原始 JSON 报告 机器可读
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 12766,
"has_wiki": true,
"homepage": "https://klarlabs-studio.github.io/statekit/",
"languages": {
"Go": 821856
},
"pushed_at": "2026-07-27T10:15:06Z",
"created_at": "2025-12-25T20:14:01Z",
"owner_type": "Organization",
"updated_at": "2026-07-27T10:16:41Z",
"description": "Go-native statechart execution engine with XState JSON compatibility for visualization",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": "https://klarlabs.de",
"name": "Klarlabs",
"type": "Organization",
"login": "klarlabs-studio",
"company": null,
"location": "Munich, Germany",
"followers": 1,
"avatar_url": "https://avatars.githubusercontent.com/u/291279584?v=4",
"created_at": "2026-06-06T11:23:11Z",
"is_verified": null,
"public_repos": 36,
"account_age_days": 51
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v1.12.0",
"kind": "minor",
"published_at": "2026-07-10T20:36:19Z"
},
{
"tag": "v1.11.1",
"kind": "patch",
"published_at": "2026-07-03T07:46:40Z"
},
{
"tag": "v1.10.0",
"kind": "minor",
"published_at": "2026-06-20T20:46:55Z"
},
{
"tag": "v1.9.0",
"kind": "minor",
"published_at": "2026-06-20T15:15:16Z"
},
{
"tag": "v1.7.0",
"kind": "minor",
"published_at": "2026-06-02T21:41:06Z"
},
{
"tag": "v1.6.0",
"kind": "minor",
"published_at": "2026-06-02T16:51:26Z"
},
{
"tag": "v1.5.1",
"kind": "patch",
"published_at": "2026-06-02T15:22:44Z"
},
{
"tag": "v1.5.0",
"kind": "minor",
"published_at": "2026-05-10T07:02:00Z"
},
{
"tag": "v1.4.2",
"kind": "patch",
"published_at": "2026-05-09T22:32:57Z"
},
{
"tag": "v1.4.1",
"kind": "patch",
"published_at": "2026-05-09T20:34:39Z"
},
{
"tag": "v1.4.0",
"kind": "minor",
"published_at": "2026-05-09T19:45:26Z"
},
{
"tag": "v1.3.2",
"kind": "patch",
"published_at": "2026-03-25T08:40:51Z"
},
{
"tag": "v1.3.1",
"kind": "patch",
"published_at": "2026-03-01T20:37:11Z"
},
{
"tag": "v1.3.0",
"kind": "minor",
"published_at": "2026-01-29T09:02:35Z"
},
{
"tag": "v1.2.1",
"kind": "patch",
"published_at": "2026-01-28T17:11:35Z"
},
{
"tag": "v1.2.0",
"kind": "minor",
"published_at": "2026-01-28T09:52:19Z"
},
{
"tag": "v1.0.1",
"kind": "patch",
"published_at": "2025-12-30T22:57:46Z"
},
{
"tag": "v1.0.0",
"kind": "major",
"published_at": "2025-12-30T21:53:28Z"
},
{
"tag": "v0.14.0",
"kind": "minor",
"published_at": "2025-12-30T21:07:52Z"
},
{
"tag": "v0.12.1",
"kind": "patch",
"published_at": "2025-12-30T18:34:18Z"
},
{
"tag": "v0.12.0",
"kind": "minor",
"published_at": "2025-12-30T17:38:35Z"
},
{
"tag": "v0.11.0",
"kind": "minor",
"published_at": "2025-12-30T17:21:10Z"
},
{
"tag": "v0.10.0",
"kind": "minor",
"published_at": "2025-12-30T15:54:03Z"
},
{
"tag": "v0.9.0",
"kind": "minor",
"published_at": "2025-12-30T14:45:58Z"
},
{
"tag": "v0.8.0",
"kind": "minor",
"published_at": "2025-12-30T14:23:47Z"
},
{
"tag": "v0.5.0",
"kind": "minor",
"published_at": "2025-12-30T09:44:21Z"
},
{
"tag": "v0.4.1",
"kind": "patch",
"published_at": "2025-12-30T08:35:02Z"
},
{
"tag": "v0.4.0",
"kind": "minor",
"published_at": "2025-12-30T08:26:13Z"
},
{
"tag": "v0.3.0",
"kind": "minor",
"published_at": "2025-12-30T08:25:58Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2025-12-30T08:25:47Z"
}
],
"recent_commits": [
{
"oid": "7d3d1cf71a087194b0cc1b26d77bd6c81593a1d1",
"body": "Co-authored-by: nox-remediate <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(security): nox remediation (deps + actions) (#97)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-27T10:15:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0c73fd0c78a2c79c84cb39a54d1d15fc8fcbacdf",
"body": "Clear GHSA-4x5r-pxfx-6jf8 (@babel/core: arbitrary file read via\nsourceMappingURL comment) in docs/: 7.29.0 -> 7.29.7, pinned via npm\n`overrides` (@babel/core is transitive).\n\nNote on the version choice: nox reports fixed_in = 8.0.0-rc.6, which is\nthe fix for the OTHER affected range. OSV lists two r\n[…]\nadvisory in the repo.\n\nVerified: astro docs build passes (26 pages); nox reports 0 dependency\nCVEs and 0 net-new critical/high.\n\nClaude-Session: https://claude.ai/code/session_01Cr6YdzphmFF3NJqm7kSJom",
"is_bot": false,
"headline": "fix(security): bump @babel/core to the patched 7.29.6+ release (#96)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-25T20:24:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c54c950da075f5526b54ce1fbc8dfe5f7ecb938d",
"body": "Clears a medium-severity reflected XSS advisory in astro\n(GHSA-4g3v-8h47-v7g6). Minor bump within 7.x; the docs range moves to\n^7.1.0 and the lockfile resolves to 7.1.3.\n\nDeliberately NOT addressed: @babel/core 7.29.0 (GHSA-4x5r-pxfx-6jf8,\nlow). The only published fix is 8.0.0-rc.6 -- a release cand\n[…]\nadvisory is gone and there are 0\nactive critical/high findings.\n\n`npm run build` and `npm run check` for docs/ pass (0 errors).\n\nClaude-Session: https://claude.ai/code/session_01Cr6YdzphmFF3NJqm7kSJom",
"is_bot": false,
"headline": "chore(deps): bump astro 7.0.6 -> 7.1.0 (GHSA-4g3v-8h47-v7g6) (#95)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-25T19:58:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8f99d9474076fb98eb8e8d5403041dcb16694fa8",
"body": "* fix(ci): run CI on docs-only PRs so required checks can report\n\nBranch protection requires `ci / Lint`, `ci / Test (ubuntu-latest)`,\n`ci / Build` and `ci / Security (nox)`, but the pull_request trigger had\npaths-ignore for **.md, docs/** and LICENSE. A docs-only PR therefore\nskipped the whole work\n[…]\nripts intact)\n\nVerified: build (astro build) and tests (vitest, 29/29) pass; nox scan\nreports 0 net-new critical/high findings.\n\nClaude-Session: https://claude.ai/code/session_01Cr6YdzphmFF3NJqm7kSJom",
"is_bot": false,
"headline": "fix(ci): unblock docs-only PRs + remediate JS dep CVEs (#94)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-25T17:43:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "98ed8d11c2955e1afccce6781ea500f4ed350123",
"body": "Co-authored-by: nox-remediate <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(security): nox remediation (deps + actions) (#92)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-20T09:40:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1755b4a0e94af043825f3aee2c329dd63118be22",
"body": "The release job installs nox/cli@v0.8.1, which requires a newer Go than go.mod\npins, so `go install` failed under the runner's GOTOOLCHAIN=local. Set\nGOTOOLCHAIN=auto for that step so the toolchain is fetched on demand. Fixes the\nv1.12.0 release run (SBOM step never reached).\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "fix(release): let Install nox fetch its required Go toolchain (#91)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T20:33:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b0727f7aa338f06efd65c540d2f9e6382f550c2c",
"body": "Statekit doesn't need a built-in MCP server. Remove the mcp/ package and the\ncmd/statekit-mcp binary, drop the go.klarlabs.de/mcp dependency (go mod tidy),\nand strip the MCP references from the README and docs (stability, backlog).\n\nNothing else in the module imported statekit/mcp, so this is a self\n[…]\n\nremoval — build and tests are unaffected. Generated docs under docs/dist/ will\ndrop their MCP sections on the next docs build.\n\nClaude-Session: https://claude.ai/code/session_01LCyhyAffdzBmzG3yPPqzTT",
"is_bot": false,
"headline": "chore: remove the MCP server (#90)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-10T19:59:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "bb4aea039433936327b5582e31b8cf2057824503",
"body": "Co-authored-by: nox-remediate <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(security): nox remediation (deps + actions) (#87)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T12:27:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "78c031950202eaee9f7837809339d88d126a09d2",
"body": "nox 1.7.0 uses fingerprint v2; the committed v1 baseline no longer matched.\nMigrated v1->v2 + refreshed so pre-accepted findings are recognized again.\nNo real finding suppressed. Claude-Session: https://claude.ai/code/session_01QKTcmXFTKoTQr7mB3HCuHZ",
"is_bot": false,
"headline": "chore(nox): refresh baseline to fingerprint v2 (nox 1.7.0) (#86)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T11:09:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0e26d9cc6b7202119f001cdcd6bff7adc3b235a9",
"body": "Secure-by-default hardening release. build + tests green; go directive unchanged.\n\nClaude-Session: https://claude.ai/code/session_01QKTcmXFTKoTQr7mB3HCuHZ",
"is_bot": false,
"headline": "chore(deps): bump go.klarlabs.de/mcp to v1.21.0 (#85)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-06T08:24:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6dc6a5d31e3bdbbb6155d8844a71417a4eeb420c",
"body": null,
"is_bot": false,
"headline": "chore(ci): use reusable nox-remediate workflow (#84)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-03T13:52:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "400e7984768b411bfb08a29f16c550fcd22fb49f",
"body": "Co-authored-by: nox-remediate <41898282+github-actions[bot]@users.noreply.github.com>",
"is_bot": false,
"headline": "chore(security): nox remediation (deps + actions) (#83)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-03T12:38:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "124d74b3188d0a99bb9e377d18bd198044f7950f",
"body": null,
"is_bot": false,
"headline": "ci: remove dependabot (superseded by nox-remediate)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-03T12:20:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9a876883bcd614c62e2a82597eb58a6858a29c62",
"body": null,
"is_bot": false,
"headline": "ci: remove dependabot (superseded by nox-remediate)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-03T12:20:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5df2a7a670c52b4130a119706ea5ad552cf8337c",
"body": null,
"is_bot": false,
"headline": "ci: nox-remediate (replaces dependabot)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-03T12:20:48Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1a45b4f8cc70d3b06728f9a94e5556cf534aa730",
"body": null,
"is_bot": false,
"headline": "ci(nox-remediate): use NOX_TOKEN for workflow-file pushes",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-03T11:42:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d5bf20cf8a455afdbaff923e31767685bddb32b7",
"body": null,
"is_bot": false,
"headline": "ci: add nox-remediate workflow (replaces dependabot)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-03T11:39:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "37643bb710e6554d91b306f2f7a2fc763b74d37f",
"body": "Bumps [esbuild](https://github.com/evanw/esbuild) to 0.28.1 and updates ancestor dependencies [esbuild](https://github.com/evanw/esbuild), [@astrojs/vue](https://github.com/withastro/astro/tree/HEAD/packages/integrations/vue) and [astro](https://github.com/withastro/astro/tree/HEAD/packages/astro). \n[…]\nendency-version: 7.0.6\n dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "ci: bump esbuild, @astrojs/vue and astro in /docs (#82)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-03T08:58:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5c7e5a19229d578d9a7490ed4022b849bf4396b5",
"body": "Local gate config (pre-commit/pre-push: lint + race tests, parallel) plus an\ninformational warden-verify PR check. Aligns with the klarlabs-studio convention.",
"is_bot": false,
"headline": "chore: adopt warden — .warden.yaml + provenance-skip CI",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-03T08:56:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "56928f9cdd1e5ed22172d642e3055e32e6ab5f2c",
"body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v6...v7)\n\n---\nupdated-dependenc\n[…]\nirect:production\n update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "ci: bump actions/checkout from 6 to 7 (#71)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-03T08:52:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c0e9f3dfcc595db5b08bfd30fbe21e0fb1b8748a",
"body": "Bumps [undici](https://github.com/nodejs/undici) from 7.25.0 to 7.28.0.\n- [Release notes](https://github.com/nodejs/undici/releases)\n- [Commits](https://github.com/nodejs/undici/compare/v7.25.0...v7.28.0)\n\n---\nupdated-dependencies:\n- dependency-name: undici\n dependency-version: 7.28.0\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps-dev): bump undici from 7.25.0 to 7.28.0 in /docs (#73)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-03T08:51:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c760c91a2518b672fc2e483ecfc7a4bbe0f2f624",
"body": "Bumps [js-yaml](https://github.com/nodeca/js-yaml) from 4.1.1 to 4.3.0.\n- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.0/CHANGELOG.md)\n- [Commits](https://github.com/nodeca/js-yaml/compare/4.1.1...4.3.0)\n\n---\nupdated-dependencies:\n- dependency-name: js-yaml\n dependency-version: 4.3.0\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump js-yaml from 4.1.1 to 4.3.0 in /docs (#80)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-03T08:51:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "29d48a25ac6ed5802cf866d8eff96b34df7f9ad0",
"body": "Publishes a GitHub Release with auto-generated notes + CycloneDX/SPDX SBOM\nartifacts on every v* tag — matching fortify and mcp, so future statekit\nreleases no longer need manual creation.",
"is_bot": false,
"headline": "ci: add tag-triggered release workflow",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-03T07:59:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ace456073789168a4e509d30e214744242c93a83",
"body": "Bumps [vite](https://github.com/vitejs/vite/tree/HEAD/packages/vite) from 7.3.3 to 7.3.6.\n- [Release notes](https://github.com/vitejs/vite/releases)\n- [Changelog](https://github.com/vitejs/vite/blob/v7.3.6/packages/vite/CHANGELOG.md)\n- [Commits](https://github.com/vitejs/vite/commits/v7.3.6/packages\n[…]\nite\n dependency-version: 7.3.6\n dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "build(deps): bump vite from 7.3.3 to 7.3.6 in /docs (#81)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-07-03T07:38:36Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3f37db22419f0d259f7939c45db09a256ddd6591",
"body": "- go.klarlabs.de/mcp v1.15.0 → v1.20.1\n- go.klarlabs.de/fortify v1.6.0 → v1.8.1\n- go get -u ./...: spf13/pflag, golang.org/x/{mod,tools,text}, grpc, genproto\nBuild + tests green.",
"is_bot": false,
"headline": "chore(deps): update dependencies to latest",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-07-03T07:35:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9f3bc74976631760ad63eb082ff1a81e7d34c9db",
"body": "feat(interpreter): SendResult — report whether an event was handled",
"is_bot": false,
"headline": "Merge pull request #77 from klarlabs-studio/feat/send-result",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-21T14:53:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7ca509673479d2696970ab3aecbc0c40f8bb526e",
"body": "Send is void and silently returns when no transition matches or every\ncandidate's guard blocks it, so callers cannot tell an applied transition from\na silently-rejected one. SendResult processes the event identically and returns\nwhether a transition (or parallel-region delivery) actually fired. Send\n[…]\nsurfaced while debugging a senat-os agent loop where a policy-allowed\ntransition had no machine edge and Send silently no-op'd.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "feat(interpreter): add SendResult to report whether an event was handled",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-21T14:49:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "67d5ec500f80a3a7473ab14dc9332b5c30ab1b8b",
"body": "spec compliance: FromJSON constructors + distributed subpackage",
"is_bot": false,
"headline": "Merge pull request #76 from klarlabs-studio/feat/spec-compliance",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T20:40:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7f6c8c3c8a2bc2ed946601096b8ccc1415f2dd2b",
"body": "…sub-package\n\nThe spec lists `distributed/` as a separate sub-package and requires that\noptional sub-packages never affect core module dependencies. StreamLock,\nDistributedInterpreter, and the consistent-hash StreamRouter previously lived\nin the root-package file distributed.go, which would pull the\n[…]\ntains zero external dependencies; no code outside distributed/\nreferences the moved symbols; distributed tests pass with -race.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "refactor(distributed): move StreamLock and DistributedInterpreter to …",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T19:36:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f94aaf9d496b2593eb6009b2f3dfc619f3245126",
"body": "Add statekit.FromJSON[C] (and FromJSONWithContext[C]) — a typed, core-package\nloader that builds *MachineConfig[C] from Statekit Native JSON. This makes JSON\na first-class machine-definition path alongside the fluent builder and the\nreflection DSL, matching the spec's \"fluent builder, reflection DSL\n[…]\nerror\nat load time rather than installing silent no-ops.\n\nVerified core retains zero external dependencies after this addition.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "feat(core): add typed FromJSON core machine loader",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T19:36:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9a940515547c1fa42946da36cf302a5d476bb579",
"body": "…ngelog\n\ndocs(changelog): ai/aiplugin removal is v1.9.0 (stay on v1)",
"is_bot": false,
"headline": "Merge pull request #75 from klarlabs-studio/chore/statekit-v1.9.0-cha…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T14:18:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1bc19705dfb12a06a8283ceddc5d3b5164116f04",
"body": "Stay on the v1 line (no /v2 module-path migration). The removed ai/aiplugin\npackages had no remaining in-stack consumer, so this ships as a minor with\na clear migration note rather than a major.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "docs(changelog): release ai/aiplugin removal as v1.9.0, not v2.0.0",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T14:17:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c7adaed0cc9c1dd403de03388c0aee0c94f4dc12",
"body": "feat!: remove ai and aiplugin packages (v2)",
"is_bot": false,
"headline": "Merge pull request #74 from klarlabs-studio/chore/remove-ai-aiplugin-v2",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T14:12:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "eebf69231ae91881c4fa3f172ae772994e4f0d47",
"body": "…gin-v2",
"is_bot": false,
"headline": "Merge remote-tracking branch 'origin/main' into chore/remove-ai-aiplu…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T14:05:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ceaa7050a4b1a7008615cf7c2a81106099536b33",
"body": "Document the BREAKING removal of the ai and aiplugin packages (rehomed\nin agent-go contrib) and the dropped llm_agent example.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "docs: add 2.0.0 changelog for ai/aiplugin removal",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T13:54:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a7a509f200735fe1d1a1b13806758b9bae9e9231",
"body": "Drop the \"AI agent runtime\" positioning and aiplugin/llm_agent mentions\nfrom README, docs site (index.astro + rebuilt dist), stability and\nmigration docs. statekit core no longer ships LLM-aware packages; that\ncapability moved to agent-go contrib. Also prune stale nox baseline\nentries pointing at the deleted ai/, aiplugin/, and llm_agent files.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "docs: remove ai/aiplugin and llm_agent references",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T13:53:59Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a04d33fdc331d773cb565ffd9df537b9be7b1dfa",
"body": "BREAKING CHANGE: The ai/ and aiplugin/ packages have been removed from\nstatekit. statekit core must not know about LLMs. These packages have\nbeen rehomed in agent-go (contrib/ai, contrib/aiplugin). No deprecated\nshims are left behind. The examples/llm_agent example is dropped.\n\nClaude-Session: https://claude.ai/code/session_01Cah5LkQHbpxog74NLpujQ9",
"is_bot": false,
"headline": "feat!: remove ai and aiplugin packages (moved to agent-go contrib)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-20T13:49:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f3b1ebdbe1c7a837f11570c2b78e2d68fd04a8e1",
"body": "nox/taint-analysis (cosign-verified, community trust, enforced in\ngo-ci.yml) now covers the taint rules gosec provided (G703/G704/G706 —\nSSRF, path traversal, injection), and nox's core ruleset covers gosec's\ncredential/crypto/file-perm checks. Removes gosec from the linter set,\nits settings and its exclusion rules. `golangci-lint config verify` passes.",
"is_bot": false,
"headline": "ci(security): drop gosec — nox owns code-level security (#67)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-09T09:09:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fb3e0031f52e7e66de1f0282ba342f91fd339a3a",
"body": "Declares nox/taint-analysis in plugins.required so nox scan runs\nsource-to-sink taint analysis (SSRF, injection, path traversal) and\nmerges findings into the security gate. Step toward nox owning all\ncode-level security (then gosec is dropped).",
"is_bot": false,
"headline": "ci(security): enable nox taint-analysis SAST (#66)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-09T06:01:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "855faeb3ca5583a1ef51e5b89ee344b7d449845d",
"body": "fix(parser): reflect.Ptr -> reflect.Pointer (v2.12.2 lint)",
"is_bot": false,
"headline": "Merge pull request #65 from klarlabs-studio/fix/v2.12-lint",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-08T18:13:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4d0301786732446a76fab8aa5d9428059a7dd0aa",
"body": "G115/G118/G204/G703/G704/G706 are high-noise rules that v2.12.2's\nbundled gosec newly enforces (none fired under v2.7.2). Taint\n(G703/G704/G706) moves to nox once nox/taint-analysis is verified;\nthe rest are noisy. gosec keeps its stable high-signal rules.",
"is_bot": false,
"headline": "ci(lint): exclude FP-prone gosec rules new in golangci v2.12.2",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-08T18:10:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6af153a7079031d551a782248b9179c2887c5bd4",
"body": "reflect.Ptr is the deprecated pre-Go-1.18 alias; staticcheck (under\ngolangci v2.12.2) flags it. Mechanical rename, no behavior change.",
"is_bot": false,
"headline": "fix(parser): reflect.Ptr -> reflect.Pointer",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-08T18:02:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "92c2e496e3951bbfa2511a4c6462aa2c73f61ef7",
"body": "ci(nox): add .nox.yaml golden excludes",
"is_bot": false,
"headline": "Merge pull request #63 from klarlabs-studio/ci/nox-excludes",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-08T12:34:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "602ed0fbb5cdc6a37af0ebbdf7f9d42044c91a33",
"body": "Adds the golden .nox.yaml so the security gate flags real findings,\nnot commit-SHA / module-digest / doc-example patterns that the entropy\nsecret rules misfire on. Matches the org nox.reference.yaml.",
"is_bot": false,
"headline": "ci(nox): exclude workflows/docs/go.sum from scanning",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-08T12:31:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c4b32165ffee31a140faac2a963bd40d3e0f7dae",
"body": "ci: adopt shared reusable Go CI workflow",
"is_bot": false,
"headline": "Merge pull request #62 from klarlabs-studio/ci/adopt-shared-workflow",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-08T10:32:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5175f8e5f4f5044ab42d1a4c540a5a8759212b9c",
"body": "- cmd/statekit-mcp: extract run() so log.Fatal doesn't skip defer stop()\n (exitAfterDefer)\n- health: if-else chain -> switch (ifElseChain)\n- statetest: separate Deprecated notice into its own paragraph\n (deprecatedComment)",
"is_bot": false,
"headline": "fix: resolve gocritic findings surfaced by shared lint",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-08T10:28:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7b5c4739efd1f570831a7a109a379c489fc7a29b",
"body": "Replace the bespoke 5-job ci.yml with the org reusable workflow\n(klarlabs-studio/.github). Same gate — fmt, golangci-lint+gocritic,\nrace tests, coverctl check, nox baseline gate — defined once org-wide.\nAdds .golangci.yml (gocritic was not enabled before). Drops the weekly\nfull-CI cron (runtime waste flagged in the org audit).",
"is_bot": false,
"headline": "ci: adopt shared reusable Go CI workflow",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-08T10:22:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "56da4aabb92d08899a7cef332d09675bfb50a74c",
"body": null,
"is_bot": false,
"headline": "fix(ci): bump Pages deploy to Node 22 (Astro requires >=22.12)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-07T20:07:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f0604e5ab628e1942c8fc25d9fcea13bb67238b6",
"body": null,
"is_bot": false,
"headline": "ci: install coverctl from go.klarlabs.de vanity path",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-07T18:22:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "97269e548ce98780dd49f0f6f3ab8f5ac38bcc1f",
"body": "…h migration\n\nThe import path rename to go.klarlabs.de/statekit changed interpreter.go\ncontent, invalidating the CI (nox 0.8.1) fingerprints of four existing\nSEC-574 false positives (Go function name matching the Wise API key\nregex). Re-added via 'nox baseline add -fingerprint' with the same\nrationale as the prior entries.",
"is_bot": false,
"headline": "chore(security): baseline nox SEC-574 fingerprints invalidated by pat…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-06T20:13:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3e8254c01cbdac69116b270a4d883c456cf1611c",
"body": null,
"is_bot": false,
"headline": "style: fix import grouping in generate.go after module path rename",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-06T20:13:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a1c3a8e0d52cdd3132b4e9d19a79cb7874a67c90",
"body": "Repository moved to the klarlabs-studio organization. Module is now\nserved via the go.klarlabs.de vanity import host.\n\nBREAKING CHANGE: import path changed from github.com/felixgeelhaar/statekit\nto go.klarlabs.de/statekit; old path remains available at existing tags via\nGitHub redirect.",
"is_bot": false,
"headline": "feat!: migrate module path to go.klarlabs.de/statekit",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-06T20:06:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d60806bec3b6088592c0e784af8de8715043eb34",
"body": null,
"is_bot": false,
"headline": "ci: dependabot auto-merge (patch+minor) (#59)",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-04T05:45:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a35de6847f4f6607459be85609612b6d01e07dc7",
"body": "…ctions (#58)\n\nThree more XState-class primitives:\n\n- Wildcard '*' event: catch-all transition matched when no exact event\n handler applies; exact matches keep priority; honors guards and\n hierarchical child-priority bubbling.\n- Internal(): transition runs its actions without exiting/re-entering t\n[…]\nrip through the Native JSON and\nXState v5 exporters (on[\"*\"], internal: true, targetless = internal).\n\n9 new feature tests + export round-trip tests. Full suite green, lint\nclean, coverage gates pass.",
"is_bot": false,
"headline": "feat: wildcard (*) events, internal transitions, Choose conditional a…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-02T21:40:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "019dc0addc1ba3142edf0a52803519203fae4035",
"body": "…gs (#57)\n\nAdds three XState-class primitives to the core engine:\n\n- Always(): eventless transitions evaluated on entry and after every\n transition; first enabled (guard-passing) wins, target required.\n- Raise(): enqueue internal events processed in the same macrostep,\n before control returns and \n[…]\nclosing\nthe previously-missing pieces of the Stately Studio export story.\n\nBuilder, IR, validation, interpreter, and exporters wired; 10 new tests\nplus export round-trip coverage. Coverage gates pass.",
"is_bot": false,
"headline": "feat: eventless (Always) transitions, Raise internal events, state Ta…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-06-02T16:51:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f7281bc354c9cdb02d845f954f5a9564e85945b6",
"body": "Bumps [github.com/felixgeelhaar/mcp-go](https://github.com/felixgeelhaar/mcp-go) from 1.9.0 to 1.13.0.\n- [Release notes](https://github.com/felixgeelhaar/mcp-go/releases)\n- [Changelog](https://github.com/felixgeelhaar/mcp-go/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/felixgeelhaar/mcp-go\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "deps: bump github.com/felixgeelhaar/mcp-go from 1.9.0 to 1.13.0 (#51)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-01T19:37:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "234dfc85be734948caf094e4ab6c5c15163250c7",
"body": "Bumps [go.opentelemetry.io/otel/sdk](https://github.com/open-telemetry/opentelemetry-go) from 1.43.0 to 1.44.0.\n- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)\n- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)\n- [Commits](https://\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "deps: bump go.opentelemetry.io/otel/sdk from 1.43.0 to 1.44.0 (#54)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-01T19:34:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8f5eb675b28c14f80d767739875fa117364874e9",
"body": "Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.35.4 to 4.36.0.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/6\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "ci: bump github/codeql-action from 4.35.4 to 4.36.0 (#52)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-01T19:30:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "92a65b52fa73c370b84b8d2083a3285b43e4ba20",
"body": "Bumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action) from 9.2.0 to 9.2.1.\n- [Release notes](https://github.com/golangci/golangci-lint-action/releases)\n- [Commits](https://github.com/golangci/golangci-lint-action/compare/1e7e51e771db61008b38414a730f564565cf7c20...82\n[…]\nirect:production\n update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "ci: bump golangci/golangci-lint-action from 9.2.0 to 9.2.1 (#53)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-01T19:30:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9e26a112511237940e7772da3465827518358328",
"body": "Bumps [go.opentelemetry.io/otel/trace](https://github.com/open-telemetry/opentelemetry-go) from 1.43.0 to 1.44.0.\n- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)\n- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)\n- [Commits](https:\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "deps: bump go.opentelemetry.io/otel/trace from 1.43.0 to 1.44.0 (#55)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-01T19:30:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ed777a7cdd7a6e2a8753c0921e627505ac4b3a5d",
"body": "Bumps [go.opentelemetry.io/otel](https://github.com/open-telemetry/opentelemetry-go) from 1.43.0 to 1.44.0.\n- [Release notes](https://github.com/open-telemetry/opentelemetry-go/releases)\n- [Changelog](https://github.com/open-telemetry/opentelemetry-go/blob/main/CHANGELOG.md)\n- [Commits](https://gith\n[…]\nirect:production\n update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
"is_bot": true,
"headline": "deps: bump go.opentelemetry.io/otel from 1.43.0 to 1.44.0 (#56)",
"author_name": "dependabot[bot]",
"author_login": "dependabot[bot]",
"committed_at": "2026-06-01T19:30:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0c2cff94f05607e93c65f4beafdbf4f22287c6cf",
"body": "Resolves dependabot alerts:\n- devalue prototype pollution (CVE-2026-42570, high)\n- yaml stack overflow on deeply nested collections (GHSA-48c2-rrv3-qjmp, moderate)\n\nyaml is a deep transitive of @astrojs/check (via @astrojs/language-server\n→ volar-service-yaml → yaml-language-server). Pinned via package.json\noverrides to bypass the unpatched upstream chain. devalue patched\ntransitively via astro upgrade.",
"is_bot": false,
"headline": "chore(deps): patch devalue + yaml in docs site",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-23T14:22:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f69d233e709b559f670ce8ebdb54cb5ec3fe7ef7",
"body": "- Add concurrency.cancel-in-progress to kill duplicate runs.\n- Skip CI on **.md, docs/**, LICENSE changes.",
"is_bot": false,
"headline": "ci(actions): add concurrency + path filter",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-23T13:22:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7bfb5e3b0f40001a61960e9069a3c1c84b5522ae",
"body": "CI's nox plugin set flags 8 distinct secret patterns (Braintree, Maven,\nNuGet, DigitalOcean, Datadog, SendGrid, Grafana) on README.md lines 77\nand 82 — all are docs/code-sample false positives, not real keys. Local\nnox doesn't auto-install the same plugins so these only surface in CI.\n\nBaselining lets the gate ignore them while keeping future net-new\ncritical/high findings blocking.",
"is_bot": false,
"headline": "chore(security): baseline 16 README.md secret false positives",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-10T09:31:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6649932ac98eeb8b26bbd313e814a19150645b65",
"body": "- Pin all GitHub Actions to commit SHAs with version comments to satisfy\n nox 0.8.1's IAC-013 rule (10 net-new high findings on ci.yml).\n- Add `|| true` to `nox scan` so the severity gate runs; nox exits 1 on\n any unsuppressed finding regardless of severity, but only critical/high\n should block.\n- Fix gate jq to PascalCase fields (.Severity, .Status, .Location.*) to\n match actual findings.json schema; previous lowercase paths always\n counted 0 so the gate never fired.",
"is_bot": false,
"headline": "ci(security): pin actions to SHAs, fix gate jq paths, tolerate nox exit",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-10T09:24:32Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0058826c0a9c8e939db593cc1d014541cca58a6e",
"body": "…dd weekly sweep\n\nHardens the existing nox security job:\n\n- Bumps the pinned nox version from 0.7.0 to 0.8.1 (matches the\n installed CLI / MCP server in development).\n- Adds a weekly cron schedule (Mon 06:17 UTC) so the scan runs even\n when the repo is quiet — catches newly-disclosed CVEs in deps\n\n[…]\nE badge tracks live state.\n\nAll other steps (scan, SARIF upload, PR annotate, remediation plan,\nartifact upload) unchanged.\n\nSource: user request — strengthen nox in CI beyond the basic scan\npipeline.",
"is_bot": false,
"headline": "ci(security): bump nox to 0.8.1, gate on unbaselined critical/high, a…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-10T07:16:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d98a9919fd737fa8e0c52b8ce92f44b2bb4ac6d4",
"body": "…ation plan\n\nBrings the nox security pipeline up to date with the new code that\nlanded since v1.4.x:\n\n- Baseline 14 new false positives surfaced after v1.4.0+ commits\n (ai/ai_test test fixtures, viz/fuzz_test seed lines flagged as LLM\n seeds, aiplugin entropy hex from concurrent counters, JSON-LD \n[…]\ne score.\n- Both new steps are continue-on-error to avoid blocking releases\n if nox emits unexpected output.\n\nSource: user request — wire up nox security scans + badge + the\nnew remediation plan flow.",
"is_bot": false,
"headline": "build(security): refresh nox baseline, add A-grade badge, wire remedi…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-10T07:10:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7c36c017caf2296bb904343214c34bb24d9a0f8f",
"body": "Two new rules from the lint-followup task:\n\n- auto-forward-redundancy: warns when a state's MachineInvocations\n AutoForward list includes an event the same state declares a\n transition for. The parent's transition consumes the event first,\n so the AutoForward never reaches the child — almost alwa\n[…]\nn-\naction) need runtime data, expression analysis, or declarative\nannotations not present in the IR — deferred until the missing\ninputs exist.\n\n87.9% coverage. lint domain still PASS at 85% threshold.",
"is_bot": false,
"headline": "feat(lint): add auto-forward-redundancy and deep-nesting rules",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-10T06:58:24Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "273dd8b396154576d02ba798c14a67c6c5f225be",
"body": "Closes the t.Parallel sweep started in commit 6b4f822. Adds\nt.Parallel() to ~70 additional unit tests across 10 files:\nactor, persist, distributed, invoke, invoke_machine, interpreter,\ninterpreter_property, parallel, plugin, snapshot_actor, history.\n\nRace-clean under go test -race ./... — confirms t\n[…]\nrk_test.go, performance_bench_test.go (benchmarks)\n- example_test.go (no Test funcs)\n- testmain_test.go (only declares TestMain for goleak)\n\nSource: quality review — top-3 leverage move, now complete.",
"is_bot": false,
"headline": "test: enable t.Parallel() across remaining test files",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-10T06:55:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a5b1ba7977f524e8e1a6bf0a96e32b52edc2e2d4",
"body": "…r/touch handlers\n\nFrontend review: Visualizer.vue (424 LOC) god component mixed state\nownership, simulation engine, toast manager, and event handlers.\nStateCanvas was mouse-only — touch users couldn't pan or zoom.\n\n- composables/useToasts.ts: single ref<Toast[]> store with show/\n dismiss/clear. Er\n[…]\nrrors.\n\nMobile sidebar drawer + extracting useLayout/useKeyboard/canvas-\nrenderer deferred — bigger refactors that need a follow-up PR.\n\nSource: 4-expert website review — Frontend dimension top-3 ROI.",
"is_bot": false,
"headline": "refactor(docs): extract useToasts + useSimulation composables, pointe…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T21:58:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6a5ceeef9dbbea658612b33c8858c13c078191b4",
"body": "Frontend review flagged zero CI safety net for the visualizer. This\naddresses the testable surface; Playwright e2e deferred (browser\ndownload adds ~100MB to the lockfile and is better as a separate\nPR).\n\n- npm scripts: check (astro check), test (vitest run), test:watch,\n test:ui.\n- vitest.config.ts\n[…]\nrun check` reports 0 errors, 0 warnings, 2 hints (deprecated\nunescape — see followup task).\n`npm test` reports 15/15 passing in <500ms.\n\nSource: 4-expert website review — Frontend dimension top-3 ROI.",
"is_bot": false,
"headline": "test(docs): add Vitest + astro check infrastructure",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T21:28:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "151b539409a2f38c3990fd586a29c0afca0802d2",
"body": "Closes the biggest GTM gap from the website review: 25 markdown\nfiles lived in the repo unrendered. Now each is a real page with\nits own canonical URL, OG tags, and an SEO-friendly title.\n\n- src/pages/docs/[slug].astro: dynamic route. import.meta.glob\n loads every ../../*.md eagerly; getStaticPaths\n[…]\narkdown-body cover headings, code blocks,\n tables, blockquotes, links, hr — matches the dark theme.\n\nBuild now emits 26 pages (was 2).\n\nSource: 4-expert website review — GTM dimension top-3 ROI move.",
"is_bot": false,
"headline": "feat(docs): publish 23 markdown docs as routed pages under /docs/",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T21:26:01Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9fb05ed1e266685f4807c56d79322bd183b420ce",
"body": "Viral primitive that turns the visualizer into a sharable artifact.\n\n- New utils/share-url.ts:\n - encodeMachine / decodeMachine (URL-safe base64 over JSON)\n - readMachineFromHash() inspects #m=... on load\n - buildPermalink(machine) emits a self-referential URL\n - machineToMermaid generates a sta\n[…]\nxpert website review — Product dimension top-3 ROI move\n(\"share-URL + LZ-compressed JSON in hash\" + \"copy as Mermaid\" +\n\"copy as Go builder\"). Compression deferred until size becomes a\nconcrete issue.",
"is_bot": false,
"headline": "feat(docs): share-URL permalinks + copy-as-Mermaid + copy-as-Go-builder",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T21:14:30Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "29db71c4b13a8ab2ecb2331db30827cba968325d",
"body": "UX review: 3-second auto-dismiss is too short to read a JSON error\nmessage. Errors now stay until the user dismisses them; success\ntoasts auto-dismiss as before.\n\n- showToast: skip the auto-removal timer for type='error'.\n- dismissToast: explicit removal handler invoked from a per-toast\n close butt\n[…]\n the existing modal-close pattern.\n\nMobile + canvas-touch handlers + inline-line-number JSON errors\ndeferred to component refactor task.\n\nSource: 4-expert website review — UX dimension top-3 friction.",
"is_bot": false,
"headline": "fix(docs): persistent error toasts with dismiss button",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T21:11:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f1d9fbe068e0665d2d4adf8ed10255c6578a26c0",
"body": "…error boundary\n\nThree correctness fixes flagged by the frontend review:\n\n- Visualizer.vue: extract resolveInitialLeaf() with a Set-based\n cycle guard. Replaces the previous `while (states[x].initial)`\n loops at startSimulation + sendEvent that would infinite-loop on\n cyclic initial chains in mal\n[…]\nthat surfaces\n descendant render errors as an error toast instead of blanking\n the page. Returns false to suppress propagation.\n\nSource: 4-expert website review — Frontend dimension robustness\nhits.",
"is_bot": false,
"headline": "fix(docs): visualizer robustness — cycle guards, roundRect polyfill, …",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T21:09:50Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "644f24f57df3eefc00afa26363e5111003cfc547",
"body": "Two improvements from the frontend + UX reviews:\n\n- play.astro now mounts <Visualizer client:idle /> as an Astro Vue\n island. Was: manual createApp(Visualizer).mount('#visualizer-mount')\n in inline <script> on page load — Vue runtime + visualizer\n hydrated eagerly even when canvas not in viewport\n[…]\nmode, embeds) still get the sample\n rather than an empty canvas — Jakob's-law violation killed.\n\nSource: 4-expert website review — Frontend (eager hydration) + UX\n(empty-state bounce on first paint).",
"is_bot": false,
"headline": "perf(docs): convert Visualizer to Astro island + auto-load sample",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T21:06:46Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "dac68db80f9e08e4008d7bb77a12eae29e5cec9e",
"body": "Visualizer accessibility sweep targeting the issues UX review flagged:\n\n- KeyboardShortcuts.vue gets role=\"dialog\", aria-modal=true,\n aria-labelledby, focus trap (Tab/Shift+Tab cycle, Esc closes),\n return-focus to trigger on close, aria-label on close button.\n- JsonImporter.vue file-upload zone is\n[…]\n bumps on --text-secondary 8b949e→adbac7 and --text-muted\n484f58→7d8590, plus header nav ARIA shipped in landing-rebuild\ncommit e4465de.)\n\nSource: 4-expert website review — UX dimension WCAG 2.2 hits.",
"is_bot": false,
"headline": "feat(docs/a11y): WCAG 2.2 AA fixes — focus trap, ARIA, contrast",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T21:05:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1f8639c86a78819cb4cf8391bb308e56b2200fc3",
"body": null,
"is_bot": false,
"headline": "build(docs): rebuild static dist for landing + /play",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T21:02:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e4465debb758c4998bc6e30fca2f4c8edb00faaf",
"body": "Replaces the visualizer-as-homepage that all four expert reviews\nflagged as the top issue (wrong category framing, zero conversion\npath, no positioning).\n\nNew /:\n- Hero with concrete-pain headline + 10-line code sample\n- \"Why Statekit\" 6-card grid lifted from README positioning\n- Comparison table vs\n[…]\nimg\" on Header SVGs and icon-only buttons\n- Mobile breakpoint hides nav cleanly at <720px\n\nSource: 4-expert website review (UX/GTM/Product/Frontend) — top\nconsensus actions across all four dimensions.",
"is_bot": false,
"headline": "feat(docs): landing page at /, visualizer moved to /play, OG + sitemap",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T21:02:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a17ac42f9407bc2322f626d7ed8ea60bcbb21428",
"body": "README fixes:\n- Bump Go requirement 1.24 → 1.25 (matches go.mod).\n- Standardize on `defer interp.Close()` everywhere (was mixed\n Stop/Close/none across Quick Start, hierarchical, delayed,\n parallel examples).\n- Refresh \"Additional Packages\" table — adds ai, aiplugin, mcp tier\n notes, replaces \"XS\n[…]\n(cancellation recovery), plus a\n TransitionBudget reference.\n- qmuntal/stateless guide adds TransitionBudget reference for the\n runaway-halt pattern (#77).\n\nNo code changes; tests still 33/33 green.",
"is_bot": false,
"headline": "docs: README polish + migration-guide TransitionBudget callouts",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T20:45:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e845fc5c36fa53fb1426f613a989b6138ce8048a",
"body": "Directly addresses the qmuntal/stateless #77 pattern: workflow\nexecution that needs to halt after N transitions to prevent runaway\nloops. The author there had to fight the library — statekit users\ncan drop in TransitionBudget instead.\n\nBehavior:\n- AfterTransition counts only state-changing transitio\n[…]\n an end-to-end runaway-machine scenario that\nconfirms the budget halts a real loop within the configured budget.\n\n91.8% coverage.\n\nSource: ICP signal sweep — verbatim quote from qmuntal/stateless #77.",
"is_bot": false,
"headline": "feat(aiplugin): add TransitionBudget for runaway prevention",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T20:23:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "47bee81454260acb7da9cf6b647a291b9f821232",
"body": "ICP signal sweep findings (verbatim quotes from competitor open issues)\ninformed two new README sections above the \"Why\" block:\n\n- \"Two jobs\" — explicit narrative thread linking the backend wedge\n (Stripe webhook saga example) with the AI wedge (llm_agent + ai +\n aiplugin). Same primitives, two ad\n[…]\noccupied by dstotijn/go-xstate and\nCorrectRoadH/XState-For-Golang.\n\nSource: ICP signal sweep across HN, /r/golang, GitHub issues on\nlooplab/fsm + qmuntal/stateless, and 2026 agentic-runtime landscape.",
"is_bot": false,
"headline": "docs(readme): add two-jobs section + migration callout for FSM refugees",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T20:21:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b41da5b54c3aa5c0b0547b9c97e71ea3091e101a",
"body": "Two competitor-issue counter-tests that lock in differentiation:\n\n- cancellation_recovery_test.go targets the looplab/fsm #115 pattern\n (cancelled context leaves FSM in InTransitionError limbo with no\n recovery). statekit doesn't tie an external context.Context to the\n Send path; the analog is se\n[…]\nlly.\n\nBoth tests double as regression guards and as documented public\nguarantees.\n\nSource: ICP signal sweep — direct verbatim quotes from the two top\nopen issues across the incumbent Go FSM libraries.",
"is_bot": false,
"headline": "test: counter-tests vs looplab/fsm #115 + #40 production pain",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T20:19:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ff55e99f248ba5d7c98cf72e5875447d6c9f6a3b",
"body": null,
"is_bot": false,
"headline": "chore(lint): satisfy errcheck and staticcheck before release",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T19:43:29Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6b4f8223dcb3f71dd626aef239ca02ed25159fba",
"body": "Adds t.Parallel() to 46 unit tests across 6 test files (types,\nvalidation, builder, hierarchy, snapshot, reflect). These cover pure\nmachine construction and snapshot logic — no timer, lock, or\nevent-store state, so parallelism is safe.\n\nRace-clean under go test -race.\n\nSkipped (intentionally sequent\n[…]\nnce_bench_test.go.\n\nSource: quality review — t.Parallel sweep was top-3 leverage move.\nThis is the safe subset; remaining files need lock/event-store\nisolation per package before they can parallelize.",
"is_bot": false,
"headline": "test: enable t.Parallel() across non-timer unit tests",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T18:29:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "856247f2451253ef83c12c3cedf3fdcaa93314e4",
"body": "XStateExporter[C] converts a MachineConfig to XState v5 JSON consumable\nby Stately Studio (https://stately.ai/studio). Closes the loop with\nthe existing Native JSON ↔ Go codegen path:\n\n Stately ─JSON─► statekit generate ─Go─► your service\n │\n \n[…]\nnd-trip JSON parsing.\n\nSource: product + UX reviews — Stately bidirectional sync was the\ntop \"moat compounder\" recommendation. VSCode preview extension\ndeferred — needs separate repo + npm publishing.",
"is_bot": false,
"headline": "feat(export): add XState v5 exporter for Stately Studio round-trip",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T18:28:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ee20bd750a8f39a555b833dbed38bf073bd52c3a",
"body": "Adds:\n- docs/README.md — Diataxis index (tutorials / how-to / reference /\n explanation) with quick decision table for picking an API\n- docs/choosing-an-api.md — decision tree for builder vs reflection\n DSL vs codegen, plus mixing patterns and named-action rationale\n\nRemoves:\n- docs/prd.md — projec\n[…]\nly; the docs/README.md\nindex gives the same navigability without the breakage.\n\nSource: UX review — Diataxis fail callout. Lighter shipping path\nthat improves discovery without breaking inbound links.",
"is_bot": false,
"headline": "docs: Diataxis-organized index, choosing-an-api guide, drop project-meta",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T18:24:49Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "02e96f41a3f3101da011ca4fd394b1ce011f947c",
"body": "Two AI primitives that bridge LLM output into deterministic state\ntransitions without bringing an LLM SDK into the core library.\n\n- Decider[C] — typed function that picks an event from declared\n candidates given the current machine context.\n- Drive[C] — invokes the decider, validates the chosen eve\n[…]\ning this gives reproducible\nagent runs.\n\nSource: AI review — top 3 features call-out (LLMTransition,\ntool-call schema, streaming hooks). Streaming hook deferred — would\nneed a new plugin hook in core.",
"is_bot": false,
"headline": "feat(ai): add Drive helper and Tool schema for LLM-backed transitions",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T18:22:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e5eda69f55b70399322dd4bd96332dad9dd71076",
"body": "Models a Stripe payment_intent.succeeded webhook handler as a 5-state\nsaga with the outbox pattern:\n\n received → checking_idempotency → fulfilling → succeeded | failed\n ↘ retry_decision ↗\n\nDemonstrates load-bearing patterns:\n- Idempotency check via Invoke service + \n[…]\nws — flagship tutorial called for in\n\"ship one polished real-world template\" recommendation. Webhook\nhandlers are the canonical \"stateful microservice\" job most teams\nget wrong with switch statements.",
"is_bot": false,
"headline": "feat(examples): add stripe_webhook saga — flagship real-world example",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T18:16:56Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d41cea50721ea1e956f74a6c064bf7dcc5531329",
"body": "Drops the abstract \"Go-native statechart execution engine\" framing in\nfavor of the concrete pain users actually feel: switch statements and\nad-hoc FSMs sprawled across order/payment/incident lifecycles.\n\nLead changes:\n- 1-line value prop + 10-line working code snippet above the fold,\n not a 16-bull\n[…]\ned\nwith the stability tiers doc (commit 58701e3), this realigns the\nproject narrative around the in-process domain-logic wedge instead\nof competing on workflow-orchestration ground statekit can't win.",
"is_bot": false,
"headline": "docs(readme): rewrite hero — concrete pain, demote experimental",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T16:27:58Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e9ae9895ab99ab8b0d067525a5245cb6161786a9",
"body": "Replaces wall-clock sleeps and assertEventually-style polling with\ndeterministic FakeClock advances. Eliminates the timer-flake risk\nidentified by the quality review (50ms windows + 30ms sleeps under\nshared CI load).\n\nTest runtime drops from ~3-5s to ~0.4s. All tests now run in\nt.Parallel without race conditions.\n\nSource: quality review — top-1 risk was timer flake bomb in\ndelayed_test.go. Followup to commit 66ac9cf which introduced the\nClock + FakeClock + WithClock infrastructure.",
"is_bot": false,
"headline": "test: convert delayed_test.go to FakeClock",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T16:26:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "248ca4adf83ed9b4104be2feac22231625e4bbf2",
"body": "…liases\n\nNaming improvements that ship without breaking v1.0 API:\n\n- StateBuilder.EndMachine() and TransitionBuilder.EndMachine() — new\n terminators that return *MachineBuilder. Equivalent to Done() but\n names the intent clearly. Done() retains its semantics; godoc now\n warns about the nested-sta\n[…]\nype names remain functional. The new names are preferred in new\ncode.\n\nSource: UX review — top friction point cited Done()/End()/EndState\nambiguity and InvokeBuilder vs MachineInvokeBuilder collision.",
"is_bot": false,
"headline": "feat(builder): add EndMachine + clearer InvokeService/InvokeMachine a…",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T16:24:57Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6c5de14460c43b55e76922ab2a8a70c2ffac4dc8",
"body": "New docs/stability.md explicitly tiers the v1.0 surface:\n\n- Tier 1 — Stable (semver-protected): builder API, interpreter, core\n types, reflection DSL, snapshots, plugin system, lint, visualization,\n testing utilities, HTTP, OTel, Prometheus, health, codegen, Clock.\n- Tier 2 — Experimental (may ite\n[…]\na was too broad to lock\nall of v1.0 at the same stability grade. This is the lower-risk\nshipping path of the \"demote experimental\" recommendation; physical\npackage moves to x/ remain a v2.0 candidate.",
"is_bot": false,
"headline": "docs(stability): publish API tier classification",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T16:22:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "524b703ef7549772ba7109f06e56c27c681a844d",
"body": "Two new migration guides target users of the incumbent Go FSM\nlibraries:\n\n- docs/migration-from-looplab-fsm.md — concept mapping table,\n worked door example before/after, replacement patterns for\n metadata → typed context, before_event → guards, manual\n goroutines → Invoke services. Step-by-step \n[…]\ntranslation (Substate → nested State blocks).\n\nBoth linked from README under Documentation.\n\nSource: product review — direct rivals in Go FSM space; migration\nguides lower switching cost dramatically.",
"is_bot": false,
"headline": "docs(migration): add looplab/fsm and qmuntal/stateless migration guides",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T16:22:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8b281c44f1019147f72c7f4d2bceca00026da38f",
"body": null,
"is_bot": false,
"headline": "docs(roady): track 6 follow-ups discovered during execution",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T16:22:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0458de1bffe674303d56fd684f33ef998b080477",
"body": "Adds a Clock interface and FakeClock implementation so timer-driven\nbehavior (delayed transitions, future supervision timers) can be\ncontrolled deterministically in tests.\n\n- Clock.AfterFunc(d, fn) → Timer interface, mirroring time.AfterFunc.\n- SystemClock(): default wall-clock implementation.\n- Fak\n[…]\ntest.go (50ms wall-clock windows + 30ms sleep). Existing\nwall-clock tests untouched; new tests can opt in to FakeClock for\nflake-free determinism (see TestInterpreter_WithFakeClock_DelayedTransition).",
"is_bot": false,
"headline": "feat(interpreter): inject Clock for deterministic timer-driven tests",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T16:22:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e68dd38a20938a6ae4339af1c48a14e0fa127f9f",
"body": "Demonstrates statekit + aiplugin as a deterministic agent runtime.\n4-state RAG pipeline: idle → retrieving → generating → awaiting_review\n→ done, with HITL approval and an error sink. The machine itself is\ndeterministic; LLM nondeterminism is contained in actions that emit\nevents with token/cost pay\n[…]\n AFTER guard evaluation.\n\nSource: AI review — top positioning move (examples/llm_agent was\nexplicitly called out alongside rag_pipeline and hitl_approval as\nneeded examples for the runtime narrative).",
"is_bot": false,
"headline": "feat(examples): add llm_agent — deterministic RAG pipeline",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T16:22:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7201b96160fee25e86e27599c4a36af098f84801",
"body": "New aiplugin package providing AI/LLM-specific plugins that build on\nthe core plugin system:\n\n- TokenCounter[C] — accumulates input/output tokens and USD cost\n from event payloads. Uses atomic counters; safe\n under concurrent OnEvent.\n- PromptRecorder[C] —\n[…]\nt counters were missing despite Prometheus\nhaving generic metrics; replay-based debugging needs prompt snapshots.\nThis is the foundation for the broader \"deterministic agent runtime\"\npositioning move.",
"is_bot": false,
"headline": "feat(aiplugin): add token counter and prompt recorder plugins",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T16:22:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "728c59016d5e80d020bf29fb78cdf6a2589fdd7a",
"body": "Adds ExposeInterpreter[C] which inverts the existing authoring-\ndirection MCP server. The current server lets Claude create machines\nfrom JSON; this lets a running typed interpreter be driven from the\noutside by an MCP-speaking agent.\n\nRegisters four tools under a caller-chosen prefix:\n- <prefix>.se\n[…]\n and easier testing.\n\nSource: AI review — top positioning move. Closes the loop for\nagent-driven workflows; combined with OTel tracing + event sourcing\nthis is the \"deterministic agent runtime\" story.",
"is_bot": false,
"headline": "feat(mcp): expose running interpreters as MCP tools",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T16:22:06Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "175d4f569486218b32ff78ddb25131cf45644d88",
"body": "ParseNativeJSON now has fuzz-test coverage for arbitrary input. The\nparser must not panic regardless of input shape; malformed bytes\nshould yield a clean error.\n\n3-second sweep runs 1.1M executions and finds 197 new interesting\ninputs — all handled without panics.\n\nSource: quality review — only 1 fuzz file existed previously\n(internal/parser); critical input boundaries left unfuzzed.",
"is_bot": false,
"headline": "test(viz): add fuzz test for Native JSON parser",
"author_name": "Felix Geelhaar",
"author_login": "felixgeelhaar",
"committed_at": "2026-05-09T16:22:06Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 30,
"commits_last_year": 232,
"latest_release_at": "2026-07-10T20:36:19Z",
"latest_release_tag": "v1.12.0",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 16,
"days_since_latest_release": 17,
"mean_days_between_releases": 6.9
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 75,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": true
},
"ecosystem": {
"packages": [
{
"name": "go.klarlabs.de/statekit",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": null,
"registry_url": "https://pkg.go.dev/go.klarlabs.de/statekit",
"is_deprecated": false,
"latest_version": "v1.12.0",
"repository_url": null,
"versions_count": 34,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-10T20:33:02Z",
"latest_version_yanked": null,
"days_since_latest_publish": 17
}
]
},
"popularity": {
"forks": 0,
"stars": 0,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": {
"days": [],
"complete": true,
"collected": 0,
"total_stars": 0,
"collected_at": null
},
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"docs/tsconfig.json"
],
"toolchain_manifests": [
"go.mod"
],
"largest_source_bytes": 46384,
"source_files_sampled": 144,
"oversized_source_files": 0,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 38202
},
"dependencies": {
"manifests": [
"docs/package.json",
"go.mod"
],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go",
"npm"
],
"dependencies": [
{
"name": "github.com/charmbracelet/bubbletea",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.3.10"
},
{
"name": "github.com/charmbracelet/lipgloss",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.0"
},
{
"name": "github.com/prometheus/client_golang",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.23.2"
},
{
"name": "github.com/spf13/cobra",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.10.2"
},
{
"name": "go.opentelemetry.io/otel",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/otel/sdk",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.opentelemetry.io/otel/trace",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.44.0"
},
{
"name": "go.uber.org/goleak",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.3.0"
},
{
"name": "golang.org/x/tools",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.47.0"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 63,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 34
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "felixgeelhaar",
"commits": 196,
"avatar_url": "https://avatars.githubusercontent.com/u/6020564?v=4"
}
],
"contributors_sampled": 1,
"top_contributor_share": 1
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"deploy.yml",
"nox-remediate.yml",
"provenance.yml",
"release.yml"
],
"has_docs_dir": true,
"linter_configs": [
".golangci.yml"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"go.sum",
"package-lock.json"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 9,
"reason": "binaries present in source code",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 3,
"reason": "branch protection is not maximal on development and all release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 8,
"reason": "17 out of 19 merged PRs checked by a CI test -- score normalized to 8",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/22 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 3,
"reason": "project has 1 contributing companies or organizations -- score normalized to 3",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 10,
"reason": "project is fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 6,
"reason": "dependency not pinned by hash detected -- score normalized to 6",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 0,
"reason": "SAST tool is not run on all commits -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 10,
"reason": "security policy file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": 0,
"reason": "Project has not signed or included provenance with any releases.",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 0,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 10,
"reason": "0 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "7d3d1cf71a087194b0cc1b26d77bd6c81593a1d1",
"ran_at": "2026-07-28T08:09:36Z",
"aggregate_score": 6,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-27T10:18:35Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-07-27T10:15:06Z",
"ci_last_conclusion": "SUCCESS",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/klarlabs-studio/statekit",
"host": "github.com",
"name": "statekit",
"owner": "klarlabs-studio"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 62,
"inputs": {
"security": 60,
"vitality": 81,
"community": 36,
"governance": 47,
"engineering": 84
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 81,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"commits_last_year": 232,
"human_commit_share": 0.89,
"days_since_last_push": 0,
"active_weeks_last_year": 16
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "16/52 weeks with commits",
"points": 11.1,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 16
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "232 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 232
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"releases_count": 30,
"latest_release_tag": "v1.12.0",
"releases_from_tags": false,
"days_since_latest_release": 17,
"mean_days_between_releases": 6.9
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "30 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 30
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 17 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 17
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~6.9 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 6.9
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 0,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 0 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 0
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "at_risk",
"name": "Community & Adoption",
"value": 36,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 1,
"inputs": {
"forks": 0,
"stars": 0,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "0 stars",
"points": 0,
"status": "missed",
"details": [
{
"code": "stars",
"params": {
"count": 0
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "good",
"name": "Community health",
"note": null,
"notes": [],
"value": 77,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 6.3,
"status": "met",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "at_risk",
"name": "Sustainability & Governance",
"value": 47,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 13,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 1,
"top_contributor_share": 1
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 100% of commits",
"points": 0,
"status": "missed",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 100
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "1 contributors",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 1
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 3,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "at_risk",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 47,
"inputs": {
"merged_prs": 63,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 34
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "63/97 decided PRs merged",
"points": 24.8,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 63,
"decided": 97
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/22 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 44,
"inputs": {
"followers": 1,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "klarlabs-studio",
"public_repos": 36,
"account_age_days": 51
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "1 followers of klarlabs-studio",
"points": 2.2,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 1,
"login": "klarlabs-studio"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "36 public repos, account ~0 yr old",
"points": 11.7,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 36
}
},
{
"code": "account_age_years",
"params": {
"years": 0
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"go.klarlabs.de/statekit"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 17
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 17 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 17
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "34 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 34
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 84,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 80,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "5 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 5
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": ".golangci.yml",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "17 out of 19 merged PRs checked by a CI test -- score normalized to 8",
"points": 16,
"status": "partial",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": "https://klarlabs-studio.github.io/statekit/",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://klarlabs-studio.github.io/statekit/",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 60,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"packaging"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 60,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 17,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 1,
"scorecard_aggregate": 6
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "binaries present in source code",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection is not maximal on development and all release branches",
"points": 2.2,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "17 out of 19 merged PRs checked by a CI test -- score normalized to 8",
"points": 2,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/22 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 1 contributing companies or organizations -- score normalized to 3",
"points": 0.8,
"status": "partial",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is fuzzed",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 6",
"points": 3,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is not run on all commits -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file detected",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "Project has not signed or included provenance with any releases.",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "0 existing vulnerabilities detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "excellent",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"review_only_matches": 0,
"assessed_self_published_locations": 2
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 79,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.989,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 38202
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "88 of 89 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 88,
"sampled": 89
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 81,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum",
"package-lock.json"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"docs/tsconfig.json"
],
"agent_commit_share": 0,
"toolchain_manifests": [
"go.mod"
],
"dependency_bot_commit_share": 0.11
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "go.mod (toolchain convention, no task runner)",
"points": 12.6,
"status": "partial",
"details": [
{
"code": "toolchain_convention",
"params": {
"files": "go.mod"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": ".golangci.yml",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "docs/tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "docs/tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "no agent-authored commits among the last 100",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_agent_authored_commits",
"params": {
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "11 of the last 100 commits are automated dependency updates",
"points": 8,
"status": "met",
"details": [
{
"code": "dependency_bot_commits",
"params": {
"count": 11,
"sampled": 100
}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 6",
"points": 6,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 46384,
"source_files_sampled": 144,
"oversized_source_files": 0
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "0/144 source files over 60KB",
"points": 55,
"status": "met",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 144,
"oversized": 0
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "at_risk",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": false,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-28T08:09:50.718411Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/k/klarlabs-studio/statekit.svg",
"full_name": "klarlabs-studio/statekit",
"license_state": "standard",
"license_spdx": "MIT"
}