公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-23 20:36 UTC

midnightcoderagent / Midnight-Coder

AI coding agent built for local LLMs. Fast, lightweight, and designed for Ollama, llama.cpp, and LM Studio.

RustApache-2.0★ 0 星标⑂ 0 复刻始于 2026年7月在 GitHub 上查看 ↗

midnightcoderagent/Midnight-Coder 的健康指数为 100 分中的 65 分,处于「中等」区间。 其得分最高的类别是Vitality(93/100),最低的是Community & Adoption(42/100)。 最近一次更新在 5 天前。 近期的大部分工作由 5 位贡献者完成。

65
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

65
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

midnightcoderagent个人账户
0 关注者4 个公开仓库始于 2026年7月

该仓库由个人账户拥有。相较于组织支持的项目,单一所有者项目的延续性风险更高。

软件包生态系统

注册表软件包版本月下载量版本数最近发布
npmmidnight-coder1.0.52,714235 天前

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

93优秀 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 5 天前
36/36提交节奏 — 52 周中有 52 周有提交
18/18提交量 — 最近一年 7,398 次提交
0/10OpenSSF Scorecard:Maintained — project was created within the last 90 days. Please review its contents carefully
所用输入
commits_last_year7,398
human_commit_share1
days_since_last_push5
active_weeks_last_year52

发布纪律

98优秀
评分方式
27/27有发布版本 — 已发布 5 个发布版本
36/36发布时效 — 最近一次发布版本于 5 天前
27/27发布节奏 — 约每 2.5 天发布一次
8/10OpenSSF Scorecard:Signed-Releases — 5 out of the last 5 releases have a total of 5 signed artifacts.
所用输入
releases_count5
latest_release_tagrust-v1.0.5
releases_from_tags
days_since_latest_release5
mean_days_between_releases2.5

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

42存在风险 · 占总体的 18%
评分方式
0/60星标 — 0 个星标
0/25复刻 — 0 个复刻
0/15关注者 — 0 位关注者
所用输入
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

77良好
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(Apache-2.0)
18/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
6.3/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
45.8/80月度下载量 — npm 合计每月 2,714 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packagesmidnight-coder
dependents
ecosystemsnpm
total_downloads
monthly_downloads2,714
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

51中等 · 占总体的 24%
评分方式
45.9/54巴士系数 — 5 位贡献者贡献了半数提交
18.9/22.5提交分布 — 头号贡献者编写了 16% 的提交
13.5/13.5贡献者广度 — 98 位贡献者
10/10OpenSSF Scorecard:Contributors — project has 3 contributing companies or organizations -- score normalized to 10
所用输入
bus_factor5
contributors_sampled98
top_contributor_share0.161
评分方式
0/46.8议题解决 — 没有议题或无数据
0/38.3PR 接受 — 已裁定的 PR 中 0/2 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/30 approved changesets -- score normalized to 0
所用输入
merged_prs0
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs2
已排除计分(无数据或不适用):议题解决。 其余权重已重新归一化。
评分方式
10/30所有权背书 — 个人(用户)账户
0/20已验证域名 — 不适用于个人账户
0/25所有者影响力 — midnightcoderagent 有 0 位关注者
5.2/25既往记录 — 4 个公开仓库,账户约 0 年
所用输入
followers0
owner_typeUser
is_verified
owner_loginmidnightcoderagent
public_repos4
account_age_days20
已排除计分(无数据或不适用):已验证域名。 其余权重已重新归一化。
评分方式
25/25已发布且可解析 — npm 上有 1 个软件包
35/35发布时效 — 最近一次发布于 5 天前
20/20版本历史 — 23 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesmidnight-coder
ecosystemsnpm
any_deprecated
min_days_since_publish5

工程质量

基础的工程与文档实践是否到位?

83良好 · 占总体的 20%

工程实践

88优秀
评分方式
24/24CI 工作流 — 26 个工作流
24/24存在测试
16/16Linter 配置 — eslint.config.js
0/9.6Pre-commit 钩子
6.4/6.4.editorconfig
0/20OpenSSF Scorecard:CI-Tests — 无数据
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config
已排除计分(无数据或不适用):OpenSSF Scorecard:CI-Tests。 其余权重已重新归一化。

文档

75良好
评分方式
30/30README
25/25文档目录
0/15文档 / 主页站点
10/10仓库描述
0/10主题标签
10/10Wiki
所用输入
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

49存在风险 · 占总体的 16%

安全态势

49存在风险
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — 无数据
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 3 contributing companies or organizations -- score normalized to 10
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
5/5Packaging — packaging workflow detected
4.5/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
0/5SAST — no SAST tool detected
5/5Security-Policy — security policy file detected
6/7.5Signed-Releases — 5 out of the last 5 releases have a total of 5 signed artifacts.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 67 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate4.9
已排除计分(无数据或不适用):ci_tests。 其余权重已重新归一化。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

89优秀 · 占总体的 0%
评分方式
45/45代理指令 — AGENTS.md, codex-rs/tui/src/bottom_pane/AGENTS.md
0/15机器可读文档(llms.txt)
37.9/40可读的提交历史 — 100 次人类提交中有 71 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.71
agent_instruction_filesAGENTS.md, codex-rs/tui/src/bottom_pane/AGENTS.md
agent_instruction_max_bytes23,188
评分方式
18/18一条命令的引导启动 — justfile
22/22自动化测试
11/11Lint / 格式化配置 — eslint.config.js
11/11静态类型检查 — sdk/python/src/openai_codex/py.typed, sdk/typescript/tsconfig.json
10/10可复现环境 — devcontainer, Dockerfile, Nix, lockfile
0/10已体现的代理实践 — 最近 100 次提交中没有代理编写的提交
5/8自动化维护 — 已配置依赖自动化,但在抽样提交中未观察到
9/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 9
所用输入
has_nix
has_tests
lockfilesCargo.lock, pnpm-lock.yaml, uv.lock
has_dockerfile
typed_language
bootstrap_filesjustfile
has_devcontainer
has_linter_config
typecheck_configssdk/python/src/openai_codex/py.typed, sdk/typescript/tsconfig.json
agent_commit_share0
toolchain_manifestscodex-rs/Cargo.toml, codex-rs/agent-graph-store/Cargo.toml, codex-rs/agent-identity/Cargo.toml, codex-rs/analytics/Cargo.toml, codex-rs/ansi-escape/Cargo.toml, codex-rs/app-server-client/Cargo.toml, codex-rs/app-server-daemon/Cargo.toml, codex-rs/app-server-protocol/Cargo.toml, codex-rs/app-server-test-client/Cargo.toml, codex-rs/app-server-transport/Cargo.toml, codex-rs/app-server/Cargo.toml, codex-rs/app-server/tests/common/Cargo.toml, codex-rs/apply-patch/Cargo.toml, codex-rs/arg0/Cargo.toml, codex-rs/async-utils/Cargo.toml, codex-rs/aws-auth/Cargo.toml, codex-rs/backend-client/Cargo.toml, codex-rs/bwrap/Cargo.toml, codex-rs/chatgpt/Cargo.toml, codex-rs/cli/Cargo.toml, codex-rs/cloud-config/Cargo.toml, codex-rs/cloud-tasks-client/Cargo.toml, codex-rs/cloud-tasks-mock-client/Cargo.toml, codex-rs/cloud-tasks/Cargo.toml, codex-rs/code-mode-host/Cargo.toml, codex-rs/code-mode-protocol/Cargo.toml, codex-rs/code-mode/Cargo.toml, codex-rs/codex-api/Cargo.toml, codex-rs/codex-backend-openapi-models/Cargo.toml, codex-rs/codex-client/Cargo.toml, codex-rs/codex-experimental-api-macros/Cargo.toml, codex-rs/codex-home/Cargo.toml, codex-rs/codex-mcp/Cargo.toml, codex-rs/collaboration-mode-templates/Cargo.toml, codex-rs/config/Cargo.toml, codex-rs/connectors/Cargo.toml, codex-rs/context-fragments/Cargo.toml, codex-rs/core-api/Cargo.toml, codex-rs/core-plugins/Cargo.toml, codex-rs/core-skills/Cargo.toml, codex-rs/core/Cargo.toml, codex-rs/core/tests/common/Cargo.toml, codex-rs/exec-server-protocol/Cargo.toml, codex-rs/exec-server/Cargo.toml, codex-rs/exec/Cargo.toml, codex-rs/execpolicy-legacy/Cargo.toml, codex-rs/execpolicy/Cargo.toml, codex-rs/ext/connectors/Cargo.toml, codex-rs/ext/extension-api/Cargo.toml, codex-rs/ext/goal/Cargo.toml, codex-rs/ext/guardian/Cargo.toml, codex-rs/ext/image-generation/Cargo.toml, codex-rs/ext/mcp/Cargo.toml, codex-rs/ext/memories/Cargo.toml, codex-rs/ext/skills/Cargo.toml, codex-rs/ext/web-search/Cargo.toml, codex-rs/external-agent-migration/Cargo.toml, codex-rs/external-agent-sessions/Cargo.toml, codex-rs/features/Cargo.toml, codex-rs/feedback/Cargo.toml, codex-rs/file-search/Cargo.toml, codex-rs/file-system/Cargo.toml, codex-rs/file-watcher/Cargo.toml, codex-rs/git-utils/Cargo.toml, codex-rs/hooks/Cargo.toml, codex-rs/install-context/Cargo.toml, codex-rs/keyring-store/Cargo.toml, codex-rs/linux-sandbox/Cargo.toml, codex-rs/lmstudio/Cargo.toml, codex-rs/login/Cargo.toml, codex-rs/mcp-server/Cargo.toml, codex-rs/mcp-server/tests/common/Cargo.toml, codex-rs/memories/read/Cargo.toml, codex-rs/memories/write/Cargo.toml, codex-rs/message-history/Cargo.toml, codex-rs/model-provider-info/Cargo.toml, codex-rs/model-provider/Cargo.toml, codex-rs/models-manager/Cargo.toml, codex-rs/network-proxy/Cargo.toml, codex-rs/ollama/Cargo.toml, codex-rs/otel/Cargo.toml, codex-rs/plugin/Cargo.toml, codex-rs/process-hardening/Cargo.toml, codex-rs/prompts/Cargo.toml, codex-rs/protocol/Cargo.toml, codex-rs/realtime-webrtc/Cargo.toml, codex-rs/response-debug-context/Cargo.toml, codex-rs/responses-api-proxy/Cargo.toml, codex-rs/rmcp-client/Cargo.toml, codex-rs/rollout-trace/Cargo.toml, codex-rs/rollout/Cargo.toml, codex-rs/sandboxing/Cargo.toml, codex-rs/secrets/Cargo.toml, codex-rs/shell-command/Cargo.toml, codex-rs/shell-escalation/Cargo.toml, codex-rs/skills/Cargo.toml, codex-rs/state/Cargo.toml, codex-rs/stdio-to-uds/Cargo.toml, codex-rs/terminal-detection/Cargo.toml, codex-rs/test-binary-support/Cargo.toml, codex-rs/thread-manager-sample/Cargo.toml, codex-rs/thread-store/Cargo.toml, codex-rs/tools/Cargo.toml, codex-rs/tui/Cargo.toml, codex-rs/uds/Cargo.toml, codex-rs/utils/absolute-path/Cargo.toml, codex-rs/utils/approval-presets/Cargo.toml, codex-rs/utils/cache/Cargo.toml, codex-rs/utils/cargo-bin/Cargo.toml, codex-rs/utils/cli/Cargo.toml, codex-rs/utils/elapsed/Cargo.toml, codex-rs/utils/fuzzy-match/Cargo.toml, codex-rs/utils/home-dir/Cargo.toml, codex-rs/utils/image/Cargo.toml, codex-rs/utils/json-to-toml/Cargo.toml, codex-rs/utils/oss/Cargo.toml, codex-rs/utils/output-truncation/Cargo.toml, codex-rs/utils/path-uri/Cargo.toml, codex-rs/utils/path-utils/Cargo.toml, codex-rs/utils/plugins/Cargo.toml, codex-rs/utils/pty/Cargo.toml, codex-rs/utils/readiness/Cargo.toml, codex-rs/utils/rustls-provider/Cargo.toml, codex-rs/utils/sandbox-summary/Cargo.toml, codex-rs/utils/sleep-inhibitor/Cargo.toml, codex-rs/utils/stream-parser/Cargo.toml, codex-rs/utils/string/Cargo.toml, codex-rs/utils/template/Cargo.toml, codex-rs/v8-poc/Cargo.toml, codex-rs/windows-sandbox-rs/Cargo.toml, tools/argument-comment-lint/Cargo.toml
dependency_bot_commit_share0
评分方式
45/45可类型检查的代码 — Rust(静态类型)
52.9/55可控的文件大小 — 采样的 3,213 个源文件中有 120 个超过 60KB
所用输入
primary_languageRust
largest_source_bytes438,946
source_files_sampled3,213
oversized_source_files120
评分方式
40/40API 模式(OpenAPI/GraphQL/proto) — codex-rs/config/src/thread_config/proto/codex.thread_config.v1.proto, codex-rs/exec-server/src/proto/codex.exec_server.relay.v1.proto
20/20MCP 服务器
40/40可运行示例 — demos, examples, notebooks, samples
所用输入
example_dirsdemos, examples, notebooks, samples
has_mcp_signal
api_schema_filescodex-rs/config/src/thread_config/proto/codex.thread_config.v1.proto, codex-rs/exec-server/src/proto/codex.exec_server.relay.v1.proto

关键数据

0GitHub 星标
98贡献者
7,398最近 12 个月提交数
5距最近推送天数
5发布版本数
5巴士系数(bus factor)
0开放议题
crates.io, npm, PyPI软件包生态系统数

数据采集警告

  • Could not fetch pypi package 'codex-scripts' from its registry
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index npm:midnight-coder@1.0.5; advisories assessed against the repository dependency graph instead

更多细节

OpenSSF Scorecard 4.9 / 10
4.9综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-23 20:36 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
不适用CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
10Contributorsproject has 3 contributing companies or organizations -- score normalized to 10
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
10Packagingpackaging workflow detected
9Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 9
0SASTno SAST tool detected
10Security-Policysecurity policy file detected
8Signed-Releases5 out of the last 5 releases have a total of 5 signed artifacts.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities67 existing vulnerabilities detected
直接依赖 1
注册表软件包版本约束清单文件
PyPIruff>=0.15.8scripts/pyproject.toml
全部依赖 未采集

本报告未能采集到解析后的依赖集合:GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 336718,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "C": 62,
        "Nix": 4574,
        "HTML": 19419,
        "Just": 6434,
        "Rust": 39533825,
        "Shell": 60756,
        "Python": 1097662,
        "Smarty": 5982,
        "Starlark": 91712,
        "Dockerfile": 910,
        "JavaScript": 30631,
        "PowerShell": 50911,
        "TypeScript": 90119,
        "Jupyter Notebook": 21368
      },
      "pushed_at": "2026-07-18T11:47:53Z",
      "created_at": "2026-07-03T02:27:01Z",
      "owner_type": "User",
      "updated_at": "2026-07-18T11:47:56Z",
      "description": "AI coding agent built for local LLMs. Fast, lightweight, and designed for Ollama, llama.cpp, and LM Studio.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Rust",
      "significant_languages": [
        "Rust"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "User",
      "login": "midnightcoderagent",
      "company": null,
      "location": null,
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/299350851?v=4",
      "created_at": "2026-07-03T02:22:31Z",
      "is_verified": null,
      "public_repos": 4,
      "account_age_days": 20
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "rust-v1.0.5",
          "kind": "other",
          "published_at": "2026-07-18T12:52:59Z"
        },
        {
          "tag": "rust-v1.0.4",
          "kind": "other",
          "published_at": "2026-07-15T17:19:17Z"
        },
        {
          "tag": "rust-v1.0.1",
          "kind": "other",
          "published_at": "2026-07-13T03:32:06Z"
        },
        {
          "tag": "rust-v1.0.0",
          "kind": "other",
          "published_at": "2026-07-08T19:34:41Z"
        },
        {
          "tag": "rust-v0.1.0-alpha.6",
          "kind": "other",
          "published_at": "2026-07-08T12:01:54Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "9acdc15a545f3d6a66379835d7be798de6899a38",
          "body": null,
          "is_bot": false,
          "headline": "Document smartcontext and monitor status line",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-18T11:47:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "930820bec96abb6a73c516394c53d356ba427fae",
          "body": null,
          "is_bot": false,
          "headline": "Release 1.0.5 with monitor status line",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-18T11:21:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f3bde5631558f6c6cf03b22f6fc254b27256da1",
          "body": null,
          "is_bot": false,
          "headline": "Release 1.0.4 for Linux Windows Android npm",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-15T15:43:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e15fd0d2025b3fe4f15e30cea32e3fc188f65af1",
          "body": null,
          "is_bot": false,
          "headline": "Release 1.0.3 with cross-platform npm builds",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-15T13:57:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9a5bc4c9e55955f590c537256ebd076f7d31f53d",
          "body": null,
          "is_bot": false,
          "headline": "Use hosted Windows runners for release builds",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-15T10:54:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4501a2f2a70f32434da16b584c0efe6be34b584f",
          "body": null,
          "is_bot": false,
          "headline": "Release 1.0.2 and expand npm platforms",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-14T20:37:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2c1d42c3062ea94a8d3b250ac0b6793a39fc9f84",
          "body": null,
          "is_bot": false,
          "headline": "Release Midnight Coder 1.0.1",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-12T13:53:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "723ff6dfff42dc049cf19334d7b93d260ad3ccf0",
          "body": null,
          "is_bot": false,
          "headline": "Prepare Midnight Coder 1.0.0 release",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-08T18:42:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f7bc39a190f62b0e1747a54e13905225e0e43f30",
          "body": null,
          "is_bot": false,
          "headline": "Fix npm latest dist-tag",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-08T17:26:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f84ebb9271cc6819e06d101d016d42cf5dc493b3",
          "body": null,
          "is_bot": false,
          "headline": "Remove non-npm release publish jobs",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-08T14:49:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f454eb25485cb53226d0a17df0a1b99536649c45",
          "body": null,
          "is_bot": false,
          "headline": "Make postmerge CI manual in fork",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-08T13:54:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f00f2a12bd562cd7f9e79f348e95d41fa8e0fd1d",
          "body": null,
          "is_bot": false,
          "headline": "Quiet fork blocking CI on main pushes",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-08T13:54:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6fa072b981ca173d18ec3c22fc87ddc2e80a16e2",
          "body": null,
          "is_bot": false,
          "headline": "Fix Midnight Coder npm release workflow",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-08T13:48:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "78ac210b41786ca4e2554f48c1d3e6507139a816",
          "body": null,
          "is_bot": false,
          "headline": "Expand root README for Midnight Coder",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-08T12:54:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a58f06f1df48c062576afa9d7607f58ddab020c4",
          "body": null,
          "is_bot": false,
          "headline": "Update root README for Midnight Coder",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-08T12:51:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f4479a978a656a8a385c11e5c8e7afe14f72b84",
          "body": null,
          "is_bot": false,
          "headline": "Fix release scripts CRLF handling",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-08T11:07:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ab651851cfc034fee3628cf5f8432a77106d92d",
          "body": null,
          "is_bot": false,
          "headline": "Fix npm release staging",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-08T09:06:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7e9affbd7d924b7413330df993038cfddd45ccd",
          "body": null,
          "is_bot": false,
          "headline": "Do not require zsh manifest for Linux release",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-07T14:17:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8e1bc970d0402c3f17736cd5eeae332cb4f995d6",
          "body": null,
          "is_bot": false,
          "headline": "Build midnight-coder in release workflow",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-07T13:48:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "580e18d385c30ed5fa3f8b125d747a6dfd80c58f",
          "body": null,
          "is_bot": false,
          "headline": "Fix hosted musl tool setup",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-07T13:38:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ea7771ce1d9298b03be2969e8e17fca5eef403ad",
          "body": null,
          "is_bot": false,
          "headline": "Fix midnight-coder npm release workflow",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-07T13:34:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6bf951c1083cfc0fac1a34441ba5ceace3964016",
          "body": null,
          "is_bot": false,
          "headline": "Make release lint workflow Linux-only",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-03T19:18:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3239d2bdb6740f19e6f42bfd51570853d0eaf2ec",
          "body": null,
          "is_bot": false,
          "headline": "Make rust release Linux-only temporarily",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-03T19:07:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5783c98b2c44bb5e3222ee74245d6daf7be8450d",
          "body": null,
          "is_bot": false,
          "headline": "Bump release version to 0.1.0-alpha.5",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-03T18:41:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "48b45fadab2e7b84ff19c0d08357dffb9736fc1a",
          "body": null,
          "is_bot": false,
          "headline": "Fix release workflow permissions",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-03T18:40:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e5c0fb44ef35d9eaf45e1cc59437284822da5d88",
          "body": null,
          "is_bot": false,
          "headline": "Publish Midnight Coder npm package",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-03T18:37:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8d661c67528943f0ff5c10e95c324233bdc7b5a4",
          "body": null,
          "is_bot": false,
          "headline": "Ignore generated snapshot previews",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-03T15:50:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73837568514f017b59b7b68a6d6a7bb97791bf70",
          "body": null,
          "is_bot": false,
          "headline": "Publish Midnight Coder workspace",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-03T15:49:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f9ef818bb2bc915226bcd898dfbb348056c865a",
          "body": null,
          "is_bot": false,
          "headline": "Rebrand to Midnight Coder",
          "author_name": "Midnight-Coder",
          "author_login": "midnightcoderagent",
          "committed_at": "2026-07-03T15:42:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c464468493e965a5e5e2f6490b81b4635ac358b1",
          "body": null,
          "is_bot": false,
          "headline": "Update security check wording (#30317)",
          "author_name": "Eric Traut",
          "author_login": "etraut-openai",
          "committed_at": "2026-06-27T03:05:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4f1b5a4b734da8f159e1b727042b4534ed091307",
          "body": "## Why\n\n`LOG_FORMAT=json` and `RUST_LOG` are supported by app-server, but the\nbehavior was only covered indirectly. We should verify the actual JSONL\nwritten by both user-facing entry points: `codex app-server` and the\nstandalone `codex-app-server` binary.\n\nThe existing processor shutdown message al\n[…]\nable `level`, `fields`, and `target` payload.\n\n## Test plan\n\n- `just test -p codex-app-server\nstandalone_app_server_emits_json_info_events`\n- `just test -p codex-cli app_server_emits_json_info_events`",
          "is_bot": false,
          "headline": "app-server: structure and test JSON shutdown logs (#30314)",
          "author_name": "Michael Bolin",
          "author_login": "bolinfest",
          "committed_at": "2026-06-27T01:19:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3ae0543fddd79ed215f9c1f57e2096ea66486c61",
          "body": "## Why\n\nRemote diff-root discovery is independent of world-state construction,\nbut it ran afterward and added filesystem metadata latency before the\nfirst model request. Overlap the independent work so thread-cold turns\ndo not pay those waits serially.\n\n## What\n\n- Run `record_context_updates_and_set\n[…]\nhe or behavior lifecycle changes are\nintroduced.\n\n## Validation\n\nA synthetic executor-skill benchmark with artificial network delay:\nthread-cold model-request p50 improved from about 1.79 s to 1.58 s.",
          "is_bot": false,
          "headline": "core: overlap diff root discovery with world state (#30286)",
          "author_name": "Adam Perry @ OpenAI",
          "author_login": "anp-oai",
          "committed_at": "2026-06-27T01:07:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d4ec08b8f0bab08d5945c903289ec10d8490e7df",
          "body": "## Summary\n\n- complete unified-exec processes from the ordered event stream instead\nof issuing a final zero-wait `process/read`\n- add optional executor sandbox-denial state to `process/exited`\n- retain `process/read` as a retained-output and compatibility fallback\nfor receiver lag, sequence gaps, an\n[…]\n across 16 shards\n- scoped `just fix` passed for core and exec-server\n- `just fmt` passed\n\nThe complete workspace suite was not rerun; focused Cargo and Bazel\ncoverage passed for the changed behavior.",
          "is_bot": false,
          "headline": "[codex] consume pushed exec-server process events (#30273)",
          "author_name": "richardopenai",
          "author_login": "richardopenai",
          "committed_at": "2026-06-27T01:05:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d047c33a1b13024dd3815c1ad0597491cacb038a",
          "body": "## Why\n\nRemote-control websocket reconnects and pairing requests proactively\nrefresh their server token. When `/server/refresh` returns a transient\nerror such as `502`, the still-valid token was discarded as a usable\nconnection path, causing reconnect failures and repeated refresh\nattempts that coul\n[…]\nient;\n- an expired token, including one that expires during refresh, cannot\nproceed to websocket connection;\n- auth failures clear the attempted token without overwriting a\nconcurrently rotated token.",
          "is_bot": false,
          "headline": "fix(remote-control): avoid server token refresh retry storms (#30201)",
          "author_name": "Anton Panasenko",
          "author_login": "apanasenko-oai",
          "committed_at": "2026-06-27T00:34:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a107b84967eb9a3444fd2d4de03f200337acd52b",
          "body": "## Description\n\nThis PR adds canonical core `TurnItem` shapes for command execution,\ndynamic tool calls, collab agent tool calls, and sub-agent activity, to\nbe stored in the rollout file soon.\n\nIt also teaches app-server protocol / `ThreadHistoryBuilder` how to\nrender those items, and adds the small\n[…]\nnew item variants.\n\n## Follow-up\n\nThe next PR https://github.com/openai/codex/pull/30283 switches the live\ncore producers for these item families onto canonical `ItemStarted` /\n`ItemCompleted` events.",
          "is_bot": false,
          "headline": "feat(protocol): define missing rollout turn items (#30282)",
          "author_name": "Owen Lin",
          "author_login": "owenlin0",
          "committed_at": "2026-06-26T23:44:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1168254bd9366faab73835a2cf8eb43d00acad78",
          "body": "## Why\n\nIt's hard to change the set of required jobs when they're managed in the\nGitHub UI, and when each workflow is responsible for choosing it's own\nscheduling it's easy to end up with skew between what we enforce on PRs\nvs. on main.\n\n## What\n\n- add a `blocking-ci` caller workflow, triggered by p\n[…]\nnch ruleset. Retain `cla` as\na separate required check. Until that change is coordinated, this PR\ncannot satisfy the old standalone check names. In-flight PRs will need\nto be rebased after this lands.",
          "is_bot": false,
          "headline": "[codex] group blocking and postmerge CI workflows (#30146)",
          "author_name": "Adam Perry @ OpenAI",
          "author_login": "anp-oai",
          "committed_at": "2026-06-26T22:07:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6509f3148a248f5da6c03cdf008f2ad70526cd31",
          "body": "## Why\n\nMarketplace source deserialization treated `{\"source\":\"npm\", ...}` as\nunsupported. The loader logged and skipped the entry, so npm-backed\nplugins never appeared in `plugin list --available` and `plugin add`\nreturned \"plugin not found\".\n\nCodex plugins are installed from a plugin root, not fro\n[…]\ntdio_server` helper binary.\n- Installed an npm-published Codex plugin package through a throwaway\nlocal marketplace and throwaway `CODEX_HOME` to exercise the real npm\nmaterialization path end to end.",
          "is_bot": false,
          "headline": "[codex] Support npm marketplace plugin sources (#29375)",
          "author_name": "charlesgong-openai",
          "author_login": "charlesgong-openai",
          "committed_at": "2026-06-26T21:24:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "526f495f3a904e29ec1d07a927992c904c8a1f5c",
          "body": "## Summary\n\n- classify authentication-required RMCP startup failures, including\nerrors nested inside `ClientInitializeError::TransportError`\n- let `codex-mcp` consume that classification so the existing\n`reauthenticationRequired` startup failure reason is emitted\n- add a regression test that perform\n[…]\n_oauth_and_auth_failure`\n- `cargo build -p codex-cli --bin codex`\n- local app-server probe emitted `failureReason:\n\"reauthenticationRequired\"`\n- manual end-to-end reconnect flow confirmed\n- `just fmt`",
          "is_bot": false,
          "headline": "[codex] Classify nested MCP authentication startup errors (#30257)",
          "author_name": "felixxia-oai",
          "author_login": "felixxia-oai",
          "committed_at": "2026-06-26T21:11:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c55ce3b51bc3b8bb2805cbee0afc1a8c6e1e7ee2",
          "body": "### Summary\n\nRelease live thread persistence when a session ends because its\nsubmission channel closes. This prevents a later same-process resume\nfrom failing with `thread ... already has a live local writer`.\n\n### Details\n\nThe issue is in the `codex-core` session teardown path used by Codex\nhosts, \n[…]\nw regression passed;\n79 unrelated integration tests failed in the local harness, primarily\nbecause helper binaries such as `test_stdio_server` were unavailable,\nplus local proxy/shell timing failures.",
          "is_bot": false,
          "headline": "Close thread persistence when submission channel closes (#30173)",
          "author_name": "Abdulrahman Alfozan",
          "author_login": "alfozan",
          "committed_at": "2026-06-26T20:56:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "69596f0e428ae6698b0b9f1174e05bac0a023ded",
          "body": "## Summary\n\n- add Sol (`openai.gpt-5.6-sol`), Terra (`openai.gpt-5.6-terra`), and\nLuna (`openai.gpt-5.6-luna`) to the Amazon Bedrock static model catalog\n- derive all three entries from the bundled GPT-5.5 metadata and add the\nBedrock-only `max` reasoning effort\n- keep the new entries below the curr\n[…]\nGPT-5.4 models at\npriorities 2, 3, and 4, preserving GPT-5.5 as the default\n- add deep-equality coverage for inherited model configuration, catalog\nordering, context windows, and service-tier behavior",
          "is_bot": false,
          "headline": "feat: add GPT-5.6 variants to Bedrock catalog (#30285)",
          "author_name": "Celia Chen",
          "author_login": "celia-oai",
          "committed_at": "2026-06-26T20:32:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ac85409b7b137843e1ec59d9ecaa063e88c60e6c",
          "body": "## Why\n\nI use the `$code-review` skill a lot and it'd be nice to add my own\nadditional review criteria in `$CODEX_HOME/skills/code-review-*`.\n\n## What\n\nRemoves phrasing about \"code-review-* skills in this repository\" which\nin practice seems like enough to get Codex to consult my user-level code\nreview skills in addition to the repo-level ones.",
          "is_bot": false,
          "headline": "Let Codex consult user-level code-review-* skills. (#30143)",
          "author_name": "Adam Perry @ OpenAI",
          "author_login": "anp-oai",
          "committed_at": "2026-06-26T19:36:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f72976a5f1e5bba3e1af18cc2ddffedfb2687376",
          "body": "## Description\n\nThis adds stable optional `turnId` support to `thread/fork`. When\nsupplied, the fork copies persisted history through that terminal turn,\ninclusive, and drops later turns from the new thread.\n\nOmitting or passing `null` preserves the existing full-history fork\nbehavior, including the\n[…]\nion marker when the stored source\nhistory ends mid-turn.\n\n## Why\n\nWe're deprecating `thread/rollback` and this will help certain UX use\ncases work around it by using `thread/fork` + `turn_id` instead.",
          "is_bot": false,
          "headline": "feat(app-server): add optional turn_id to thread/fork (#30277)",
          "author_name": "Owen Lin",
          "author_login": "owenlin0",
          "committed_at": "2026-06-26T19:35:54Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "812cd2bb57ddb3a04a10d59495ac0212d2eb52a3",
          "body": "## Description\n\nThis PR makes `thread.history_mode` immutable after the thread's\ncanonical first `SessionMeta` has been written. Later same-thread\n`SessionMeta` lines are compatibility metadata writes, not a new thread\ndefinition.\n\nWithout this, an older binary could append a `SessionMeta` that omit\n[…]\nI caught this after the parent\nhistory-mode PR landed.\n\n## Validation\n\n- `just fmt`\n- `just test -p codex-thread-store`\n- `just test -p codex-state\nsession_meta_does_not_set_model_or_reasoning_effort`",
          "is_bot": false,
          "headline": "ensure thread.history_mode is immutable (#30261)",
          "author_name": "Owen Lin",
          "author_login": "owenlin0",
          "committed_at": "2026-06-26T19:32:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cf36c688b3d5c9122e818a93d272d4024c8a2bae",
          "body": "## Why\n\n#29683 exposes managed defaults for new-thread model settings through\n`configRequirements/read` without applying them server-wide. The TUI is\nan app-server client, so it should explicitly consume those defaults\nwhen it creates a fresh thread.\n\nThis lets plain `codex` start on the managed mod\n[…]\nged defaults.\n- Explicit launch choices such as `codex -m <model>` continue to win.\n\n## Validation\n\n- `just test -p codex-tui managed_new_thread_defaults`\n- `just fix -p codex-tui`\n\nDepends on #29683.",
          "is_bot": false,
          "headline": "[codex] Use managed defaults for TUI threads (#30147)",
          "author_name": "hefuc-oai",
          "author_login": "hefuc-oai",
          "committed_at": "2026-06-26T19:27:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "79a8ffdbf7ca08820e0b44cab0261eb61ff72465",
          "body": "Prompt update of MAv2 to include agents.md and skills more explicitly\n\nshould mimic: https://github.com/openai/codex/pull/27919",
          "is_bot": false,
          "headline": "[codex] allow AGENTS.md and skills to authorize delegation (#30274)",
          "author_name": "Charles Du",
          "author_login": "charlesdu-openai",
          "committed_at": "2026-06-26T19:17:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a938d5f6071f0430b1ed05e381ad9239baeb26f7",
          "body": "## Why\n\nEnvironment skill discovery needs two independent pieces of information:\n\n- plugin namespaces from `plugin.json` files; and\n- skill metadata from each `SKILL.md` file.\n\nToday these happen in sequence. Codex waits for every plugin namespace\nlookup to finish before it starts reading any skill \n[…]\nalls, or\nreduce the number of files transferred. A frontmatter-only read or\nserver-side skill catalog can remain a separate follow-up if benchmarks\nshow that transferred bytes are the next bottleneck.",
          "is_bot": false,
          "headline": "Overlap executor skill reads with namespace discovery (#30225)",
          "author_name": "jif",
          "author_login": "jif-oai",
          "committed_at": "2026-06-26T18:37:59Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d9cf931d0eafa18f4fdfc7ab8c9c241b48df3216",
          "body": "## Why\n\nAdmins need persistent defaults for the model, reasoning effort, and\nservice tier shown when the Desktop App creates a new thread. These are\ninitialization defaults rather than runtime constraints: the App should\nuse them to initialize its draft while still allowing a user to make an\nexplici\n[…]\nls.new_thread]`\n- Requirements-layer precedence coverage\n- App-server API mapping coverage\n- `configRequirements/read` integration coverage\n- Regenerated app-server JSON and TypeScript schema fixtures",
          "is_bot": false,
          "headline": "[codex] Add managed new-thread model settings (#29683)",
          "author_name": "hefuc-oai",
          "author_login": "hefuc-oai",
          "committed_at": "2026-06-26T18:37:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f91334380e46cfd909c3642c1e05d3d8283c40ef",
          "body": "Introduced by a merge race around thread.history_mode.",
          "is_bot": false,
          "headline": "fix main (#30276)",
          "author_name": "Owen Lin",
          "author_login": "owenlin0",
          "committed_at": "2026-06-26T18:05:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5267e805fb830891c0b23376bcd9cbd382c3473c",
          "body": "## Description\n\nThis PR adds a new `historyMode = \"legacy\" | \"paginated\"` to `Thread`.\nThis will be stored in `SessionMeta` in the JSONL rollout file and as a\nnew column in the SQLite thread_metadata table, and exposed on\n`thread/start` and on the `Thread` object in app-server.\n\n## What changed\n\n- A\n[…]\ninated thread. That gives us the behavior we want for Release N:\nfuture paginated threads are visible, but this binary fails closed\ninstead of trying to operate on them as if they were legacy threads.",
          "is_bot": false,
          "headline": "feat(app-server): add history_mode to thread (#29927)",
          "author_name": "Owen Lin",
          "author_login": "owenlin0",
          "committed_at": "2026-06-26T16:12:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2c5bc5e284402d2e618c15e396d2e81bcc1ec257",
          "body": "## Summary\n- Allow a top-level `description` string in `hooks.json`.\n- Continue rejecting unknown top-level keys and root-level hook events;\nevents must remain under `hooks`.\n\n## Testing\n- `just test -p codex-config`",
          "is_bot": false,
          "headline": "Relax hooks.json top-level metadata validation (#30229)",
          "author_name": "charlesgong-openai",
          "author_login": "charlesgong-openai",
          "committed_at": "2026-06-26T15:24:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "914c8eeb4e41442e04a7706ca1638491ceabf4a4",
          "body": "## Summary\n\n- stop publicly re-exporting the internally used\n`SKILLS_INTRO_WITH_ALIASES` constant\n- keep the constant and all skills rendering behavior unchanged\n- preserve every integration helper, API, fixture, assertion, and module\nused by tests\n\n## Scope guardrails\n\nThis revision keeps all remot\n[…]\nackage and failed their isolation assertions. The scoped renderer suite\nand all-target compile pass, and CI runs in an isolated environment.\n\nFinal code delta: 1 insertion, 2 deletions across 2 files.",
          "is_bot": false,
          "headline": "[codex] narrow unused skills intro export (#29991)",
          "author_name": "Ahmed Ibrahim",
          "author_login": "aibrahim-oai",
          "committed_at": "2026-06-26T12:52:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3c03bb4f182c91b07c12bcd4d79ac61df10dd084",
          "body": "## Why\n\nThe selected-capability integration test already covers initial\nattachment and cold resume, but it resumes while the selected executor\nis still reachable.\n\nThat leaves an important World State transition untested: a thread\nremembers its selected capability root, resumes while that environmen\n[…]\n Scope\n\nThis is test-only. It keeps the existing assumption that an environment\nID refers to stable capability contents. It does not add package-file\ninvalidation or live transport reconnect behavior.",
          "is_bot": false,
          "headline": "Test selected capabilities across unavailable resume (#30215)",
          "author_name": "jif",
          "author_login": "jif-oai",
          "committed_at": "2026-06-26T10:02:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6d2168f06ae275d5e1f73cabf935d2bcc8549998",
          "body": "## Why\n\nMCP runtime reuse was keyed by every ready selected-capability\nenvironment, even when an environment contributed no MCP servers or\nconnectors.\n\nFor example:\n\n1. a global stdio MCP is running;\n2. a selected remote environment contains only a skill;\n3. that environment becomes ready;\n4. the MC\n[…]\nt/reconnect handling.\n- Selected environment IDs and their capability contents retain the\nstack's existing stability assumption.\n- Delayed `required = true` executor MCP behavior remains out of scope.",
          "is_bot": false,
          "headline": "Reuse MCP runtimes when selected availability changes nothing (#30148)",
          "author_name": "jif",
          "author_login": "jif-oai",
          "committed_at": "2026-06-26T08:27:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "451c0a437f2434a95c5e3893613f8afb192f4781",
          "body": "## Summary\n\n- initialize `selected_capability_roots` in the new\n`attach_in_memory_thread_store` test helper\n- restore `codex-core` test compilation on `main`\n\n## Root cause\n\n[#30144](https://github.com/openai/codex/pull/30144) added the helper\nfrom commit `0c3d0742`, whose parent was `c38b2e9b`. Tha\n[…]\nroduction behavior or\nworkflow configuration.\n\n## Validation\n\n- `just fmt`\n- `just test -p codex-core\nturn_complete_flushes_terminal_event_after_delivery` (1 passed, 2909\nskipped)\n- `git diff --check`",
          "is_bot": false,
          "headline": "[codex] fix CreateThreadParams test initializer (#30198)",
          "author_name": "Adam Perry @ OpenAI",
          "author_login": "anp-oai",
          "committed_at": "2026-06-26T07:47:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7d8906b4785d9e2d6ebe8c75a163f97de4f7ca35",
          "body": "## Summary\n\n- add the `code_mode_host` feature flag and select\n`ProcessOwnedCodeModeSessionProvider` in `CodeModeService` when enabled\n- initialize code-mode sessions lazily so a missing host reports a tool\nerror without failing thread startup\n- resolve `codex-code-mode-host` beside the running Code\n[…]\nned-session-runtime-4-client`\n\n## Validation\n\nBuild `codex` and `codex-code-mode-host`\n`CODEX_CODE_MODE_HOST_PATH=\"$PWD/target/debug/codex-code-mode-host\"\n./target/debug/codex --enable code_mode_host`",
          "is_bot": false,
          "headline": "[codex] wire process-owned code mode host into core (#30142)",
          "author_name": "Channing Conger",
          "author_login": "cconger",
          "committed_at": "2026-06-26T07:23:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ab16046c88b2ea9e9af849ab6662129c6becb151",
          "body": "## Summary\n\n- add `ProcessOwnedCodeModeSessionProvider` and logical session\ngeneration/rebinding state\n- add the supervised child-process connection, reader/writer tasks, and\ndriver state machine\n- make dropped execute/wait/open callers cancellation-safe with explicit\nownership handoff and durable c\n[…]\nnit-tests\n//codex-rs/code-mode-host:code-mode-host-unit-tests\n//codex-rs/code-mode-host:code-mode-host-stdio-test\n//codex-rs/code-mode-protocol:code-mode-protocol-unit-tests` — 4/4\npassed\n- `just fmt`",
          "is_bot": false,
          "headline": "[codex] add process-owned code-mode session client (#30112)",
          "author_name": "Channing Conger",
          "author_login": "cconger",
          "committed_at": "2026-06-26T06:46:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b5866eebd631a62a1f3f29ac5e44752e38949c73",
          "body": "[Codex Thread\n019ef1f9-36e2-7e91-9337-504f097b9dc1](https://codex-thread-link.openai.chatgpt-team.site/thread/019ef1f9-36e2-7e91-9337-504f097b9dc1)\n\n## Why\n\nHosted plugin-service Streamable HTTP MCP traffic uses\n`https://chatgpt.com/backend-api/ps/mcp` and depends on Cloudflare's\n`__cflb` cookie for\n[…]\n No special composition of caller-provided `Cookie` headers.\n- No plugin-service, connector-cache, Habitat/habicache, routing,\nredirect, or API-contract changes.\n- No broader incident RCA conclusions.",
          "is_bot": false,
          "headline": "Persist Cloudflare affinity cookies for MCP HTTP (#29516)",
          "author_name": "stevenlee-oai",
          "author_login": "stevenlee-oai",
          "committed_at": "2026-06-26T06:23:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "92d2e1df7079b5bd549c92a17fa234706d0580b3",
          "body": "## Problem\n\nThe built-in Codex Apps MCP client shares a future for the full startup\noperation: connect, complete `initialize`, fetch the initial tools, and\nreturn a usable client. Sharing deduplicates startup work, but it also\nmemoizes terminal errors.\n\nAfter a transient connection, handshake, or in\n[…]\ntest -p codex-mcp` — 95 passed\n- `just test -p codex-core\nlater_follow_up_uses_background_recovered_apps_after_mid_thread_startup_failures\n--no-capture` — passed\n- `just fix -p codex-mcp`\n- `just fmt`",
          "is_bot": false,
          "headline": "Retry failed Codex Apps MCP startup (#29920)",
          "author_name": "kbazzi",
          "author_login": "kbazzi",
          "committed_at": "2026-06-26T04:31:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f5f812389ee49ab4c9ef1237781ea1013e733fdc",
          "body": "Currently session code does not flush the thread store after appending\nthe `TurnComplete` / `TurnAborted` events.\n\nThis isn't a problem in practice for local storage because append_items\nitself effectively blocks, but any thread stores that buffer in\nappend_items and only commit on flush effectively\n[…]\ninterruption.\n\nAdded test cases that assert the number of flushes when completing or\naborting turns. These are admittedly a little brittle and I'm open to\nbetter ideas on how to add automated testing.",
          "is_bot": false,
          "headline": "[codex] fix terminal rollout event durability (#30144)",
          "author_name": "Tom",
          "author_login": "wiltzius-openai",
          "committed_at": "2026-06-26T04:01:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "25f50de6ed95627e1ffe7f11ca30d3d62c6e20e6",
          "body": "## Why\n\nThis stack crosses World State, executor skills, selected plugin\nmetadata, MCP processes, connectors, dynamic environments, and resume.\nThis PR adds two end-to-end scenarios that validate those pieces\ntogether.\n\nBoth tests enable `deferred_executor`, so they exercise the real\ndelayed-environ\n[…]\nese are integration tests only. They do not add a combinatorial matrix\nfor unsupported plugin-file mutation, environment generations, transport\ndisconnects, or delayed `required = true` executor MCPs.",
          "is_bot": false,
          "headline": "Test selected capabilities across availability and resume (#30157)",
          "author_name": "jif",
          "author_login": "jif-oai",
          "committed_at": "2026-06-26T02:11:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0d4351c1b80cae3a40a2d0d64d4e87ca1d5c4afa",
          "body": "## Summary\n\n- allow the standalone image-generation and web-search extensions for\nthe actor-authorized provider shape used by CCA\n- preserve builtin `image_generation` and `web_search` for older models\nand existing flows\n- keep ordinary non-OpenAI providers excluded from both extensions\n- remove onl\n[…]\n_auth_model_and_config_gates`\n- `just test -p codex-image-generation-extension`\n- `just test -p codex-web-search-extension`\n- `just test -p codex-model-provider-info`\n- `just fmt`\n- `git diff --check`",
          "is_bot": false,
          "headline": "[codex] allow CCA image generation and web search extensions (#29909)",
          "author_name": "Won Park",
          "author_login": "won-openai",
          "committed_at": "2026-06-26T01:34:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ec300bc7bd7355833f579a603df067d59c1963cb",
          "body": "## Why\n\nMCP tool-call events need to expose trusted app identity and action\nmetadata directly so v2 clients do not have to infer it from tool names\nor resource URIs.\n\n## What changed\n\n- Add optional `appName`, `templateId`, and `actionName` fields to MCP\ntool-call `appContext`.\n- Populate `appName` \n[…]\ntrusts_codex_apps_identity\nmcp_tool_call_item_includes_app_identity`\n- `just write-app-server-schema`\n\n---------\n\nCo-authored-by: Martin Au-Yeung <280153141+martinauyeung-oai@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Expose MCP app identity in app context (#29934)",
          "author_name": "Martin Au-Yeung",
          "author_login": "martinauyeung-oai",
          "committed_at": "2026-06-26T01:31:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fb8598df3ff05366a295c407c91f3d9316a1630c",
          "body": "## Why\n\nAn MCP tool call can still be waiting for an elicitation response when\nan environment update replaces the thread's MCP runtime.\n\nBefore this change:\n\n```text\nruntime A starts a tool call and asks the user\nenvironment becomes ready, so runtime B is published\nclient answers the prompt through \n[…]\nelicitation response routing across MCP runtime\nreplacement. It does not change when runtimes are rebuilt, which\nenvironments contribute MCP configuration, or how environment\navailability is detected.",
          "is_bot": false,
          "headline": "Keep MCP elicitation routable across runtime refreshes (#30127)",
          "author_name": "jif",
          "author_login": "jif-oai",
          "committed_at": "2026-06-26T01:28:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "723b23efd0c06289e878b294b29f6d7ed98a66e8",
          "body": "## Why\n\nWorld State restores its structured snapshot on resume so unchanged\nsections do not have to be rendered again. That is safe only when the\nmodel-visible fragment represented by the snapshot is still present in\nretained history.\n\nFor selected executor skills, the failing selected-capability sc\n[…]\ntory\nreconstruction.\n\n## Coverage\n\nA focused World State regression test verifies both sides:\n\n- a missing retained fragment is rendered again\n- a matching retained fragment avoids duplicate injection",
          "is_bot": false,
          "headline": "Reinject missing World State fragments on resume (#30152)",
          "author_name": "jif",
          "author_login": "jif-oai",
          "committed_at": "2026-06-26T01:18:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "841f30598c05eebb62139bdd75abef1b7b61d5f7",
          "body": "## Why\n\nDesktop Work threads and regular Codex threads can share the same\napp-server connection. App-server analytics currently copy\n`product_client_id` from connection metadata for every thread-scoped\nevent, so Work thread activity is attributed to the Desktop connection\ninstead of the thread's res\n[…]\nanalytics\nthread_start_tracks_thread_initialized_analytics\nthread_fork_tracks_thread_initialized_analytics\nthread_resume_tracks_thread_initialized_analytics`\n- `just test -p codex-core thread_manager`",
          "is_bot": false,
          "headline": "[codex] Attribute app-server analytics by thread originator (#29935)",
          "author_name": "alexsong-oai",
          "author_login": "alexsong-oai",
          "committed_at": "2026-06-26T01:15:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "da78d5fdc5d8b30a80b402100d8b25ed8031f8c4",
          "body": "## Summary\n\n- implement the standalone `codex-code-mode-host` stdio service\n- route sessions, cells, delegate requests, responses, and cancellation\nthrough a bounded host peer\n- supervise request, writer, cell-forwarding, actor, and V8 failure\nboundaries\n- bound request/session tombstones and fail-s\n[…]\ngets this branch\n\n## Validation\n\n- `just test -p codex-code-mode-host` — 7 host-only tests passed\n- `just fix -p codex-code-mode-host`\n- `just bazel-lock-update`\n- `just bazel-lock-check`\n- `just fmt`",
          "is_bot": false,
          "headline": "[codex] implement standalone code-mode process host (#30111)",
          "author_name": "Channing Conger",
          "author_login": "cconger",
          "committed_at": "2026-06-26T01:00:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8ebf71ec257fcb95d72a71c7d3bedbbe9a861e45",
          "body": "## Why\n\nEnvironment skill discovery already asks the executor to run one\n`fs/walk`. That response contains every regular file path found under\nthe selected root, including any `agents/openai.yaml` files.\n\nToday Core keeps the discovered `SKILL.md` paths but discards the rest\nof that file inventory. \n[…]\nlace, which is why\nthis PR reaches 69 calls rather than the broader 68-call estimate. That\nlookup has separate alternate-path, ancestor, and symlink semantics and\nshould not be mixed into this change.",
          "is_bot": false,
          "headline": "Reuse walk inventory for environment skill metadata (#30145)",
          "author_name": "jif",
          "author_login": "jif-oai",
          "committed_at": "2026-06-26T00:47:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3095ea9c3d155bfc89197d2628eb818a55c2755d",
          "body": "## Why\n\nSelected plugin metadata is stable, but MCP processes are live runtime\nstate. They need different lifetimes:\n\n- the MCP extension caches manifest, MCP, and connector declarations for\neach stable selected root;\n- each model step projects that cached metadata through the roots that\nresolved as\n[…]\n_managed_requirements_for_the_selected_root_id`\n- The stacked integration PR covers unavailable to ready activation,\nunchanged-runtime reuse, skills, MCP tools, connector attribution, and\ncold resume.",
          "is_bot": false,
          "headline": "Project selected plugin runtime by environment availability (#30093)",
          "author_name": "jif",
          "author_login": "jif-oai",
          "committed_at": "2026-06-26T00:36:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5044062704af7667e460cc401221a081054ef3ab",
          "body": "## Why\n\nThe Windows cross-build skip used the broad `powershell` substring,\nwhich hid unrelated Windows tests. Narrowing it exposed the same ConPTY\nCtrl-C timeout that is breaking `main`; that test is not reliable in\neither cross-built or native Windows Bazel CI yet.\n\n## What changed\n\n- scope the cr\n[…]\nted PowerShell tests\n- [Windows shard\n4/4](https://github.com/openai/codex/actions/runs/28204844286/job/83553063859)\nreproduced the `main` ConPTY timeout before the exact CI-only exclusion\nwas applied",
          "is_bot": false,
          "headline": "ci: narrow Windows test skips (#30134)",
          "author_name": "Adam Perry @ OpenAI",
          "author_login": "anp-oai",
          "committed_at": "2026-06-26T00:01:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ee9e0f6387b91cd14008ea59a8e4315b2a2fdacb",
          "body": "## Why\n\nAn MCP refresh can replace the session's current manager while a model\nstep is still running. The step must execute calls through the same\nmanager whose tools it advertised.\n\n## Boundary\n\n```text\ncurrent session MCP runtime\n          |\n          | capture once for this model step\n          v\n[…]\n skills through World State.\n3. **This PR:** pin one MCP runtime to each model step.\n4. Project selected MCP/app/connector metadata by environment\navailability.\n5. One end-to-end integration scenario.",
          "is_bot": false,
          "headline": "Pin MCP runtimes to model steps (#30101)",
          "author_name": "jif",
          "author_login": "jif-oai",
          "committed_at": "2026-06-25T23:53:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8ce931ab763541736bd08d0507b4777543532762",
          "body": "Fixes distributed trace continuity across exec-server JSON-RPC HTTP\negress by adding an executor client span and injecting its W3C context\nthrough a reusable `codex-otel` helper.\n\nThis preserves the caller trace across core/tool → executor →\nprovider/MCP instead of dropping parentage at raw reqwest.\n\nNote that this doesn't include the websocket path, which is needed to\nreally get the full story but at least we cover the basic http path with\nthis change.",
          "is_bot": false,
          "headline": "[codex] Propagate traces through exec-server HTTP (#30117)",
          "author_name": "Tom",
          "author_login": "wiltzius-openai",
          "committed_at": "2026-06-25T23:22:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5eebeb816905f44fd847124ea610922795362cbc",
          "body": "## Why\n\nA selected executor environment can be unavailable in one model step and\nready in the next. The model should see its skills only while that\nenvironment is ready, without rescanning stable files on every sample.\n\nThe product assumption is simple:\n\n- an environment ID names one stable logical \n[…]\nched executor skills through World State.\n3. Pin one MCP runtime to each model step.\n4. Project selected MCP/app/connector metadata by environment\navailability.\n5. One end-to-end integration scenario.",
          "is_bot": false,
          "headline": "Project executor skills through World State (#30088)",
          "author_name": "jif",
          "author_login": "jif-oai",
          "committed_at": "2026-06-25T23:13:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6c21297bba7da6ef9c14362406eec59aba5cbfce",
          "body": "## Why\n\nA process host should be discarded and rebuilt after critical actor or\nV8 failure, while the existing in-process production path must keep its\ncurrent cell-error semantics. This change establishes that failure\nboundary without adding the host process or remote client.\n\n## What changed\n\n- add\n[…]\n8 is merged into `main`\n- The next PR targets this branch\n\n## Validation\n\n- `just test -p codex-code-mode` — 53 passed\n- `just argument-comment-lint -p codex-code-mode`\n- `just fix -p codex-code-mode`",
          "is_bot": false,
          "headline": "[codex] add code-mode host failure supervision hooks (#30110)",
          "author_name": "Channing Conger",
          "author_login": "cconger",
          "committed_at": "2026-06-25T22:33:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e2746fd7e90d4f6095da62d70f50194cc21d2d3e",
          "body": "## Summary\n\n- recognize `codex_work_web` and `codex_work_mobile` as supported\n`thread/start.serviceName` values\n- use the recognized value as the thread-scoped originator, with the\nsame persistence and request propagation added for `codex_work_desktop`\n- cover precedence over persisted and inherited\n[…]\n97)\nonly after both consumers are deployed.\n\n## Validation\n\n- `just test -p codex-core\neffective_originator_prefers_thread_scoped_sources_before_env_originator`\n- `just fix -p codex-core`\n- `just fmt`",
          "is_bot": false,
          "headline": "Recognize Work web and mobile thread originators (#29988)",
          "author_name": "chiam-oai",
          "author_login": "chiam-oai",
          "committed_at": "2026-06-25T22:30:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a6d20ed29701bd8f291e94526154dcac90367d92",
          "body": "## Summary\n\n- distinguish expired, non-refreshable stored MCP OAuth credentials from\nfirst-time missing credentials\n- carry a typed `failureReason: \"reauthenticationRequired\"` on the\nexisting `mcpServer/startupStatus/updated` notification only when user\naction is required\n- keep the public MCP auth-\n[…]\nust test -p codex-rmcp-client -p codex-mcp` — 184 passed, 2 skipped\n- `just test -p codex-protocol -p codex-app-server-protocol -p\ncodex-mcp` — 579 passed\n- `just write-app-server-schema`\n- `just fmt`",
          "is_bot": false,
          "headline": "[codex] Surface MCP reauthentication-required startup failures (#29877)",
          "author_name": "felixxia-oai",
          "author_login": "felixxia-oai",
          "committed_at": "2026-06-25T21:50:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b80fbb70cd2f6e6ae32cca8c2eba923bf3c0055e",
          "body": "## Why\n\nThe TUI uses `thread/rollback` internally for user-facing flows such as\nprompt cancellation/backtracking. After `thread/rollback` was marked\ndeprecated, those internal calls started surfacing `deprecationNotice`\nmessages in the TUI, even though the user did not explicitly call the\ndeprecated\n[…]\nverify an external app-server client that calls\n`thread/rollback` still receives `deprecationNotice`.\n\nTargeted tests:\n\n- `just test -p codex-app-server thread_rollback`\n- `just argument-comment-lint`",
          "is_bot": false,
          "headline": "fix(app-server): suppress TUI rollback warning (#30124)",
          "author_name": "Felipe Coury",
          "author_login": "fcoury-oai",
          "committed_at": "2026-06-25T21:44:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c9e6d9783dfe99a819f00318f753b6f5cbcc38e8",
          "body": "## Why\n\n#29856 already owns the durable thread intent and exact environment\nbinding. This PR adds only the small missing extension boundary: an\nextension can contribute one named World State section, while core still\nowns persistence, diffing, and model-visible fragment types.\n\nThis lets skills stay\n[…]\nutor skills through the skills extension.\n3. Pin one MCP runtime to each model step.\n4. Project selected MCP/app/connector metadata by environment\navailability.\n5. One end-to-end integration scenario.",
          "is_bot": false,
          "headline": "Let extensions contribute World State sections (#30100)",
          "author_name": "jif",
          "author_login": "jif-oai",
          "committed_at": "2026-06-25T21:23:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "db541f45536f18741b50c74b05904a2c5f628c96",
          "body": "## Summary\n\nThis PR extends the existing managed `mcp_servers` identity requirement\nso that one name-qualified rule can use either:\n\n- the released exact command or URL identity;\n- an exact stdio executable with an exact-length, ordered argument\nmatcher list; or\n- a direct MCP URL matcher.\n\nMatcher-\n[…]\ns internal MCP URLs passed to a proxy.\n\n## Validation\n\n- `just fmt`\n- `git diff --check`\n- `just test -p codex-config` (198 passed)\n- `just test -p codex-core mcp_servers_by_matchers --lib` (2 passed)",
          "is_bot": false,
          "headline": "[codex] Add managed MCP server matchers (#29648)",
          "author_name": "felixxia-oai",
          "author_login": "felixxia-oai",
          "committed_at": "2026-06-25T21:15:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e23e7cbe4634bf1eed1584414e6bbb8a2be349f6",
          "body": "## Why\n\nOnce #30114 publishes zsh independently, regular Rust releases should\nreuse that protected, versioned artifact set instead of rebuilding\nidentical zsh binaries for every Codex version. Keeping the zsh release\ntag explicit in the workflow also makes future artifact upgrades\ndeliberate and eas\n[…]\nies a standalone manifest\noverride and verifies the extracted zsh bytes.\n- Ran the `scripts/codex_package` unit test suite.\n- Validated `.github/scripts/build-codex-package-archive.sh` with `bash\n-n`.",
          "is_bot": false,
          "headline": "release: consume standalone zsh artifacts (#30116)",
          "author_name": "Michael Bolin",
          "author_login": "bolinfest",
          "committed_at": "2026-06-25T21:05:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "891f1f4c8584a082fc4658cabd48f1a8b01354e0",
          "body": "## Why\n\nThe patched zsh artifacts rarely change, but\n`.github/workflows/rust-release-zsh.yml` currently runs as part of every\nRust release. Rebuilding the same four binaries for each Codex version\nwastes release capacity and ties an independently versioned runtime\ndependency to the main release cade\n[…]\n\n\n\n---\n[//]: # (BEGIN SAPLING FOOTER)\nStack created with [Sapling](https://sapling-scm.com). Best reviewed\nwith [ReviewStack](https://reviewstack.dev/openai/codex/pull/30114).\n* #30116\n* __->__ #30114",
          "is_bot": false,
          "headline": "release: publish standalone zsh artifacts (#30114)",
          "author_name": "Michael Bolin",
          "author_login": "bolinfest",
          "committed_at": "2026-06-25T20:56:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "703793c22efc1e47de51703150f5cf16976ff456",
          "body": "## Description\n\nThis makes Codex Apps tool reads use a shared in-memory snapshot instead\nof rereading the disk cache every time `list_all_tools()` runs. Disk\nstill seeds the cache on startup and gets updated after successful\nfetches, but it is no longer the live read path.\n\nThe core change is that `\n[…]\nist_all_tools()` and tool-payload construction.\n\nThis is on my M2 Max macbook, so with a slower disk this would be much\nworse (and indeed we did see this really blew up turn runtime with a\nslow disk).",
          "is_bot": false,
          "headline": "feat(core, mcp): cache codex_apps tools in memory (#29003)",
          "author_name": "Owen Lin",
          "author_login": "owenlin0",
          "committed_at": "2026-06-25T20:54:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "62c7f506d9a8892724ee025da04bfef74f092ccb",
          "body": "## Summary\n\n- make the external app-server time provider establish sleep deadlines\nusing `currentTime/read`\n- poll the external clock once per second and complete `clock.sleep`\nwhen the deadline is reached\n- keep the system-clock timer and existing steer/agent-message\ninterruption behavior unchanged\n[…]\nits existing external\nsimulated clock without adding separate sleep/wake protocol methods.\n\n## Testing\n\n- `just fmt`\n- `just test -p codex-app-server\nexternal_sleep_polls_current_time_and_emits_items`",
          "is_bot": false,
          "headline": "[codex] poll external clock during sleep (#30113)",
          "author_name": "rka-oai",
          "author_login": "rka-oai",
          "committed_at": "2026-06-25T20:46:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3b22498f69112eb1f7dd3061e278e344626e834c",
          "body": "## Summary\n\n- Record bounded duration and outcome metrics for remote environment\nregistration and Noise rendezvous connection attempts.\n- Count reconnects by bounded reason: disconnect, connection failure, or\nrejected registration.\n- Trace registration at the owning client boundary without exporting\n[…]\nserver --lib` (149 passed)\n- `just test -p codex-cli --test exec_server` (4 passed)\n- `just argument-comment-lint`\n- `just bazel-lock-check`\n- `just fix -p codex-exec-server -p codex-cli`\n- `just fmt`",
          "is_bot": false,
          "headline": "[codex] Observe remote exec-server lifecycle (#27470)",
          "author_name": "richardopenai",
          "author_login": "richardopenai",
          "committed_at": "2026-06-25T20:42:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3b78f58fb2e672fc1e5f808963dc65544f571392",
          "body": "## Summary\n\n- add an `EncodedFrame` type so IPC payloads are serialized and\nsize-checked before entering bounded queues\n- add the V1 `operation/cancel` client-to-host message\n- pin the new wire shape with protocol tests\n\n## Why\n\nThe process-owned code-mode host needs bounded, pre-encoded outbound\nme\n[…]\n the process-owned code-mode session stack. The\nnext PR targets this branch.\n\n## Validation\n\n- `just test -p codex-code-mode-protocol` — 22 passed\n- `just fix -p codex-code-mode-protocol`\n- `just fmt`",
          "is_bot": false,
          "headline": "[codex] extend code-mode host IPC transport (#30108)",
          "author_name": "Channing Conger",
          "author_login": "cconger",
          "committed_at": "2026-06-25T20:26:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "adccb464d075a39d5450d6bc879e3bb6c97ce14b",
          "body": "…ries (#30033)\n\n## Summary\n- track user-like input and tool-output boundaries in current-time\nreminder state\n- gate reminder injection when delivery_mode is\nafter_user_or_tool_output\n- preserve interval debounce and forced reminders after context-window\nchanges\n\n## Why\nTraining can request reminders\n[…]\nputs\n- just test -p codex-core\ncurrent_time_reminders_follow_time_interval_and_persist_in_history\n- just test -p codex-core\ncurrent_time_reminder_is_refreshed_after_compaction\n- just fix -p codex-core",
          "is_bot": false,
          "headline": "[codex] impl delivery_mode: current time reminders on response bounda…",
          "author_name": "rka-oai",
          "author_login": "rka-oai",
          "committed_at": "2026-06-25T19:28:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "964b138c3db16088a3bff5cc599bfd31428d03e9",
          "body": "## Summary\n\n- retry ERS `409 environment_offline` responses inside the existing\nexec-server recovery loop\n- keep all other registry conflicts terminal\n- add focused coverage for both cases\n\n## Root cause\n\nWhen an exec server disconnects and reconnects, the client already\nstarts recovery and calls ER\n[…]\nt -p codex-exec-server` reached unrelated macOS\nfilesystem-sandbox integration failures because nested\n`/usr/bin/sandbox-exec` is denied in this environment (`sandbox_apply:\nOperation not permitted`).",
          "is_bot": false,
          "headline": "[codex] Retry temporarily offline exec-server recovery (#30098)",
          "author_name": "richardopenai",
          "author_login": "richardopenai",
          "committed_at": "2026-06-25T19:25:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e8d4a1a411bbab9be85e704ae3847915916bf347",
          "body": "```python\ndelivery_mode = \"any_inference\" # default\ndelivery_mode = \"after_user_or_tool_output\" # new mode\n``` \n\n## Validation\n- just test -p codex-core load_config_resolves_current_time_reminder\n- just test -p codex-core\nlock_contains_prompts_and_materializes_features",
          "is_bot": false,
          "headline": "[codex] add current time reminder delivery mode config (#30031)",
          "author_name": "rka-oai",
          "author_login": "rka-oai",
          "committed_at": "2026-06-25T19:06:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c65cfeab1478c4c8356b42aca3d06c92b2730334",
          "body": "## tl;dr\n\nInject a `CODEX_PERMISSION_PROFILE` environment variable with the name\nof the current permission profile when invoking a shell tool.\n\n## Why\n\nShell tool owners may need to launch nested commands under the same\nnamed permission profile, including through `codex sandbox -P PROFILE\n--include-\n[…]\nd coverage for overriding and removing stale profile values.\n- Verified `shell_command` receives the selected active profile.\n- Added shell snapshot coverage using `printenv\nCODEX_PERMISSION_PROFILE`.",
          "is_bot": false,
          "headline": "core: expose permission profile to shell tools (#29941)",
          "author_name": "Michael Bolin",
          "author_login": "bolinfest",
          "committed_at": "2026-06-25T19:00:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cc78903379773233264ae9e3ccd3740439d70b51",
          "body": "A zero interval lets callers request a reminder at every\notherwise-eligible inference boundary.\n\n## Validation\n- just test -p codex-core load_config_resolves_current_time_reminder",
          "is_bot": false,
          "headline": "[codex] current time reminder interval to be set to 0 (#30029)",
          "author_name": "rka-oai",
          "author_login": "rka-oai",
          "committed_at": "2026-06-25T18:30:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "31b99f65cf4b3eaf9180f625b48b5614806cd121",
          "body": "## Why\n\n`codex sandbox` accepts a single named permissions profile, so the\nexisting plural `--permissions-profile` spelling is misleading. The\ncanonical flag and its help text should use the singular form without\nbreaking scripts that already use the old spelling.\n\n## What changed\n\n- Make `--permiss\n[…]\nion tests.\n\n## Testing\n\nRan `just c sandbox --help` and verified I saw:\n\n```shell\n  -P, --permission-profile <NAME>\n          Named permissions profile to apply from the active configuration stack\n```",
          "is_bot": false,
          "headline": "cli: rename sandbox permission profile flag (#30095)",
          "author_name": "Michael Bolin",
          "author_login": "bolinfest",
          "committed_at": "2026-06-25T18:25:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6d9dbacf1af69fc9b633132e34d63be202556a24",
          "body": "## Why\n\nHelper threads such as task title generation can request a model ID that\nis valid for the default OpenAI provider but unavailable from the active\nprovider. With Amazon Bedrock, `gpt-5.4-mini` is rejected while the\nprovider static catalog exposes Bedrock model IDs such as\n`openai.gpt-5.5` and\n[…]\nel\": \"gpt-5.4-mini\",\n>   \"modelProvider\": null,\n>   \"allowProviderModelFallback\": true,\n>   ...\n> }\n\n< \"result\": {\n<   \"model\": \"openai.gpt-5.5\",\n<   \"modelProvider\": \"amazon-bedrock\",\n<   ...\n< }\n```",
          "is_bot": false,
          "headline": "feat: add provider-aware model fallback to thread start (#29942)",
          "author_name": "Celia Chen",
          "author_login": "celia-oai",
          "committed_at": "2026-06-25T18:24:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2dec46e30ae81aa4844cc7a5474ff5c95c6998c0",
          "body": "## Summary\n\n- Record bounded connection, request, and process lifecycle metrics.\n- Report active gauges from callbacks on every collection, including\ndelta exports.\n- Serialize active-count updates so concurrent starts and finishes\ncannot publish stale values.\n- Serialize process exit, explicit term\n[…]\nassed)\n- `just test -p codex-otel\nobservable_gauge_is_collected_on_every_delta_snapshot` (1 passed)\n- `CARGO_BUILD_JOBS=1 just fix -p codex-otel -p codex-exec-server`\n- `just fmt`\n- `git diff --check`",
          "is_bot": false,
          "headline": "[codex] Record exec-server lifecycle metrics (#27467)",
          "author_name": "richardopenai",
          "author_login": "richardopenai",
          "committed_at": "2026-06-25T18:02:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8f02973d2541fb98d9a626f07d8f3661cb2a9e71",
          "body": "…step (#29856)\n\n## Why\n\n`selectedCapabilityRoots` is durable thread intent: “use this capability\nroot from environment `worker`.”\n\nThe important product assumption is:\n\n> One environment ID always names the same logical executor and stable\ncontents.\n\n`worker` does not silently change from executor A\n[…]\n\nan exact model-step handle.\n2. #29960: cache stable skill metadata and project available skills into\nWorld State.\n3. #29946: cache stable plugin declarations and manage the separate live\nMCP runtime.",
          "is_bot": false,
          "headline": "Persist selected capability roots and resolve availability per model …",
          "author_name": "jif",
          "author_login": "jif-oai",
          "committed_at": "2026-06-25T17:49:43Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "268328001f899ec02cebab238fdeafda052525b6",
          "body": "We will drop support for this in the near future due to the complexity\nit introduces.",
          "is_bot": false,
          "headline": "chore(app-server): mark thread/rollback as deprecated (#29928)",
          "author_name": "Owen Lin",
          "author_login": "owenlin0",
          "committed_at": "2026-06-25T17:15:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c38b2e9ba69cb57d197c6e5ba78b5e52ae0870f9",
          "body": "## Why\n\n#28529 proves OAuth discovery uses the selected executor, but its\nend-to-end test stops before the callback and token exchange.\n\n## What changed\n\n- add an executor-only mock token endpoint\n- complete the OAuth callback using the authorization URL's `state` and\n`redirect_uri`\n- assert the PKCE token exchange reaches the executor-only endpoint\n- assert the completion notification reports the selected thread and\nsucceeds\n\nDepends on #28529.",
          "is_bot": false,
          "headline": "Test executor-routed MCP OAuth token exchange (#29656)",
          "author_name": "jif",
          "author_login": "jif-oai",
          "committed_at": "2026-06-25T09:45:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b215961a56b2553a4612a22a812747403c08a58b",
          "body": "…8529)\n\n## Why\n\n#28522 routes selected-plugin HTTP MCP traffic through the owning\nexecutor, but OAuth bootstrap and refresh still used host-local clients.\nExecutor-only servers therefore cannot complete discovery or login\nthrough the same network boundary as the MCP connection.\n\n## What changed\n\n- a\n[…]\nn notification\n- implement RMCP's redirect policy and 1 MiB OAuth response limit over\nexecutor HTTP\n- cover selected-thread OAuth discovery and login through an\nexecutor-only route\n\nDepends on #28522.",
          "is_bot": false,
          "headline": "Support OAuth for HTTP MCP servers from selected executor plugins (#2…",
          "author_name": "jif",
          "author_login": "jif-oai",
          "committed_at": "2026-06-25T09:31:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6368937939dceb07b4a3c47c4448027d0d1a85a6",
          "body": "## Why\n\nSelected executor plugins can declare both stdio and Streamable HTTP MCP\nservers, but only stdio registrations were retained. That silently drops\npart of the plugin's tool surface and prevents HTTP traffic from using\nthe owning executor's network.\n\n## What changed\n\n- retain selected-plugin S\n[…]\nutor environment\n- preserve local auth-header environment references while rejecting them\nfor executor-hosted declarations\n- cover thread isolation, refresh, and an executor-only HTTP route end\nto end",
          "is_bot": false,
          "headline": "Support HTTP MCP servers from selected executor plugins (#28522)",
          "author_name": "jif",
          "author_login": "jif-oai",
          "committed_at": "2026-06-25T09:10:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5579792b3b881b44ba42139f9fcd191c4a944128",
          "body": "## Why\n\nAvoid a request waterfall for loading lots of skills at once by hiding\nlatency in concurrent tasks.\n\n## What changed\n\nPoll the per-skill parse futures concurrently with an order-preserving\nstream capped at 64 in-flight loads. Results retain discovery order, and\nthe existing filtering, warnings, and final catalog sorting are\nunchanged.",
          "is_bot": false,
          "headline": "Parallelize environment skill loading (#29990)",
          "author_name": "Adam Perry @ OpenAI",
          "author_login": "anp-oai",
          "committed_at": "2026-06-25T09:02:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ab80d4d484609719621826946cd9e137a3558862",
          "body": "## Why\n\nOlder rollouts can retain model-visible context for a WorldState section\nwithout having a persisted snapshot for that section. Treating the\nmissing snapshot as definitely absent can duplicate old context or fail\nto tell the model that it was replaced or removed.\n\nThis provides a generic migr\n[…]\nng when persisted section data is\nmissing or malformed\n\n## Testing\n\n- `just test -p codex-core world_state`\n- `just test -p codex-core\ncold_resume_invalidates_deleted_legacy_agents_md_once -- --exact`",
          "is_bot": false,
          "headline": "core: reconcile legacy WorldState sections (#29997)",
          "author_name": "sayan-oai",
          "author_login": "sayan-oai",
          "committed_at": "2026-06-25T07:03:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f2f80ef442ff84612004bad064991283eb17cdb5",
          "body": "## Why\n\nWith deferred executors, a turn can begin before a remote environment\nattaches. AGENTS.md discovery previously ran only during session setup,\nso instructions from a later environment never reached the model or the\nsession instruction sources.\n\nWorldState persistence has now landed, so this u\n[…]\nning creation-time instructions in\nthe live session and cold resume appending one replacement when the\nsource changed.\n- Ran focused `codex-core` AGENTS.md, WorldState, and context-update\ntest suites.",
          "is_bot": false,
          "headline": "core: make AGENTS.md react to environment changes (#29810)",
          "author_name": "sayan-oai",
          "author_login": "sayan-oai",
          "committed_at": "2026-06-25T05:57:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        }
      ],
      "releases_count": 5,
      "commits_last_year": 7398,
      "latest_release_at": "2026-07-18T12:52:59Z",
      "latest_release_tag": "rust-v1.0.5",
      "releases_from_tags": false,
      "days_since_last_push": 5,
      "active_weeks_last_year": 52,
      "days_since_latest_release": 5,
      "mean_days_between_releases": 2.5
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 85,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "midnight-coder",
          "exists": true,
          "license": "Apache-2.0",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/midnight-coder",
          "is_deprecated": false,
          "latest_version": "1.0.5",
          "repository_url": "https://github.com/midnightcoderagent/Midnight-Coder",
          "versions_count": 23,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2714,
          "first_published_at": "2026-07-08T17:11:31.455000Z",
          "latest_published_at": "2026-07-18T12:54:53.926000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 11
    },
    "ai_readiness": {
      "has_nix": true,
      "example_dirs": [
        "demos",
        "examples",
        "notebooks",
        "samples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": true,
      "bootstrap_files": [
        "justfile"
      ],
      "api_schema_files": [
        "codex-rs/config/src/thread_config/proto/codex.thread_config.v1.proto",
        "codex-rs/exec-server/src/proto/codex.exec_server.relay.v1.proto"
      ],
      "has_devcontainer": true,
      "typecheck_configs": [
        "sdk/python/src/openai_codex/py.typed",
        "sdk/typescript/tsconfig.json"
      ],
      "toolchain_manifests": [
        "codex-rs/Cargo.toml",
        "codex-rs/agent-graph-store/Cargo.toml",
        "codex-rs/agent-identity/Cargo.toml",
        "codex-rs/analytics/Cargo.toml",
        "codex-rs/ansi-escape/Cargo.toml",
        "codex-rs/app-server-client/Cargo.toml",
        "codex-rs/app-server-daemon/Cargo.toml",
        "codex-rs/app-server-protocol/Cargo.toml",
        "codex-rs/app-server-test-client/Cargo.toml",
        "codex-rs/app-server-transport/Cargo.toml",
        "codex-rs/app-server/Cargo.toml",
        "codex-rs/app-server/tests/common/Cargo.toml",
        "codex-rs/apply-patch/Cargo.toml",
        "codex-rs/arg0/Cargo.toml",
        "codex-rs/async-utils/Cargo.toml",
        "codex-rs/aws-auth/Cargo.toml",
        "codex-rs/backend-client/Cargo.toml",
        "codex-rs/bwrap/Cargo.toml",
        "codex-rs/chatgpt/Cargo.toml",
        "codex-rs/cli/Cargo.toml",
        "codex-rs/cloud-config/Cargo.toml",
        "codex-rs/cloud-tasks-client/Cargo.toml",
        "codex-rs/cloud-tasks-mock-client/Cargo.toml",
        "codex-rs/cloud-tasks/Cargo.toml",
        "codex-rs/code-mode-host/Cargo.toml",
        "codex-rs/code-mode-protocol/Cargo.toml",
        "codex-rs/code-mode/Cargo.toml",
        "codex-rs/codex-api/Cargo.toml",
        "codex-rs/codex-backend-openapi-models/Cargo.toml",
        "codex-rs/codex-client/Cargo.toml",
        "codex-rs/codex-experimental-api-macros/Cargo.toml",
        "codex-rs/codex-home/Cargo.toml",
        "codex-rs/codex-mcp/Cargo.toml",
        "codex-rs/collaboration-mode-templates/Cargo.toml",
        "codex-rs/config/Cargo.toml",
        "codex-rs/connectors/Cargo.toml",
        "codex-rs/context-fragments/Cargo.toml",
        "codex-rs/core-api/Cargo.toml",
        "codex-rs/core-plugins/Cargo.toml",
        "codex-rs/core-skills/Cargo.toml",
        "codex-rs/core/Cargo.toml",
        "codex-rs/core/tests/common/Cargo.toml",
        "codex-rs/exec-server-protocol/Cargo.toml",
        "codex-rs/exec-server/Cargo.toml",
        "codex-rs/exec/Cargo.toml",
        "codex-rs/execpolicy-legacy/Cargo.toml",
        "codex-rs/execpolicy/Cargo.toml",
        "codex-rs/ext/connectors/Cargo.toml",
        "codex-rs/ext/extension-api/Cargo.toml",
        "codex-rs/ext/goal/Cargo.toml",
        "codex-rs/ext/guardian/Cargo.toml",
        "codex-rs/ext/image-generation/Cargo.toml",
        "codex-rs/ext/mcp/Cargo.toml",
        "codex-rs/ext/memories/Cargo.toml",
        "codex-rs/ext/skills/Cargo.toml",
        "codex-rs/ext/web-search/Cargo.toml",
        "codex-rs/external-agent-migration/Cargo.toml",
        "codex-rs/external-agent-sessions/Cargo.toml",
        "codex-rs/features/Cargo.toml",
        "codex-rs/feedback/Cargo.toml",
        "codex-rs/file-search/Cargo.toml",
        "codex-rs/file-system/Cargo.toml",
        "codex-rs/file-watcher/Cargo.toml",
        "codex-rs/git-utils/Cargo.toml",
        "codex-rs/hooks/Cargo.toml",
        "codex-rs/install-context/Cargo.toml",
        "codex-rs/keyring-store/Cargo.toml",
        "codex-rs/linux-sandbox/Cargo.toml",
        "codex-rs/lmstudio/Cargo.toml",
        "codex-rs/login/Cargo.toml",
        "codex-rs/mcp-server/Cargo.toml",
        "codex-rs/mcp-server/tests/common/Cargo.toml",
        "codex-rs/memories/read/Cargo.toml",
        "codex-rs/memories/write/Cargo.toml",
        "codex-rs/message-history/Cargo.toml",
        "codex-rs/model-provider-info/Cargo.toml",
        "codex-rs/model-provider/Cargo.toml",
        "codex-rs/models-manager/Cargo.toml",
        "codex-rs/network-proxy/Cargo.toml",
        "codex-rs/ollama/Cargo.toml",
        "codex-rs/otel/Cargo.toml",
        "codex-rs/plugin/Cargo.toml",
        "codex-rs/process-hardening/Cargo.toml",
        "codex-rs/prompts/Cargo.toml",
        "codex-rs/protocol/Cargo.toml",
        "codex-rs/realtime-webrtc/Cargo.toml",
        "codex-rs/response-debug-context/Cargo.toml",
        "codex-rs/responses-api-proxy/Cargo.toml",
        "codex-rs/rmcp-client/Cargo.toml",
        "codex-rs/rollout-trace/Cargo.toml",
        "codex-rs/rollout/Cargo.toml",
        "codex-rs/sandboxing/Cargo.toml",
        "codex-rs/secrets/Cargo.toml",
        "codex-rs/shell-command/Cargo.toml",
        "codex-rs/shell-escalation/Cargo.toml",
        "codex-rs/skills/Cargo.toml",
        "codex-rs/state/Cargo.toml",
        "codex-rs/stdio-to-uds/Cargo.toml",
        "codex-rs/terminal-detection/Cargo.toml",
        "codex-rs/test-binary-support/Cargo.toml",
        "codex-rs/thread-manager-sample/Cargo.toml",
        "codex-rs/thread-store/Cargo.toml",
        "codex-rs/tools/Cargo.toml",
        "codex-rs/tui/Cargo.toml",
        "codex-rs/uds/Cargo.toml",
        "codex-rs/utils/absolute-path/Cargo.toml",
        "codex-rs/utils/approval-presets/Cargo.toml",
        "codex-rs/utils/cache/Cargo.toml",
        "codex-rs/utils/cargo-bin/Cargo.toml",
        "codex-rs/utils/cli/Cargo.toml",
        "codex-rs/utils/elapsed/Cargo.toml",
        "codex-rs/utils/fuzzy-match/Cargo.toml",
        "codex-rs/utils/home-dir/Cargo.toml",
        "codex-rs/utils/image/Cargo.toml",
        "codex-rs/utils/json-to-toml/Cargo.toml",
        "codex-rs/utils/oss/Cargo.toml",
        "codex-rs/utils/output-truncation/Cargo.toml",
        "codex-rs/utils/path-uri/Cargo.toml",
        "codex-rs/utils/path-utils/Cargo.toml",
        "codex-rs/utils/plugins/Cargo.toml",
        "codex-rs/utils/pty/Cargo.toml",
        "codex-rs/utils/readiness/Cargo.toml",
        "codex-rs/utils/rustls-provider/Cargo.toml",
        "codex-rs/utils/sandbox-summary/Cargo.toml",
        "codex-rs/utils/sleep-inhibitor/Cargo.toml",
        "codex-rs/utils/stream-parser/Cargo.toml",
        "codex-rs/utils/string/Cargo.toml",
        "codex-rs/utils/template/Cargo.toml",
        "codex-rs/v8-poc/Cargo.toml",
        "codex-rs/windows-sandbox-rs/Cargo.toml",
        "tools/argument-comment-lint/Cargo.toml"
      ],
      "largest_source_bytes": 438946,
      "source_files_sampled": 3213,
      "oversized_source_files": 120,
      "agent_instruction_files": [
        "AGENTS.md",
        "codex-rs/tui/src/bottom_pane/AGENTS.md"
      ],
      "agent_instruction_max_bytes": 23188
    },
    "dependencies": {
      "manifests": [
        "codex-cli/package.json",
        "codex-rs/Cargo.toml",
        "package.json",
        "scripts/pyproject.toml"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates",
        "npm",
        "pypi"
      ],
      "dependencies": [
        {
          "name": "ruff",
          "manifest": "scripts/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.15.8"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 11,
        "merged_prs": 0,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 2
      },
      "bus_factor": 5,
      "bot_contributors": 2,
      "top_contributors": [
        {
          "type": "User",
          "login": "jif-oai",
          "commits": 1160,
          "avatar_url": "https://avatars.githubusercontent.com/u/230027070?v=4"
        },
        {
          "type": "User",
          "login": "bolinfest",
          "commits": 1001,
          "avatar_url": "https://avatars.githubusercontent.com/u/655869?v=4"
        },
        {
          "type": "User",
          "login": "aibrahim-oai",
          "commits": 582,
          "avatar_url": "https://avatars.githubusercontent.com/u/219906144?v=4"
        },
        {
          "type": "User",
          "login": "pakrym-oai",
          "commits": 532,
          "avatar_url": "https://avatars.githubusercontent.com/u/204937752?v=4"
        },
        {
          "type": "User",
          "login": "etraut-openai",
          "commits": 472,
          "avatar_url": "https://avatars.githubusercontent.com/u/223546144?v=4"
        },
        {
          "type": "User",
          "login": "dylan-hurd-oai",
          "commits": 219,
          "avatar_url": "https://avatars.githubusercontent.com/u/220976066?v=4"
        },
        {
          "type": "User",
          "login": "nornagon-openai",
          "commits": 204,
          "avatar_url": "https://avatars.githubusercontent.com/u/172423086?v=4"
        },
        {
          "type": "User",
          "login": "owenlin0",
          "commits": 166,
          "avatar_url": "https://avatars.githubusercontent.com/u/947871?v=4"
        },
        {
          "type": "User",
          "login": "viyatb-oai",
          "commits": 143,
          "avatar_url": "https://avatars.githubusercontent.com/u/234056686?v=4"
        },
        {
          "type": "User",
          "login": "iceweasel-oai",
          "commits": 133,
          "avatar_url": "https://avatars.githubusercontent.com/u/234057055?v=4"
        }
      ],
      "contributors_sampled": 98,
      "top_contributor_share": 0.161
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "bazel.yml",
        "blob-size-policy.yml",
        "blocking-ci.yml",
        "cargo-deny.yml",
        "cla.yml",
        "close-stale-contributor-prs.yml",
        "codespell.yml",
        "issue-deduplicator.yml",
        "issue-labeler.yml",
        "issue-translator.yml",
        "postmerge-ci.yml",
        "python-runtime-build.yml",
        "python-runtime-release.yml",
        "python-sdk-release.yml",
        "repo-checks.yml",
        "rust-ci-full-nextest-platform.yml",
        "rust-ci-full.yml",
        "rust-ci.yml",
        "rust-release-argument-comment-lint.yml",
        "rust-release-prepare.yml",
        "rust-release-windows.yml",
        "rust-release-zsh.yml",
        "rust-release.yml",
        "rusty-v8-release.yml",
        "sdk.yml",
        "v8-canary.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        "eslint.config.js"
      ],
      "has_editorconfig": true,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock",
        "pnpm-lock.yaml",
        "uv.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 3 contributing companies or organizations -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 9,
            "reason": "dependency not pinned by hash detected -- score normalized to 9",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 8,
            "reason": "5 out of the last 5 releases have a total of 5 signed artifacts.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "67 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "9acdc15a545f3d6a66379835d7be798de6899a38",
        "ran_at": "2026-07-23T20:36:22Z",
        "aggregate_score": 4.9,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": true
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-23T17:03:27Z",
      "oldest_open_prs": [
        {
          "number": 2,
          "created_at": "2026-07-03T17:35:11Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 3,
          "created_at": "2026-07-03T17:35:16Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 4,
          "created_at": "2026-07-03T17:35:18Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 5,
          "created_at": "2026-07-03T17:35:21Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 6,
          "created_at": "2026-07-03T17:35:32Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 7,
          "created_at": "2026-07-03T17:44:30Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 8,
          "created_at": "2026-07-03T17:45:00Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 9,
          "created_at": "2026-07-03T17:45:59Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 10,
          "created_at": "2026-07-03T17:46:55Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 11,
          "created_at": "2026-07-03T17:47:50Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 13,
          "created_at": "2026-07-17T13:06:01Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": null,
      "ci_last_conclusion": "SKIPPED",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/midnightcoderagent/Midnight-Coder",
    "host": "github.com",
    "name": "Midnight-Coder",
    "owner": "midnightcoderagent"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 65,
      "inputs": {
        "security": 49,
        "vitality": 93,
        "community": 42,
        "governance": 51,
        "engineering": 83
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 93,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "excellent",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "commits_last_year": 7398,
              "human_commit_share": 1,
              "days_since_last_push": 5,
              "active_weeks_last_year": 52
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "52/52 weeks with commits",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 52
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "7398 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 7398
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "releases_count": 5,
              "latest_release_tag": "rust-v1.0.5",
              "releases_from_tags": false,
              "days_since_latest_release": 5,
              "mean_days_between_releases": 2.5
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "5 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 5 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~2.5 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 2.5
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "5 out of the last 5 releases have a total of 5 signed artifacts.",
                "points": 8,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 42,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 57,
            "inputs": {
              "packages": [
                "midnight-coder"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 2714
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "2,714 downloads/month across npm",
                "points": 45.8,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 2714,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 51,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "excellent",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 88,
            "inputs": {
              "bus_factor": 5,
              "contributors_sampled": 98,
              "top_contributor_share": 0.161
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "5 contributor(s) cover half of all commits",
                "points": 45.9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 5
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 16% of commits",
                "points": 18.9,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 16
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "98 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 98
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "critical",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 1,
            "inputs": {
              "merged_prs": 0,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 2
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "0/2 decided PRs merged",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 0,
                      "decided": 2
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "critical",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 19,
            "inputs": {
              "followers": 0,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "midnightcoderagent",
              "public_repos": 4,
              "account_age_days": 20
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of midnightcoderagent",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "midnightcoderagent"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "4 public repos, account ~0 yr old",
                "points": 5.2,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 4
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "midnight-coder"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 5
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 5 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 5
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "23 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 23
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 83,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "excellent",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 88,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": true,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "26 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 26
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.js",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 6.4,
                "status": "met",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 49,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 49,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 4.9
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 3 contributing companies or organizations -- score normalized to 10",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "5 out of the last 5 releases have a total of 5 signed artifacts.",
                "points": 6,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "67 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 1
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "excellent",
        "name": "AI Readiness",
        "value": 89,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "good",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 83,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.71,
              "agent_instruction_files": [
                "AGENTS.md",
                "codex-rs/tui/src/bottom_pane/AGENTS.md"
              ],
              "agent_instruction_max_bytes": 23188
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, codex-rs/tui/src/bottom_pane/AGENTS.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, codex-rs/tui/src/bottom_pane/AGENTS.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "71 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 37.9,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 71,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "excellent",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 86,
            "inputs": {
              "has_nix": true,
              "has_tests": true,
              "lockfiles": [
                "Cargo.lock",
                "pnpm-lock.yaml",
                "uv.lock"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [
                "justfile"
              ],
              "has_devcontainer": true,
              "has_linter_config": true,
              "typecheck_configs": [
                "sdk/python/src/openai_codex/py.typed",
                "sdk/typescript/tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "codex-rs/Cargo.toml",
                "codex-rs/agent-graph-store/Cargo.toml",
                "codex-rs/agent-identity/Cargo.toml",
                "codex-rs/analytics/Cargo.toml",
                "codex-rs/ansi-escape/Cargo.toml",
                "codex-rs/app-server-client/Cargo.toml",
                "codex-rs/app-server-daemon/Cargo.toml",
                "codex-rs/app-server-protocol/Cargo.toml",
                "codex-rs/app-server-test-client/Cargo.toml",
                "codex-rs/app-server-transport/Cargo.toml",
                "codex-rs/app-server/Cargo.toml",
                "codex-rs/app-server/tests/common/Cargo.toml",
                "codex-rs/apply-patch/Cargo.toml",
                "codex-rs/arg0/Cargo.toml",
                "codex-rs/async-utils/Cargo.toml",
                "codex-rs/aws-auth/Cargo.toml",
                "codex-rs/backend-client/Cargo.toml",
                "codex-rs/bwrap/Cargo.toml",
                "codex-rs/chatgpt/Cargo.toml",
                "codex-rs/cli/Cargo.toml",
                "codex-rs/cloud-config/Cargo.toml",
                "codex-rs/cloud-tasks-client/Cargo.toml",
                "codex-rs/cloud-tasks-mock-client/Cargo.toml",
                "codex-rs/cloud-tasks/Cargo.toml",
                "codex-rs/code-mode-host/Cargo.toml",
                "codex-rs/code-mode-protocol/Cargo.toml",
                "codex-rs/code-mode/Cargo.toml",
                "codex-rs/codex-api/Cargo.toml",
                "codex-rs/codex-backend-openapi-models/Cargo.toml",
                "codex-rs/codex-client/Cargo.toml",
                "codex-rs/codex-experimental-api-macros/Cargo.toml",
                "codex-rs/codex-home/Cargo.toml",
                "codex-rs/codex-mcp/Cargo.toml",
                "codex-rs/collaboration-mode-templates/Cargo.toml",
                "codex-rs/config/Cargo.toml",
                "codex-rs/connectors/Cargo.toml",
                "codex-rs/context-fragments/Cargo.toml",
                "codex-rs/core-api/Cargo.toml",
                "codex-rs/core-plugins/Cargo.toml",
                "codex-rs/core-skills/Cargo.toml",
                "codex-rs/core/Cargo.toml",
                "codex-rs/core/tests/common/Cargo.toml",
                "codex-rs/exec-server-protocol/Cargo.toml",
                "codex-rs/exec-server/Cargo.toml",
                "codex-rs/exec/Cargo.toml",
                "codex-rs/execpolicy-legacy/Cargo.toml",
                "codex-rs/execpolicy/Cargo.toml",
                "codex-rs/ext/connectors/Cargo.toml",
                "codex-rs/ext/extension-api/Cargo.toml",
                "codex-rs/ext/goal/Cargo.toml",
                "codex-rs/ext/guardian/Cargo.toml",
                "codex-rs/ext/image-generation/Cargo.toml",
                "codex-rs/ext/mcp/Cargo.toml",
                "codex-rs/ext/memories/Cargo.toml",
                "codex-rs/ext/skills/Cargo.toml",
                "codex-rs/ext/web-search/Cargo.toml",
                "codex-rs/external-agent-migration/Cargo.toml",
                "codex-rs/external-agent-sessions/Cargo.toml",
                "codex-rs/features/Cargo.toml",
                "codex-rs/feedback/Cargo.toml",
                "codex-rs/file-search/Cargo.toml",
                "codex-rs/file-system/Cargo.toml",
                "codex-rs/file-watcher/Cargo.toml",
                "codex-rs/git-utils/Cargo.toml",
                "codex-rs/hooks/Cargo.toml",
                "codex-rs/install-context/Cargo.toml",
                "codex-rs/keyring-store/Cargo.toml",
                "codex-rs/linux-sandbox/Cargo.toml",
                "codex-rs/lmstudio/Cargo.toml",
                "codex-rs/login/Cargo.toml",
                "codex-rs/mcp-server/Cargo.toml",
                "codex-rs/mcp-server/tests/common/Cargo.toml",
                "codex-rs/memories/read/Cargo.toml",
                "codex-rs/memories/write/Cargo.toml",
                "codex-rs/message-history/Cargo.toml",
                "codex-rs/model-provider-info/Cargo.toml",
                "codex-rs/model-provider/Cargo.toml",
                "codex-rs/models-manager/Cargo.toml",
                "codex-rs/network-proxy/Cargo.toml",
                "codex-rs/ollama/Cargo.toml",
                "codex-rs/otel/Cargo.toml",
                "codex-rs/plugin/Cargo.toml",
                "codex-rs/process-hardening/Cargo.toml",
                "codex-rs/prompts/Cargo.toml",
                "codex-rs/protocol/Cargo.toml",
                "codex-rs/realtime-webrtc/Cargo.toml",
                "codex-rs/response-debug-context/Cargo.toml",
                "codex-rs/responses-api-proxy/Cargo.toml",
                "codex-rs/rmcp-client/Cargo.toml",
                "codex-rs/rollout-trace/Cargo.toml",
                "codex-rs/rollout/Cargo.toml",
                "codex-rs/sandboxing/Cargo.toml",
                "codex-rs/secrets/Cargo.toml",
                "codex-rs/shell-command/Cargo.toml",
                "codex-rs/shell-escalation/Cargo.toml",
                "codex-rs/skills/Cargo.toml",
                "codex-rs/state/Cargo.toml",
                "codex-rs/stdio-to-uds/Cargo.toml",
                "codex-rs/terminal-detection/Cargo.toml",
                "codex-rs/test-binary-support/Cargo.toml",
                "codex-rs/thread-manager-sample/Cargo.toml",
                "codex-rs/thread-store/Cargo.toml",
                "codex-rs/tools/Cargo.toml",
                "codex-rs/tui/Cargo.toml",
                "codex-rs/uds/Cargo.toml",
                "codex-rs/utils/absolute-path/Cargo.toml",
                "codex-rs/utils/approval-presets/Cargo.toml",
                "codex-rs/utils/cache/Cargo.toml",
                "codex-rs/utils/cargo-bin/Cargo.toml",
                "codex-rs/utils/cli/Cargo.toml",
                "codex-rs/utils/elapsed/Cargo.toml",
                "codex-rs/utils/fuzzy-match/Cargo.toml",
                "codex-rs/utils/home-dir/Cargo.toml",
                "codex-rs/utils/image/Cargo.toml",
                "codex-rs/utils/json-to-toml/Cargo.toml",
                "codex-rs/utils/oss/Cargo.toml",
                "codex-rs/utils/output-truncation/Cargo.toml",
                "codex-rs/utils/path-uri/Cargo.toml",
                "codex-rs/utils/path-utils/Cargo.toml",
                "codex-rs/utils/plugins/Cargo.toml",
                "codex-rs/utils/pty/Cargo.toml",
                "codex-rs/utils/readiness/Cargo.toml",
                "codex-rs/utils/rustls-provider/Cargo.toml",
                "codex-rs/utils/sandbox-summary/Cargo.toml",
                "codex-rs/utils/sleep-inhibitor/Cargo.toml",
                "codex-rs/utils/stream-parser/Cargo.toml",
                "codex-rs/utils/string/Cargo.toml",
                "codex-rs/utils/template/Cargo.toml",
                "codex-rs/v8-poc/Cargo.toml",
                "codex-rs/windows-sandbox-rs/Cargo.toml",
                "tools/argument-comment-lint/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "justfile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "justfile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.js",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "sdk/python/src/openai_codex/py.typed, sdk/typescript/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "sdk/python/src/openai_codex/py.typed, sdk/typescript/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "devcontainer, Dockerfile, Nix, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "devcontainer, Dockerfile, Nix, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "dependency automation configured, none observed in the sampled commits",
                "points": 5,
                "status": "partial",
                "details": [
                  {
                    "code": "dependency_bot_config_only",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 9",
                "points": 9,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 98,
            "inputs": {
              "primary_language": "Rust",
              "largest_source_bytes": 438946,
              "source_files_sampled": 3213,
              "oversized_source_files": 120
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Rust (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Rust"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "120/3213 source files over 60KB",
                "points": 52.9,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 3213,
                      "oversized": 120
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "excellent",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "example_dirs": [
                "demos",
                "examples",
                "notebooks",
                "samples"
              ],
              "has_mcp_signal": true,
              "api_schema_files": [
                "codex-rs/config/src/thread_config/proto/codex.thread_config.v1.proto",
                "codex-rs/exec-server/src/proto/codex.exec_server.relay.v1.proto"
              ]
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": "codex-rs/config/src/thread_config/proto/codex.thread_config.v1.proto, codex-rs/exec-server/src/proto/codex.exec_server.relay.v1.proto",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "codex-rs/config/src/thread_config/proto/codex.thread_config.v1.proto, codex-rs/exec-server/src/proto/codex.exec_server.relay.v1.proto"
                    }
                  }
                ],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 20,
                "status": "met",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "demos, examples, notebooks, samples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "demos, examples, notebooks, samples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Could not fetch pypi package 'codex-scripts' from its registry",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index npm:midnight-coder@1.0.5; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-23T20:36:45.658897Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/m/midnightcoderagent/Midnight-Coder.svg",
  "full_name": "midnightcoderagent/Midnight-Coder",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计npm.