公开记录
软件健康报告模式 0.27.0 · 指标 2.3.1 · 2026-08-01 09:24 UTC

solpbc / solstone-journal

Navigate Life Intelligently

PythonAGPL-3.0★ 17 星标⑂ 7 复刻始于 2025年5月在 GitHub 上查看 ↗
类型命令行工具如何判定

solpbc/solstone-journal 的健康指数为 100 分中的 63 分,处于「中等」区间。 其得分最高的类别是Vitality(96/100),最低的是Security(25/100)。 最近一次更新在今天。 近期的大部分工作由 1 位贡献者完成。

63
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均,再依据公开记录的分布进行校准,使各等级具有百分位含义;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 34(存在风险)的上限。

63
卓越93-100公开记录中的最高层级(约前 5%);基本满足所有检验标准
优秀80-92各方面均表现强劲;仅有少量不足
良好65-79健康;不足之处有限且可控
中等50-64可接受,但存在明显不足;建议进行审查
薄弱35-49多个领域存在实质性薄弱环节
存在风险20-34存在重大薄弱环节;采用时应保持审慎
危急1-19问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

加权总体分 59 经校准后在公布的指数量表上为 63(记录校准 2026-08-02)。

所有权

sol pbc组织
5 关注者30 个公开仓库始于 2026年1月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布标签
PyPIsolstone1.0.216,851780 天前audiotranscriptionscreenshotmultimodalaigemini

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

96卓越 · 占总体的 21%
评分方式
36/36推送新近度 — 最近一次推送于 0 天前
36/36提交节奏 — 52 周中有 52 周有提交
18/18提交量 — 最近一年 6,213 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year6,213
human_commit_share1
days_since_last_push0
active_weeks_last_year52

发布纪律

90优秀
评分方式
27/27有发布版本 — 已发布 69 个发布版本
36/36发布时效 — 最近一次发布版本于 1 天前
27/27发布节奏 — 约每 1.3 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — Project has not signed or included provenance with any releases.
所用输入
releases_count69
latest_release_tagv1.0.20
releases_from_tags
days_since_latest_release1
mean_days_between_releases1.3

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

51中等 · 占总体的 17%

流行度与采用

26存在风险
评分方式
19.5/60星标 — 17 个星标
6.5/25复刻 — 7 个复刻
0/15关注者 — 1 位关注者
所用输入
forks7
stars17
watchers1
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

70良好
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(AGPL-3.0)
18/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
0/6.3PR 模板
所用输入
has_readme
has_license
readme_badges
has_contributing
has_issue_template
has_code_of_conduct
readme_badge_services
has_pull_request_template
评分方式
51.1/80月度下载量 — pypi 合计每月 6,851 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packagessolstone
dependents
ecosystemspypi
total_downloads
monthly_downloads6,851
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

59中等 · 占总体的 23%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0.3/22.5提交分布 — 头号贡献者编写了 99% 的提交
4.1/13.5贡献者广度 — 3 位贡献者
10/10OpenSSF Scorecard:Contributors — project has 4 contributing companies or organizations
所用输入
bus_factor1
contributors_sampled3
top_contributor_share0.988
评分方式
42/42议题解决 — 100% 的议题已关闭
29.5/30PR 接受 — 已裁定的 PR 中 380/387 已合并
0/13Newcomer PR acceptance — 30 天内没有首次贡献者的 PR 得到裁决
0/15OpenSSF Scorecard:Code-Review — Found 0/30 approved changesets -- score normalized to 0
所用输入
merged_prs380
open_issues0
closed_issues2
prs_merged_7d
prs_decided_7d
prs_merged_30d
prs_decided_30d
issue_closed_ratio1
closed_unmerged_prs7
first_time_authors_30d
first_time_prs_merged_30d
first_time_prs_decided_30d
已排除计分(无数据或不适用):newcomer_pr_acceptance。 其余权重已重新归一化。
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
5.6/25所有者影响力 — solpbc 有 5 位关注者
12/25既往记录 — 30 个公开仓库,账户约 0 年
所用输入
followers5
owner_typeOrganization
is_verified
owner_loginsolpbc
public_repos30
account_age_days211
评分方式
25/25已发布且可解析 — pypi 上有 1 个软件包
35/35发布时效 — 最近一次发布于 0 天前
20/20版本历史 — 78 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagessolstone
ecosystemspypi
any_deprecated
min_days_since_publish0

工程质量

基础的工程与文档实践是否到位?

50中等 · 占总体的 19%

工程实践

30存在风险
评分方式
0/24CI 工作流
24/24存在测试
0/16Linter 配置
0/9.6Pre-commit 钩子
0/6.4.editorconfig
0/20OpenSSF Scorecard:CI-Tests — 无数据
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config
已排除计分(无数据或不适用):OpenSSF Scorecard:CI-Tests。 其余权重已重新归一化。

文档

80优秀
评分方式
30/30README
25/25文档目录
15/15文档 / 主页站点 — https://solstone.app
10/10仓库描述
0/10主题标签
0/10Wiki
所用输入
topics
has_wiki
homepagehttps://solstone.app
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

25存在风险 · 占总体的 16%

安全态势

25存在风险
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
0/7.5Branch-Protection — branch protection not enabled on development/release branches
0/2.5CI-Tests — 无数据
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
2.5/2.5Contributors — project has 4 contributing companies or organizations
0/10Dangerous-Workflow — 无数据
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
0/5Packaging — 无数据
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — no SAST tool detected
0/5Security-Policy — security policy file not detected
0/7.5Signed-Releases — Project has not signed or included provenance with any releases.
0/7.5Token-Permissions — 无数据
0/7.5Vulnerabilities — 100 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated14
scorecard_versionv5.5.0
checks_inconclusive4
scorecard_aggregate2.5
已排除计分(无数据或不适用):ci_tests, dangerous_workflow, packaging, token_permissions。 其余权重已重新归一化。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?权重刻意设小(4%):代理工具链是一项真实的维护信号,但完全不具备的仓库仍可达到 100/100。

67良好 · 占总体的 4%
评分方式
45/45代理指令 — AGENTS.md, CLAUDE.md, GEMINI.md, journal/AGENTS.md, journal/CLAUDE.md, journal/GEMINI.md, solstone/apps/import/guides/claude.md, solstone/apps/import/guides/gemini.md, tests/fixtures/journal/AGENTS.md, tests/fixtures/journal/CLAUDE.md, tests/fixtures/journal/GEMINI.md
0/15机器可读文档(llms.txt)
38.9/40可读的提交历史 — 100 次人类提交中有 73 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.73
agent_instruction_filesAGENTS.md, CLAUDE.md, GEMINI.md, journal/AGENTS.md, journal/CLAUDE.md, journal/GEMINI.md, solstone/apps/import/guides/claude.md, solstone/apps/import/guides/gemini.md, tests/fixtures/journal/AGENTS.md, tests/fixtures/journal/CLAUDE.md, tests/fixtures/journal/GEMINI.md
agent_instruction_max_bytes52,085
评分方式
18/18一条命令的引导启动 — Makefile, tests/systemd-test/Makefile
22/22自动化测试
0/11Lint / 格式化配置
0/11静态类型检查
10/10可复现环境 — Dockerfile, lockfile
10/10已体现的代理实践 — 最近 100 次提交中有 11 次由代理编写或署名代理
0/8自动化维护 — 未观察到自动依赖更新
0/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
所用输入
has_nix
has_tests
lockfilesCargo.lock, uv.lock
has_dockerfile
typed_language
bootstrap_filesMakefile, tests/systemd-test/Makefile
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0.11
toolchain_manifestscore/Cargo.toml, core/crates/solstone-core-cli/Cargo.toml, core/crates/solstone-core-indexer-store/Cargo.toml, core/crates/solstone-core-indexer/Cargo.toml, core/crates/solstone-core-journal/Cargo.toml, core/crates/solstone-core-sol-client-cli/Cargo.toml, core/crates/solstone-core-sol-client/Cargo.toml, core/crates/solstone-core-sol-link/Cargo.toml, core/crates/solstone-core-sol/Cargo.toml, core/crates/solstone-core-speakers-analyze/Cargo.toml, core/crates/solstone-core-speakers-onnx/Cargo.toml, core/crates/solstone-core-speakers/Cargo.toml, core/crates/solstone-core-spl/Cargo.toml, core/crates/solstone-core/Cargo.toml
dependency_bot_commit_share0
评分方式
0/45可类型检查的代码 — Python,未配置类型检查
52.5/55可控的文件大小 — 采样的 1,751 个源文件中有 81 个超过 60KB
所用输入
primary_languagePython
largest_source_bytes251,353
source_files_sampled1,751
oversized_source_files81

关键数据

17GitHub 星标
3贡献者
6,213最近 12 个月提交数
0距最近推送天数
69发布版本数
1巴士系数(bus factor)
0开放议题
crates.io, PyPI软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository
  • deps.dev does not index pypi:solstone@1.0.21; advisories assessed against the repository dependency graph instead

更多细节

Star 与 Fork 历史 0 ★ / 7 ⇿
0Star
7Fork
48发布

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

1234567712026-012026-042026-07
主版本 0次版本 3修订 45
OpenSSF Scorecard 2.5 / 10
2.5综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-08-01 09:23 UTC

10Binary-Artifactsno binaries found in the repo
0Branch-Protectionbranch protection not enabled on development/release branches
不适用CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
10Contributorsproject has 4 contributing companies or organizations
不适用Dangerous-Workflowno workflows found
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
不适用Packagingpackaging workflow not detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTno SAST tool detected
0Security-Policysecurity policy file not detected
0Signed-ReleasesProject has not signed or included provenance with any releases.
不适用Token-PermissionsNo tokens found
0Vulnerabilities100 existing vulnerabilities detected
直接依赖 9
注册表软件包版本约束清单文件
PyPIsetproctitlepyproject.toml
PyPItyperpyproject.toml
PyPIrequestspyproject.toml
PyPIpsutilpyproject.toml
PyPIuserpath>=1.9.2,<2pyproject.toml
PyPIsolstone-core==1.0.21pyproject.toml
PyPIsolstone-core==1.0.21pyproject.toml
PyPIsolstone-core==1.0.21pyproject.toml
PyPIsolstone-core-unsupported-platform==1.0.21pyproject.toml
全部依赖 未采集

本报告未能采集到解析后的依赖集合:GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 73016,
      "has_wiki": false,
      "homepage": "https://solstone.app",
      "languages": {
        "CSS": 145070,
        "HTML": 1711393,
        "Rust": 2194504,
        "Shell": 55059,
        "Swift": 11115,
        "Python": 23243736,
        "Makefile": 49420,
        "Dockerfile": 3089,
        "JavaScript": 933352
      },
      "pushed_at": "2026-08-01T09:23:17Z",
      "created_at": "2025-05-26T02:31:17Z",
      "owner_type": "Organization",
      "updated_at": "2026-08-01T08:51:27Z",
      "description": "Navigate Life Intelligently",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "AGPL-3.0",
      "default_branch": "main",
      "license_spdx_raw": "AGPL-3.0",
      "primary_language": "Python",
      "significant_languages": [
        "Python"
      ]
    },
    "owner": {
      "blog": "https://solpbc.org/",
      "name": "sol pbc",
      "type": "Organization",
      "login": "solpbc",
      "company": null,
      "location": null,
      "followers": 5,
      "avatar_url": "https://avatars.githubusercontent.com/u/252481466?v=4",
      "created_at": "2026-01-01T17:58:09Z",
      "is_verified": null,
      "public_repos": 30,
      "account_age_days": 211
    },
    "license": {
      "state": "standard",
      "spdx_id": "AGPL-3.0",
      "raw_spdx": "AGPL-3.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v1.0.20",
          "kind": "patch",
          "published_at": "2026-07-31T06:45:30Z"
        },
        {
          "tag": "v1.0.19",
          "kind": "patch",
          "published_at": "2026-07-29T06:49:43Z"
        },
        {
          "tag": "v1.0.18",
          "kind": "patch",
          "published_at": "2026-07-28T16:45:37Z"
        },
        {
          "tag": "v1.0.17",
          "kind": "patch",
          "published_at": "2026-07-26T07:44:38Z"
        },
        {
          "tag": "v1.0.16",
          "kind": "patch",
          "published_at": "2026-07-25T23:14:40Z"
        },
        {
          "tag": "v1.0.15",
          "kind": "patch",
          "published_at": "2026-07-25T16:14:54Z"
        },
        {
          "tag": "v1.0.13",
          "kind": "patch",
          "published_at": "2026-07-24T06:24:02Z"
        },
        {
          "tag": "v1.0.12",
          "kind": "patch",
          "published_at": "2026-07-23T05:11:20Z"
        },
        {
          "tag": "v0.9.1",
          "kind": "patch",
          "published_at": "2026-07-22T16:12:25Z"
        },
        {
          "tag": "v0.9.0",
          "kind": "minor",
          "published_at": "2026-07-19T19:25:30Z"
        },
        {
          "tag": "v0.8.9",
          "kind": "patch",
          "published_at": "2026-07-17T06:42:19Z"
        },
        {
          "tag": "v0.8.8",
          "kind": "patch",
          "published_at": "2026-07-16T12:43:02Z"
        },
        {
          "tag": "v0.8.7",
          "kind": "patch",
          "published_at": "2026-07-15T13:32:05Z"
        },
        {
          "tag": "v0.8.6",
          "kind": "patch",
          "published_at": "2026-07-14T12:56:50Z"
        },
        {
          "tag": "v0.8.5",
          "kind": "patch",
          "published_at": "2026-07-14T12:08:11Z"
        },
        {
          "tag": "v0.8.4",
          "kind": "patch",
          "published_at": "2026-07-12T07:02:49Z"
        },
        {
          "tag": "v0.8.3",
          "kind": "patch",
          "published_at": "2026-07-10T17:35:34Z"
        },
        {
          "tag": "v0.8.2",
          "kind": "patch",
          "published_at": "2026-07-08T05:15:55Z"
        },
        {
          "tag": "v0.8.1",
          "kind": "patch",
          "published_at": "2026-07-07T05:32:35Z"
        },
        {
          "tag": "v0.8.0",
          "kind": "minor",
          "published_at": "2026-07-07T05:10:10Z"
        },
        {
          "tag": "v0.7.0",
          "kind": "minor",
          "published_at": "2026-07-05T14:32:07Z"
        },
        {
          "tag": "v0.6.24",
          "kind": "patch",
          "published_at": "2026-07-04T19:35:23Z"
        },
        {
          "tag": "v0.6.23",
          "kind": "patch",
          "published_at": "2026-07-04T17:19:14Z"
        },
        {
          "tag": "v0.6.22",
          "kind": "patch",
          "published_at": "2026-07-03T07:49:35Z"
        },
        {
          "tag": "v0.6.21",
          "kind": "patch",
          "published_at": "2026-07-02T06:53:29Z"
        },
        {
          "tag": "v0.6.20",
          "kind": "patch",
          "published_at": "2026-07-02T01:33:00Z"
        },
        {
          "tag": "v0.6.19",
          "kind": "patch",
          "published_at": "2026-07-01T05:48:56Z"
        },
        {
          "tag": "v0.6.18",
          "kind": "patch",
          "published_at": "2026-06-30T09:06:35Z"
        },
        {
          "tag": "v0.6.17",
          "kind": "patch",
          "published_at": "2026-06-29T14:55:22Z"
        },
        {
          "tag": "v0.6.16",
          "kind": "patch",
          "published_at": "2026-06-28T07:02:25Z"
        },
        {
          "tag": "v0.6.15",
          "kind": "patch",
          "published_at": "2026-06-27T05:50:04Z"
        },
        {
          "tag": "v0.6.14",
          "kind": "patch",
          "published_at": "2026-06-26T05:35:17Z"
        },
        {
          "tag": "v0.6.13",
          "kind": "patch",
          "published_at": "2026-06-25T04:57:23Z"
        },
        {
          "tag": "v0.6.12",
          "kind": "patch",
          "published_at": "2026-06-24T04:27:47Z"
        },
        {
          "tag": "v0.6.11",
          "kind": "patch",
          "published_at": "2026-06-23T01:20:46Z"
        },
        {
          "tag": "v0.6.10",
          "kind": "patch",
          "published_at": "2026-06-22T05:38:56Z"
        },
        {
          "tag": "v0.6.9",
          "kind": "patch",
          "published_at": "2026-06-20T02:36:03Z"
        },
        {
          "tag": "v0.6.8",
          "kind": "patch",
          "published_at": "2026-06-19T05:15:00Z"
        },
        {
          "tag": "v0.6.7",
          "kind": "patch",
          "published_at": "2026-06-18T04:08:59Z"
        },
        {
          "tag": "v0.6.5",
          "kind": "patch",
          "published_at": "2026-06-17T06:39:19Z"
        },
        {
          "tag": "v0.6.4",
          "kind": "patch",
          "published_at": "2026-06-15T19:49:01Z"
        },
        {
          "tag": "v0.6.3",
          "kind": "patch",
          "published_at": "2026-06-15T04:59:25Z"
        },
        {
          "tag": "v0.6.2",
          "kind": "patch",
          "published_at": "2026-06-15T03:36:29Z"
        },
        {
          "tag": "v0.6.1",
          "kind": "patch",
          "published_at": "2026-06-15T01:04:03Z"
        },
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-06-14T23:42:48Z"
        },
        {
          "tag": "v0.5.6",
          "kind": "patch",
          "published_at": "2026-06-14T17:48:03Z"
        },
        {
          "tag": "v0.5.5",
          "kind": "patch",
          "published_at": "2026-06-14T05:16:26Z"
        },
        {
          "tag": "v0.5.4",
          "kind": "patch",
          "published_at": "2026-06-12T20:40:31Z"
        },
        {
          "tag": "v0.5.3",
          "kind": "patch",
          "published_at": "2026-06-10T07:11:28Z"
        },
        {
          "tag": "v0.5.2",
          "kind": "patch",
          "published_at": "2026-06-06T05:24:39Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2026-06-05T13:26:24Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-06-05T13:11:29Z"
        },
        {
          "tag": "v0.4.10",
          "kind": "patch",
          "published_at": "2026-06-02T22:19:23Z"
        },
        {
          "tag": "v0.4.9",
          "kind": "patch",
          "published_at": "2026-06-02T02:27:34Z"
        },
        {
          "tag": "v0.4.8",
          "kind": "patch",
          "published_at": "2026-06-01T05:56:31Z"
        },
        {
          "tag": "v0.4.7",
          "kind": "patch",
          "published_at": "2026-06-01T03:14:53Z"
        },
        {
          "tag": "v0.4.6",
          "kind": "patch",
          "published_at": "2026-05-31T15:58:30Z"
        },
        {
          "tag": "v0.4.5",
          "kind": "patch",
          "published_at": "2026-05-30T17:32:40Z"
        },
        {
          "tag": "v0.4.4",
          "kind": "patch",
          "published_at": "2026-05-28T05:16:38Z"
        },
        {
          "tag": "v0.4.3",
          "kind": "patch",
          "published_at": "2026-05-27T06:48:42Z"
        },
        {
          "tag": "v0.4.2",
          "kind": "patch",
          "published_at": "2026-05-27T02:26:16Z"
        },
        {
          "tag": "v0.4.1",
          "kind": "patch",
          "published_at": "2026-05-27T00:14:08Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-05-26T22:39:11Z"
        },
        {
          "tag": "v0.3.9",
          "kind": "patch",
          "published_at": "2026-05-25T19:34:26Z"
        },
        {
          "tag": "v0.3.8",
          "kind": "patch",
          "published_at": "2026-05-22T05:46:22Z"
        },
        {
          "tag": "v0.3.6",
          "kind": "patch",
          "published_at": "2026-05-18T15:58:41Z"
        },
        {
          "tag": "v0.3.5",
          "kind": "patch",
          "published_at": "2026-05-18T01:15:46Z"
        },
        {
          "tag": "v0.3.4",
          "kind": "patch",
          "published_at": "2026-05-16T22:48:36Z"
        },
        {
          "tag": "v0.3.3",
          "kind": "patch",
          "published_at": "2026-05-16T15:20:37Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "827cd6fe1a0ecaa44c79812d4eb3cdba6b041037",
          "body": "Bump the workspace, the Python packages and the tombstone sdist to 1.0.21,\nregenerate both lockfiles, and land the release notes for this cut.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(packaging): cut release metadata to 1.0.21",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T08:42:08Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "70785e18ecd09be0874b660bd461e9d00235edcd",
          "body": "device_superseded no longer exists as a producer or a documented event, so asserting it is not emitted is vacuously true for every input. The two test_duplicate_label_pair_keeps_predecessor_authorized_* tests already fail if auto-retire is reintroduced, and they fail on the certificate that actually got revoked rather than on an event name.\n\ndevice_superseded now has zero matches repo-wide. Also annotate the label-addressed unpair helper with the Flask test-client response type.",
          "is_bot": false,
          "headline": "test(network): drop stale device-superseded assertion",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T08:16:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "46657e99153bf8d99c6f1af2929c2798f2902506",
          "body": "Resolve label-addressed unpair against display_label multiplicity instead of base-label equality. A name the owner can see remains usable when it is unique after migration; only an un-migrated or hand-edited ledger can still be ambiguous. The lookup deliberately widens blank assigned labels too: bec\n[…]\n_only compares enum lists by equality. link.unpair and link.devices are not among the bundle's 8 projected operations, so only the fragment.link source digest and projection-builder self-digest moved.",
          "is_bot": false,
          "headline": "fix(link): stop revoking device certs on a bare label match",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T08:10:01Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0e38f0520485f585a40e33b2cec072a70a045e46",
          "body": "The auth.py docstring's label_ordinal entry now states the rule the code enforces: optional positive int, absent or invalid loads as 1, and omitted from the payload when 1. It also lines up with the JSON example block's comment column.\n\nrename()'s not-paired branch now tests updated is None rather than relying on ClientEntry truthiness. No behavior change.",
          "is_bot": false,
          "headline": "style(link): state the label_ordinal contract and the rename null check",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T06:52:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f94d88d31b095cbe0058f0b5aeed1d5f7e08385",
          "body": "…tion\n\nDeclare the link.devices 200 response item schema, including display_label and device_label, so paired-device payloads have a concrete generated contract.\n\nAdd the first OperationSpec for POST /app/network/rename, covering the persisted label response and the route's structured error reason c\n[…]\nenAPI artifacts with the network contract update. Bump the observer client bundle semver to 5.0.7 because the bundle compatibility gate requires a version change when generated bundle content changes.",
          "is_bot": false,
          "headline": "feat(network): declare link.devices item schema and link.rename opera…",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T06:52:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6b9deebbc1394f75568c11d59f797013c5b8983a",
          "body": "Store label_ordinal on ClientEntry and persist it through the authorized_clients.json writer, omitting the field when the ordinal is 1.\n\nAllocate ordinals inside the existing hold_lock window in add, add_browser, and update_label so concurrent writers and secure-listener touch_last_seen preserve per\n[…]\nsuffix remains renameable.\n\nReturn persisted labels from /rename and link pair_complete, and add an explicit idempotent backfill_label_ordinals repair invoked once per process from start_link_runtime.",
          "is_bot": false,
          "headline": "feat(link): stored label ordinal disambiguates same-named devices",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T06:52:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "288471c48f98f501fe884238731433c285ff52e6",
          "body": "…m anywhere\n\nThe secure listener reports a loopback peer the same way it reports a relay\ntunnel, because a relay tunnel terminates on loopback. Reach derived from the\npeer therefore read as anywhere for a machine pairing with itself, so the\nowners own computer would have appeared in their device lis\n[…]\nver-correct.\n\nAlso stop rebuilding the nonce field by field when marking it used: that\nreconstruction silently dropped every field added after it was written, which\nis exactly what it did to this one.",
          "is_bot": false,
          "headline": "fix(link): a machine paired with itself is at home, not reachable fro…",
          "author_name": "Jer Miller",
          "author_login": null,
          "committed_at": "2026-08-01T06:13:12Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "366969b02e5d096786122117e933911c321d0be7",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/main' into spl-rust-lane-a",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T05:31:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bc1de8f7b76d790688a85ab2334b2c00413dfbbb",
          "body": "A completed conversion wave declares the Python roots it removed. The check\nasked the filesystem whether those directories still existed, so a checkout\nthat deleted the sources but left ignored build output behind reported the\nwave as unfinished. The failure named the wave rather than the working tr\n[…]\nunt, so a\ngenuine leftover fails exactly as before, and the message now names an\noffending file. When git cannot answer, fall back to the on-disk test rather\nthan passing a retirement we cannot prove.",
          "is_bot": false,
          "headline": "fix(checks): retirement is a repository fact, not a disk fact",
          "author_name": "Jer Miller",
          "author_login": null,
          "committed_at": "2026-08-01T05:26:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "1bfb49f05967cd5454ed91214ad9a3707cab2275",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/main' into spl-rust-lane-a",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T05:22:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c5f3da4ccb4faba3638bff61a8908a90926715ff",
          "body": "A connected home stopped re-reporting its health snapshot once it went quiet.\nThe web layer treats a snapshot older than its freshness window as evidence the\nlink is down, so `_derive_spl_relay_state` returned `offline` for a perfectly\nhealthy connected link — and nothing else re-emits between tunne\n[…]\nconfigurable so tests that\nassert exact event sequences are unaffected. The regression test drives a real\nlisten socket that never sends a control frame and was watched failing with the\nloop disabled.",
          "is_bot": false,
          "headline": "fix(spl): keep refreshing health while the listen socket is up",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T05:13:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "38f47fb5857844a254bb5f2a748278facd2a42aa",
          "body": "Assert the shared bound-observer registration helper writes a cert-class device binding with the expected fingerprint. This prevents helper regressions from silently minting unbound records while downstream tests continue authenticating on bearer keys.",
          "is_bot": false,
          "headline": "test(observer): guard bound registration helper",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T04:03:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "21125838e05718acdf69043c01486928ad2248fd",
          "body": "Update the network operation contract for same_machine pair-start requests and revoked observer details on unpair. Regenerate the observer client bundle and OpenAPI artifacts with the patch semver bump.",
          "is_bot": false,
          "headline": "chore(contract): refresh observer client contract",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T04:03:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "19d29f6f1d2996bbfd73be5569a1ad56c2aa2910",
          "body": "Keep the observer create route but return the retired-operation response, remove the workspace add form, and migrate tests to registration helpers that preserve bound and unbound shapes. Refuse URL export destinations and keep peer-label export coverage on the live path.",
          "is_bot": false,
          "headline": "fix(observer): refuse manual observer minting",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T04:03:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8650467c26ef9018ce514da05a32125c5d227327",
          "body": "Expose device_binding_kind across observer CLI and capture health surfaces without changing status semantics. Return revoked observer stream details from unpair, carry partial failure payloads, and render the new response in the native command.",
          "is_bot": false,
          "headline": "feat(observer): surface bindings in observer health",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T04:03:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1f9b4aec969574feac47407eac22594e6933455",
          "body": "Allow local callers to request a loopback pair link explicitly with same_machine while preserving the existing posture-based paths when the field is absent. Harden the shared loopback predicate for pair-start and local-endpoints by rejecting proxy-forwarding headers.",
          "is_bot": false,
          "headline": "feat(network): add same-machine pair links",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T04:03:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "22c01091f5f87d1abffff17ac4e1d3d94f9cca94",
          "body": null,
          "is_bot": false,
          "headline": "Merge remote-tracking branch 'origin/main' into spl-rust-lane-a",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T03:46:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2b6e9b3af8b8f76795eba91ab5b520118aaae6ae",
          "body": "The verbose and debug flags were parsed and never read. A complete successful\nlifecycle — start, listen open, tunnel brokered, bytes both ways, posture flip,\nclean shutdown — produced zero bytes of output, while the Python it replaces\nlogged thirty-three lifecycle messages. The supervisor launches t\n[…]\ng for.\n\nVerified live: the reconnect loop this immediately exposed turned out to be two\ndaemons sharing one instance id in the test rig, which is precisely the class of\nproblem the silence was hiding.",
          "is_bot": false,
          "headline": "fix(spl): make the supervised service observable at -v",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T03:39:05Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ab0fdd88925ef02a1acfdba8ea720105fd7f24a8",
          "body": "…tory\n\nThe zero-unsafe inventory gate matches the bare substring, so prose using the\nword tripped it. Reworded rather than loosened: making the gate token-precise\nwould suit one crate's comment at every crate's expense, and the invariant it\nguards is real — the workspace forbids unsafe outright, and\n[…]\ncontains any.\n\nThe replacement also says more than the original: an unreadable posture fails\nclosed and does not open the listener, which is the gate's security property\nrather than an aside about it.",
          "is_bot": false,
          "headline": "docs(spl): reword the posture-read comment away from the unsafe inven…",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T02:26:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "9527c8e500ea8f2a734abfea2fd3eb16c6baf03e",
          "body": "The health vocabulary moved from the spl package to the link package, which\nchanges where those imports sort. Import ordering is enforced by the lint gate,\nwhich is a separate step from the formatter and from a focused per-file run.",
          "is_bot": false,
          "headline": "style(spl): reorder the link-health imports after the module move",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T02:09:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a0fbe51e7d2f92471f16216df5fe8a32e5aa6c47",
          "body": "Caught by the repository formatting gate — the same step that caught the\nforwarding test. Behaviour unchanged; re-verified green against both sources\nafter reformatting.",
          "is_bot": false,
          "headline": "style(spl): format the health-vocabulary gate",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T02:08:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "54784057a2e90a2feb0ffd9c79c22cb1c0062844",
          "body": "The formatter wraps the handshake-result lambda across three lines. Caught by the\nrepository formatting gate, which is a separate step from the lint run.",
          "is_bot": false,
          "headline": "style(spl): format the native-service forwarding test",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T02:06:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4c9f777a08e5e8a26bf7789659b53b864ff3247a",
          "body": "After the native cutover the reason codes, the callosum event name, and the\noffline subset live in two languages: the native service emits them, and the web\nlayer consumes them to classify link state into owner-visible copy. Nothing else\nmakes them agree, and drift is silent — a reason code that sto\n[…]\nr reason\ndrift, a language-only reason, an event-name change, an offline-subset change,\nand a missing source file. The last matters most — renaming a source cannot\nsilently turn the gate into a no-op.",
          "is_bot": false,
          "headline": "test(spl): gate the link-health vocabulary across both implementations",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T02:06:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d34d55390c0025bfd04942468cbb049e6b83da26",
          "body": "The lane's running work log is operator-process instrumentation — accepted-unit\nhistory, delegate review outcomes, contract-rework accounting — not a product\nartifact, and every publicly visible file in this repo is public surface.\n\nIt also carried an operator-role reference in its own text, which i\n[…]\nxactly the\nclass the public-file rule covers. Preserved operator-side; nothing about the\nconversion's result is lost from this repo, which records it in the code, the\ntests, and the divergence ledger.",
          "is_bot": false,
          "headline": "chore(spl): keep the conversion work log out of the product tree",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T02:04:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "db4b26dfdab76c5e0943651a6226338754c2c15a",
          "body": "…oad key\n\nThe browser transport removal deleted solstone/think/link/upload_key.py, but the\njournal-io access gate still listed it as a direct owner. OWNER_FILES is a plain\nmembership set with no staleness check, so the entry never matches and never\nflags — it rots silently rather than failing.\n\nHarmless in isolation, since an allowlist entry for a file that does not exist\npermits nothing. Removed so the list keeps describing the tree it gates.",
          "is_bot": false,
          "headline": "chore(spl): drop the stale journal-io owner entry for the removed upl…",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T02:03:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d3c3a3c6a71f1b4d2635365321f19f191e487f1f",
          "body": null,
          "is_bot": false,
          "headline": "Complete U6 SPL transport cutover",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T02:01:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d30a4abf49d557d2fdae2b3c90a2ea4489c429e",
          "body": null,
          "is_bot": false,
          "headline": "Add U5 native service composition",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T00:57:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "02358be5d583d9c3d685782f0ba153f3edc004cc",
          "body": null,
          "is_bot": false,
          "headline": "Fix U4 relay lifecycle events",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T00:33:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a158aa5c2112776885068668b2b477fbe46ead8e",
          "body": null,
          "is_bot": false,
          "headline": "Update U4 transport scope docs",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T00:11:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f0501b86a9afb23075e625ef6eb0bd51dbe84770",
          "body": null,
          "is_bot": false,
          "headline": "Add U4 TLS relay client",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T00:11:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e32fb0c49d21e09ad34475ee89f3e8812929fe17",
          "body": null,
          "is_bot": false,
          "headline": "Record SPL scope redirect",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-08-01T00:03:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be77c444cc65f21c7c11c8491e679f3435ec638f",
          "body": null,
          "is_bot": false,
          "headline": "Checkpoint held U2 dependency rework",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T23:55:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "79f28f842df59f4754415490d402dd8fcf2e8e4e",
          "body": null,
          "is_bot": false,
          "headline": "Checkpoint U2 BlobDeps contract rework",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T23:45:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d2f546b5cd5dc9c17a538ed127519002d49c1ad8",
          "body": "Adds a passing case for a member entry that renames an inherited SPL dependency (package set, workspace = true, no source or selector keys). It is accepted because the entry draws its source and tag from the workspace pin and its lockfile record is keyed by the real package name, so both remain governed by the existing workspace and lockfile checks.\n\nRecords that boundary as an invariant so the guard is not later tightened into a false positive.\n\nRemoves an unused test helper.",
          "is_bot": false,
          "headline": "test(rust): pin the SPL guard's member-inheritance boundary",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T23:31:00Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a788551edbffa6232f64c284fd0d525b06f5dddf",
          "body": "Add a repository guard that derives the approved SPL source and tag from core/Cargo.toml [workspace.dependencies], keeping the tag value out of the guard as a literal.\n\nBind both core/Cargo.lock SPL records to that derived tag and to one shared resolved commit.\n\nRequire member manifests to inherit v\n[…]\ncement, and tracked in-tree SPL package copies.\n\nThe existing pin, lockfile, and cargo-deny source rail are unchanged. The guard is wired into install-checks, so make ci and make verify both cover it.",
          "is_bot": false,
          "headline": "feat(rust): guard the workspace-owned SPL tag pin",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T23:31:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "aac8b4b3b35b2f3da62fd15d10812fdf7be3471f",
          "body": null,
          "is_bot": false,
          "headline": "Add U1 HPKE process dispatch",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T23:07:02Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6a53e68941c617ffeb3948b01d32a753de6c0aa8",
          "body": null,
          "is_bot": false,
          "headline": "Add U4 WebSocket transport halves",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T23:04:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dad8b4a155a912dd222c192191947c8b5a88c832",
          "body": "…essages\n\nMalformed requirement strings in the derived pin now raise the installer error instead of surfacing an InvalidRequirement traceback during make install.\n\nThe malformed-metadata error names what project.dependencies actually contained, and the interpreter guard that binds marker evaluation to the target venv now has negative test coverage.",
          "is_bot": false,
          "headline": "fix(install): speakers-analyze helper installer fails with specific m…",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:59:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6edc225a7def406524b3f40435178ff7dcde9697",
          "body": null,
          "is_bot": false,
          "headline": "Add U5 service supervisor",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:56:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "400d5eb47b048ec99ae241c5cdcb883f1c57c822",
          "body": "… helper\n\nuv sync prunes the workspace-excluded helper, leaving source checkouts with a journal doctor blocker and an EX_CONFIG supervisor exit.\n\nAdd make speakers-analyze-helper to reinstall the published wheel using a pin derived at run time from packages/solstone-journal/pyproject.toml and uv pip\n[…]\nter uv syncs do not prune it.\n\nUpdate the speakers-analyze repair text to keep the packaged message unchanged while source checkouts point contributors to make speakers-analyze-helper or make install.",
          "is_bot": false,
          "headline": "fix(install): source checkouts install the published speakers-analyze…",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:52:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e937b1cfe89ccd782ee251b4fb30a8e4eaa6c147",
          "body": null,
          "is_bot": false,
          "headline": "Add U4 split tunnel pipe",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:50:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dc4481dfa5572b846343e73a6c87d5e76e438e30",
          "body": null,
          "is_bot": false,
          "headline": "Add SPL parity corpus fixtures",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:48:49Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ddf7653564b5e8223413b8019e53eb8f7c74580",
          "body": null,
          "is_bot": false,
          "headline": "Add U2 blob receiver",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:47:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "deb8238ad09e2586e3a4410ab3aa352721616d14",
          "body": null,
          "is_bot": false,
          "headline": "Add U1 framed HPKE command core",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:36:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3a98a4dd6c14341ebd627e72616ff0f67d51e292",
          "body": null,
          "is_bot": false,
          "headline": "Add U2 split WebSocket sink",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:33:10Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "440e3f3efbfce0f44986b2240397c38df2a0e5e6",
          "body": null,
          "is_bot": false,
          "headline": "Register accepted SPL conversion units",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:31:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84a4dd30137deda8c931ed6ea439fd7655322edb",
          "body": null,
          "is_bot": false,
          "headline": "Add U1 SPL command parsing",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:31:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "61c149a5e2ab4e6df6604bd4b2be7f460f317d44",
          "body": null,
          "is_bot": false,
          "headline": "Add U5 supervision support",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:31:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "51514ba56b5db84db6bd76bd7619450677c90408",
          "body": null,
          "is_bot": false,
          "headline": "Add U4 relay dispatch support",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:31:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1ff0a344b43618e29315d9be8fd9eb27b2ca4940",
          "body": null,
          "is_bot": false,
          "headline": "Add U2 blob preparation units",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:31:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3600657960ce73bf3f7e91721c7e93dad559541b",
          "body": null,
          "is_bot": false,
          "headline": "Add U3 buffering admission and health",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:31:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3c009c0ab1664cc581186d783639139b7411a69",
          "body": null,
          "is_bot": false,
          "headline": "Add U2 blob wire framing",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:31:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6f7c313c13e7e70c302d42a942853f33c0db88cb",
          "body": null,
          "is_bot": false,
          "headline": "Add U1 HPKE base and auth primitives",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T22:30:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c7349edf5ef1d7a9b273eb07e419ada4998e6ff0",
          "body": null,
          "is_bot": false,
          "headline": "docs: align owner-facing terminology canon",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T21:31:45Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3f4804a354a2fb372cbd46a734864454c530b62f",
          "body": null,
          "is_bot": false,
          "headline": "docs: retire customer-facing observer wording",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T21:24:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5ed4dacb8012d2af862ab7b9ec9b17afd0d60e67",
          "body": "…provider\n\nThe 60s provider truth observation re-ran while the local model server was running and compared available system RAM against the 13.00 GiB MLX admission floor, after the provider's own approximately 9.74 GiB resident footprint had already been subtracted from that available-memory reading\n[…]\nng this removes; the eviction was accidental and fired at 13 GiB available, nowhere near OOM, so the OS now handles memory pressure.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(providers): admission-only block reasons no longer evict a ready …",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T20:51:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c3b7cc6e50961fb36981bcaa7103aa8ff510c400",
          "body": "The direct dial previously bounded only reaching the peer, so a peer that\naccepted the connection and never spoke TLS could hold a dial open for the\ncallers whole budget instead of failing over. v0.4.1 bounds the handshake\nitself on both the direct and control-plane dials.\n\nNo wire behavior, framing, flow control, pinning, or API change.",
          "is_bot": false,
          "headline": "chore(deps): adopt spl-rust v0.4.1",
          "author_name": "Jer Miller",
          "author_login": null,
          "committed_at": "2026-07-31T20:28:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2bc42ee10275d7b4c84b6c5ffdebcafd8efd9e55",
          "body": "statement_embeddings.payload_format and statement_embeddings.dtype were validated against legacy Python literals. The Rust helper emits raw-f32le-row-major-v1 and float32-le, while the adapter wrongly required f32le and float32.\n\ncore/crates/solstone-core-speakers-analyze/src/lib.rs remains the sour\n[…]\nscripts/release_install_smoke.py now share one constant pair in solstone/apps/speakers/encoder_config.py, pinned to that Rust source by tests/test_speakers_analyze_wire_constants.py.\n\nCarrier: vpe-98.",
          "is_bot": false,
          "headline": "fix(speakers): align analyze wire literals",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T19:45:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "adf2e9c5ff88d63aa03872c53bfe08cee7017bc3",
          "body": "Follow-on to #391. The detail endpoint's second metadata read sat outside\nthe not-found guard, so an import removed between the two reads raised\ninstead of returning import_not_found. Both reads now share the guard;\nstatus resolution stays outside it, since it touches no filesystem.\n\nAdds the server\n[…]\nitself\nreturns status, error and error_stage — the half a later refactor drops\nsilently. Two tests now pin it: an unfinished import reads running, and a\nfailed one carries its error and stage through.",
          "is_bot": false,
          "headline": "fix(import): guard both detail reads and pin the status contract",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T16:12:27Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a114a2ce85427915d91a018043b9d4918fe521d8",
          "body": null,
          "is_bot": false,
          "headline": "feat(import): enhance import status handling and UI updates.",
          "author_name": "ha-ye",
          "author_login": "ha-ye",
          "committed_at": "2026-07-31T12:49:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d44ef202b64f1ad0729dd6faddae5eeee7ac4a86",
          "body": null,
          "is_bot": false,
          "headline": "chore(release): witness transparency for 1.0.20",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T06:50:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "354c775f6602ac207ce37160a0fc4ceeb9569c2c",
          "body": "The differential harness proof deliberately creates a run directory under the\nrepository tmp/ scratch root, because proving the oracle ignores concurrent\n__pycache__ churn requires an in-repo location. Under xdist that directory\nappears and disappears inside an unrelated consumer window, so the verd\n[…]\n and joins the existing\nruntime-directory exclusions for the same reason each of those was added. The\nin-repo write invariant remains asserted directly by the harness in-repo\ndestination refusal test.",
          "is_bot": false,
          "headline": "test(speakers): exclude gitignored repo scratch from the no-write oracle",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T02:56:31Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "57432d517e92dd6059d107377d77a22857f1cc7b",
          "body": null,
          "is_bot": false,
          "headline": "feat(packaging): cut release metadata to 1.0.20",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T02:43:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "73af7c07741ab7a73ec87e74a5b202ffe6132439",
          "body": "Bump BUNDLE_SEMVER 5.0.4 -> 5.0.5 after the reason-code vocabulary text moved. That file is a digest-pinned producer, so the manifest must record the new producer digest even though the route projection is unchanged.\n\nRegenerated the contract bundle; projection, vectors, and wire-behavior fixtures regenerated byte-identical, so only the manifest moved.",
          "is_bot": false,
          "headline": "chore(observer): re-pin observer client contract",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T01:57:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6104e6b4d386912d511e322c19eb7351a6d24e3b",
          "body": "local_request_only is used for callers that fail register admission and for admitted callers that target a stream already bound elsewhere. Keep the shared owner-facing error general enough for both cases, while the response detail names the specific refusal.\n\nUpdate the retired observer create guidance and unreleased notes so they describe the shipping behavior: local observers can register directly, remote observers use pairing, and existing streams cannot be taken over by another device.",
          "is_bot": false,
          "headline": "fix(observer): clarify register refusal copy",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T01:56:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "27412a72294c9fa4167473803293e30ec58d136e",
          "body": "Bump BUNDLE_SEMVER 5.0.3 -> 5.0.4 after the register admission and observer auth changes moved digest-pinned producers. The manifest now records updated digests for observer_bundle.py, the observer contract fragment and extension, observer routes, observer utils, root SSE, and the reason-code vocabu\n[…]\ncription matches the local/device admission behavior. The recorded vectors and wire-behavior fixtures regenerated byte-identical and are not changed, keeping the bound-record recording surface stable.",
          "is_bot": false,
          "headline": "chore(observer): re-pin observer client contract",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T01:43:09Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6b35189d1ea87170fe1433f8f91c54ff36f7f15a",
          "body": "Unbound records are valid handle-authenticated observers, so operator surfaces should not treat a missing device binding as degraded or as a separate status. Capture health now derives freshness and ingest rejection state without adding an unbound degradation.\n\nDoctor and the observer CLI no longer read or count unbound state. A fresh unbound observer reports connected like any other active observer, while revoked and disconnected states keep their existing meanings.",
          "is_bot": false,
          "headline": "fix(observer): remove unbound operator warnings",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T01:42:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fea0b8a8df15eb5a6c50da8474c97f2b87a26920",
          "body": "Enforce device bindings only when an observer record has one. Unbound records now authenticate after the existing handle, revoked, and disabled checks, so records without a binding keep handle-based behavior while bound records still require the matching cert or browser pairing.\n\nRestore register's \n[…]\necord in place and preserve the key, created_at, stats, and history. SSE streams on unbound records skip only device-level rechecks; observer-level revoked and disabled checks still run each interval.",
          "is_bot": false,
          "headline": "fix(observer): relax unbound observer auth",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-31T01:42:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "04543c5a96fb15cc4be0fac1e62d36878b0c83f2",
          "body": "Update the owner-facing refusal copy and API contract description for observer self-registration when the required device pairing is missing or mismatched.\n\nThe reason code remains local_request_only, and the observer client contract bundle takes a patch bump to 5.0.3.",
          "is_bot": false,
          "headline": "fix(observer): say a device pairing is required on register refusal",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T23:22:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9bd97eefcad89024eccc0570eee20c0872bd09b8",
          "body": "Re-register journal observer create as a write-free refusal so old invocations see pairing guidance instead of argparse usage output.\n\nAccept a trailing --json flag and a bare create command on the retired path, but keep one terminal stderr contract and exit 2.",
          "is_bot": false,
          "headline": "fix(observer): explain why manual observer creation is retired",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T23:22:26Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bfbc7522f104be74cfab909748486936688e5039",
          "body": "Pin both spl-core and spl-transport to the v0.4.0 tag.\n\nBoth crates resolve to 742bc9dc789c5a75658844849a04d75033aeb6e3.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(deps): pin spl-rust to v0.4.0",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T22:44:04Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "e38889cf7c6ec041ef23548c0209f03cd40bd542",
          "body": "Remove a dead helper left behind by the register rewrite. The register route now resolves device binding directly, so keeping a caller-free trust helper would make future edits look for an authorization seam that no longer exists.\n\nThe observer-client-contract manifest pins solstone/apps/observer/ro\n[…]\ne-visible surface moved.\n\nPrecedent: bac06ff57 and f7cfe2a85 did the same re-pin after earlier changes to\nthe pinned producer files.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(observer): remove stale register trust helper",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T22:34:29Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fdb5bd99fe6268deda0a5afb2bd4665ca3276f0f",
          "body": "Shared fixtures and contract recording now need the same verified device proof as real observer registration. Seed bound observer records with matching ledger entries, stamp contract recorder requests with request-scoped identity, and regenerate the observer client bundle manifest without changing reason-code sets.",
          "is_bot": false,
          "headline": "test(observer): bind fixtures for contract recording",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T22:23:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6ea28d164afa81af3ce203efdf15af5a4866af28",
          "body": "Unbound records remain loadable for inspection but are refused at auth time. Show that state in observer status output and escalate it through the existing capture-health degraded path so operators can see why capture is not healthy.",
          "is_bot": false,
          "headline": "feat(observer): surface unbound records",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T22:23:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3d5149a2bbe921c9be8671c59444c401f7d3f42f",
          "body": "Observer records now require verified device binding at registration time, so a local CLI command that minted bearer-only records would create unusable credentials. Remove the create subcommand and its reuse path, letting argparse report the clean break while docs point operators to paired observer installers.",
          "is_bot": false,
          "headline": "feat(observer): retire manual observer creation",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T22:23:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4ea5392476134c62c7f2ba2e7da69247b89f7521",
          "body": "Unpair removes the device from the paired-device ledger first, then asks the observer owner to revoke records bound to that device. This keeps the network app out of direct observer-record writes while making device removal take effect for observer streams.",
          "is_bot": false,
          "headline": "feat(network): revoke bound observers on unpair",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T22:21:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "15518d1229cc3205b063cde30090019a9348b870",
          "body": "Browser pairing needs the ledger entry to exist before observer registration can prove device ownership. Allow pending browser entries without an observer handle, then attach the handle under the authorized-client writer once register succeeds.",
          "is_bot": false,
          "headline": "feat(link): attach browser observer handles after register",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T22:21:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a2d623e98051be8f08b483ee1bb09a8328d567bc",
          "body": "Observer handles were portable bearer credentials. Store the owning device class and identifier on each observer record, require the bound device in the shared identity resolver, and make register mint records only from verified device proof so the handle becomes only a per-stream selector.\n\nThe SSE stream now rechecks the bound device on a bounded interval so revocation closes busy streams without waiting for an idle heartbeat.",
          "is_bot": false,
          "headline": "feat(observer): bind records to verified devices",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T22:21:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f6753328eae83d7db8bc517127a1271f6ab5b3d",
          "body": "Defect B was that _release_provider_startup_gate_if_ready released the buffered TaskQueue after a 60s wall-clock window while _start_llama_local_server is allowed 300s to load a model. The gate only learned about a provider through gate.terminal, and launch outcomes only reached that set after the r\n[…]\n nine steps inside a boundary that swallows every non-fatal exception, so a deterministic raise in any earlier step meant neither backstop ever fired.\n\nCo-Authored-By: GPT-5 Codex <noreply@openai.com>",
          "is_bot": false,
          "headline": "fix(supervisor): release the startup gate on the first concluded launch",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T19:35:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4dc8bd237bb79fd928c0563ae402780109e2ab73",
          "body": "Dropped the unreachable has_execution_error arm from summary_counts' failed count; probe.run_check already builds error results with status fail, so errors are a subset of failed by construction.\n\nAdded probe.results_failed, the single aggregate rule for any execution error or any blocker-severity f\n[…]\nsummary_status, and preflight.main instead of duplicated conditions.\n\nAdded preflight --json coverage asserting the structured execution_error payload and a nonzero exit for an advisory raising check.",
          "is_bot": false,
          "headline": "refactor(doctor): share the aggregate failure predicate",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T18:46:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e103c98ad71b948277543b7cda41e5f5f8dc5ce4",
          "body": "An ordinary Exception from one check now becomes that check's own fail result carrying an additive execution_error payload: exception type plus a message truncated to 512 chars, with no traceback. The fan-out continues in original order.\n\nThe shared boundary is probe.run_check, used by doctor's batt\n[…]\nconflict execution error now takes the unknown-topology fix policy so repair guidance cannot render 'first: None'.\n\nNo new status value, event type, or error code is added; setup.py remains unchanged.",
          "is_bot": false,
          "headline": "fix(doctor): isolate check execution failures from the battery",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T18:46:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "85f81dc18d72e0fbd988dc8e23d6172309ce2de2",
          "body": "Add the owner-facing held-by-backoff reason and route/client handling so process-now reports the held state instead of queued.\n\nRegenerate the Convey OpenAPI and observer-client projection, and bump BUNDLE_SEMVER from 4.0.2 to 5.0.0. An Error.reason_code enum change is a changed component schema; the compatibility gate requires exact list equality for additive-only, so it classifies MAJOR.",
          "is_bot": false,
          "headline": "surface held process-now refusals",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T17:54:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1df190213ed4de48a51c79031384ae64d5286fb8",
          "body": "Add a catchup-state read helper that proves when a day is held by daily catchup or segment repair backoff from one snapshot, with active records falling through to status quo behavior.\n\nHave reprocess_day return HELD_BY_BACKOFF before sending the supervisor drain request, and pin the CLI/process-now behavior plus the forced-drain regression guard.",
          "is_bot": false,
          "headline": "refuse held process-now drains",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T17:53:48Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "40d71831d69f77bff46f1fd8f39cbfd9d0acde97",
          "body": null,
          "is_bot": false,
          "headline": "test: split release checks from development ci",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T17:44:47Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0cfb735886bf97cbc0600bbae89dc819581a95b9",
          "body": "Four owner-facing entries under [Unreleased]: refused arrivals now leave a trace,\nimports queue instead of silently vanishing, a slow chat reply is no longer read\nas a stopped one, and a passing readiness check no longer leaves a third-party\nerror line in the error list and support diagnostics.\n\nDrafted through the changelog recipe. The refusal-recording entry describes what\nyour journal accepts and refuses, so it carries a sensitive-content flag and needs\napproval before this publishes.",
          "is_bot": false,
          "headline": "docs(changelog): record the batch-18 fix arc",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T17:15:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "346bdeb1ec59a92a2e13936e8fd8a41d27a6e022",
          "body": null,
          "is_bot": false,
          "headline": "test: remove remaining non-unit journal groups",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T16:59:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a219df21a0d84ce12532c513244452f7fa179605",
          "body": "connect() now raises local_model_loading when the health probe reports STATE_LOADING instead of collapsing that state into local_model_not_ready. The owner-facing message is unchanged because LOCAL_MODEL_NOT_READY_COPY is reused; the no-port and STATE_FAILED paths remain local_model_not_ready.\n\ntest\n[…]\nn _STARTUP_REASON_CODES, so is_blocking_reason and backlog_reason_category, and every rendered surface downstream of them, are unchanged. This changes what the system knows, not what any surface says.",
          "is_bot": false,
          "headline": "fix(local): raise loading reason for loading server",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T16:38:52Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "57ca91bb2945520b5fb290d26770b6b44ef931cd",
          "body": null,
          "is_bot": false,
          "headline": "test: trim scaffolding and checker self-tests",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T16:28:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c6c7903dbf392b6dde592e230954b2daf386da66",
          "body": "The concurrency test for JSONEventWriter.emit passed with the emit lock removed.\nThe lock is correct; the test could not detect its absence.\n\nCause is the test double, not the assertions. _CollectingStdout.write is a bare\nlist append, so print()'s two writes - payload then newline - never interleave\n[…]\nis the terminal finish event, the answer is dropped and the use hangs\nto a 600s kill. That is the original defect made worse and silent, and this is\nthe only test standing between it and a regression.",
          "is_bot": false,
          "headline": "test(talents): make the concurrent-emit gate able to fail",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T15:33:29Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "bac06ff57eeb3e2cec2cbaba6c81a835540dbbcb",
          "body": "…n log\n\nThe observer-client-contract manifest pins solstone/apps/observer/routes.py and\nsolstone/apps/observer/utils.py by digest under producer.observer_routes and\nproducer.observer_utils. Routing ingest auth rejections through the accountant\nchanges both hashes, so `make check-openapi` goes red wi\n[…]\nfe2a85 did the same re-pin after the chat watchdog change, and\n996a67fa4 after an earlier change to solstone/apps/observer/utils.py.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(convey): re-pin observer producer digests for the ingest rejectio…",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T14:47:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7be059b51d314b13a42e598dbe9ee1a3855517ba",
          "body": "Follow up the audit by adding the return type annotation on the new _rejection_response helper.",
          "is_bot": false,
          "headline": "Annotate observer rejection response helper",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T14:46:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "06b7cc6421081a8a7b046a623e0f7f55fe715d5c",
          "body": "Note that observer ingest auth failures now produce an in-memory, rate-limited operational log signal: periodic WARNING records during a live burst and a quiet-close ERROR carrying active_count for support diagnostics.",
          "is_bot": false,
          "headline": "Document observer auth rejection signal",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T14:46:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "84b3904ad1bb471854370ae2e7b17feeb9329853",
          "body": "Split observer identity resolution into one authoritative _resolve_identity()\ncore and two named entry points: resolve_observer_identity() keeps the exact\nexisting 3-tuple contract, while resolve_ingest_identity(surface) adds the\nin-memory burst sweep and rejection accounting. This was chosen over w\n[…]\nt contract\ncompatibility failed: bundle content changed without a version bump from\n2.1.9\". Clearing that would require bumping a shipped-client wire-contract\nbundle version, which this scope forbids.",
          "is_bot": false,
          "headline": "Route observer ingest auth rejections to logs",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T14:46:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "39fe1dc5b3e88d92bc3d2973a391e11bc9609bea",
          "body": "Add the in-memory observer auth rejection accounting module with the 300 second warning window, 300 second quiet-close threshold, 64 bucket cap, keyless sentinel, lock-protected table, sweep, reset seam, and the single WARNING/ERROR emission sites.\n\nThe module keeps the signal slash-free and prefix-only: one WARNING per bucket per window while a rejection burst remains live, and one ERROR on time-based close carrying active_count. It has no persisted file and no config key.",
          "is_bot": false,
          "headline": "Add observer auth rejection accountant",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T14:46:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f7cfe2a85ddf65b3fecbe0fb3767091a75745f51",
          "body": "…ange\n\nThe observer-client-contract manifest pins solstone/convey/chat.py by digest\nunder producer.chat_routes. Adding the watchdog cancel path to that file\nchanges its hash, so `make check-openapi` goes red without regenerating the\nbundle.\n\nBump bundle_semver 4.0.0 -> 4.0.1 and regenerate. The chan\n[…]\ne\nidentical, so no wire-visible surface moved.\n\nPrecedent: 996a67fa4 did the same re-pin after dfad79db2 changed\nsolstone/apps/observer/utils.py.\n\nCo-Authored-By: Claude Opus 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(convey): re-pin observer producer digest for the chat watchdog ch…",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T14:11:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ede18852f27be4334db559dfd91be290df5c03bb",
          "body": "The coupling assertion previously ran against a monkeypatched interval, so it could not catch the production constant being widened past the chat watchdog cap.\n\nMove the guard into a dedicated test that imports the production talents interval and convey watchdog timeouts directly. The failure messag\n[…]\nnstead of a line number, and removes the unsent ts field from the docs cancel example so the documented wire shape matches the code.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(talents): bind the liveness interval to the watchdog cap",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T14:11:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "249b41979538907688d10c9b087416c930b3e686",
          "body": "When the chat watchdog tripped, convey abandoned the raw use and discarded its result, but the talent ran to completion holding its slot.\n\nThe watchdog now issues a cortex cancel for the abandoned raw use: chat kind only, after the owner-visible error and before any queued turn is spawned, guarded s\n[…]\nd like the abandoned-use map and evicted wherever a turn ends. This also corrects a stale code citation for cortex's inbound filter.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(chat): cancel the abandoned use when the watchdog fires",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T14:11:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "0ba83ee57d0ca743f2ee35f922e740ead3213900",
          "body": "Cortex's inbound filter accepted only event=request, so a cancel was silently dropped. The filter now also accepts event=cancel, and the work is queued to a dedicated FIFO worker rather than handled inline.\n\nTalentProcess.stop() blocks in process.wait(timeout=10), and the talent cannot service SIGTE\n[…]\n after the cancel terminal. The file is still completed exactly once and the use is already abandoned, so nothing reaches the owner.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(cortex): accept a cancel request off the receive thread",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T14:11:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "5178a8941acfb7b6641f2cd1adeb7431ac66fb55",
          "body": "_execute_generate calls generate_with_result synchronously, so the event loop is blocked for the whole generation and it emitted nothing between start and its terminal event. The 30 s chat watchdog was therefore measuring latency, not silence.\n\nA daemon OS thread now emits a progress event every _GE\n[…]\n would drop the answer entirely.\n\nOn the reported chat path the watchdog fired at roughly a quarter of the generation's own timeout.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(talents): emit liveness progress during blocking generation",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T14:11:08Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ee0dee0be5dafcb92043c5e38b256408f754727d",
          "body": "The brain readiness probe runs a canned cogitate prompt with a deliberate 2-turn ceiling, so the vendored OpenHands SDK logs `Agent reached maximum iterations limit (N).` at ERROR while our layer treats the run as a success and brain reports ready.\n\nAdd a diagnostic-only context manager that install\n[…]\ndiagnostics still behave as before, while the demoted line no longer carries an ERROR token. Two golden fixture rows pin both forms.\n\nCo-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(providers): demote the readiness probe's max-iterations ERROR",
          "author_name": "Jer Miller",
          "author_login": "quartzjer",
          "committed_at": "2026-07-30T13:53:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        }
      ],
      "releases_count": 69,
      "commits_last_year": 6213,
      "latest_release_at": "2026-07-31T06:45:30Z",
      "latest_release_tag": "v1.0.20",
      "releases_from_tags": false,
      "days_since_last_push": 0,
      "active_weeks_last_year": 52,
      "days_since_latest_release": 1,
      "mean_days_between_releases": 1.3
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 50,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": false
    },
    "ecosystem": {
      "packages": [
        {
          "name": "solstone",
          "exists": true,
          "license": "AGPL-3.0-only",
          "keywords": [
            "audio",
            "transcription",
            "screenshot",
            "multimodal",
            "ai",
            "gemini",
            "Development Status :: 3 - Alpha",
            "Intended Audience :: Developers",
            "License :: OSI Approved :: GNU Affero General Public License v3",
            "Operating System :: MacOS :: MacOS X",
            "Operating System :: POSIX :: Linux",
            "Programming Language :: Python :: 3",
            "Programming Language :: Python :: 3.12",
            "Programming Language :: Python :: 3.13",
            "Topic :: Multimedia :: Graphics :: Capture :: Screen Capture",
            "Topic :: Multimedia :: Sound/Audio :: Analysis",
            "Topic :: Scientific/Engineering :: Artificial Intelligence"
          ],
          "ecosystem": "pypi",
          "matches_repo": true,
          "registry_url": "https://pypi.org/project/solstone/",
          "is_deprecated": false,
          "latest_version": "1.0.21",
          "repository_url": "https://github.com/solpbc/solstone-journal",
          "versions_count": 78,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": 6851,
          "first_published_at": "2026-05-07T04:05:48.769890Z",
          "latest_published_at": "2026-08-01T09:22:36.902583Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 0
        }
      ]
    },
    "popularity": {
      "forks": 7,
      "stars": 17,
      "watchers": 1,
      "fork_history": {
        "days": [
          {
            "date": "2026-01-08",
            "count": 1
          },
          {
            "date": "2026-04-05",
            "count": 1
          },
          {
            "date": "2026-05-11",
            "count": 1
          },
          {
            "date": "2026-05-14",
            "count": 1
          },
          {
            "date": "2026-05-27",
            "count": 1
          },
          {
            "date": "2026-06-12",
            "count": 1
          },
          {
            "date": "2026-07-05",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 7,
        "total_forks": 7
      },
      "star_history": null,
      "open_issues_and_prs": 2
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile",
        "tests/systemd-test/Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "core/Cargo.toml",
        "core/crates/solstone-core-cli/Cargo.toml",
        "core/crates/solstone-core-indexer-store/Cargo.toml",
        "core/crates/solstone-core-indexer/Cargo.toml",
        "core/crates/solstone-core-journal/Cargo.toml",
        "core/crates/solstone-core-sol-client-cli/Cargo.toml",
        "core/crates/solstone-core-sol-client/Cargo.toml",
        "core/crates/solstone-core-sol-link/Cargo.toml",
        "core/crates/solstone-core-sol/Cargo.toml",
        "core/crates/solstone-core-speakers-analyze/Cargo.toml",
        "core/crates/solstone-core-speakers-onnx/Cargo.toml",
        "core/crates/solstone-core-speakers/Cargo.toml",
        "core/crates/solstone-core-spl/Cargo.toml",
        "core/crates/solstone-core/Cargo.toml"
      ],
      "largest_source_bytes": 251353,
      "source_files_sampled": 1751,
      "oversized_source_files": 81,
      "agent_instruction_files": [
        "AGENTS.md",
        "CLAUDE.md",
        "GEMINI.md",
        "journal/AGENTS.md",
        "journal/CLAUDE.md",
        "journal/GEMINI.md",
        "solstone/apps/import/guides/claude.md",
        "solstone/apps/import/guides/gemini.md",
        "tests/fixtures/journal/AGENTS.md",
        "tests/fixtures/journal/CLAUDE.md",
        "tests/fixtures/journal/GEMINI.md"
      ],
      "agent_instruction_max_bytes": 52085
    },
    "dependencies": {
      "manifests": [
        "core/Cargo.toml",
        "pyproject.toml"
      ],
      "advisories": {
        "error": null,
        "scope": null,
        "source": null,
        "findings": [],
        "collected": false,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 0,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "crates",
        "pypi"
      ],
      "dependencies": [
        {
          "name": "setproctitle",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": null
        },
        {
          "name": "typer",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": null
        },
        {
          "name": "requests",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": null
        },
        {
          "name": "psutil",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": null
        },
        {
          "name": "userpath",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": ">=1.9.2,<2"
        },
        {
          "name": "solstone-core",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "==1.0.21"
        },
        {
          "name": "solstone-core",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "==1.0.21"
        },
        {
          "name": "solstone-core",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "==1.0.21"
        },
        {
          "name": "solstone-core-unsupported-platform",
          "manifest": "pyproject.toml",
          "ecosystem": "pypi",
          "version_constraint": "==1.0.21"
        }
      ],
      "all_dependencies": {
        "error": "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
        "source": null,
        "packages": [],
        "collected": false,
        "truncated": false,
        "total_count": null,
        "direct_count": null,
        "indirect_count": null
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 2,
        "merged_prs": 380,
        "open_issues": 0,
        "closed_ratio": 1,
        "closed_issues": 2,
        "closed_unmerged_prs": 7
      },
      "bus_factor": 1,
      "bot_contributors": 1,
      "top_contributors": [
        {
          "type": "User",
          "login": "quartzjer",
          "commits": 7184,
          "avatar_url": "https://avatars.githubusercontent.com/u/61632?v=4"
        },
        {
          "type": "User",
          "login": "maxspeed27",
          "commits": 85,
          "avatar_url": "https://avatars.githubusercontent.com/u/129209864?v=4"
        },
        {
          "type": "User",
          "login": "ha-ye",
          "commits": 2,
          "avatar_url": "https://avatars.githubusercontent.com/u/58130581?v=4"
        }
      ],
      "contributors_sampled": 3,
      "top_contributor_share": 0.988
    },
    "quality_signals": {
      "has_ci": false,
      "has_tests": true,
      "ci_workflows": [],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "Cargo.lock",
        "uv.lock"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 0,
            "reason": "branch protection not enabled on development/release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 10,
            "reason": "project has 4 contributing companies or organizations",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": null,
            "reason": "no workflows found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 0,
            "reason": "security policy file not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": 0,
            "reason": "Project has not signed or included provenance with any releases.",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": null,
            "reason": "No tokens found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 0,
            "reason": "100 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "827cd6fe1a0ecaa44c79812d4eb3cdba6b041037",
        "ran_at": "2026-08-01T09:23:51Z",
        "aggregate_score": 2.5,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-08-01T08:51:24Z",
      "oldest_open_prs": [
        {
          "number": 386,
          "created_at": "2026-05-11T14:55:57Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 389,
          "created_at": "2026-06-30T19:53:44Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-31T16:12:42Z",
      "ci_last_conclusion": null,
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/solpbc/solstone-journal",
    "host": "github.com",
    "name": "solstone-journal",
    "owner": "solpbc"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": "The weighted overall 59 is calibrated to 63 on the published index scale (record calibration 2026-08-02).",
      "notes": [
        {
          "code": "overall_calibration",
          "params": {
            "raw": 59,
            "calibrated": 63,
            "calibration": "2026-08-02"
          }
        }
      ],
      "value": 63,
      "inputs": {
        "security": 25,
        "vitality": 96,
        "community": 51,
        "governance": 59,
        "calibration": "2026-08-02",
        "engineering": 50,
        "ai_readiness": 67,
        "weighted_overall_raw": 59
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "exceptional",
        "name": "Vitality",
        "value": 96,
        "weight": 0.21,
        "metrics": [
          {
            "key": "development_activity",
            "band": "exceptional",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "commits_last_year": 6213,
              "human_commit_share": 1,
              "days_since_last_push": 0,
              "active_weeks_last_year": 52
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 0 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "52/52 weeks with commits",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 52
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "6213 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 6213
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "releases_count": 69,
              "latest_release_tag": "v1.0.20",
              "releases_from_tags": false,
              "days_since_latest_release": 1,
              "mean_days_between_releases": 1.3
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "69 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 69
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~1.3 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 1.3
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "exceptional",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "maintained",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": null,
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": 1,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "last human commit 1 days ago",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_maintained",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "moderate",
        "name": "Community & Adoption",
        "value": 51,
        "weight": 0.17,
        "metrics": [
          {
            "key": "popularity",
            "band": "at_risk",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 26,
            "inputs": {
              "forks": 7,
              "stars": 17,
              "watchers": 1,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "17 stars",
                "points": 19.5,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 17
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "7 forks",
                "points": 6.5,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 7
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "1 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 70,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "readme_badges": null,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "readme_badge_services": [],
              "has_pull_request_template": false
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (AGPL-3.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "AGPL-3.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "moderate",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 64,
            "inputs": {
              "packages": [
                "solstone"
              ],
              "dependents": null,
              "ecosystems": "pypi",
              "total_downloads": null,
              "monthly_downloads": 6851
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "6,851 downloads/month across pypi",
                "points": 51.1,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 6851,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 59,
        "weight": 0.23,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 23,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 3,
              "top_contributor_share": 0.988
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 99% of commits",
                "points": 0.3,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 99
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "3 contributors",
                "points": 4.1,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 3
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 4 contributing companies or organizations",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "excellent",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "newcomer_pr_acceptance"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 82,
            "inputs": {
              "merged_prs": 380,
              "open_issues": 0,
              "closed_issues": 2,
              "prs_merged_7d": null,
              "prs_decided_7d": null,
              "prs_merged_30d": null,
              "prs_decided_30d": null,
              "issue_closed_ratio": 1,
              "closed_unmerged_prs": 7,
              "first_time_authors_30d": null,
              "first_time_prs_merged_30d": null,
              "first_time_prs_decided_30d": null
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "100% of issues closed",
                "points": 42,
                "status": "met",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 42
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "380/387 decided PRs merged",
                "points": 29.5,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 380,
                      "decided": 387
                    }
                  }
                ],
                "max_points": 30
              },
              {
                "key": "newcomer_pr_acceptance",
                "name": "Newcomer PR acceptance",
                "detail": "no first-time contributor's PR decided in 30d",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_newcomer_prs",
                    "params": {
                      "days": 30
                    }
                  }
                ],
                "max_points": 13
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "weak",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 48,
            "inputs": {
              "followers": 5,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "solpbc",
              "public_repos": 30,
              "account_age_days": 211
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "5 followers of solpbc",
                "points": 5.6,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 5,
                      "login": "solpbc"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "30 public repos, account ~0 yr old",
                "points": 12,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 30
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "exceptional",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "packages": [
                "solstone"
              ],
              "ecosystems": "pypi",
              "any_deprecated": false,
              "min_days_since_publish": 0
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on pypi",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "pypi"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 0 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 0
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "78 published versions",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 78
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 50,
        "weight": 0.19,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 30,
            "inputs": {
              "has_ci": false,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 80,
            "inputs": {
              "topics": [],
              "has_wiki": false,
              "homepage": "https://solstone.app",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://solstone.app",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "at_risk",
        "name": "Security",
        "value": 25,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Dangerous-Workflow, Packaging, Token-Permissions. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "dangerous_workflow",
                    "packaging",
                    "token_permissions"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 25,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 14,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 4,
              "scorecard_aggregate": 2.5
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection not enabled on development/release branches",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 4 contributing companies or organizations",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no workflows found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file not detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "Project has not signed or included provenance with any releases.",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "No tokens found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "100 existing vulnerabilities detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "exceptional",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "commit_weight_rule": {
                "min_commits": 50,
                "min_commit_share": 0.1
              },
              "review_only_matches": 0,
              "below_threshold_exposures": [],
              "assessed_self_published_locations": 1
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 67,
        "weight": 0.04,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.73,
              "agent_instruction_files": [
                "AGENTS.md",
                "CLAUDE.md",
                "GEMINI.md",
                "journal/AGENTS.md",
                "journal/CLAUDE.md",
                "journal/GEMINI.md",
                "solstone/apps/import/guides/claude.md",
                "solstone/apps/import/guides/gemini.md",
                "tests/fixtures/journal/AGENTS.md",
                "tests/fixtures/journal/CLAUDE.md",
                "tests/fixtures/journal/GEMINI.md"
              ],
              "agent_instruction_max_bytes": 52085
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "AGENTS.md, CLAUDE.md, GEMINI.md, journal/AGENTS.md, journal/CLAUDE.md, journal/GEMINI.md, solstone/apps/import/guides/claude.md, solstone/apps/import/guides/gemini.md, tests/fixtures/journal/AGENTS.md, tests/fixtures/journal/CLAUDE.md, tests/fixtures/journal/GEMINI.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "AGENTS.md, CLAUDE.md, GEMINI.md, journal/AGENTS.md, journal/CLAUDE.md, journal/GEMINI.md, solstone/apps/import/guides/claude.md, solstone/apps/import/guides/gemini.md, tests/fixtures/journal/AGENTS.md, tests/fixtures/journal/CLAUDE.md, tests/fixtures/journal/GEMINI.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "73 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 38.9,
                "status": "partial",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 73,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "moderate",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 60,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "Cargo.lock",
                "uv.lock"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [
                "Makefile",
                "tests/systemd-test/Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.11,
              "toolchain_manifests": [
                "core/Cargo.toml",
                "core/crates/solstone-core-cli/Cargo.toml",
                "core/crates/solstone-core-indexer-store/Cargo.toml",
                "core/crates/solstone-core-indexer/Cargo.toml",
                "core/crates/solstone-core-journal/Cargo.toml",
                "core/crates/solstone-core-sol-client-cli/Cargo.toml",
                "core/crates/solstone-core-sol-client/Cargo.toml",
                "core/crates/solstone-core-sol-link/Cargo.toml",
                "core/crates/solstone-core-sol/Cargo.toml",
                "core/crates/solstone-core-speakers-analyze/Cargo.toml",
                "core/crates/solstone-core-speakers-onnx/Cargo.toml",
                "core/crates/solstone-core-speakers/Cargo.toml",
                "core/crates/solstone-core-spl/Cargo.toml",
                "core/crates/solstone-core/Cargo.toml"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile, tests/systemd-test/Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile, tests/systemd-test/Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "11 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 11,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 52,
            "inputs": {
              "primary_language": "Python",
              "largest_source_bytes": 251353,
              "source_files_sampled": 1751,
              "oversized_source_files": 81
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Python without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "Python"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "81/1751 source files over 60KB",
                "points": 52.5,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 1751,
                      "oversized": 81
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
      }
    ],
    "classification": {
      "labels": [
        "library",
        "cli"
      ],
      "scores": {
        "cli": 4,
        "library": 6
      },
      "primary": "library",
      "evidence": [
        {
          "tier": "distribution",
          "label": "library",
          "source": "registry:pypi",
          "weight": 6
        },
        {
          "tier": "dependencies",
          "label": "cli",
          "source": "dep:typer",
          "weight": 4
        }
      ],
      "artifacts": [],
      "confidence": "medium",
      "host_extension": false,
      "runs_as_process": true,
      "consumed_by_code": true
    },
    "metrics_version": "2.3.1"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "GitHub dependency-graph SBOM unavailable (404); the dependency graph may be disabled for this repository",
    "deps.dev does not index pypi:solstone@1.0.21; advisories assessed against the repository dependency graph instead"
  ],
  "report_type": "repository",
  "generated_at": "2026-08-01T09:24:01.850966Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/s/solpbc/solstone-journal.svg",
  "full_name": "solpbc/solstone-journal",
  "license_state": "standard",
  "license_spdx": "AGPL-3.0"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v2.3.1、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计PyPI.