公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-27 09:20 UTC

orangecheck / oc-packages

Monorepo for the @orangecheck/* npm packages + the orangecheck Python SDK. SDK, gate middleware, React bindings, wallet adapter, CLI, Strfry relay filter, airdrop-gate.

TypeScriptMIT★ 0 星标⑂ 0 复刻始于 2026年4月在 GitHub 上查看 ↗

orangecheck/oc-packages 的健康指数为 100 分中的 55 分,处于「中等」区间。 其得分最高的类别是Vitality(84/100),最低的是Community & Adoption(34/100)。 最近一次更新在 4 天前。 近期的大部分工作由 1 位贡献者完成。

55
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

55
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

3 关注者19 个公开仓库始于 2025年4月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

84良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 4 天前
9/36提交节奏 — 52 周中有 13 周有提交
18/18提交量 — 最近一年 309 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year309
human_commit_share1
days_since_last_push4
active_weeks_last_year13

发布纪律

100优秀
评分方式
27/27有发布版本 — 已发布 100 个发布版本
36/36发布时效 — 最近一次发布版本于 6 天前
27/27发布节奏 — 约每 2 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count100
latest_release_tagdesign-v0.28.13
releases_from_tags
days_since_latest_release6
mean_days_between_releases2
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

34存在风险 · 占总体的 18%
评分方式
0/60星标 — 0 个星标
0/25复刻 — 0 个复刻
0/15关注者 — 0 位关注者
所用输入
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

50中等
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(MIT)
0/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
50.4/80月度下载量 — npm, pypi 合计每月 5,998 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packages@orangecheck/ui, @orangecheck/cli, @orangecheck/sdk, @orangecheck/gate, @orangecheck/legal, @orangecheck/react, @orangecheck/design, orangecheck
dependents
ecosystemsnpm, pypi
total_downloads
monthly_downloads5,998
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

44存在风险 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0/22.5提交分布 — 头号贡献者编写了 100% 的提交
1.4/13.5贡献者广度 — 1 位贡献者
0/10OpenSSF Scorecard:Contributors — project has 0 contributing companies or organizations -- score normalized to 0
所用输入
bus_factor1
contributors_sampled1
top_contributor_share1
评分方式
0/46.8议题解决 — 0% 的议题已关闭
38.2/38.3PR 接受 — 已裁定的 PR 中 19/19 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/30 approved changesets -- score normalized to 0
所用输入
merged_prs19
open_issues1
closed_issues0
issue_closed_ratio0
closed_unmerged_prs0
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
4.3/25所有者影响力 — orangecheck 有 3 位关注者
12/25既往记录 — 19 个公开仓库,账户约 1 年
所用输入
followers3
owner_typeOrganization
is_verified
owner_loginorangecheck
public_repos19
account_age_days456
评分方式
25/25已发布且可解析 — npm, pypi 上有 8 个软件包
35/35发布时效 — 最近一次发布于 6 天前
20/20版本历史 — 55 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packages@orangecheck/ui, @orangecheck/cli, @orangecheck/sdk, @orangecheck/gate, @orangecheck/legal, @orangecheck/react, @orangecheck/design, orangecheck
ecosystemsnpm, pypi
any_deprecated
min_days_since_publish6

工程质量

基础的工程与文档实践是否到位?

66中等 · 占总体的 20%

工程实践

60中等
评分方式
24/24CI 工作流 — 6 个工作流
24/24存在测试
0/16Linter 配置
0/9.6Pre-commit 钩子
0/6.4.editorconfig
0/20OpenSSF Scorecard:CI-Tests — 无数据
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config
已排除计分(无数据或不适用):OpenSSF Scorecard:CI-Tests。 其余权重已重新归一化。

文档

75良好
评分方式
30/30README
0/25文档目录
15/15文档 / 主页站点 — https://ochk.io
10/10仓库描述
10/10主题标签 — 10 个主题标签
10/10Wiki
所用输入
topicsbip322, bitcoin, express, middleware, nextjs, nostr, python, sdk, sybil-resistance, typescript
has_wiki
homepagehttps://ochk.io
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

42存在风险 · 占总体的 16%

安全态势

42存在风险
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — 无数据
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
7.5/7.5Dependency-Update-Tool — update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — 无数据
0/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
0/7.5Vulnerabilities — 47 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated16
scorecard_versionv5.5.0
checks_inconclusive2
scorecard_aggregate4.2
已排除计分(无数据或不适用):ci_tests, signed_releases。 其余权重已重新归一化。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

57中等 · 占总体的 0%
评分方式
0/45代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 100 次人类提交中有 95 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.95
agent_instruction_files
agent_instruction_max_bytes
评分方式
0/18一条命令的引导启动
22/22自动化测试
0/11Lint / 格式化配置
11/11静态类型检查 — agent-anthropic/tsconfig.json, agent-cli/tsconfig.json, agent-core/tsconfig.json, agent-langgraph/tsconfig.json, agent-mcp/tsconfig.json, agent-openai/tsconfig.json, agent-signer/tsconfig.json, agent-vercel/tsconfig.json, airdrop-gate/tsconfig.json, auth-client/tsconfig.json, auth-core/tsconfig.json, cli/tsconfig.json, design/tsconfig.json, gate/tsconfig.json, insights-client/tsconfig.json, legal/tsconfig.json, lock-core/tsconfig.json, lock-crypto/tsconfig.json, lock-device/tsconfig.json, me-client/tsconfig.json, nostr-core/tsconfig.json, pledge-core/tsconfig.json, react/tsconfig.json, relay-filter/tsconfig.json, sdk-py/orangecheck/py.typed, sdk/tsconfig.json, stamp-cli/tsconfig.json, stamp-core/tsconfig.json, stamp-ots/tsconfig.json, ui/tsconfig.json, vault-cli/tsconfig.json, vault-core/tsconfig.json, vote-cli/tsconfig.json, vote-core/tsconfig.json, vote-react/tsconfig.json, wallet-adapter/tsconfig.json, webhook-verify/tsconfig.json
10/10可复现环境 — lockfile
10/10已体现的代理实践 — 最近 100 次提交中有 29 次由代理编写或署名代理
0/8自动化维护 — 未观察到自动依赖更新
0/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
所用输入
has_nix
has_tests
lockfilesyarn.lock
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configsagent-anthropic/tsconfig.json, agent-cli/tsconfig.json, agent-core/tsconfig.json, agent-langgraph/tsconfig.json, agent-mcp/tsconfig.json, agent-openai/tsconfig.json, agent-signer/tsconfig.json, agent-vercel/tsconfig.json, airdrop-gate/tsconfig.json, auth-client/tsconfig.json, auth-core/tsconfig.json, cli/tsconfig.json, design/tsconfig.json, gate/tsconfig.json, insights-client/tsconfig.json, legal/tsconfig.json, lock-core/tsconfig.json, lock-crypto/tsconfig.json, lock-device/tsconfig.json, me-client/tsconfig.json, nostr-core/tsconfig.json, pledge-core/tsconfig.json, react/tsconfig.json, relay-filter/tsconfig.json, sdk-py/orangecheck/py.typed, sdk/tsconfig.json, stamp-cli/tsconfig.json, stamp-core/tsconfig.json, stamp-ots/tsconfig.json, ui/tsconfig.json, vault-cli/tsconfig.json, vault-core/tsconfig.json, vote-cli/tsconfig.json, vote-core/tsconfig.json, vote-react/tsconfig.json, wallet-adapter/tsconfig.json, webhook-verify/tsconfig.json
agent_commit_share0.29
toolchain_manifests
dependency_bot_commit_share0
评分方式
45/45可类型检查的代码 — TypeScript(静态类型)
55/55可控的文件大小 — 采样的 482 个源文件中有 0 个超过 60KB
所用输入
primary_languageTypeScript
largest_source_bytes56,314
source_files_sampled482
oversized_source_files0

关键数据

0GitHub 星标
1贡献者
309最近 12 个月提交数
4距最近推送天数
100发布版本数
1巴士系数(bus factor)
1开放议题
npm, PyPI软件包生态系统数

数据采集警告

  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

更多细节

OpenSSF Scorecard 4.2 / 10
4.2综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-27 09:20 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
不适用CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
10Dependency-Update-Toolupdate tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
不适用Signed-Releasesno releases found
0Token-Permissionsdetected GitHub workflow tokens with excessive permissions
0Vulnerabilities47 existing vulnerabilities detected
直接依赖 85
注册表软件包版本约束清单文件
npm@noble/hashes^1.5.0agent-anthropic/package.json
npm@orangecheck/agent-core^0.3.0agent-anthropic/package.json
npm@orangecheck/agent-signer^0.1.0agent-anthropic/package.json
npm@noble/hashes^1.5.0agent-cli/package.json
npm@orangecheck/agent-core^0.1.0agent-cli/package.json
npmbip322-js^3.0.0agent-cli/package.json
npmcommander^12.1.0agent-cli/package.json
npm@noble/hashes^1.5.0agent-core/package.json
npm@orangecheck/stamp-core^1.0.0agent-core/package.json
npm@orangecheck/lock-core^1.0.1agent-core/package.json
npm@noble/hashes^1.5.0agent-langgraph/package.json
npm@orangecheck/agent-core^0.3.0agent-langgraph/package.json
npm@orangecheck/agent-signer^0.1.0agent-langgraph/package.json
npm@noble/hashes^1.5.0agent-mcp/package.json
npm@orangecheck/agent-core^0.1.0agent-mcp/package.json
npm@orangecheck/agent-signer^0.1.0agent-mcp/package.json
npm@noble/hashes^1.5.0agent-openai/package.json
npm@orangecheck/agent-core^0.3.0agent-openai/package.json
npm@orangecheck/agent-signer^0.1.0agent-openai/package.json
npm@noble/hashes^1.5.0agent-signer/package.json
npm@orangecheck/agent-core^0.3.0agent-signer/package.json
npm@noble/hashes^1.5.0agent-vercel/package.json
npm@orangecheck/agent-core^0.3.0agent-vercel/package.json
npm@orangecheck/agent-signer^0.1.0agent-vercel/package.json
npm@orangecheck/sdk^0.1.3airdrop-gate/package.json
npm@simplewebauthn/browser^13.3.0auth-client/package.json
npmjose^6.2.2auth-core/package.json
npm@orangecheck/me-client^0.18.0cli/package.json
npm@orangecheck/sdk^0.1.3cli/package.json
npmcommander^12.1.0cli/package.json
npm@radix-ui/react-accordion^1.2.12design/package.json
npm@radix-ui/react-checkbox^1design/package.json
npm@radix-ui/react-dialog^1.1.15design/package.json
npm@radix-ui/react-label^2.1.7design/package.json
npm@radix-ui/react-popover^1.1.15design/package.json
npm@radix-ui/react-radio-group^1design/package.json
npm@radix-ui/react-select^2.2.6design/package.json
npm@radix-ui/react-separator^1.1.7design/package.json
npm@radix-ui/react-slot^1.2.3design/package.json
npm@radix-ui/react-switch^1design/package.json
npm@radix-ui/react-tabs^1.1.3design/package.json
npmclass-variance-authority^0.7.1design/package.json
npmclsx^2.1.1design/package.json
npmqrcode^1.5.4design/package.json
npmsonner^2.0.7design/package.json
npmtailwind-merge^3.3.1design/package.json
npm@orangecheck/sdk^0.1.4gate/package.json
npm@vercel/functions^3.7.3insights-client/package.json
npm@orangecheck/lock-crypto^0.1.0lock-core/package.json
npm@noble/ciphers^1.3.0lock-crypto/package.json
npm@noble/curves^1.6.0lock-crypto/package.json
npm@noble/hashes^1.5.0lock-crypto/package.json
npm@noble/curves^1.6.0lock-device/package.json
npm@orangecheck/lock-cryptofile:../lock-cryptolock-device/package.json
npm@orangecheck/auth-core^2.0.0me-client/package.json
npm@noble/hashes^1.5.0pledge-core/package.json
npm@orangecheck/sdk^0.1.3react/package.json
npm@orangecheck/sdk^0.1.3relay-filter/package.json
PyPIhttpx>=0.25sdk-py/pyproject.toml
npm@bitcoinerlab/secp256k1^1.1.1sdk/package.json
npm@noble/curves^2.2.0sdk/package.json
npm@noble/hashes^1.5.0sdk/package.json
npm@scure/base^1.1.9sdk/package.json
npmbip322-js^3.0.0sdk/package.json
npmbitcoinjs-message^2.2.0sdk/package.json
npmbuffer^6.0.3sdk/package.json
npm@orangecheck/stamp-core^0.1.2stamp-cli/package.json
npm@orangecheck/stamp-ots^0.1.1stamp-cli/package.json
npmbip322-js^3.0.0stamp-cli/package.json
npmcommander^12.1.0stamp-cli/package.json
npm@noble/hashes^1.5.0stamp-core/package.json
npm@orangecheck/stamp-core^0.1.2stamp-ots/package.json
npm@orangecheck/vault-core^0.2.0vault-cli/package.json
npmcommander^12.1.0vault-cli/package.json
npm@noble/hashes^1.5.0vault-core/package.json
npm@orangecheck/lock-crypto^0.1.0vault-core/package.json
npm@noble/curves^1.6.0vote-cli/package.json
npm@noble/hashes^1.5.0vote-cli/package.json
npm@orangecheck/vote-core^0.1.1vote-cli/package.json
npm@orangecheck/lock-core^0.1.0vote-cli/package.json
npm@orangecheck/lock-crypto^0.1.0vote-cli/package.json
npmbip322-js^3.0.0vote-cli/package.json
npmcommander^12.1.0vote-cli/package.json
npmws^8.18.0vote-cli/package.json
npm@noble/hashes^1.5.0vote-core/package.json
全部依赖 未采集

本报告未能采集到解析后的依赖集合:GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [
        "bip322",
        "bitcoin",
        "express",
        "middleware",
        "nextjs",
        "nostr",
        "python",
        "sdk",
        "sybil-resistance",
        "typescript"
      ],
      "is_fork": false,
      "size_kb": 2104,
      "has_wiki": true,
      "homepage": "https://ochk.io",
      "languages": {
        "CSS": 77541,
        "Python": 161481,
        "JavaScript": 40861,
        "TypeScript": 2377914
      },
      "pushed_at": "2026-07-22T17:53:37Z",
      "created_at": "2026-04-22T00:05:01Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-22T17:28:43Z",
      "description": "Monorepo for the @orangecheck/* npm packages + the orangecheck Python SDK. SDK, gate middleware, React bindings, wallet adapter, CLI, Strfry relay filter, airdrop-gate.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "TypeScript",
      "significant_languages": [
        "TypeScript"
      ]
    },
    "owner": {
      "blog": "https://ochk.io",
      "name": "OrangeCheck",
      "type": "Organization",
      "login": "orangecheck",
      "company": null,
      "location": null,
      "followers": 3,
      "avatar_url": "https://avatars.githubusercontent.com/u/209241724?v=4",
      "created_at": "2025-04-26T12:20:56Z",
      "is_verified": null,
      "public_repos": 19,
      "account_age_days": 456
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "design-v0.28.13",
          "kind": "other",
          "published_at": "2026-07-20T18:30:23Z"
        },
        {
          "tag": "me-client-v0.24.0",
          "kind": "other",
          "published_at": "2026-07-08T18:24:22Z"
        },
        {
          "tag": "auth-client-v2.22.0",
          "kind": "other",
          "published_at": "2026-07-06T16:59:29Z"
        },
        {
          "tag": "design-v0.28.12",
          "kind": "other",
          "published_at": "2026-07-06T16:59:23Z"
        },
        {
          "tag": "me-client-v0.23.0",
          "kind": "other",
          "published_at": "2026-07-05T00:00:01Z"
        },
        {
          "tag": "design-v0.28.11",
          "kind": "other",
          "published_at": "2026-07-04T06:33:03Z"
        },
        {
          "tag": "design-v0.28.10",
          "kind": "other",
          "published_at": "2026-07-04T03:15:39Z"
        },
        {
          "tag": "design-v0.28.9",
          "kind": "other",
          "published_at": "2026-07-03T22:13:30Z"
        },
        {
          "tag": "design-v0.28.8",
          "kind": "other",
          "published_at": "2026-07-02T22:59:03Z"
        },
        {
          "tag": "design-v0.28.7",
          "kind": "other",
          "published_at": "2026-07-02T22:20:35Z"
        },
        {
          "tag": "design-v0.28.6",
          "kind": "other",
          "published_at": "2026-07-02T21:09:54Z"
        },
        {
          "tag": "design-v0.28.5",
          "kind": "other",
          "published_at": "2026-07-02T20:37:53Z"
        },
        {
          "tag": "design-v0.28.4",
          "kind": "other",
          "published_at": "2026-07-02T20:23:02Z"
        },
        {
          "tag": "design-v0.28.3",
          "kind": "other",
          "published_at": "2026-07-02T20:10:02Z"
        },
        {
          "tag": "design-v0.28.2",
          "kind": "other",
          "published_at": "2026-07-02T19:47:25Z"
        },
        {
          "tag": "design-v0.28.1",
          "kind": "other",
          "published_at": "2026-07-02T19:25:37Z"
        },
        {
          "tag": "design-v0.28.0",
          "kind": "other",
          "published_at": "2026-07-02T19:12:44Z"
        },
        {
          "tag": "design-v0.27.0",
          "kind": "other",
          "published_at": "2026-07-02T18:35:04Z"
        },
        {
          "tag": "design-v0.26.0",
          "kind": "other",
          "published_at": "2026-07-02T18:17:23Z"
        },
        {
          "tag": "design-v0.25.0",
          "kind": "other",
          "published_at": "2026-06-30T18:02:48Z"
        },
        {
          "tag": "design-v0.24.0",
          "kind": "other",
          "published_at": "2026-06-30T17:55:10Z"
        },
        {
          "tag": "design-v0.23.0",
          "kind": "other",
          "published_at": "2026-06-30T14:28:08Z"
        },
        {
          "tag": "design-v0.22.0",
          "kind": "other",
          "published_at": "2026-06-29T15:33:36Z"
        },
        {
          "tag": "design-v0.21.0",
          "kind": "other",
          "published_at": "2026-06-25T20:02:45Z"
        },
        {
          "tag": "design-v0.20.0",
          "kind": "other",
          "published_at": "2026-06-25T19:07:04Z"
        },
        {
          "tag": "insights-client-v0.1.1",
          "kind": "other",
          "published_at": "2026-06-23T21:04:19Z"
        },
        {
          "tag": "auth-client-v2.21.0",
          "kind": "other",
          "published_at": "2026-06-23T19:50:49Z"
        },
        {
          "tag": "auth-client-v2.20.0",
          "kind": "other",
          "published_at": "2026-06-23T01:15:44Z"
        },
        {
          "tag": "design-v0.19.0",
          "kind": "other",
          "published_at": "2026-06-22T19:38:00Z"
        },
        {
          "tag": "auth-client-v2.19.0",
          "kind": "other",
          "published_at": "2026-06-22T19:08:39Z"
        },
        {
          "tag": "wallet-adapter-v0.4.1",
          "kind": "other",
          "published_at": "2026-06-16T05:08:37Z"
        },
        {
          "tag": "design-v0.18.0",
          "kind": "other",
          "published_at": "2026-06-15T17:32:58Z"
        },
        {
          "tag": "design-v0.17.0",
          "kind": "other",
          "published_at": "2026-06-12T02:28:38Z"
        },
        {
          "tag": "design-v0.16.0",
          "kind": "other",
          "published_at": "2026-06-11T23:54:28Z"
        },
        {
          "tag": "design-v0.15.0",
          "kind": "other",
          "published_at": "2026-06-11T14:49:43Z"
        },
        {
          "tag": "auth-core-v2.5.0",
          "kind": "other",
          "published_at": "2026-06-11T14:49:28Z"
        },
        {
          "tag": "auth-client-v2.18.0",
          "kind": "other",
          "published_at": "2026-06-11T14:49:23Z"
        },
        {
          "tag": "me-client-v0.22.0",
          "kind": "other",
          "published_at": "2026-06-09T22:19:58Z"
        },
        {
          "tag": "design-v0.14.0",
          "kind": "other",
          "published_at": "2026-06-05T23:07:58Z"
        },
        {
          "tag": "design-v0.13.1",
          "kind": "other",
          "published_at": "2026-06-05T23:04:05Z"
        },
        {
          "tag": "agent-core-v1.1.0",
          "kind": "other",
          "published_at": "2026-06-05T19:04:31Z"
        },
        {
          "tag": "design-v0.13.0",
          "kind": "other",
          "published_at": "2026-06-05T18:14:30Z"
        },
        {
          "tag": "design-v0.12.0",
          "kind": "other",
          "published_at": "2026-06-05T17:33:53Z"
        },
        {
          "tag": "design-v0.11.0",
          "kind": "other",
          "published_at": "2026-06-05T16:28:28Z"
        },
        {
          "tag": "legal-v0.2.1",
          "kind": "other",
          "published_at": "2026-06-04T12:00:11Z"
        },
        {
          "tag": "insights-client-v0.1.0",
          "kind": "other",
          "published_at": "2026-06-04T06:28:48Z"
        },
        {
          "tag": "design-v0.10.0",
          "kind": "other",
          "published_at": "2026-06-03T05:48:52Z"
        },
        {
          "tag": "design-v0.9.1",
          "kind": "other",
          "published_at": "2026-06-02T17:52:36Z"
        },
        {
          "tag": "design-v0.9.0",
          "kind": "other",
          "published_at": "2026-06-02T17:25:31Z"
        },
        {
          "tag": "design-v0.8.0",
          "kind": "other",
          "published_at": "2026-06-01T19:53:52Z"
        },
        {
          "tag": "design-v0.7.6",
          "kind": "other",
          "published_at": "2026-05-28T17:25:25Z"
        },
        {
          "tag": "design-v0.7.5",
          "kind": "other",
          "published_at": "2026-05-27T19:52:33Z"
        },
        {
          "tag": "design-v0.7.4",
          "kind": "other",
          "published_at": "2026-05-27T19:26:39Z"
        },
        {
          "tag": "design-v0.7.3",
          "kind": "other",
          "published_at": "2026-05-27T17:51:19Z"
        },
        {
          "tag": "design-v0.7.2",
          "kind": "other",
          "published_at": "2026-05-27T17:36:29Z"
        },
        {
          "tag": "design-v0.7.1",
          "kind": "other",
          "published_at": "2026-05-27T16:21:23Z"
        },
        {
          "tag": "design-v0.7.0",
          "kind": "other",
          "published_at": "2026-05-27T15:12:34Z"
        },
        {
          "tag": "design-v0.6.1",
          "kind": "other",
          "published_at": "2026-05-26T19:34:13Z"
        },
        {
          "tag": "design-v0.6.0",
          "kind": "other",
          "published_at": "2026-05-26T19:21:26Z"
        },
        {
          "tag": "design-v0.5.3",
          "kind": "other",
          "published_at": "2026-05-26T19:11:39Z"
        },
        {
          "tag": "design-v0.5.2",
          "kind": "other",
          "published_at": "2026-05-26T15:33:32Z"
        },
        {
          "tag": "design-v0.5.1",
          "kind": "other",
          "published_at": "2026-05-25T21:15:56Z"
        },
        {
          "tag": "design-v0.5.0",
          "kind": "other",
          "published_at": "2026-05-25T17:58:45Z"
        },
        {
          "tag": "design-v0.4.0",
          "kind": "other",
          "published_at": "2026-05-25T15:28:10Z"
        },
        {
          "tag": "design-v0.3.0",
          "kind": "other",
          "published_at": "2026-05-25T15:15:29Z"
        },
        {
          "tag": "design-v0.2.0",
          "kind": "other",
          "published_at": "2026-05-25T14:32:04Z"
        },
        {
          "tag": "design-v0.1.1",
          "kind": "other",
          "published_at": "2026-05-22T23:23:28Z"
        },
        {
          "tag": "design-v0.1.0",
          "kind": "other",
          "published_at": "2026-05-22T21:28:09Z"
        },
        {
          "tag": "auth-client-v2.17.2",
          "kind": "other",
          "published_at": "2026-05-21T05:08:14Z"
        },
        {
          "tag": "ui-v0.15.2",
          "kind": "other",
          "published_at": "2026-05-20T22:01:30Z"
        },
        {
          "tag": "ui-v0.15.1",
          "kind": "other",
          "published_at": "2026-05-20T20:03:21Z"
        },
        {
          "tag": "auth-client-v2.17.1",
          "kind": "other",
          "published_at": "2026-05-20T20:03:15Z"
        },
        {
          "tag": "ui-v0.15.0",
          "kind": "other",
          "published_at": "2026-05-20T17:45:59Z"
        },
        {
          "tag": "auth-client-v2.17.0",
          "kind": "other",
          "published_at": "2026-05-20T17:38:04Z"
        },
        {
          "tag": "auth-client-v2.15.0",
          "kind": "other",
          "published_at": "2026-05-19T15:48:40Z"
        },
        {
          "tag": "auth-client-v2.14.1",
          "kind": "other",
          "published_at": "2026-05-19T03:42:51Z"
        },
        {
          "tag": "ui-v0.14.0",
          "kind": "other",
          "published_at": "2026-05-19T01:33:04Z"
        },
        {
          "tag": "auth-client-v2.14.0",
          "kind": "other",
          "published_at": "2026-05-18T23:02:43Z"
        },
        {
          "tag": "ui-v0.13.0",
          "kind": "other",
          "published_at": "2026-05-18T17:14:16Z"
        },
        {
          "tag": "ui-v0.12.0",
          "kind": "other",
          "published_at": "2026-05-18T16:03:10Z"
        },
        {
          "tag": "auth-client-v2.13.0",
          "kind": "other",
          "published_at": "2026-05-18T15:55:11Z"
        },
        {
          "tag": "auth-core-v2.4.0",
          "kind": "other",
          "published_at": "2026-05-18T15:42:17Z"
        },
        {
          "tag": "ui-v0.11.0",
          "kind": "other",
          "published_at": "2026-05-18T15:03:31Z"
        },
        {
          "tag": "auth-client-v2.12.0",
          "kind": "other",
          "published_at": "2026-05-18T15:03:21Z"
        },
        {
          "tag": "cli-v0.2.0",
          "kind": "other",
          "published_at": "2026-05-10T04:28:36Z"
        },
        {
          "tag": "me-client-v0.18.0",
          "kind": "other",
          "published_at": "2026-05-10T04:24:27Z"
        },
        {
          "tag": "me-client-v0.17.0",
          "kind": "other",
          "published_at": "2026-05-10T04:06:56Z"
        },
        {
          "tag": "me-client-v0.16.0",
          "kind": "other",
          "published_at": "2026-05-09T08:16:44Z"
        },
        {
          "tag": "me-client-v0.15.0",
          "kind": "other",
          "published_at": "2026-05-09T08:01:03Z"
        },
        {
          "tag": "nostr-core-v0.1.1",
          "kind": "other",
          "published_at": "2026-05-09T07:14:46Z"
        },
        {
          "tag": "nostr-core-v0.1.0",
          "kind": "other",
          "published_at": "2026-05-08T19:28:42Z"
        },
        {
          "tag": "agent-core-v1.0.1",
          "kind": "other",
          "published_at": "2026-05-07T21:58:43Z"
        },
        {
          "tag": "lock-core-v1.0.1",
          "kind": "other",
          "published_at": "2026-05-07T21:57:26Z"
        },
        {
          "tag": "agent-core-v1.0.0",
          "kind": "other",
          "published_at": "2026-05-07T19:16:57Z"
        },
        {
          "tag": "vote-core-v1.0.0",
          "kind": "other",
          "published_at": "2026-05-07T19:16:49Z"
        },
        {
          "tag": "sdk-v1.0.0",
          "kind": "other",
          "published_at": "2026-05-07T19:16:23Z"
        },
        {
          "tag": "stamp-core-v1.0.0",
          "kind": "other",
          "published_at": "2026-05-07T19:16:18Z"
        },
        {
          "tag": "lock-core-v1.0.0",
          "kind": "other",
          "published_at": "2026-05-07T19:16:18Z"
        },
        {
          "tag": "pledge-core-v1.0.0",
          "kind": "other",
          "published_at": "2026-05-07T18:27:11Z"
        },
        {
          "tag": "sdk-py-v1.0.0",
          "kind": "other",
          "published_at": "2026-05-07T18:27:07Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "2238e09092ca384e98d417e2ce4a668259611619",
          "body": "oc-media-kit added the globe brand, so its generated glyphs.ts now carries 16\nglyphs. Re-vendor to keep design in sync (check-glyph-drift green). No version\nbump — globe's site doesn't consume the sigil glyph; this rides the next\ndesign publish.",
          "is_bot": false,
          "headline": "re-vendor glyph catalog: add globe",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-22T17:26:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69fa507175fa1ae3dc5c000b294dde7c8a00d9cf",
          "body": "globe.ochk.io shipped with `slug: 'globe' as EcosystemSlug` — a cast that\npapered over the slug being absent from the union, FAMILY_PROPERTIES and the\nswitcher ENTRIES. The visible cost: globe does not self-highlight in its own\nlogo dropdown and does not appear in any sibling's switcher at all.\n\nRegistered alongside btc as the family's second read-only terminal.",
          "is_bot": false,
          "headline": "register oc·globe in the family registry",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-20T18:29:05Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b866d062dba6c2a06f272bf07458a7673ab5d3d9",
          "body": "Make the live-mode revenue path actually work.\n\noc.event.fire / fireBatch gain:\n- signingSecret → X-OC-Signature HMAC authenticating the call as the\n  INTEGRATOR. Live mode 401s without it (a user session proves a user,\n  never the paying project). Server-side only.\n- bearerToken → the forwarded use\n[…]\ne) HMAC keeps the package isomorphic (no node:crypto\nimport); a parity test asserts the signature byte-matches the server's\nnode:crypto verifier, and that the secret never leaks into the request body.",
          "is_bot": false,
          "headline": "me-client: sign billable events + drop the user_address footgun",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-08T18:23:26Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f3764727d0f9035bfc2bef888f97fcda689f074f",
          "body": "…ount a tab is on\n\nThe '§ show as' list resolves per-account via the tab's session; a tab\nsigned into a different account than your other tabs showed only a did,\nso it looked like the menu 'lost' your email. Two fixes:\n\n- design: surface the current account's identity (email/bitcoin/nostr)\n  in the \n[…]\n itself\n  so the show-as list is the tab's actual account even when called\n  outside a provider (previously relied solely on the global fetch\n  interceptor). Host already reads the header fail-closed.",
          "is_bot": false,
          "headline": "auth-client@2.22.0 + design@0.28.12: account menu tells you which acc…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-06T16:58:02Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "22ecbd125a7faf713a598c103737984e5e5b8f7d",
          "body": "…og (#34)\n\nThe app already accepts integrator-defined event keys (open catalog, #23) but\nthe SDK still typed subtype as the closed EventSubtype union, so a custom event\nwouldn't type-check for SDK users. Add EventKey = EventSubtype | (string & {})\n— keeps built-in autocomplete, accepts any custom ke\n[…]\nEventInput.subtype, BillableEvent.subtype, the OC-Subtype webhook header,\nand validation errors. Built-in metadata + drop schedules stay closed.\nBackward-compatible (EventKey ⊇ EventSubtype). +1 test.",
          "is_bot": false,
          "headline": "me-client@0.23.0: widen EventKey — SDK matches the open project catal…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-04T23:59:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "89d103335a5f5f86bbaf6ee838cbc248bb74d432",
          "body": "…rflow-x-auto — the latter forced overflow-y:auto and clipped the active-tab underline (regression in 0.28.10)",
          "is_bot": false,
          "headline": "design@0.28.11: TabsList wraps on overflow (flex-wrap) instead of ove…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-04T06:31:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cac9626d37cf0ec90bd3664e0f22a09239213664",
          "body": "…verflow the page on mobile",
          "is_bot": false,
          "headline": "design@0.28.10: TabsList scrolls on overflow so long tab rows never o…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-04T03:14:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "80e34fc34c7b7e323e67414a12fa4fa309ebed84",
          "body": "…(prev commit reformatted the whole file with prettier defaults); TabsList scroll fix unchanged",
          "is_bot": false,
          "headline": "design: restore tabs.tsx to the package's single-quote/4-space style …",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-04T02:58:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e613a6dee3bad3be8a3a22bd85a474c6382dce1c",
          "body": "…-x-auto, hidden scrollbar) so a long tab row never overflows the page on mobile",
          "is_bot": false,
          "headline": "design: TabsList scrolls horizontally on overflow (min-w-0 + overflow…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-04T02:55:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5bbe622abc6241dc2094ae976198909c72b23cac",
          "body": "…gisters\n\nStrip tile frames so pictograms emboss (not the square); floor/cap strokes so\nno mark vanishes or bloats; per-verb focus sizing. Lit letterpress relief under\nember (specular leaf, chromatic shade) vs unlit echo stack under cypherpunk;\ndepth melts to transparent (composites over the aurora). Calmer pose, eased\nrelief, corner-aware mask, mobile presence floor. New band deboss preset +\nband prop; --oc-sigil-bg removed. verify-sigil-transforms guards the regexes.",
          "is_bot": false,
          "headline": "design@0.28.9: OcSigil beauty pass — mark surgery, lit relief, two re…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-03T22:10:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8f4041c631efdbb656fc9ca97d9b8385731c64ca",
          "body": "…{{ gl: false }})\n\nFlip the provider default so a bare/true aurora (or an intensity-only object)\nmounts the GL silk field. The CSS blobs stay the floor, so failure/degradation\nbehavior is unchanged. Reading + owner-console surfaces opt out with gl:false.",
          "is_bot": false,
          "headline": "design@0.28.8: OcAuroraGL is the family default (opt out with aurora=…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T22:56:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b94e3f51162eaac84094f11d6a2d337adbcff72",
          "body": "…e-on-brand)",
          "is_bot": false,
          "headline": "design@0.28.7: OcSigil --oc-sigil-ink — mark on a coloured band (whit…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T22:18:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "38d497bd7cb51cb7a538fe20ac233dcd9bb2aa39",
          "body": "…alog\n\nRe-vendored glyphs.ts (emitter now emits solid vs outline per is_glyph_only),\nsub() resolves only the ink sentinel, and the PerVerb story is a 15-mark\ncatalog that catches a broken glyph. All marks render as coherent 3D marks.",
          "is_bot": false,
          "headline": "design@0.28.6: fix broken per-verb sigil glyphs + rebuild PerVerb cat…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T21:07:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0aca867702df0ef9939bfbc53ff6aa2a81a5cec6",
          "body": "…ment",
          "is_bot": false,
          "headline": "design@0.28.5: OcSigil — light-mode presence + mobile top-right place…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T20:36:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf0117483fa18bdf9c37ff398ed59c4d83244087",
          "body": "…ment",
          "is_bot": false,
          "headline": "design@0.28.4: OcSigil — light-mode presence + mobile top-right place…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T20:21:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "34b80e7f4e348935b7eba31f26680b92adbfd5cc",
          "body": "Address real feedback: the opaque corner object read loud and barely\npresent, and it was display:none on phones. Rework to a see-through 3D\nwatermark — the relief composites at --oc-sigil-opacity so the aurora reads\nthrough, softer color ramp, responsive clamp() size, and it stays visible\n(smaller/quieter) on mobile instead of vanishing. All tunable via CSS vars.",
          "is_bot": false,
          "headline": "design@0.28.3: OcSigil — translucent, muted, responsive watermark",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T20:07:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "75115230f6215d46ab5e348cd146a5ef9f026a53",
          "body": "The sub-brand glyphs are tiles (filled square + frame + detail); filling fg\nmade a solid block. Render the outline form (fg=none) so the tile drops away,\nleaving the recognizable framed mark — an engraved seal. And replace the 6\nflat overlapping layers with 22 computed layers of real z-separation: lit\nfront face, shadowed extrusion walls, back dissolving into --background — a\ntrue 3D object catching light as it drifts. One treatment recolored per skin.",
          "is_bot": false,
          "headline": "design@0.28.2: OcSigil — fix the orange block, add real 3D extrusion",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T19:46:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0150cddc6c12bbfc8287e55ee2e99c329ec81be",
          "body": "The filled letterpress register was invisible on ember: a low-contrast\nsame-hue relief over the aurora's warm bloom in the same corner failed the\nminimum-visibility floor. Strengthen the relief ramp so the front face is a\ndefined --primary silhouette (opaque, occluding the aurora within the glyph)\nwhile the back layers still dissolve into --background. Wireframe register\nuntouched. Caught by real-browser taste check on the stamp pilot.",
          "is_bot": false,
          "headline": "design@0.28.1: OcSigil emboss visibility — ember-first ramp",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T19:24:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d8049605a43ba4a3ab6d8b0950eb4dc8a7ec161",
          "body": "…pth R3, ships dormant)\n\nThe figure component of the backdrop program: 6 stacked <use> layers of the\nverb's own normalized media-kit glyph under perspective+translateZ, opaque\ncolor-mix ramp toward --background (contrast ceiling + visibility floor are\ncompiled in, not consumer-tunable), damped ±5° p\n[…]\nield + one figure; one motion\nsource per hero). Glyph geometry is vendored from oc-media-kit's new\nemit_glyphs.py artifact; scripts/check-glyph-drift.mjs guards the sync and\nruns first in yarn verify.",
          "is_bot": false,
          "headline": "design@0.28.0: OcSigil — the mark as a corner-bleed emboss (aurora de…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T19:10:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4f31cfe855e16d82506b54387b9852df9fefc2bd",
          "body": "… R2, default off)\n\nOne ~8KB WebGL2 fragment shader supersedes the perceptual output of the\n5-blob CSS aurora: domain-warped fBm recolored live from the same --au-*\nslots via the color-mix probe rail (scene-tokens.ts — OKLCH tokens resolve\nnatively in the browser, no parser), IGN dither so dark mode\n[…]\nde (one aurora at a time). Settle-to-static after 90s idle.\nPer-site kill: .oc-aurora { --oc-aurora-gl: off }. gl is opt-in via the\nprovider prop; chat/docs intensity objects keep compiling unchanged.",
          "is_bot": false,
          "headline": "design@0.27.0: OcAuroraGL — the token-driven silk field (aurora depth…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T18:32:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a14528f134e7b578e57f28c1aa9e984d035d02b8",
          "body": "…epth R1)\n\nWCAG 2.2.2 Pause/Stop/Hide has no exemption for >5s decorative motion and\nprefers-reduced-motion alone doesn't satisfy it — the aurora has shipped that\ngap on every family site. This release closes it: an oc_motion cookie at\nDomain=.ochk.io, applied pre-paint by getOcThemeInitScript as\nda\n[…]\nhand-rolled bg-primary/10 blur-3xl divs (mark baked from\nthe normalized media-kit render, never the raw font-space path). Groundwork\nfor aurora depth R2 (OcAuroraGL) per research/AURORA-DEPTH-PLAN.md.",
          "is_bot": false,
          "headline": "design@0.26.0: ambient-motion governance + backdrop texture (aurora d…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-07-02T18:14:21Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a629620f484e69e654dc59b2bf9afcb7c8c37223",
          "body": "Add optional legalCopyright / legalLinks / builtWith props so sites keep\none consistent legal-bar shape while preserving meaningful content (btc's\n'read on bitcoin' + disclaimer, me's charter link). Defaults unchanged.",
          "is_bot": false,
          "headline": "feat(design): OcFamilyFooter legal-bar overrides",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-30T18:01:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7a2f30232ddffb0ca1a7eef1dcbd03f74382bcb8",
          "body": "Extracts the per-site LayoutFooter shape (brand block · §-labelled link\ncolumns · legal bar + built-with-bitcoin) into one component. The\nfamily product/protocol columns are driven off FAMILY_PROPERTIES via the\n`family` prop, so any footer that lists the family can never drift from\nthe canonical table again.",
          "is_bot": false,
          "headline": "feat(design): OcFamilyFooter — one canonical family footer",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-30T17:53:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "00911eb0de584fe894ea22e42a8f97718aab781e",
          "body": "The dashboard/data composites (StatGrid, StatCard, DataRow lists,\nDefinitionList, data tables) + a new Panel (DataSection) now re-skin per\ntheme: flat/sharp/mono terminal under the cypherpunk skins (byte-for-byte\nunchanged), soft/warm/rounded cards under ember. Built via semantic classes\n(.oc-stat-g\n[…]\nded by an ember-scoped CSS block — so data-dense technical\nsubpages (status, dashboards, api surfaces) read as ember instead of terminal.\nVerified both skins in Storybook; themes 5/5, stories 135/135.",
          "is_bot": false,
          "headline": "design@0.23.0: ember treatments for data-dense technical surfaces",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-30T14:26:53Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4c646f37ba9dc5d1f857f905fbd7ce2a8ef6b91c",
          "body": "ember now owns the bare :root/.dark base (the no-JS / pre-hydration / SSR\nfallback); orangecheck + phosphor + lightning + gold become attribute-only\narms imported after it. DEFAULT_OC_THEME='ember' and OC_THEMES lists ember\nfirst, so a user with no oc_skin cookie gets ember and the picker leads with\n[…]\n/--au-blue under ember so the ambient field\n  stays amber/terracotta instead of leaking cool teal/blue.\n- MarketingHeading onBrand muted clause /60 → /75 (was below AA-large on the\n  terracotta band).",
          "is_bot": false,
          "headline": "design@0.22.0: make ember the family default skin + first in the picker",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-29T15:32:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ef5363f001d2cfe681d64257fbb45992ddc987f5",
          "body": "Stories for the 12 new ember-era components (Surface, IconBadge, plus the\nmarketing composites: MarketingHeading, FeatureCard, Section/BrandBand,\nComparisonTable, StepList, Faq, EmailCapture, CheckList, AccentNote,\nVerifiedChip). README documents the five skins, ember's self-hosted font,\nand the verify-script step when adding a skin. Stories-only — no version bump.\nverify-stories: 134/134 OK.",
          "is_bot": false,
          "headline": "design: Storybook stories for the ember marketing tier + skin docs",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-29T14:07:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e0798432e9a5acb90aeb974feb61a01fbb7d0b91",
          "body": "Append oc·btc (category product) to FAMILY_PROPERTIES + EcosystemSwitcher\nENTRIES + the EcosystemSlug union, so btc.ochk.io shows up in every sibling's\nlogo dropdown and account menu. Additive — no existing entry changes.",
          "is_bot": false,
          "headline": "design: v0.21.0 — add btc.ochk.io to the family site-picker",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-25T20:01:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e2d991439d4a795a8852ea3bdce61a45a0cf9d87",
          "body": "ember references 'Hanken Grotesk'; ship it IN the package (OFL variable woff2,\nlatin + latin-ext, wght 400–900) via @font-face so the skin renders correctly on\nevery consumer with ZERO per-site next/font wiring. The browser only fetches it\nwhen the family is actually used (ember active), so the cyph\n[…]\ntier (Surface,\nIconBadge, FeatureCard, MarketingHeading, Section, ComparisonTable, StepList,\nFaq, EmailCapture, CheckList, AccentNote, VerifiedChip), Button onBrand variants,\nand the self-hosted font.",
          "is_bot": false,
          "headline": "design@0.20.0: self-host Hanken Grotesk for the ember skin + release",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-25T19:05:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4a3f4457c270335926ab3f82cd681c017359ed22",
          "body": "The terminal-window chrome (mono body, cool-gray strip, traffic-light dots,\nsharp/tight corners) is the cypherpunk skins' identity — there is no reason a\nwarm consumer skin should render Card / Modal / Confirm / Prompt as green-screen\nwindows. Skin-scoped (ember only) so the other skins keep their t\n[…]\n  → rounded, with the message + action labels in warm sans/normal-case via a\n  :has(.terminal-title) anchor; secret/value inputs stay mono.\n\nVerified: 99/99 stories, ember AA both modes, 5/5 distinct.",
          "is_bot": false,
          "headline": "design: de-terminalize the system surfaces under ember (no green-screen)",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-25T18:40:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "68b535fcd53b04de86e03ec1b5931f8a244a96e4",
          "body": "…leteness)\n\nSection-by-section comparison against the source mockups drove these:\n- Eyebrows now render TERRACOTTA, not gray. Root cause: .label-mono hardcoded a\n  muted color that overrode the caller's text-primary. Made .label-mono type-only\n  (no color); every eyebrow + SectionHeader tone + Callo\n[…]\ntrast); the OC button check sits in a chip; FAQ has its\n  hairline; the for-business closing line is back; the footer headline is one line.\n\nVerified: 99/99 stories, ember AA both modes, 5/5 distinct.",
          "is_bot": false,
          "headline": "design: tighten ember fidelity to Sou's mockups (eyebrows, type, comp…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-25T18:06:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "be92b7ac1b5f8cd878078a941601d6d713068e73",
          "body": "The real gap the showcase exposed: no Button variant for CTAs placed ON a brand\nband or dark section, so they were hacked with classNames — and one rendered\nwhite-text-on-white (the hero \"See how it works\" was unreadable). Add proper\nvariants so the rollout just works:\n- Button `onBrand` (white pill\n[…]\n → accent-foreground\n  (adapts light↔dark).\n- checkbox/radio invalid now show a persistent destructive ring (was invisible\n  when checked).\n\nVerified: 99/99 stories, ember AA both modes, 5/5 distinct.",
          "is_bot": false,
          "headline": "design: first-class on-brand Button variants + ember legibility fixes",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-25T17:42:23Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5b7570f18cc77d73ed66ba9d0d0d601bc0cd0ae3",
          "body": "…ntity\n\nFull component audit under ember (light+dark) surfaced and fixed:\n- bg-brand bands: tailwind-merge dropped bg-brand next to bg-diagonal (both read\n  as bg-*). Renamed motifs to currentColor .oc-diagonal/.oc-dots (non-bg prefix)\n  so brand/CTA bands actually render terracotta.\n- dark --primar\n[…]\na/switch) now use destructive (red)\n  for aria-invalid instead of brand — invalid no longer looks like valid.\n\nVerified: 99/99 stories render error-free, 5/5 skins distinct, ember AA-clean\nboth modes.",
          "is_bot": false,
          "headline": "design: fix ember theme across every component + embrace the warm ide…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-25T17:20:37Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9eba38dda2c5676b6c2e0b3099f360ad122fefaa",
          "body": "A new warm, consumer-grade skin (the counterpoint to the sharp/cypherpunk\ndefaults): deep burnt-sienna terracotta, peach accents, 1rem radius, pill\nbuttons, soft warm elevation, Hanken Grotesk. Full light+dark token arms,\nregistered via the data-driven registry so it reaches every site's appearance\n\n[…]\nCard\nor dashboard SectionHeader.\n\nThemes/Ember Showcase reproduces the full redesign from these components.\nVerified: 5/5 skins distinct, ember AA-clean in both modes, 99/99 stories\nrender error-free.",
          "is_bot": false,
          "headline": "design: add the ember skin + marketing composite tier",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-25T16:36:17Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e92d2c00b8511950c200686ec942bc391864a051",
          "body": "…overflows the page as a grid/flex child",
          "is_bot": false,
          "headline": "design: .terminal min-width:0 + max-width:100% so a code panel never …",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-25T14:34:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3c4b73c03bc7e1be07c8db81aa05f586dabbd330",
          "body": "cosign (5 @orangecheck/* deps), chat (8), forge (4), and vault-extension (1) were\nnever added to the global consumer list, so they silently drift on every\n@orangecheck/* package — including the insights-client@0.1.1 Lane-2 fix. All four\nhave live GitHub remotes; enroll them so the auto-bumper keeps them current\n(CI-gated auto-merge, same as the rest). Found while verifying the insights-client\nfanout reaches www/attest/me (it does — they were already enrolled).",
          "is_bot": false,
          "headline": "renovate: enroll the 4 missing family-package consumers",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-23T22:43:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2fde1a3cbc248834af36557c72c5f40a85ab5497",
          "body": "The fire-and-forget emit was being dropped on Vercel: the serverless function\nfreezes after the response before the keepalive POST flushes, so every\nconsumer's `void emit()` reached the collector with ZERO events (verified\nempty across www/attest/me despite tokens being set). emitEvent now hands its\n[…]\non, no per-app change. No-op outside a Vercel request\ncontext (try/catch); the keepalive fetch stays as the off-Vercel fallback.\nPatch bump so ^0.1.0 consumers auto-fanout via Renovate. 9 tests green.",
          "is_bot": false,
          "headline": "insights-client@0.1.1: deliver on Vercel via internal waitUntil",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-23T21:03:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "82a32c9cf75d59ac73c972226fce963afb2d5fba",
          "body": "…n tabs\n\nA new tab (CTRL/⌘/middle-click) can't inherit the opener's sessionStorage\npin, so it resolved to the shared cookie's default account. The opener\nnow stamps its effective did:oc onto outgoing family-origin links\n(#oc-as=<did> — a public selector in a fragment, never the JWT), and the\nlanding\n[…]\nAccountHint are auto-installed by\nOcSessionProvider, so consumers need only the version bump. auth-core is\nunchanged (resolveSessionFromRequest already resolves the tab header\nfirst and fails closed).",
          "is_bot": false,
          "headline": "auth-client@2.21.0: inherit the tab's account into new/cross-subdomai…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-23T19:40:39Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "25e101f85e51f50a4b0ae60f884dbe62de9618c3",
          "body": "OcSignIn now defaults providersFirst=true (OAuth on top, email one-time-code the\ndefault tab, BIP-322 wallet one tab away) — the email/OAuth-first ceremony is now\nthe family standard every consumer inherits without per-site props. initialPath\ndefaults to 'email'. Pass providersFirst={false} for legacy bitcoin-first order.",
          "is_bot": false,
          "headline": "auth-client@2.20.0: providersFirst on by default",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-23T01:14:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9fc120059c5ce8e5da5349baa569715c321d4587",
          "body": "cosign.ochk.io (cofounder matching, commercial product) joins the\nproduct tier of the ecosystem switcher + family-properties registry.",
          "is_bot": false,
          "headline": "design: add oc·cosign to the family switcher",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-22T19:36:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9470cb2b2cd511e568295aab8b53339b499eafde",
          "body": "…front door\n\nThe canonical ceremony leads with the BIP-322 wallet — the right default\nfor the family, the wrong one for ochk.io's public homepage, where a\nfirst-time visitor who's never held bitcoin bounces off a wallet prompt.\n\nprovidersFirst (opt-in, default off) promotes Google/GitHub above the\np\n[…]\nl and defaults the active tab to email, with the wallet path one tab\naway as 'bitcoin · self-custody'. Email/OAuth stays the bridge; the\nBitcoin address is still the canonical identity it resolves to.",
          "is_bot": false,
          "headline": "auth-client: providersFirst on OcSignIn for a non-Bitcoiner-friendly …",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-22T19:07:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "30a6828b6377f02bad1842e5307c3cf344d4ce6a",
          "body": "… window.prompt (0.4.1)\n\nThe \"paste signature\" wallet invoked getSigner -> signManual -> window.prompt — an\nunstyled, un-themed, mobile-hostile native dialog every consumer (chat, vault, me)\ninherited. Clicking it now opens an inline panel inside the component: the\ncanonical message in a read-only b\n[…]\npy button, a real <textarea>, and\nUse-signature / back controls. The prompt-based signManual stays as the\nprogrammatic (non-React) fallback in sign.ts; only the React component changed.\nNo API change.",
          "is_bot": false,
          "headline": "wallet-adapter: OcWalletButton manual path is an inline textarea, not…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-16T05:07:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8050a5e4e9ac9a85996b77e8ebdc6431bb6c7b5b",
          "body": "fleet.ochk.io is now a private, owner-gated product. Recategorize it from\n'product' to 'owner' in both family registries (FAMILY_PROPERTIES and the\nEcosystemSwitcher ENTRIES -> OWNER_ENTRIES) so it's hidden from the public\nfamily switcher and visible only to owners (is_owner JWT claim), like\nanalytics/bot/forge. docsHref now points at its own origin (no public docs).",
          "is_bot": false,
          "headline": "design: move oc·fleet to the owner-only switcher section",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-15T17:30:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "20b786da592393dd554e8ff4fe417d994e5525d7",
          "body": "…d theme in\n\nA centered hamburger in the middle of the header was wrong. OcPrimaryNav is\nnow desktop-inline-only; on mobile the nav + appearance live in a `☰` that\nOcAccountMenu renders to the LEFT of the identity chip, so the right cluster is\n`[☰][identity]`. The standalone appearance palette folds\n[…]\nmobile and console sites keep their desktop nav.\n\nAdds AppearanceControls (the mode+skin block) so any surface — the palette, the\naccount `☰`, a site's own Sheet drawer — can host appearance settings.",
          "is_bot": false,
          "headline": "design: move mobile nav into the account menu (left of identity), fol…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-12T02:27:06Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aa7cfd08caa3beacf1ef59b9dd18bf8a0c49d8a8",
          "body": "The ecosystem status strip was fully transparent, so it bled the hero/aurora\nbehind it and the loud uppercase right-side tags wrapped on phones. Give it a\nfaint skin-tinted translucent band (.oc-substrip) that carries the active skin's\nhue across light/dark, collapse it to heartbeat + product below \n[…]\nhows\ninline at md+ and collapses to one shared menu disclosure below that. The\nOcAccountMenu identity chip condenses to dot + chevron below sm so a long\ndid/display-name no longer eats a phone header.",
          "is_bot": false,
          "headline": "design: shade the sub-header strip + make header chrome mobile-correct",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-11T23:52:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b6227a27163122d340ac79815f44819d5db6437f",
          "body": "…t pinning\n\nOne browser, N roster accounts, each tab operating as its own one. A\ntab pins itself by holding its account's session JWT (sessionStorage)\nand presenting it as x-oc-tab-session — a credential verified exactly\nlike the cookie token, never a bare selector. Switching re-pins the\nswitching t\n[…]\nh provider hop (it\npreviously clamped to the embedding origin, stranding consumer-site\nusers on the ochk.io homepage after an OAuth add).\n\ndesign 0.15.0 surfaces a quiet '· this tab' hint when pinned.",
          "is_bot": false,
          "headline": "auth-core 2.5.0 + auth-client 2.18.0 + design 0.15.0 · per-tab accoun…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-11T14:48:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "c6c7715f1841766e992a888bba45ccba48381431",
          "body": "Optional `auth?: AuthSigner` on publishEvent/queryEvents — the caller passes a\nsigner for the kind-22242 challenge so the package stays dependency-free. On an\n`auth-required` relay's [\"AUTH\", challenge] frame, sign + send AUTH + re-send the\nEVENT/REQ; absent a signer the challenge is ignored (today'\n[…]\nrelay AUTH). NOT released — no version\nbump / no tag; the next nostr-core release picks it up. The client glue + an AUTH\nrelay to test against are the remaining gates (research/INSTITUTIONAL-PLAN.md).",
          "is_bot": false,
          "headline": "nostr-core: additive NIP-42 AUTH support (no release)",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-10T16:57:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3082458c17e9754bcd72122889681e2bc7a82cbb",
          "body": "…irror\n\nDrop periods shipped on me.ochk.io: integrator-scheduled payout\nwindows where covered events' user-share matures and vests as one\nbatch at a block-denominated boundary. SDK surface:\n\n- BillableEvent.drop (signed canonical v=4 stamp: window_id +\n  close_height_target)\n- DropCadence / DropSche\n[…]\nross − platform, rebate as exact remainder — the\n  oc.event.verify replay no longer reports false divergences on edge\n  values\n- IntegratorEventConfig.agent (AgentClassOverride) was missing\n  entirely",
          "is_bot": false,
          "headline": "feat(me-client): 0.22.0 — drop-period types + re-sync the canonical m…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-09T22:19:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b01621d345536a82676f3883650b122608d8831e",
          "body": "The .app-bar utility escalated gutters like .container (px-4 sm:px-6\nlg:px-8), but a full-bleed app shell pins a fixed-width 56px icon rail\nflush left — so the header logo drifted off the rail at every width\n(worst at desktop's 32px). Fix to a flat 18px gutter, which seats the\n20px logo mark exactly over the rail's glyph column (center 28px).",
          "is_bot": false,
          "headline": "design 0.14.1: fix OcAppBar full-variant gutter",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-06T01:42:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cc29a9f6e9a78586d0e2532b9ecc12d9eb8dda77",
          "body": "… utility\n\nAdds the app-surface counterpart to the constrained .container header: OcAppBar (chrome) mounts the same primitives (OcLogoDropdown/OcPrimaryNav/OcAccountMenu via start/center/end slots) in an edge-to-edge .app-bar row (gutters only, no max-width), so a full-bleed app shell aligns with the chrome above. Marketing/content pages keep .container unchanged. For chat /app and other full-screen app surfaces (analytics cockpit, forge console). Additive; purely opt-in.",
          "is_bot": false,
          "headline": "design 0.14.0 — OcAppBar: sanctioned full-bleed app header + .app-bar…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-05T23:06:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "caceaa10b078633cd9976e129ed1e26b02222dfd",
          "body": "OcPrimaryNav's active item shipped a 1px orange bottom stripe. Active is\nnow orange text only — restrained, matches the family taste. The three\nhand-rolled commercial navs (vault/fleet/me) drop the copy-pasted stripe\nin their own repos in lockstep.",
          "is_bot": false,
          "headline": "fix(primary-nav): text-only active affordance, drop the orange stripe",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-05T23:03:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3ebf7822ef293aef61d13ae2d9990af51b8442d2",
          "body": "…ive)\n\nverifyFederationDelegation / verifyFederationRevocation +\ncomputeFederationDescriptorId, conformant against FEDERATION.md vectors v18-v26.\nAdditive — v1 single-address path unchanged.",
          "is_bot": false,
          "headline": "agent-core@1.1.0: federation-principal verifier (OC Agent v1.2 normat…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-05T19:03:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dd2a8187c23d1d00d55375f572197a6d0c9b282a",
          "body": "FEDERATION.md + its v18-v26 vectors live on the oc-agent-protocol\nspec/federation-v1.2 DRAFT branch, not merged to main. CI clones spec main\n(no federation vectors) so the test hard-failed with ENOENT. Guard with\nexistsSync: run + pass where the draft fixtures exist (local branch checkout),\nskip cleanly where they don't (CI on main). The verifier itself is still\ntype-checked + built either way; conformance re-activates automatically when the\ndraft branch merges to main.",
          "is_bot": false,
          "headline": "agent-core: federation conformance test skips when draft vectors absent",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-05T18:57:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f875a5ffb781e9042c7be6cd5195b180cfc025b",
          "body": "The spec's federation vectors (v18-v26) were committed without a verifier, so\nagent-core's vector suite had 20 failing tests. This adds the missing v1.2\nverifier path, conformant against all of them.\n\nNew src/federation.ts — purely additive; the v1 single-address DelegationEnvelope\n+ verifyDelegatio\n[…]\n filter. Suite green: 82 passed, 0 failed.\n\nNOT published — no version bump or tag. Federation is a draft spec; ship the npm\nrelease on explicit go (it triggers the 24h Renovate fan-out to consumers).",
          "is_bot": false,
          "headline": "agent-core: federation-principal verifier (FEDERATION.md) — additive",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-05T18:52:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a30a164af2a8bffd9e54d3aaa4d35b77d3af7efa",
          "body": null,
          "is_bot": false,
          "headline": "design 0.13.0 — add oc·forge family slug",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-05T18:13:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "cf637f5fcf05b1e4a939e364eaa5b74bb4a7e848",
          "body": "Adds 'chat' to the EcosystemSlug union, the switcher ENTRIES, and FAMILY_PROPERTIES (chat.ochk.io, category product). Unblocks oc-chat-web scaffolding (slug:'chat' otherwise TS-errors and the family switcher omits chat). Tag design-v0.12.0 to publish; oc-chat-web pins ^0.12.0 directly at scaffold time.",
          "is_bot": false,
          "headline": "design 0.12.0 — add oc·chat family slug (#23)",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-06-05T17:31:52Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1a4f7a1601cc1ffae2c07668ab5853af21eb88cd",
          "body": "Cards/panels over the ambient <OcAurora/> were either opaque (solid boxes\nhiding it) or fully transparent. Add .oc-surface: fill = color-mix(--card,\ntransparent) so it recolours across every skin + mode, + backdrop-blur so the\naurora bleeds through subtly while text stays legible. Mode-tuned via\n--oc-surface-translucency / --oc-surface-blur. Outermost-panel-only; @supports\nfallback to near-opaque where backdrop-filter is unavailable.",
          "is_bot": false,
          "headline": "design: v0.11.0 — .oc-surface aurora-aware frosted translucent surface",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-05T16:27:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "582fc6d7f558eea3ef4a0da3b283d2d949057fba",
          "body": "…ausible)\n\nAdd an oc insights clause beside the existing Plausible disclosure in the\nprotocol + fleet privacy policies — first-party, cookieless, no cross-site\nidentity, IP hashed + immediately discarded, DNT/GPC honored. Plausible\ndisclosure unchanged (both run side by side). Wire the legal-v* release\ntrigger. Bump 0.2.0 → 0.2.1.",
          "is_bot": false,
          "headline": "feat(legal): disclose first-party oc insights analytics (alongside Pl…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-04T11:59:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "92213c60128a32d07d2a2de32b3e4483299b6283",
          "body": "Wire insights-client-v* tag → npm publish for @orangecheck/insights-client\n(no @orangecheck deps, so the generic install/build/publish path applies).",
          "is_bot": false,
          "headline": "ci(release): add insights-client publish trigger",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-04T06:27:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f6fcf2bf1d53a5510018116b3eca35bc13cce62",
          "body": "Lane 2 of oc insights (see research/INSIGHTS-PLAN.md): a server-side\nemit() API for first-party, protocol-aware events that run ALONGSIDE\nPlausible — BIP-322 success, Connect logins, settlements, attestations,\nvotes, pledges, agent delegations. Fire-and-forget and never throws into\nthe caller (an em\n[…]\n inert\nno-op when OC_INSIGHTS_INGEST_TOKEN is unset so call sites ship before\nthe collector exists. Ships the API first (invariant #6) before any\ninsights.ochk.io surface. CI matrix gains the package.",
          "is_bot": false,
          "headline": "feat(insights-client): new @orangecheck/insights-client package",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-04T05:54:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6172d5b5e7c656a70eb37c148fabdd8f61f6e582",
          "body": null,
          "is_bot": false,
          "headline": "renovate: track oc-bot-web (repo renamed from oc-bot)",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-04T03:28:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6dcbd1722955fd9c89ea2f210cb6567c2986a5b",
          "body": "oc-bot now ships @orangecheck/design as a first-class owner family\nproperty; enroll it so family publishes reach it like every other\nconsumer. Pairs with oc-bot/renovate.json.",
          "is_bot": false,
          "headline": "ci(renovate): add oc-bot to the fan-out repo list",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-03T05:54:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac47a43599a82a2562624f4d47e52f9903971e88",
          "body": "Registers bot.ochk.io as an owner-category family property, mirroring\noc·analytics. OcLogoDropdown + EcosystemSwitcher surface it only when\nshowOwnerEntries (account.isOwner) is set; non-owners never see it.\nAdds the 'bot' EcosystemSlug + an OwnerView story documenting the gate.",
          "is_bot": false,
          "headline": "feat(design): add oc·bot to owner-gated family switcher",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-03T05:47:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "96a33af287cd015c808e0066e34d6894be1ac2f7",
          "body": "…perms, not the window\n\nRenovate is 403 on GitHub commits/{sha}/statuses (can't read CI to auto-merge);\nthat's a RENOVATE_TOKEN scope issue, independent of the stability window. Restore\ndefaults; the design 0.9.1 fan-out resumes once the token gains commit-statuses\n+ checks read.",
          "is_bot": false,
          "headline": "chore(renovate): revert design fast-track — fan-out blocked by token …",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-02T18:33:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fab8128c784b51b44a3d67e8a0069bd7dd11f61a",
          "body": "The earlier 403s came from cranking concurrency to 25 (registry rate-limit).\nThis keeps prConcurrentLimit/prHourlyLimit at the default 5/10 and only waives\nthe 1-day window for @orangecheck/design. Reverted once the fan-out lands.",
          "is_bot": false,
          "headline": "chore(renovate): re-apply design 0.9.1 age bypass at default concurrency",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-02T18:21:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b59e840c4edea366f7950d460dc8f3f507c2979b",
          "body": "The design 0.9.1 accelerated fan-out was blocked by intermittent Renovate 403s\nin the branch-update step (registry-auth infra, independent of the change) —\neven CI-green branches didn't merge. Restoring the 1-day stability window +\ndefault concurrency; design 0.9.1 (with the switcher tooltip) reaches consumers\nvia the standard flow once the Renovate 403 is resolved.",
          "is_bot": false,
          "headline": "chore(renovate): revert temp fast-track + concurrency lifts",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-02T18:13:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9b617eef218f3c3d84b60955af996e9a6ef15d49",
          "body": "The header's title group lacked min-w-0, so the truncate on the title +\nsubtitle never engaged and long text spilled past the strip. Add min-w-0\nflex-1 to the title group and shrink-0 to the actions group.",
          "is_bot": false,
          "headline": "design: fix Card title/subtitle overflow (min-w-0 so truncate engages)",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-02T17:51:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d9d1737f506e1f7e23fb27887a5e2aeaf7100c5d",
          "body": "Paired with the design-only age bypass — push all consumer bump branches at\nonce. Reverted with the bypass once the rollout lands.",
          "is_bot": false,
          "headline": "chore(renovate): TEMP lift concurrency for the design 0.9.0 fan-out",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-02T17:45:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4640ecc7adfeee73cf3cd86e969cd9262e38efc0",
          "body": "Bypass the 1-day stability window for @orangecheck/design ONLY so the switcher\nhover-tooltip (already browser-verified across skins + touch) fans out now.\nGlobal window unchanged for every other package; reverted immediately after.",
          "is_bot": false,
          "headline": "chore(renovate): TEMP fast-track @orangecheck/design 0.9.0 rollout",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-02T17:35:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ed6faba4426058230e038ee91ab311213e9c7240",
          "body": "Adds a themed hover/focus <Tooltip> primitive (the system had none — only the\nclick-based HelpHint) on @radix-ui/react-popover: hover-intent + keyboard\nfocus, pointer-fine only (never on touch), force-closable, reduced-motion via\nthe family reset.\n\nWires it into OcLogoDropdown, replacing the native \n[…]\n\ntrigger + menu aria-labels. Click model unchanged. Verified across all four\nskins (light+dark): hover, keyboard focus, Escape, touch (no tip, menu is the\npath home), all 92 stories render error-free.",
          "is_bot": false,
          "headline": "design: v0.9.0 — Tooltip primitive + OcLogoDropdown hover tooltip",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-02T17:24:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fd9da34cfad26005398127daa98243ac0f94872b",
          "body": "The scheduled Renovate job failed (run 26809354691, 11s) on a ghcr.io 502\nBad Gateway while pulling renovate:latest — renovatebot/github-action runs\ndocker run with no retry, so any registry blip reds the check. Pre-pull the\nimage with 5× retry/backoff first; docker run then uses the local image. No\nbehavior change otherwise (still :latest). Node-20 deprecation on the action\n(forced to Node 24 by 2026-06-16) noted separately.",
          "is_bot": false,
          "headline": "ci(renovate): retry image pre-pull to survive transient ghcr.io 5xx",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-02T15:04:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "510209562dffc881d6b5b59fb829c83afe91c469",
          "body": "…ovider\n\nAdds the bitcoin-aurora background (a soft, theme-reactive mesh gradient that\nslowly undulates) as a first-class component + CSS that auto-ships via\nstyles.css. OcThemeProvider renders it by default with an `aurora` prop escape\nhatch (false / { intensity }). Recolours across light/dark + all four skins from\n--brand/--success/--info/--primary; pure CSS, transform-only, reduced-motion safe.",
          "is_bot": false,
          "headline": "design: v0.8.0 — OcAurora ambient background, default-on in OcThemePr…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-06-01T19:52:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f001b554cdeaf2ec4e67bc230a69635cbc7ec10f",
          "body": "Two small additions to the @orangecheck/design/format subpath so the\nsats↔USD pattern is fully family-shared rather than copied per\nconsumer. Additive only — every existing export still works exactly\nas it did at 0.7.5.\n\nsrc/format/index.ts\n  asOf(iso) → \"as of HH:MM\" provenance caption helper.\n  nu\n[…]\n oc-me-web: drops lib/utils satsToUsd duplicates + lib/price/\n    usePrice.ts; ~10 callers migrate to @orangecheck/design imports.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): asOf + useSpotPrice (0.7.6)",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-28T17:24:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cf3aadd592f8f86406240caa5631ce5e24ab1ceb",
          "body": "…rsion)\n\nPorts oc-me-web's more-evolved HelpHint into the package: `size` ('xs'|'sm')\n+ `tone` ('default'|'subtle'), click-stopPropagation (so a \"?\" inside a\nclickable row doesn't trigger the row), an arrow + max-w-xs popover. Default\nside now `top`. Lets me retire its local HelpHint (38 importers) to the\npackage. SectionHeader's `hint` slot still works (title/side/children).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): v0.7.5 — HelpHint gains size/tone (lifts me's richer ve…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-27T19:51:28Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b3ff9c5df966c5ae3f00e8e4f16b7ef91a7d1020",
          "body": "…tile\n\nStatBlock rendered a non-bold value while StatGrid's Tile (and StatCard, which\nwraps StatBlock) used `font-bold tabular-nums tracking-tight`. Unifies them so\nevery stat — StatBlock, StatCard, StatGrid — renders the same canonical bold\ntabular value. (Restores bold weight for fleet Stat→StatCard and me\nRecon→StatBlock converged on 0.7.2/0.7.3.)\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(design): v0.7.4 — StatBlock value matches canonical bold/tabular …",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-27T19:25:36Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "cac1bdc77d5af4c264055b744cc6f9a9774c4640",
          "body": "Chrome components (AccountMenu/Dashboard/Logo&Switcher/PrimaryNav/\nLayoutSubHeader) moved Composites/* → Chrome/*; data + bitcoin primitives\nnested under Primitives/Data/* and Primitives/Bitcoin. Storybook nav now\nmirrors /primitives · /composites · /chrome. (Stories are dev-only; no\npackage version change.)\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(design): align Storybook taxonomy to the 3 tiers",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-27T18:58:04Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "ed5754d87811f2501b58589db441b86d67155478",
          "body": "Adds `filled` (bg-{tone}/10) to the bordered StatusPill + makeStatusPill\noptions, for the at-a-glance filled-chip emphasis me's compliance/severity\npills use on dense operator dashboards. Additive; default unfilled.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): v0.7.3 — StatusPill bordered `filled` option",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-27T17:49:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d9476cfbe57f2deec0f84f2873d2e51c7c0028e6",
          "body": "The standalone counterpart to StatBlock (bare cell) and StatGrid (grid):\na single stat in a bordered bg-card frame, wrapping StatBlock. Closes the\ngap fleet (dashboard/Stat) and me (StatCell + fee/recon tiles) each hand-roll.\nAdditive; caret ^0.7.0 admits it on re-install.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): v0.7.2 — StatCard composite (bordered single-stat card)",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-27T17:35:18Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "7900f8ef852de34c91fe4a10d6788918b20c1f23",
          "body": "… variant option\n\nAdds the bordered/uppercase status-badge variant (border-{tone}/40 text-{tone})\nthat fleet (PledgeStatusPill), www (StateBadge), and me (compliance/severity)\neach hand-roll. `<StatusPill variant=\"bordered\" />` and\n`makeStatusPill(map, { variant: 'bordered' })`. Additive; `plain` stays default.\nUnblocks the Phase-3 deep-fork convergence of those bordered pills with no\nvisual regression.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): v0.7.1 — StatusPill `bordered` variant + makeStatusPill…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-27T16:20:10Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "bddb7bc259101d8924fbe3fade19c57b5e08c654",
          "body": "…gence components\n\nSingle design-system package with three dependency-honest tiers:\n  - /primitives (zero-dep atoms)\n  - /composites (generic, auth-free)  ← NEW tier\n  - /chrome      (auth/family-coupled) ← NEW tier\n  - /components remains as a back-compat alias re-exporting both new tiers.\n\nThis re\n[…]\nery new/changed component; type-check, tsup build, and\nbuild-storybook all green; all stories render headless with styles applied.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): v0.7.0 — fold composites+chrome into design, add conver…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-27T15:09:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8dbd0b0b4a3f4dcde7d5b1aabef2e39ed98b3954",
          "body": "Add [overflow-wrap:anywhere] to the ConfirmHost message body so long\nunbroken tokens (addresses, hashes, URLs) wrap inside the dialog instead\nof overflowing it.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(design): confirm-dialog message wraps long unbroken strings (0.6.1)",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-26T19:33:17Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2fe0f93e4f85c03d2f30c27fe9b04bdc7bcc4b25",
          "body": "…ves (0.6.0)\n\nCloses the one real coverage gap the UI/UX audit surfaced: the family used\nraw native <input type=checkbox> (~18 files), type=radio (~6), and role=switch\ncontrols — unstyled, inconsistent across skins, missing the focus-ring/aria\ntreatment every other primitive has. These are Radix-bac\n[…]\nlibrary — no react-hook-form conflict. Storybook:\nPrimitives/Controls. Sites adopt incrementally (replace raw natives as touched).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): add Checkbox + RadioGroup + Switch form-control primiti…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-26T19:20:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1f6a1c907665ce84bb2ba9e4960d6ce06cb4a023",
          "body": "…alid (0.5.3)\n\n- prefers-reduced-motion now near-zeros ALL animations/transitions family-wide\n  (Accordion/Sheet/Dialog/Select/tw-animate overlays + skin transitions), not\n  just the working indicator — WCAG 2.3.3. Keeps 0.01ms so *end events fire.\n- Textarea gains the same aria-invalid error stylin\n[…]\nton have.\n\nNon-breaking, no brand/visual change in default motion-on state. Flows to all\nconsumers in-range (^0.5.2) via Renovate.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): a11y polish — global reduced-motion + Textarea aria-inv…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-26T19:10:34Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "34920b7c3bfd5939f3c14c7f547d2f7d57568978",
          "body": "…ow skin (0.5.2)\n\ngetOcThemeInitScript installs window.__ocApplySkinChrome (single owner of the\nswap): captures the favicon's original SVG once, recolors #f97316 → the active\nskin's accent into a data: URI, and sets <meta name=theme-color>. OcThemeProvider\nre-invokes it on every skin change/cross-ta\n[…]\ne single source of truth, mirrored by oc-media-kit. Verified in\na browser: cookie=phosphor → favicon #55d671, theme-color #55d671.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): theme-aware browser chrome — favicon + theme-color foll…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-26T15:32:25Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "611bc83488adf1e40ffa42d34c899524a93ce8b2",
          "body": "Standard shadcn Sheet parts that were missing from the package — vault's\nEntryEditor (and any sheet with a footer/explicit close) needs them.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): add SheetClose + SheetFooter exports (0.5.1)",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-25T21:15:01Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "748388cae7628325c8ae4a8b6e0da288fee668a4",
          "body": "oc-vote-web uses <Badge variant=\"brand\"> (brand-soft tinted badge). Adding it as\na canonical Badge variant (bg-brand-soft text-brand border-brand-soft, all\nexisting --brand utilities) so vote converges without losing its brand badge.\nStory updated.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): add Badge `brand` variant (0.5.0) (#22)",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-25T17:57:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "a9c75ffd221a3afbb914960d68b4c910f84959f7",
          "body": "… (#21)\n\nSingle header dropdown consolidating BOTH appearance axes so every family site\ncarries exactly one control instead of two:\n  • mode  — light / dark / system (next-themes)\n  • theme — the registered skins (data-oc-theme, persisted .ochk.io)\n\nOne Palette icon → dropdown with a segmented light\n[…]\nparate ThemeToggle + OcThemePicker (both kept for standalone\nuse / mobile drawer). 73 stories, all browser-verified render+styled.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): OcAppearanceMenu — one control for mode + theme (0.4.0)…",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-25T15:27:02Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1c4ab69624a63982a4039169f2941449870dc626",
          "body": "…fill from deep dive) (#20)\n\nThe deep dive across me/vault/fleet/analytics showed the canonical set (extracted\nfrom simple oc-stamp-web) was missing whole categories the complex sites\nreimplement. Fills them, ported from the real implementations:\n\nData/dashboard tier: Card (terminal-frame, expand→Mo\n[…]\nge\naccent at 2.93 remains, by design). Fixed a real satsToUsd bug found by the\ngate (Intl min>max RangeError for amounts >= $100).\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): v0.3 — data/dashboard + Bitcoin-domain primitives (gap-…",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-25T15:14:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "4b331d71c42373d376918c94074f1ffbde49044c",
          "body": "… lightning/gold (0.2.0) (#19)\n\nTheme ethos review: midnight (indigo + Manrope + 0.625 rounded) and aurora\n(teal + soft elevation + 0.75 rounded) were generic SaaS palettes that violated\nthe OrangeCheck/cypherpunk ethos (\"hard borders, no soft shadows, not SaaS\").\nReplaced with two Bitcoin-meaningfu\n[…]\n midnight/aurora removed (no consumer used them;\nthe picker reads OC_THEMES dynamically and resolveTheme() falls back to default).\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design)!: Bitcoin-ethos theme set — replace midnight/aurora with…",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-25T14:31:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6cf13409da2906aef5037b9c40a17dc421139427",
          "body": "… gates (0.1.1) (#18)\n\nCompleteness/perfection review pass:\n- aurora light --primary darkened oklch .6→.5 so white button labels clear AA\n  (4.5:1, was 3.51) and the accent clears AA-large; ring matched. The other\n  alternate skins (midnight/phosphor) already pass AA on every pair, light+dark.\n- Add\n[…]\nthe existing production brand orange, unchanged here (parity is load-bearing);\nflagged for a separate brand decision, not altered.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(design): aurora AA contrast + ErrorBoundary story + contrast/page…",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-22T23:22:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c6013c5d7418e031660a66e11cb7576e4fc74be7",
          "body": "…amp script (#17)\n\nThe oc-stamp-web pilot surfaced a required step the recipe was missing:\n@orangecheck/design must be added to next.config transpilePackages (it\nre-exports @orangecheck/ui whose ESM uses a bare next/link import; without\ntranspiling, SSR page-data collection fails). Documented so the\n[…]\noesn't\nrepeat the failure. Also adds scripts/verify-stamp.mjs (the browser parity +\nskin-switch check used to validate the pilot).\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs(design): MIGRATION.md — require transpilePackages; add verify-st…",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-22T22:50:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "817129668dc6948b14a860e2c5056bcd8b63d6a5",
          "body": "- Elevation: set orangecheck --oc-shadow-* to EXACTLY Tailwind v4 stock values\n  so adopting @orangecheck/design is a pixel no-op for the default skin (verified\n  in-browser: default shadow-lg == stock; aurora stays elevated). Prevents a\n  subtle global shadow shift on every consumer at migration ti\n[…]\n docs-sync job (oc-docs/sdk/design) stays green.\n- Add MIGRATION.md: the mechanical, per-site, no-op-for-default migration recipe.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(design): zero-regression hardening + publish prerequisites (#16)",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-22T21:27:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f32731600b1400aabac8cbfe15da0daf6ff4a75c",
          "body": "… dimension (#15)\n\nExhaustive census across ALL component dirs (not just ui/) confirmed the full\nshared surface. Additions, ported verbatim from the canonical repos:\n  · PromptDialog (prompt()/PromptHost) — pairs with ConfirmDialog\n  · Modal — family-standard near-fullscreen titled modal\n  · Paginat\n[…]\nht): 56/56 render styled &\nerror-free; 4/4 distinct skin identities; elevation provably differs (aurora vs\ndefault) in both modes.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): complete the inventory + 4th theme (aurora) + elevation…",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-22T21:16:41Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6e92a218b63a6342285dcb0ca3444b171a4a2798",
          "body": "…browser verification (#14)\n\nCloses the comprehensiveness + multi-theme-depth gaps surfaced in review.\n\nPrimitives — extended to the full shared set used across the family (usage\ncensus over all web repos). Added, ported verbatim from the canonical sites:\nSheet, Dialog, ConfirmDialog (confirm()/Conf\n[…]\nright, scripts/verify-*.mjs): 50/50 stories render styled\n& error-free; radius + font + primary all change per skin in both modes.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): complete primitive set, 3rd theme, shape+type theming, …",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-22T20:48:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "79404a7b68b546e89aeb5f9991c52c2f6f518117",
          "body": "…heme matrix (#13)\n\nExpands the design.ochk.io showcase from 12 → 37 stories:\n\n- Primitives: Form (Input/Label/Textarea), Alert, Working, Theme Toggle —\n  joining the existing Button, Badge, Tokens.\n- Composites: SectionHeader, EmptyState, StatGrid, OcPrimaryNav, OcDashboardHub,\n  AppShell, OcLogoDr\n[…]\nlti-theme\n  proof. Global theme decorator can stand down (disableGlobalTheme) so light\n  panels aren't forced dark by the toolbar.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): full Storybook coverage — all primitives, composites, t…",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-22T20:06:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "53db8eb711054dfc4939bf39e9e80619b1798b7a",
          "body": "…m (#12)\n\nNew umbrella package @orangecheck/design (oc-packages/design):\n\n- Multi-theme token layer. Two orthogonal axes: mode (.dark, next-themes,\n  unchanged) × skin (data-oc-theme attribute). Current look ported byte-for-byte\n  as the `orangecheck` skin; `midnight` ships as a demonstrator. styles\n[…]\n+dts) green, type-check green, storybook build green. No consumer site\ntouched — migration is Phase 3+, gated behind a checkpoint.\n\nCo-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(design): scaffold @orangecheck/design — multi-theme design syste…",
          "author_name": "Wil",
          "author_login": "Xaxis",
          "committed_at": "2026-05-22T19:53:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8c923caa1a7d94d371722e5002421fb4cf3c6e85",
          "body": "…ubdomains\n\nThe multi-account switcher (roster/switch/leave) shipped in 2.17.1 + ui 0.15.x,\nbut on consumer subdomains the roster stayed empty: the provider read it from\nthe LOCAL /api/auth/me, which verifies the JWT but has no DB and so never\ncarries the roster (it's host state). Result: the switch\n[…]\ne local /me. Bumped refresh() deps to [cfg].\n\n+2 provider tests (host fallback populates; no host call when local roster present).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "patch(auth-client@2.17.2): source roster from auth host on consumer s…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-21T05:07:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7a96492a541bd2a3c4c8d9b11fa55fd70517c420",
          "body": "…uto-payouts\n\nme-client/src/subtypes.ts described the pledge_resolution billable event as\nfiring when \"an oc-pledge bonded commitment resolves (paid out, slashed,\nor refunded) on your surface\" — both \"slashed\" and \"paid out\" misrepresent\nPledge. Per oc-pledge-protocol/WHY.md H5 and H7, slashing is e\n[…]\ng fix; no API surface change. Not tagged for publish in\nthis commit — bump + tag separately if propagation to consumers is wanted.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(me-client): correct pledge_resolution subtype — no slashing, no a…",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-21T00:53:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ce0a82782cf2cb6dbf6c1fbd5b23a8c34734a24f",
          "body": "Fixes the visible 'dropdown flashes when I switch accounts' report.\nTwo coupled issues:\n\n1. IdentityPromoteSection used fetchedRef.current as a one-shot\n   guard — it fetched linked identities the FIRST time the popover\n   opened and never again. After a multi-account switch the section\n   was rende\n[…]\ns back to null so the section\n  returns null briefly · prevents the stale 1-option-vs-3-options\n  flash before the new data lands.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "patch(ui@0.15.2): refetch linked identities on account switch",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-20T22:00:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dd4f8d521e411fdede9fd249e82551d3f063bcf3",
          "body": "ui@0.15.1\n---------\n- Empty-roster bug: the 'leave this account' button rendered even\n  when there were no peers in the roster, producing a redundant\n  second sign-out alongside the parent menu's bottom 'sign out' row.\n  Gate the per-account leave button on roster.length > 0 so the\n  empty-roster pa\n[…]\no arguments.\n\nTotal auth-client tests: 34/34 passing.\n\nCompanion to oc-www c1cfe4a (host useAuth + roster.test.ts +\nOpenAPI spec).\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "patch(auth-client@2.17.1, ui@0.15.1): polish + tests for multi-account",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-20T20:02:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b8ec444c839bfd0d28128b380ed0afe06b2905a9",
          "body": "Frozen-lockfile install rejected the ui-v0.15.0 publish because\nyarn.lock pinned auth-client@2.13.0 but ui's package.json now\nrequires ^2.17.0 (the new peer with the multi-account surface).\nRegenerated via yarn install in oc-packages/ui.\n\nCo-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(ui): bump yarn.lock to @orangecheck/auth-client@2.17.0",
          "author_name": "Xaxis",
          "author_login": "Xaxis",
          "committed_at": "2026-05-20T17:42:14Z",
          "body_truncated": false,
          "is_coding_agent": true
        }
      ],
      "releases_count": 100,
      "commits_last_year": 309,
      "latest_release_at": "2026-07-20T18:30:23Z",
      "latest_release_tag": "design-v0.28.13",
      "releases_from_tags": false,
      "days_since_last_push": 4,
      "active_weeks_last_year": 13,
      "days_since_latest_release": 6,
      "mean_days_between_releases": 2
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": false,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "@orangecheck/ui",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "orangecheck",
            "ui",
            "react",
            "internal"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@orangecheck/ui",
          "is_deprecated": false,
          "latest_version": "0.15.2",
          "repository_url": "https://github.com/orangecheck/oc-packages",
          "versions_count": 24,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 142,
          "first_published_at": "2026-04-26T14:29:12.373000Z",
          "latest_published_at": "2026-05-20T22:01:26.102000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 67
        },
        {
          "name": "@orangecheck/cli",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "orangecheck",
            "bitcoin",
            "sybil-resistance",
            "bip322",
            "cli",
            "nostr"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@orangecheck/cli",
          "is_deprecated": false,
          "latest_version": "0.2.0",
          "repository_url": "https://github.com/orangecheck/oc-packages",
          "versions_count": 5,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 71,
          "first_published_at": "2026-04-22T14:13:53.066000Z",
          "latest_published_at": "2026-05-10T04:28:33.399000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 78
        },
        {
          "name": "@orangecheck/sdk",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "bitcoin",
            "sybil-resistance",
            "bip322",
            "nostr",
            "attestation",
            "anti-spam",
            "verification",
            "orangecheck"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@orangecheck/sdk",
          "is_deprecated": false,
          "latest_version": "1.3.0",
          "repository_url": "https://github.com/orangecheck/oc-packages",
          "versions_count": 10,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 236,
          "first_published_at": "2026-04-22T14:06:47.479000Z",
          "latest_published_at": "2026-05-18T13:10:42.630000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 69
        },
        {
          "name": "@orangecheck/gate",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "orangecheck",
            "bitcoin",
            "sybil-resistance",
            "middleware",
            "express",
            "nextjs",
            "fastify",
            "hono",
            "workers",
            "bip322",
            "nostr"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@orangecheck/gate",
          "is_deprecated": false,
          "latest_version": "0.1.3",
          "repository_url": "https://github.com/orangecheck/oc-packages",
          "versions_count": 4,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 67,
          "first_published_at": "2026-04-22T14:13:43.386000Z",
          "latest_published_at": "2026-04-22T18:28:09.734000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 95
        },
        {
          "name": "@orangecheck/legal",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "orangecheck",
            "legal",
            "terms",
            "privacy",
            "internal"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@orangecheck/legal",
          "is_deprecated": false,
          "latest_version": "0.2.1",
          "repository_url": "https://github.com/orangecheck/oc-packages",
          "versions_count": 4,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 218,
          "first_published_at": "2026-05-15T18:22:21.220000Z",
          "latest_published_at": "2026-06-04T12:00:04.509000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 52
        },
        {
          "name": "@orangecheck/react",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "orangecheck",
            "bitcoin",
            "sybil-resistance",
            "bip322",
            "nostr",
            "react",
            "components"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@orangecheck/react",
          "is_deprecated": false,
          "latest_version": "0.1.3",
          "repository_url": "https://github.com/orangecheck/oc-packages",
          "versions_count": 4,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 66,
          "first_published_at": "2026-04-22T14:14:03.886000Z",
          "latest_published_at": "2026-04-22T21:07:35.144000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 95
        },
        {
          "name": "@orangecheck/design",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "orangecheck",
            "design-system",
            "ui",
            "tokens",
            "themes",
            "react",
            "internal"
          ],
          "ecosystem": "npm",
          "matches_repo": true,
          "registry_url": "https://www.npmjs.com/package/@orangecheck/design",
          "is_deprecated": false,
          "latest_version": "0.28.13",
          "repository_url": "https://github.com/orangecheck/oc-packages",
          "versions_count": 55,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 5198,
          "first_published_at": "2026-05-22T21:28:03.774000Z",
          "latest_published_at": "2026-07-20T18:30:17.142000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 6
        },
        {
          "name": "orangecheck",
          "exists": true,
          "license": "MIT",
          "keywords": [
            "attestation",
            "bip322",
            "bitcoin",
            "nostr",
            "orangecheck",
            "sybil-resistance",
            "Development Status :: 4 - Beta",
            "Intended Audience :: Developers",
            "License :: OSI Approved :: MIT License",
            "Programming Language :: Python :: 3",
            "Programming Language :: Python :: 3.10",
            "Programming Language :: Python :: 3.11",
            "Programming Language :: Python :: 3.12",
            "Programming Language :: Python :: 3.13",
            "Programming Language :: Python :: 3.9",
            "Topic :: Internet :: WWW/HTTP",
            "Topic :: Security",
            "Typing :: Typed"
          ],
          "ecosystem": "pypi",
          "matches_repo": true,
          "registry_url": "https://pypi.org/project/orangecheck/",
          "is_deprecated": false,
          "latest_version": "1.0.0",
          "repository_url": "https://github.com/orangecheck/oc-packages",
          "versions_count": 8,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": "2026-04-22T14:19:03.838807Z",
          "latest_published_at": "2026-05-07T18:27:04.083532Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 80
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 4
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [
        "agent-anthropic/tsconfig.json",
        "agent-cli/tsconfig.json",
        "agent-core/tsconfig.json",
        "agent-langgraph/tsconfig.json",
        "agent-mcp/tsconfig.json",
        "agent-openai/tsconfig.json",
        "agent-signer/tsconfig.json",
        "agent-vercel/tsconfig.json",
        "airdrop-gate/tsconfig.json",
        "auth-client/tsconfig.json",
        "auth-core/tsconfig.json",
        "cli/tsconfig.json",
        "design/tsconfig.json",
        "gate/tsconfig.json",
        "insights-client/tsconfig.json",
        "legal/tsconfig.json",
        "lock-core/tsconfig.json",
        "lock-crypto/tsconfig.json",
        "lock-device/tsconfig.json",
        "me-client/tsconfig.json",
        "nostr-core/tsconfig.json",
        "pledge-core/tsconfig.json",
        "react/tsconfig.json",
        "relay-filter/tsconfig.json",
        "sdk-py/orangecheck/py.typed",
        "sdk/tsconfig.json",
        "stamp-cli/tsconfig.json",
        "stamp-core/tsconfig.json",
        "stamp-ots/tsconfig.json",
        "ui/tsconfig.json",
        "vault-cli/tsconfig.json",
        "vault-core/tsconfig.json",
        "vote-cli/tsconfig.json",
        "vote-core/tsconfig.json",
        "vote-react/tsconfig.json",
        "wallet-adapter/tsconfig.json",
        "webhook-verify/tsconfig.json"
      ],
      "toolchain_manifests": [],
      "largest_source_bytes": 56314,
      "source_files_sampled": 482,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "agent-anthropic/package.json",
        "agent-cli/package.json",
        "agent-core/package.json",
        "agent-langgraph/package.json",
        "agent-mcp/package.json",
        "agent-openai/package.json",
        "agent-signer/package.json",
        "agent-vercel/package.json",
        "airdrop-gate/package.json",
        "auth-client/package.json",
        "auth-core/package.json",
        "cli/package.json",
        "design/package.json",
        "gate/package.json",
        "insights-client/package.json",
        "legal/package.json",
        "lock-core/package.json",
        "lock-crypto/package.json",
        "lock-device/package.json",
        "me-client/package.json",
        "nostr-core/package.json",
        "package.json",
        "pledge-core/package.json",
        "react/package.json",
        "relay-filter/package.json",
        "sdk-py/pyproject.toml",
        "sdk/package.json",
        "stamp-cli/package.json",
        "stamp-core/package.json",
        "stamp-ots/package.json",
        "ui/package.json",
        "vault-cli/package.json",
        "vault-core/package.json",
        "vote-cli/package.json",
        "vote-core/package.json",
        "vote-react/package.json",
        "wallet-adapter/package.json",
        "webhook-verify/package.json"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "npm",
        "pypi"
      ],
      "dependencies": [
        {
          "name": "@noble/hashes",
          "manifest": "agent-anthropic/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/agent-core",
          "manifest": "agent-anthropic/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.3.0"
        },
        {
          "name": "@orangecheck/agent-signer",
          "manifest": "agent-anthropic/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "agent-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/agent-core",
          "manifest": "agent-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "bip322-js",
          "manifest": "agent-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "commander",
          "manifest": "agent-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.1.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "agent-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/stamp-core",
          "manifest": "agent-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.0.0"
        },
        {
          "name": "@orangecheck/lock-core",
          "manifest": "agent-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.0.1"
        },
        {
          "name": "@noble/hashes",
          "manifest": "agent-langgraph/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/agent-core",
          "manifest": "agent-langgraph/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.3.0"
        },
        {
          "name": "@orangecheck/agent-signer",
          "manifest": "agent-langgraph/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "agent-mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/agent-core",
          "manifest": "agent-mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "@orangecheck/agent-signer",
          "manifest": "agent-mcp/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "agent-openai/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/agent-core",
          "manifest": "agent-openai/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.3.0"
        },
        {
          "name": "@orangecheck/agent-signer",
          "manifest": "agent-openai/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "agent-signer/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/agent-core",
          "manifest": "agent-signer/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.3.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "agent-vercel/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/agent-core",
          "manifest": "agent-vercel/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.3.0"
        },
        {
          "name": "@orangecheck/agent-signer",
          "manifest": "agent-vercel/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "@orangecheck/sdk",
          "manifest": "airdrop-gate/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.3"
        },
        {
          "name": "@simplewebauthn/browser",
          "manifest": "auth-client/package.json",
          "ecosystem": "npm",
          "version_constraint": "^13.3.0"
        },
        {
          "name": "jose",
          "manifest": "auth-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.2.2"
        },
        {
          "name": "@orangecheck/me-client",
          "manifest": "cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.18.0"
        },
        {
          "name": "@orangecheck/sdk",
          "manifest": "cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.3"
        },
        {
          "name": "commander",
          "manifest": "cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.1.0"
        },
        {
          "name": "@radix-ui/react-accordion",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.2.12"
        },
        {
          "name": "@radix-ui/react-checkbox",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1"
        },
        {
          "name": "@radix-ui/react-dialog",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.15"
        },
        {
          "name": "@radix-ui/react-label",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.7"
        },
        {
          "name": "@radix-ui/react-popover",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.15"
        },
        {
          "name": "@radix-ui/react-radio-group",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1"
        },
        {
          "name": "@radix-ui/react-select",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.2.6"
        },
        {
          "name": "@radix-ui/react-separator",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.7"
        },
        {
          "name": "@radix-ui/react-slot",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.2.3"
        },
        {
          "name": "@radix-ui/react-switch",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1"
        },
        {
          "name": "@radix-ui/react-tabs",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.3"
        },
        {
          "name": "class-variance-authority",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.7.1"
        },
        {
          "name": "clsx",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.1"
        },
        {
          "name": "qrcode",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.4"
        },
        {
          "name": "sonner",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.7"
        },
        {
          "name": "tailwind-merge",
          "manifest": "design/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.3.1"
        },
        {
          "name": "@orangecheck/sdk",
          "manifest": "gate/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.4"
        },
        {
          "name": "@vercel/functions",
          "manifest": "insights-client/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.7.3"
        },
        {
          "name": "@orangecheck/lock-crypto",
          "manifest": "lock-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "@noble/ciphers",
          "manifest": "lock-crypto/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.3.0"
        },
        {
          "name": "@noble/curves",
          "manifest": "lock-crypto/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "lock-crypto/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@noble/curves",
          "manifest": "lock-device/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.0"
        },
        {
          "name": "@orangecheck/lock-crypto",
          "manifest": "lock-device/package.json",
          "ecosystem": "npm",
          "version_constraint": "file:../lock-crypto"
        },
        {
          "name": "@orangecheck/auth-core",
          "manifest": "me-client/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.0.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "pledge-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/sdk",
          "manifest": "react/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.3"
        },
        {
          "name": "@orangecheck/sdk",
          "manifest": "relay-filter/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.3"
        },
        {
          "name": "httpx",
          "manifest": "sdk-py/pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=0.25"
        },
        {
          "name": "@bitcoinerlab/secp256k1",
          "manifest": "sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.1"
        },
        {
          "name": "@noble/curves",
          "manifest": "sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.2.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@scure/base",
          "manifest": "sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.1.9"
        },
        {
          "name": "bip322-js",
          "manifest": "sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "bitcoinjs-message",
          "manifest": "sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.2.0"
        },
        {
          "name": "buffer",
          "manifest": "sdk/package.json",
          "ecosystem": "npm",
          "version_constraint": "^6.0.3"
        },
        {
          "name": "@orangecheck/stamp-core",
          "manifest": "stamp-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.2"
        },
        {
          "name": "@orangecheck/stamp-ots",
          "manifest": "stamp-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.1"
        },
        {
          "name": "bip322-js",
          "manifest": "stamp-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "commander",
          "manifest": "stamp-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.1.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "stamp-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/stamp-core",
          "manifest": "stamp-ots/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.2"
        },
        {
          "name": "@orangecheck/vault-core",
          "manifest": "vault-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.2.0"
        },
        {
          "name": "commander",
          "manifest": "vault-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.1.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "vault-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/lock-crypto",
          "manifest": "vault-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "@noble/curves",
          "manifest": "vote-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "vote-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        },
        {
          "name": "@orangecheck/vote-core",
          "manifest": "vote-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.1"
        },
        {
          "name": "@orangecheck/lock-core",
          "manifest": "vote-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "@orangecheck/lock-crypto",
          "manifest": "vote-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^0.1.0"
        },
        {
          "name": "bip322-js",
          "manifest": "vote-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^3.0.0"
        },
        {
          "name": "commander",
          "manifest": "vote-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.1.0"
        },
        {
          "name": "ws",
          "manifest": "vote-cli/package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.18.0"
        },
        {
          "name": "@noble/hashes",
          "manifest": "vote-core/package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.5.0"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 3,
        "merged_prs": 19,
        "open_issues": 1,
        "closed_ratio": 0,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "Xaxis",
          "commits": 309,
          "avatar_url": "https://avatars.githubusercontent.com/u/396863?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "docs-drift.yml",
        "docs-sync-manual.yml",
        "packages.yml",
        "python.yml",
        "release.yml",
        "renovate.yml"
      ],
      "has_docs_dir": false,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "yarn.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 10,
            "reason": "update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 0,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "47 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "2238e09092ca384e98d417e2ce4a668259611619",
        "ran_at": "2026-07-27T09:20:45Z",
        "aggregate_score": 4.2,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-27T09:14:54Z",
      "oldest_open_prs": [
        {
          "number": 1,
          "created_at": "2026-04-30T16:44:47Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 2,
          "created_at": "2026-04-30T16:52:02Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 7,
          "created_at": "2026-04-30T19:46:39Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-06-05T17:31:52Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 11,
          "created_at": "2026-05-20T14:30:24Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/orangecheck/oc-packages",
    "host": "github.com",
    "name": "oc-packages",
    "owner": "orangecheck"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 55,
      "inputs": {
        "security": 42,
        "vitality": 84,
        "community": 34,
        "governance": 44,
        "engineering": 66
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 84,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 73,
            "inputs": {
              "commits_last_year": 309,
              "human_commit_share": 1,
              "days_since_last_push": 4,
              "active_weeks_last_year": 13
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 4 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 4
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "13/52 weeks with commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 13
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "309 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 309
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 100,
              "latest_release_tag": "design-v0.28.13",
              "releases_from_tags": false,
              "days_since_latest_release": 6,
              "mean_days_between_releases": 2
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "100 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 100
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 6 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~2 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 2
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 34,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "moderate",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 50,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": false,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 63,
            "inputs": {
              "packages": [
                "@orangecheck/ui",
                "@orangecheck/cli",
                "@orangecheck/sdk",
                "@orangecheck/gate",
                "@orangecheck/legal",
                "@orangecheck/react",
                "@orangecheck/design",
                "orangecheck"
              ],
              "dependents": null,
              "ecosystems": "npm, pypi",
              "total_downloads": null,
              "monthly_downloads": 5998
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "5,998 downloads/month across npm, pypi",
                "points": 50.4,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 5998,
                      "ecosystems": "npm, pypi"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 44,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "at_risk",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 38,
            "inputs": {
              "merged_prs": 19,
              "open_issues": 1,
              "closed_issues": 0,
              "issue_closed_ratio": 0,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "0% of issues closed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 0
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "19/19 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 19,
                      "decided": 19
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "at_risk",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 46,
            "inputs": {
              "followers": 3,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "orangecheck",
              "public_repos": 19,
              "account_age_days": 456
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "3 followers of orangecheck",
                "points": 4.3,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 3,
                      "login": "orangecheck"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "19 public repos, account ~1 yr old",
                "points": 12,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 19
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 1
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "excellent",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "@orangecheck/ui",
                "@orangecheck/cli",
                "@orangecheck/sdk",
                "@orangecheck/gate",
                "@orangecheck/legal",
                "@orangecheck/react",
                "@orangecheck/design",
                "orangecheck"
              ],
              "ecosystems": "npm, pypi",
              "any_deprecated": false,
              "min_days_since_publish": 6
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "8 package(s) on npm, pypi",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 8,
                      "ecosystems": "npm, pypi"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 6 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 6
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "55 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 55
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 66,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "moderate",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 60,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "6 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [
                "bip322",
                "bitcoin",
                "express",
                "middleware",
                "nextjs",
                "nostr",
                "python",
                "sdk",
                "sybil-resistance",
                "typescript"
              ],
              "has_wiki": true,
              "homepage": "https://ochk.io",
              "has_readme": true,
              "has_docs_dir": false,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://ochk.io",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "10 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 10
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 42,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 42,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 16,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 2,
              "scorecard_aggregate": 4.2
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "update tool detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "47 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 57,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.95,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "95 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 95,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 53,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "yarn.lock"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [
                "agent-anthropic/tsconfig.json",
                "agent-cli/tsconfig.json",
                "agent-core/tsconfig.json",
                "agent-langgraph/tsconfig.json",
                "agent-mcp/tsconfig.json",
                "agent-openai/tsconfig.json",
                "agent-signer/tsconfig.json",
                "agent-vercel/tsconfig.json",
                "airdrop-gate/tsconfig.json",
                "auth-client/tsconfig.json",
                "auth-core/tsconfig.json",
                "cli/tsconfig.json",
                "design/tsconfig.json",
                "gate/tsconfig.json",
                "insights-client/tsconfig.json",
                "legal/tsconfig.json",
                "lock-core/tsconfig.json",
                "lock-crypto/tsconfig.json",
                "lock-device/tsconfig.json",
                "me-client/tsconfig.json",
                "nostr-core/tsconfig.json",
                "pledge-core/tsconfig.json",
                "react/tsconfig.json",
                "relay-filter/tsconfig.json",
                "sdk-py/orangecheck/py.typed",
                "sdk/tsconfig.json",
                "stamp-cli/tsconfig.json",
                "stamp-core/tsconfig.json",
                "stamp-ots/tsconfig.json",
                "ui/tsconfig.json",
                "vault-cli/tsconfig.json",
                "vault-core/tsconfig.json",
                "vote-cli/tsconfig.json",
                "vote-core/tsconfig.json",
                "vote-react/tsconfig.json",
                "wallet-adapter/tsconfig.json",
                "webhook-verify/tsconfig.json"
              ],
              "agent_commit_share": 0.29,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "agent-anthropic/tsconfig.json, agent-cli/tsconfig.json, agent-core/tsconfig.json, agent-langgraph/tsconfig.json, agent-mcp/tsconfig.json, agent-openai/tsconfig.json, agent-signer/tsconfig.json, agent-vercel/tsconfig.json, airdrop-gate/tsconfig.json, auth-client/tsconfig.json, auth-core/tsconfig.json, cli/tsconfig.json, design/tsconfig.json, gate/tsconfig.json, insights-client/tsconfig.json, legal/tsconfig.json, lock-core/tsconfig.json, lock-crypto/tsconfig.json, lock-device/tsconfig.json, me-client/tsconfig.json, nostr-core/tsconfig.json, pledge-core/tsconfig.json, react/tsconfig.json, relay-filter/tsconfig.json, sdk-py/orangecheck/py.typed, sdk/tsconfig.json, stamp-cli/tsconfig.json, stamp-core/tsconfig.json, stamp-ots/tsconfig.json, ui/tsconfig.json, vault-cli/tsconfig.json, vault-core/tsconfig.json, vote-cli/tsconfig.json, vote-core/tsconfig.json, vote-react/tsconfig.json, wallet-adapter/tsconfig.json, webhook-verify/tsconfig.json",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "agent-anthropic/tsconfig.json, agent-cli/tsconfig.json, agent-core/tsconfig.json, agent-langgraph/tsconfig.json, agent-mcp/tsconfig.json, agent-openai/tsconfig.json, agent-signer/tsconfig.json, agent-vercel/tsconfig.json, airdrop-gate/tsconfig.json, auth-client/tsconfig.json, auth-core/tsconfig.json, cli/tsconfig.json, design/tsconfig.json, gate/tsconfig.json, insights-client/tsconfig.json, legal/tsconfig.json, lock-core/tsconfig.json, lock-crypto/tsconfig.json, lock-device/tsconfig.json, me-client/tsconfig.json, nostr-core/tsconfig.json, pledge-core/tsconfig.json, react/tsconfig.json, relay-filter/tsconfig.json, sdk-py/orangecheck/py.typed, sdk/tsconfig.json, stamp-cli/tsconfig.json, stamp-core/tsconfig.json, stamp-ots/tsconfig.json, ui/tsconfig.json, vault-cli/tsconfig.json, vault-core/tsconfig.json, vote-cli/tsconfig.json, vote-core/tsconfig.json, vote-react/tsconfig.json, wallet-adapter/tsconfig.json, webhook-verify/tsconfig.json"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "29 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 29,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "TypeScript",
              "largest_source_bytes": 56314,
              "source_files_sampled": 482,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "TypeScript (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "TypeScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/482 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 482,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-27T09:20:52.626244Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/o/orangecheck/oc-packages.svg",
  "full_name": "orangecheck/oc-packages",
  "license_state": "standard",
  "license_spdx": "MIT"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计npm, PyPI.