
          "name": "github.com/zalando/go-keyring",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.8"
        },
        {
          "name": "github.com/charmbracelet/bubbles",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.21.1-0.20250623103423-23b8fd6302d7"
        },
        {
          "name": "github.com/charmbracelet/x/windows",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.2.2"
        },
        {
          "name": "golang.org/x/sys",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.45.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/aws/aws-sdk-go-v2",
            "direct": true,
            "version": "v1.42.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/config",
            "direct": true,
            "version": "v1.32.30",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/bedrock",
            "direct": true,
            "version": "v1.65.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/sts",
            "direct": true,
            "version": "v1.44.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/burntsushi/toml",
            "direct": true,
            "version": "v1.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/bubbles",
            "direct": true,
            "version": "v0.21.1-0.20250623103423-23b8fd6302d7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/huh",
            "direct": true,
            "version": "v1.0.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/windows",
            "direct": true,
            "version": "v0.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/gofrs/flock",
            "direct": true,
            "version": "v0.13.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/cobra",
            "direct": true,
            "version": "v1.10.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/spf13/pflag",
            "direct": true,
            "version": "v1.0.9",
            "ecosystem": "go"
          },
          {
            "name": "github.com/zalando/go-keyring",
            "direct": true,
            "version": "v0.2.8",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sys",
            "direct": true,
            "version": "v0.45.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/atotto/clipboard",
            "direct": false,
            "version": "v0.1.4",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/credentials",
            "direct": false,
            "version": "v1.19.29",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/feature/ec2/imds",
            "direct": false,
            "version": "v1.18.30",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/configsources",
            "direct": false,
            "version": "v1.4.30",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/endpoints/v2",
            "direct": false,
            "version": "v2.7.30",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/internal/v4a",
            "direct": false,
            "version": "v1.4.31",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding",
            "direct": false,
            "version": "v1.13.13",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/internal/presigned-url",
            "direct": false,
            "version": "v1.13.30",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/signin",
            "direct": false,
            "version": "v1.4.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/sso",
            "direct": false,
            "version": "v1.32.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/aws-sdk-go-v2/service/ssooidc",
            "direct": false,
            "version": "v1.37.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aws/smithy-go",
            "direct": false,
            "version": "v1.27.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/aymanbagabas/go-osc52/v2",
            "direct": false,
            "version": "v2.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/catppuccin/go",
            "direct": false,
            "version": "v0.3.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/bubbletea",
            "direct": false,
            "version": "v1.3.6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/colorprofile",
            "direct": false,
            "version": "v0.2.3-0.20250311203215-f60798e515dc",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/lipgloss",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/ansi",
            "direct": false,
            "version": "v0.9.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/cellbuf",
            "direct": false,
            "version": "v0.0.13",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/exp/strings",
            "direct": false,
            "version": "v0.0.0-20240722160745-212f7b056ed0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/charmbracelet/x/term",
            "direct": false,
            "version": "v0.2.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/danieljoos/wincred",
            "direct": false,
            "version": "v1.2.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/dustin/go-humanize",
            "direct": false,
            "version": "v1.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/erikgeiser/coninput",
            "direct": false,
            "version": "v0.0.0-20211004153227-1c3628e74d0f",
            "ecosystem": "go"
          },
          {
            "name": "github.com/godbus/dbus/v5",
            "direct": false,
            "version": "v5.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/inconshreveable/mousetrap",
            "direct": false,
            "version": "v1.1.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/lucasb-eyer/go-colorful",
            "direct": false,
            "version": "v1.2.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-isatty",
            "direct": false,
            "version": "v0.0.20",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-localereader",
            "direct": false,
            "version": "v0.0.1",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mattn/go-runewidth",
            "direct": false,
            "version": "v0.0.16",
            "ecosystem": "go"
          },
          {
            "name": "github.com/mitchellh/hashstructure/v2",
            "direct": false,
            "version": "v2.0.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/muesli/ansi",
            "direct": false,
            "version": "v0.0.0-20230316100256-276c6243b2f6",
            "ecosystem": "go"
          },
          {
            "name": "github.com/muesli/cancelreader",
            "direct": false,
            "version": "v0.2.2",
            "ecosystem": "go"
          },
          {
            "name": "github.com/muesli/termenv",
            "direct": false,
            "version": "v0.16.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/rivo/uniseg",
            "direct": false,
            "version": "v0.4.7",
            "ecosystem": "go"
          },
          {
            "name": "github.com/stretchr/objx",
            "direct": false,
            "version": "v0.5.3",
            "ecosystem": "go"
          },
          {
            "name": "github.com/xo/terminfo",
            "direct": false,
            "version": "v0.0.0-20220910002029-abceb7e1c41e",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/exp",
            "direct": false,
            "version": "v0.0.0-20240909161429-701f63a606c0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": false,
            "version": "v0.20.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/text",
            "direct": false,
            "version": "v0.37.0",
            "ecosystem": "go"
          },
          {
            "name": "juggernaut-bedrock-darwin-arm64",
            "direct": false,
            "version": "0.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "juggernaut-bedrock-darwin-x64",
            "direct": false,
            "version": "0.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "juggernaut-bedrock-linux-arm64",
            "direct": false,
            "version": "0.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "juggernaut-bedrock-linux-x64",
            "direct": false,
            "version": "0.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "juggernaut-bedrock-win32-x64",
            "direct": false,
            "version": "0.0.0",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 58,
        "direct_count": 13,
        "indirect_count": 45
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 290,
        "open_issues": 1,
        "closed_ratio": 0.955,
        "closed_issues": 21,
        "closed_unmerged_prs": 12
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "jpvelasco",
          "commits": 330,
          "avatar_url": "https://avatars.githubusercontent.com/u/143497?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "codeql.yml",
        "octopus.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 4,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/26 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 10,
            "reason": "all dependencies are pinned",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 4,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 9,
            "reason": "1 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "50714f567815e98b732b57c642ec47177c1b5329",
        "ran_at": "2026-07-23T11:09:10Z",
        "aggregate_score": 6.2,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": true,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-21T19:55:55Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-21T19:54:18Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 208,
          "created_at": "2026-06-26T18:27:06Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/jpvelasco/juggernaut",
    "host": "github.com",
    "name": "juggernaut",
    "owner": "jpvelasco"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 69,
      "inputs": {
        "security": 70,
        "vitality": 83,
        "community": 48,
        "governance": 56,
        "engineering": 86
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 83,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 78,
            "inputs": {
              "commits_last_year": 346,
              "human_commit_share": 0.92,
              "days_since_last_push": 1,
              "active_weeks_last_year": 21
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "21/52 weeks with commits",
                "points": 14.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 21
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "346 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 346
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 71,
              "latest_release_tag": "v5.5.0",
              "releases_from_tags": false,
              "days_since_latest_release": 1,
              "mean_days_between_releases": 2.5
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "71 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 71
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~2.5 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 2.5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 1,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 1 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 48,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 61,
            "inputs": {
              "packages": [
                "github.com/jpvelasco/juggernaut/v5",
                "juggernaut-bedrock"
              ],
              "dependents": null,
              "ecosystems": "go, npm",
              "total_downloads": null,
              "monthly_downloads": 4471
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "4,471 downloads/month across go, npm",
                "points": 48.7,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 4471,
                      "ecosystems": "go, npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 56,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "merged_prs": 290,
              "open_issues": 1,
              "closed_issues": 21,
              "issue_closed_ratio": 0.955,
              "closed_unmerged_prs": 12
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "96% of issues closed",
                "points": 44.6,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 96
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "290/302 decided PRs merged",
                "points": 36.7,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 290,
                      "decided": 302
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/26 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 47,
            "inputs": {
              "followers": 12,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "jpvelasco",
              "public_repos": 11,
              "account_age_days": 6117
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "12 followers of jpvelasco",
                "points": 8,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 12,
                      "login": "jpvelasco"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "11 public repos, account ~16 yr old",
                "points": 19.9,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 11
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 16
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "github.com/jpvelasco/juggernaut/v5",
                "juggernaut-bedrock"
              ],
              "ecosystems": "go, npm",
              "any_deprecated": false,
              "min_days_since_publish": 1
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on go, npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "go, npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 1 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "40 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 40
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "excellent",
        "name": "Engineering Quality",
        "value": 86,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [
                "anthropic",
                "aws",
                "bedrock",
                "claude",
                "cli",
                "developer-tools",
                "claude-code"
              ],
              "has_wiki": false,
              "homepage": "https://www.npmjs.com/package/juggernaut-bedrock",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://www.npmjs.com/package/juggernaut-bedrock",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "7 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 70,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": null,
            "notes": [],
            "value": 62,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 18,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 0,
              "scorecard_aggregate": 6.2
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/26 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 21 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "1 existing vulnerabilities detected",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 58 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 58
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 1,
              "affected_packages": 1,
              "assessed_packages": 58,
              "unassessed_packages": 0,
              "affected_by_severity": "unknown 1",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 58,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "excellent",
        "name": "AI Readiness",
        "value": 90,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                ".github/instructions/codacy.instructions.md",
                "AGENTS.md",
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 21205
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": ".github/instructions/codacy.instructions.md, AGENTS.md, CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".github/instructions/codacy.instructions.md, AGENTS.md, CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "92 of 92 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 92,
                      "sampled": 92
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0.08
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "8 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 8,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 84677,
              "source_files_sampled": 141,
              "oversized_source_files": 1
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "1/141 source files over 60KB",
                "points": 54.6,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 141,
                      "oversized": 1
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "deps.dev does not index npm:juggernaut-bedrock@5.5.0; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T11:09:27.713669Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/j/jpvelasco/juggernaut.svg",
  "full_name": "jpvelasco/juggernaut",
  "license_state": "standard",
  "license_spdx": "MIT"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计Go, npm.