公开记录
软件健康报告模式 0.26.0 · 指标 1.13.0 · 2026-07-22 20:50 UTC

nodeve-com / nodeve

nodeve public npm packages (pnpm workspace)

TypeScriptMIT★ 0 星标⑂ 0 复刻始于 2026年6月在 GitHub 上查看 ↗

nodeve-com/nodeve 的健康指数为 100 分中的 53 分,处于「中等」区间。 其得分最高的类别是Vitality(71/100),最低的是Community & Adoption(34/100)。 最近一次更新在 3 天前。 近期的大部分工作由 1 位贡献者完成。

53
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

53
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

1 关注者1 个公开仓库始于 2026年6月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布
npm@nodeve/text2.1.0401428 天前
npm@nodeve/checks2.1.02,464235 天前
npm@nodeve/config0.5.11,03975 天前
npm@nodeve/encoding0.2.098233 天前
npm@nodeve/grimoire4.11.02,204153 天前
npm@nodeve/schema-case1.0.021019 天前

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

71良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 3 天前
3.5/36提交节奏 — 52 周中有 5 周有提交
18/18提交量 — 最近一年 118 次提交
0/10OpenSSF Scorecard:Maintained — project was created within the last 90 days. Please review its contents carefully
所用输入
commits_last_year118
human_commit_share0.99
days_since_last_push3
active_weeks_last_year5

发布纪律

90优秀
评分方式
27/27有发布版本 — 已发布 15 个发布版本
36/36发布时效 — 最近一次发布版本于 3 天前
27/27发布节奏 — 约每 0.3 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — Project has not signed or included provenance with any releases.
所用输入
releases_count15
latest_release_tag@nodeve/grimoire@4.11.0
releases_from_tags
days_since_latest_release3
mean_days_between_releases0.3

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

34存在风险 · 占总体的 18%
评分方式
0/60星标 — 0 个星标
0/25复刻 — 0 个复刻
0/15关注者 — 0 位关注者
所用输入
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

50中等
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(MIT)
0/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
50.8/80月度下载量 — npm 合计每月 6,416 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packages@nodeve/text, @nodeve/checks, @nodeve/config, @nodeve/encoding, @nodeve/grimoire, @nodeve/schema-case
dependents
ecosystemsnpm
total_downloads
monthly_downloads6,416
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

53中等 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0/22.5提交分布 — 头号贡献者编写了 100% 的提交
1.4/13.5贡献者广度 — 1 位贡献者
10/10OpenSSF Scorecard:Contributors — project has 11 contributing companies or organizations
所用输入
bus_factor1
contributors_sampled1
top_contributor_share1
评分方式
0/46.8议题解决 — 没有议题或无数据
38.2/38.3PR 接受 — 已裁定的 PR 中 3/3 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/28 approved changesets -- score normalized to 0
所用输入
merged_prs3
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
已排除计分(无数据或不适用):议题解决。 其余权重已重新归一化。
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
2.2/25所有者影响力 — nodeve-com 有 1 位关注者
2.4/25既往记录 — 1 个公开仓库,账户约 0 年
所用输入
followers1
owner_typeOrganization
is_verified
owner_loginnodeve-com
public_repos1
account_age_days34
评分方式
25/25已发布且可解析 — npm 上有 6 个软件包
35/35发布时效 — 最近一次发布于 3 天前
20/20版本历史 — 23 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packages@nodeve/text, @nodeve/checks, @nodeve/config, @nodeve/encoding, @nodeve/grimoire, @nodeve/schema-case
ecosystemsnpm
any_deprecated
min_days_since_publish3

工程质量

基础的工程与文档实践是否到位?

58中等 · 占总体的 20%

工程实践

64中等
评分方式
24/24CI 工作流 — 1 个工作流
24/24存在测试
16/16Linter 配置 — eslint.config.js
0/9.6Pre-commit 钩子
0/6.4.editorconfig
0/20OpenSSF Scorecard:CI-Tests — 0 out of 3 merged PRs checked by a CI test -- score normalized to 0
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

50中等
评分方式
30/30README
0/25文档目录
0/15文档 / 主页站点
10/10仓库描述
0/10主题标签
10/10Wiki
所用输入
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

41存在风险 · 占总体的 16%

安全态势

26危急
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — 0 out of 3 merged PRs checked by a CI test -- score normalized to 0
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/28 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 11 contributing companies or organizations
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — 无数据
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
3/7.5Vulnerabilities — 6 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate2.5
已排除计分(无数据或不适用):packaging。 其余权重已重新归一化。
评分方式
35/35直接依赖不含已知公告 — 没有直接依赖携带已知公告
25/25间接依赖不含已知公告 — 没有间接依赖携带已知公告
0/40没有长期未处理的公告 — 没有公告带有发布日期
所用输入
sourceosv
advisories0
affected_packages0
assessed_packages1
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
已排除计分(无数据或不适用):没有长期未处理的公告。 其余权重已重新归一化。 比对的是 npm:@nodeve/text@2.1.0 的运行时依赖闭包——安装已发布的软件包时真正被拉取进来的内容——共 1 个软件包。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

60中等 · 占总体的 0%
评分方式
18/45代理指令 — AGENTS.md, CLAUDE.md, packages/checks/AGENTS.md, packages/checks/CLAUDE.md, packages/config/CLAUDE.md, packages/encoding/CLAUDE.md, packages/grimoire/CLAUDE.md, packages/grimoire/concepts/CLAUDE.md, packages/grimoire/concepts/catalog/CLAUDE.md, packages/grimoire/concepts/property/CLAUDE.md, packages/text/CLAUDE.md(占位文件)
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 99 次人类提交中有 94 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.949
agent_instruction_filesAGENTS.md, CLAUDE.md, packages/checks/AGENTS.md, packages/checks/CLAUDE.md, packages/config/CLAUDE.md, packages/encoding/CLAUDE.md, packages/grimoire/CLAUDE.md, packages/grimoire/concepts/CLAUDE.md, packages/grimoire/concepts/catalog/CLAUDE.md, packages/grimoire/concepts/property/CLAUDE.md, packages/text/CLAUDE.md
agent_instruction_max_bytes177
评分方式
0/18一条命令的引导启动
22/22自动化测试
11/11Lint / 格式化配置 — eslint.config.js
11/11静态类型检查 — packages/checks/tsconfig.json, packages/config/tsconfig.json, packages/encoding/tsconfig.json, packages/grimoire/tsconfig.json, packages/schema-case/tsconfig.json, packages/text/tsconfig.json
10/10可复现环境 — Dockerfile, Nix, lockfile
0/10已体现的代理实践 — 最近 100 次提交中没有代理编写的提交
0/8自动化维护 — 未观察到自动依赖更新
0/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
所用输入
has_nix
has_tests
lockfilespnpm-lock.yaml
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configspackages/checks/tsconfig.json, packages/config/tsconfig.json, packages/encoding/tsconfig.json, packages/grimoire/tsconfig.json, packages/schema-case/tsconfig.json, packages/text/tsconfig.json
agent_commit_share0
toolchain_manifests
dependency_bot_commit_share0
评分方式
45/45可类型检查的代码 — TypeScript(静态类型)
55/55可控的文件大小 — 采样的 132 个源文件中有 0 个超过 60KB
所用输入
primary_languageTypeScript
largest_source_bytes14,024
source_files_sampled132
oversized_source_files0

机器可读接口

40存在风险
评分方式
0/40API 模式(OpenAPI/GraphQL/proto)
0/20MCP 服务器
40/40可运行示例 — examples
所用输入
example_dirsexamples
has_mcp_signal
api_schema_files

关键数据

0GitHub 星标
1贡献者
118最近 12 个月提交数
3距最近推送天数
15发布版本数
1巴士系数(bus factor)
0开放议题
npm软件包生态系统数

数据采集警告

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

更多细节

OpenSSF Scorecard 2.5 / 10
2.5综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-22 20:50 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
0CI-Tests0 out of 3 merged PRs checked by a CI test -- score normalized to 0
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/28 approved changesets -- score normalized to 0
10Contributorsproject has 11 contributing companies or organizations
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
不适用Packagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
4Vulnerabilities6 existing vulnerabilities detected
直接依赖 20
注册表软件包版本约束清单文件
npm@ast-grep/napicatalog:packages/checks/package.json
npm@nodeve/textworkspace:*packages/checks/package.json
npmjs-tiktokencatalog:packages/checks/package.json
npmjscpdcatalog:packages/checks/package.json
npmpluralizecatalog:packages/checks/package.json
npmprettiercatalog:packages/checks/package.json
npmremedacatalog:packages/checks/package.json
npmts-morphcatalog:packages/checks/package.json
npmtypescriptcatalog:packages/checks/package.json
npmyamlcatalog:packages/checks/package.json
npm@noble/hashescatalog:packages/encoding/package.json
npm@scure/basecatalog:packages/encoding/package.json
npm@nodeve/schema-caseworkspace:*packages/grimoire/package.json
npm@sinclair/typeboxcatalog:packages/grimoire/package.json
npmajvcatalog:packages/grimoire/package.json
npmremedacatalog:packages/grimoire/package.json
npmremeda-humpscatalog:packages/grimoire/package.json
npmyamlcatalog:packages/grimoire/package.json
npmremedacatalog:packages/schema-case/package.json
npmremedacatalog:packages/text/package.json
全部依赖 未采集

本报告未能采集到解析后的依赖集合:GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

依赖安全公告 0

安装 npm:@nodeve/text@2.1.0 会引入 1 个包(直接与传递):其中 0 个存在已知公告,0 个为直接依赖。

没有已知公告影响已评估的依赖。

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 1819,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Nix": 654,
        "Shell": 10,
        "JavaScript": 39738,
        "TypeScript": 1806527
      },
      "pushed_at": "2026-07-19T10:15:49Z",
      "created_at": "2026-06-18T12:19:22Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-19T10:15:05Z",
      "description": "nodeve public npm packages (pnpm workspace)",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": null,
      "name": null,
      "type": "Organization",
      "login": "nodeve-com",
      "company": null,
      "location": null,
      "followers": 1,
      "avatar_url": "https://avatars.githubusercontent.com/u/294811199?v=4",
      "created_at": "2026-06-18T12:18:07Z",
      "is_verified": null,
      "public_repos": 1,
      "account_age_days": 34
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "@nodeve/grimoire@4.11.0",
          "kind": "other",
          "published_at": "2026-07-19T10:15:49Z"
        },
        {
          "tag": "@nodeve/grimoire@4.10.0",
          "kind": "other",
          "published_at": "2026-07-18T23:10:51Z"
        },
        {
          "tag": "@nodeve/grimoire@4.9.0",
          "kind": "other",
          "published_at": "2026-07-17T15:47:05Z"
        },
        {
          "tag": "@nodeve/checks@2.1.0",
          "kind": "other",
          "published_at": "2026-07-17T15:47:02Z"
        },
        {
          "tag": "@nodeve/grimoire@4.8.0",
          "kind": "other",
          "published_at": "2026-07-17T13:35:34Z"
        },
        {
          "tag": "@nodeve/grimoire@4.7.0",
          "kind": "other",
          "published_at": "2026-07-16T19:35:28Z"
        },
        {
          "tag": "@nodeve/grimoire@4.6.0",
          "kind": "other",
          "published_at": "2026-07-16T14:36:42Z"
        },
        {
          "tag": "@nodeve/grimoire@4.5.0",
          "kind": "other",
          "published_at": "2026-07-16T10:21:51Z"
        },
        {
          "tag": "@nodeve/grimoire@4.4.0",
          "kind": "other",
          "published_at": "2026-07-16T09:45:27Z"
        },
        {
          "tag": "@nodeve/grimoire@4.3.0",
          "kind": "other",
          "published_at": "2026-07-16T09:21:39Z"
        },
        {
          "tag": "@nodeve/grimoire@4.2.0",
          "kind": "other",
          "published_at": "2026-07-14T18:45:45Z"
        },
        {
          "tag": "@nodeve/grimoire@4.1.0",
          "kind": "other",
          "published_at": "2026-07-14T11:01:06Z"
        },
        {
          "tag": "@nodeve/grimoire@4.0.3",
          "kind": "other",
          "published_at": "2026-07-13T19:09:50Z"
        },
        {
          "tag": "@nodeve/grimoire@4.0.2",
          "kind": "other",
          "published_at": "2026-07-13T19:09:43Z"
        },
        {
          "tag": "@nodeve/grimoire@4.0.1",
          "kind": "other",
          "published_at": "2026-07-13T14:45:06Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "1c13499dcd0b349c9256c4286c36fa7e955e52c1",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Version Packages (#3)",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-19T10:14:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "05dd5b8f7764d344c5f04e7f309cc79047146501",
          "body": "feature/archetype/property/part list-or-dump with inline prose; schema\n<kind> <slug> [camel] dumps the JSON Schema twin; help/-h/--help to\nstdout exit 0. docs/ added to published files.",
          "is_bot": false,
          "headline": "feat(grimoire): CLI concept + schema queries; ship docs/",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-19T10:14:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ad7814ec9766b01acd9639300de027e7ba67a04d",
          "body": "Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>",
          "is_bot": false,
          "headline": "Version Packages (#2)",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-18T23:09:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa509d931539e1431387ada89da1b412cdfc212b",
          "body": "…clean PR\n\ngh pr merge --auto errors 'clean status' when main has no required checks;\nGitHub refuses to enable auto-merge with nothing to wait for. Fall back to a\nplain --squash merge. Both PAT-authored, so either re-triggers the publish run.\n\nClaude-Session: https://claude.ai/code/session_0179yEDWB1qfhDhcZQLmdkjj",
          "is_bot": false,
          "headline": "fix(release): fall back to direct squash when auto-merge rejected on …",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-18T23:09:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d97ee95747478909bae8cab09af25e834ada393e",
          "body": "Claude-Session: https://claude.ai/code/session_0179yEDWB1qfhDhcZQLmdkjj",
          "is_bot": false,
          "headline": "chore(zed): YAML soft_wrap to editor width",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-18T23:03:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f787db0cf9312dd89f1e78c970c50e9ede040503",
          "body": "Claude-Session: https://claude.ai/code/session_0179yEDWB1qfhDhcZQLmdkjj",
          "is_bot": false,
          "headline": "chore(grimoire): changeset — interval axes + body field (minor)",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-18T23:03:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cfe7c383bd236d3842488f145b9d5bc0f8c9feb6",
          "body": "… blocks\n\nComments vanish when YAML bakes to JSON/TS. Add body (i18n text on thing,\nso every def carries it) as the durable home for rationale/spec prose —\nbakes into artifacts + TS emit. Sweep 129 files' comment blocks into body;\nguard-comment-blocks fails runs of 4+ comment lines.\n\nClaude-Session: https://claude.ai/code/session_0179yEDWB1qfhDhcZQLmdkjj",
          "is_bot": false,
          "headline": "feat(grimoire): body field for concept prose; guard oversized comment…",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-18T22:51:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "36c54cc803259f3303d8eefbb028a45e0ba62d5d",
          "body": "…e trigger_on axis\n\nA stateful hysteretic trigger is any interval carrying `trigger_on` (most\noften a zone, whose name handles the boolean sensor; a startup/shutdown\nrating takes it too) — an axis orthogonal to interval_kind, not a fourth\nkind. Kinds are now measurable/rating/zone. trigger_on no longer derives a\nkind; excluded it from the bare-value→rating branch too.\n\nClaude-Session: https://claude.ai/code/session_0179yEDWB1qfhDhcZQLmdkjj",
          "is_bot": false,
          "headline": "refactor(grimoire): drop threshold interval_kind — statefulness is th…",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-18T21:57:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "933ca58c984e405a29f72d4a29ee42bcd2c2269a",
          "body": "- merge `nominal` property into `value` (one role-neutral point); nominal-ness\n  moves to a real `severity: nominal` member (healthy centre, keys no slug token)\n- rename feature nominal_range -> valued_range (value + band)\n- threshold: drop `direction`; edges ARE min/max (deadband/hold zone) +\n  `tr\n[…]\noint. Derivation + docs + fox-ess entry updated\n- rating loses phantom `nominal` tier; catalog nominal:->value:+severity, regen\n\nClaude-Session: https://claude.ai/code/session_0179yEDWB1qfhDhcZQLmdkjj",
          "is_bot": false,
          "headline": "refactor(grimoire): unify interval point on value; trigger_on threshold",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-18T21:45:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8c4c7f045e2ac76deebe1bd3b01d3be78d35aea7",
          "body": "Header comment, interval_kind enums line, and the feature description still\ndescribed the pre-threshold model (zone as \"condition anchor\", `operating`\nrating). Add the stateless/stateful split + threshold; drop dead `operating`.",
          "is_bot": false,
          "headline": "docs(grimoire): sync interval header/description to threshold + zone",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-18T18:34:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a2c3f740b1f22988f90c42711eb2b6aaa224e80",
          "body": "…threshold\n\nRetire free-form `mode`; model named operating regions as the enumerated `zone`\naxis, and fold the stateful single-bound trigger into `interval_kind: threshold`.\n\n- zone (enumeration/zone): mppt/mpp/open_circuit/off/idle/running → interval_kind:\n  zone, a stateless boolean \"in this regio\n[…]\n→zone).\n- zone member `running` (not `active` — that stem is the in-service config flag).\n- Sync prose: feature-model, interval/rating/zone/severity/hysteresis/direction\n  concept comments, pv_module.",
          "is_bot": false,
          "headline": "feat(grimoire): interval axes — zone / severity sub-grade / stateful …",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-18T18:33:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ccf056ec551a4e87c1ef7380347c2ca6b715c067",
          "body": "Spec value is the `intervals` list (rating + measurable bands in one),\nnot a separate measurement map keyed by quantity_kind. Fix inverter.ts→.yaml.",
          "is_bot": false,
          "headline": "docs(grimoire): fix stale ps10sh header — measurement map/ranges gone",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-18T16:53:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e9d0c043256041c6b9d8c5112757adde20e12628",
          "body": "`operating` rating + separate `measurements` slot are gone; `interval_kind`\n(measurable/rating/zone) is the top classifier, `rating` the tier\n(continuous/intermittent/short_term/…). `limit_class` was never formal — collapse to `rating`.\n\n- feature-model + catalog-generation-pipeline docs; README poi\n[…]\nval/rating/duration/is_specification/quantity_kind concept comments\n- electrical + cooling feature comments; ps10sh/ac_phase_three_point examples\n- band key + backfillRegisterSpecNodes rename in prose",
          "is_bot": false,
          "headline": "docs(grimoire): sync prose to interval_kind/rating split",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-18T16:52:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0567fca85cddef4dc5404bfb25cd4dc181a0d251",
          "body": "Follow-up to a0285e0 — land the checkpoint green.\n\n- Extract interval-slug logic (desugar/autoSlug/validate) out of\n  repeated-emit into kit/interval-slugs.ts (326L -> 173L)\n- collectBandSlugs: bundle bands+targets into one acc (4 params -> 3)\n- checkTriple: bundle coords into Triple + ctx into TripleCtx (6 -> 2)\n- bake-site featurePatch: bundle partId+ordinal into PartRef (arrows 4 -> 3, fn <35L)",
          "is_bot": false,
          "headline": "refactor(grimoire): clear file-size + max-params gates",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-18T16:39:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0285e013e4c0361462cdd8670f30a1d7d1b16ae",
          "body": "Checkpoint — far-reaching. Green on tests/typecheck/generate-mirror;\nskips file-size + max-params/max-lines gates (repeated-emit, bake-site,\nvalidate-conditions) pending refactor.\n\n- Drop standalone quantity enum + measures feature; model channels via\n  interval (interval_kind/period/flow_direction)\n[…]\nrating: measurable/operating -> continuous/intermittent/short_term/shutdown\n- Add orgs (ietf, isa) + registries (rfc_5424, iso_8601, isa_18_2), severity\n- Rename quantity-layer test -> energy-channels",
          "is_bot": false,
          "headline": "wip(grimoire): interval-based quantity model + standards registries",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-18T16:33:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1a745413d8d6aca3a738f1de3985cb14afa14144",
          "body": "Consumes the pending changesets locally so the push publishes directly.\nOrigin's auto-merged Version Packages PR already released 4.8.0 (quantity\nlayer only); the artifact query surface (baked base kinds, shipped\nartifacts/ tree, grimoire CLI) lands as 4.9.0. checks 2.1.0 ships the Vale\nprose gate.",
          "is_bot": false,
          "headline": "chore(release): version packages — grimoire 4.9.0, checks 2.1.0",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-17T15:45:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a85fe46a3763ef5170fa9ded3fdaf065fe61c53",
          "body": "Docs kept accreting fat, hedging, and prior-version narration the TS checks\ncan't see; prose needs its own engine. Ship the house rules (Narration,\nEphemeral, Hedging, SentenceLength) as a Vale package under styles/nodeve/\nwith .vale.ini as the canonical severity block; consumers vale-sync them in,\nand the lefthook gate gains a guarded vale job that skips where vale is\nabsent.",
          "is_bot": false,
          "headline": "feat(checks): org prose gate — Vale house rules as a shipped package",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-17T15:45:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5c56346d2612ed5ea7c894c428e9ff3ba6caf7b8",
          "body": "- bake resolved base quantity_kind onto named-quantity registers (JSON readers route without the TS enumeration module)\n- bake display-policy + parts to artifacts/; ship whole artifacts/ tree (+ ./artifacts/*.json export)\n- guard-artifacts-baked: every generated TS module needs an artifacts JSON twin\n- grimoire bin: catalog [slug [path]], registers <slug> [column], enumeration, quantity\n- TODO(move-display-policy): flagged — the one generator input outside concepts/",
          "is_bot": false,
          "headline": "feat(grimoire): artifacts as full query surface + grimoire CLI",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-17T15:45:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f45f4cfebc58809197965c7d585b10d8e8e932aa",
          "body": null,
          "is_bot": false,
          "headline": "ci(release): bump actions/checkout v4 -> v7",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-17T15:45:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "37b7b57b4f4bed227210855ffc4330fa4a508a96",
          "body": "Publish becomes hands-off while keeping the changesets PR checkpoint. The\nVersion PR is now authored + merged under a fine-grained PAT (RELEASE_PAT)\ninstead of GITHUB_TOKEN, because GitHub suppresses workflow runs on\nGITHUB_TOKEN-authored events — a GITHUB_TOKEN merge would not re-trigger the\npublis\n[…]\n re-triggers release.yml, which (no changesets\nleft) runs `pnpm release` and publishes.\n\nPrereqs (one-time): RELEASE_PAT secret (contents + PRs write, this repo) +\n\"Allow auto-merge\" in repo settings.",
          "is_bot": false,
          "headline": "ci(release): auto-merge the Version Packages PR via RELEASE_PAT",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-17T15:45:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5e8bb69b2d502a40b37efb70673941cf90f4c3d8",
          "body": "Version Packages",
          "is_bot": false,
          "headline": "Merge pull request #1 from nodeve-com/changeset-release/main",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-17T13:34:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c9aca9074941d8f92acb069794ef1a71f93dee33",
          "body": null,
          "is_bot": true,
          "headline": "Version Packages",
          "author_name": "github-actions[bot]",
          "author_login": "github-actions[bot]",
          "committed_at": "2026-07-17T13:31:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "54049e0aa10af800e740d30dea3ec5f05aae961b",
          "body": null,
          "is_bot": false,
          "headline": "chore: changeset for foxess grid-CT split + quantity layer",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-17T13:28:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "657e60a2154823d4b19be4582db5dc08f877cb21",
          "body": "…y layer\n\nWhat was `ac_phase_three_grid` on the FoxESS H3 PS-10.0-SH was actually the\ninverter's grid-tie OUTPUT (grid_voltage/inv_current/inv_power/reactive/\napparent). Move it to a new `ac_phase_three_out` feature; `ac_phase_three_grid`\nnow models the real grid CT / utility meter (net power per-ph\n[…]\nty/*; registers link via an optional `quantity` field;\nmeasurand-tree merges them into column detection + baseQuantityKind(); QUANTITY\nvocab exported; guard-register-links honors the effective column.",
          "is_bot": false,
          "headline": "feat(grimoire): split inverter output/grid-CT on ps10sh + add quantit…",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-17T13:25:56Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c2cf984ae5c312427d750f79786dff2314e5f63c",
          "body": "pnpm@11 does the OIDC token exchange itself; it never shells out to npm. But\nchangesets' already-published check uses node-24's bundled npm (npm info), and\nforcing npm@12 made it report every published package as unpublished, triggering\na doomed republish that crashed in isAlreadyPublishedError. Use the bundled npm.",
          "is_bot": false,
          "headline": "ci(release): drop npm@latest upgrade — broke changesets publish check",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-17T10:53:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "42a1f7e27feb0a23e536e37ab4b45d42881cca0b",
          "body": "…re-json.yml\n\nThe tag-triggered grimoire-json.yml can't fire on CI releases (changesets tags\nwith GITHUB_TOKEN, whose events GitHub suppresses). Fold the bake into release.yml\nas a step gated on a grimoire publish (generate → tar → gh release upload to the\n@nodeve/grimoire@<v> release). Removes the redundant second copy of the bake.",
          "is_bot": false,
          "headline": "ci(release): bake grimoire JSON artifacts in release.yml, drop grimoi…",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-17T10:50:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b995a96794e7c76886f29815e4217bc33b26c0bd",
          "body": "CI-driven releases via changesets/action: pending changesets open a Version\nPackages PR; merging it triggers pnpm release (build + changeset publish).\nAuth is OIDC (id-token: write) against npm's registered Trusted Publisher, so no\nNPM_TOKEN secret and no local npm/pnpm login — kills the daily-login E401.",
          "is_bot": false,
          "headline": "ci: add Changesets release workflow with npm Trusted Publishing (OIDC)",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-17T10:35:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "860cb9e62843682a4a48b3c31cfd26e0102a8bf7",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): @nodeve/config@0.5.1",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-17T09:53:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d696ef467c8ffe65b4fe255fde625d3cb3ad784e",
          "body": "eslint/base.js imports @eslint/js, eslint-config-prettier, globals, and\ntypescript-eslint unconditionally. Marked optional, they were skipped by frozen/\nCI installs, so consumers (familiar) failed lint with ERR_MODULE_NOT_FOUND. As\nrequired peers, auto-installing package managers pull them into the consumer\nlockfile. Svelte/prettier-plugin/vite peers stay optional.",
          "is_bot": false,
          "headline": "fix(config): make ESLint peers required, not optional",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-17T09:52:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "48b2356940f1a13433a1f42a477afdbb89594f6e",
          "body": "…ersion\n\nPS10SH gains the SMART lifetime solar-generation energy counter; changeset\napplied for the 4.7.0 minor. Mirror-sweep test timeout raised to 20s — the\n1310-file comparison outgrew vitest's 5s default.",
          "is_bot": false,
          "headline": "feat(grimoire): FoxESS H3 lifetime solar-generation counter + 4.7.0 v…",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-16T19:31:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8141eccaedc15c605f08a385a671ac7458a5bf92",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): @nodeve/grimoire 4.6.0",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-16T14:34:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6dcc8d7bc478f021ab8de342032a4d66703c1a57",
          "body": "… export\n\nPS10SH meters household load per leg (foxess load_power_r/s/t, holdings 39219/21/23) — add the default.ac_phase reading spec and modbus registers so per-leg load telemetry decodes. Export binarySensorStateTopic so consumers derive the boolean-reading MQTT topic instead of hand-spelling it.",
          "is_bot": false,
          "headline": "feat(grimoire): per-leg house load on ps10sh + binarySensorStateTopic…",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-16T14:34:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a008f6acbc55e5757d1e3335eab560c60f370bae",
          "body": "…bset\n\n- features/filter.yaml (throttle_average_ms | exponential_moving_average_ms, exactly one) on the intervals archetype: the band claims the conditioned signal, consumer must apply it\n- site-bake cadence gate: filter window ≥ adapter's fastest known cadence; catalog level unvalidatable by design (device doesn't know its polling frequency)",
          "is_bot": false,
          "headline": "feat(grimoire): interval filter — required conditioning, smoothing su…",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-16T10:16:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "550719116f9f2b61337e8d731fc10b4976be5a13",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): @nodeve/grimoire 4.4.0",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-16T09:43:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "475456bb6a851d503832dfb9e75a1347d99784b3",
          "body": "- bakeSite merges site-authored keys into the slug patch via shared overlayPatch (src/overlay.ts) — custom intervals bands append by identity.slug instead of clobbering baked slugs\n- sensorId grows trailing interval segment; intervalSensorId composes boolean ids from baked slugs",
          "is_bot": false,
          "headline": "feat(grimoire): site feature_spec overlay + interval id segment",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-16T09:38:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "740851a1f2034d70bd62f7b51d04ef9f16c495b0",
          "body": "Interval identity.slug de-sugar, condition ref gate, and the member-valued\ngrid_region knob (replaces the raw numeric knobs; settings_schema has no\nknown downstream use, so minor).",
          "is_bot": false,
          "headline": "chore(release): @nodeve/grimoire 4.3.0",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-16T09:18:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a59900a8b00168dea526feed1b839ad22d5e90f",
          "body": "- desugarIntervalSlugs: unslugged intervals get identity.slug from rating; duplicates per intervals list fail the bake\n- validateConditionRefs: interval_item resolves to feature→property→interval slug within the entry; setting gates check settings_schema key + enum membership\n- migrate dtsu666 + ps10sh to the one member-valued grid_region knob (drops grid_frequency); condition-split bands slugged by region member",
          "is_bot": false,
          "headline": "feat(grimoire): interval identity.slug de-sugar + condition ref gate",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-16T09:12:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "462d061ecc9cb5f366e3f6c55d33354d571ea102",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): @nodeve/config 0.5.0, @nodeve/checks 2.0.0",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-15T10:49:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c80d19d44364323186ca27eba34c21e232960d5b",
          "body": "eslint-config-prettier turns OFF every stylistic eslint rule, and the only\nprettier in the gate was the markdown fixer — so nothing judged code formatting\nat all. The org base had shipped a double-quoted `max-depth` line among single\nquotes since it was written, and no gate had an opinion.\n\nRename t\n[…]\nachine output via .prettierignore, not by narrowing the\nglob. Note `pnpm install` will not relink a renamed bin in an existing checkout\n— remove node_modules/.pnpm-workspace-state-v1.json to force it.",
          "is_bot": false,
          "headline": "feat(checks)!: format code, not just docs",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-15T10:46:47Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "55c73e139b1de72dda6c0bf73d10b1e289edb471",
          "body": "max-depth (3), max-params (3), and max-lines-per-function (35) landed in the\neslint base after the 0.4.1 cut with no changeset, so every consumer on 0.4.1\ngot func-names and nothing else. They have been enforced inside this repo the\nwhole time — the workspace link resolves to source, not the tarball — which is\nwhy the gap stayed invisible.\n\nRules unchanged; this only releases them.",
          "is_bot": false,
          "headline": "fix(config): ship the org function-shape rules",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-15T10:46:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "86d1c3e115b36b193e12753fa99e9fa2c96a3104",
          "body": "…ing knob\n\nRegional AC supply standard as a Term: one knob fixing nominal voltage +\nfrequency at install, crosswalked to IEC 60038.\n\n- archetypes/grid_region — composes thing, nests mains\n- features/mains — nominal voltage + frequency, grouped once\n- catalog/registries/iec_60038 — bare token; IEC no\n[…]\n230v_50hz, na_120v_60hz, na_208v_60hz,\n  br_220v_60hz\n\nAdditive. Catalog entries still carry the inlined grid_region/grid_frequency\nknobs (fox-ess/h3/ps10sh); migration to this vocabulary is separate.",
          "is_bot": false,
          "headline": "feat(grimoire): grid_region archetype — nominal mains as a commission…",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-15T10:32:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "80f52570ec344a5d6ef35a2a5fc9c5f4585396ff",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): @nodeve/grimoire 4.2.0",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-14T18:43:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fc02c336ae3bb007c142bd0043316987701dd988",
          "body": "… NIC\n\nA polled-master site adapter can name which of the metered device's\nnetwork_interfaces it dials, overriding the service_binding's default.\nA site fact (which NIC the poller can reach), so it rides the adapter,\nnot the catalog device.",
          "is_bot": false,
          "headline": "feat(grimoire): ingest.network_interface_id — adapter pins the dialed…",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-14T18:40:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0f1f508a7aec6712a066aefa0c89ba6f43f937c5",
          "body": "tsconfig.build.json extended the shared config directly, so it missed the\npackage-local `types: [\"node\"]` and failed to emit (node:fs/node:path\nunresolved). Extend the package base instead — node types and\nrewriteRelativeImportExtensions come along, no duplication.",
          "is_bot": false,
          "headline": "fix(grimoire): inherit node types in build tsconfig",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-14T11:42:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "68328bb2ffad570fcfc99f99e856a4823417f033",
          "body": "The catalog gate scanned only workspace-package manifests, so a literal\nversion pin in the root package.json's devDependencies — shared tooling\nespecially — slipped through. workspaceManifests now includes the root\nmanifest, so every manifest the package manager installs from obeys the\nsame org rule. Migrated nodeve's own root devDeps to catalog:.",
          "is_bot": false,
          "headline": "feat(checks): gate root package.json in catalog check",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-14T11:38:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d4ff0740b31314a852d3a33fe681c76fc2a8f74",
          "body": "- typescript 5.9 -> 6.0.3 (7.x blocked by typescript-eslint peer <6.1.0)\n- @types/node ^22 -> ^24 (TS6 needs it; matches engines >=24)\n- add types:[\"node\"] to node packages (TS6 dropped ambient @types auto-scan)\n- eslint 10.7.0, typescript-eslint 8.63.0, prettier 3.9.5",
          "is_bot": false,
          "headline": "chore(deps): bump catalog; adopt typescript 6",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-14T11:19:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "eafa3c1336345c514eef2e892c2701a9a838fa85",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): @nodeve/checks 1.8.0",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-14T11:01:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b0fc69b9418df397713ac3d6d6edabb176e42488",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): @nodeve/grimoire 4.1.0",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-14T10:46:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c53853390328f1e9fd599c37dd175d2f92d90a09",
          "body": "New require-eslint check enforces a root flat config on every project.\nWire nodeve's own eslint.config.js on @nodeve/config/eslint/base and add\nmax-depth/max-params/max-lines-per-function to the base. Conform checks,\ngrimoire, schema-case, and text sources to the new rules; add ts-morph +\n@ast-grep/\n[…]\n/emit-types.ts (→emit-type-box.ts) and kit/resolve.ts\n(→resolve-slug.ts) under the file-size budget; dedupe the composed\ntype/literal emitters; drop bake-site's camelKeys reinvention for\nremeda-humps.",
          "is_bot": false,
          "headline": "feat(checks): add require-eslint gate, adopt eslint org-wide",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-14T10:20:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "968b7be3da96b5e6266b7a1b5f2e2cc422177499",
          "body": "farana's build.rs embeds the catalog register maps at compile time from\nthe installed package; artifacts/ being release-only left npm consumers\nwith no JSON grain. Publish artifacts/catalog and bake it during build.",
          "is_bot": false,
          "headline": "feat(grimoire): ship baked catalog JSON in the npm package",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-13T19:55:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25e09b0a808473a25bd24091fa671cb054def941",
          "body": "The camel TS-catalog cutover left measurand-tree walking the old snake keys\n(feature_spec / snake columns), so bakeSite silently minted EMPTY catalog\npatches and site-view found no slugs. Walk featureSpec + camel column keys,\nkeep snake wire codes on cells/ids, mirror patches in camel, and camelize\nthe authored snake overlay keys before merging onto the device.",
          "is_bot": false,
          "headline": "fix(grimoire): bake/read measurand slugs on the camel device grain",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-13T19:51:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62b3d2607485c1c3567112327c3f2041ead7df6d",
          "body": "A platform: telegraf site adapter (polled Modbus master) names WHICH of the\nmetered device's offered services it dials; the schema gate rejected the\nservice_id key those bundles already carry. Mirrors network_interface_id:\nan intra-catalog slug pointer, the service owning the dialed surface.",
          "is_bot": false,
          "headline": "feat(grimoire): add ingest.service_id pointer for polled masters",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-13T19:39:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "80a57e12c131b58ca396d0a23aa800270f91e1c8",
          "body": null,
          "is_bot": false,
          "headline": "fix(grimoire): declare ajv as a runtime dependency",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-13T19:25:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ee7718a66071a8c6de1811f65c4c2ad40c16b52f",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): @nodeve/grimoire 4.0.3",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-13T19:07:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ddf0addf51fb2996497012eed0498fdcbe562e12",
          "body": "- archetypes/archetype.yaml: the meta-def every archetype def validates\n  against (assertArchetypeDocsValid, same self-hosting gate as features);\n  title/description now REQUIRED on every archetype — all missing labels\n  authored (thing, feature, property, building, battery_charger, ...)\n- empty/com\n[…]\ne\n  'archetype' slug for the meta-def; *_id pointer convention). Wire:\n  identity.archetype_id + catalog_item {archetype_id, slug}; TS surface:\n  CatalogIdentity.archetypeId, new CatalogItemRef export",
          "is_bot": false,
          "headline": "feat(grimoire)!: archetype meta-def gate + identity.archetype_id rename",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-13T18:15:42Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d4a861be4f3ca42b8aa96decb4383de22e2cf6b0",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): @nodeve/grimoire 4.0.2",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-13T17:34:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f980921dd78c3ed1735b23d7102805965413878",
          "body": "Per-concept generated modules ARE the def node: authored fields + live\nschema + parsed type as named exports (import { title, schema, type Inverter });\ncomposition via namespace imports, so every nested slot carries its schema.\nLayer subpaths lose the generated/ segment (@nodeve/grimoire/archetypes/\n[…]\nr its layer aggregate — generate now refuses); frame offsets moved\nusb -> frame; root index drops hand-picked concept wrappers (BREAKING — use\nConceptTypes + parseConcept or the concept's own module).",
          "is_bot": false,
          "headline": "feat(grimoire)!: def-node modules, clean subpaths, identity de-sugar",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-13T16:58:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b8b974c906b2bb258c1509a2755799630bc6238b",
          "body": null,
          "is_bot": false,
          "headline": "docs(grimoire): usage section for generated subpath imports",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-13T16:04:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ffe694ec08deb9b284f41f371183b8a3bd4af823",
          "body": "package.json gains a ./generated/* subpath export, so every generated per-concept\nmodule (archetypes/features/property/enumeration/catalog) is importable directly.\nNew generated/<layer>.ts aggregates (archetypes/features/property) map camel slug ->\nauthored data tree; Object.keys lists the layer. Ag\n[…]\nNG: root index drops hand-picked SiteLocation/AmbientTank/SolarArray/SolarString\n+ parseLocation/parseAmbientTank/parseSolarArray — use ConceptTypes['...'] +\nparseConcept, or the concept's own module.",
          "is_bot": false,
          "headline": "feat(grimoire)!: subpath exports for generated modules; layer lists",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-13T16:01:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "056f22e54f879342c50d21416725276be69d3e59",
          "body": "…re-commit\n\nEmitters now camelize object KEYS at every TS emit — the aggregate index\n(conceptSchema/ConceptTypes keyed by camelized slug), catalog entry modules\n(deep humps; settings_schema via camelizeSchema so x-key-map rides along),\nand vocab dicts (member wire literal stays in .code). Lookups re\n[…]\nte job\nregenerates, re-stages, and runs the guards on any staged grimoire path —\nthe README's 'pre-commit regenerates' promise, now real.\n\nIndex emitters split to kit/emit-index.ts (file-size budget).",
          "is_bot": false,
          "headline": "fix(grimoire): camelize every generated-TS key; run generate+guards p…",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-13T15:42:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "896f79fd380e869a796eb78045ae1fa66623eb2c",
          "body": "AST-walk src/generated/**/*.ts; fail on snake in name positions (decl\nidentifiers, object keys, type members, import specifiers). String\nvalues, module paths, and x-key-map aliases exempt. Wired into guards.\n\nCurrently red: index slug keys + catalog trees + enum member dicts all\nemit snake — the emitters (emit-types/catalog/enumeration) must camelize.",
          "is_bot": false,
          "headline": "feat(grimoire): guard snake_case off the generated TS surface",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-13T15:23:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d58bdba91d6825d7f2ad0523d9b1d71407748c45",
          "body": null,
          "is_bot": false,
          "headline": "docs(memory): record grimoire-json tag-trigger release gotchas",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-13T14:49:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7821455159ecf3a83b706c8a7c2f2cbab726cd00",
          "body": "grimoire codegen imports @nodeve/schema-case + encoding from their dist/;\nCI installed but never built them, so generate hit ERR_MODULE_NOT_FOUND.",
          "is_bot": false,
          "headline": "ci(grimoire-json): build workspace deps before generate",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-13T14:44:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bffd2c6bcb249f2a5cbf42c47aada596cef22445",
          "body": "lefthook is a local-only git-hook installer, absent in CI; `lefthook install`\nhard-failed `pnpm install` in the grimoire-json release workflow. Guard it so\ninstalls succeed where hooks are irrelevant.",
          "is_bot": false,
          "headline": "ci: make prepare tolerant of missing lefthook",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-13T14:42:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f33f45710344a8f2903f1230bf5bb591095639d",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): grimoire@4.0.1",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-13T14:33:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "82ee80b7fd509162fad7fd07366931cc84dab977",
          "body": "… compose\n\n_eps/_grid/_point/_load were duplicate parted shapes. Single-slug compose of\na shape-less def now reuses the sibling's WHOLE resolved node (feature_spec/\npart intact), folding to a $ref spread of its Data. featureNature/\nfeatureCombined follow the compose chain so catalog part-expansion still sees\nthe parted nature. The four instances drop from ~1461 lines each to 29-48;\nthe parted shape lives once.",
          "is_bot": false,
          "headline": "refactor(grimoire): ac_phase_three canonical; instances spread it via…",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-13T14:32:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8cf19c36a71d37750e30df45187bb2fc4f196fd3",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): checks@1.7.0, grimoire@4.0.0, schema-case@1.0.0",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-13T14:03:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "561a83018544ebae8ae3753781160b8b07d864d5",
          "body": "…Case wall-to-wall\n\nNew package @nodeve/schema-case: casing projections of snake_case JSON Schema\n(camelizeSchema/camelizeInstance/snakePath). Grimoire regenerates through it —\ngenerated TypeBox schemas camel wall-to-wall, .camel.schema.json artifacts beside\nsnake wire schemas, parse renames before \n[…]\ncamel-keyed); validateAndCamelize\ndeleted (use parseConcept/parseSnake); Display*Schema values camel; validateSite\nerror paths stay snake. Collapse quantity_kind onto shared makeVocab (QUANTITY_KIND).",
          "is_bot": false,
          "headline": "feat(schema-case): add @nodeve/schema-case; regenerate grimoire camel…",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-13T13:58:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "293a65d0482337fad8d6f39d79a1e6e8ffea9a0a",
          "body": "…ignored artifacts/\n\n- src/: npm-surfaced runtime (index, loaders, display-policy) + committed src/generated TS\n- kit/: codegen only — generate.ts entry + compile/project/emit helpers; drop unused seal.ts\n- artifacts/: generated JSON (data trees, .schema.json, catalog) — gitignored, attached to\n  Gi\n[…]\nthe no-longer-committed JSON)\n\nBypasses gate: plural-arrays (conceptSchemas — retires with the camelCase-emit fix) and\ninline-dupes findings are known pending work, not regressions from this refactor.",
          "is_bot": false,
          "headline": "refactor(grimoire): split src/ runtime from kit/ codegen; JSON to git…",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-13T10:42:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d94f315f4ede1faa5c8b7eb81be02d5999ee413a",
          "body": null,
          "is_bot": false,
          "headline": "feat(checks): add find-similar-svelte structural-similarity bin",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-12T18:37:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c311475e78e23b58c08f935a20b3dfe083498435",
          "body": null,
          "is_bot": false,
          "headline": "docs: convert CLAUDE.md to real file, tighten README, add .zed settings",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-12T18:37:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "897a708bd3b070323375dd5ce7abbd73c406884d",
          "body": "Referential data emit (property atom modules; features/archetypes/identity/\nspecification $ref'd); catalog index composes per-slug parts; repeated-feature\ndefault hoisted per part. Temporarily scopes clones off generated/ (compose\nreferential form deferred, docs/data-tree-normalization.md).",
          "is_bot": false,
          "headline": "feat(grimoire): add @nodeve/grimoire concept schema + catalog package",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-12T18:37:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7883c5df06228812e2dc3d91d18089ce9ff969e4",
          "body": "… maps\n\nA count-plural variable name (`users`, `tags`) promises an array; binding\nit to a keyed collection makes every reader guess the shape. The new\n`plural-arrays` gate fails when the binding provably isn't an array — an\nobject literal, `new Map()`, a `Record<…>`/index-signature type, or an\n`Obje\n[…]\n`unwrap` in lib/ast, `locationRows` in lib/report. Dogfood renames of the\nthree in-repo sites the check surfaced: names→namesByLib,\ncollisions→collisionByPair, ABBREVIATIONS→EXPANSION_BY_ABBREVIATION.",
          "is_bot": false,
          "headline": "feat(checks): add plural-arrays check for count-plural names bound to…",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-07T12:33:41Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1d2ee225cc476a92c3adaf1873ca45d2f9037a2f",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): @nodeve/checks@1.5.2",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-07T09:47:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa732e30c67b14a09a9af9d6e2ef7374ca7d8aec",
          "body": null,
          "is_bot": false,
          "headline": "fix(checks): fail clones gate when jscpd binary is unresolvable",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-07T09:47:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d022730943c29ecb88cadada979d2ba4a5be7ace",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): @nodeve/checks@1.5.1",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-07T08:49:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c689c52279a7f0bba80d1ca56895edd716a8d7ab",
          "body": "…s missing",
          "is_bot": false,
          "headline": "fix(checks): fail helper-collisions when configured lib-names index i…",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-07-07T08:49:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5a471938547ff83bf8ac5231b941751c83e9f260",
          "body": null,
          "is_bot": false,
          "headline": "feat(checks): add per-check rerun pointer to failure output",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-30T10:07:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6dee7eb01752bc352c7b32f3f7f65709a0d72ad7",
          "body": "…ages",
          "is_bot": false,
          "headline": "feat(checks): drop clones lefthook glob so formats owns scanned langu…",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-30T09:55:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d00bb61b5256942226c811c8e592781528ab071d",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): @nodeve/checks@1.3.0",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-25T09:28:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ec175443f1158ecad43f19c221855f9e96e1a301",
          "body": "Add a single `nodeve-check` entrypoint that runs one check or the whole\nsuite summary-first, with a shared uniform reporter and an --explain flag.\nChecks now return structured CheckResults instead of printing + exiting;\nbehavior and exit codes are unchanged. Per-check bins remain.",
          "is_bot": false,
          "headline": "feat(checks): add nodeve-check dispatcher and unify check output",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-25T09:28:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cb322b3309de4852682881f34f1e090f8fe8ee7f",
          "body": null,
          "is_bot": false,
          "headline": "docs(memory): note push before pnpm release in release-flow",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-24T19:53:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "10717bc31e94d8e6962911c89d8ace476b42d4e4",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): @nodeve/config@0.4.1",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-24T19:52:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "da98d96643512917c262e3fb1903989f87d1332e",
          "body": null,
          "is_bot": false,
          "headline": "feat(config): ship types for the ./vite subpath",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-24T19:52:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "917ef54603a8bff6e4e2cce98079a531b0b250a4",
          "body": "Consume the vite changeset: bump to 0.4.0, regenerate the CHANGELOG, and\nsync the lockfile for the new @vitest/browser-playwright catalog entry.\nReady for `pnpm release` to publish.",
          "is_bot": false,
          "headline": "chore(release): @nodeve/config@0.4.0",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-24T19:28:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "83e35c6dc5d8f7885aa19dd007e78aca49c6cd97",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): @nodeve/config@0.3.0",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-24T18:57:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b484595d872f3495a5e1c84b80064527027258d",
          "body": "SvelteKit-app ESLint factory (svelte recommended + prettier compat + the\ntype-aware .svelte parser block) for uniform Svelte linting across nodeve\nsister repos. Adds @eslint/compat and eslint-plugin-svelte as optional peers\nplus catalog entries.",
          "is_bot": false,
          "headline": "feat(config): add @nodeve/config/eslint/svelte preset",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-24T18:57:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bfdb3d0914471c025af42698bf01d4650a78152f",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): @nodeve/checks@1.2.1",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-24T18:31:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e337361a817e137cffcf0e72bed3e0275b2020e5",
          "body": "Switch the jscpd reporter from console to consoleFull so a failing clone\ngate surfaces each duplicated block with both file locations and the\noffending code inline, not just a summary table.",
          "is_bot": false,
          "headline": "feat(checks): print full clone listing on gate failure",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-24T18:31:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "77b9ef9f1f384fb4b39e2ea786d9bd0cc1f118be",
          "body": "Add shared ESLint flat config: @nodeve/config/eslint/base (org defaults)\nand @nodeve/config/eslint (base + Svelte-stack @lucide/svelte barrel ban).\nAdds eslint peers (optional) and catalog entries.",
          "is_bot": false,
          "headline": "chore(release): @nodeve/config@0.2.0",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-24T18:29:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fea96e3de5c40175d5e2f1dd4773595a02a749e0",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): @nodeve/checks@1.2.0",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-24T17:02:42Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "260fd1188bc5a72f2d944d07e9bcd52f6e1ee8c3",
          "body": "Adds nodeve-check-commit-msg, the first gate to run on the commit-msg hook\nrather than pre-commit. It validates the header against Conventional Commits\nand requires a body once the staged diff exceeds bodyRequiredOverLines\n(default 50), so non-trivial commits explain the why while small ones stay\none-liners. Merge/revert/fixup messages are skipped; commitMsg.enforce:false\nopts out. Wired through the shared lefthook.checks.yml so consumers pick it up\nfrom the existing extends line.",
          "is_bot": false,
          "headline": "feat(checks): add commit-msg Conventional Commits gate",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-24T17:02:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "38007ebe75764c8436160929d172cb5d3547d239",
          "body": null,
          "is_bot": false,
          "headline": "Version packages: @nodeve/text@2.1.0, @nodeve/checks@1.1.0",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-24T15:50:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "923e0ad924be0292ac69dbb63a6bb659ebe84677",
          "body": null,
          "is_bot": false,
          "headline": "Version packages: @nodeve/checks@1.0.0",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-24T13:54:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cc1b2a7d585599f6476af5d17c5f84edd3454bbc",
          "body": "…defaults.js",
          "is_bot": false,
          "headline": "@nodeve/checks: single-source config defaults, ship as nodeve.checks.…",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-24T13:54:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6bab94e23f95e1700c686d5ec382782a1a6af276",
          "body": null,
          "is_bot": false,
          "headline": "@nodeve/text: test that slugify treats dots as separators",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-21T22:40:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1b0fa41d8f88c023469e79bfc56fc4df385df757",
          "body": "…tter\n\n- page-size: ship a default rule { glob: '*+page.svelte', maxLines: 280 }\n  so the SvelteKit page budget is on out of the box (no-op where the glob\n  matches nothing); reword the failure to \"rip inline components out into\n  their own files\".\n- format-markdown: new nodeve-format-markdown fixer\n[…]\nthook config (runs before the checks group, stage_fixed). Bundles its\n  own prettier for pnpm/bun portability while honoring the repo's prettier\n  config/.prettierignore/plugins; skips symlinked docs.",
          "is_bot": false,
          "headline": "@nodeve/checks@0.5.0: default-on Svelte page-size, add markdown forma…",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-21T22:36:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b2416364d9de2bb92e5dc22df8e8e53d57cf149a",
          "body": "Add LICENSE + license field across all packages (MIT). Only encoding is\nreleased today; the license additions to checks/config/text ride along\nwith their next version bump.",
          "is_bot": false,
          "headline": "@nodeve/encoding@0.2.0: add short-code CLI bin; add MIT license files",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-19T10:06:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ab0c8844ab7d5db70dc597516cb937e1866b11a",
          "body": null,
          "is_bot": false,
          "headline": "Version packages: @nodeve/text@2.0.0, @nodeve/checks@0.4.2",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-19T09:55:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "63bcd902c90773e5d60597a8b6a3b8f45d3c0c90",
          "body": "Wire helper-collisions to a committed .nodeve/lib-names.json (remeda +\ndate-fns) and add date-fns to the catalog + require-deps.",
          "is_bot": false,
          "headline": "@nodeve/text: drop titleCase for remeda, strip affixes in similarity",
          "author_name": "Kai Curry",
          "author_login": "webmasterkai",
          "committed_at": "2026-06-19T09:55:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 15,
      "commits_last_year": 118,
      "latest_release_at": "2026-07-19T10:15:49Z",
      "latest_release_tag": "@nodeve/grimoire@4.11.0",
      "releases_from_tags": false,
      "days_since_last_push": 3,
      "active_weeks_last_year": 5,
      "days_since_latest_release": 3,
      "mean_days_between_releases": 0.3
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@nodeve/text",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@nodeve/text",
          "is_deprecated": false,
          "latest_version": "2.1.0",
          "repository_url": "https://github.com/nodeve-com/nodeve",
          "versions_count": 4,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 401,
          "first_published_at": "2026-06-18T13:13:01.759000Z",
          "latest_published_at": "2026-06-24T15:51:49.026000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 28
        },
        {
          "name": "@nodeve/checks",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@nodeve/checks",
          "is_deprecated": false,
          "latest_version": "2.1.0",
          "repository_url": "https://github.com/nodeve-com/nodeve",
          "versions_count": 23,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2464,
          "first_published_at": "2026-06-18T13:12:59.610000Z",
          "latest_published_at": "2026-07-17T15:46:58.674000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@nodeve/config",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@nodeve/config",
          "is_deprecated": false,
          "latest_version": "0.5.1",
          "repository_url": "https://github.com/nodeve-com/nodeve",
          "versions_count": 7,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 1039,
          "first_published_at": "2026-06-18T12:22:30.369000Z",
          "latest_published_at": "2026-07-17T09:58:07.306000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 5
        },
        {
          "name": "@nodeve/encoding",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@nodeve/encoding",
          "is_deprecated": false,
          "latest_version": "0.2.0",
          "repository_url": "https://github.com/nodeve-com/nodeve",
          "versions_count": 2,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 98,
          "first_published_at": "2026-06-19T00:19:18.282000Z",
          "latest_published_at": "2026-06-19T10:06:56.162000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 33
        },
        {
          "name": "@nodeve/grimoire",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@nodeve/grimoire",
          "is_deprecated": false,
          "latest_version": "4.11.0",
          "repository_url": "https://github.com/nodeve-com/nodeve",
          "versions_count": 15,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 2204,
          "first_published_at": "2026-07-13T14:08:00.981000Z",
          "latest_published_at": "2026-07-19T10:15:47.466000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 3
        },
        {
          "name": "@nodeve/schema-case",
          "exists": true,
          "license": "MIT",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@nodeve/schema-case",
          "is_deprecated": false,
          "latest_version": "1.0.0",
          "repository_url": "https://github.com/nodeve-com/nodeve",
          "versions_count": 1,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 210,
          "first_published_at": "2026-07-13T14:08:03.181000Z",
          "latest_published_at": "2026-07-13T14:08:03.480000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 9
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": true,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "packages/checks/tsconfig.json",
        "packages/config/tsconfig.json",
        "packages/encoding/tsconfig.json",
        "packages/grimoire/tsconfig.json",
        "packages/schema-case/tsconfig.json",
        "packages/text/tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 14024,
      "source_files_sampled": 132,
      "oversized_source_files": 0,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md",
        "packages/checks/AGENTS.md",
        "packages/checks/CLAUDE.md",
        "packages/config/CLAUDE.md",
        "packages/encoding/CLAUDE.md",
        "packages/grimoire/CLAUDE.md",
        "packages/grimoire/concepts/CLAUDE.md",
        "packages/grimoire/concepts/catalog/CLAUDE.md",
        "packages/grimoire/concepts/property/CLAUDE.md",
        "packages/text/CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 177
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "published_package",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 1,
        "malicious_count": 0,
        "assessed_package": "npm:@nodeve/text@2.1.0",
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "@ast-grep/napi",
          "manifest": "packages/checks/package.json",
          "ecosystem": "npm",
          "version_constraint": "catalog:"
        },
        {
          "name": "@nodeve/text",
          "manifest": "packages/checks/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "js-tiktoken",
          "manifest": "packages/checks/package.json",
          "ecosystem": "npm",
          "version_constraint": "catalog:"
        },
        {
          "name": "jscpd",
          "manifest": "packages/checks/package.json",
          "ecosystem": "npm",
          "version_constraint": "catalog:"
        },
        {
          "name": "pluralize",
          "manifest": "packages/checks/package.json",
          "ecosystem": "npm",
          "version_constraint": "catalog:"
        },
        {
          "name": "prettier",
          "manifest": "packages/checks/package.json",
          "ecosystem": "npm",
          "version_constraint": "catalog:"
        },
        {
          "name": "remeda",
          "manifest": "packages/checks/package.json",
          "ecosystem": "npm",
          "version_constraint": "catalog:"
        },
        {
          "name": "ts-morph",
          "manifest": "packages/checks/package.json",
          "ecosystem": "npm",
          "version_constraint": "catalog:"
        },
        {
          "name": "typescript",
          "manifest": "packages/checks/package.json",
          "ecosystem": "npm",
          "version_constraint": "catalog:"
        },
        {
          "name": "yaml",
          "manifest": "packages/checks/package.json",
          "ecosystem": "npm",
          "version_constraint": "catalog:"
        },
        {
          "name": "@noble/hashes",
          "manifest": "packages/encoding/package.json",
          "ecosystem": "npm",
          "version_constraint": "catalog:"
        },
        {
          "name": "@scure/base",
          "manifest": "packages/encoding/package.json",
          "ecosystem": "npm",
          "version_constraint": "catalog:"
        },
        {
          "name": "@nodeve/schema-case",
          "manifest": "packages/grimoire/package.json",
          "ecosystem": "npm",
          "version_constraint": "workspace:*"
        },
        {
          "name": "@sinclair/typebox",
          "manifest": "packages/grimoire/package.json",
          "ecosystem": "npm",
          "version_constraint": "catalog:"
        },
        {
          "name": "ajv",
          "manifest": "packages/grimoire/package.json",
          "ecosystem": "npm",
          "version_constraint": "catalog:"
        },
        {
          "name": "remeda",
          "manifest": "packages/grimoire/package.json",
          "ecosystem": "npm",
          "version_constraint": "catalog:"
        },
        {
          "name": "remeda-humps",
          "manifest": "packages/grimoire/package.json",
          "ecosystem": "npm",
          "version_constraint": "catalog:"
        },
        {
          "name": "yaml",
          "manifest": "packages/grimoire/package.json",
          "ecosystem": "npm",
          "version_constraint": "catalog:"
        },
        {
          "name": "remeda",
          "manifest": "packages/schema-case/package.json",
          "ecosystem": "npm",
          "version_constraint": "catalog:"
        },
        {
          "name": "remeda",
          "manifest": "packages/text/package.json",
          "ecosystem": "npm",
          "version_constraint": "catalog:"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 3,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "webmasterkai",
          "commits": 117,
          "avatar_url": "https://avatars.githubusercontent.com/u/969456?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "release.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [
        "eslint.config.js"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "pnpm-lock.yaml"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 0,
            "reason": "0 out of 3 merged PRs checked by a CI test -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/28 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 11 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 4,
            "reason": "6 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "1c13499dcd0b349c9256c4286c36fa7e955e52c1",
        "ran_at": "2026-07-22T20:50:06Z",
        "aggregate_score": 2.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-19T10:16:14Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-19T10:14:58Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/nodeve-com/nodeve",
    "host": "github.com",
    "name": "nodeve",
    "owner": "nodeve-com"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 53,
      "inputs": {
        "security": 41,
        "vitality": 71,
        "community": 34,
        "governance": 53,
        "engineering": 58
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 71,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "commits_last_year": 118,
              "human_commit_share": 0.99,
              "days_since_last_push": 3,
              "active_weeks_last_year": 5
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "5/52 weeks with commits",
                "points": 3.5,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 5
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "118 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 118
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 15,
              "latest_release_tag": "@nodeve/grimoire@4.11.0",
              "releases_from_tags": false,
              "days_since_latest_release": 3,
              "mean_days_between_releases": 0.3
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "15 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 15
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 3 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~0.3 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 0.3
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 34,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 64,
            "inputs": {
              "packages": [
                "@nodeve/text",
                "@nodeve/checks",
                "@nodeve/config",
                "@nodeve/encoding",
                "@nodeve/grimoire",
                "@nodeve/schema-case"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 6416
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "6,416 downloads/month across npm",
                "points": 50.8,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 6416,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 53,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 20,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 11 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 72,
            "inputs": {
              "merged_prs": 3,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "3/3 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 3,
                      "decided": 3
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/28 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 35,
            "inputs": {
              "followers": 1,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "nodeve-com",
              "public_repos": 1,
              "account_age_days": 34
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "1 followers of nodeve-com",
                "points": 2.2,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 1,
                      "login": "nodeve-com"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "1 public repos, account ~0 yr old",
                "points": 2.4,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 1
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@nodeve/text",
                "@nodeve/checks",
                "@nodeve/config",
                "@nodeve/encoding",
                "@nodeve/grimoire",
                "@nodeve/schema-case"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 3
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "6 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 6,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 3 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 3
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "23 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 23
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 58,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 64,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": "eslint.config.js",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "0 out of 3 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "moderate",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 41,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "critical",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Packaging. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "packaging"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 26,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 2.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "0 out of 3 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/28 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 11 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "6 existing vulnerabilities detected",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:@nodeve/text@2.1.0 runtime dependency closure — what installing the published package pulls in — 1 packages. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_published",
                "params": {
                  "package": "npm:@nodeve/text@2.1.0",
                  "assessed": 1
                }
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 1,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "no indirect dependency carries a known advisory",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "no_indirect_advisories",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 1,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 7
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 60,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "moderate",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 58,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.949,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md",
                "packages/checks/AGENTS.md",
                "packages/checks/CLAUDE.md",
                "packages/config/CLAUDE.md",
                "packages/encoding/CLAUDE.md",
                "packages/grimoire/CLAUDE.md",
                "packages/grimoire/concepts/CLAUDE.md",
                "packages/grimoire/concepts/catalog/CLAUDE.md",
                "packages/grimoire/concepts/property/CLAUDE.md",
                "packages/text/CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 177
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md, packages/checks/AGENTS.md, packages/checks/CLAUDE.md, packages/config/CLAUDE.md, packages/encoding/CLAUDE.md, packages/grimoire/CLAUDE.md, packages/grimoire/concepts/CLAUDE.md, packages/grimoire/concepts/catalog/CLAUDE.md, packages/grimoire/concepts/property/CLAUDE.md, packages/text/CLAUDE.md (stub)",
                "points": 18,
                "status": "partial",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md, packages/checks/AGENTS.md, packages/checks/CLAUDE.md, packages/config/CLAUDE.md, packages/encoding/CLAUDE.md, packages/grimoire/CLAUDE.md, packages/grimoire/concepts/CLAUDE.md, packages/grimoire/concepts/catalog/CLAUDE.md, packages/grimoire/concepts/property/CLAUDE.md, packages/text/CLAUDE.md"
                    }
                  },
                  {
                    "code": "agent_instructions_stub",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "94 of 99 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 94,
                      "sampled": 99
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 54,
            "inputs": {
              "has_nix": true,
              "has_tests": true,
              "lockfiles": [
                "pnpm-lock.yaml"
              ],
              "has_dockerfile": true,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [
                "packages/checks/tsconfig.json",
                "packages/config/tsconfig.json",
                "packages/encoding/tsconfig.json",
                "packages/grimoire/tsconfig.json",
                "packages/schema-case/tsconfig.json",
                "packages/text/tsconfig.json"
              ],
              "agent_commit_share": 0,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": "eslint.config.js",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "eslint.config.js"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "packages/checks/tsconfig.json, packages/config/tsconfig.json, packages/encoding/tsconfig.json, packages/grimoire/tsconfig.json, packages/schema-case/tsconfig.json, packages/text/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "packages/checks/tsconfig.json, packages/config/tsconfig.json, packages/encoding/tsconfig.json, packages/grimoire/tsconfig.json, packages/schema-case/tsconfig.json, packages/text/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, Nix, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, Nix, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 14024,
              "source_files_sampled": 132,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/132 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 132,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T20:50:13.507184Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/n/nodeve-com/nodeve.svg",
  "full_name": "nodeve-com/nodeve",
  "license_state": "standard",
  "license_spdx": "MIT"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.26.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计npm.