原始 JSON 报告 机器可读
{
"data": {
"repo": {
"topics": [],
"is_fork": false,
"size_kb": 34393,
"has_wiki": true,
"homepage": null,
"languages": {
"Go": 3635740,
"CSS": 11645,
"Vue": 209368,
"HTML": 287,
"Makefile": 3778,
"JavaScript": 118390,
"TypeScript": 599
},
"pushed_at": "2026-07-21T08:52:50Z",
"created_at": "2026-04-22T09:20:17Z",
"owner_type": "User",
"updated_at": "2026-07-21T08:53:09Z",
"description": "A thin Go framework for REST, GraphQL, WebSocket — into a central registry, traces each request through an in-memory event bus, and exposes the lot at /__nexus for a Vue dashboard that renders live service topology, endpoint catalog, and request traces.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "Go",
"significant_languages": [
"Go"
]
},
"owner": {
"blog": null,
"name": null,
"type": "User",
"login": "paulmanoni",
"company": null,
"location": null,
"followers": 3,
"avatar_url": "https://avatars.githubusercontent.com/u/63920907?v=4",
"created_at": "2020-04-18T16:32:54Z",
"is_verified": null,
"public_repos": 13,
"account_age_days": 2285
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": true,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v1.20.4",
"kind": "patch",
"published_at": "2026-06-19T18:53:44Z"
},
{
"tag": "v1.20.3",
"kind": "patch",
"published_at": "2026-06-19T06:02:44Z"
},
{
"tag": "v1.20.2",
"kind": "patch",
"published_at": "2026-06-19T05:49:12Z"
},
{
"tag": "v1.20.1",
"kind": "patch",
"published_at": "2026-06-19T05:39:42Z"
},
{
"tag": "v1.18.1",
"kind": "patch",
"published_at": "2026-06-17T21:04:52Z"
},
{
"tag": "v1.13.0",
"kind": "minor",
"published_at": "2026-06-11T09:44:58Z"
},
{
"tag": "v1.1.1",
"kind": "patch",
"published_at": "2026-05-28T21:45:56Z"
},
{
"tag": "v1.1.0",
"kind": "minor",
"published_at": "2026-05-28T21:41:51Z"
},
{
"tag": "v1.0.0",
"kind": "major",
"published_at": "2026-05-26T12:52:44Z"
},
{
"tag": "v0.97.1",
"kind": "patch",
"published_at": "2026-05-26T12:04:29Z"
},
{
"tag": "v0.97.0",
"kind": "minor",
"published_at": "2026-05-26T11:48:35Z"
},
{
"tag": "v0.96.0",
"kind": "minor",
"published_at": "2026-05-26T10:58:29Z"
},
{
"tag": "v0.95.0",
"kind": "minor",
"published_at": "2026-05-26T10:45:00Z"
},
{
"tag": "v0.94.0",
"kind": "minor",
"published_at": "2026-05-26T10:36:03Z"
},
{
"tag": "v0.93.0",
"kind": "minor",
"published_at": "2026-05-26T10:29:05Z"
},
{
"tag": "v0.92.0",
"kind": "minor",
"published_at": "2026-05-26T09:42:18Z"
},
{
"tag": "v0.91.0",
"kind": "minor",
"published_at": "2026-05-26T08:30:23Z"
},
{
"tag": "v0.90.2",
"kind": "patch",
"published_at": "2026-05-26T07:12:42Z"
},
{
"tag": "v0.90.1",
"kind": "patch",
"published_at": "2026-05-26T07:06:49Z"
},
{
"tag": "v0.90.0",
"kind": "minor",
"published_at": "2026-05-26T06:57:39Z"
},
{
"tag": "v0.89.0",
"kind": "minor",
"published_at": "2026-05-25T15:14:00Z"
},
{
"tag": "v0.88.1",
"kind": "patch",
"published_at": "2026-05-25T14:34:23Z"
},
{
"tag": "v0.88.0",
"kind": "minor",
"published_at": "2026-05-25T09:48:18Z"
},
{
"tag": "v0.87.0",
"kind": "minor",
"published_at": "2026-05-25T08:32:16Z"
},
{
"tag": "v0.86.1",
"kind": "patch",
"published_at": "2026-05-25T07:25:09Z"
},
{
"tag": "v0.86.0",
"kind": "minor",
"published_at": "2026-05-25T01:07:30Z"
},
{
"tag": "v0.85.0",
"kind": "minor",
"published_at": "2026-05-25T00:35:41Z"
},
{
"tag": "v0.84.6",
"kind": "patch",
"published_at": "2026-05-24T23:28:58Z"
},
{
"tag": "v0.84.4",
"kind": "patch",
"published_at": "2026-05-24T08:08:33Z"
},
{
"tag": "v0.84.3",
"kind": "patch",
"published_at": "2026-05-24T05:52:02Z"
},
{
"tag": "v0.83.0",
"kind": "minor",
"published_at": "2026-05-23T20:40:42Z"
},
{
"tag": "v0.82.0",
"kind": "minor",
"published_at": "2026-05-23T19:41:51Z"
},
{
"tag": "v0.81.1",
"kind": "patch",
"published_at": "2026-05-23T07:31:05Z"
},
{
"tag": "v0.81.0",
"kind": "minor",
"published_at": "2026-05-23T07:30:09Z"
},
{
"tag": "v0.80.0",
"kind": "minor",
"published_at": "2026-05-22T08:30:31Z"
},
{
"tag": "v0.79.1",
"kind": "patch",
"published_at": "2026-05-21T13:24:11Z"
},
{
"tag": "v0.79.0",
"kind": "minor",
"published_at": "2026-05-21T13:16:05Z"
},
{
"tag": "v0.78.0",
"kind": "minor",
"published_at": "2026-05-21T03:25:18Z"
},
{
"tag": "v0.77.0",
"kind": "minor",
"published_at": "2026-05-21T03:00:11Z"
},
{
"tag": "v0.76.2",
"kind": "patch",
"published_at": "2026-05-20T22:05:50Z"
},
{
"tag": "v0.76.1",
"kind": "patch",
"published_at": "2026-05-20T21:57:42Z"
},
{
"tag": "v0.76.0",
"kind": "minor",
"published_at": "2026-05-20T21:45:51Z"
},
{
"tag": "v0.75.8",
"kind": "patch",
"published_at": "2026-05-20T20:09:15Z"
},
{
"tag": "v0.75.7",
"kind": "patch",
"published_at": "2026-05-20T16:59:40Z"
},
{
"tag": "v0.75.6",
"kind": "patch",
"published_at": "2026-05-20T16:18:55Z"
},
{
"tag": "v0.75.5",
"kind": "patch",
"published_at": "2026-05-20T15:44:11Z"
},
{
"tag": "v0.75.4",
"kind": "patch",
"published_at": "2026-05-20T15:39:42Z"
},
{
"tag": "v0.75.3",
"kind": "patch",
"published_at": "2026-05-20T15:38:55Z"
},
{
"tag": "v0.75.2",
"kind": "patch",
"published_at": "2026-05-20T15:31:14Z"
},
{
"tag": "v0.75.1",
"kind": "patch",
"published_at": "2026-05-20T14:55:02Z"
},
{
"tag": "v0.75.0",
"kind": "minor",
"published_at": "2026-05-20T14:24:26Z"
},
{
"tag": "v0.74.1",
"kind": "patch",
"published_at": "2026-05-20T12:34:29Z"
},
{
"tag": "v0.74.0",
"kind": "minor",
"published_at": "2026-05-20T11:32:37Z"
},
{
"tag": "v0.74.0-rc1",
"kind": "prerelease",
"published_at": "2026-05-20T09:46:50Z"
},
{
"tag": "v0.73.4",
"kind": "patch",
"published_at": "2026-05-20T09:08:38Z"
},
{
"tag": "v0.73.2",
"kind": "patch",
"published_at": "2026-05-20T07:09:03Z"
},
{
"tag": "v0.73.0",
"kind": "minor",
"published_at": "2026-05-20T06:36:33Z"
},
{
"tag": "v0.72.0",
"kind": "minor",
"published_at": "2026-05-20T06:18:10Z"
},
{
"tag": "v0.62.0",
"kind": "minor",
"published_at": "2026-05-15T06:31:30Z"
},
{
"tag": "v0.61.0",
"kind": "minor",
"published_at": "2026-05-15T05:12:22Z"
},
{
"tag": "v0.60.1",
"kind": "patch",
"published_at": "2026-05-15T04:56:15Z"
},
{
"tag": "v0.60.0",
"kind": "minor",
"published_at": "2026-05-14T22:47:56Z"
},
{
"tag": "v0.59.0",
"kind": "minor",
"published_at": "2026-05-14T20:43:10Z"
}
],
"recent_commits": [
{
"oid": "cca02623cece32bce88a0bb211ab2e6bfc0c7d3b",
"body": null,
"is_bot": false,
"headline": "chore(release): 1.34.0",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-21T08:52:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "878de115aa6590925234cbfe16f039a5c11bb1c0",
"body": "…remove tour\n\nAdded\n- extension/proxy: reverse-proxy legacy routes to an upstream and register them\n on the dashboard tagged as proxies (registry.ProxyTag), clustered in their own\n module. Auto-yield: a route with a native handler at the same method+path is\n skipped, so migrating is purely additi\n[…]\n.Describe -> auth.InspectExtractor (alias kept); internal gin* helpers\n renamed to authMiddleware / corsHandler post router-seam.\n\nRemoved\n- extension/tour (self-contained; nothing else imported it).",
"is_bot": false,
"headline": "feat: extension/proxy strangler-fig bridge, API-consistency cleanup, …",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-21T08:52:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6fd1b7e2578812da872a49e414d7c6668bce7ae8",
"body": null,
"is_bot": false,
"headline": "chore(release): 1.33.3",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-17T19:08:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7b2e8218bd29f9b96f9acd34efff159f8d7862bb",
"body": "viteless/internal/store used golang.org/x/sys/unix unconditionally,\nbreaking 'go build' of any nexus app on Windows (undefined: unix.LOCK_SH).\nviteless v0.2.1 splits the store cache lock behind a platform seam\n(flock on unix, LockFileEx on Windows). Dependency bump only.",
"is_bot": false,
"headline": "fix(build): bump viteless to v0.2.1 for Windows go build",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-17T19:08:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "000226c1fec1f6b47432028d6d060b737ff89dea",
"body": null,
"is_bot": false,
"headline": "chore(release): 1.33.2",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-09T05:27:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "020779f333cc8eeb235c40cd1ae843077e14a2e4",
"body": "WS handlers ran in the connection read-loop goroutine with no recover, so a\npanic (nil map write, slice OOB) crashed the whole process while the same bug\nin REST was caught. callWSHandler now recovers → *trace.StackError → finish(500)\n+ bus event + error envelope + stderr, and the read loop survives\n[…]\nhe bare config auto-load panics with nexus: context, adds ERRORS.md\n(the three-layer error model + recover invariant), and TestUserHandlerPanics-\nAreRecovered enforcing the invariant across REST + WS.",
"is_bot": false,
"headline": "fix(ws): recover panics in WS handlers; feat: dev boot self-check",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-09T05:27:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9a3e00b5072fa5a84ea9ef4e47f2601a5fc4af96",
"body": null,
"is_bot": false,
"headline": "chore(release): 1.33.1",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-08T16:44:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b332f9a4b4010c0f0c90e42fdcd680372e65520b",
"body": "…gs outside dev\n\nclient: the SDK auto-dump merged tsconfig.json with a strict encoding/json\nparse, which failed on comments or trailing commas (both valid JSONC that tsc\naccepts). Strip // and /* */ comments and trailing commas before decoding;\nstring literals are preserved and the rewritten file st\n[…]\n are quiet by default.\nOpt out per connection via [databases.<name>] log = \"...\" (silent/false/off,\nerror, warn/true/on, info/all) or db.Config.LogLevel. Record-not-found no\nlonger logged as an error.",
"is_bot": false,
"headline": "fix(client): parse tsconfig/jsconfig as JSONC; feat(db): quiet SQL lo…",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-08T16:44:13Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "51fc903d5463acbd910fab511a954bfbd51d558e",
"body": null,
"is_bot": false,
"headline": "chore(release): 1.33.0",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-08T16:26:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5ebd77e1b307daa7a474b484848c6db2a881ab42",
"body": "…s + oauth2.Backend\n\nAdd auth.Config.Endpoints{Login,Logout,Token,Revoke} so auth.Module mounts its\nown HTTP front doors from the backend's capabilities, and extend the cohesive\nbackend with three optional token-server capabilities: Issue, RevokeToken, and\nTokenHandler. oauth2.Backend returns a read\n[…]\nder/atomic-pointer bridge). Deprecate auth.LoginEndpoint/LogoutEndpoint in\nfavor of Config.Endpoints; both keep working as thin wrappers.\n\nAll additive: the Config.Endpoints zero value mounts nothing.",
"is_bot": false,
"headline": "feat(auth): fold OAuth2 into a single auth.Module via Config.Endpoint…",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-08T16:23:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b0f9513dc622837d12d0d5df47e8412c53e9b884",
"body": null,
"is_bot": false,
"headline": "chore(release): 1.32.3",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-07T20:28:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b336b363f82f4612a944d8b2de19ccd88af5f4d5",
"body": "…oker\n\nWithIssuer/WithRevoker are static callbacks set at module-build time, so they\ncan't reach DI-provided services (e.g. an OAuth2 token server). Export the\nhandler builders LoginEndpoint/LogoutEndpoint install so an app can wire them\ninside its own AsRestHandler factory — where deps ARE injected — without a\npackage global. The Endpoint helpers now delegate to them; behavior unchanged.",
"is_bot": false,
"headline": "feat(auth): export LoginHandler/LogoutHandler for DI-wired issuer/rev…",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-07T20:28:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "918ae4c332df8c54e559eefa6176e6b90f3c9730",
"body": null,
"is_bot": false,
"headline": "chore(release): 1.32.2",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-07T20:20:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "784f5b505c13b132f70443c3a59a7e482496b92e",
"body": "Registers a POST logout endpoint (default /auth/logout) that extracts the\npresented token, drops it from the identity cache (Manager.Invalidate), and —\nwith WithRevoker(func(ctx, token) error) — invalidates it in the app's own\nstore (OAuth2 server, DB session). Options: LogoutAt(path), LogoutExtractor(e)\n(default Bearer(); use Cookie(...) for cookie sessions). Public and idempotent:\nauthenticates by the token it revokes, always 200 {\"ok\": true}, reveals\nnothing about whether a session existed.",
"is_bot": false,
"headline": "feat(auth): LogoutEndpoint — companion to LoginEndpoint",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-07T20:20:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "47c1f13604990f89297c34815be098d3652b24a0",
"body": null,
"is_bot": false,
"headline": "chore(release): 1.32.1",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-07T20:18:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d8080cf2ed1e7713abf4e51ad1602979947bab9a",
"body": "A one-line helper that registers a POST login endpoint (default /auth/login)\nauthenticating a {username,password} body through the login-capable\nConfig.Backend, so apps don't hand-write a handler to reach Manager.Login.\nOptions: LoginAt(path) and WithIssuer(func(ctx, *Identity) (any, error)) to\nshap\n[…]\nn); without an issuer it returns\n{\"identity\": ...}. Public (you can't require a token to obtain one), 401 on\ninvalid credentials with no user enumeration, needs a Config.Backend that\nimplements Login.",
"is_bot": false,
"headline": "feat(auth): LoginEndpoint — HTTP front door for Manager.Login",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-07T20:18:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8e338a447c61a617324a0970cadfde765a43b417",
"body": null,
"is_bot": false,
"headline": "chore(release): 1.32.0",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-07T19:49:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "10be1f03f23906520e7b9299de169683dadf1070",
"body": "…orize plug\n\nA static Scheme.Resolve can't see DI dependencies, so apps needing a resolver\nbound to app services (a DB, a token server) resorted to package globals + a\nbackfill Invoke, with authorization split into a separate Authorization block.\nConfig.Backend collapses this into one DI-constructed\n[…]\nprior behavior; Scheme.Resolve, Config.Authorization, Authenticate,\nand ModelBackend are unchanged. UseBackend returns the app's concrete type,\ndistinct from the existing auth.Backend login interface.",
"is_bot": false,
"headline": "feat(auth): Config.Backend — one cohesive DI-built resolve+login+auth…",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-07T19:48:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "be3e763fc2483bb13ad272c31313a64eff9d0044",
"body": null,
"is_bot": false,
"headline": "chore(release): 1.31.0",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-06T09:11:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1798edb349627f66e94904676cc65ee016366fbe",
"body": "A Laravel-Mail / ActionMailer-style abstraction: app code composes a\nmail.Message and hands it to one Mailer interface; the transport is chosen by\nconfig (log in dev, SMTP in prod). Wired like a cache or disk — mail.Bind[T]\nwith T embedding *mail.Manager, injected into handlers and shown on the\ndash\n[…]\nlds\n multipart/alternative (text+HTML) and multipart/mixed (attachments) with\n quoted-printable bodies and RFC 2047 headers.\n\nAdds resource.KindMail + resource.NewMail and a 'nexus docs mail' topic.",
"is_bot": false,
"headline": "feat(mail): add extension/mail — outbound email (SMTP + log)",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-06T09:10:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e1de1e0e618579c5c3d35a46398e073e567db67d",
"body": null,
"is_bot": false,
"headline": "chore(release): 1.30.0",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-06T07:40:33Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fed24979a589c220a03b8bfeb29bea5e8d14c6dd",
"body": "nexus build now bakes the project's nexus.toml into the compiled binary via\nthe linker (-ldflags -X, base64-encoded), so the artifact is self-contained\nand needs no config file shipped alongside it. Boot uses the embedded copy as\na fallback after the disk resolution chain (NEXUS_CONFIG -> cwd -> nex\n[…]\nides without a rebuild. The\nraw file is embedded with ${VAR} placeholders intact, so secrets resolve from\nthe runtime environment and are never baked in. Pure-Go apps with no nexus.toml\nembed nothing.",
"is_bot": false,
"headline": "feat(build): embed nexus.toml into the binary",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-06T07:40:27Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f68793ed08346a78f513bf7ebd4d9cce365b0399",
"body": null,
"is_bot": false,
"headline": "chore(release): 1.29.2",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-05T17:41:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f653cad17a21d9be5e531a2d8d7e036fbe88d70c",
"body": "Boot only looked for nexus.toml in the current working directory, so a\ndeployed binary launched from another directory silently fell back to\nframework defaults — most visibly binding :8080 instead of the configured\n[runtime.server].addr. resolveConfigPath now tries NEXUS_CONFIG, then cwd,\nthen a nexus.toml sitting beside the executable, and autoLoad warns on\nstderr when no config is found instead of defaulting silently.",
"is_bot": false,
"headline": "fix(config): resolve nexus.toml next to the executable; warn when absent",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-05T17:41:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "11d1c113fecb8d9e3c6a8212114a9988ced60545",
"body": null,
"is_bot": false,
"headline": "chore(release): 1.29.1",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-04T10:38:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e9424a977bdc60f160b2eb408639e0e60740fc29",
"body": "fix(cli): make -ldflags version stamping actually work",
"is_bot": false,
"headline": "Merge pull request #56 from paulmanoni/fix/cli-version-ldflags",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-07-04T07:13:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2be0310a88d20093b93d72e1a4603a5042a68213",
"body": "fix(ci): build golangci-lint from source (go1.26 target) + stale db comments",
"is_bot": false,
"headline": "Merge pull request #55 from paulmanoni/fix/stale-db-bind-comments",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-07-04T07:13:47Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d11ce31ed28c92305012505a70db71ba47802b00",
"body": "…irement)\n\nA scaffolded app pinned go 1.25.1 while nexus itself requires go 1.26.2,\nso the very first build/tidy had to bump it. Scaffold go 1.26 to match the\nREADME's 'Needs Go 1.26+' and the framework's go.mod.",
"is_bot": false,
"headline": "fix(cli): scaffold go directive 1.25.1 → 1.26 (matches framework requ…",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-04T07:13:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "71a3a3c5fdc7794afafa9f7d5db477680b4b1052",
"body": "`nexus version` ignored the release-time -ldflags \"-X main.Version=...\"\nvalue: `var Version = resolveVersion()` ran the initializer at startup and\noverwrote whatever the linker injected, so a stamped binary still printed\n\"dev\". Leave Version uninitialized (so the -X value survives) and fill the\nBuil\n[…]\nall …@vX.Y.Z);\nthis fixes the release/goreleaser path documented as priority 1.\n\nVerified: `go run -ldflags \"-X main.Version=v1.29.0\" ./cmd/nexus version`\nnow prints \"nexus v1.29.0\" (was \"nexus dev\").",
"is_bot": false,
"headline": "fix(cli): make -ldflags version stamping actually work",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-03T12:04:21Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "5173626a902e7c2bdf982f485d18814c2cef4d25",
"body": "The prebuilt golangci-lint v1.64.8 binary is compiled with go1.24 and\nrefuses to analyze the go1.26.2 modules (\"the Go language version used to\nbuild golangci-lint is lower than the targeted Go version\"), failing the\nlint job on every matrix module. install-mode: goinstall compiles it with\nthe runner's Go (1.26) instead — matching how make lint runs it locally.",
"is_bot": false,
"headline": "fix(ci): build golangci-lint from source to match the go1.26 target",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-03T11:53:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ac286e7eb1e3acbe5ba3a9ba529e8664e5e27920",
"body": null,
"is_bot": false,
"headline": "docs: fix stale DatabaseFromConfig comments → db.BindFromConfig",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-03T11:53:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "22885612d904e164cbc97af6a1e35600a736606f",
"body": null,
"is_bot": false,
"headline": "chore(release): 1.29.0",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-03T10:47:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cd9be68c2e3357fa174c8297b5d125cbe56d329b",
"body": "# Conflicts:\n#\tCHANGELOG.md",
"is_bot": false,
"headline": "Merge #52: enforce gofmt + golangci-lint gate",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-03T10:45:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "246ba161787b3137c6d19b543ec6766c0a201c79",
"body": null,
"is_bot": false,
"headline": "Merge docs: security/storage/auth feature guides",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-03T10:44:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a6a8d3a395fed023a64c68fc74cf6017b099f3e1",
"body": "# Conflicts:\n#\tCHANGELOG.md",
"is_bot": false,
"headline": "Merge #54: password hashing + credential login backends",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-03T10:44:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c59ed31b8942de7c7a5bf07c04873a2f3586315e",
"body": "# Conflicts:\n#\tCHANGELOG.md",
"is_bot": false,
"headline": "Merge #53: file/object storage (local + S3 disks)",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-03T10:44:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9bf3f115d087e67d9230f29feeae8dc8fa82436f",
"body": null,
"is_bot": false,
"headline": "Merge #51: built-in web security (headers + CSRF)",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-03T10:38:14Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e68b98c9d61e53926145897df458ad1f1d8764c0",
"body": null,
"is_bot": false,
"headline": "Merge #50: Inertia SSR Phase 2",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-03T10:37:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e63df3e7b36a87a585931b620dbb094de9e59827",
"body": "- README: a \"Built in: security, storage, passwords\" section with\n copy-paste usage for the new features + links in the Going-further table.\n- CLAUDE.md: [runtime.middleware.security] block; storage subsection in §6;\n password hashing / validators / login backends in §8; fix the stale\n nexus.DatabaseFromConfig reference → db.BindFromConfig.",
"is_bot": false,
"headline": "docs: document security, storage, and password-auth features",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-03T10:27:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fa1b8efbc32b45e440a1edff257ef7c289f512fd",
"body": "…e, phase 1)\n\nFill in the \"login\" half of auth that nexus lacked, mirroring Django's\nswappable-backend model — each piece an interface with a shipped default,\nnon-breaking around the existing token-Resolver/Scheme surface.\n\n- Hasher / Hashers (PASSWORD_HASHERS analogue): self-describing encoded\n ha\n[…]\nn-user path to avoid\n enumeration. In-memory MemoryUserStore ships for dev/tests.\n\nnexus docs auth gains a \"Passwords & login backends\" section. Auth suite\ngreen under -race; go.mod/go.sum untouched.",
"is_bot": false,
"headline": "feat(auth): password hashing + credential login backends (Django-styl…",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-03T10:18:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "349f3d5d55d7e154072f09ec22d9e47968bb62e3",
"body": "Add extension/storage, the Go equivalent of Laravel Storage / Rails\nActiveStorage: app code talks to one Disk interface (Put/Get/Exists/\nDelete/Stat/List/URL/SignedURL) and the backend is chosen by config, so\nlocal-in-dev / S3-in-prod is a config change, not a code change.\n\nTwo backends, both depend\n[…]\n+ NewStorage).\n\nThe SigV4 signer is verified against AWS's published GET-object example\nvector. nexus docs storage + CHANGELOG added. Full storage suite green;\ngo.mod/go.sum untouched (zero new deps).",
"is_bot": false,
"headline": "feat(storage): file/object storage abstraction — local + S3 disks",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-03T10:00:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c39d542e7f2a0c3672232244f3342a4c39e9fd8b",
"body": "CI previously ran only vet/test/cover/codegen-drift — formatting and lint\nwere unchecked, and 130 files were not gofmt-clean under the Go 1.26\ntoolchain.\n\n- Reformat the whole tree with gofmt (130 files: doc-comment reindentation\n + trailing newlines; no logic changes).\n- Add a gofmt gate: `make fm\n[…]\nrrcheck/unused/staticcheck/bodyclose/\n errorlint are noted in-config as the next tighten-up candidates.\n- Wire both into `make ci`.\n\nFull suite green (45 pkgs); gofmt/lint green on all three modules.",
"is_bot": false,
"headline": "chore(ci): enforce gofmt + add golangci-lint gate",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-03T09:13:55Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d9fd0b3bd90691bf1ef07513fc8c02a8f233346b",
"body": "…n CSRF\n\nAdd the web-security defaults every incumbent framework (Django, Rails,\nLaravel, Phoenix) ships and nexus previously left to the operator.\n\nCore, config-driven, secure by default:\n- Security response headers (X-Frame-Options: DENY, X-Content-Type-\n Options: nosniff, Referrer-Policy: strict\n[…]\nre.security] block; CSRF is\n pre-enabled for --inertia apps.\n\nDocs: nexus docs security + the nexustoml topic. CHANGELOG updated.\nTests: full suite green (47 pkgs), including e2e via nexus.InProcess.",
"is_bot": false,
"headline": "feat(security): built-in web security — headers on by default + opt-i…",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-07-03T04:34:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "994f21eae728b2529c5bf7fbb5f3125c8e05e13d",
"body": "Scaffold an Inertia SSR app: a hydrating client entry (createSSRApp), a\nNode SSR bundle entry (web/src/ssr.ts — createServer + renderToString), a\ntwo-bundle build (vite build && vite build --ssr → web/dist/ssr/ssr.js),\nand the Go wiring (inertia.Config{SSR: ssrhttp.New(\"\")}).\n\n--ssr implies --inerti\n[…]\nit errors clearly otherwise. Production runs the Node SSR sidecar\non :13714 alongside the app; nexus dev falls back to client rendering with\nHMR (no sidecar). Documents the flow in nexus docs inertia.",
"is_bot": false,
"headline": "feat(inertia): nexus new --inertia --ssr scaffold (SSR Phase 2)",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-28T15:09:40Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9eb73921109d9c19c716cd503365a70388a83260",
"body": null,
"is_bot": false,
"headline": "Merge Inertia CSP nonce (#48) + SSR Phase 1 (#49)",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T14:51:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "13250ac90c1fcc77deb57037ce609213844b1f9b",
"body": "Add Inertia SSR via a small pluggable seam, v3-compatible and dependency-free\non the Go side:\n\n- SSRRenderer interface + SSRResult{Head, Body}. On the initial (non-XHR) load\n the engine POSTs the page object to the renderer and injects head into <head>\n and body inside the root div, flagged data-s\n[…]\nror + OnSSRError, strict 500), and\nssrhttp prod/dev-URL/transport-error.\n\nPhase 2 (viteless --ssr build + managed sidecar) and an experimental zero-Node\nQuickJS renderer are deliberately out of scope.",
"is_bot": false,
"headline": "feat(inertia): server-side rendering (Phase 1) — SSRRenderer + ssrhttp",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T14:49:59Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f5d6705d8623e3ef20a93532cd54fad876f37a52",
"body": "Config.Nonce func(*httpx.Ctx) string supplies a per-request CSP nonce. When set\nand non-empty, the shell stamps nonce=\"…\" on every engine-injected\n<script>/<link> (asset tags, dev preamble, and Config.Head), so they pass a\nstrict script-src 'nonce-…' / style-src 'nonce-…' policy. The app's CSP\nmiddl\n[…]\nd. Stamping is a targeted prefix replace over the\nengine-generated head (known tag shapes), no HTML parser.\n\nTest: TestShellNonce (script/link/Config.Head all stamped, none without a nonce,\nescaping).",
"is_bot": false,
"headline": "feat(inertia): optional CSP nonce on the document shell",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T14:36:51Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4cadc9f080f13f0bc5390329c6497d8db494c664",
"body": "…ramework-aware dev preamble (#47)",
"is_bot": false,
"headline": "Merge Inertia Vite-integration fidelity: manifest tag graph (#46) + f…",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T14:30:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4b32c5339506f3caa009952f4465513eae279ae2",
"body": "devHeadTags hardcoded /src/main.ts and emitted only the Vue-style client tags,\nso a React app got no Fast Refresh (edits did full reloads) and any app with a\nnon-default entry was stuck.\n\n- Config.Entry sets the dev-server entry module (default \"src/main.ts\";\n \"src/main.tsx\" for React). Ignored in \n[…]\ne entry, as the React plugin requires.\n\nTest: TestDevHeadTags (Vue has no preamble; React preamble ordered before client\n< entry; custom entry honored). Existing TestDevTagsPreferViteServer unchanged.",
"is_bot": false,
"headline": "feat(inertia): framework-aware, configurable dev preamble",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T14:28:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "a14a833a7e98babe21fa350e432f5704706da858",
"body": "… CSS)\n\nThe production head-tag generator only emitted the entry chunk's file + its\ndirect CSS. On a code-split build that:\n - dropped CSS that lives on imported/shared chunks (flash of unstyled / missing\n styles), and\n - emitted no <link rel=modulepreload> for imported chunks (the browser only\n[…]\nsmallest isEntry key).\n\nTest: TestHeadTags_ImportsGraph (recursive CSS, modulepreload of imports,\nentry-not-preloaded, dynamic-imports-excluded, dedup). Existing single-entry\nmanifest tests unchanged.",
"is_bot": false,
"headline": "fix(inertia): full manifest tag fidelity (modulepreload + split-chunk…",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T14:24:19Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "29244097d9c779324017baeaa0e0866984bdb74f",
"body": "TestMergeVariants bound 127.0.0.1:8831, the same port extension/inertia/iauth's\ntest uses. `go test ./...` runs package test binaries in parallel, so the two\nraced to bind 8831 → 'address already in use' → the inertia package failed.\nThat failure also tripped `make cover-check` (it runs go test ./... first).\nMove TestMergeVariants to 8840 (unused). Coverage itself is fine (50.3% > 45%).",
"is_bot": false,
"headline": "test(inertia): fix port collision with iauth package (CI green)",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T14:10:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4376a2d81308fa282f252fddd388d6648f723b6c",
"body": "chore: remove dead code (unused unexported helpers)",
"is_bot": false,
"headline": "Merge pull request #40 from paulmanoni/chore/remove-dead-code",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-26T14:03:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f47504ad03eae3fe902976e5f1db68c6e89e3e07",
"body": "docs: collapse boot entry points to three blessed verbs",
"is_bot": false,
"headline": "Merge pull request #39 from paulmanoni/docs/boot-entry-points",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-26T14:03:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d790eb0a8f3eae69e69434dd67b1dd9090b1e43a",
"body": "…-discovery, runnable example (#42-#45)",
"is_bot": false,
"headline": "Merge Inertia stack: validation, history/defer, infinite scroll, auto…",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T14:02:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "efd66a5ba5fadd98c56554f3cdcce4e44c52dd6c",
"body": "feat(inertia): Partial-Except, Reset, and shell Vary (protocol correctness)",
"is_bot": false,
"headline": "Merge pull request #41 from paulmanoni/feat/inertia-protocol-correctness",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-26T13:58:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f61fd104530510e4b96a992962270ccb2ace1806",
"body": "The inertia example was server-only — no web/, so it couldn't actually render.\nAdd a zero-install viteless Vue client matching the server's page components:\n\n- web/src/Pages/Users/Index.vue (props from NewUsers)\n- web/src/Pages/Auth/Login.vue (useForm POST to /login; reads page.props.errors)\n- we\n[…]\nRun it with\n`nexus dev ./examples/inertia` (zero-install HMR) or `nexus build`.\n\nweb/.gitignore keeps dist build output + node_modules out of the tree (the\nindex.html stub stays so go:embed compiles).",
"is_bot": false,
"headline": "examples(inertia): add a runnable Vue client (end-to-end Inertia)",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T13:57:37Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "987f659a3f4aff065da600f77ab447dd9797bcbb",
"body": "…ted FS)\n\nAn Inertia app named its built bundle twice — once to ServeFrontend (which\nserves the hashed assets) and again to inertia.Config{Frontend, Root} (which\nonly reads the Vite manifest for the asset version + shell tags). Same bundle,\ntwo different jobs, but the FS arg was duplicated.\n\nNow Ser\n[…]\n // bundle auto-discovered\n\nTest: TestFrontendAutoDiscovery (manifest version resolves through ServeFrontend\nwith an empty inertia.Config). Existing tests that pass Frontend explicitly\nkeep working.",
"is_bot": false,
"headline": "feat(inertia): auto-discover the ServeFrontend bundle (drop the repea…",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T13:55:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7e283518734c403185c9126d1922da58c1ad4695",
"body": "Round out Inertia v2 merge props:\n\n- DeepMerge(fn[, matchOn]) flags a prop into the page object's deepMergeProps\n for a recursive merge (vs Merge's shallow append).\n- Merge and DeepMerge now take an optional matchOn key; each emits a\n matchPropsOn entry \"<prop>.<field>\" so the client de-dupes merg\n[…]\nop to return the full Prop descriptor (kind/group/matchOn)\ninstead of a widening tuple.\n\nTest: TestMergeVariants (mergeProps/deepMergeProps/matchPropsOn populated, and\nall cleared by X-Inertia-Reset).",
"is_bot": false,
"headline": "feat(inertia): infinite-scroll merge variants — DeepMerge + matchOn",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T13:34:16Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7170cfbe037f0f8c89430984be4a5fc47095e6d5",
"body": "Two Inertia v2 page-object features:\n\n- Deferred groups: Defer now takes an optional group name —\n Defer(fn, \"report\") — and deferredProps is emitted per group instead of a\n single hardcoded \"default\". The client fetches each group in its own\n request, so a slow report and a fast sidebar load in \n[…]\nts: TestDeferredGroups (named + default groups, all excluded from the\ninitial payload), TestHistoryEncryption (per-response flags + omitted when\nuntouched), TestHistoryEncryptDefault (Config default).",
"is_bot": false,
"headline": "feat(inertia): deferred prop groups + history encryption (v2)",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T13:26:45Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ea89d97091af98e4739832b111e2fa6e0772872d",
"body": "…useForm flow)\n\nAdd the Inertia validation contract — the useForm unlock — without a server\nsession:\n\n- inertia.Invalid(map[field]message) and inertia.InvalidField(field, message)\n are the sentinels a page handler returns on a failed submit.\n pageRenderer.RenderError catches them, flashes the mess\n[…]\nsafety TTL, consumed and cleared on next render).\n\nTests: TestErrorsPropAlwaysPresent, TestValidationFlow (end-to-end 303 +\nflash + re-render + cookie clear), TestInvalidField, TestValidationErrorBag.",
"is_bot": false,
"headline": "feat(inertia): validation errors via inertia.Invalid / InvalidField (…",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T13:18:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9e8f1f2d2698ffa4a832dd304dc997c37942e0dd",
"body": "Close three Inertia-protocol gaps in the page renderer:\n\n- X-Inertia-Partial-Except: partial reloads now exclude the listed props\n (and send all plain props when only Except is given). Except takes\n precedence over Partial-Data; Always props bypass both filters.\n- X-Inertia-Reset: a Merge prop nam\n[…]\n shared caches never serve the document shell to an XHR visit\n of the same URL, or vice versa.\n\nAdd tests for each (TestPartialExcept incl. Except>Data precedence,\nTestResetMergeProp, TestShellVary).",
"is_bot": false,
"headline": "feat(inertia): support Partial-Except, Reset, and Vary on the shell",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T13:04:05Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0ac4d5e4c024eff63c7ff5e9910a8bdff701793c",
"body": "Delete unexported functions/consts/vars with zero call sites (verified by\ngrep; gopls unusedfunc; staticcheck can't run on go1.26):\n\n- resource_declare.go (whole file) — resourceConfig + its resourceOpts,\n embeddedFieldIndex, mustEmbeddedField, requireResourceArgs, newHandle. The\n db/cache/pubsub \n[…]\nt\nfield is live via the manifest/registry/routes path) and the obs_health peer\nmethods (recordPeer/allPeersReady back the live /__nexus/ready contract — an\nunwired feature surface, not dead leftover).",
"is_bot": false,
"headline": "chore: remove dead code flagged by unusedfunc",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T12:35:39Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6da4005dc3a1455215abc737c222730e755ec8dc",
"body": "Document the entry-point surface so newcomers know which to call instead of\nguessing among Boot/BootFrom/Run/New/MustLoad*/LoadConfig/LoadExtensionOptions:\n\n- Package doc gains an \\\"Entry points\\\" section: Boot (default, toml-driven),\n Run (Config built in Go), InProcess (tests). New/MustLoad*/Load\n[…]\nfault).\n\nDocs only; no API or behavior change. (Examples that build Config in Go keep\nusing Run by design — they run via `go run ./examples/X` from the repo root,\nwhere Boot would find no nexus.toml.)",
"is_bot": false,
"headline": "docs: collapse boot entry points to three blessed verbs",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T12:23:11Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7a365ea05066fb857914236262f4a7caf62a944e",
"body": "feat: prefer \"path\" struct tag for REST path params (uri stays supported)",
"is_bot": false,
"headline": "Merge pull request #36 from paulmanoni/feat/path-param-tag",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-26T12:13:55Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4b2c754efcfca9d02ab2300510c541cce610a158",
"body": "# Conflicts:\n#\tCLAUDE.md",
"is_bot": false,
"headline": "Merge branch 'main' into feat/path-param-tag",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T12:13:46Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b867ee4b71c81d27e1e7e36b9186338cb36c7b36",
"body": "chore(security): bump pgx to v5.9.2 (GO-2026-5004) + CI action versions",
"is_bot": false,
"headline": "Merge pull request #38 from paulmanoni/chore/security-pgx-and-ci-actions",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-26T12:12:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "09820aa105c36901f7cbeccc1724a216a9c3f405",
"body": "feat: quiet-boot seam — Config.Server.NoListener for socket-free boot",
"is_bot": false,
"headline": "Merge pull request #37 from paulmanoni/feat/quiet-boot",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-26T12:12:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7e40c641b88df37c788ef2b58cccae6d4e02a297",
"body": "feat: unify endpoint description into cross-transport nexus.Describe",
"is_bot": false,
"headline": "Merge pull request #35 from paulmanoni/feat/describe-cross-transport",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-26T12:12:18Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ea5fd16c8cd17e5ec6958a3323fc0673e60ef14c",
"body": "…ions\n\ngovulncheck flagged GO-2026-5004 in jackc/pgx/v5 v5.6.0 — reachable through\ndb.Manager.Ping → sql.DB.PingContext → sanitize.SanitizeSQL. Bump pgx to\nv5.9.2 (the fix release); govulncheck no longer reports it. The remaining\nfindings are stdlib vulns in go1.26.2 fixed in later patch releases, w\n[…]\ncally.\n\nAlso clear the Actions deprecation warnings: actions/checkout@v4 → v5 and\nactions/setup-go@v5 → v6 (Node 20 → Node 24 runtimes), and\ngithub/codeql-action/upload-sarif@v3 → v4 (v3 deprecation).",
"is_bot": false,
"headline": "chore(security): bump pgx to v5.9.2 (GO-2026-5004) and CI action vers…",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T12:11:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fbe5e7a3b22c053390c81d47ad342c7bcfd3f28c",
"body": "Add Config.Server.NoListener: registerLifecycle still runs startup tasks,\nmanifest resolution, the SDK dump, cron, and liveness, but skips net.Listen,\nServe, and the \"listening on …\" banner. The app remains a fully wired\nhttp.Handler (App.ServeHTTP).\n\nInProcess sets it instead of the old bind-to-:0 \n[…]\nles serverless/embedded deploys where an outer runtime owns the socket.\n\nAdd tests: two InProcess apps on the same fixed addr both boot (no bind\nconflict), and ServeHTTP still routes with no listener.",
"is_bot": false,
"headline": "feat: quiet-boot seam — Config.Server.NoListener for socket-free boot",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T12:06:08Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "7eca946fd3609a48f37e7402d2891422b166a9d7",
"body": "…ted)\n\nPath params bound via the gin-legacy \\`uri:\"id\"\\` tag now also bind via the\nclearer \\`path:\"id\"\\` tag — the natural spelling now that the stdlib router is\nthe default. ShouldBindUri reads \"path\" first and falls back to \"uri\", and\ntagSurvey recognizes either. No behavior change for existing \\`uri\\` code.\n\nDogfood path:\"\" on the framework CRUD id arg; update docs (CLAUDE.md, nexus\ndocs rest) to lead with path. Add httpx bind tests covering both tags and the\npath-wins precedence.",
"is_bot": false,
"headline": "feat: prefer \"path\" struct tag for REST path params (uri stays suppor…",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T11:59:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e4d51f2abf038a49412a3e9fe4440107fe015bed",
"body": "Add nexus.Describe(s) — a single per-op option that sets an endpoint's\ndescription on REST, GraphQL, and WS, mirroring HideFromDashboard and\nWithIcon. It sets the shared baseEndpointConfig.description that\nregisterEndpoint already stamps onto every transport's registry entry\n(GraphQL additionally em\n[…]\ne.\n\nMigrate the oauth2 token/revoke endpoints and the AsRestHandler doc\nexample onto Describe. Add TestDescribe_CrossTransport asserting the\ndescription reaches all three transports' registry entries.",
"is_bot": false,
"headline": "feat: unify endpoint description into cross-transport nexus.Describe",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-26T11:48:17Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "e6e204609670cd6885ef0f2a11a0da34eefb4db7",
"body": "test: in-process harness, seam conformance suites, golden tests, CI",
"is_bot": false,
"headline": "Merge pull request #34 from paulmanoni/test/harness-and-ci",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-24T04:16:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d7f992735395450dec430ba3e220cc399cbb7b5c",
"body": "Build a coherent testing system on top of the existing per-package tests.\n\nHarness\n- nexus.InProcess: public listener-less boot that mirrors Run's full\n early->user->late option ordering, so every REST/GraphQL/WS route mounts\n for real and the app is driven via ServeHTTP (no socket, parallel-safe)\n[…]\nating all three modules; .github/workflows/ci.yml delegates to it.\n Coverage floor ratchet (45%, current 49.8%) + handler codegen drift gate.\n\nAll three modules pass under -race with zero data races.",
"is_bot": false,
"headline": "test: in-process harness, seam conformance suites, golden tests, CI",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-24T04:12:32Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "324bb8c9d954d41f9e36b77642c6961806c0741e",
"body": "…tors (#33)\n\nCustom (dotted) decorators like //@inertia.Page previously rejected modifier\nannotations (\"does not accept modifier annotations\"), which skipped the whole\npackage's codegen. Now modifiers are appended as trailing options to the\nregistrar call, e.g.\n\n //@auth Required\n //@inertia.P\n[…]\n\n- renderPrimary: append optTail in the custom-decorator branch.\n- emit test flipped from reject → append; docs (inertia topic, DESIGN.md) updated.\n\nCo-authored-by: paulmanoni <01paulmanoni@gmail.com>",
"is_bot": false,
"headline": "feat(decorate): allow //@auth and //@use on custom //@pkg.Func decora…",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-23T23:59:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "eadbf833e7ff00f1a0749c510300003b1535da52",
"body": "nexus dev now auto-detects an Inertia app (its build graph imports the inertia\nextension) and uses the Inertia dev topology (browser at the app port, app\nshell pointed at viteless for HMR) — no config needed. [runtime.inertia]\nenabled becomes an optional override: true forces it on, false opts a hyb\n[…]\nnted opt-out instead of forcing it.\n- docs (inertia topic) updated.\n\nTests: config override (unset/true/false), import detection, resolution order.\n\nCo-authored-by: paulmanoni <01paulmanoni@gmail.com>",
"is_bot": false,
"headline": "feat(dev): auto-detect Inertia dev topology (#32)",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-23T23:18:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "406f39d9e623a404b29aa0586ea8d2832841ece0",
"body": "…rators (#31)\n\nBuild path:\n- `nexus build` now injects decorator-form handler registrations via\n `go build -overlay` (mirroring `nexus dev`), so nothing is written into\n the source tree. Codegen errors are fatal here (a shipped binary must not\n silently omit registrations). `nexus generate handle\n[…]\n.\n\nDocs: build --help, CLAUDE.md, inertia + nexustoml docs topics.\nTests: all four resolver layers, blank/dot imports, alias, ambiguity,\nnot-found.\n\nCo-authored-by: paulmanoni <01paulmanoni@gmail.com>",
"is_bot": false,
"headline": "feat(cli): nexus build via overlay + auto-import for //@pkg.Func deco…",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-23T23:00:29Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "216366c9c2483532383532228792213227d2131a",
"body": "By default request activity goes to the dashboard trace stream\n(/__nexus), never the console, so navigating pages leaves the terminal\nquiet. Under nexus dev (NEXUS_DEV=1) the app now logs one structured\n(zap-JSON) line per HTTP request to stdout, rendered through the Dev\nServer Logs view: GET /users\n[…]\nlse. Installed\nas a whole-mux middleware in New(cfg), registered as dev-request-log.\n\nAlso gofmt the palette struct from the prior dev-logs commit.\n\nCo-authored-by: paulmanoni <01paulmanoni@gmail.com>",
"is_bot": false,
"headline": "feat(dev): per-request console log under nexus dev (#30)",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-23T12:05:47Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "8efc07713b294c49cd0bd522d7fcedd584adf9ac",
"body": "Two nexus dev additions:\n\n1. --dist: keep web/dist fresh during dev. The HMR server serves the\n frontend from memory and never writes dist, so the //go:embed bundle\n stays frozen at the last nexus build — a mid-session go build ships\n stale assets. --dist runs a debounced background viteless b\n[…]\naw/json passthrough. Add a format by registering a logFormatter.\n\nDocs in CLAUDE.md; tests for the dist watch filters and all three log\nformatters.\n\nCo-authored-by: paulmanoni <01paulmanoni@gmail.com>",
"is_bot": false,
"headline": "feat(dev): --dist watch-build + configurable Dev Server Logs view (#29)",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-23T11:29:38Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "0a670b381daf701ecf1bb1a3458dcf66770a26c3",
"body": "The dev server forced a full page reload whenever a dependency used only\ninside an Inertia page (resolved via import.meta.glob — dynamic imports\nthe startup dep-scanner doesn't follow) was discovered lazily on first\nnavigation, re-running esbuild pre-bundling. HMR cannot survive a new dep\nbeing opti\n[…]\nnfig.ts gets a\ntyped default export and NexusVitePluginOptions instead of any.\n\nRegenerated the committed petstore-spa example SDK copies to match.\n\nCo-authored-by: paulmanoni <01paulmanoni@gmail.com>",
"is_bot": false,
"headline": "fix(vite-plugin): pre-bundle deps at startup + ship TS types (#28)",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-23T10:53:14Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "6c8a21e364c8ef049699e051ae52c1fb2e7869ea",
"body": "The builtin container resolved a variadic constructor's trailing\nparameter by type, so nexus.Provide(zap.NewExample) — and any\nfunc(...T) — failed with \"di: no provider for []T\". dig (fx's\ncontainer) ignores variadic arguments and calls such constructors with\nnone; the builtin now matches that.\n\nres\n[…]\nded in di and the fxcontainer parity suite (same graph\nthrough both backends).\n\nCo-authored-by: paulmanoni <01paulmanoni@gmail.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(di): ignore unannotated variadic ctor params (dig/fx parity) (#27)",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-22T19:47:52Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "4a206bdbadb47d2c56bcdebbca892544c23f7c6b",
"body": "Show the decorator-form workflow alongside the explicit one — annotated\nhandlers (//@provide/@rest/@query/@auth), an empty `func main(){ nexus.Boot() }`,\nand `nexus dev` / `nexus generate handlers`. Notes per-package dashboard modules\nand custom extension decorators (//@inertia.Page).\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(readme): add a //@ decorator usage example",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-22T17:40:44Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "a40b1ef19fc6ac21e7568369bc9a5b0d4df4b5d4",
"body": "…UDE.md\n\nAdd a §5 \"Decorator-form registration\" subsection (annotation catalog, the\nzero-wiring nexus generate handlers flow, per-package modules, dev-overlay vs\ncommitted build, nexus.WithIcon branding) and list `nexus generate handlers`\nin the §11 CLI cheatsheet.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(decorate): document the //@-annotation decorator workflow in CLA…",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-22T17:35:28Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "48a1b6595bd617801c68f0f900e789f56a3d10c0",
"body": "…(#26)\n\nAdd nexus/decorate + a `nexus generate handlers` codegen so handlers register\nthemselves from //@ doc-comment annotations, with zero wiring ceremony in the\napp. Built on the deco scanner (github.com/paulmanoni/deco v0.12.0,\ntranspiler.Scan) and the di seam.\n\nAuthoring:\n //@provide / //@re\n[…]\n/@inertia.Page); CLAUDE.md DI/decorator notes\nand the path:→uri: REST tag fix.\n\nCo-authored-by: paulmanoni <01paulmanoni@gmail.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(decorate): //@-annotation handler registration with auto-wiring …",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-22T17:31:18Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "f17d042a59c328168ef79b4211d5339c92e24348",
"body": "Add a \"DI container backend (pluggable; built-in by default)\" subsection\ncovering the built-in nexus/di container, nexus.WithContainer + the opt-in\nfxcontainer module, the nexus.Lifecycle/Hook + nexus.Error helpers, and the\nParamTags/ResultTags value-group wiring. Correct stale \"fx-based\" / \"fx graph\"\n/ \"fx-injected\" references throughout to reflect that the default build links\nno go.uber.org/fx.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(di): document the DI container seam in CLAUDE.md",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-22T14:30:07Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "31599b962afa61a5ad2df5c1ec03d2beeda990c4",
"body": "* changes\n\n* feat(di): make uber/fx optional via a built-in DI container seam\n\nIntroduce nexus/di, a small zero-third-party-dependency dependency-injection\ncontainer implementing exactly the subset of go.uber.org/fx the framework used\n(Provide/Supply/Invoke, value groups + optional via ResultTags/Pa\n[…]\no-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: paulmanoni <01paulmanoni@gmail.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(di): make uber/fx optional via a built-in DI container seam (#25)",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-22T14:24:06Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0190aef52787f4cad489c5d766f92c549fc71bf7",
"body": "…kends\n\nAfter the seam migration c.Param(\"rest\") for a *rest route returned \"app.js\"\non stdlib (ServeMux drops the slash) and \"\" on chi (capture stored under \"*\"),\nwhere gin gave \"/app.js\". The dashboard builds \"assets\"+c.Param(\"filepath\"),\nso its assets 404'd and JS modules were served with an empty MIME type and\nblocked by the browser. Normalize the wildcard capture to gin's leading-slash\nform (new httpx.WildcardName helper) so c.Param is identical on gin/chi/stdlib.",
"is_bot": false,
"headline": "fix(httpx): wildcard route params keep gin's leading slash on all bac…",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-19T18:53:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3411324e7df5fd6939dd68605ccb602144e6a0c8",
"body": "ServeMux treats a pattern ending in / as a subtree match, so a home-page\nroute like GET / (e.g. inertia.Page(\"GET\",\"/\",…)) became a catch-all that\nshadowed every unmatched GET path — including GET /assets/* — so SPA assets\nnever reached the ServeFrontend NoRoute fallback and pages loaded with no\nassets. Append ServeMux's {$} end-of-path marker to trailing-slash routes to\nrestore gin's exact-match semantics; wildcard, NoRoute and Static catch-alls\nare unaffected.",
"is_bot": false,
"headline": "fix(stdrouter): trailing-slash routes match exactly, not as a subtree",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-19T06:02:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9042c762fdf533cd0fb978dcf06a673e54de2005",
"body": "…oute\n\nA method-less Static prefix (/media/) is ambiguous against an app's GET /\ncatch-all under Go 1.22's ServeMux — more specific path but more methods, so\nneither is a subset — and panics at boot (SPA frontend + Static upload dir).\nA static server only needs GET/HEAD (ServeMux serves HEAD off GET), and\nGET /media/ is a strict path-refinement of GET /, so the conflict is gone.",
"is_bot": false,
"headline": "fix(stdrouter): scope Static to GET so it coexists with a catch-all r…",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-19T05:48:57Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d4f05980be57d7b161e94b73dd28f53f1d652c6e",
"body": "…, …)\n\nThe router-seam migration left no neutral equivalent for gin's POST-body\nform methods, so low-level handlers reading form data failed to compile\nagainst *httpx.Ctx. Add PostForm/DefaultPostForm/GetPostForm/PostFormArray\nplus FormFile/MultipartForm/SaveUploadedFile, reading *http.Request directly\nso they behave identically on every router backend.",
"is_bot": false,
"headline": "feat(httpx): gin-compatible form accessors on Ctx (PostForm, FormFile…",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-19T05:39:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "24704b6cfa4e9e174d989cc92816c89c6cf1bb8f",
"body": "… go.mod (#24)\n\nhttpx/ginrouter is now its own Go module, so gin (and its sonic/golang-asm/\ngoccy/validator/json-iterator tree) leaves the main module's dependency graph\nentirely — go.mod/go.sum no longer reference gin, and `go list -m all` drops\nfrom 182 to 161 modules. The default build was alread\n[…]\nelease this\nis pinned to a parent tag that no longer contains httpx/ginrouter.\n\nCo-authored-by: paulmanoni <01paulmanoni@gmail.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "refactor(ginrouter): extract to a separate module; drop gin from main…",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-19T04:04:45Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "214c54973fc87d970bb71acb84bedfefcd5fce26",
"body": "The HTTP router is pluggable (v1.19.0): default is the stdlib net/http with zero\nthird-party router deps; Gin and chi are opt-in via nexus.WithRouter(...). Update\nthe intro accordingly and add a live deps.dev dependencies badge.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "docs(readme): add deps.dev badge; nexus no longer \"built on Gin\"",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-19T03:50:03Z",
"body_truncated": false,
"is_coding_agent": true
},
{
"oid": "cde04bc655b1d0af21cde757bb735dbc9f610448",
"body": "…ing) (#23)\n\n* feat(httpx): make the HTTP router pluggable; default to stdlib (drop gin coupling)\n\nIntroduce github.com/paulmanoni/nexus/httpx — a router-agnostic seam. Handlers\nand middleware now see a transport-neutral *httpx.Ctx; the concrete router is an\nadapter chosen at boot via nexus.WithRout\n[…]\no-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: paulmanoni <01paulmanoni@gmail.com>\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat(httpx): pluggable HTTP router; default to stdlib (drop gin coupl…",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-18T20:35:01Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "47b9bd2dc31317cab0b28e412d1d3032502650e7",
"body": null,
"is_bot": false,
"headline": "chore(release): stamp v1.18.1 in changelog",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-17T21:04:31Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "db887a795b8583d4f528ea3a6437e3face37085b",
"body": "…c (#22)\n\nCo-authored-by: paulmanoni <01paulmanoni@gmail.com>",
"is_bot": false,
"headline": "ci(security): pin govulncheck to v1.3.0 to avoid v1.4.0 generics pani…",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-17T20:55:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "cb366a18b722ad5221f705e812e66e4909be62f6",
"body": "* feat(client): lock down SDK routes + secure auth token/CSRF defaults\n\nHarden the embedded client SDK surface:\n\n- Gate /__nexus/client/* behind the introspection network gate (same as\n the dashboard) so an explicit Client{Enabled:true} mount no longer\n serves the manifest/.d.ts anonymously in a l\n[…]\n.\n\n* docs(readme): add Client SDK section with secure-by-default notes\n\n* docs(cli): refresh 'nexus docs client' for secure SDK defaults\n\n---------\n\nCo-authored-by: paulmanoni <01paulmanoni@gmail.com>",
"is_bot": false,
"headline": "Lock down SDK routes + secure auth token/CSRF defaults (#21)",
"author_name": "paulmanoni",
"author_login": "paulmanoni",
"committed_at": "2026-06-17T20:39:41Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f84dcba1393b89b1032279ef561f88f0eafec128",
"body": "Resolvers often store a richer value in Identity.Extra than the bare domain user (e.g. a \"me\" payload that also carries roles). auth.User[T] now resolves through an optional Principal interface — if Extra is not a T (or *T) but implements Principal() any, it unwraps and retries, repeatedly, with a bounded depth + self-reference guard so a cyclic Principal cannot loop. Direct *T / value-T Extras behave exactly as before.",
"is_bot": false,
"headline": "feat(auth): unwrap wrapper Extra via Principal in auth.User[T]",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-17T09:23:03Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "586eda48f382b80cfbedc2409e7d4d3622644ad1",
"body": "The redesigned screenshot was pushed correctly but kept the same path (docs/dashboard.png), so GitHub + browsers served the cached old image. Rename to docs/dashboard-signal.png so the README references a fresh URL.",
"is_bot": false,
"headline": "docs(readme): rename dashboard image to bust GitHub CDN cache",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-17T09:04:37Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4820af2571362b1a1fea9415837b7c36bc29f77c",
"body": "Rewrite the README around a fast first-run path (install → nexus dev → a verified first-handler example that serves GraphQL + REST + the dashboard), with deep topics moved to a compact \"going further\" links table. Fixes two latent bugs from the old quick start: Params field p.Input → p.Args, and the\n[…]\nm the redesigned dashboard (module selected, showing the live Inspector facets). Remove three orphaned dashboard components (ActivityRail, OverlayToggles, TimeScrubber) left unused after the redesign.",
"is_bot": false,
"headline": "docs(readme): beginner-first rewrite + redesigned dashboard screenshot",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-16T14:34:43Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "eef65d94afc0eaf66edcb49c5468a8605f8660bd",
"body": "Stream the last two polled sources over /__nexus/live: the middleware chain (middlewares + global) and an auth summary, the latter via a new plugin seam dashboard.RegisterSnapshotExtra(name, fn) that places plugin live state in the snapshot extra map (auth registers cached identities). All gathered \n[…]\ne limits (effective + override), global middleware chain, GraphQL document cache, and auth summary in the overview; restore deployment tags on cards and the on-demand trace waterfall in the op drawer.",
"is_bot": false,
"headline": "feat(dashboard): WebSocket-drive all live data + full Inspector parity",
"author_name": "paulmanoni",
"author_login": "Manpaul1",
"committed_at": "2026-06-16T13:56:38Z",
"body_truncated": true,
"is_coding_agent": false
}
],
"releases_count": 63,
"commits_last_year": 688,
"latest_release_at": "2026-06-19T18:53:44Z",
"latest_release_tag": "v1.20.4",
"releases_from_tags": false,
"days_since_last_push": 1,
"active_weeks_last_year": 13,
"days_since_latest_release": 32,
"mean_days_between_releases": 2.7
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": false,
"health_percentage": 42,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "github.com/paulmanoni/nexus",
"exists": true,
"license": null,
"keywords": [],
"ecosystem": "go",
"matches_repo": true,
"registry_url": "https://pkg.go.dev/github.com/paulmanoni/nexus",
"is_deprecated": false,
"latest_version": "v1.34.0",
"repository_url": "https://github.com/paulmanoni/nexus",
"versions_count": 424,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": null,
"monthly_downloads": null,
"first_published_at": null,
"latest_published_at": "2026-07-21T08:52:43Z",
"latest_version_yanked": null,
"days_since_latest_publish": 1
}
]
},
"popularity": {
"forks": 0,
"stars": 3,
"watchers": 0,
"fork_history": {
"days": [],
"complete": true,
"collected": 0,
"total_forks": 0
},
"star_history": null,
"open_issues_and_prs": 0
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [
"Makefile"
],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"examples/inertia/web/tsconfig.json",
"examples/petstore-spa/web/tsconfig.json"
],
"toolchain_manifests": [
"di/fxcontainer/go.mod",
"go.mod",
"httpx/ginrouter/go.mod"
],
"largest_source_bytes": 78620,
"source_files_sampled": 606,
"oversized_source_files": 2,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 42506
},
"dependencies": {
"manifests": [
"go.mod"
],
"advisories": {
"error": null,
"scope": null,
"source": null,
"findings": [],
"collected": false,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 0,
"malicious_count": 0,
"assessed_package": null,
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"go"
],
"dependencies": [
{
"name": "braces.dev/errtrace",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.4.0"
},
{
"name": "github.com/charmbracelet/bubbletea",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.3.10"
},
{
"name": "github.com/charmbracelet/lipgloss",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.1.0"
},
{
"name": "github.com/failsafe-go/failsafe-go",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.9.6"
},
{
"name": "github.com/fsnotify/fsnotify",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.10.1"
},
{
"name": "github.com/glebarez/sqlite",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.11.0"
},
{
"name": "github.com/go-oauth2/oauth2/v4",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v4.5.4"
},
{
"name": "github.com/google/uuid",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "github.com/gorilla/websocket",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.5.3"
},
{
"name": "github.com/graphql-go/graphql",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.8.1"
},
{
"name": "github.com/graphql-go/handler",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.2.4"
},
{
"name": "github.com/mitchellh/mapstructure",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.5.0"
},
{
"name": "github.com/patrickmn/go-cache",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.1.0+incompatible"
},
{
"name": "github.com/pelletier/go-toml/v2",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v2.3.1"
},
{
"name": "github.com/rabbitmq/amqp091-go",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.11.0"
},
{
"name": "github.com/redis/go-redis/v9",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v9.19.0"
},
{
"name": "github.com/robfig/cron/v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.0.1"
},
{
"name": "github.com/spf13/cobra",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.10.2"
},
{
"name": "go.uber.org/zap",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.28.0"
},
{
"name": "golang.org/x/crypto",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.51.0"
},
{
"name": "golang.org/x/tools",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.45.0"
},
{
"name": "gopkg.in/yaml.v3",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v3.0.1"
},
{
"name": "gorm.io/driver/mysql",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "gorm.io/driver/postgres",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.6.0"
},
{
"name": "gorm.io/gorm",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v1.31.1"
},
{
"name": "github.com/go-chi/chi/v5",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v5.3.0"
},
{
"name": "github.com/paulmanoni/viteless",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.2.1"
},
{
"name": "github.com/vmihailenco/msgpack/v5",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v5.4.1"
},
{
"name": "github.com/paulmanoni/deco",
"manifest": "go.mod",
"ecosystem": "go",
"version_constraint": "v0.12.0"
}
],
"all_dependencies": {
"error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
"source": null,
"packages": [],
"collected": false,
"truncated": false,
"total_count": null,
"direct_count": null,
"indirect_count": null
}
},
"maintainership": {
"issues": {
"open_prs": 0,
"merged_prs": 50,
"open_issues": 0,
"closed_ratio": null,
"closed_issues": 0,
"closed_unmerged_prs": 6
},
"bus_factor": 1,
"bot_contributors": 1,
"top_contributors": [
{
"type": "User",
"login": "Manpaul1",
"commits": 646,
"avatar_url": "https://avatars.githubusercontent.com/u/32482735?v=4"
},
{
"type": "User",
"login": "paulmanoni",
"commits": 41,
"avatar_url": "https://avatars.githubusercontent.com/u/63920907?v=4"
}
],
"contributors_sampled": 2,
"top_contributor_share": 0.94
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"ci.yml",
"security.yml"
],
"has_docs_dir": true,
"linter_configs": [
".golangci.yml"
],
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [
"go.sum",
"package-lock.json"
],
"scorecard": {
"checks": [
{
"name": "Binary-Artifacts",
"score": 10,
"reason": "no binaries found in the repo",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
},
{
"name": "Branch-Protection",
"score": 0,
"reason": "branch protection not enabled on development/release branches",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
},
{
"name": "CI-Tests",
"score": 10,
"reason": "2 out of 2 merged PRs checked by a CI test -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
},
{
"name": "CII-Best-Practices",
"score": 0,
"reason": "no effort to earn an OpenSSF best practices badge detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
},
{
"name": "Code-Review",
"score": 0,
"reason": "Found 0/27 approved changesets -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
},
{
"name": "Contributors",
"score": 0,
"reason": "project has 0 contributing companies or organizations -- score normalized to 0",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
},
{
"name": "Dangerous-Workflow",
"score": 10,
"reason": "no dangerous workflow patterns detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
},
{
"name": "Dependency-Update-Tool",
"score": 10,
"reason": "update tool detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
},
{
"name": "Fuzzing",
"score": 0,
"reason": "project is not fuzzed",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
},
{
"name": "License",
"score": 10,
"reason": "license file detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
},
{
"name": "Maintained",
"score": 10,
"reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
},
{
"name": "Packaging",
"score": null,
"reason": "packaging workflow not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
},
{
"name": "Pinned-Dependencies",
"score": 1,
"reason": "dependency not pinned by hash detected -- score normalized to 1",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
},
{
"name": "SAST",
"score": 10,
"reason": "SAST tool is run on all commits",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
},
{
"name": "Security-Policy",
"score": 0,
"reason": "security policy file not detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
},
{
"name": "Signed-Releases",
"score": null,
"reason": "no releases found",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
},
{
"name": "Token-Permissions",
"score": 9,
"reason": "detected GitHub workflow tokens with excessive permissions",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
},
{
"name": "Vulnerabilities",
"score": 0,
"reason": "18 existing vulnerabilities detected",
"documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
}
],
"commit": "cca02623cece32bce88a0bb211ab2e6bfc0c7d3b",
"ran_at": "2026-07-22T09:42:58Z",
"aggregate_score": 5.4,
"scorecard_version": "v5.5.0"
},
"has_codeql_workflow": false,
"has_security_policy": false,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-21T08:55:24Z",
"oldest_open_prs": [],
"last_merged_pr_at": "2026-07-04T07:13:51Z",
"ci_last_conclusion": "FAILURE",
"oldest_open_issues": []
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/paulmanoni/nexus",
"host": "github.com",
"name": "nexus",
"owner": "paulmanoni"
},
"metrics": {
"overall": {
"key": "overall",
"band": "moderate",
"name": "Overall health",
"note": null,
"notes": [],
"value": 60,
"inputs": {
"security": 54,
"vitality": 84,
"community": 26,
"governance": 51,
"engineering": 80
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "good",
"name": "Vitality",
"value": 84,
"weight": 0.22,
"metrics": [
{
"key": "development_activity",
"band": "good",
"name": "Development activity",
"note": null,
"notes": [],
"value": 73,
"inputs": {
"commits_last_year": 688,
"human_commit_share": 1,
"days_since_last_push": 1,
"active_weeks_last_year": 13
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 1 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 1
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "13/52 weeks with commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 13
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "688 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 688
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "excellent",
"name": "Release discipline",
"note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"openssf_scorecard_signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 100,
"inputs": {
"releases_count": 63,
"latest_release_tag": "v1.20.4",
"releases_from_tags": false,
"days_since_latest_release": 32,
"mean_days_between_releases": 2.7
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "63 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 63
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 32 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 32
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~2.7 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 2.7
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "excellent",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "unverified",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": "repository_too_young",
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": null,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "maintenance record not established from the collected data",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_unverified",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "critical",
"name": "Community & Adoption",
"value": 26,
"weight": 0.18,
"metrics": [
{
"key": "popularity",
"band": "critical",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 5,
"inputs": {
"forks": 0,
"stars": 3,
"watchers": 0,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "3 stars",
"points": 4.9,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 3
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "0 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 0
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "0 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 0
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "moderate",
"name": "Community health",
"note": null,
"notes": [],
"value": 50,
"inputs": {
"has_readme": true,
"has_license": true,
"has_contributing": false,
"has_issue_template": false,
"has_code_of_conduct": false,
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 51,
"weight": 0.24,
"metrics": [
{
"key": "maintainer_resilience",
"band": "critical",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 13,
"inputs": {
"bus_factor": 1,
"contributors_sampled": 2,
"top_contributor_share": 0.94
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "1 contributor(s) cover half of all commits",
"points": 9,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 1
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 94% of commits",
"points": 1.4,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 94
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "2 contributors",
"points": 2.7,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 2
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "moderate",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"issue_resolution"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 64,
"inputs": {
"merged_prs": 50,
"open_issues": 0,
"closed_issues": 0,
"issue_closed_ratio": null,
"closed_unmerged_prs": 6
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "no issues or no data",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_issues_or_data",
"params": {}
}
],
"max_points": 46.75
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "50/56 decided PRs merged",
"points": 34.2,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 50,
"decided": 56
}
}
],
"max_points": 38.25
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "Found 0/27 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "at_risk",
"name": "Ownership & stewardship",
"note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"verified_domain"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 43,
"inputs": {
"followers": 3,
"owner_type": "User",
"is_verified": null,
"owner_login": "paulmanoni",
"public_repos": 13,
"account_age_days": 2285
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "personal (user) account",
"points": 10,
"status": "partial",
"details": [
{
"code": "owner_personal",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": "not applicable to user accounts",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_applicable_to_user_accounts",
"params": {}
}
],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "3 followers of paulmanoni",
"points": 4.3,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 3,
"login": "paulmanoni"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "13 public repos, account ~6 yr old",
"points": 20.3,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 13
}
},
{
"code": "account_age_years",
"params": {
"years": 6
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "excellent",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"github.com/paulmanoni/nexus"
],
"ecosystems": "go",
"any_deprecated": false,
"min_days_since_publish": 1
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on go",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "go"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 1 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 1
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "424 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 424
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 80,
"weight": 0.2,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 84,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": false,
"has_linter_config": true,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "2 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 2
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": ".golangci.yml",
"points": 16,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "2 out of 2 merged PRs checked by a CI test -- score normalized to 10",
"points": 20,
"status": "met",
"details": [],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "good",
"name": "Documentation",
"note": null,
"notes": [],
"value": 75,
"inputs": {
"topics": [],
"has_wiki": true,
"homepage": null,
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 54,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "moderate",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Packaging, Signed-Releases. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"packaging",
"signed_releases"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 54,
"inputs": {
"source": "openssf_scorecard",
"checks_evaluated": 16,
"scorecard_version": "v5.5.0",
"checks_inconclusive": 2,
"scorecard_aggregate": 5.4
},
"components": [
{
"key": "binary_artifacts",
"name": "Binary-Artifacts",
"detail": "no binaries found in the repo",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "branch_protection",
"name": "Branch-Protection",
"detail": "branch protection not enabled on development/release branches",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "ci_tests",
"name": "CI-Tests",
"detail": "2 out of 2 merged PRs checked by a CI test -- score normalized to 10",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "cii_best_practices",
"name": "CII-Best-Practices",
"detail": "no effort to earn an OpenSSF best practices badge detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "code_review",
"name": "Code-Review",
"detail": "Found 0/27 approved changesets -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
},
{
"key": "contributors",
"name": "Contributors",
"detail": "project has 0 contributing companies or organizations -- score normalized to 0",
"points": 0,
"status": "missed",
"details": [],
"max_points": 2.5
},
{
"key": "dangerous_workflow",
"name": "Dangerous-Workflow",
"detail": "no dangerous workflow patterns detected",
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "dependency_update_tool",
"name": "Dependency-Update-Tool",
"detail": "update tool detected",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "fuzzing",
"name": "Fuzzing",
"detail": "project is not fuzzed",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "license",
"name": "License",
"detail": "license file detected",
"points": 2.5,
"status": "met",
"details": [],
"max_points": 2.5
},
{
"key": "maintained",
"name": "Maintained",
"detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
"points": 7.5,
"status": "met",
"details": [],
"max_points": 7.5
},
{
"key": "packaging",
"name": "Packaging",
"detail": "packaging workflow not detected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 5
},
{
"key": "pinned_dependencies",
"name": "Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 1",
"points": 0.5,
"status": "partial",
"details": [],
"max_points": 5
},
{
"key": "sast",
"name": "SAST",
"detail": "SAST tool is run on all commits",
"points": 5,
"status": "met",
"details": [],
"max_points": 5
},
{
"key": "security_policy",
"name": "Security-Policy",
"detail": "security policy file not detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 5
},
{
"key": "signed_releases",
"name": "Signed-Releases",
"detail": "no releases found",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 7.5
},
{
"key": "token_permissions",
"name": "Token-Permissions",
"detail": "detected GitHub workflow tokens with excessive permissions",
"points": 6.8,
"status": "partial",
"details": [],
"max_points": 7.5
},
{
"key": "vulnerabilities",
"name": "Vulnerabilities",
"detail": "18 existing vulnerabilities detected",
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.5
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "good",
"name": "AI Readiness",
"value": 80,
"weight": 0,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 0.97,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 42506
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "97 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 97,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "good",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 83,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [
"go.sum",
"package-lock.json"
],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [
"Makefile"
],
"has_devcontainer": false,
"has_linter_config": true,
"typecheck_configs": [
"examples/inertia/web/tsconfig.json",
"examples/petstore-spa/web/tsconfig.json"
],
"agent_commit_share": 0.09,
"toolchain_manifests": [
"di/fxcontainer/go.mod",
"go.mod",
"httpx/ginrouter/go.mod"
],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": "Makefile",
"points": 18,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "Makefile"
}
}
],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": ".golangci.yml",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": ".golangci.yml"
}
}
],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "examples/inertia/web/tsconfig.json, examples/petstore-spa/web/tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples/inertia/web/tsconfig.json, examples/petstore-spa/web/tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": "lockfile",
"points": 10,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "lockfile"
}
}
],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "9 of the last 100 commits agent-authored or agent-credited",
"points": 10,
"status": "met",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 9,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "dependency not pinned by hash detected -- score normalized to 1",
"points": 1,
"status": "partial",
"details": [],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "excellent",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "Go",
"largest_source_bytes": 78620,
"source_files_sampled": 606,
"oversized_source_files": 2
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "Go (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "Go"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "2/606 source files over 60KB",
"points": 54.8,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 606,
"oversized": 2
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "at_risk",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": false,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
}
],
"metrics_version": "1.13.0"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository"
],
"report_type": "repository",
"generated_at": "2026-07-22T09:43:07.369823Z",
"schema_version": "0.26.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/p/paulmanoni/nexus.svg",
"full_name": "paulmanoni/nexus",
"license_state": "standard",
"license_spdx": "MIT"
}