公开记录
软件健康报告模式 0.27.0 · 指标 2.3.1 · 2026-08-01 13:11 UTC

logly / mureo

Your local-first AI ad ops crew. Works with Claude Code, Cursor, Codex & Gemini.

PythonApache-2.0★ 23 星标⑂ 3 复刻始于 2026年3月在 GitHub 上查看 ↗
类型MCP 服务器命令行工具如何判定

logly/mureo 的健康指数为 100 分中的 81 分,处于「优秀」区间。 其得分最高的类别是Vitality(86/100),最低的是AI Readiness(54/100)。 最近一次更新在今天。 近期的大部分工作由 1 位贡献者完成。

81
总分 / 100
优秀

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均,再依据公开记录的分布进行校准,使各等级具有百分位含义;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 34(存在风险)的上限。

81
卓越93-100公开记录中的最高层级(约前 5%);基本满足所有检验标准
优秀80-92各方面均表现强劲;仅有少量不足
良好65-79健康;不足之处有限且可控
中等50-64可接受,但存在明显不足;建议进行审查
薄弱35-49多个领域存在实质性薄弱环节
存在风险20-34存在重大薄弱环节;采用时应保持审慎
危急1-19问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

加权总体分 69 经校准后在公布的指数量表上为 81(记录校准 2026-08-02)。

所有权

0 关注者7 个公开仓库始于 2012年11月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布标签
PyPImureo0.10.385,105690 天前advertisingai-agentcligoogle-adsmcpmeta-adsorchestrationstrategyworkflow

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

86优秀 · 占总体的 21%
评分方式
36/36推送新近度 — 最近一次推送于 0 天前
12.5/36提交节奏 — 52 周中有 18 周有提交
18/18提交量 — 最近一年 498 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 26 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year498
human_commit_share0.97
days_since_last_push0
active_weeks_last_year18

发布纪律

100卓越
评分方式
27/27有发布版本 — 已发布 72 个发布版本
36/36发布时效 — 最近一次发布版本于 0 天前
27/27发布节奏 — 约每 1.5 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count72
latest_release_tagv0.10.38
releases_from_tags
days_since_latest_release0
mean_days_between_releases1.5
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

57中等 · 占总体的 17%

流行度与采用

24存在风险
评分方式
21.8/60星标 — 23 个星标
2.5/25复刻 — 3 个复刻
0/15关注者 — 0 位关注者
所用输入
forks3
stars23
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

92优秀
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(Apache-2.0)
18/18CONTRIBUTING 指南
13.5/13.5行为准则
0/7.2议题模板
6.3/6.3PR 模板
所用输入
has_readme
has_license
readme_badges
has_contributing
has_issue_template
has_code_of_conduct
readme_badge_services
has_pull_request_template
评分方式
49.4/80月度下载量 — pypi 合计每月 5,105 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packagesmureo
dependents
ecosystemspypi
total_downloads
monthly_downloads5,105
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

56中等 · 占总体的 23%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0/22.5提交分布 — 头号贡献者编写了 100% 的提交
1.4/13.5贡献者广度 — 1 位贡献者
3/10OpenSSF Scorecard:Contributors — project has 1 contributing companies or organizations -- score normalized to 3
所用输入
bus_factor1
contributors_sampled1
top_contributor_share1
评分方式
40.9/42议题解决 — 97% 的议题已关闭
29.3/30PR 接受 — 已裁定的 PR 中 397/406 已合并
0/13Newcomer PR acceptance — 30 天内没有首次贡献者的 PR 得到裁决
0/15OpenSSF Scorecard:Code-Review — Found 0/30 approved changesets -- score normalized to 0
所用输入
merged_prs397
open_issues3
closed_issues110
prs_merged_7d
prs_decided_7d
prs_merged_30d
prs_decided_30d
issue_closed_ratio0.973
closed_unmerged_prs9
first_time_authors_30d
first_time_prs_merged_30d
first_time_prs_decided_30d
已排除计分(无数据或不适用):newcomer_pr_acceptance。 其余权重已重新归一化。
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
0/25所有者影响力 — logly 有 0 位关注者
18.6/25既往记录 — 7 个公开仓库,账户约 13 年
所用输入
followers0
owner_typeOrganization
is_verified
owner_loginlogly
public_repos7
account_age_days5,016
评分方式
25/25已发布且可解析 — pypi 上有 1 个软件包
35/35发布时效 — 最近一次发布于 0 天前
20/20版本历史 — 69 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesmureo
ecosystemspypi
any_deprecated
min_days_since_publish0

工程质量

基础的工程与文档实践是否到位?

77良好 · 占总体的 19%

工程实践

68良好
评分方式
24/24CI 工作流 — 4 个工作流
24/24存在测试
0/16Linter 配置
0/9.6Pre-commit 钩子
0/6.4.editorconfig
20/20OpenSSF Scorecard:CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

90优秀
评分方式
30/30README
25/25文档目录
15/15文档 / 主页站点 — https://mureo.io
10/10仓库描述
10/10主题标签 — 17 个主题标签
0/10Wiki
所用输入
topicsadvertising, ai-agents, cli, google-ads, marketing, mcp, model-context-protocol, python, agentic-ai, claude-code, codex, cursor, gemini-cli, marketing-automation, search-console, meta-ads, facebook-ads
has_wiki
homepagehttps://mureo.io
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

74良好 · 占总体的 16%

安全态势

74良好
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
2.5/2.5CI-Tests — 30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 26 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
1.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 3
5/5SAST — SAST tool is run on all commits
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — 无数据
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate7.4
已排除计分(无数据或不适用):signed_releases。 其余权重已重新归一化。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?权重刻意设小(4%):代理工具链是一项真实的维护信号,但完全不具备的仓库仍可达到 100/100。

54中等 · 占总体的 4%
评分方式
45/45代理指令 — AGENTS.md, CLAUDE.md
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 97 次人类提交中有 97 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share1
agent_instruction_filesAGENTS.md, CLAUDE.md
agent_instruction_max_bytes23,836
评分方式
0/18一条命令的引导启动
22/22自动化测试
0/11Lint / 格式化配置
0/11静态类型检查
10/10可复现环境 — Dockerfile
0/10已体现的代理实践 — 最近 100 次提交中没有代理编写的提交
8/8自动化维护 — 最近 100 次提交中有 3 次为自动依赖更新
3/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 3
所用输入
has_nix
has_tests
lockfiles
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0.03
评分方式
0/45可类型检查的代码 — Python,未配置类型检查
54.1/55可控的文件大小 — 采样的 595 个源文件中有 10 个超过 60KB
所用输入
primary_languagePython
largest_source_bytes138,910
source_files_sampled595
oversized_source_files10

机器可读接口

20存在风险
评分方式
0/40API 模式(OpenAPI/GraphQL/proto)
20/20MCP 服务器
0/40可运行示例
所用输入
example_dirs
has_mcp_signal
api_schema_files

关键数据

23GitHub 星标
1贡献者
498最近 12 个月提交数
0距最近推送天数
72发布版本数
1巴士系数(bus factor)
3开放议题
PyPI软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • deps.dev does not index pypi:mureo@0.10.38; advisories assessed against the repository dependency graph instead
  • No resolved dependencies carried a version and a supported ecosystem

更多细节

Star 与 Fork 历史 0 ★ / 3 ⇿
0Star
3Fork
4发布

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

12233312026-072026-072026-07
主版本 0次版本 0修订 4
OpenSSF Scorecard 7.4 / 10
7.4综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-08-01 13:11 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
10CI-Tests30 out of 30 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 26 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
3Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 3
10SASTSAST tool is run on all commits
10Security-Policysecurity policy file detected
不适用Signed-Releasesno releases found
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
10Vulnerabilities0 existing vulnerabilities detected
直接依赖 16
注册表软件包版本约束清单文件
PyPIgoogle-ads>=28.0,<30pyproject.toml
PyPIgoogle-auth>=2.28,<3pyproject.toml
PyPIgoogle-auth-oauthlib>=1.2,<2pyproject.toml
PyPIfacebook-business>=20.0,<22pyproject.toml
PyPIhttpx>=0.27,<1pyproject.toml
PyPIbeautifulsoup4>=4.12,<5pyproject.toml
PyPIlxml>=6.1,<7pyproject.toml
PyPIpydantic>=2.5,<3pyproject.toml
PyPItyper>=0.12,<1pyproject.toml
PyPIrich>=13.0,<14pyproject.toml
PyPIsimple-term-menu>=1.6,<2pyproject.toml
PyPImcp>=1.0,<2pyproject.toml
PyPIjsonschema>=4.20,<5pyproject.toml
PyPIopenpyxl>=3.1,<4pyproject.toml
PyPIpyyaml>=6.0,<7pyproject.toml
PyPIpackaging>=23.0,<26pyproject.toml
全部依赖 25

来自 GitHub 依赖图的完整解析依赖集合:16 个直接依赖与 9 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
PyPIbeautifulsoup4直接
PyPIfacebook-business直接
PyPIgoogle-ads直接
PyPIgoogle-auth直接
PyPIgoogle-auth-oauthlib直接
PyPIhttpx直接
PyPIjsonschema直接
PyPIlxml直接
PyPImcp直接
PyPIopenpyxl直接
PyPIpackaging直接
PyPIpydantic直接
PyPIpyyaml直接
PyPIrich直接
PyPIsimple-term-menu直接
PyPItyper直接
PyPIblack间接
PyPIjinja2间接
PyPImypy间接
PyPIplaywright间接
PyPIpytest间接
PyPIpytest-asyncio间接
PyPIpytest-cov间接
PyPIpytest-mock间接
PyPIruff间接
依赖安全公告 未评估

本报告未能完成公告比对:No resolved dependencies carried a version and a supported ecosystem

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [
        "advertising",
        "ai-agents",
        "cli",
        "google-ads",
        "marketing",
        "mcp",
        "model-context-protocol",
        "python",
        "agentic-ai",
        "claude-code",
        "codex",
        "cursor",
        "gemini-cli",
        "marketing-automation",
        "search-console",
        "meta-ads",
        "facebook-ads"
      ],
      "is_fork": false,
      "size_kb": 5725,
      "has_wiki": false,
      "homepage": "https://mureo.io",
      "languages": {
        "CSS": 46444,
        "HTML": 26823,
        "Jinja": 8967,
        "Shell": 10757,
        "Python": 7477049,
        "Dockerfile": 1998,
        "JavaScript": 270785
      },
      "pushed_at": "2026-08-01T13:05:52Z",
      "created_at": "2026-03-30T22:25:22Z",
      "owner_type": "Organization",
      "updated_at": "2026-08-01T13:05:57Z",
      "description": "Your local-first AI ad ops crew. Works with Claude Code, Cursor, Codex & Gemini.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Python",
      "significant_languages": [
        "Python"
      ]
    },
    "owner": {
      "blog": "https://corp.logly.co.jp/",
      "name": "LOGLY, Inc.",
      "type": "Organization",
      "login": "logly",
      "company": null,
      "location": "Japan",
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/2733811?v=4",
      "created_at": "2012-11-06T09:30:12Z",
      "is_verified": null,
      "public_repos": 7,
      "account_age_days": 5016
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.10.38",
          "kind": "patch",
          "published_at": "2026-08-01T13:05:52Z"
        },
        {
          "tag": "v0.10.37",
          "kind": "patch",
          "published_at": "2026-07-31T09:22:06Z"
        },
        {
          "tag": "v0.10.36",
          "kind": "patch",
          "published_at": "2026-07-31T02:47:29Z"
        },
        {
          "tag": "v0.10.35",
          "kind": "patch",
          "published_at": "2026-07-30T06:49:20Z"
        },
        {
          "tag": "v0.10.34",
          "kind": "patch",
          "published_at": "2026-07-30T02:15:41Z"
        },
        {
          "tag": "v0.10.33",
          "kind": "patch",
          "published_at": "2026-07-29T12:31:16Z"
        },
        {
          "tag": "v0.10.32",
          "kind": "patch",
          "published_at": "2026-07-29T05:00:24Z"
        },
        {
          "tag": "v0.10.31",
          "kind": "patch",
          "published_at": "2026-07-27T23:03:33Z"
        },
        {
          "tag": "v0.10.30",
          "kind": "patch",
          "published_at": "2026-07-27T07:30:57Z"
        },
        {
          "tag": "v0.10.29",
          "kind": "patch",
          "published_at": "2026-07-18T23:27:24Z"
        },
        {
          "tag": "v0.10.28",
          "kind": "patch",
          "published_at": "2026-07-18T01:25:25Z"
        },
        {
          "tag": "v0.10.27",
          "kind": "patch",
          "published_at": "2026-07-15T22:50:38Z"
        },
        {
          "tag": "v0.10.26",
          "kind": "patch",
          "published_at": "2026-07-15T01:30:25Z"
        },
        {
          "tag": "v0.10.25",
          "kind": "patch",
          "published_at": "2026-07-14T20:01:39Z"
        },
        {
          "tag": "v0.10.24",
          "kind": "patch",
          "published_at": "2026-07-14T06:29:21Z"
        },
        {
          "tag": "v0.10.23",
          "kind": "patch",
          "published_at": "2026-07-13T02:53:08Z"
        },
        {
          "tag": "v0.10.22",
          "kind": "patch",
          "published_at": "2026-07-12T09:24:56Z"
        },
        {
          "tag": "v0.10.21",
          "kind": "patch",
          "published_at": "2026-07-12T07:48:46Z"
        },
        {
          "tag": "v0.10.20",
          "kind": "patch",
          "published_at": "2026-07-11T23:51:01Z"
        },
        {
          "tag": "v0.10.19",
          "kind": "patch",
          "published_at": "2026-07-09T02:29:19Z"
        },
        {
          "tag": "v0.10.18",
          "kind": "patch",
          "published_at": "2026-07-07T02:56:16Z"
        },
        {
          "tag": "v0.10.17",
          "kind": "patch",
          "published_at": "2026-07-06T10:46:57Z"
        },
        {
          "tag": "v0.10.16",
          "kind": "patch",
          "published_at": "2026-07-03T05:44:56Z"
        },
        {
          "tag": "v0.10.14",
          "kind": "patch",
          "published_at": "2026-06-24T10:44:16Z"
        },
        {
          "tag": "v0.10.13",
          "kind": "patch",
          "published_at": "2026-06-24T09:01:17Z"
        },
        {
          "tag": "v0.10.12",
          "kind": "patch",
          "published_at": "2026-06-23T05:52:39Z"
        },
        {
          "tag": "v0.10.11",
          "kind": "patch",
          "published_at": "2026-06-22T13:21:40Z"
        },
        {
          "tag": "v0.10.10",
          "kind": "patch",
          "published_at": "2026-06-22T10:21:59Z"
        },
        {
          "tag": "v0.10.9",
          "kind": "patch",
          "published_at": "2026-06-20T21:30:34Z"
        },
        {
          "tag": "v0.10.8",
          "kind": "patch",
          "published_at": "2026-06-20T06:17:38Z"
        },
        {
          "tag": "v0.10.7",
          "kind": "patch",
          "published_at": "2026-06-17T23:28:54Z"
        },
        {
          "tag": "v0.10.6",
          "kind": "patch",
          "published_at": "2026-06-16T22:52:54Z"
        },
        {
          "tag": "v0.10.5",
          "kind": "patch",
          "published_at": "2026-06-16T00:59:18Z"
        },
        {
          "tag": "v0.10.4",
          "kind": "patch",
          "published_at": "2026-06-14T05:35:55Z"
        },
        {
          "tag": "v0.10.3",
          "kind": "patch",
          "published_at": "2026-06-14T05:00:00Z"
        },
        {
          "tag": "v0.10.2",
          "kind": "patch",
          "published_at": "2026-06-14T03:50:05Z"
        },
        {
          "tag": "v0.10.1",
          "kind": "patch",
          "published_at": "2026-06-14T01:18:00Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-06-13T23:42:16Z"
        },
        {
          "tag": "v0.9.33",
          "kind": "patch",
          "published_at": "2026-06-13T11:42:01Z"
        },
        {
          "tag": "v0.9.32",
          "kind": "patch",
          "published_at": "2026-06-12T23:42:10Z"
        },
        {
          "tag": "v0.9.31",
          "kind": "patch",
          "published_at": "2026-06-12T11:49:27Z"
        },
        {
          "tag": "v0.9.30",
          "kind": "patch",
          "published_at": "2026-06-12T04:42:32Z"
        },
        {
          "tag": "v0.9.29",
          "kind": "patch",
          "published_at": "2026-06-10T17:42:34Z"
        },
        {
          "tag": "v0.9.28",
          "kind": "patch",
          "published_at": "2026-06-10T08:01:47Z"
        },
        {
          "tag": "v0.9.27",
          "kind": "patch",
          "published_at": "2026-06-09T10:30:47Z"
        },
        {
          "tag": "v0.9.26",
          "kind": "patch",
          "published_at": "2026-06-09T03:39:26Z"
        },
        {
          "tag": "v0.9.25",
          "kind": "patch",
          "published_at": "2026-06-05T23:27:04Z"
        },
        {
          "tag": "v0.9.23",
          "kind": "patch",
          "published_at": "2026-05-31T11:08:55Z"
        },
        {
          "tag": "v0.9.21",
          "kind": "patch",
          "published_at": "2026-05-30T03:17:53Z"
        },
        {
          "tag": "v0.9.19",
          "kind": "patch",
          "published_at": "2026-05-29T23:45:43Z"
        },
        {
          "tag": "v0.9.17",
          "kind": "patch",
          "published_at": "2026-05-29T03:04:54Z"
        },
        {
          "tag": "v0.9.13",
          "kind": "patch",
          "published_at": "2026-05-27T08:05:00Z"
        },
        {
          "tag": "v0.9.12",
          "kind": "patch",
          "published_at": "2026-05-26T02:33:35Z"
        },
        {
          "tag": "v0.9.11",
          "kind": "patch",
          "published_at": "2026-05-26T01:35:24Z"
        },
        {
          "tag": "v0.9.10",
          "kind": "patch",
          "published_at": "2026-05-25T11:27:57Z"
        },
        {
          "tag": "v0.9.9",
          "kind": "patch",
          "published_at": "2026-05-23T08:23:11Z"
        },
        {
          "tag": "v0.9.8",
          "kind": "patch",
          "published_at": "2026-05-22T07:28:34Z"
        },
        {
          "tag": "v0.9.7",
          "kind": "patch",
          "published_at": "2026-05-22T06:09:41Z"
        },
        {
          "tag": "v0.9.6",
          "kind": "patch",
          "published_at": "2026-05-22T02:29:20Z"
        },
        {
          "tag": "v0.9.5",
          "kind": "patch",
          "published_at": "2026-05-21T10:58:54Z"
        },
        {
          "tag": "v0.9.4",
          "kind": "patch",
          "published_at": "2026-05-21T07:02:53Z"
        },
        {
          "tag": "v0.9.3",
          "kind": "patch",
          "published_at": "2026-05-19T05:31:34Z"
        },
        {
          "tag": "v0.9.2",
          "kind": "patch",
          "published_at": "2026-05-18T03:55:28Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2026-05-18T00:51:29Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-05-16T10:09:50Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-05-02T01:28:57Z"
        },
        {
          "tag": "v0.7.1",
          "kind": "patch",
          "published_at": "2026-04-29T09:15:36Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-04-20T12:06:32Z"
        },
        {
          "tag": "v0.3.2",
          "kind": "patch",
          "published_at": "2026-04-10T07:34:31Z"
        },
        {
          "tag": "v0.3.1",
          "kind": "patch",
          "published_at": "2026-04-10T05:56:05Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-04-09T04:50:36Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-03-31T07:24:45Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "fa9bcf2df1d5ce4786425cced4e8ed3ef6e34968",
          "body": null,
          "is_bot": false,
          "headline": "chore: release 0.10.38 (#519)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-08-01T13:05:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84cd24159873741def84c35d4be6a117dccb5a85",
          "body": "…gainst the real tool surface (#518)\n\nThe first live end-to-end Amazon setup produced a real 85-tool manifest,\nand checking the shipped behaviour against it exposed three defects that\nno amount of reasoning from documentation had caught.\n\nManifest location (closes #516)\n- The configure UI wrote the \n[…]\nacross all 85 tools, and\nwhite-box order and fail-closed assertions that fail against the\npre-fix code. Full suite 6940 passed with only the known\nenvironment-only failures; ruff / black / mypy clean.",
          "is_bot": false,
          "headline": "fix(amazon): correct the manifest location and the money guardrails a…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-08-01T12:55:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "21146a3b9145fff6bbe8f6f430166f8f3278e2aa",
          "body": "Document the SecretStore runtime-capability family in\ndocs/plugin-authoring.md (new section 15): the\nmureo.runtime_context_factory entry point, resolution and caching\nrules, and each store capability (credentials_write_path,\nmulti_account_auth, ui_plugin_credential_fields, the per-client\naccount allow-lists, amazon_token_saver) with their defensive-getattr\nsemantics, including the fail-closed behavior of the allow-lists on\nmulti-account backends. Adds a minimal example store and factory.",
          "is_bot": false,
          "headline": "docs: add multi-tenant backend authoring guide (#515)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-31T14:58:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a03084956766a6afc60c537ae42c1f665670efb",
          "body": "…ts (#514)\n\nCloses #511. AmazonAdsBridge's default token persistence can now be\nbound by the active runtime context: a secret store may declare an\n`amazon_token_saver: Callable[[str, str | None], None]` capability\n(access_token, refresh_token), resolved at persist time by the new\n`runtime_amazon_tok\n[…]\neives the refreshed tokens with the legacy writer\nuntouched, injected-saver precedence, failure-surface parity). Full\nsuite green except the known environment-only failures; ruff / black /\nmypy clean.",
          "is_bot": false,
          "headline": "feat(amazon): runtime-bindable token persistence for multi-tenant hos…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-31T10:51:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f3afb5224231c43828c50b4b6099ea5740809dae",
          "body": null,
          "is_bot": false,
          "headline": "chore: release 0.10.37 (#513)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-31T09:08:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5416d4c91069464806e566ebbd8c65109466fc96",
          "body": "…path (#512)\n\nIn a multi-tenant runtime context the credentials location is\nruntime-resolved, and every loader reads through the secret-store seam —\nbut three writers still resolved path=None to the legacy per-user file,\nso their writes landed where no reader looks (silent read/write\ndivergence; a r\n[…]\nrough the runtime store,\nno-override unchanged, explicit path wins), RED-verified against the\nold code. Full suite 6741 passed with only the known environment-only\nfailures; ruff / black / mypy clean.",
          "is_bot": false,
          "headline": "fix(auth): route all credential writers through the runtime-resolved …",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-31T08:54:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1abe137814d2c36f3263b1512e8ca3332e44c750",
          "body": "…e.atomic_json (#507)\n\n* refactor: extract atomic-JSON helpers into mureo.core.atomic_json\n\nmureo/providers/config_writer.py is documented and default-pathed for\nClaude Code MCP settings, but ten unrelated writers had come to depend\non its private atomic-write internals. Pure move, no behavior chang\n[…]\nmove to mureo.core.atomic_json; pin the\n  ConfigWriteError re-export identity.\n\nTests: 6614 passed with only the known environment-only failures;\nruff / black / mypy introduce no new findings vs HEAD.",
          "is_bot": false,
          "headline": "refactor: consolidate remaining atomic-JSON duplicates onto mureo.cor…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-31T04:22:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a84f9967fcb3972a53528a8f87b6867681bd9024",
          "body": null,
          "is_bot": false,
          "headline": "chore: release 0.10.36 (#509)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-31T02:47:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "275fd2becc8454897fdd9ec32dd7feb93e712ac4",
          "body": "…n expiry signal (#121) (#508)\n\nAmazon setup previously ended with \"obtain a refresh token yourself and\npaste it\". This adds the guided flow, built on the documented\ndirect-advertiser pattern (an allowed return URL like https://amazon.com\nplus manual code copy — no loopback callback, whose support L\n[…]\nmatrix, scrubber redaction and\nfalse-positive suites, asset/i18n contracts). Full suite 6728 passed\nwith only the known environment-only failures; ruff / black / mypy /\nnode --check clean.\n\nRefs #121.",
          "is_bot": false,
          "headline": "feat(amazon): guided paste-code authorization wizard and refresh-toke…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-31T01:05:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8273da3096e7ebb120c1000d2806d972498dc75c",
          "body": "…s) (#506)\n\nOpenAI and Codex providers advertised max_size [1536, 1536], but GPT\nImage cannot generate a 1536x1536 square — the real menu is 1024x1024 /\n1536x1024 / 1024x1536. No downstream code computed with max_size, so\nthis is an honesty fix:\n\n- capabilities() gains an optional supported_sizes ke\n[…]\nt max_size\nequals the per-axis maxima, clamp targets subset of the advertised\nmenu, providers_list passthrough). Full suite green except the known\nenvironment-only failures; ruff / black / mypy clean.",
          "is_bot": false,
          "headline": "fix(creative-studio): report honest size capabilities (supported_size…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-30T22:04:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "05f7db40290aa1590a2c804cc7f3029116530ab5",
          "body": "mureo/providers/config_writer.py is documented and default-pathed for\nClaude Code MCP settings, but ten unrelated writers had come to depend\non its private atomic-write internals. Pure move, no behavior change:\n\n- New mureo/core/atomic_json.py with the public trio\n  load_existing_json / atomic_write\n[…]\nng, failure leaves the original intact,\n  malformed raises) and pins the re-export identity.\n\nCloses #500.\n\nTests: 6613 passed with only the known environment-only failures;\nruff / black / mypy clean.",
          "is_bot": false,
          "headline": "refactor: extract atomic-JSON helpers into mureo.core.atomic_json (#505)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-30T21:55:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "277b34932321e946db98106ca6fdcf99093e7d68",
          "body": "…(#504)\n\nAmazon Ads shipped as a mureo-mediated official-MCP bridge, but the\ndocumentation still presented it as absent or \"Planned\". This sweep\nbrings every doc and skill surface in line with the code:\n\n- README(.ja): Amazon in every platform enumeration, a connection\n  section, and honest notes (m\n[…]\ntics/BYOD overclaims; en/ja parity; skills mirrors byte-identical.\nSkill contract suites pass.\n\nRefs #121. Depends on the safety-core branch (pattern fallback,\nMUREO_DISABLE_AMAZON_ADS) landing first.",
          "is_bot": false,
          "headline": "docs: present Amazon Ads as a first-class platform everywhere (#121) …",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-30T12:17:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "18644d8cdb14014e007dc8307994f846582305de",
          "body": "…I (#121) (#503)\n\nGives Amazon the same operator-facing surfaces Google/Meta have:\n\n- Setup wizard: amazon_ads is a selectable platform. Its credential\n  step is a new generic pluginProvider slot that fetches the\n  server-declared account_credential_fields at runtime and saves\n  through the existing\n[…]\nsts: +35 (handler security, env mapping, asset/i18n contracts, CLI).\nFull suite green except the known environment-only failures;\nruff / black / mypy clean; node --check on all touched JS.\n\nRefs #121.",
          "is_bot": false,
          "headline": "feat(ux): Amazon Ads operator parity in the wizard, dashboard, and CL…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-30T12:08:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8f281792dbf0ed0144522eb24fba7bbf2030009c",
          "body": "…azon core parity (#121) (#502)\n\nAmazon rides the plugin dispatch path with a manifest that cannot carry\nmureo _meta declarations, which left several safety surfaces silently\nuncovered. This closes the code-side gaps from the first-class parity\naudit:\n\n- Budget/bid guardrail pattern fallback: mutati\n[…]\nern fallback, staleness, rollback matching,\nbridge scrubbing, wiring, CLI, status, reports. Full suite 6567 passed\nwith only the known environment-only failures; ruff / black / mypy\nclean.\n\nRefs #121.",
          "is_bot": false,
          "headline": "feat(safety): budget/bid pattern fallback, manifest staleness, and Am…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-30T11:59:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4d5f8306f83a7cb15c424a12dd67d2aac069f41b",
          "body": "…en mint (#121) (#501)\n\nAmazon Ads previously required hand-editing the credentials file with a\nself-obtained short-lived access token. This closes the setup-UX gap\n(issue #121 item 3, phase A — the browser OAuth wizard is a later\nchange):\n\n- The Amazon bridge now declares account_credential_fields \n[…]\nadowing, secret non-leak through the UI\nlisting, loader/env matrix, proactive mint bounds, status row). Full\nsuite 6417 passed with only the known environment-only failures;\nruff / black / mypy clean.",
          "is_bot": false,
          "headline": "feat(amazon): configure-UI setup, env-var fallback, and first-use tok…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-30T10:25:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f9ee84f8d30315d1feb6cd0431443cfea49b5956",
          "body": "…(#113) (#499)\n\n* feat(amazon): Phase 1 — Amazon Ads via official MCP, mureo-mediated bridge (#113)\n\nmureo sits in the request path (Claude → local mureo → Amazon hosted\nMCP), like mureo-native Google/Meta: credentials in\n~/.mureo/credentials.json (Claude never sees them), and Amazon calls\ninherit t\n[…]\nurrency: 4 passed; full suite\ngreen except the known environment-only failures. black / ruff / mypy\nclean on the CI gates.\n\n* test(amazon): skip POSIX 0600 mode assertions on Windows (repo convention)",
          "is_bot": false,
          "headline": "feat(amazon): Amazon Ads via the official MCP, mureo-mediated bridge …",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-30T09:12:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4a22df56e38567adbcd7ce1bc8b07795acf94d11",
          "body": "* feat: Codex CLI image provider for Creative Studio (no API key)\n\nCreative Studio assumed a hosted-API key for every provider. Teams that\ngenerate images through the locally-installed Codex CLI (ChatGPT login,\nno API key) had no way to point Creative Studio at it. New built-in\nprovider \"codex\" clos\n[…]\negression test proves a metacharacter-laden prompt\n  (\" & % ^ |) arrives as one byte-identical argv element.\n\n34 tests in the provider file (169 -> 175 in creative_studio/);\nblack / ruff / mypy clean.",
          "is_bot": false,
          "headline": "feat: Codex CLI image provider for Creative Studio (no API key) (#497)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-30T08:51:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ed27dc273ffba2c8fc980a1fbf1b7631516496c6",
          "body": "Bump the version on all 55 surfaces and cut the 0.10.35 CHANGELOG\nsection.\n\nHighlights:\n- /daily-check is incremental by default: analytics-first gathering,\n  scoped action_log reads, diff-first reporting with the Action-needed\n  safety rule, deep mode on demand with a weekly recommendation, and\n  evaluation records that close pending observations (#495)",
          "is_bot": false,
          "headline": "chore: release 0.10.35 (#496)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-30T06:49:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "45855569ca103b81bd9847ceccc2629bde6513b1",
          "body": "Field feedback: /daily-check burned too much context (raw pulls from\nevery platform every run) and its report repeated unchanged items\ndaily. The previous run's summary was already persisted to\nreports.daily — this turns it into the diff anchor.\n\nTwo modes\n- Incremental (default): analytics-first da\n[…]\nat the fields carry behavioral weight.\n\nTests: 6270 passed with no new failures; legacy STATE.json entries\nload unchanged; default mureo_state_get output pinned byte-identical;\nmirrors byte-identical.",
          "is_bot": false,
          "headline": "feat: make /daily-check incremental by default (#495)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-30T04:50:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c36690da202c07ddef312afb57d156ca2a3eda39",
          "body": "Bump the version on all 55 surfaces and cut the 0.10.34 CHANGELOG\nsection.\n\nHighlights:\n- mureo --version and a version subcommand, with a drift guard pinning\n  __version__ to pyproject (#490, fixes #487)\n- Google SDKs no longer imported eagerly by the CLI: zero\n  FutureWarnings on py3.10 for every \n[…]\n3, fixes #486)\n- No-credentials quickstart smoke: shared script + CI workflow with a\n  weekly from-PyPI variant (#493, fixes #488)\n- README: TikTok Ads connector and configure-first quick start (#489)",
          "is_bot": false,
          "headline": "chore: release 0.10.34 (#494)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-30T02:15:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6e09bfb4ed4bf5ab2c42d405feb8df436df1e670",
          "body": "…ke (#493)\n\nEvery CLI command on Python 3.10 printed two google FutureWarnings at\nimport time, and nothing guarded the README's no-credentials\nquickstart against regressions.\n\nLazy Google SDK imports (#486) — root fix, no warnings filter\n- Two eager chains removed: mureo/auth.py imported the Google \n[…]\n-to-end (both pythons, including a claude-off-PATH run\n  exercising the hand-merge fallback).\n\nTests: 6240 passed with no new failures; black / ruff / mypy at the\nmain baseline.\n\nFixes #486\nFixes #488",
          "is_bot": false,
          "headline": "fix: stop the CLI importing Google SDKs eagerly, add a quickstart smo…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-30T01:56:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0774e37711573b1e397e862db04240baacf08acf",
          "body": "…#492)\n\n* docs: quick start now says to pick the demo scenario and skip OAuth\n\nThe quick start opened with \"no credentials, no OAuth\" but then sent\nthe reader into mureo configure, whose UI also shows a platform-\nconnection (OAuth) step — an apparent contradiction. Both READMEs now\nsay explicitly: c\n[…]\n Japanese-site note and the redundant free-to-use line\n\nmureo.jp is getting an English version, and open-source in the\nheadline plus the license badge already say what Apache 2.0 / free\nwas repeating.",
          "is_bot": false,
          "headline": "docs: quick start now says to pick the demo scenario and skip OAuth (…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-29T23:16:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ded46317635cad6d50fa96bebea610d13a74fdd1",
          "body": "… (#491)\n\nThe Japanese README read like machine translation in places. Applied\nthe house style guide across the whole file:\n\n- Removed every em dash: term-definition bullets now use a full-width\n  colon, inline dashes became punctuation\n- Removed interpunct-joined lists (A・B・C) in favor of commas or\n[…]\n-> 制御基盤, aligned the tagline\n  with the wording already used on mureo.jp\n- Rewrote image alt texts as full sentences\n\nStructure, headings used as anchors, links, tables, and code blocks\nare unchanged.",
          "is_bot": false,
          "headline": "docs: rewrite README.ja.md to follow the Japanese writing style guide…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-29T21:57:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f45e25887be125394598b93c1789bd1eb8a0ca4a",
          "body": "Checking the version is the first command a developer runs after\ninstalling, and what bug reports ask for — yet mureo --version errored\nwith \"No such option\".\n\n- Standard Typer eager --version option on the root app and a\n  `mureo version` subcommand alias, both printing `mureo <version>`\n  (one pla\n[…]\n1 new CliRunner tests (exit codes, exact patched output for\nboth surfaces, fallback path, bare-invocation regression, tagline).\nFull suite unchanged apart from the known env-only failures.\n\nFixes #487",
          "is_bot": false,
          "headline": "feat: add mureo --version and a version subcommand (#490)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-29T21:29:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a3a571b6f78000e54249cff52b5708e6afb8bb6a",
          "body": "* docs: mention TikTok Ads support in both READMEs\n\nTikTok Ads has shipped as the tiktok-ads-official provider (TikTok's\nofficial hosted MCP, added via mureo configure / mureo providers add,\nfirst-class tiktok_ads platform key in workflows and reports) but the\nREADMEs never mentioned it. Add it to t\n[…]\nAPI, and hosts sections led with raw commands.\nReorder so configure is the primary path everywhere it applies, with the\nterminal command kept as a one-line scriptable equivalent. English and\nJapanese.",
          "is_bot": false,
          "headline": "docs: mention TikTok Ads and lead setup with mureo configure (#489)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-29T14:29:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bf31ebe533917187dacfef5d41e1ec0fc9c42cac",
          "body": "…#485)\n\n* docs: restructure README around a single no-credentials quick start\n\nThe README had grown to 1,261 lines with setup instructions repeated in\nfour different forms and a 500-line tool table duplicating docs/mcp-server.md.\nA first-time visitor faced three mode/host decisions before seeing wha\n[…]\nhost table, and a reference section linking to the docs/ guides.\n708 -> 355 lines; reuses the existing Japanese translations for the\nretained sections (Features, Workflow Commands, samples, security).",
          "is_bot": false,
          "headline": "docs: restructure README around a single no-credentials quick start (…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-29T14:13:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c850a1bd794eac82153f7d2863e03b0a870b779b",
          "body": "Bump the version on all 55 surfaces and cut the 0.10.33 CHANGELOG\nsection.\n\nHighlights:\n- Advice gated on delivery state: /daily-check delivery-state guard,\n  platform-independent not-running exclusion in /ad-fatigue-check\n  (#482, fixes #479)\n- External-change diff hardened: campaign-status diff, c\n[…]\nred-vs-stored comparison, Status vocabulary contract, reported\n  skips (#482, fixes #480)\n- plugin:<dist> as the one canonical plugin platform key, single-sourced\n  and hijack-proof (#483, fixes #481)",
          "is_bot": false,
          "headline": "chore: release 0.10.33 (#484)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-29T12:31:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cdf40178193763ffa3aa9c39a1d285d6b3de3031",
          "body": "…(#483)\n\nA plugin platform's data could be written into STATE.json under one\nkey and read back under another: STATE.json, action_log, and the\ndashboard agreed on plugin:<dist>, while the analytics registry\nreported the entry-point name. The two identifiers never reconciled,\nso persisted state and an\n[…]\nately; no bridge code change needed.)\n\nTests: 6210 passed, no new failures; hijack, reserved-prefix, and\nduplicate-distribution cases pinned. black / ruff clean; mypy at the\nmain baseline.\n\nFixes #481",
          "is_bot": false,
          "headline": "fix: make plugin:<dist> the one canonical plugin platform key (#481) …",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-29T10:18:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5d44f5056b31ee68a75296ba48a0c7e7e2fed55f",
          "body": "…reliable (#482)\n\nSkills-and-tests-only follow-up to #468, closing #479 and #480.\n\nDelivery-state guard (#479)\n- /daily-check gains a Delivery-state guard next to the Learning-state\n  guard: an entity that was not delivering for part of the period is\n  Watch at most, never Action needed on efficienc\n[…]\n to report.\n\nTests: 10 new skill-contract tests (mutation-verified: all fail\nagainst the pre-fix wording). Full suite 6179 passed with no new\nfailures; mirrors byte-identical.\n\nCloses #479\nCloses #480",
          "is_bot": false,
          "headline": "fix: gate advice on delivery state and make the external-change diff …",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-29T09:28:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d02337299e1758e5543e07165e02016eee3f7084",
          "body": "Bump the version on all 55 surfaces and cut the 0.10.32 CHANGELOG\nsection.\n\nHighlights:\n- Two-tier /learn completed: workspace-tier insights are read by\n  mureo_learning_insights_get, new mureo learn tiers subcommand,\n  /learn scope selection (#475)\n- Ad-level delivery status in the standard flows: Meta status fields\n  actually requested, STATE.json AdState audit trail, /sync-state and\n  /daily-check ad-level diffs, BYOD freshness envelope, untrue\n  description claims removed (#477, fixes #468)",
          "is_bot": false,
          "headline": "chore: release 0.10.32 (#478)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-29T05:00:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "324ac37a92f18a2035e58731936fa6f717b17f38",
          "body": "Manual changes made in the platform UI were invisible to mureo: the\nstandard flows never fetched ad-level (creative-level) delivery state,\nso an ad paused by hand kept being treated as delivering — and advice\nbuilt on that state could mislead. Manual operation and mureo-driven\noperation coexist, esp\n[…]\n the 800-line guideline).\n\nTests: 6169 passed (+13 in the review round; 502 targeted), legacy\nbyte-identity pinned, JST frozen-clock coverage for as_of stamping.\nblack / ruff / mypy clean.\n\nFixes #468",
          "is_bot": false,
          "headline": "fix: surface ad-level delivery status in standard flows (#468) (#477)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-29T01:50:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d452f70d584af0475b58fb2ec4ea21f4c1290d20",
          "body": "The KnowledgeStore Protocol has had a workspace tier on the write side\n(mureo learn add --scope workspace) with no production reader, so\nworkspace-scoped insights were invisible to every diagnostic workflow.\nClose the loop on both sides:\n\n- mureo_learning_insights_get now reads BOTH tiers. When the \n[…]\ne per-call; both are\nnow pinned by dedicated tests. Tool schema unchanged (still zero\narguments).\n\nTests: 38 targeted (+15 new), full suite 6108 passed with no new\nfailures. ruff / black / mypy clean.",
          "is_bot": false,
          "headline": "feat: complete the two-tier /learn loop with workspace-tier reads (#475)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-28T04:20:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f18f42bfc83f30d0fb0815ceabb2ce02552fd358",
          "body": "Bump 0.10.30 -> 0.10.31 (pyproject, __init__, plugin.json,\ngemini-extension.json, 51 SKILL.md frontmatters) and cut the CHANGELOG for the\nallocation and learning-state diagnostic discipline (#465), end-to-end Meta\nvideo creatives (#467), the server-clock injection that stops daily checks\nrunning on \n[…]\nin extraction with streaming video upload (#472) changes merged since\n0.10.30.\n\nNo entry text was changed: the [Unreleased] body moved verbatim into\n[0.10.31], leaving the empty [Unreleased] skeleton.",
          "is_bot": false,
          "headline": "chore(release): 0.10.31 (#474)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-27T23:03:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d42e9ddfabd5e127afb459b331df2b36d3803a6f",
          "body": "Splits the /advideos machinery out of _creatives.py (939 -> 789 lines;\nnew _videos.py 208, mixin count 16 -> 17 in docs) with zero\ncross-imports. Behavioral part: upload_ad_video_file no longer\nmaterializes up to 1 GB in memory — the open file handle streams\nthrough the shared request machinery, and\n[…]\n attempt so retries resend identical bytes; an unseekable\npart now fails loud with RuntimeError instead of risking a silently\ntruncated retry body. Wire shape, timeout and size-cap behavior\nunchanged.",
          "is_bot": false,
          "headline": "refactor(meta): extract VideosMixin and stream video uploads (#472)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-27T22:10:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2030f3e0a61237bc9bcbd423435d4f0c3091e63c",
          "body": "…Slot (#473)\n\nThe host check is done inline where needed (state.host comparisons in\nauth_wizards_meta.js and the codex branches); this binding was never read.",
          "is_bot": false,
          "headline": "refactor: remove unused onDesktop declaration in buildProviderInstall…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-27T21:42:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "abb26d6aac7229d8ce1bac93c8f9ff2425af334c",
          "body": "auth_wizards.js exceeded the 800-line budget (1248). The Meta-specific\nregions (hosted-connector setup card, connection-method chooser,\nsystem-user token card) move verbatim to auth_wizards_meta.js (539\nlines; main file now 734), published via the established\nwindow.MUREO_AUTH_META namespace pattern\n[…]\nsure and now takes (wrap, state, providerId), plus the call sites.\nStatic allowlist gains the new filename; wheel packaging verified.\nAsset tests read the concatenated pair; no assertion text changed.",
          "is_bot": false,
          "headline": "refactor(web): split the Meta auth step into auth_wizards_meta.js (#471)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-27T21:25:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2d0f5b3335a0b0d010af4360cab39bb65c0dfe33",
          "body": "…itive skills (#470)\n\nCompletes the #460 follow-up: the step-0 \"establish the current date\nfrom server_now\" discipline added to daily-check, sync-state and\nbudget-pacing in #469 now covers every skill that computes a date\nwindow or writes observation_due — weekly-report, monthly-report,\ngoal-review,\n[…]\n the two remaining creative-studio manifest created_at\nsites onto mureo.core.clock (display-only field; verified no consumer\nparses it), with a guard test asserting the module carries no second\nclock.",
          "is_bot": false,
          "headline": "fix(skills): roll the server_now date discipline across all date-sens…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-27T21:17:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9ba62322bb53ab0495ba255d8cc6c4f8e906c695",
          "body": "… stale date (#469)\n\nAgents running /daily-check could adopt a days-old notion of \"today\"\nfrom the dates already sitting in STATE.json (reports.*.period,\nlast_synced_at, action_log timestamps) and short-circuit with a\nre-display of an old report instead of fetching fresh data. Nothing in\nmureo injec\n[…]\nls\n- Two observation-window tests that compared against the real UTC\n  wall clock are frozen onto the injected clock (they failed\n  deterministically on positive-offset hosts during local small hours)",
          "is_bot": false,
          "headline": "fix(context): inject the server clock so daily checks cannot run on a…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-27T20:08:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6e1facb49b8beaba1ec96168646a6878a42ba9ee",
          "body": "Bumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb9\n[…]\ny: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Hirokazu Yoshinaga <4027404+hyoshi@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#466)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-27T12:07:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6e2484a44dd975c35f3ae9780824b48935151fe5",
          "body": "Video was half-built: uploads existed but only Lead Ads could build a\nvideo creative, videos could not be status-polled or thumbnailed, and\nthe local-file upload path predated the shared client machinery. A\nfield report confirmed video creative submission was impossible for\nstandard objectives.\n\n- c\n[…]\np-by-step video\n  creative flow (upload -> poll -> thumbnail -> creative -> ad), and\n  the tool-summary table completed to all 88 tools (five pre-existing\n  tools were missing from the numbered table)",
          "is_bot": false,
          "headline": "feat(meta): end-to-end video creative support (#467)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-27T11:39:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a96ae7d243c36407876090605cafabcc88da7349",
          "body": "Add three cross-platform principles to the pro-diagnosis framework\ncatalogue, grounded in documented Meta and Google Ads delivery\nmechanics:\n\n- Judge by marginal efficiency, not averages: automated delivery\n  spends the cheapest inventory first, so average-CPA rankings misfire\n  in both directions; \n[…]\nll's routing description; the audience-review worked\nexample is updated to match the new discipline. Mirrors kept\nbyte-identical; pro-diagnosis stays canonical-only per the /learn\nwrite-path contract.",
          "is_bot": false,
          "headline": "docs(skills): allocation and learning-state diagnostic discipline (#465)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-27T08:26:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8faa542fca427145144ae3d9716f138c9b4b3c0e",
          "body": "Bump 0.10.29 -> 0.10.30 (pyproject, __init__, plugin.json,\ngemini-extension.json, 51 SKILL.md frontmatters) and cut the CHANGELOG for the\nMeta pixels_create (#451), bidding controls and pages_list (#452), targeting\ndiscovery (#453), strict input schemas (#454), bid-cap guardrails (#455),\nplugin bid \n[…]\nder Added (a later PR's section header orphaned it into Changed), and\nthe adimages fix (#463), which was written into the already-released [0.10.29]\nsection, into [0.10.30]. No entry text was changed.",
          "is_bot": false,
          "headline": "chore(release): 0.10.30 (#464)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-27T07:30:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "21a9ffc8cafd7d667c4400816e6eabf38ad38a9c",
          "body": "…(#463)\n\nmeta_ads_images_upload_file returned 400 for every file. Even a\nprovably well-formed multipart request (correct boundary, image/* part\nContent-Type, raw binary) was rejected by Graph /adimages with\nFileTypeNotSupported (subcode 1487411), so the multipart approach was\nabandoned in favor of t\n[…]\ness_token form\n  field)\n- Tests pin the bytes wire shape, Bearer-only auth, 60s timeout,\n  identical body on retry, non-ASCII path handling, and the Meta error\n  round-trip with the real-world subcode",
          "is_bot": false,
          "headline": "fix(meta): switch adimages file upload to the base64 bytes form body …",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-27T07:13:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "73b0dca776f3351f4eb1801150025071fe1f916c",
          "body": "…(#462)\n\nField feedback: the Meta auth step showed the prominent Login with\nFacebook button with the token card collapsed below, so operators who\nmust use a system-user token (Live apps, where OAuth can never\ncomplete) clicked OAuth anyway. The two paths are mutually exclusive\nalternatives and the U\n[…]\n keys are unchanged (stable contract\n  for downstream extensions); the OAuth timeout hint wording follows\n  the new layout\n- Card construction decomposed into helpers within the function-size\n  budget",
          "is_bot": false,
          "headline": "feat(web): present Meta auth as an explicit either/or method chooser …",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-27T07:01:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1280ece096e769bc9c4236fc5496ee00131be9c9",
          "body": "…optional (#461)\n\nAfter Validate, the account select was populated with probed accounts\nonly — no placeholder — so the browser silently pre-selected the first\naccount and Save persisted it even if the operator never opened the\ndropdown. The picker now defaults to a \"Select an ad account (optional)\"\n\n[…]\n so tokens that reach\nzero ad accounts failed Save with a spurious 400 account_not_accessible.\n\nTests: placeholder/default pinning, absent/null/blank account_id save\npaths, prior-selection carry-over.",
          "is_bot": false,
          "headline": "fix(web): make the Meta token card's ad-account selection explicitly …",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-27T05:46:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b1967e76d55b1c267a7037af3b011a3b8b5332aa",
          "body": "…I (#459)\n\nLive-mode Meta apps cannot complete OAuth from the localhost configure\nUI (Facebook rejects the localhost redirect on Facebook's own page, so\nthe callback never fires), while dev-mode apps cannot create ad\ncreatives (Marketing API subcode 1885183) — a dead end either way.\nThe escape is a \n[…]\nirement,\n  BM guide, configure-UI path)\n\nSecurity review: no CRITICAL/HIGH; token never echoed in any response,\nnever logged, redacted from error strings; multipart/DOM insertion via\ntextContent only.",
          "is_bot": false,
          "headline": "feat(web): first-class Meta system-user token path in the configure U…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-24T20:05:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "34c0a8bf651212c0b2424414ad0e581f065f04a6",
          "body": "…larations.py (#457)\n\nPure move, zero behavior change: BudgetDeclaration, BidDeclaration,\ntheir registries and register/lookup/reset helpers, and the shared\ndeclared-key readers (_Unreadable, _saturate, _declared_amount) move to\na new sibling module, bringing strategy_gate.py from 877 back under the\n[…]\nry dicts stay identical objects across both module paths.\nInternal callers (plugin_semantics, server registration) repoint at the\ncanonical module. Existing gate and declaration test files unmodified.",
          "is_bot": false,
          "headline": "refactor(policy): extract declaration machinery into mureo/policy/dec…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-23T10:55:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bea7b4c0e1b3a8041bc1911954feb97f27b1a22d",
          "body": "…ardrails (#456)\n\nThe bid-cap guardrails (#455) scan only the builtin keys (bid_amount,\ncpc_bid_micros), so a plugin bid tool using different argument\nvocabulary was silently unenforced — the same gap BudgetDeclaration\n(#414) closed for budgets.\n\n- BidDeclaration(bid_amount_key, cpc_bid_key, micros)\n[…]\ns a bid-declaration subsection\n\nNote: strategy_gate.py now exceeds the 800-line budget; extracting the\ndeclaration machinery (budget + bid) into a sibling module is planned\nas a follow-up refactor PR.",
          "is_bot": false,
          "headline": "feat(policy): plugin bid declarations so custom bid keys reach the gu…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-23T10:18:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "df8053a6118c5f585b5b1cede31b18dd7148bd74",
          "body": "…id_micros (#455)\n\nThe bidding controls added in #452 exposed bid_amount (Meta ad sets)\nand the pre-existing cpc_bid_micros (Google ad groups) with no\nSTRATEGY.md guardrail — an agent could set an arbitrarily high bid cap\nwithout any policy check, unlike budgets.\n\n- New optional Guardrails fields: m\n[…]\n2\n  wire-reachability tests (json.loads-constructed args) across all four\n  capped channels\n- STRATEGY.md skill docs updated with currency-annotated examples\n  demonstrating the minor-units convention",
          "is_bot": false,
          "headline": "feat(policy): bid-cap guardrails for Meta bid_amount and Google cpc_b…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-23T09:35:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "16b91400ad49889c1403e61f7fa2cd330d83e49e",
          "body": "…hemas (#454)\n\nUnknown parameters used to pass schema validation and be silently\ndiscarded by handler whitelists — a field-reported footgun where a\ncaller's misspelled or unsupported argument produced no error and no\neffect. Every builtin tool schema (203 across 9 registries; 197 fixed\nhere, 6 alrea\n[…]\nink_text, RSA campaign_id, landing-page\n  url, creatives image_url, and the create_dynamic required set;\n  mirrored into mureo/_data/skills/\n- CHANGELOG: breaking for callers relying on typo-tolerance",
          "is_bot": false,
          "headline": "feat(mcp): enforce additionalProperties: false on all builtin tool sc…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-23T08:55:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "65a23e4add7260c21c857e3cb5f60644c5f6850d",
          "body": "…talogues (#453)\n\nAgents could not resolve Meta's internal targeting IDs (interests,\nbehaviors such as \"Facebook Page admins\") needed to build ad-set\ntargeting specs. Adds two read-only tools backed by the Graph API\nroot /search endpoint via a new TargetingMixin:\n\n- meta_ads_targeting_search: keywor\n[…]\n and limit; inputs validated at the\n  boundary (empty query / unknown class fail fast); schemas declare\n  additionalProperties: false\n- Tool counts 201 -> 203 (Meta Ads 84 -> 86) across tests and docs",
          "is_bot": false,
          "headline": "feat(mcp): Meta targeting discovery — interest search and category ca…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-23T07:12:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "41d67db8f2893c6d011e5a86054680e77e7686c6",
          "body": "…oted_object, pages_list (#452)\n\nAnswers a field report where automated bidding could not be configured\nand non-CBO (ad-set-level budget) campaigns could not be created.\n\n- bid_strategy (LOWEST_COST_WITHOUT_CAP / LOWEST_COST_WITH_BID_CAP /\n  COST_CAP / LOWEST_COST_WITH_MIN_ROAS) on campaigns create/\n[…]\n silently\n  dropped\n- Read side: campaigns list/get return is_adset_budget_sharing_enabled;\n  ad_sets list/get return promoted_object\n- Tool counts 200 -> 201 (Meta Ads 83 -> 84) across tests and docs",
          "is_bot": false,
          "headline": "feat(mcp): Meta bidding controls — bid_strategy, ad-set budgets, prom…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-23T06:02:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ec3c0fbc9dbb2269eb9ed73547ee1bf30f85eeaa",
          "body": "…451)\n\nAdd a mutating MCP tool that creates a Meta Pixel on an ad account via\nGraph API POST /act_{ad_account_id}/adspixels.\n\n- PixelsMixin gains create_ad_pixel(name) with non-empty-name validation\n  (the mixin is no longer read-only; _post stub added)\n- New handler handle_pixels_create following t\n[…]\n: client path/body assertions, empty-name rejection, handler\n  success / missing-name / missing-credentials / API-error round-trip\n- Tool counts bumped 199 -> 200 (Meta Ads 82 -> 83) in tests and docs",
          "is_bot": false,
          "headline": "feat(mcp): add meta_ads_pixels_create tool for Meta Pixel creation (#…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-23T01:51:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "527bf0308c32d4493959fb4dba5ef0e10cf8a23b",
          "body": "Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6.3.0 to 7.0.0.\n- [Release notes](https://github.com/actions/setup-python/releases)\n- [Commits](https://github.com/actions/setup-python/compare/ece7cb06caefa5fff74198d8649806c4678c61a1...5fda3b95a4ea91299a34e894583c3862153e4b\n[…]\ny: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>\nCo-authored-by: Hirokazu Yoshinaga <4027404+hyoshi@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump actions/setup-python from 6.3.0 to 7.0.0 (#450)",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-21T22:05:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "35c916d5b530c0a07d64a036b11dbe53638e315b",
          "body": "…#449)\n\nBumps [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish) from 1.14.0 to 1.14.1.\n- [Release notes](https://github.com/pypa/gh-action-pypi-publish/releases)\n- [Commits](https://github.com/pypa/gh-action-pypi-publish/compare/cef221092ed1bacb1cc03d23a2d87d1d172e277b...\n[…]\nirect:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] <support@github.com>\nCo-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>",
          "is_bot": true,
          "headline": "chore(deps): bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1 (…",
          "author_name": "dependabot[bot]",
          "author_login": "dependabot[bot]",
          "committed_at": "2026-07-21T06:29:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8e15a3431834714c4a0556e4033786e14b1d5339",
          "body": "Bump 0.10.28 -> 0.10.29 (pyproject, __init__, plugin.json,\ngemini-extension.json, 51 SKILL.md frontmatters) and cut the CHANGELOG for the\nSearch Console site_url schema fix (#447/H1) and the full documentation refresh\n(#446) merged since 0.10.28.\n\nClaude-Session: https://claude.ai/code/session_01X3WKmku93ucAR8DsatzLpG",
          "is_bot": false,
          "headline": "chore(release): 0.10.29 (#448)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-18T23:23:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5678dd8002dabb5014090a72f9ad916e94baff55",
          "body": "…e works (H1) (#447)\n\nEvery Search Console tool declared `site_url` in its inputSchema `required`, so\n`server.handle_call_tool` rejected an omitted `site_url` at `_validate_tool_input`\nbefore the handler ran — making `_resolve_site_url`'s single-property\nauto-resolution (for a tenant-scoped multi-ac\n[…]\na that was the actual bug), updates the\n`test_required_fields` expectations, and syncs the docs/mcp-server.md required\ncolumns.\n\nClaude-Session: https://claude.ai/code/session_01X3WKmku93ucAR8DsatzLpG",
          "is_bot": false,
          "headline": "fix(mcp): make Search Console site_url optional so tenant auto-resolv…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-18T23:10:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b162065b1eebee5266d72ca6b65cb8e423d99776",
          "body": "…tool counts) (#446)\n\nBring the documentation back in line with the code after 0.10.28. Audited every\ndoc against the codebase; the notable drift fixed:\n\n- README / mcp-server / architecture: tool inventory corrected to 199 (Google\n  Ads 86, Meta 82, SC 10, Rollback 2, Analysis 1, mureo-context 9, a\n[…]\n-web`), native\n  tool counts, Codex parity, bundled foundation-skill count, skills paths.\n\nDocs only — no code or test changes.\n\nClaude-Session: https://claude.ai/code/session_01X3WKmku93ucAR8DsatzLpG",
          "is_bot": false,
          "headline": "docs: refresh docs for 0.10.28 (native skills, analytics dispatcher, …",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-18T22:28:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "25b1a487807b6fafcfa074220cb684f6f5ca8bea",
          "body": "Bump 0.10.27 -> 0.10.28 (pyproject, __init__, plugin.json,\ngemini-extension.json, 51 SKILL.md frontmatters) and cut the CHANGELOG for the\nplugin native-skills (#439), analytics dispatcher (#440), onboard guardrails\n(#364), GA4 multi-account gate (#442), analytics account_id scoping\n(#413/#435), atomic host snapshot (#407), and full-codebase security review\n(#441) changes merged since 0.10.27.\n\nClaude-Session: https://claude.ai/code/session_01X3WKmku93ucAR8DsatzLpG",
          "is_bot": false,
          "headline": "chore(release): 0.10.28 (#445)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-18T01:24:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "13750078e69258d5df34881a3700ceec9e899968",
          "body": "Address findings from a full-codebase review, spanning CRITICAL–LOW severity.\n\nSecurity\n- google_ads: validate ad_group_id in update_ad_group before it reaches the\n  GAQL pre-check and resource path (C1); validate campaign/geo/criterion IDs\n  in location & schedule targeting updates (H4); restrict t\n[…]\n safe fix needs a dedicated design (the\nattempted lock-across-await fix could deadlock the concurrently-dispatched\nMCP server).\n\nClaude-Session: https://claude.ai/code/session_01X3WKmku93ucAR8DsatzLpG",
          "is_bot": false,
          "headline": "fix: security and correctness fixes from full-codebase review (#441)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-18T01:12:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a1cedb6dc541713c1d0b7e9e590131742bca4e59",
          "body": "…#444)\n\n* fix(#442): gate GA4 credential wizard under a multi-account backend\n\nGA4 auth is a single service account. Under a multi-account backend (a\nSecretStore declaring credentials_write_path), the Setup-tab GA4 wizard\nwrote that one SA into the shared credentials.json `ga4` section, so it\nreache\n[…]\ntAuth.\n\nThe server-side 403 (_post_env_var) is unchanged and remains the\nauthoritative boundary. Adds static-asset guard tests.\n\nClaude-Session: https://claude.ai/code/session_01X3WKmku93ucAR8DsatzLpG",
          "is_bot": false,
          "headline": "fix(#442): gate GA4 credential wizard under a multi-account backend (…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-18T00:53:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a42c7b41ea2d39e7a94672e90f2e8b7392f92962",
          "body": "… (#443)\n\n* feat: plugin native slash skills (#439) + analytics dispatcher (#440)\n\nTwo plugin-extension surfaces requested by the mureo-logly-bridge plugin.\n\n#439 — Deploy plugin native slash skills\n- New entry-point group `mureo.native_skills` (constant in\n  core/providers/registry.py): a plugin re\n[…]\ner-module TOOLS lists. This CI failure was masked locally because the dev\nenv's agency plugin inflates the count independently.\n\nClaude-Session: https://claude.ai/code/session_01X3WKmku93ucAR8DsatzLpG",
          "is_bot": false,
          "headline": "feat: plugin native slash skills (#439) + analytics dispatcher (#440)…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-18T00:04:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f8f855536006500560f2ec3e7d1d66b2ddcbc495",
          "body": "…64) (#438)\n\nv0.10.18's hard budget-guardrail enforcement (StrategyPolicyGate) is fail-open\nand had no onboarding prompt, so it stayed dormant for operators who didn't know\nto ask. onboard now offers to seed the machine-readable ## Guardrails keys from\nthe operator's inputs, confirms every number, writes the section, and is\nskippable — with an honest note that hard enforcement covers only mureo-\ndispatched native google_ads/meta_ads (hosted/official MCPs bypass; #359).",
          "is_bot": false,
          "headline": "feat(onboard): proactively offer to set STRATEGY.md ## Guardrails (#3…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-16T01:37:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a54b204c0baa494129f92675854f5ad5d6eb4fe1",
          "body": "…path (#435) (#437)\n\nFollow-up to #435. _open_meta_ads_client resolved account_id via the #411\nresolver, but the non-tenant-scoped path returned it verbatim — a bare\n(non-act_) id then raised a raw ValueError from MetaAdsApiClient, escaping the\nadapters' graceful except-NoCredentialsError handler. Apply the idempotent\n_canonical_meta_account_id after resolution so both paths pass (and thread\ndownstream) the act_-prefixed id.",
          "is_bot": false,
          "headline": "fix(analytics): canonicalize Meta account_id to act_ on the unscoped …",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-16T01:13:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "742fb69fad7b897401edf61791c184fc6afc718f",
          "body": "…#435) (#436)\n\nFollow-up to #413. (1) A workspace-scope refusal from the #411 resolver now\nraises AccountNotAvailableError (a NoCredentialsError subclass), so the\nAnalyticsModule adapters' existing `except NoCredentialsError` renders the\ngraceful empty sentinel instead of letting a raw ValueError es\n[…]\n (client,\nresolved_id) and all 8 fetch call sites rebind account_id, so aggregation /\nlabeling / conversion-override lookup use the same (canonicalized) id the\nclient was opened with — no format skew.",
          "is_bot": false,
          "headline": "fix(analytics): graceful scope refusal + thread resolved account_id (…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-16T00:49:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d00860d7e80d247d972a3202487febfb9a7f48d2",
          "body": "…ist (#413) (#434)\n\nThe built-in analytics live-client helpers passed the caller account_id\nverbatim to the client factory, bypassing the workspace allow-list the MCP\nhandlers enforce. Route _open_google_ads_client / _open_meta_ads_client through\n_resolve_customer_id / _resolve_account_id: non-tenant-scoped passes through;\ntenant-scoped refuses an out-of-set id (fail-closed), so a future tool wiring a\ncaller-supplied id into the AnalyticsModule Protocol can't silently escape #411\nscoping.",
          "is_bot": false,
          "headline": "fix(analytics): scope live-client account_id through the #411 allow-l…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-16T00:02:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "98e6dbd34082120007b52e75421df576f440a611",
          "body": "Reading session.host and host_paths as two separate accesses let a\nconcurrent set_host pair one host with another host's bundle. Publish both\nunder a dedicated _host_lock and add wizard.host_snapshot(); the two handlers\nthat read the pair (_serve_status, _post_providers_install) now take one\nsnapshot. set_host builds the new bundle outside the lock (keeps the #406\nguarantee) and early-returns on a non-allow-listed host.",
          "is_bot": false,
          "headline": "fix(web): capture host + host_paths as one atomic snapshot (#407) (#433)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-15T23:31:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b070af5dd46a244cce0027677e8521565fd05663",
          "body": "Bump 0.10.26 -> 0.10.27 (pyproject, __init__, plugin.json, 51 SKILL.md\nfrontmatters) and cut the CHANGELOG for the report-flag changes merged since\n0.10.26 (#428 / #429 / #430 / #431).\n\nAdded — structured, localizable report-flag chips on the Reports dashboard:\nflags persisted via mureo_state_report\n[…]\nview skills author flags in this shape.\n\nChanged — mureo_state_report_set validates report flags (unknown non-custom\ncodes rejected, severities defaulted); legacy bare-string flags still pass through.",
          "is_bot": false,
          "headline": "chore(release): 0.10.27 (#432)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-15T22:50:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8d11ce91b3d858ac11a60d7f23fafd6e8c1daa49",
          "body": "…l-review (#431)\n\nBring the weekly-report and goal-review skills onto the canonical\n{code, severity, params} flag vocabulary (both copies each, byte-identical),\nmatching daily-check. Keeps detail in params, not baked into the code;\ndocuments the custom escape hatch. Completes the report-flag migration.",
          "is_bot": false,
          "headline": "feat(skills): author structured report flags in weekly-report and goa…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-15T09:26:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9312e7d027fe763e80457734dd7afc359c7b206e",
          "body": "… (#430)\n\nUpdate the daily-check skill (both copies) to persist report flags as\nstructured {code, severity, params} objects drawn from the canonical\nvocabulary, keeping detail in params (not baked into the code) so the\ndashboard renders coarse, localizable chips with a drill-down. Documents\nthe custom escape hatch and severity buckets; legacy string flags still work.",
          "is_bot": false,
          "headline": "feat(daily-check): author structured report flags from the vocabulary…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-15T08:32:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a96ae8ba214c433e8feeb5a9e1507a1bc942671",
          "body": "…(#429)\n\nLocalize report-flag chips by canonical code (dashboard.reports_flag_<code>)\nin both en and ja, colour them by the four severity buckets (adds a neutral\nis-info), and move per-flag detail (adspot ids, yen, ctr) off the chip face\ninto a click-to-expand drill-down built from the flag's params. Custom flags\nuse their author-supplied label; legacy bare-string flags still humanize.",
          "is_bot": false,
          "headline": "feat(web): render structured report flags as coarse, localized chips …",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-15T08:25:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "24906d4d6711e312b6bb9625d04602c97ac85772",
          "body": "…ation (#428)\n\nAdd a fixed vocabulary of report-flag codes each mapped to a severity\nbucket (action/watch/info/positive), and validate/normalize a report's\n`flags` in mureo_state_report_set. Structured flags {code, severity,\nparams} keep detail in params (not the code) so the dashboard can show a\ncoarse, localizable chip; a `custom` code carries an author label for\nnovel findings. Legacy bare-string flags pass through unchanged.",
          "is_bot": false,
          "headline": "feat(context): canonical report-flag vocabulary with severity + valid…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-15T07:55:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c8ad3d607f6c548f865a28f0f28b2b7e9cab7486",
          "body": "Bump 0.10.25 -> 0.10.26 (pyproject, __init__, plugin.json, 51 SKILL.md\nfrontmatters) and cut the CHANGELOG for the two changes merged since 0.10.25.\n\nAdded — extensions can contribute a DashboardCard to the Reports tab (#425):\n\"reports\" joins \"advanced\" in BUILTIN_CARD_GROUPS so an extension can pla\n[…]\nhboard\ninstall read ✓ while absent. Each part is now detected on every status read;\nthe flag file is no longer written or read.\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
          "is_bot": false,
          "headline": "chore(release): 0.10.26 (#427)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-15T01:29:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "90c591752773753c3ec8f1d38c5b3177017e7a2a",
          "body": "BUILTIN_CARD_GROUPS accepted only \"advanced\", where operator *settings*\nlive. An extension that wants to offer a reporting action — \"refresh\nevery client's numbers now\", a cross-client daily-check — had no home for\nit beside the built-in report cards; Advanced is the wrong fit and a whole\nseparate t\n[…]\nensions.js CARD_GROUPS and asserts it\nequals BUILTIN_CARD_GROUPS exactly (one-sided drift fails red). Docs +\nCHANGELOG updated.\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
          "is_bot": false,
          "headline": "feat(web): allow a \"reports\" DashboardCard group (#425) (#426)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-15T00:52:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8fc2b4cc114aad23abae65c582921afdaae20d36",
          "body": "…ling a flag (#424)\n\nEvery row on the status snapshot is read off the filesystem — except the three\nbasic-setup rows, which came from `setup_state.json`, a record only the\ndashboard's own actions ever wrote. So the record drifted from reality the\nmoment anything else touched the filesystem:\n\n- Skill\n[…]\ninstallers through the\ndetectors rather than hand-written fixtures, so the writer and the reader cannot\ndrift apart in silence.\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
          "is_bot": false,
          "headline": "fix(configure): detect the basic-setup parts on disk instead of recal…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-14T22:46:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9ef734318058a9aebacb4052506314a907fb6e1f",
          "body": "Bump 0.10.24 -> 0.10.25 (pyproject, __init__, plugin.json, 51 SKILL.md\nfrontmatters) and cut the CHANGELOG for the two changes merged since 0.10.24.\n\nFixed — a budget declaration no longer switches off max_daily_budget_increase_pct\nor max_total_daily_budget (#418). The declaration seam (#414) replac\n[…]\nich is untrue for those shapes; it now shows the\nnormalize-and-delegate gate to register instead, and the rules it must follow.\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
          "is_bot": false,
          "headline": "chore(release): 0.10.25 (#422)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-14T12:25:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "435ec8da21245b69ec0f5f651bad5bb52574aea7",
          "body": "…dget (#417) (#421)\n\nA declaration (#414) names a TOP-LEVEL argument key. Two ordinary plugin shapes\nare outside what that can express, as #417 reports from adopting the seam:\n\n- The budget is NESTED. A native passthrough tool takes the platform's raw\n  request body, so the budget is at `body.daily_\n[…]\n75) is the right extension\npoint for these shapes, and mureo's decision layer stays the single owner of\nwhat a guardrail means.\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
          "is_bot": false,
          "headline": "docs: what to do when a budget declaration cannot reach a plugin's bu…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-14T11:31:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "79e4d6aae8a7ee5aa5ca5355363e0ffdd9afb175",
          "body": "…t or total budget caps (#418)\n\nThe declaration seam (#414) replaced the built-in key scan for EVERY channel —\nincluding the two budget figures the CALLER supplies rather than the tool. A\nplugin that declared the expected, documented shape (just `daily`) therefore had\n`max_daily_budget_increase_pct`\n[…]\nhe seam in a provider plugin: declaring `daily` made the\nplugin's own percentage-cap regression test start passing calls it used to refuse.\n\nTDD, red first, in tests/test_plugin_budget_declaration.py.",
          "is_bot": false,
          "headline": "fix(policy): a budget declaration must not switch off the increase-pc…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-14T10:22:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1da1c5b74363c22dae202121c07300b00e5e1490",
          "body": "Bump 0.10.23 -> 0.10.24 (pyproject, __init__, plugin.json, 51 SKILL.md\nfrontmatters) and cut the CHANGELOG for the seven changes merged since\n0.10.23:\n\nSecurity — workspace-scope Meta account_id / Google customer_id on\nmulti-account backends (#411) and fail closed on non-finite / oversized\nbudgets s\n[…]\n6).\nDocs — Japanese skill triggers (#396), plugin-authoring.md refresh\n(#414), and the credentials-backup rotation note (#394).\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
          "is_bot": false,
          "headline": "chore(release): 0.10.24 (#420)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-14T06:28:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3356ee69ddbfa4321a49008440e450f6b17cc7a6",
          "body": "…t bypass caps (#419)\n\nStrategyPolicyGate's budget extraction read a proposed budget with a bare\nfloat(). A Python int too large for float64 — int(\"9\"*309), 10**400 — makes\nfloat() raise OverflowError, which was uncaught and bubbled to\nStrategyPolicyGate.evaluate's blanket `except Exception: return\n\n[…]\napped channel, and the increase-pct-only current\ncase. Legitimate large-but-finite budgets and \"no budget proposed\" still pass.\n\nClaude-Session: https://claude.ai/code/session_01UFvgHU2TbFPPu4qckkLhNM",
          "is_bot": false,
          "headline": "fix(policy): fail closed on non-finite budgets so oversized/NaN canno…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-14T06:04:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0991cbfda4cdfccda4b68e196a9b4e4d731317e3",
          "body": "…s reach them (#414) (#416)\n\nStrategyPolicyGate (#360) enforces STRATEGY.md ## Guardrails before\ndispatch, but its budget extraction is hard-wired to the built-in\nGoogle/Meta argument keys. A plugin tool that carries its budget under any\nother name was read as \"no budget proposed\" and sailed past ev\n[…]\nypes and both\nchannels, the registry, an end-to-end gate denial against a real\nSTRATEGY.md, and the server wiring.\n\nCloses #414\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
          "is_bot": false,
          "headline": "feat(policy): let plugin tools declare their budget keys so Guardrail…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-14T04:07:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "871fcdf914e042069b4385b2e84d96595289e507",
          "body": "…ve workspace (#411) (#415)\n\nMost Meta Ads and Google Ads MCP tools take the per-account id as a free\ncaller argument, and the shared handler choke point (_get_client — every\ntool funnels through it) used it with the operator-shared credentials\nwithout validating it against the active workspace's bo\n[…]\n these\nresolvers but are unreachable from any wired tool today, are tracked as\n#413 and carry a warning docstring.\n\nCloses #411\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
          "is_bot": false,
          "headline": "fix(security): scope Meta account_id / Google customer_id to the acti…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-14T03:59:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "21053c9ec9d87a543504e2318eb4e7e612fbd409",
          "body": "…) (#410)\n\nCreative Studio writes generated visuals and composed banners to\n<workspace>/creative_studio/<run_id>/ with a provenance manifest.json,\nbut the filesystem was the only viewer. Add a read-only gallery tab to\nthe configure dashboard.\n\nBackend — new pure data layer mureo/web/creative_gallery\n[…]\n layer (envelope, query\nforwarding, uniform 404 incl. the vanished-file branch), static-asset\nguards, i18n parity.\n\nCloses #409\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
          "is_bot": false,
          "headline": "feat(web): Creative Studio gallery tab with per-client browsing (#409…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-14T01:36:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "982250c54736dd632368bd6a159a406900ccfd8c",
          "body": "…entials-path race (#406) (#408)\n\nThe configure server is threaded, but ConfigureWizard.set_host()\npublished the freshly rebuilt base HostPaths BEFORE re-applying the\ncredentials-path override (#194/#196). Between the two, concurrent\nrequests read — or wrote — the unresolved host-default credentials\n[…]\n pre-existing seam (handlers pairing session.host and\nhost_paths via two unsynchronized reads) is tracked as #407.\n\nCloses #406\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
          "is_bot": false,
          "headline": "fix(web): publish host_paths atomically in set_host to close the cred…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-14T00:23:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "704a3570661b7d97ab2e9a1f771ff17231dcd27d",
          "body": "…guidance (#394) (#404)\n\nInvestigation of #394 found most of it already resolved or not\nreproducible from mureo's own machinery: credentials only ever get a\nsingle rolling backup (credentials.json.bak, overwritten each save,\n0o600 via secure_chmod), the generation-accumulating timestamped mode\nis ST\n[…]\nwas considered and deferred (bounded, protected,\nsingle-generation exposure). Full analysis recorded on the issue.\n\nCloses #394\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
          "is_bot": false,
          "headline": "docs(security): document the rolling credentials backup and rotation …",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-13T03:58:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fdb57a38541d65de04c26f86a8d1af0eb3c48755",
          "body": "…ptions (#396) (#403)\n\nOperators phrase requests in Japanese, but 12 older operational skills\nhad English-only description frontmatter (the skill-firing trigger\nsurface), lowering match confidence for natural Japanese asks — e.g.\nrescue only matched \"Use when the user reports a sudden CPA spike\"\naga\n[…]\n(splitting the two large foundation SKILL.md\nfiles into references/) is deferred — decision recorded on the issue.\n\nCloses #396\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
          "is_bot": false,
          "headline": "fix(skills): add Japanese trigger phrases to operational skill descri…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-13T03:34:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fd0c41b2055ef6e7f9c6ac1a62ab7d83eb20c0f4",
          "body": "Bump version 0.10.22 -> 0.10.23 (pyproject, __init__, plugin.json, all\n51 SKILL.md frontmatters). Cut CHANGELOG [0.10.23] with the\ncredential-guard fix train: the guard now actually blocks via deny-JSON\n(#393), `mureo upgrade` refreshes stale installed hooks (#398), and the\ndashboard (re)install but\n[…]\ninstallations to run `mureo upgrade` once (or press\nthe configure UI's Reinstall button) to replace the old non-blocking\nhooks.\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
          "is_bot": false,
          "headline": "chore(release): 0.10.23 (#402)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-13T02:52:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "816039663a0afe0776a303fc9c860ed82710f791",
          "body": "…ttons (#400) (#401)\n\nThe per-row (re)install buttons on the dashboard's basic-setup section\n(credential-guard hook, workflow skills) only toasted the error\nenvelope; ok and noop reloaded status silently. On an already-installed\nrow nothing visible changes, so pressing \"Reinstall\" produced zero\nreac\n[…]\ncInstallButton\nblock in test_web_assets_dashboard_cards_and_toasts.py, following the\nhouse patterns of both files.\n\nCloses #400\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
          "is_bot": false,
          "headline": "fix(web): toast success and noop outcomes on dashboard (re)install bu…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-13T02:39:16Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d82f09b8d011a23737a07fbac911583381f2498e",
          "body": "…#398) (#399)\n\n#393 (PR #397) made the credential-guard installers upgrade-aware, but\nthey only run from setup — `mureo upgrade` alone left the old\nnon-blocking sys.exit(1) hooks in ~/.claude/settings.json and\n~/.codex/hooks.json forever.\n\nAdd _refresh_credential_guard() to the post-upgrade refresh,\n[…]\ntall (both surfaces + tag-outside-entries),\nabsent-file no-op, error swallowing, and _post_upgrade_refresh wiring.\n\nCloses #398\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
          "is_bot": false,
          "headline": "fix(upgrade): refresh stale credential-guard hooks on mureo upgrade (…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-13T01:45:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a423db4f215cd1e0f4546b84893039c1672f9dc4",
          "body": "…N (#393) (#397)\n\nThe PreToolUse credential-guard hooks installed into Claude Code's\n~/.claude/settings.json and Codex's ~/.codex/hooks.json used\nsys.exit(1), which both hosts treat as a NON-blocking hook error — the\ntool call proceeds. Reading ~/.mureo/credentials.json was never\nactually blocked (r\n[…]\nbling-dir\nfalse-positive guard. Installer tests cover upgrade, legacy-schema\nmigration, and both-location removal.\n\nCloses #393\n\nClaude-Session: https://claude.ai/code/session_0115NBUphwqsL1isTV8R7NHg",
          "is_bot": false,
          "headline": "fix(credential-guard): actually block credential access with deny JSO…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-13T00:48:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "411a3128791c162c3016e759f903a36eff863675",
          "body": "Bump version 0.10.20 -> 0.10.22 (pyproject, __init__, plugin.json, all\n51 SKILL.md frontmatters). Restructure CHANGELOG: record the shipped\nskills-only [0.10.21] section verbatim from release/0.10.21, and cut\n[0.10.22] with the Creative Studio feature set (visual layer,\ncomposition, /creative-genera\n[…]\n0 -> 0.10.22.\n\nTest: derive the creative-generate frontmatter version pin from\nmureo.__version__ instead of a hardcoded string.\n\nClaude-Session: https://claude.ai/code/session_01DjF1BFWDKrZYTN6YWMM8Tt",
          "is_bot": false,
          "headline": "chore(release): 0.10.22 (#392)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-12T09:24:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0b8212f8b1747128df4b7553a23b70aa75ca368d",
          "body": "…dent-postmortem workflow skills (#391)\n\nFour new bundled workflow skills, each with a packaged copy under\nmureo/_data/skills/ and a byte-identical repo-root mirror under skills/:\n\n- experiment (A/Bテスト設計・実行・評価): turns an ad-hoc change into a\n  designed experiment — a falsifiable hypothesis (variable\n[…]\nional skills); getting-started\noperational count 16->20 and upload list +4 in both languages; CHANGELOG\nUnreleased Added entry.\n\nClaude-Session: https://claude.ai/code/session_01AbvhGbHZoK8VqP3kR9nWWp",
          "is_bot": false,
          "headline": "feat(skills): experiment, audience-review, ad-fatigue-check, and inci…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-12T07:19:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a3e66e5d9d0e23d406a7d0644ece29d84cac68d4",
          "body": "…flow skills (#390)\n\nThree new bundled workflow skills, each with a packaged copy under\nmureo/_data/skills/ and a byte-identical repo-root mirror under skills/:\n\n- tracking-health (計測ヘルスチェック): preventive conversion-tracking\n  audit — Meta pixel inventory/health (meta_ads_pixels_list/get/stats/\n  eve\n[…]\n.ja workflow tables +3 rows; CHANGELOG\nUnreleased Added entry; getting-started operational-skill count 11→16\nin both languages.\n\nClaude-Session: https://claude.ai/code/session_01AbvhGbHZoK8VqP3kR9nWWp",
          "is_bot": false,
          "headline": "feat(skills): tracking-health, budget-pacing, and monthly-report work…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-12T06:41:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "071f97abeb65d75f1f7a8057803c8a00216a61ff",
          "body": "…ix stale labels (#389)\n\n- Dedup the ~20-line learning-insights + advisor diagnostic preamble into a\n  single canonical \"Diagnostic preamble\" section in _mureo-shared/SKILL.md.\n  Nine workflow skills (daily-check, rescue, budget-rebalance, goal-review,\n  search-term-cleanup, competitive-scan, creati\n[…]\ns name/description/version against pyproject for every\npackaged SKILL.md. All skills stay byte-identical between the two trees.\n\nClaude-Session: https://claude.ai/code/session_01AbvhGbHZoK8VqP3kR9nWWp",
          "is_bot": false,
          "headline": "chore(skills): deduplicate diagnostic preamble, normalize versions, f…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-12T06:11:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6fb4b77a62183d80e2fd1db0d4ba47bfe620c89c",
          "body": "…te-aware negative space (#388)\n\nRaise the ceiling of generated visuals by systematizing prompt craft and\nenforcing composition mechanically.\n\nCode:\n- Add TEMPLATE_NEGATIVE_SPACE mapping each composer template id to one precise\n  English composition sentence.\n- Extend build_visual_prompt(user_prompt\n[…]\nmplate rejection) and\ntest_creative_generate_skill.py pins (scaffold, genre presets, provider table,\ntemplate-arg instruction).\n\nClaude-Session: https://claude.ai/code/session_01AbvhGbHZoK8VqP3kR9nWWp",
          "is_bot": false,
          "headline": "feat(creative-studio): visual prompt engineering framework and templa…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-12T05:26:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a3877a240448234e4bb6ff48db4ec58c2fd2723d",
          "body": "… provider parse hardening, format dedupe (#387)\n\nM1: compose() now resolves manifest fonts via asyncio.to_thread so the\nsynchronous httpx download never blocks the event loop; ensure_font()\nnegative-caches a failed download (<filename>.unavailable, 24h TTL) so an\noffline / egress-filtered host no l\n[…]\nler defensively dedupes (order-preserving) before calling compose.\n\nAlso pins the OpenAI edit multipart request shape in tests.\n\nClaude-Session: https://claude.ai/code/session_01AbvhGbHZoK8VqP3kR9nWWp",
          "is_bot": false,
          "headline": "fix(creative-studio): review follow-ups — async-safe font resolution,…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-12T05:03:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c77574ee12eb2196e097c2231cecac434752a5a4",
          "body": "…er keys (#386)\n\nAdds a first-class \"Creative Studio (image generation)\" section to the\nconfigure dashboard's Setup tab for the three image-provider API keys\n(OPENAI_API_KEY / GEMINI_API_KEY / FAL_KEY), sitting between the plugin\ncredentials card and the advanced env list.\n\nEach provider gets a labe\n[…]\neased line. Tests: i18n EN/JA parity\nclass + static-asset section-shell/wiring guards (no JS harness in repo,\nper house style).\n\nClaude-Session: https://claude.ai/code/session_01AbvhGbHZoK8VqP3kR9nWWp",
          "is_bot": false,
          "headline": "feat(creative-studio): dashboard credentials section for image-provid…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-12T02:50:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d20da70c31dd38d9ca262f388c67a36b93941a5a",
          "body": "* feat(creative-studio): /creative-generate skill and documentation\n\nPR-C (final slice) of Creative Studio: the operator-facing surface over\nthe creative_studio_* MCP tools shipped in PR-A/PR-B.\n\n- New bundled skill creative-generate/SKILL.md (packaged copy under\n  mureo/_data/skills + repo-root ski\n[…]\n: https://claude.ai/code/session_01AbvhGbHZoK8VqP3kR9nWWp\n\n* test: add creative-generate to the bundled-skill remove allow-list\n\nClaude-Session: https://claude.ai/code/session_01AbvhGbHZoK8VqP3kR9nWWp",
          "is_bot": false,
          "headline": "feat(creative-studio): /creative-generate skill and documentation (#385)",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-12T02:22:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0e916f3d0db66131a6ce6d539032e708a50d6f95",
          "body": "… font pipeline (#384)\n\n* feat(creative-studio): HTML/CSS composition engine, brand kit, and JP font pipeline\n\nPR-B of Creative Studio adds the typography & layout layer that composites ad\ncopy over the text-free key visuals produced by PR-A, plus the three new MCP\ntools that drive it.\n\nModules:\n- c\n[…]\n runners). Mirrors the accepted win32 tolerance in\ntest_web_handlers.py's spoofed-Host tests; POSIX still requires a clean\n413.\n\nClaude-Session: https://claude.ai/code/session_01AbvhGbHZoK8VqP3kR9nWWp",
          "is_bot": false,
          "headline": "feat(creative-studio): HTML/CSS composition engine, brand kit, and JP…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-12T01:50:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6d3bb71177834512af13f79f7a780cb66eddf428",
          "body": "…on tools (#383)\n\nAdd the visual layer of Creative Studio (PR-A): a pluggable, BYO-API-key\nimage-provider abstraction plus MCP tools to enumerate providers and\ngenerate text-free ad key visuals.\n\n- mureo/creative_studio/providers: ImageProvider Protocol, first-wins\n  registry with fault-isolated ent\n[…]\nistration gated by MUREO_DISABLE_CREATIVE_STUDIO=1.\n- Tests: providers (mocked httpx), workspace, formats, MCP tools, env gate.\n\nClaude-Session: https://claude.ai/code/session_01AbvhGbHZoK8VqP3kR9nWWp",
          "is_bot": false,
          "headline": "feat(creative-studio): image provider abstraction and visual generati…",
          "author_name": "Hirokazu Yoshinaga",
          "author_login": "hyoshi",
          "committed_at": "2026-07-12T00:33:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 72,
      "commits_last_year": 498,
      "latest_release_at": "2026-08-01T13:05:52Z",
      "latest_release_tag": "v0.10.38",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 18,
      "days_since_latest_release": 0,
      "mean_days_between_releases": 1.5
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "mureo",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [
            "advertising",
            "ai-agent",
            "cli",
            "google-ads",
            "mcp",
            "meta-ads",
            "orchestration",
            "strategy",
            "workflow",
            "Development Status :: 4 - Beta",
            "Intended Audience :: Developers",
            "License :: OSI Approved :: Apache Software License",
            "Programming Language :: Python :: 3",
            "Programming Language :: Python :: 3.10",
            "Programming Language :: Python :: 3.11",
            "Programming Language :: Python :: 3.12",
            "Topic :: Software Development :: Libraries"
          ],
          "ecosystem": "pypi",
          "matches_repo": true,
          "registry_url": "https://pypi.org/project/mureo/",
          "is_deprecated": false,
          "latest_version": "0.10.38",
          "repository_url": "https://github.com/logly/mureo",
          "versions_count": 69,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 5105,
          "first_published_at": "2026-04-20T12:04:45.211193Z",
          "latest_published_at": "2026-08-01T13:06:31.547109Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 3,
      "stars": 23,
      "watchers": 0,
      "fork_history": {
        "days": [
          {
            "date": "2026-07-20",
            "count": 1
          },
          {
            "date": "2026-07-28",
            "count": 1
          },
          {
            "date": "2026-07-30",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 3,
        "total_forks": 3
      },
      "star_history": null,
      "open_issues_and_prs": 3
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 138910,
      "source_files_sampled": 595,
      "oversized_source_files": 10,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 23836
    },
    "dependencies": {
      "manifests": [
        "pyproject.toml"
      ],
      "advisories": {
        "error": "No resolved dependencies carried a version and a supported ecosystem",
        "scope": "repository_graph",
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 25,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "pypi"
      ],
      "dependencies": [
        {
          "name": "google-ads",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=28.0,<30"
        },
        {
          "name": "google-auth",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.28,<3"
        },
        {
          "name": "google-auth-oauthlib",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.2,<2"
        },
        {
          "name": "facebook-business",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=20.0,<22"
        },
        {
          "name": "httpx",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.27,<1"
        },
        {
          "name": "beautifulsoup4",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=4.12,<5"
        },
        {
          "name": "lxml",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=6.1,<7"
        },
        {
          "name": "pydantic",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=2.5,<3"
        },
        {
          "name": "typer",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.12,<1"
        },
        {
          "name": "rich",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=13.0,<14"
        },
        {
          "name": "simple-term-menu",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.6,<2"
        },
        {
          "name": "mcp",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.0,<2"
        },
        {
          "name": "jsonschema",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=4.20,<5"
        },
        {
          "name": "openpyxl",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=3.1,<4"
        },
        {
          "name": "pyyaml",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=6.0,<7"
        },
        {
          "name": "packaging",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=23.0,<26"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "beautifulsoup4",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "facebook-business",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "google-ads",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "google-auth",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "google-auth-oauthlib",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "httpx",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "jsonschema",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "lxml",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "mcp",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "openpyxl",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "packaging",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pydantic",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pyyaml",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "rich",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "simple-term-menu",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "typer",
            "direct": true,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "black",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "jinja2",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "mypy",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "playwright",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pytest",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pytest-asyncio",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pytest-cov",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "pytest-mock",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          },
          {
            "name": "ruff",
            "direct": false,
            "version": null,
            "ecosystem": "pypi"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 25,
        "direct_count": 16,
        "indirect_count": 9
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 397,
        "open_issues": 3,
        "closed_ratio": 0.973,
        "closed_issues": 110,
        "closed_unmerged_prs": 9
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "hyoshi",
          "commits": 491,
          "avatar_url": "https://avatars.githubusercontent.com/u/4027404?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "quickstart-smoke.yml",
        "release.yml",
        "security.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 26 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 3,
            "reason": "dependency not pinned by hash detected -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 10,
            "reason": "SAST tool is run on all commits",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "fa9bcf2df1d5ce4786425cced4e8ed3ef6e34968",
        "ran_at": "2026-08-01T13:11:31Z",
        "aggregate_score": 7.4,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-08-01T13:10:47Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-08-01T13:05:48Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 104,
          "created_at": "2026-05-16T08:58:30Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 121,
          "created_at": "2026-05-18T23:23:40Z",
          "last_comment_at": "2026-07-30T12:18:16Z",
          "last_comment_author": "hyoshi"
        },
        {
          "number": 359,
          "created_at": "2026-07-06T22:51:30Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/logly/mureo",
    "host": "github.com",
    "name": "mureo",
    "owner": "logly"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "excellent",
      "name": "Overall health",
      "note": "The weighted overall 69 is calibrated to 81 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 69,
            "calibrated": 81,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 81,
      "inputs": {
        "security": 74,
        "vitality": 86,
        "community": 57,
        "governance": 56,
        "calibration": "2026-08-02",
        "engineering": 77,
        "ai_readiness": 54,
        "weighted_overall_raw": 69
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 86,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 76,
            "inputs": {
              "commits_last_year": 498,
              "human_commit_share": 0.97,
              "days_since_last_push": 0,
              "active_weeks_last_year": 18
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "18/52 weeks with commits",
                "points": 12.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 18
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "498 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 498
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 26 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "exceptional",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 72,
              "latest_release_tag": "v0.10.38",
              "releases_from_tags": false,
              "days_since_latest_release": 0,
              "mean_days_between_releases": 1.5
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "72 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 72
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~1.5 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 1.5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 57,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 24,
            "inputs": {
              "forks": 3,
              "stars": 23,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "23 stars",
                "points": 21.8,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 23
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "3 forks",
                "points": 2.5,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "readme_badges": null,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "readme_badge_services": [],
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 62,
            "inputs": {
              "packages": [
                "mureo"
              ],
              "dependents": null,
              "ecosystems": "pypi",
              "total_downloads": null,
              "monthly_downloads": 5105
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "5,105 downloads/month across pypi",
                "points": 49.4,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 5105,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 56,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 13,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 81,
            "inputs": {
              "merged_prs": 397,
              "open_issues": 3,
              "closed_issues": 110,
              "prs_merged_7d": null,
              "prs_decided_7d": null,
              "prs_merged_30d": null,
              "prs_decided_30d": null,
              "issue_closed_ratio": 0.973,
              "closed_unmerged_prs": 9,
              "first_time_authors_30d": null,
              "first_time_prs_merged_30d": null,
              "first_time_prs_decided_30d": null
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "97% of issues closed",
                "points": 40.9,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 97
                    }
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "397/406 decided PRs merged",
                "points": 29.3,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 397,
                      "decided": 406
                    }
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "weak",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 49,
            "inputs": {
              "followers": 0,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "logly",
              "public_repos": 7,
              "account_age_days": 5016
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of logly",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "logly"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "7 public repos, account ~13 yr old",
                "points": 18.6,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 7
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 13
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "exceptional",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "mureo"
              ],
              "ecosystems": "pypi",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on pypi",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "69 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 69
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 77,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "4 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 4
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [
                "advertising",
                "ai-agents",
                "cli",
                "google-ads",
                "marketing",
                "mcp",
                "model-context-protocol",
                "python",
                "agentic-ai",
                "claude-code",
                "codex",
                "cursor",
                "gemini-cli",
                "marketing-automation",
                "search-console",
                "meta-ads",
                "facebook-ads"
              ],
              "has_wiki": false,
              "homepage": "https://mureo.io",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://mureo.io",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "17 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 17
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "good",
        "name": "Security",
        "value": 74,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "good",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 74,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 7.4
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "30 out of 30 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 26 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 3",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is run on all commits",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "exceptional",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "commit_weight_rule": {
                "min_commits": 50,
                "min_commit_share": 0.1
              },
              "review_only_matches": 0,
              "below_threshold_exposures": [],
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 54,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 23836
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "97 of 97 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 97,
                      "sampled": 97
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "weak",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 43,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0.03
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "3 of the last 100 commits are automated dependency updates",
                "points": 8,
                "status": "met",
                "details": [
                  {
                    "code": "dependency_bot_commits",
                    "params": {
                      "count": 3,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 54,
            "inputs": {
              "primary_language": "Python",
              "largest_source_bytes": 138910,
              "source_files_sampled": 595,
              "oversized_source_files": 10
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Python without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "Python"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "10/595 source files over 60KB",
                "points": 54.1,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 595,
                      "oversized": 10
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "example_dirs": [],
              "has_mcp_signal": true,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "labels": [
        "mcp-server",
        "cli",
        "library"
      ],
      "scores": {
        "cli": 6,
        "library": 6,
        "mcp-server": 7
      },
      "primary": "mcp-server",
      "evidence": [
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:pypi",
          "weight": 6
        },
        {
          "tier": "dependencies",
          "label": "cli",
          "source": "dep:typer",
          "weight": 4
        },
        {
          "tier": "dependencies",
          "label": "mcp-server",
          "source": "dep:mcp",
          "weight": 4
        },
        {
          "tier": "structure",
          "label": "mcp-server",
          "source": "mcp_signal",
          "weight": 3
        },
        {
          "tier": "tags",
          "label": "cli",
          "source": "tag:cli",
          "weight": 2
        }
      ],
      "artifacts": [],
      "confidence": "medium",
      "host_extension": false,
      "runs_as_process": true,
      "consumed_by_code": true
    },
    "metrics_version": "2.3.1"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "deps.dev does not index pypi:mureo@0.10.38; advisories assessed against the repository dependency graph instead",
    "No resolved dependencies carried a version and a supported ecosystem"
  ],
  "report_type": "repository",
  "generated_at": "2026-08-01T13:11:47.694642Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/l/logly/mureo.svg",
  "full_name": "logly/mureo",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v2.3.1、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计PyPI.