公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-23 23:17 UTC

lux-db / lux

A Redis-compatable key-value store. Up to 10x faster. Native vector support.

RustMIT★ 272 星标⑂ 21 复刻始于 2026年3月在 GitHub 上查看 ↗

lux-db/lux 的健康指数为 100 分中的 63 分,处于「中等」区间。 其得分最高的类别是Vitality(81/100),最低的是Security(49/100)。 最近一次更新在 4 天前。 近期的大部分工作由 1 位贡献者完成。

63
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

63
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

Lux组织
4 关注者2 个公开仓库始于 2026年3月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布标签
crates.iolux0.1.21673612 天前
crates.iolux-cli指向其他仓库——不计分0.39.25431551 天前luaneovimbuildpackagemanagerluarockscommand-line-utilitiesdevelopment-tools
npm@luxdb/sdk2.10.02,237255 天前luxdatabaseapplication-databaseauthtablesvectorsrealtimerediscachequeuestimeseries

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

81良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 4 天前
11.1/36提交节奏 — 52 周中有 16 周有提交
18/18提交量 — 最近一年 359 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year359
human_commit_share1
days_since_last_push4
active_weeks_last_year16

发布纪律

90优秀
评分方式
27/27有发布版本 — 已发布 99 个发布版本
36/36发布时效 — 最近一次发布版本于 4 天前
27/27发布节奏 — 约每 0.6 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — Project has not signed or included provenance with any releases.
所用输入
releases_count99
latest_release_tagcli-v0.26.1
releases_from_tags
days_since_latest_release4
mean_days_between_releases0.6

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

58中等 · 占总体的 18%
评分方式
39.5/60星标 — 272 个星标
10.8/25复刻 — 21 个复刻
0/15关注者 — 2 位关注者
所用输入
forks21
stars272
watchers2
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

70良好
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(MIT)
18/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
44.7/80月度下载量 — crates, npm 合计每月 2,253 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packageslux, @luxdb/sdk
dependents
ecosystemscrates, npm
total_downloads27,898
monthly_downloads2,253
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

54中等 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
1.3/22.5提交分布 — 头号贡献者编写了 94% 的提交
6.8/13.5贡献者广度 — 5 位贡献者
3/10OpenSSF Scorecard:Contributors — project has 1 contributing companies or organizations -- score normalized to 3
所用输入
bus_factor1
contributors_sampled5
top_contributor_share0.942
评分方式
40.1/46.8议题解决 — 86% 的议题已关闭
30.6/38.3PR 接受 — 已裁定的 PR 中 32/40 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/30 approved changesets -- score normalized to 0
所用输入
merged_prs32
open_issues1
closed_issues6
issue_closed_ratio0.857
closed_unmerged_prs8
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
5/25所有者影响力 — lux-db 有 4 位关注者
4.2/25既往记录 — 2 个公开仓库,账户约 0 年
所用输入
followers4
owner_typeOrganization
is_verified
owner_loginlux-db
public_repos2
account_age_days130
评分方式
25/25已发布且可解析 — crates, npm 上有 2 个软件包
35/35发布时效 — 最近一次发布于 5 天前
20/20版本历史 — 25 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packageslux, @luxdb/sdk
ecosystemscrates, npm
any_deprecated
min_days_since_publish5

工程质量

基础的工程与文档实践是否到位?

71良好 · 占总体的 20%

工程实践

68中等
评分方式
24/24CI 工作流 — 6 个工作流
24/24存在测试
0/16Linter 配置
0/9.6Pre-commit 钩子
0/6.4.editorconfig
20/20OpenSSF Scorecard:CI-Tests — 7 out of 7 merged PRs checked by a CI test -- score normalized to 10
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

75良好
评分方式
30/30README
0/25文档目录
15/15文档 / 主页站点 — https://luxdb.dev
10/10仓库描述
10/10主题标签 — 9 个主题标签
10/10Wiki
所用输入
topicslux, redis, database, embeddings, rust, vector, dragonflydb, postgres, supabase
has_wiki
homepagehttps://luxdb.dev
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

49存在风险 · 占总体的 16%

安全态势

49存在风险
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — 无数据
2.5/2.5CI-Tests — 7 out of 7 merged PRs checked by a CI test -- score normalized to 10
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
5/5Fuzzing — project is fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
1.5/7.5Vulnerabilities — 8 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate4.8
已排除计分(无数据或不适用):branch_protection。 其余权重已重新归一化。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

59中等 · 占总体的 0%
评分方式
0/45代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 100 次人类提交中有 100 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share1
agent_instruction_files
agent_instruction_max_bytes
评分方式
18/18一条命令的引导启动 — Justfile
22/22自动化测试
0/11Lint / 格式化配置
11/11静态类型检查 — sdk/tsconfig.json
10/10可复现环境 — Dockerfile, Nix, lockfile
0/10已体现的代理实践 — 最近 100 次提交中没有代理编写的提交
0/8自动化维护 — 未观察到自动依赖更新
0/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
所用输入
has_nix
has_tests
lockfilesCargo.lock
has_dockerfile
typed_language
bootstrap_filesJustfile
has_devcontainer
has_linter_config
typecheck_configssdk/tsconfig.json
agent_commit_share0
toolchain_manifestsCargo.toml, cli/Cargo.toml, fuzz/Cargo.toml
dependency_bot_commit_share0
评分方式
45/45可类型检查的代码 — Rust(静态类型)
49.1/55可控的文件大小 — 采样的 112 个源文件中有 12 个超过 60KB
所用输入
primary_languageRust
largest_source_bytes291,115
source_files_sampled112
oversized_source_files12

关键数据

272GitHub 星标
5贡献者
359最近 12 个月提交数
4距最近推送天数
99发布版本数
1巴士系数(bus factor)
1开放议题
crates.io, npm软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • crates package 'lux-cli' points at a different repository (https://github.com/lumen-oss/lux); excluded from ecosystem scoring
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

更多细节

Star 与 Fork 历史 0 ★ / 21 ⇿
0Star
21Fork
71发布

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

48121620242152026-032026-052026-06
主版本 0次版本 19修订 31
OpenSSF Scorecard 4.8 / 10
4.8综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-23 23:17 UTC

10Binary-Artifactsno binaries found in the repo
不适用Branch-Protectioninternal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
10CI-Tests7 out of 7 merged PRs checked by a CI test -- score normalized to 10
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
10Fuzzingproject is fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
2Vulnerabilities8 existing vulnerabilities detected
直接依赖 34
注册表软件包版本约束清单文件
crates.iotokio1Cargo.toml
crates.iorayon1Cargo.toml
crates.iobytes1Cargo.toml
crates.iobase640.22Cargo.toml
crates.iofutures-util0.3Cargo.toml
crates.ioparking_lot0.12Cargo.toml
crates.iohashbrown0.14Cargo.toml
crates.ioordered-float4Cargo.toml
crates.iomlua0.10Cargo.toml
crates.iosha1_smol1Cargo.toml
crates.iormp0.8Cargo.toml
crates.ioserde_json1Cargo.toml
crates.iotokio-tungstenite0.24Cargo.toml
crates.ioargon20.5Cargo.toml
crates.iobcrypt0.17Cargo.toml
crates.iojsonwebtoken10Cargo.toml
crates.iop2560.13Cargo.toml
crates.iorand_core0.6Cargo.toml
crates.ioserde1Cargo.toml
crates.iosha20.10Cargo.toml
crates.ioring0.17Cargo.toml
crates.ioreqwest0.12Cargo.toml
crates.ioclap4cli/Cargo.toml
crates.ioreqwest0.12cli/Cargo.toml
crates.iorustls0.23cli/Cargo.toml
crates.ioserde1cli/Cargo.toml
crates.ioserde_json1cli/Cargo.toml
crates.iotokio1cli/Cargo.toml
crates.iodirs6cli/Cargo.toml
crates.iocolored3cli/Cargo.toml
crates.ioopen5cli/Cargo.toml
crates.iochrono0.4cli/Cargo.toml
crates.iowebpki-roots0.26cli/Cargo.toml
npmioredis^5.0.0sdk/package.json
全部依赖 未采集

本报告未能采集到解析后的依赖集合:GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [
        "lux",
        "redis",
        "database",
        "embeddings",
        "rust",
        "vector",
        "dragonflydb",
        "postgres",
        "supabase"
      ],
      "is_fork": false,
      "size_kb": 7534,
      "has_wiki": true,
      "homepage": "https://luxdb.dev",
      "languages": {
        "Nix": 898,
        "Just": 1980,
        "Rust": 3245131,
        "Shell": 36080,
        "Dockerfile": 519,
        "TypeScript": 224622
      },
      "pushed_at": "2026-07-19T21:49:13Z",
      "created_at": "2026-03-15T18:07:32Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-23T20:35:03Z",
      "description": "A Redis-compatable key-value store. Up to 10x faster. Native vector support.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "Rust",
      "significant_languages": [
        "Rust"
      ]
    },
    "owner": {
      "blog": "https://luxdb.dev",
      "name": "Lux",
      "type": "Organization",
      "login": "lux-db",
      "company": null,
      "location": null,
      "followers": 4,
      "avatar_url": "https://avatars.githubusercontent.com/u/268421784?v=4",
      "created_at": "2026-03-15T18:06:17Z",
      "is_verified": null,
      "public_repos": 2,
      "account_age_days": 130
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "cli-v0.26.1",
          "kind": "other",
          "published_at": "2026-07-19T21:29:40Z"
        },
        {
          "tag": "v0.32.2",
          "kind": "patch",
          "published_at": "2026-07-18T15:29:07Z"
        },
        {
          "tag": "v0.32.1",
          "kind": "patch",
          "published_at": "2026-07-18T14:51:50Z"
        },
        {
          "tag": "v0.32.0",
          "kind": "minor",
          "published_at": "2026-07-18T02:50:08Z"
        },
        {
          "tag": "v0.31.0",
          "kind": "minor",
          "published_at": "2026-07-17T02:05:35Z"
        },
        {
          "tag": "v0.30.0",
          "kind": "minor",
          "published_at": "2026-07-16T21:21:50Z"
        },
        {
          "tag": "v0.29.0",
          "kind": "minor",
          "published_at": "2026-07-16T18:09:44Z"
        },
        {
          "tag": "v0.28.0",
          "kind": "minor",
          "published_at": "2026-07-16T13:00:08Z"
        },
        {
          "tag": "cli-v0.26.0",
          "kind": "other",
          "published_at": "2026-07-15T19:09:15Z"
        },
        {
          "tag": "cli-v0.25.0",
          "kind": "other",
          "published_at": "2026-07-14T03:25:06Z"
        },
        {
          "tag": "cli-v0.24.0",
          "kind": "other",
          "published_at": "2026-07-14T02:55:06Z"
        },
        {
          "tag": "cli-v0.23.0",
          "kind": "other",
          "published_at": "2026-07-08T00:35:01Z"
        },
        {
          "tag": "v0.27.0",
          "kind": "minor",
          "published_at": "2026-07-08T00:36:55Z"
        },
        {
          "tag": "v0.26.2",
          "kind": "patch",
          "published_at": "2026-07-07T22:01:09Z"
        },
        {
          "tag": "v0.26.1",
          "kind": "patch",
          "published_at": "2026-07-07T17:44:11Z"
        },
        {
          "tag": "v0.26.0",
          "kind": "minor",
          "published_at": "2026-07-06T14:39:31Z"
        },
        {
          "tag": "v0.25.0",
          "kind": "minor",
          "published_at": "2026-07-05T18:50:49Z"
        },
        {
          "tag": "cli-v0.22.0",
          "kind": "other",
          "published_at": "2026-07-05T18:45:10Z"
        },
        {
          "tag": "v0.24.6",
          "kind": "patch",
          "published_at": "2026-07-03T01:52:24Z"
        },
        {
          "tag": "v0.24.5",
          "kind": "patch",
          "published_at": "2026-07-03T00:56:18Z"
        },
        {
          "tag": "v0.24.4",
          "kind": "patch",
          "published_at": "2026-06-28T21:57:50Z"
        },
        {
          "tag": "v0.24.3",
          "kind": "patch",
          "published_at": "2026-06-28T16:03:57Z"
        },
        {
          "tag": "v0.24.2",
          "kind": "patch",
          "published_at": "2026-06-25T00:49:27Z"
        },
        {
          "tag": "v0.24.1",
          "kind": "patch",
          "published_at": "2026-06-23T19:06:29Z"
        },
        {
          "tag": "v0.24.0",
          "kind": "minor",
          "published_at": "2026-06-23T02:11:18Z"
        },
        {
          "tag": "v0.23.1",
          "kind": "patch",
          "published_at": "2026-06-23T01:35:19Z"
        },
        {
          "tag": "v0.23.0",
          "kind": "minor",
          "published_at": "2026-06-22T23:31:45Z"
        },
        {
          "tag": "v0.22.0",
          "kind": "minor",
          "published_at": "2026-06-22T03:45:38Z"
        },
        {
          "tag": "v0.21.6",
          "kind": "patch",
          "published_at": "2026-06-21T16:32:52Z"
        },
        {
          "tag": "v0.21.5",
          "kind": "patch",
          "published_at": "2026-06-21T03:01:41Z"
        },
        {
          "tag": "cli-v0.21.1",
          "kind": "other",
          "published_at": "2026-06-21T02:43:15Z"
        },
        {
          "tag": "cli-v0.21.0",
          "kind": "other",
          "published_at": "2026-06-21T02:09:36Z"
        },
        {
          "tag": "cli-v0.20.0",
          "kind": "other",
          "published_at": "2026-06-20T21:39:51Z"
        },
        {
          "tag": "v0.21.4",
          "kind": "patch",
          "published_at": "2026-06-20T20:21:11Z"
        },
        {
          "tag": "v0.21.3",
          "kind": "patch",
          "published_at": "2026-06-19T18:33:45Z"
        },
        {
          "tag": "v0.21.2",
          "kind": "patch",
          "published_at": "2026-06-19T18:12:12Z"
        },
        {
          "tag": "v0.21.1",
          "kind": "patch",
          "published_at": "2026-06-19T17:49:34Z"
        },
        {
          "tag": "cli-v0.19.0",
          "kind": "other",
          "published_at": "2026-06-19T01:52:33Z"
        },
        {
          "tag": "v0.21.0",
          "kind": "minor",
          "published_at": "2026-06-19T01:54:23Z"
        },
        {
          "tag": "v0.20.4",
          "kind": "patch",
          "published_at": "2026-06-18T18:34:17Z"
        },
        {
          "tag": "cli-v0.18.3",
          "kind": "other",
          "published_at": "2026-06-18T18:27:39Z"
        },
        {
          "tag": "v0.20.3",
          "kind": "patch",
          "published_at": "2026-06-18T15:15:36Z"
        },
        {
          "tag": "cli-v0.18.2",
          "kind": "other",
          "published_at": "2026-06-18T15:08:23Z"
        },
        {
          "tag": "v0.20.2",
          "kind": "patch",
          "published_at": "2026-06-18T14:18:11Z"
        },
        {
          "tag": "cli-v0.18.1",
          "kind": "other",
          "published_at": "2026-06-18T14:11:49Z"
        },
        {
          "tag": "v0.20.1",
          "kind": "patch",
          "published_at": "2026-06-18T00:07:22Z"
        },
        {
          "tag": "cli-v0.18.0",
          "kind": "other",
          "published_at": "2026-06-18T00:00:41Z"
        },
        {
          "tag": "cli-v0.17.0",
          "kind": "other",
          "published_at": "2026-06-17T22:56:51Z"
        },
        {
          "tag": "v0.20.0",
          "kind": "minor",
          "published_at": "2026-06-17T22:40:12Z"
        },
        {
          "tag": "v0.19.0",
          "kind": "minor",
          "published_at": "2026-06-17T19:57:25Z"
        },
        {
          "tag": "v0.18.0",
          "kind": "minor",
          "published_at": "2026-06-14T20:18:21Z"
        },
        {
          "tag": "cli-v0.16.0",
          "kind": "other",
          "published_at": "2026-06-14T19:46:37Z"
        },
        {
          "tag": "v0.17.0",
          "kind": "minor",
          "published_at": "2026-06-13T18:41:59Z"
        },
        {
          "tag": "cli-v0.15.0",
          "kind": "other",
          "published_at": "2026-06-13T00:52:01Z"
        },
        {
          "tag": "v0.16.0",
          "kind": "minor",
          "published_at": "2026-06-12T23:28:25Z"
        },
        {
          "tag": "v0.15.0",
          "kind": "minor",
          "published_at": "2026-06-12T20:06:12Z"
        },
        {
          "tag": "v0.14.3",
          "kind": "patch",
          "published_at": "2026-06-09T00:57:15Z"
        },
        {
          "tag": "cli-v0.14.2",
          "kind": "other",
          "published_at": "2026-06-07T21:06:01Z"
        },
        {
          "tag": "v0.14.2",
          "kind": "patch",
          "published_at": "2026-06-06T15:16:31Z"
        },
        {
          "tag": "cli-v0.14.1",
          "kind": "other",
          "published_at": "2026-06-05T13:30:28Z"
        },
        {
          "tag": "v0.14.0",
          "kind": "minor",
          "published_at": "2026-06-04T23:48:46Z"
        },
        {
          "tag": "cli-v0.14.0",
          "kind": "other",
          "published_at": "2026-06-04T23:31:25Z"
        },
        {
          "tag": "v0.13.2",
          "kind": "patch",
          "published_at": "2026-05-30T22:30:47Z"
        },
        {
          "tag": "v0.13.0",
          "kind": "minor",
          "published_at": "2026-05-30T21:44:29Z"
        },
        {
          "tag": "v0.12.1",
          "kind": "patch",
          "published_at": "2026-04-19T00:07:28Z"
        },
        {
          "tag": "luxctl-v0.4.0",
          "kind": "other",
          "published_at": "2026-04-12T03:20:48Z"
        },
        {
          "tag": "v0.12.0",
          "kind": "minor",
          "published_at": "2026-04-12T03:24:59Z"
        },
        {
          "tag": "luxctl-v0.3.2",
          "kind": "other",
          "published_at": "2026-04-05T01:22:56Z"
        },
        {
          "tag": "luxctl-v0.3.1",
          "kind": "other",
          "published_at": "2026-04-03T23:05:02Z"
        },
        {
          "tag": "luxctl-v0.3.0",
          "kind": "other",
          "published_at": "2026-04-03T21:57:50Z"
        },
        {
          "tag": "v0.11.3",
          "kind": "patch",
          "published_at": "2026-04-03T22:04:49Z"
        },
        {
          "tag": "v0.11.2",
          "kind": "patch",
          "published_at": "2026-03-26T05:31:25Z"
        },
        {
          "tag": "v0.11.1",
          "kind": "patch",
          "published_at": "2026-03-26T05:20:23Z"
        },
        {
          "tag": "v0.11.0",
          "kind": "minor",
          "published_at": "2026-03-26T04:38:21Z"
        },
        {
          "tag": "luxctl-v0.2.0",
          "kind": "other",
          "published_at": "2026-03-24T00:31:27Z"
        },
        {
          "tag": "v0.10.1",
          "kind": "patch",
          "published_at": "2026-03-23T03:38:28Z"
        },
        {
          "tag": "v0.10.0",
          "kind": "minor",
          "published_at": "2026-03-23T03:15:31Z"
        },
        {
          "tag": "luxctl-v0.1.3",
          "kind": "other",
          "published_at": "2026-03-22T20:00:15Z"
        },
        {
          "tag": "luxctl-v0.1.2",
          "kind": "other",
          "published_at": "2026-03-22T19:50:43Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2026-03-22T01:24:24Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-03-21T23:30:53Z"
        },
        {
          "tag": "v0.8.2",
          "kind": "patch",
          "published_at": "2026-03-21T18:14:35Z"
        },
        {
          "tag": "v0.8.1",
          "kind": "patch",
          "published_at": "2026-03-21T00:45:18Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-03-20T16:21:26Z"
        },
        {
          "tag": "v0.7.3",
          "kind": "patch",
          "published_at": "2026-03-20T04:48:15Z"
        },
        {
          "tag": "v0.7.2",
          "kind": "patch",
          "published_at": "2026-03-20T04:04:06Z"
        },
        {
          "tag": "v0.7.1",
          "kind": "patch",
          "published_at": "2026-03-20T02:54:44Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-03-19T21:47:51Z"
        },
        {
          "tag": "v0.6.1",
          "kind": "patch",
          "published_at": "2026-03-19T01:19:15Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-03-19T00:07:41Z"
        },
        {
          "tag": "v0.5.3",
          "kind": "patch",
          "published_at": "2026-03-18T22:05:06Z"
        },
        {
          "tag": "v0.5.2",
          "kind": "patch",
          "published_at": "2026-03-18T05:22:07Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2026-03-17T17:48:01Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-03-17T02:33:31Z"
        },
        {
          "tag": "v0.4.1",
          "kind": "patch",
          "published_at": "2026-03-16T20:01:38Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-03-16T19:46:37Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-03-16T17:28:24Z"
        },
        {
          "tag": "v0.2.2",
          "kind": "patch",
          "published_at": "2026-03-16T03:13:56Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2026-03-16T02:40:16Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "5d72ef9c35176922d780d46eeb3c86c86fe6149d",
          "body": "…(#51)\n\nThe set-op length guards were written as `const + numkeys > args.len()`,\nwhich overflows usize and panics when numkeys is huge (parse_zstore_numkeys\naccepts any u64). The nightly `command` fuzz target hit this on ~half its\nseeds (e.g. sorted_sets.rs:975). Compare as `numkeys > len.saturating_sub(N)`\nso the guard rejects the input instead of crashing. Covers ZUNION/ZINTER/\nZDIFF (+STORE) and ZMPOP/BZMPOP. Adds a regression test.",
          "is_bot": false,
          "headline": "fix(zset): overflow-safe numkeys guards in ZUNION/ZINTER/ZDIFF/ZMPOP …",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-19T21:49:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "062a75dcd10391b5ce195f366babbaf1da413802",
          "body": "The instances->projects rename removed /instances, so login/list/create/exec\n404'd. Validate login against /workspaces, resolve the token's workspace for\nproject list + create, and move /instances/:id/* to /projects/:id/*. Bump 0.26.1.",
          "is_bot": false,
          "headline": "fix(cli): repoint to /projects, resolve workspace from token (#52)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-19T21:27:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15b3027f7fe76bf950c4537d12b5c089a256df1e",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.32.2",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-18T15:20:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "12205317e97e22275dcfbbe54cec314b5326b98b",
          "body": "* feat(push): unregister-by-token + admin stats endpoint\n\n- DELETE /v1/push/devices { token } (operator): remove a device by its token,\n  for logout-time unregister where the client has the token, not the id.\n- GET /v1/push/admin/stats (operator): process-level sends/delivered/failed/\n  devices coun\n[…]\nn scoped to the token (other device survives).\n- push_admin_routes_require_operator: a signed-in user and an unauthenticated\n  caller are both denied on DELETE /push/devices and GET /push/admin/stats.",
          "is_bot": false,
          "headline": "feat(push): unregister-by-token + admin stats endpoint (#50)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-18T15:19:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af957b7a4fa696a25367bbd457cf89994d0fe708",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.32.1",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-18T14:42:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "36485f9388e88243f1aa3108886d0a83a9661695",
          "body": "The worker cached the APNs/Web Push sink by app+platform for its whole lifetime\nand never re-read credentials, so a topic/environment/key or VAPID change only\ntook effect after an engine restart. Fingerprint the resolved credentials and\nrebuild the sink when it changes, keeping the provider-token cache between\nsends. Adds a regression test.",
          "is_bot": false,
          "headline": "fix(push): rebuild the delivery sink when credentials change (#49)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-18T14:40:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d6edd8d9fe1aee138785f8b42c315396d6a0265",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.32.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-18T02:41:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "02b9eb8b7a7bb9c1079961df673c6b3338802ad1",
          "body": null,
          "is_bot": false,
          "headline": "feat(push): native push notifications (APNs + Web Push) (#48)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-18T02:39:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f082bfafe8ccf53c683ddf60fa900f9c075c9e48",
          "body": "* feat(live): incremental view maintenance for .live() table queries\n\nEmit a typed row-delta at the table mutation leaves and maintain each\neligible live query's result from the delta by re-evaluating only the\nchanged pk, instead of re-running the whole query and diffing on every\nwrite.\n\nEligible = \n[…]\ne() clients transparently get the\nfaster path. Delta subscriptions are torn down on socket disconnect so\nthe broker's per-table channel and subscriber gate don't leak.\n\n* chore: bump version to 0.31.0",
          "is_bot": false,
          "headline": "feat(live): incremental view maintenance for .live() table queries (#47)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-17T01:52:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e92e695bb3d4974405e5049da8c19f4229ad0c3d",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.30.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T21:13:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "44f581b886c8f621313c412ebc1c68dc83fa57c3",
          "body": "Add per-field expiry to hashes: HEXPIRE/HPEXPIRE/HEXPIREAT/HPEXPIREAT\n(NX/XX/GT/LT), HTTL/HPTTL/HEXPIRETIME/HPEXPIRETIME, HPERSIST, HGETEX,\nHGETDEL. StoreValue::Hash now carries an absolute-ms per-field expiry\nmap; all hash reads filter expired fields and value-setting commands\nclear a field's TTL. \n[…]\no WAL replay is deterministic; the snapshot format gains an 'h' hash\nrecord (backward-compatible with 'H') so TTLs survive save/restore. A\nhash whose last field expires is reclaimed on the next write.",
          "is_bot": false,
          "headline": "feat(hash): implement hash field TTLs (Redis 7.4)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T21:00:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dd733d2e0f55d9cbe53d95dc6b671b1ef415b23c",
          "body": "Models BullMQ's Redis choreography in Rust (no JS/TS): cached-script\n(EVALSHA) add/complete/fail, blocking BRPOPLPUSH wait->active handoff,\nconcurrent exactly-once workers, event stream consumer groups, delayed-job\nzset promotion, and post-workload responsiveness. Exercises the Lua +\nstreams + blocking + multi-connection combination that regressed before.",
          "is_bot": false,
          "headline": "test(bullmq): add BullMQ compatibility regression suite",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T18:16:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f875ebd02bb2233293531ea4847162ea85cd9d04",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.29.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T18:02:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62bc0930f7b7e15f588d1566236d774fd289685e",
          "body": "PUBSUB CHANNELS [pattern] / NUMSUB [channel...] / NUMPAT / HELP read live\nbroker subscription state. SPUBLISH/SSUBSCRIBE/SUNSUBSCRIBE return explicit\nunsupported errors (sharded pub/sub exists for Redis Cluster, which Lux\ndoes not run) rather than unknown-command.",
          "is_bot": false,
          "headline": "feat(pubsub): PUBSUB introspection; reject sharded pub/sub",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T16:59:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e6eac25430207d5d501cd07f877a091cac95b66f",
          "body": "BITFIELD applies GET/SET/INCRBY over arbitrary-width signed/unsigned\nfields at absolute or #-indexed bit offsets, atomically under one lock,\nwith OVERFLOW WRAP (default) / SAT / FAIL. SET returns the prior value,\nINCRBY the new one, FAIL yields nil. BITFIELD_RO permits only GET.\nRaw-logged as a write (keyed at args[1], deterministic on replay).",
          "is_bot": false,
          "headline": "feat(bitmap): implement BITFIELD and BITFIELD_RO",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T16:22:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10dee3adc875428a9fe37913522cc93e61ea18a5",
          "body": "BZMPOP is the blocking ZMPOP: immediate path self-logs the ZREM effect,\nblocked path polls via handle_block_zmpop and logs on wake. ZRANGESTORE\ncomputes a ZRANGE (by index / BYSCORE / BYLEX, REV, LIMIT) from src and\nstores it into dst via write_computed_zset, self-logging DEL+ZADD keyed on\ndst for c\n[…]\nediate-BZPOPMIN/BZPOPMAX durability gap found alongside:\nthe non-blocking pop path popped without logging, so replay resurrected\nthe member. Now self-logs a keyed ZREM (completes the ENG-1317 family).",
          "is_bot": false,
          "headline": "feat(zset): implement BZMPOP and ZRANGESTORE",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T16:03:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1be7fd73374c3ccd9a307c8c36b6e3b2371e0960",
          "body": "LMPOP pops up to COUNT from the first non-empty list among the keys\n(LEFT/RIGHT), self-logging the effect keyed on the popped list so a\nsharded WAL replays it correctly. BLMPOP is the blocking variant (polls,\nlogs on wake). BRPOPLPUSH is BLMOVE src dst RIGHT LEFT, reusing the move\npath incl. its blocked-completion WAL logging.",
          "is_bot": false,
          "headline": "feat(lists): implement LMPOP, BLMPOP, BRPOPLPUSH",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T15:16:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0545090059dc1e7c02fe5c0d52bd1d576f448640",
          "body": "DUMP/RESTORE serialize a value through the snapshot format and round-trip\nwithin Lux (not RDB-compatible); RESTORE re-keys to a caller-chosen key\nwith REPLACE/ABSTTL/TTL. TOUCH returns the existing-key count. MIGRATE and\nWAITAOF return explicit unsupported errors instead of unknown-command,\nsince they conflict with Lux topology/durability. WAIT already returned 0.",
          "is_bot": false,
          "headline": "feat(compat): implement DUMP/RESTORE/TOUCH, reject MIGRATE/WAITAOF",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T15:16:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e76e91779481687e7c76e8f6cb5bed98f22fc6a6",
          "body": "CREATECONSUMER/DELCONSUMER were stubs returning 1/0. Implement real\naccounting: CREATECONSUMER creates the consumer (1 new, 0 existing),\nDELCONSUMER removes it and returns its pending count, dropping those\nentries from the group PEL. Add XGROUP HELP, XINFO CONSUMERS, and reject\nduplicate XGROUP CREATE with BUSYGROUP.",
          "is_bot": false,
          "headline": "feat(streams): real XGROUP consumer lifecycle + XINFO CONSUMERS",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T15:16:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "050af937fed9006bfa67bea558c748de375d395b",
          "body": null,
          "is_bot": false,
          "headline": "chore: bump version to 0.28.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T12:51:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2477f6ca132af17618c6d9651bda74db7e69f62a",
          "body": "…#43)\n\n* fix: correct WAL replay for multi-key writes on sharded WALs\n\nRaw-logging a multi-key command into one WAL shard replays it out of\norder vs the other key's shard. Self-log resolved single-key effects\nkeyed to the right shard: *STORE, LMOVE/RPOPLPUSH, SMOVE, COPY.\n\n* fix: self-log MSET/MSETN\n[…]\ne_block_zpop pops straight from the store outside the WAL, so a\nblocked (or immediate) BZPOP mutated memory without a durable record and\nreplay resurrected the member. Log the removal as a keyed ZREM.",
          "is_bot": false,
          "headline": "fix: correct WAL replay for multi-key and blocked-consumer list ops (…",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T04:03:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "472614042848dc6ccf8ea60ce928177393121fdc",
          "body": "ZRANDMEMBER key [count [WITHSCORES]]: no count returns a single member;\npositive count returns up to N distinct members; negative count returns\n|N| with repeats. Read-only, so no WAL concerns. Selection follows sorted-\nset order, matching the deterministic SRANDMEMBER.",
          "is_bot": false,
          "headline": "feat(zset): add ZRANDMEMBER",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T02:10:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "88d305145dea866680b250c4a9ea96717551d49e",
          "body": "ZMPOP numkeys key [key ...] MIN|MAX [COUNT count] pops from the first\nnon-empty key, reusing ZPOPMIN/ZPOPMAX. It self-logs its effect as a keyed\nZREM: the raw ZMPOP would be WAL-sharded on its numkeys arg (not the key),\nlanding in the wrong shard's WAL and replaying out of order. Covered by a\nfunctional test and a crash-recovery WAL-replay test.",
          "is_bot": false,
          "headline": "feat(zset): add ZMPOP",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T01:48:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cda74f7786e634b23833eb9641efab3460d0a2f1",
          "body": "Direct-return sorted-set set operations alongside the existing *STORE\nvariants, with WEIGHTS/AGGREGATE/WITHSCORES and ZINTERCARD LIMIT. The\nunion/inter/diff compute is factored out of the *STORE handlers and\nshared; this also fixes a latent ZUNIONSTORE bug where AGGREGATE MIN/MAX\nseeded the accumulator with 0.0 instead of the first member's score.",
          "is_bot": false,
          "headline": "feat(zset): add ZUNION, ZINTER, ZDIFF, ZINTERCARD",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T01:14:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "57495472f3678456bcec36802df0ee81e39915ad",
          "body": "A stub returning +OK where a client expects an integer or array silently\ncorrupts client logic. Now:\n- WAIT -> :0 (no replication), COMMAND COUNT -> real registry count\n- SELECT >0 / SWAPDB / DUMP / FUNCTION (non-LIST) -> clear unsupported errors\n- SELECT 0 -> OK; FUNCTION LIST / COMMAND INFO / LATENCY reporting -> correct\n  array shape; LATENCY RESET -> :0; RESET -> +RESET",
          "is_bot": false,
          "headline": "fix(server): honest responses for stub commands instead of fake OK",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-16T00:45:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7875ad59e4339a6f7623a80b665418a1ffef437a",
          "body": "A '*' server-generated timestamp was logged verbatim, so WAL replay\nre-resolved it against the recovery-time clock and the sample landed at a\ndifferent timestamp. Self-log the resolved timestamp, mirroring XADD.",
          "is_bot": false,
          "headline": "fix(timeseries): persist resolved TSADD/TSMADD timestamp to the WAL",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-15T20:24:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0d90b9d122d868599bc57ef3cb5646ee4731edf",
          "body": "SMOVE removed the member from the source before validating the destination\ntype, so a wrong-type dst returned WRONGTYPE with the member already gone.\nValidate the dst type first.\n\nFK cascade/restrict/set-null decoded the child's stored FK bytes as INT\nregardless of the column type, so UUID/FLOAT/STR foreign keys never matched\nand the action silently no-opped. Decode with the column's real field_type.",
          "is_bot": false,
          "headline": "fix: prevent data loss in SMOVE and FK cascade",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-15T20:24:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a14f13292e175a75e8d061ded70b205df3ae3e9f",
          "body": "…, format ref)",
          "is_bot": false,
          "headline": "fix: resolve clippy 1.97 lint errors (values_mut, keys, question_mark…",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-15T19:39:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a4561fe8510b050174ce249fcb55c40fe9f97dd",
          "body": "… 5890",
          "is_bot": false,
          "headline": "docs(readme): reposition as The Application Database; local HTTP port…",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-15T19:00:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d4ba543e288dd20e25c7de3febd7c848103c2971",
          "body": null,
          "is_bot": false,
          "headline": "feat(cli): default ports 5890/5891 and honor LUX_URL for Studio",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-15T19:00:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a94e04e3e5817c74ef2921d45d27f1b0acdf45f6",
          "body": null,
          "is_bot": false,
          "headline": "chore(cli): bump to 0.25.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-14T03:19:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "13018ca54db3558a3ad02a545a7d75744b8cf9f2",
          "body": "Exit 1 when any local migration is pending, so `migrate status` can gate a\nPR / CI job. Default behavior (no --check) is unchanged.",
          "is_bot": false,
          "headline": "feat(cli): `lux migrate status --check` fails on unapplied migrations",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-14T03:19:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "83feeaddab6223a0207696693d6dafdee23b9e82",
          "body": null,
          "is_bot": false,
          "headline": "chore(cli): bump to 0.24.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-14T02:52:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d25bbb94de6060cbb56113566bc6706205d63524",
          "body": "Bare `lux migrate [project]` now applies pending migrations (run is the\ndefault action). get_applied_migrations probes with PING first so an\nunreachable or unauthenticated target errors clearly instead of silently\nreporting everything as pending.",
          "is_bot": false,
          "headline": "feat(cli): implicit `lux migrate` run + surface migrate errors",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-14T02:51:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "74925591e3c3f6a2bd463e6e023ed1fa04982daf",
          "body": null,
          "is_bot": false,
          "headline": "chore(cli): bump to 0.23.0 (non-interactive login)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-08T00:31:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b35f114d0d94abd482eaa7c1fadc39f57185dd2",
          "body": "`lux login <token>` or LUX_TOKEN lets CI/CD authenticate without a prompt\n(e.g. to apply migrations); omitting both keeps the interactive paste flow.",
          "is_bot": false,
          "headline": "feat(cli): non-interactive login via token arg or LUX_TOKEN (#41)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-08T00:24:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4af39b8404b98fd36f0fa3ec0e54c7b68af51744",
          "body": "…] (#40)\n\n* feat(tables): add TSET/TGET point access by primary key\n\nAddress a table row's cells directly by PK without a WHERE query. TSET\nroutes through the same update leaf as TUPDATE (type coercion, FK/unique,\nall index maintenance, per-cell encryption, TTL, WAL self-log), so it is a\ntyped fast \n[…]\nV. Adds an integration test proving point access\nworks with a UUID primary key end to end.\n\n* chore: bump version to 0.27.0\n\n* refactor(sdk): LuxTableRow class instead of returning closures from row()",
          "is_bot": false,
          "headline": "feat: table point access by primary key (TSET/TGET + .row()) [v0.27.0…",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-08T00:20:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4b739018c8a634851d96b2aa3f3b1cfd742d68ee",
          "body": "* fix: multiple grant conditions with different column references\n\n* release: v0.26.2",
          "is_bot": false,
          "headline": "release: v0.26.2",
          "author_name": "coachjackferg",
          "author_login": "coachjackferg",
          "committed_at": "2026-07-07T21:53:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2e2ee99e750ebbdeca1983f002d19bba6e051863",
          "body": "* fix: include null fields in full row serialization\n\n* release: v0.26.1",
          "is_bot": false,
          "headline": "release: v0.26.1",
          "author_name": "coachjackferg",
          "author_login": "coachjackferg",
          "committed_at": "2026-07-07T17:37:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "90a8b7a3e6b578bdd45ddbe7e1e6635c3e02146e",
          "body": "…ning (#37)\n\n* feat(enc): encrypt list elements and stream field values\n\nLPUSH/RPUSH and XADD accept a trailing ENCRYPTED flag (mirroring\nSET/HSET): elements/field-values are sealed as envelopes at rest and\ndecrypted on read. List AAD is key-independent so LMOVE/RPOPLPUSH relocate\nciphertext without\n[…]\n\nit can't regress.\n\n* chore: release engine v0.26.0\n\nEncryption v2 (grant-gated decryption, encrypted lists/streams, encrypted\nvectors) plus the durability/safety hardening from the adversarial audit.",
          "is_bot": false,
          "headline": "release: engine v0.26.0 — encryption v2 + adversarial data-loss harde…",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-06T14:24:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fd52f261c9ad99b2158ac84d3b86aa0070036d3b",
          "body": "* feat(enc): grant-gated decryption for encrypted columns\n\nEncrypted columns now decrypt only for the operator/secret key and real\nauthenticated users; anonymous (signInAnonymously) callers get the column\nomitted from reads. is_anonymous flows from the access token into\nAuthPrincipal (derived from u\n[…]\nsserts operator and real users see the decrypted value\nwhile an anonymous (signInAnonymously) session gets the column omitted but\nstill sees the row. Covers the full token->principal->read-gate chain.",
          "is_bot": false,
          "headline": "feat(enc): grant-gated decryption for encrypted columns (#34)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-05T20:23:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "af1fc237ecfe78d67225cc18ae33f6a07bdd5eaf",
          "body": "Encryption at rest (column + KV envelope encryption, searchable blind\nindex, env-sourced seal) and the `lux enc` CLI / auto-init in lux start.",
          "is_bot": false,
          "headline": "release: engine v0.25.0 + cli v0.22.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-05T18:39:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d7c6cd2b189785de5d898ad46fe23f71739250b4",
          "body": "* feat(enc): encryption at rest with env-sourced seal\n\nEnvelope encryption for table columns and KV values (per-value DEK\nwrapped by keyring keys, AAD bound to table/field/pk), searchable\ncolumns via blind index, and ENC key lifecycle. Seal key sourced from\nLUX_ENC_SEAL_KEY (off the data volume) wit\n[…]\nenc via --project\n\n`lux enc <sub> --project <name|id|url>` proxies ENC to a hosted instance\nusing the CLI's cloud auth (or a direct connection URL); omitting\n--project keeps the local-engine behavior.",
          "is_bot": false,
          "headline": "feat(enc): encryption at rest with env-sourced seal (#32)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-05T18:32:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "dedd3138f33113b7d14b8a3154dc6426b25d0852",
          "body": "* feat: add single modifier to mutation builder",
          "is_bot": false,
          "headline": "release(sdk): v2.8.4",
          "author_name": "coachjackferg",
          "author_login": "coachjackferg",
          "committed_at": "2026-07-03T17:59:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b8618d38293d9da60b722b52c128c3af1b55ade1",
          "body": null,
          "is_bot": false,
          "headline": "release: v0.24.6",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-03T01:19:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed6420dab759c546257091406280996bae728dea",
          "body": "* ci(compat): add Redis compatibility scanner\n\n* revert: remove Redis compatibility scanner\n\n* fix(resp): improve Valkey string command compatibility\n\n* fix(keyspace): align Valkey keyspace compatibility\n\n* fix(streams): support XGROUP SETID\n\n* test(redis): add core parity inventory\n\n* test(redis): \n[…]\ny compatibility recipe\n\n* feat: add auth migration and query parity\n\n* feat: add runtime auth flow settings\n\n* feat(auth): add postmark email delivery\n\n* fix(auth): harden redirects and token handling",
          "is_bot": false,
          "headline": "feat: improve Redis and auth parity (#28)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-07-03T01:16:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "67d741148c540af08d9123b05cc6f2914993264a",
          "body": "* fix: preserve missing aliased projection keys\n\n* feat: support nested and cumulative auth grants\n\n* release: 0.24.5",
          "is_bot": false,
          "headline": "Feat/grant subquery nesting (#29)",
          "author_name": "coachjackferg",
          "author_login": "coachjackferg",
          "committed_at": "2026-07-03T00:48:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e46368cc218ed21988ec1f84596742be6c4ee382",
          "body": null,
          "is_bot": false,
          "headline": "release: v0.24.4",
          "author_name": "Jack Ferguson",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-28T21:50:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "65dd9cf445b887f201dc7f00465b75ca22f4c42c",
          "body": null,
          "is_bot": false,
          "headline": "release(sdk): v2.8.3",
          "author_name": "Jack Ferguson",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-28T21:48:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "60258600097823032126af379f14c3e6d87a4c92",
          "body": "* fix: typed insert, upsert, update, and delete\n\n* fix: type-aware parsing\n\n* fix: clippy errors",
          "is_bot": false,
          "headline": "Fix/typed parsing (#27)",
          "author_name": "coachjackferg",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-28T21:47:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "13ce1367357b6ed5eb1a2b3875d5cbb0972a4af3",
          "body": null,
          "is_bot": false,
          "headline": "test(lua): relax busy script liveness probe",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-28T15:56:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4a7b18eb595b78cb10257ca74362c7869f04a73",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v0.24.3",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-28T15:44:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c17c332b348f20f9b8fad843674a5731a87aa73",
          "body": null,
          "is_bot": false,
          "headline": "test(ci): remove external compat smoke tests",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-28T15:43:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "183e924f0ef890dbfb0ca18398d62b7b0a4ab75e",
          "body": null,
          "is_bot": false,
          "headline": "fix(resp): support Lua scripts in transactions",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-28T15:32:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d3e167764bd7fd65e1175ab2e2227bb43d19323",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v0.24.2",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-25T00:40:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "83a11cf0f28481a03cac05dcee52f09726fb706a",
          "body": "…(SMOVE)\n\nBoth #[ignore]'d so main stays green; un-ignore to fix. FK cascade decodes\nnon-INT FKs as INT (orphaned children); SMOVE removes from src before\nvalidating dst type (data loss).",
          "is_bot": false,
          "headline": "test(audit): quarantined repros for ENG-1278 (FK non-INT) + ENG-1279 …",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-25T00:27:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cc155829e3010a20fc5dc42adc102c3101423cb3",
          "body": "Same root cause as ENG-1276 (XADD *): server-generated value resolved at\nexec time but raw `*` is WAL-logged, so replay picks a new wall-clock ts.\n#[ignore]'d so main stays green; one fix closes both.",
          "is_bot": false,
          "headline": "test(audit): quarantined repro for ENG-1277 (TSADD * replay determinism)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-25T00:13:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d8797d0048dce081a9d479b013d3714101b4c1de",
          "body": "The upsert-on-conflict branch applied the row TTL outside the WAL, and a\nTTL-only upsert (no non-key fields) logged no command at all, so the\nrefreshed deadline was dropped on replay and the row never expired. Route\nthe TTL through the update leaf, carrying a TTL-only refresh on a no-op\nwrite of the conflict column so it is logged and replayed.",
          "is_bot": false,
          "headline": "fix(tables): WAL-log TTL set by an UPSERT on the conflict path",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-24T23:47:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c634041530eb99c24b325deafa18e93d23f8b11",
          "body": "The update path applied a row TTL in the caller, after the leaf, outside\nthe WAL: TUPDATE carried only SET/WHERE. On WAL-only recovery the TTL was\ndropped and the row lived forever. Thread the TTL op into the update leaf\nso it applies and logs as a trailing `TTL <secs>` clause atomically with\nthe row update. Upsert's TTL-on-conflict path is unchanged and still has\nthe same latent gap (follow-up).",
          "is_bot": false,
          "headline": "fix(tables): WAL-log TTL set by an UPDATE so replay preserves it",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-24T23:47:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4d1bd289061cda0e9633c63e94f3105766cbbc76",
          "body": "next_id bumps _t:<table>:seq via a direct, un-WAL'd incr; the id only\nrides inside the replayed TINSERT. On WAL-only recovery the counter\nstayed stale, so the next insert reused an id and silently overwrote a\nrecovered row (INT PK) or lost every row (no-PK table, implicit id was\nrejected as an unknown column). Advance the counter on explicit/replayed\nids and accept the implicit id when no PK is declared.",
          "is_bot": false,
          "headline": "fix(tables): restore auto-increment seq on WAL replay",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-24T23:47:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "142a396db615b0adf949cf533a4aa6f65c93b2d2",
          "body": "feat(sdk): sync cookie session across tabs",
          "is_bot": false,
          "headline": "Merge pull request #26 from lux-db/feat/session-sync",
          "author_name": "coachjackferg",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-23T21:18:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8df270a962287acd8b9b35d443e39beb1dd5131d",
          "body": null,
          "is_bot": false,
          "headline": "release(sdk): v2.8.2",
          "author_name": "Jack Ferguson",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-23T20:54:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fdf357338e3711eebc3c6a5604619684d313a301",
          "body": null,
          "is_bot": false,
          "headline": "feat(sdk): sync cookie session across tabs",
          "author_name": "Jack Ferguson",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-23T20:50:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0b38ba3294523a47dc6ac70b591a87b3483da94",
          "body": "Fix realtime subscriptions for joined tables and auth dependencies",
          "is_bot": false,
          "headline": "fix: realtime subscriptions to joined tables",
          "author_name": "coachjackferg",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-23T18:55:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3bf46ca24aae564c0123c69263c099f3e8f2213d",
          "body": null,
          "is_bot": false,
          "headline": "fix(http): type complexity errors",
          "author_name": "Jack Ferguson",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-23T16:30:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7162e3c33133b003c2956ea9f45e167b584c17c4",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v0.24.1",
          "author_name": "Jack Ferguson",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-23T16:07:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9c6928197e1dd1a7e440e9a5c683d22259e294a1",
          "body": null,
          "is_bot": false,
          "headline": "chore(sdk): bump version",
          "author_name": "Jack Ferguson",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-23T16:03:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa6a803b3e5c28f28db3c027fc76a18a13284785",
          "body": null,
          "is_bot": false,
          "headline": "fix: realtime subscription to joined tables",
          "author_name": "Jack Ferguson",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-23T15:38:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ef1f5efdb3d5f39bee086a83b1ad8c2166144ba",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): sdk-v2.8.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-23T01:49:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0ca9c58ce4c0aa0153a2dacbc5ebf48823a47c75",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): v0.24.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-23T01:48:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b4bb58c769bccc183695e3077b9f9c3b90901a6b",
          "body": "lux.auth.signInAnonymously() POSTs /auth/v1/signin/anonymous and saves\nthe session like signUp. Adds is_anonymous to LuxAuthUser.",
          "is_bot": false,
          "headline": "feat(sdk): signInAnonymously()",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-23T01:47:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9cd7d35338ffdc9d4a0e4eda8fe2d951c3a38a60",
          "body": "POST /auth/v1/signin/anonymous mints a user with no email/password and\nissues a session, so a browser holds a real principal (auth.uid()) for\nRLS-gated reads and .live() without collecting credentials. Flagged via\nraw_app_meta_data.provider=anonymous (no schema column, no migration);\nuser JSON exposes is_anonymous. Gated by auth.anonymous_enabled\n(LUX_AUTH_ANONYMOUS, default on).",
          "is_bot": false,
          "headline": "feat(auth): signInAnonymously for accountless sessions",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-23T01:47:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "30d2b8311a28d698a5de03ae99b340697b58d4fe",
          "body": "VECTOR columns and JSON/ARRAY columns now read back with the same shape\n(arrays/objects) no matter which operation returned them -- select,\nstream, or the insert/update RETURNING echo -- fixing a string-vs-typed\nmismatch that bit on reading back what you just wrote.",
          "is_bot": false,
          "headline": "chore(release): v0.23.1",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-23T01:25:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5433af56d28b602256a588404c3c1343d3e15ee6",
          "body": null,
          "is_bot": false,
          "headline": "test(http): JSON/ARRAY same shape in RETURNING echo as in select",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-23T01:21:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ffe158e4133c96fa0c1f2ff39fedb4f062ef1bbb",
          "body": "config.toml already carried project name + ports; add an engine_version\nkey so a project can pin a specific engine (e.g. 0.23.0) instead of\ntracking :latest. Maps to ghcr.io/lux-db/lux:<version>; re-read each\nstart so editing config.toml takes effect. Blank value falls back to\n:latest.",
          "is_bot": false,
          "headline": "feat(cli): pin local engine version via lux/config.toml",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-23T00:47:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5049f6c31b5d7c5f55ef5058d3ac06060c56215f",
          "body": "Expose the local-engine host ports as flags (shown in lux start --help)\ninstead of config keys you had to discover by grepping the binary. An\nexplicit port is pinned with a clear error if taken; without a flag the\nexisting auto-bump-past-conflict behavior is unchanged.",
          "is_bot": false,
          "headline": "feat(cli): --resp-port / --http-port flags for lux start",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-23T00:40:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "812e76962c9ae130fa3d80c52fa4eecaac6f0f1b",
          "body": "A VECTOR column is stored comma-joined and was emitted as a quoted\nstring (\"1,2,3\"), while lux types generates the column as number[] --\nso reading a vector back through the SDK gave a string, not an array.\nConsolidate the three row-JSON renderers (read, streaming, write\nRETURNING) behind one type-aware field writer that emits VECTOR as\n[1,2,3] and also fixes JSON/ARRAY columns on the RETURNING path.",
          "is_bot": false,
          "headline": "fix(http): render VECTOR columns as JSON arrays, not strings",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-23T00:37:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6c880bf4bbb6c1d591645bc1471b098e302bb048",
          "body": "The _t: reserved-namespace guard (which blocks raw-KV access to auth\ninternal storage -- password hashes, the JWT signing key, OAuth secrets)\nwas only tested on the write path. Add read-path coverage, single and\npipelined, so the protection can't silently regress.",
          "is_bot": false,
          "headline": "test(auth): cover raw-KV read of reserved _t: namespace",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-23T00:11:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6fdb834267aba2d2bb55c711ddbda2e70eb4f302",
          "body": "Security + reliability hardening: snapshot/msgpack fail-closed bounds and\nOOM/crash DoS fixes (found by new fuzzers), Lua sandbox + effects-based\nscript durability, restore V2-header + surgical purge, string-growth caps,\nshard-count validation. Plus GA contract docs and a fuzzing harness.",
          "is_bot": false,
          "headline": "chore(release): v0.23.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0678f50a4c578a143fc96c77e6c314f729840e2c",
          "body": "Scheduled + manual cargo-fuzz over all five decoder targets, time-boxed,\nuploads crash repros on failure. PRs stay gated by the proptest fuzz\ntargets in cargo test; this is the deep continuous pass.",
          "is_bot": false,
          "headline": "ci: nightly coverage-guided fuzzing (cargo-fuzz matrix)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fec2284083111d53916d03e47dd63c1996827095",
          "body": "Add a coverage-guided cargo-fuzz crate (fuzz/) with libfuzzer targets for\nthe snapshot loader, RESP parser, command path, TSELECT parser, and Lua\nmsgpack decoder, driven through a feature-gated fuzz_api module. Seed\ncorpus + FUZZING.md with run commands.\n\nWithin seconds it found two snapshot OOM DoS\n[…]\nound all snapshot pre-allocation by a fixed element\ncap so a lied-about count can't reserve gigabytes; the loop still reads\nreal data and hits EOF. Both inputs kept as corpus seeds + unit regressions.",
          "is_bot": false,
          "headline": "test(fuzz): cargo-fuzz harness; fix snapshot OOM DoS found by it",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3ff345ea3079054ea0fe9c1b062bed01f9053396",
          "body": "Add in-crate proptest fuzz targets (matching the existing disk.rs ones)\nfor the snapshot loader, RESP parser, TSELECT query parser, command\ndispatch, and Lua msgpack decoder -- every untrusted-bytes entrypoint\nthe GA fuzzing gate names. They run on stable in CI.\n\nThe msgpack target immediately found\n[…]\nua as table[nil]=v aborts the\n  process; skip invalid keys instead.\n- unbounded decode recursion could stack-overflow on nested-array markers;\n  cap nesting depth.\nBoth have explicit regression tests.",
          "is_bot": false,
          "headline": "test(fuzz): proptest fuzz targets for all decoders; fix msgpack crashes",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "beb70029557b8d580d42578e69f29d4a07cfc616",
          "body": "Every integration test spawned its server on a hardcoded port and derived\nits data dir from that port, so two tests sharing a port (within or across\nfiles) would fight over the port AND clobber each other's data. That is\nthe bug class behind the earlier crash-test flake.\n\nAdd tests/common/mod.rs wit\n[…]\nuite passes in isolation and parallel-within-binary. A separate,\npre-existing load transient (per-file read .unwrap() under full-suite\nsaturation) rotates across tests and is unrelated to this change.",
          "is_bot": false,
          "headline": "test: shared harness with OS-assigned ports + unique data dirs",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ed303bfd54018695be6c35f6e4cacb18a5aed503",
          "body": "crash_recovery_lua_script_writes reused port 17207, which keys the same\ntemp data dir as rapid_writes_then_crash. Run concurrently they wiped\neach other's data dir and fought over the port, so rapid_writes\nrecovered 0 keys and failed. Move to 17210.",
          "is_bot": false,
          "headline": "test(crash): fix port/data-dir collision in lua crash test",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ebc71e495423bae014eb6465d1aeb127e3356730",
          "body": "GA.md (1.0 release gate), COMPATIBILITY.md (Redis-compat classes +\ndivergences), DURABILITY.md (snapshot/WAL/restore/crash contract), and a\nSecurity Model + Sensitive Surfaces + Resource Exhaustion section in\nSECURITY.md. README links the contract docs. Durability doc describes\nLua effects-replication (writes logged individually, script never\nre-run) and the restricted list is KEYS/FLUSHALL/FLUSHDB/DEBUG to match\nthe engine.",
          "is_bot": false,
          "headline": "docs: add GA/durability/compatibility contracts, expand security",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5cf9352bc85c821765270da5be8a58c3c64bb757",
          "body": "shards=0 made the fx_hash % shards.len() router divide by zero at\nruntime; validate_shard_count rejects 0 and >65536 up front. Also add a\ntest pinning the intended no-password behavior: admin endpoints stay\nreachable (loopback-only instance has no auth boundary anyway), the\ninverse of locking the local operator out.",
          "is_bot": false,
          "headline": "fix(config): reject invalid shard counts; cover no-password admin",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7f556e0ede564a6446bababc97a4dbc136d27d87",
          "body": "A single value could be grown without bound (repeated APPEND, or\nSETRANGE/SETBIT at a huge offset), each call RESP-bounded but the\nrunning total unbounded. Cap the resulting size at the configured\nrequest ceiling so a value can't be ballooned to exhaust memory.",
          "is_bot": false,
          "headline": "fix(strings): cap APPEND/SETRANGE/SETBIT growth at max_resp_request",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8c62106f32f78f4422b96d3d6fda998e14dd437c",
          "body": "redis.call writes went through bare execute, so KV writes from a script\nwere never WAL-logged and a crash lost them. Route through\nexecute_with_wal: KV effects get logged (concrete args -> deterministic\nreplay), table writes still self-log their resolved command, and the\nreserved-key guards now apply to scripts too. Log effects, not the\nscript, so replay never re-runs Lua and can't diverge on a generated PK\nor now() default.",
          "is_bot": false,
          "headline": "fix(lua): make script writes durable via effects logging",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "22387944f0489d143ea6e2c95ff5edaec81ad130",
          "body": "Restore guard accepted only V1 and V3 headers, silently rejecting any\nbackup written while V2 was the format even though load_binary handles\nall three. Also narrow the storage purge to shard_* dirs we own instead\nof nuking the whole storage dir, so a storage.dir misconfigured to\noverlap data_dir can never delete the freshly-written lux.dat.",
          "is_bot": false,
          "headline": "fix(snapshot): accept V2 backups on restore, purge only owned shards",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "703dbb8f8e1958aab54f5af5ae74c4032c09b6eb",
          "body": "Nil out os/io/package/require/load/loadstring/debug/collectgarbage so\nuser scripts can't touch the filesystem, spawn processes, load bytecode,\nor introspect via debug. Split redis.call (raises on error) from\nredis.pcall (returns an error table), and deny admin/control commands\n(SAVE, MULTI, SUBSCRIBE, WATCH, etc.) from scripts. Cap cmsgpack.unpack\ncontainer lengths and never pre-allocate past the remaining input, so a\nhostile length prefix can't drive runaway allocation.",
          "is_bot": false,
          "headline": "feat(lua): sandbox scripts + bound msgpack decoding",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e1865768f27b28dac0d3389ae48fafeebc7325b5",
          "body": "… prefix)\n\nA corrupt or hostile snapshot could drive a huge up-front allocation from an\nattacker-chosen length prefix (Vec::with_capacity / vec![0u8; len]) -> OOM or\npanic during load. Bound every byte-string and collection-count read against\nMAX_SNAPSHOT_BYTES / MAX_SNAPSHOT_ITEMS; over-limit loads are rejected as\nInvalidData. Test crafts huge list-count and byte-string prefixes and asserts a\nclean rejection. (Re-authored from the adversarial GA audit; Data-Safety gate.)",
          "is_bot": false,
          "headline": "fix(snapshot): fail-closed bounds on load (no OOM from corrupt length…",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T23:24:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1800a8711dd35b9f6953bdd1e242055d18acca26",
          "body": "* fix: improve browser sdk\n\n* chore(sdk): bump version to 2.7.0\n\n* feat(sdk): session cookie chunking",
          "is_bot": false,
          "headline": "fix(sdk): improve browser sdk (#22)",
          "author_name": "coachjackferg",
          "author_login": "coachjackferg",
          "committed_at": "2026-06-22T19:48:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f02e255a9ddc525da7449ef081a7ce075e153952",
          "body": "Toward airtight-without-locks: the index is advisory and reads already\nre-validate against the authoritative row, so harden the write side to match.\n\n- Insert now commits the row hash LAST, after :ids/indexes/uniq/vector/TTL.\n  A reader that sees a reach-structure pointing at an uncommitted row re-f\n[…]\nss check is read-validated: only reject when a LIVE row genuinely\n  still holds the value; a stale uniq entry (holder gone / value changed) is\n  dropped and the insert allowed -- no false 'duplicate'.",
          "is_bot": false,
          "headline": "feat(tables): atomic row commit + read-validated uniqueness",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T03:27:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a82b7ea5de0106a768ad0937d29a6d10d7ccce1c",
          "body": "…pdate\n\nevict_key dropped the shard lock between serializing a key to disk and\nremoving it from memory. A concurrent write in that window updated the key to\na new value, which the unconditional remove then discarded -- the key reverted\nto its pre-eviction value and the update was lost (and made dura\n[…]\nusly across the disk write and the\nremoval so the serialized entry is exactly the one removed. Lock order is\nshard->disk; try_promote releases its disk lock before taking a shard lock, so\nno deadlock.",
          "is_bot": false,
          "headline": "fix(eviction): hold shard lock across evict-to-disk to prevent lost u…",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T03:07:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a50bc0cdb7edb79ba83745d1d650ea24414a917d",
          "body": "A VECTOR column stores its embedding in a side key (_t:{t}:vec:{col}:{pk}) with\nits own ANN index, but table_delete_inner and table_drop never removed it. So\ndeleting a row or dropping a table left orphaned vectors: search kept returning\nthem and they leaked. Delete the vector side key (which also clears its index)\nin both paths.",
          "is_bot": false,
          "headline": "fix(tables): clean vector index on row delete + table drop",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T02:56:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7705a8eb1d6517568d04b2d3435b3a60d74cc6af",
          "body": "V2 snapshots stored remaining-ms and rebased it to load time, so a TTL'd key\npaused across downtime and a key that should have expired while the process was\ndown came back alive (and sub-ms-remaining keys became immortal). Snapshot\nformat V3 stores an absolute epoch-ms deadline; load subtracts elaps\n[…]\ns RDB (absolute expiry) and Lux's own\nrow TTLs.\n\nNote: the cold disk tier and WAL replay still use relative TTLs (bounded by the\nsnapshot interval, since SAVE truncates the WAL) -- separate follow-up.",
          "is_bot": false,
          "headline": "fix(snapshot): persist key TTLs as absolute deadlines (V3)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T02:51:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c8f9de91763d87f6108e4217aac930dc586aba9a",
          "body": "Table data writes are now logged from the table layer as a RESOLVED command\n(explicit generated PK + resolved now()/defaults), and execute_with_wal no\nlonger raw-logs T-commands. Two bugs fixed at once:\n\n- HTTP table writes (browser SDK + cloud project client) bypassed\n  execute_with_wal and were ne\n[…]\nch writes with no\ndouble-apply. WAL is tiered-mode only (production default); memory mode stays\nsnapshot-only. Un-ignores wal_replay_preserves_autogenerated_uuid_pk; all 13\ncrash-recovery tests green.",
          "is_bot": false,
          "headline": "fix(wal): durable, deterministic table writes (resolved-command WAL)",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T02:41:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8a536782a49555d594e21f909833a0237181bb26",
          "body": "- eviction: never permanently evict reserved _t:* table/auth/ttl keys in\n  memory mode (allkeys-* could silently corrupt tables / lose rows); tiered\n  mode is unaffected (evict-to-disk is fault-safe).\n- TDROP: clear each row's _t:_ttl deadline so a dropped table's stale entry\n  can't expire a re-cre\n[…]\nhe auth API.\n\nAdds crash-recovery + regression tests. Known issue documented (ignored test):\nWAL replay regenerates uuid()/now() values (PK identity changes); fix-forward\nby logging resolved commands.",
          "is_bot": false,
          "headline": "fix(engine): reliability hardening from data-loss audit",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-22T00:00:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4ac649777043bcca2c22ac6b6d4721f54143b884",
          "body": null,
          "is_bot": false,
          "headline": "chore: release engine v0.22.0",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-21T23:12:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fd69ff048444d6c7cbaa3320c5a9e15168d4a28c",
          "body": "TINSERT/TUPSERT/TUPDATE accept TTL <secs> (and HTTP ?ttl=); rows auto-expire\nand fire a .live() delete (RLS-gated) via a table-aware sweep. TTL 0 clears;\nbare writes keep the deadline; TCREATE ... WITH TTL sets a per-table default.\nSDK gains a { ttl } option on insert/upsert (2.6.0).",
          "is_bot": false,
          "headline": "feat(tables): row TTL with realtime expiry",
          "author_name": "Matty Hogan",
          "author_login": "mattyhogan",
          "committed_at": "2026-06-21T23:08:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 99,
      "commits_last_year": 359,
      "latest_release_at": "2026-07-19T21:29:40Z",
      "latest_release_tag": "cli-v0.26.1",
      "releases_from_tags": false,
      "days_since_last_push": 4,
      "active_weeks_last_year": 16,
      "days_since_latest_release": 4,
      "mean_days_between_releases": 0.6
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 75,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "lux",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "crates",
          "matches_repo": null,
          "registry_url": "https://crates.io/crates/lux",
          "is_deprecated": false,
          "latest_version": "0.1.2",
          "repository_url": null,
          "versions_count": 7,
          "total_downloads": 27898,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 16,
          "first_published_at": "2014-11-20T20:41:03.548117Z",
          "latest_published_at": "2016-09-01T20:32:53.257034Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 3612
        },
        {
          "name": "lux-cli",
          "exists": true,
          "license": "LGPL-3.0+",
          "keywords": [
            "lua",
            "neovim",
            "build",
            "packagemanager",
            "luarocks",
            "command-line-utilities",
            "development-tools"
          ],
          "ecosystem": "crates",
          "matches_repo": false,
          "registry_url": "https://crates.io/crates/lux-cli",
          "is_deprecated": false,
          "latest_version": "0.39.2",
          "repository_url": "https://github.com/lumen-oss/lux",
          "versions_count": 155,
          "total_downloads": 37792,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 543,
          "first_published_at": "2025-02-18T21:40:45.243646Z",
          "latest_published_at": "2026-07-22T18:31:19.689461Z",
          "latest_version_yanked": false,
          "days_since_latest_publish": 1
        },
        {
          "name": "@luxdb/sdk",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "lux",
            "database",
            "application-database",
            "auth",
            "tables",
            "vectors",
            "realtime",
            "redis",
            "cache",
            "queues",
            "timeseries"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@luxdb/sdk",
          "is_deprecated": false,
          "latest_version": "2.10.0",
          "repository_url": "https://github.com/lux-db/lux",
          "versions_count": 25,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2237,
          "first_published_at": "2026-03-11T23:26:59.401000Z",
          "latest_published_at": "2026-07-18T15:21:00.428000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 21,
      "stars": 272,
      "watchers": 2,
      "fork_history": {
        "days": [
          {
            "date": "2026-03-15",
            "count": 4
          },
          {
            "date": "2026-03-16",
            "count": 5
          },
          {
            "date": "2026-03-19",
            "count": 1
          },
          {
            "date": "2026-03-20",
            "count": 1
          },
          {
            "date": "2026-03-21",
            "count": 1
          },
          {
            "date": "2026-03-22",
            "count": 3
          },
          {
            "date": "2026-03-23",
            "count": 1
          },
          {
            "date": "2026-05-09",
            "count": 1
          },
          {
            "date": "2026-05-23",
            "count": 1
          },
          {
            "date": "2026-06-06",
            "count": 1
          },
          {
            "date": "2026-06-17",
            "count": 1
          },
          {
            "date": "2026-06-22",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 21,
        "total_forks": 21
      },
      "star_history": null,
      "open_issues_and_prs": 5
    },
    "ai_readiness": {
      "has_nix": true,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Justfile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "sdk/tsconfig.json"
      ],
      "toolchain_manifests": [
        "Cargo.toml",
        "cli/Cargo.toml",
        "fuzz/Cargo.toml"
      ],
      "largest_source_bytes": 291115,
      "source_files_sampled": 112,
      "oversized_source_files": 12,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "Cargo.toml",
        "cli/Cargo.toml",
        "fuzz/Cargo.toml",
        "sdk/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates",
        "npm"
      ],
      "dependencies": [
        {
          "name": "tokio",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "rayon",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "bytes",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "base64",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.22"
        },
        {
          "name": "futures-util",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.3"
        },
        {
          "name": "parking_lot",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "hashbrown",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.14"
        },
        {
          "name": "ordered-float",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "4"
        },
        {
          "name": "mlua",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.10"
        },
        {
          "name": "sha1_smol",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "rmp",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.8"
        },
        {
          "name": "serde_json",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "tokio-tungstenite",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.24"
        },
        {
          "name": "argon2",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.5"
        },
        {
          "name": "bcrypt",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.17"
        },
        {
          "name": "jsonwebtoken",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "10"
        },
        {
          "name": "p256",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.13"
        },
        {
          "name": "rand_core",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.6"
        },
        {
          "name": "serde",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "sha2",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.10"
        },
        {
          "name": "ring",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.17"
        },
        {
          "name": "reqwest",
          "manifest": "Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "clap",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "4"
        },
        {
          "name": "reqwest",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.12"
        },
        {
          "name": "rustls",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.23"
        },
        {
          "name": "serde",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "serde_json",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "tokio",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "1"
        },
        {
          "name": "dirs",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "6"
        },
        {
          "name": "colored",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "3"
        },
        {
          "name": "open",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "5"
        },
        {
          "name": "chrono",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.4"
        },
        {
          "name": "webpki-roots",
          "manifest": "cli/Cargo.toml",
          "ecosystem": "crates",
          "version_constraint": "0.26"
        },
        {
          "name": "ioredis",
          "manifest": "sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^5.0.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 4,
        "merged_prs": 32,
        "open_issues": 1,
        "closed_ratio": 0.857,
        "closed_issues": 6,
        "closed_unmerged_prs": 8
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "mattyhogan",
          "commits": 338,
          "avatar_url": "https://avatars.githubusercontent.com/u/67698941?v=4"
        },
        {
          "type": "User",
          "login": "coachjackferg",
          "commits": 16,
          "avatar_url": "https://avatars.githubusercontent.com/u/133680445?v=4"
        },
        {
          "type": "User",
          "login": "only-cliches",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/14365337?v=4"
        },
        {
          "type": "User",
          "login": "skorotkiewicz",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/899351?v=4"
        },
        {
          "type": "User",
          "login": "neutralinsomniac",
          "commits": 1,
          "avatar_url": "https://avatars.githubusercontent.com/u/92071?v=4"
        }
      ],
      "contributors_sampled": 5,
      "top_contributor_share": 0.942
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "cli.yml",
        "docker.yml",
        "fuzz.yml",
        "publish-sdk.yml",
        "release.yml",
        "test.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": null,
            "reason": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 10,
            "reason": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 10,
            "reason": "project is fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 2,
            "reason": "8 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "5d72ef9c35176922d780d46eeb3c86c86fe6149d",
        "ran_at": "2026-07-23T23:17:36Z",
        "aggregate_score": 4.8,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T08:18:56Z",
      "oldest_open_prs": [
        {
          "number": 20,
          "created_at": "2026-05-31T04:21:00Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 25,
          "created_at": "2026-06-23T18:41:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 35,
          "created_at": "2026-07-05T21:25:03Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 36,
          "created_at": "2026-07-05T23:17:54Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-19T21:49:01Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 21,
          "created_at": "2026-06-01T06:36:19Z",
          "last_comment_at": "2026-06-08T05:51:47Z",
          "last_comment_author": "only-cliches"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/lux-db/lux",
    "host": "github.com",
    "name": "lux",
    "owner": "lux-db"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 63,
      "inputs": {
        "security": 49,
        "vitality": 81,
        "community": 58,
        "governance": 54,
        "engineering": 71
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 81,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "commits_last_year": 359,
              "human_commit_share": 1,
              "days_since_last_push": 4,
              "active_weeks_last_year": 16
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "16/52 weeks with commits",
                "points": 11.1,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 16
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "359 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 359
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 99,
              "latest_release_tag": "cli-v0.26.1",
              "releases_from_tags": false,
              "days_since_latest_release": 4,
              "mean_days_between_releases": 0.6
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "99 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 99
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.6 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.6
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 58,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "moderate",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "forks": 21,
              "stars": 272,
              "watchers": 2,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "272 stars",
                "points": 39.5,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 272
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "21 forks",
                "points": 10.8,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 21
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "2 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 56,
            "inputs": {
              "packages": [
                "lux",
                "@luxdb/sdk"
              ],
              "dependents": null,
              "ecosystems": "crates, npm",
              "total_downloads": 27898,
              "monthly_downloads": 2253
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,253 downloads/month across crates, npm",
                "points": 44.7,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2253,
                      "ecosystems": "crates, npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 54,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 5,
              "top_contributor_share": 0.942
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 94% of commits",
                "points": 1.3,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 94
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "5 contributors",
                "points": 6.8,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 71,
            "inputs": {
              "merged_prs": 32,
              "open_issues": 1,
              "closed_issues": 6,
              "issue_closed_ratio": 0.857,
              "closed_unmerged_prs": 8
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "86% of issues closed",
                "points": 40.1,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 86
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "32/40 decided PRs merged",
                "points": 30.6,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 32,
                      "decided": 40
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 39,
            "inputs": {
              "followers": 4,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "lux-db",
              "public_repos": 2,
              "account_age_days": 130
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "4 followers of lux-db",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 4,
                      "login": "lux-db"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "2 public repos, account ~0 yr old",
                "points": 4.2,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 2
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "lux",
                "@luxdb/sdk"
              ],
              "ecosystems": "crates, npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "2 package(s) on crates, npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 2,
                      "ecosystems": "crates, npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "25 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 25
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 71,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 68,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "6 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [
                "lux",
                "redis",
                "database",
                "embeddings",
                "rust",
                "vector",
                "dragonflydb",
                "postgres",
                "supabase"
              ],
              "has_wiki": true,
              "homepage": "https://luxdb.dev",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://luxdb.dev",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "9 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 9
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 49,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Branch-Protection. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "branch_protection"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 49,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 4.8
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "7 out of 7 merged PRs checked by a CI test -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is fuzzed",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "8 existing vulnerabilities detected",
                "points": 1.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 3
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 59,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 1,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 100,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 61,
            "inputs": {
              "has_nix": true,
              "has_tests": true,
              "lockfiles": [
                "Cargo.lock"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "Justfile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "sdk/tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "Cargo.toml",
                "cli/Cargo.toml",
                "fuzz/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Justfile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Justfile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "sdk/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "sdk/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, Nix, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, Nix, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 94,
            "inputs": {
              "primary_language": "Rust",
              "largest_source_bytes": 291115,
              "source_files_sampled": 112,
              "oversized_source_files": 12
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Rust (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "12/112 source files over 60KB",
                "points": 49.1,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 112,
                      "oversized": 12
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "crates package 'lux-cli' points at a different repository (https://github.com/lumen-oss/lux); excluded from ecosystem scoring",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T23:17:47.829665Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/l/lux-db/lux.svg",
  "full_name": "lux-db/lux",
  "license_state": "standard",
  "license_spdx": "MIT"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计crates.io, npm.