原始 JSON 报告 机器可读
{
"data": {
"repo": {
"topics": [
"bun",
"components",
"css",
"html",
"templating-engine",
"blade",
"stacks"
],
"is_fork": false,
"size_kb": 251402,
"has_wiki": false,
"homepage": "https://stacks-stx.netlify.app",
"languages": {
"EJS": 2026,
"PHP": 3347,
"Pug": 119,
"HTML": 36754,
"Blade": 1963,
"Shell": 6387,
"Swift": 41054,
"Kotlin": 70049,
"Liquid": 208,
"Nunjucks": 208,
"Handlebars": 1755,
"JavaScript": 31449,
"TypeScript": 466747686
},
"pushed_at": "2026-07-25T21:14:48Z",
"created_at": "2025-02-03T21:56:55Z",
"owner_type": "Organization",
"updated_at": "2026-07-25T20:31:31Z",
"description": "A performant & powerful UI templating language.",
"is_archived": false,
"is_disabled": false,
"license_spdx": "MIT",
"default_branch": "main",
"license_spdx_raw": "MIT",
"primary_language": "TypeScript",
"significant_languages": [
"TypeScript"
]
},
"owner": {
"blog": "https://stacksjs.com",
"name": "Stacks",
"type": "Organization",
"login": "stacksjs",
"company": null,
"location": "United States of America",
"followers": 119,
"avatar_url": "https://avatars.githubusercontent.com/u/114664568?v=4",
"created_at": "2022-09-29T11:34:06Z",
"is_verified": null,
"public_repos": 153,
"account_age_days": 1395
},
"license": {
"state": "standard",
"spdx_id": "MIT",
"raw_spdx": "MIT",
"file_present": true,
"scorecard_found": null,
"profile_has_license": true
},
"activity": {
"releases": [
{
"tag": "v0.2.99",
"kind": "patch",
"published_at": "2026-07-19T23:06:11Z"
},
{
"tag": "v0.2.98",
"kind": "patch",
"published_at": "2026-07-16T22:01:38Z"
},
{
"tag": "v0.2.97",
"kind": "patch",
"published_at": "2026-07-16T18:32:55Z"
},
{
"tag": "v0.2.96",
"kind": "patch",
"published_at": "2026-07-16T17:33:23Z"
},
{
"tag": "v0.2.95",
"kind": "patch",
"published_at": "2026-07-15T20:13:00Z"
},
{
"tag": "v0.2.94",
"kind": "patch",
"published_at": "2026-07-15T04:49:29Z"
},
{
"tag": "v0.2.93",
"kind": "patch",
"published_at": "2026-07-15T04:26:45Z"
},
{
"tag": "v0.2.92",
"kind": "patch",
"published_at": "2026-07-15T01:42:18Z"
},
{
"tag": "v0.2.91",
"kind": "patch",
"published_at": "2026-07-14T19:08:29Z"
},
{
"tag": "v0.2.90",
"kind": "patch",
"published_at": "2026-07-14T15:51:55Z"
},
{
"tag": "v0.2.89",
"kind": "patch",
"published_at": "2026-07-13T23:24:39Z"
},
{
"tag": "v0.2.66",
"kind": "patch",
"published_at": "2026-05-22T00:45:48Z"
},
{
"tag": "v0.2.65",
"kind": "patch",
"published_at": "2026-05-16T01:05:31Z"
},
{
"tag": "v0.2.64",
"kind": "patch",
"published_at": "2026-05-16T00:59:15Z"
},
{
"tag": "v0.2.63",
"kind": "patch",
"published_at": "2026-05-15T22:28:05Z"
},
{
"tag": "v0.2.62",
"kind": "patch",
"published_at": "2026-05-13T00:45:42Z"
},
{
"tag": "v0.2.61",
"kind": "patch",
"published_at": "2026-05-13T00:39:41Z"
},
{
"tag": "v0.2.60",
"kind": "patch",
"published_at": "2026-05-13T00:33:46Z"
},
{
"tag": "v0.2.59",
"kind": "patch",
"published_at": "2026-05-13T00:28:19Z"
},
{
"tag": "v0.2.58",
"kind": "patch",
"published_at": "2026-05-13T00:23:53Z"
},
{
"tag": "v0.2.57",
"kind": "patch",
"published_at": "2026-05-13T00:15:42Z"
},
{
"tag": "v0.2.55",
"kind": "patch",
"published_at": "2026-05-12T02:12:42Z"
},
{
"tag": "v0.2.54",
"kind": "patch",
"published_at": "2026-05-12T01:59:37Z"
},
{
"tag": "v0.2.53",
"kind": "patch",
"published_at": "2026-05-12T01:43:59Z"
},
{
"tag": "v0.2.52",
"kind": "patch",
"published_at": "2026-05-08T00:49:37Z"
},
{
"tag": "v0.2.51",
"kind": "patch",
"published_at": "2026-05-08T00:44:15Z"
},
{
"tag": "v0.2.50",
"kind": "patch",
"published_at": "2026-05-07T00:47:22Z"
},
{
"tag": "v0.2.49",
"kind": "patch",
"published_at": "2026-05-06T14:56:23Z"
},
{
"tag": "v0.2.48",
"kind": "patch",
"published_at": "2026-05-06T14:56:07Z"
},
{
"tag": "v0.2.47",
"kind": "patch",
"published_at": "2026-05-05T23:43:30Z"
},
{
"tag": "v0.2.46",
"kind": "patch",
"published_at": "2026-05-05T18:32:22Z"
},
{
"tag": "v0.2.45",
"kind": "patch",
"published_at": "2026-05-05T00:14:55Z"
},
{
"tag": "v0.2.44",
"kind": "patch",
"published_at": "2026-05-04T23:40:39Z"
},
{
"tag": "v0.2.43",
"kind": "patch",
"published_at": "2026-05-04T22:38:48Z"
},
{
"tag": "v0.2.42",
"kind": "patch",
"published_at": "2026-05-04T18:34:57Z"
},
{
"tag": "v0.2.41",
"kind": "patch",
"published_at": "2026-05-04T18:05:41Z"
},
{
"tag": "v0.2.40",
"kind": "patch",
"published_at": "2026-05-04T06:10:15Z"
},
{
"tag": "v0.2.39",
"kind": "patch",
"published_at": "2026-05-04T05:40:46Z"
},
{
"tag": "v0.2.38",
"kind": "patch",
"published_at": "2026-05-04T05:31:20Z"
},
{
"tag": "v0.2.36",
"kind": "patch",
"published_at": "2026-05-04T03:49:41Z"
},
{
"tag": "v0.2.35",
"kind": "patch",
"published_at": "2026-05-04T03:36:10Z"
},
{
"tag": "v0.2.34",
"kind": "patch",
"published_at": "2026-05-04T01:31:32Z"
},
{
"tag": "v0.2.33",
"kind": "patch",
"published_at": "2026-05-04T01:24:02Z"
},
{
"tag": "v0.2.32",
"kind": "patch",
"published_at": "2026-05-04T01:07:02Z"
},
{
"tag": "v0.2.31",
"kind": "patch",
"published_at": "2026-05-04T00:32:47Z"
},
{
"tag": "v0.2.30",
"kind": "patch",
"published_at": "2026-05-04T00:23:46Z"
},
{
"tag": "v0.2.29",
"kind": "patch",
"published_at": "2026-05-04T00:18:05Z"
},
{
"tag": "v0.2.28",
"kind": "patch",
"published_at": "2026-05-03T23:48:08Z"
},
{
"tag": "v0.2.22",
"kind": "patch",
"published_at": "2026-04-27T00:07:53Z"
},
{
"tag": "v0.2.21",
"kind": "patch",
"published_at": "2026-04-26T22:03:14Z"
},
{
"tag": "v0.2.13",
"kind": "patch",
"published_at": "2026-04-25T23:34:48Z"
},
{
"tag": "v0.2.12",
"kind": "patch",
"published_at": "2026-04-23T14:57:52Z"
},
{
"tag": "v0.2.11",
"kind": "patch",
"published_at": "2026-04-23T10:41:50Z"
},
{
"tag": "v0.2.10",
"kind": "patch",
"published_at": "2026-03-16T05:27:47Z"
},
{
"tag": "v0.2.9",
"kind": "patch",
"published_at": "2026-03-13T02:54:12Z"
},
{
"tag": "v0.2.6",
"kind": "patch",
"published_at": "2026-03-03T04:55:38Z"
},
{
"tag": "v0.2.5",
"kind": "patch",
"published_at": "2026-02-19T13:36:22Z"
},
{
"tag": "v0.2.4",
"kind": "patch",
"published_at": "2026-02-19T13:21:38Z"
},
{
"tag": "v0.2.3",
"kind": "patch",
"published_at": "2026-02-19T11:13:53Z"
},
{
"tag": "v0.2.2",
"kind": "patch",
"published_at": "2026-02-19T10:47:40Z"
},
{
"tag": "v0.2.1",
"kind": "patch",
"published_at": "2026-02-19T10:39:42Z"
},
{
"tag": "v0.2.0",
"kind": "minor",
"published_at": "2025-11-08T00:24:42Z"
},
{
"tag": "v0.1.16",
"kind": "patch",
"published_at": "2025-10-24T20:39:47Z"
},
{
"tag": "v0.1.15",
"kind": "patch",
"published_at": "2025-10-16T22:37:00Z"
},
{
"tag": "v0.1.12",
"kind": "patch",
"published_at": "2025-10-11T04:21:45Z"
},
{
"tag": "v0.1.11",
"kind": "patch",
"published_at": "2025-10-11T04:01:03Z"
},
{
"tag": "v0.1.10",
"kind": "patch",
"published_at": "2025-10-11T03:55:05Z"
},
{
"tag": "v0.1.9",
"kind": "patch",
"published_at": "2025-10-11T03:39:30Z"
},
{
"tag": "v0.0.10",
"kind": "patch",
"published_at": "2025-04-30T22:48:56Z"
},
{
"tag": "v0.0.9",
"kind": "patch",
"published_at": "2025-04-30T22:39:56Z"
},
{
"tag": "v0.0.7",
"kind": "patch",
"published_at": "2025-04-30T22:33:43Z"
},
{
"tag": "v0.0.2",
"kind": "patch",
"published_at": "2025-04-30T21:58:10Z"
}
],
"recent_commits": [
{
"oid": "7a97bf79a13a504ad37336607aa93c5e1068f5ac",
"body": "Replaces every https://discord.gg/stacksjs link with the stacksjs.com/discord\nvanity URL, which the stacksjs.com gateway now 301s to the invite. The invite\ncode lives in one place and can be rotated without touching the docs again.",
"is_bot": false,
"headline": "docs: link the community as stacksjs.com/discord",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-25T20:18:51Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c77c37f1c23f46e37c3d04db9a718524a7a08dee",
"body": null,
"is_bot": false,
"headline": "fix(components): preserve native custom elements",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-22T21:55:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "38b8e9bfd8079dd3987427894b74608bf4d47876",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.99",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-19T23:03:40Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3efbe51abbc6ebcb8d96803c53548cb781db0c26",
"body": null,
"is_bot": false,
"headline": "fix(parser): handle apostrophes in tag balance checks",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-19T23:03:19Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "fd495151e942ae3f7411ae03b69a960f5af5912f",
"body": "Recreation of Finder's sidebar (Recents / Shared, Favorites, Locations)\nusing the <Sidebar> macos theme, matching the sibling sidebar-mail and\nsidebar-notes examples: same glass window frame, Framework7 SF-Symbol\nlookalike icons, macOS system-color tints, light + dark. Renders in the\nbrowser as glass and is promoted to the native Tahoe sidebar in a Craft\nwindow.",
"is_bot": false,
"headline": "feat(components): add Finder sidebar example (macOS Tahoe)",
"author_name": "glennmichael123",
"author_login": "glennmichael123",
"committed_at": "2026-07-18T10:50:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "e7d84af248389ce40a04e8c07f1d2aad44c80940",
"body": null,
"is_bot": false,
"headline": "chore(actions): update setup bun",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-16T22:00:39Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bd604aa29af1553ef7e2f6695d2a342be0f8c499",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.98",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-16T21:59:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bc44fedc5741b34918d6d6e6a8037fe8baf640b5",
"body": null,
"is_bot": false,
"headline": "fix(screenshot): attach navigation before loading",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-16T21:50:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "71c5e14e0532b9274f5f4f519ca7740e2f1f1e1a",
"body": null,
"is_bot": false,
"headline": "fix(web-components): preserve projected light DOM",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-16T21:38:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f159257043c92a470a4d47a363dfafc7af4e5295",
"body": null,
"is_bot": false,
"headline": "fix(component-library): harden upgrade lifecycle",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-16T21:38:35Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "18dcaa6f17f4a476e0546dbb22367b0f8a412d60",
"body": null,
"is_bot": false,
"headline": "chore(deps): update very-happy-dom to 0.1.9",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-16T21:34:11Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4f09a28dbde75d2a4672f2cb56a77d729030697e",
"body": null,
"is_bot": false,
"headline": "chore(deps): refresh pantry lockfile",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-16T18:42:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3d01c625c692b8798de3d7e2d5f725c4cb288b5b",
"body": null,
"is_bot": false,
"headline": "test(dev-server): allow cold config imports",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-16T18:42:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9da324b7985e8f8c05bb8289a35a22a4e66304c9",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.97",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-16T18:10:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b92d1511c7c0c6e1f3c750a494f9696f6a085b31",
"body": "0.2.96 fixed it only for @stacksjs/stx, but the sibling packages still carried\n`sideEffects: false`, and Bun's bundler tree-shook their own graphs at build\ntime into dists that name deleted bindings:\n\n SyntaxError: Exported binding 'defineMiddleware' needs to refer to a top-level\n declared variabl\n[…]\nmoved the field from stx-router, iconify-core, iconify-generator, sanitizer,\ndesktop, bun-plugin-stx, and create-stx. stx-router now builds a parseable dist\n(33 exports), which unbreaks @stacksjs/stx.",
"is_bot": false,
"headline": "fix(pkg): drop sideEffects:false across the monorepo packages",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-16T18:10:20Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "f6e68433ffdc3ac1bb7a69af2a1a75c65442c7bc",
"body": null,
"is_bot": false,
"headline": "style(components): normalize sidebar theme types",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-16T17:52:52Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "27020c872224dd56559d34a0d12a42ad8f34c277",
"body": null,
"is_bot": false,
"headline": "fix(build): emit valid router modules",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-16T17:52:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6690d92b7513c27d3168c1b1fad2f2a8b52264a1",
"body": null,
"is_bot": false,
"headline": "refactor(crosswind): use bunfig config discovery",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-16T17:42:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "77cc19ba1d037362277b9d91e8890dc724511399",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.96",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-16T17:30:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f0e332ec347e0e00abfb073c8069e715f718acfd",
"body": "Same failure as ts-collect, bun-router, bun-query-builder, and ts-images: with\n`sideEffects: false`, Bun's bundler tree-shakes stx's own module graph while\nbuilding it, so the published dist named bindings it had deleted:\n\n SyntaxError: Exported binding 'i' needs to refer to a top-level declared\n variable.\n\nThat crashes any consumer on `import '@stacksjs/stx'`. Removing the field\nrestores a working build (dist/index.js parses, 852 exports).",
"is_bot": false,
"headline": "fix(pkg): drop sideEffects:false, it broke the published dist",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-16T17:30:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d99b236e81693ef8e40f86a80534198912b17106",
"body": null,
"is_bot": false,
"headline": "feat(web-components): add component library builds",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-16T17:15:10Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a6649fce33b14f791df2c6ddd298708b17bd617b",
"body": null,
"is_bot": false,
"headline": "chore(deps): bump @stacksjs/ts-cloud to ^0.7.26",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-16T15:32:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "4db1c4649efb9e04a26e70f528284cc1bf77b866",
"body": "So pantry provisions the toolchain (bun + bunx) from a single declared\nsource. ^1.3.14 is bun's newest public release.",
"is_bot": false,
"headline": "chore(deps): declare bun ^1.3.14 in deps.yaml",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-15T21:32:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1fa3e4cbd5afed9d9e9e6a3c333f6149bdc6dd9b",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.95",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-15T20:10:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5c88b4c8bf45807b798a9d3e22aa138a7054132e",
"body": "^0.0.5 is an exact pin under semver (caret on 0.0.x cannot float), so it\npinned ts-broadcasting at 0.0.5 alongside 0.0.8.",
"is_bot": false,
"headline": "fix(deps): bump ts-broadcasting to ^0.0.8 to dedupe",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-15T20:10:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "647486afbe43cffe0d7e287d1ce5145831a803ea",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.94",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-15T04:47:02Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8df707a4602a36aff0f5c0e3adfedf2ac4c241a6",
"body": "Point the bun condition at ./dist (was ./src) and drop src/ from the\npublished files. Bun consumers now load the built JS like everyone else,\nand the package no longer ships ~1MB of source.",
"is_bot": false,
"headline": "perf(components): serve built JS from the bun export condition",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-15T04:46:53Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "63879f0f4be23b75100ed8e809e381d9f6156513",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.93",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-15T04:24:15Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ae5a74e9d6e94bdb942c6fbe58e7fabefd56e128",
"body": "Reorder the types condition first in exports (order-sensitive for TS\nresolution) on stx/bun-plugin/components, and add sideEffects:false to\nthe pure-library packages for bundler tree-shaking.",
"is_bot": false,
"headline": "chore(pkg): publint clean — types-first exports + sideEffects:false",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-15T04:23:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a5644be10718dca65f7a3130fd084a98a04bf868",
"body": "Native sidebars track the OS light/dark appearance. Crosswind dark:\nutilities are class-based, so the controller mirrors\nprefers-color-scheme onto the root element — unless the app manages its\nown theme via a data-theme attribute.",
"is_bot": false,
"headline": "feat(components): sidebar follows the system appearance",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-15T01:46:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a45a40b5f706ac17c32b9ecb1a06c1db8ce6b408",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.92",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-15T01:39:54Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5f09535b39c4c2823c837d2330959ded1701ee4b",
"body": "Registering '@stacksjs/components/stx-plugin' in a project's stx config\nmakes every library component resolvable by tag name via the plugin\ncomponent-dir mechanism — no per-project componentsDir juggling.",
"is_bot": false,
"headline": "feat(components): add stx plugin shim exposing the ui library",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-15T01:14:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "58119f1a411b3cf21ae645f49926a84db8731bad",
"body": null,
"is_bot": false,
"headline": "test(stx): cover macOS sidebar rendering and slot/props regressions",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-15T00:58:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b1ab2eed3a3d0da558a03db7ea8d89fb67a3ed44",
"body": "Pixel-target examples of the macos sidebar theme, one per reference\napp. Run e.g.:\n\n bun packages/stx/bin/cli.ts dev packages/components/examples/sidebar-mail.stx\n\n@iconify-json/f7 provides the SF-Symbol-style glyphs crosswind resolves\nfor i-f7-* utility classes.",
"is_bot": false,
"headline": "feat(components): add Mail/Music/Notes sidebar recreations",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-15T00:58:20Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f31829f56649f683de962958431bb6317eab2736",
"body": "Pure stx + crosswind utility rendering — no native fallback path. The\nflagship 'macos' theme (aliases: tahoe, macos-tahoe, macos-latest)\nrecreates the Tahoe sidebar measured from native Mail/Music/Notes:\n30px rows with 9px-radius quaternary-fill highlights, 17px SF-style\nicons (i-f7-*) with system-c\n[…]\nserver-side (components\ncannot recurse), so SidebarSection/SidebarItem stay presentational.\n\nLegacy variants (workspace, desktop, solid, transparent, vibrancy)\nmoved into the theme registry unchanged.",
"is_bot": false,
"headline": "feat(components): revamp Sidebar into a macOS Tahoe source list",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-15T00:58:09Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fe313a663b518ff85022d17a9756215174a38102",
"body": "$props is a callable with the props spread onto it; Object.assign threw\n'Attempted to assign to readonly property' for props named 'name' or\n'length' (Function.name/length are readonly), silently killing the\ncomponent's server script. Define the properties instead — they are\nconfigurable, which is all defineProperty needs.",
"is_bot": false,
"headline": "fix(stx): tolerate props named after readonly function properties",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-15T00:58:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b574db2449d81af894a126ef7b22b21760c0858a",
"body": "- expose $slots to component server contexts so templates can gate\n optional regions (@if($slots.header))\n- stop SFC template extraction from swallowing <template #name> /\n v-slot / slot=\"...\" slot templates — a page passing named slots to a\n component previously collapsed to the first slot's content",
"is_bot": false,
"headline": "fix(stx): render named slot templates correctly inside components",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-15T00:57:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6187347383b8427433bbc6473906abf12d41d923",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.91",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-14T19:05:50Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "254988088bb5a35d83331f2d6074f1cc999b4fad",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.90",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-14T15:49:27Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "7aa2e34ebb0e1de7b0b49f13a4d8f4bc5d967aed",
"body": "splitting:true extracts code shared across the ~350 entrypoints into shared\nchunk-*.js files instead of inlining the full graph into every entry. Named\nentry files remain, so @stacksjs/stx/<subpath> imports keep resolving.",
"is_bot": false,
"headline": "perf(stx): code-split the multi-entry build (52MB -> ~9MB dist)",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-14T15:35:36Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a667404d323668dc443109dc115a90367e54bb00",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.89",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-13T23:22:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "ae3ea0478ac90367aa15b8d165593b0d863b6757",
"body": "@stacksjs/iconify-core and @stacksjs/iconify-generator had no repository\nfield, so npm sigstore provenance rejected the publish ('repository.url is\n\"\"'), and no prepublishOnly meant dist was never built. Add the stx\nrepository/homepage/bugs metadata and a prepublishOnly build so both\npublish cleanly with provenance.",
"is_bot": false,
"headline": "fix(iconify): add repository metadata + prepublishOnly build",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-13T23:22:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2c7090c1bee5d3d406e52340e7990b2c89237c60",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.88",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-13T23:16:16Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "67c800e4c04aea917ec2f94f71c7948aae9ccea3",
"body": "…configured\n\nDrop the desktop skip added while its npm trusted-publishing was\nmisconfigured; Stage 2 now publishes the full set (stx-router, sanitizer,\ndesktop, iconify-*, create-stx, markdown). Stage 1 still ships stx +\nbun-plugin first so a peripheral hiccup can't block the critical publish.",
"is_bot": false,
"headline": "chore(release): publish desktop again now that trusted publishing is …",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-13T23:16:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "40d8eac43706b5f7ecbf7c59d311950413ba4c4e",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.87",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-13T20:36:22Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3dce045154fdd55821a6623f87385f81cfe02cd5",
"body": "Fragment responses carry no <head>, so SPA navigation left the browser\ntab title stale until a full reload. The serve layer now sends the page\n<title> as an X-STX-Title header (URI-encoded) on fragment responses, and\nthe client router applies it after a fragment swap (and caches it for\nprefetch/back-forward). Full-document swaps are unaffected. Regression\ntest added.",
"is_bot": false,
"headline": "feat(router): keep document.title in sync on SPA fragment swaps",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-13T20:36:13Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "469f50e89ac2679366bebaf2dd7cabd3f5740a34",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.86",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-13T18:20:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "c2c3fa582ef3fb5929e197843a4883e65b048e75",
"body": "…eak stx\n\n@stacksjs/desktop is only ever lazily imported (native-window / story\npreview) with a graceful 'not available' fallback, so it belongs in\noptionalDependencies, not dependencies — a hard dep meant that when\ndesktop's npm publish failed (misconfigured trusted publishing), the\nwhole @stacksjs/stx install resolved to a missing version. The release\nworkflow now also skips desktop in both publish stages so a desktop\nfailure never aborts the run before stx-router and sanitizer publish.",
"is_bot": false,
"headline": "fix(release): make @stacksjs/desktop optional so its publish can't br…",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-13T18:20:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "49a1b39bf5b4157fc8495da965f58e8924a1f7c0",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.85",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-13T18:03:23Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "3075c2763839dff2ad2f868b2fe276f2f7a4c59b",
"body": "interceptAllLinks intercepts every same-origin anchor, but a page rendered\nby another engine mounted on the same origin (e.g. a BunPress blog at /blog)\ncarries none of the stx layout markers. The router was splicing such a\ndocument's <main> and styles into the stx shell, breaking the layout when\nnav\n[…]\nts a non-stx document (no stx-layout meta / __stxRouterConfig\n/ data-stx-content) and hands off to a native full navigation, so stx and\nBunPress routes coexist under one origin. Regression test added.",
"is_bot": false,
"headline": "fix(router): full-navigate non-stx pages instead of corrupting the shell",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-13T17:58:04Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "9246c62abe4e45d3d110169d6a8965d25c48a0bc",
"body": "…overlapping removal ranges",
"is_bot": false,
"headline": "fix(process): resume server-script scan after the close tag to avoid …",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-13T00:31:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "8c43338f9c0606790c8d5e6a172e67bddbdf1a2f",
"body": null,
"is_bot": false,
"headline": "test: allow screenshot tests more time",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-10T22:36:41Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a5acfb9c5ee9ad6efedbdb5364353fb5348d4d32",
"body": null,
"is_bot": false,
"headline": "chore: upgrade to TypeScript 7",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-10T22:27:28Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0183a63734159546797b323862fee0b68d3842ae",
"body": "… cookies, url, search survive concurrency\n\nServer scripts could not reliably read their own request: the module-level\nactiveServe* singletons are reset by any concurrent request's finally (the\nHMR EventSource opens on every page load) while a render is suspended at an\nawait, so cookies/search/host \n[…]\n served as the response.\n\nRegression-pinned end-to-end: test boots serve() as a subprocess and fails\n0/4 -> passes 4/4 across the fix, including the suspended-render race.\n\nCloses stacksjs/stacks#1967",
"is_bot": false,
"headline": "fix(serve): thread a per-request context to <script server> — params,…",
"author_name": "glennmichael123",
"author_login": "glennmichael123",
"committed_at": "2026-07-10T15:17:54Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4a49f5146b5d4d8111c66cd0a35cbdc5c1c5ad50",
"body": "…outs\n\nThe HMR live-reload EventSource stream sent its keepalive comment every\n15s, but that is LONGER than Bun.serve's 10s default idleTimeout (and\ntypical reverse-proxy read timeouts). The connection went idle and was\nkilled before the first ping ever arrived, so the browser saw\nERR_INCOMPLETE_CHUNKED_ENCODING and fell into a reconnect loop (visible\nas repeated failed GET /_stx/hmr behind rpx). Drop the interval to 5s,\ncomfortably under those timeouts.",
"is_bot": false,
"headline": "fix(hmr): send SSE keepalive every 5s so /_stx/hmr survives idle time…",
"author_name": "glennmichael123",
"author_login": "glennmichael123",
"committed_at": "2026-07-10T12:20:05Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "87a09fccd439d2253e49f490eade99236db79f9c",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.84",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-08T23:26:25Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9d0b7df86955c1ddb78f3869fa7855781b592223",
"body": "…string\n\nThe runtime is emitted as an inline <script>, and other passes inject scripts\nanchored on <body ...>. The runtime's comments contained the literal <body>, so\nthe <body>-anchored injection matched INSIDE the runtime and spliced the setup\n<script> into the middle of it — producing one invalid\n[…]\ninitialized and no page hydrated (@submit/@input/:value/{{ }}\nall stayed inert). Neutralize the tokens in the runtime comments; add a\nregression test asserting the runtime has no <body/<head/</script.",
"is_bot": false,
"headline": "fix(hydration): keep <body>/<head> tokens out of the signals runtime …",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-08T23:26:15Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "42854b7556c757ac5746aa24e2e7d1053f25adf2",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.83",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-08T21:42:26Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a97fe2c9cb7de2547744d165f0ac58f2fc051ea3",
"body": "processScriptSetup used a non-global regex to place the data-stx hydration\nmarker, so a page whose first tag is a skip-tag (<style>/<script>) never got\nmarked and its @/: client directives never bound. Make the regex global with a\nfirst-match guard. Adds a regression test.",
"is_bot": false,
"headline": "fix(hydration): mark first non-skip element on bare pages (no <body>)",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-08T21:38:09Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "2c239c8360e174d3378f9d8d86da07ec86b4526a",
"body": "… double-encoded strings",
"is_bot": false,
"headline": "fix(reactive): splice JSON string payloads in x-data as literals, not…",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-07T16:32:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "18160622420b6f97f3561c36942cc6ee09101e6c",
"body": null,
"is_bot": false,
"headline": "fix(signals): restore SVG attribute casing in generic :attr bindings",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-07T16:32:01Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "5df84bedc497d561c953fc718335c31734abcc81",
"body": "Assigning el.className throws on SVG elements (read-only SVGAnimatedString),\nand an exception mid-hydration aborts the binding walk — every later binding\nin the swapped subtree stays raw ({{ }} literals, dead x-shows) with the\nscope still registered. Field-captured via ts-analytics' dead-binding canary\n(stacksjs/stx#1773 comment): 'literal moustaches: {{ title }} | unregistered\nscopes: none' after doSwap.\n\nGuard: assign className when it's a string, else setAttribute('class', ...).",
"is_bot": false,
"headline": "fix(signals): x-class on SVG elements — className is SVGAnimatedString",
"author_name": "glennmichael123",
"author_login": "glennmichael123",
"committed_at": "2026-07-07T11:51:45Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "b17e1c22fc46cddce793d7acfc029481183a7718",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.82",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-06T23:20:58Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f0017751d28db1b39997190321875881d5874250",
"body": "reusePort means a zero-downtime cutover is in play: the supervisor\nSIGTERMs the old instance once the new one is healthy. Without a drain,\nrequests in flight on the old instance at that instant get connection\nresets (observed as a single dropped probe sample at cutover). Now the\nold instance stops accepting and finishes in-flight work, bounded by\nSHUTDOWN_GRACE_MS (default 15s). Scoped to reusePort so a plain dev\nserver never hooks process signals.",
"is_bot": false,
"headline": "feat(serve): graceful SIGTERM drain when reusePort is enabled",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-06T23:20:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "eff4880e9d6aa2a9cb7134c2a472efe738f381c2",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.81",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-06T23:00:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "276f063326cb261a2f64019f6138d3b23c03ce2f",
"body": "SO_REUSEPORT passthrough to Bun.serve so a new release's server can\nshare the port with the still-serving old one during a deploy cutover\n(ts-cloud's templated-unit flow). Off by default; production callers\nshould pair it with autoIncrementPort: false so an unshareable bind\nfails loudly instead of drifting to a port the gateway doesn't route.",
"is_bot": false,
"headline": "feat(serve): reusePort option for zero-downtime deploy overlaps",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-06T19:06:08Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "939b0e42506f66909eafb20d41d8f0985f4b4e62",
"body": "The serve builds the directive config for both static and dynamic routes\nwithout a `root`, so renderComponentWithSlot's `configuredRoot` was\nundefined and the convention fallbacks (`<root>/resources/views/components`,\n`<root>/src/components`, …) were skipped. `resolveBase` then degraded to the\nparen\n[…]\ner path on the serve is already\ncwd-relative, and the serve is always launched from the project root) in\nboth the static- and dynamic-route config so app-authored SFC components\nresolve by convention.",
"is_bot": false,
"headline": "fix(serve): pass project root so app components resolve",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-06T18:55:10Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "55d1edff62d2482093d7dba12508b5aeb5b29c05",
"body": "isProductionServe() only returned true when NODE_ENV/APP_ENV was explicitly\n'production', so a served app with neither set fell through to the development\n404 that enumerates every route (information disclosure) and reflects the\nrequest path unescaped. Invert the default: treat a serve as developmen\n[…]\ndevelopment/dev/local/test); anything else — including\nan unconfigured environment — is production and gets the clean, non-enumerating\n404. buddy dev keeps the browsable list via NODE_ENV=development.",
"is_bot": false,
"headline": "fix(serve): 404 route list is opt-in to development, safe by default",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-06T17:13:18Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "579af39b9b4245982d0193231e8d176159a4b09b",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.80",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-06T15:47:04Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "409a2e08f5b1545948c89bb14b35bcb3044b5637",
"body": "…id-line\n\nextractDeclaredVariableNames tracked brace depth line-by-line and only\ncaptured a declaration when depth was 0 AFTER the line. A top-level\ndeclaration whose initializer opens a brace that closes on a later line —\n const xs = items.map((x) => { … })\n const obj = {\\n … \\n}\ntherefore ende\n[…]\nrror. Gate on\nthe brace depth at the START of the line instead, so such declarations are\ncaptured while names inside the block body still aren't. Adds a regression\ntest. Full suite: 7793 pass, 0 fail.",
"is_bot": false,
"headline": "fix(variable-extractor): capture top-level consts that open a brace m…",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-06T15:46:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1ed4e1b2a94329076ac4751ef57cf1bf4cb9f35a",
"body": "A single dropped closing tag (e.g. a missing </div>) is silently auto-closed\nat EOF, re-parenting every following sibling inside the unclosed element —\nwhich then inherits its x-show/display:none and renders blank, with zero\ndiagnostics at any layer (server 200s, hydration succeeds, no console outpu\n[…]\n\n build and under the test runner (so it never adds noise to CI or the bundle).\n- Deduped per file so a broken file warns once, re-arming on edit.\n\n14 new tests; full suite green (7810 pass, 0 fail).",
"is_bot": false,
"headline": "feat(dx): dev-mode warning for unbalanced template tags (#1769) (#1770)",
"author_name": "Glenn Michael Torregosa",
"author_login": "glennmichael123",
"committed_at": "2026-07-06T15:24:34Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "da91c3448423a832cdafcc924fe0a6f2fd6be006",
"body": "The #1768 null-guard rewrote 'el.innerHTML = evalAttrExpr(value)' into a\n'var __html = ...' form, which broke the scope-lifecycle 'should handle @html'\nassertion that checks the runtime still contains 'el.innerHTML = evalAttrExpr'.\nUse the runtime's existing '?? '' idiom (cf. el.value at signals.ts) so the\nnull/undefined coercion stays AND the asserted shape is preserved. Full suite\ngreen (7796 pass, 0 fail).",
"is_bot": false,
"headline": "fix(signals): simplify x-html null-guard to '?? \"\"' (#1767)",
"author_name": "glennmichael123",
"author_login": "glennmichael123",
"committed_at": "2026-07-06T14:57:49Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "bcd6f2ce536d9f7d21c9c7dbd061d40e5d0ec434",
"body": "…#1767) (#1768)\n\nWhen a <script client> imports from a module AND declares a top-level const\nwhose name equals a top-level export of that module, Bun.build inlines the\nimport under the bare name and renames the component's local (foo -> foo2).\nThe catch-all export the bundler adds to defeat tree-sha\n[…]\nion, not the import.\n- x-html: coerce null/undefined to '' so a missing binding renders nothing\n instead of the literal string 'undefined'.\n\nAdds a regression test; full suite green (no regressions).",
"is_bot": false,
"headline": "fix(client-script): bind template names shadowed by inlined imports (…",
"author_name": "Glenn Michael Torregosa",
"author_login": "glennmichael123",
"committed_at": "2026-07-06T14:42:48Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "1ca5f4460f526d2534385ed8f02ac1746152e116",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.79",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-06T04:52:12Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "71dbd79b6ca1c964a13080136799faa51592399a",
"body": "processIfStatements() returns true whenever findIfBlocks matches any block\nand only false at zero blocks, so the driving while-loop relied entirely on\nevery pass shrinking the block count to zero. A pathological template where\na branch body reintroduces a matchable @if verbatim (or that balanced\npar\n[…]\nnprocessed\n@if in the output as a visible signal -- the same fail-loud fallback the\nper-block error handling already uses. No behavior change for well-formed\ntemplates (full suite: 7793 pass, 0 fail).",
"is_bot": false,
"headline": "fix(conditionals): guard @if processing loop against non-termination",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-06T04:51:53Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "4d094bf2a6915ab1b6f8354d49aa7ca1be668e51",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.78",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-04T02:39:42Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "a3673528dd8047326b844a5becb3cbf750b6f5f0",
"body": "The dev-debug 404 handler dumped the app's entire internal route list to\nanonymous visitors in production (information disclosure) and injected the\nHMR client script into prod responses. It also reflected the raw requested\npath unescaped.\n\n- Detect production via NODE_ENV/APP_ENV (isProductionServe(\n[…]\nustom app 404 override (404.stx/.md/.html or errors/404.*)\n rendered via the existing getRoute() machinery, in both dev and prod.\n- Add regression tests covering prod non-disclosure + dev route list.",
"is_bot": false,
"headline": "fix(serve): production-safe 404 page without route enumeration",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-04T02:39:12Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "fc4752904f00a3618ff16a39fdb780f21694be37",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.77",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-03T21:18:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "eee9e489dfbbc92ae8276d218b0fb53a799a8c2e",
"body": "…eError/process.env in <script server>\n\nTwo compounding bugs made `<script server>` variables silently render as\nempty interpolations under NODE_ENV=production with no error, even though\nthe underlying values were never actually empty (stacksjs/status#1):\n\n1. variable-extractor.ts: when the primary \n[…]\ntest.ts covering both the extraction-fallback and the\nternary-with-missing-identifier scenarios, including a full renderString()\nround trip matching the original repro's <script server> + {{ }} shape.",
"is_bot": false,
"headline": "fix(stx): stop swallowing valid fallback values on unrelated Referenc…",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-03T21:17:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "db720f0a19d7c80315d7f82e4664e2ee676da66b",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.76",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-03T02:07:17Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d3879f7bfcae28460bd189bfa475b202f781b765",
"body": "…rver> blocks\n\nThe `host`/`cookies`/`ip`/query-string ambient context added over the\nlast two commits (injectServeRequestContext) was only ever wired into\nthe STATIC-route render path. Dynamic routes ([param].stx-style, e.g.\n/status/[slug].stx) go through a separate code path that only called\ninject\n[…]\nt-level `bun --bun tsc --noEmit`\n(clean), `bun run format:check` (clean), and in the real consuming app:\na dynamic-route status page now correctly reads its unlock cookie and\nrenders unlocked content.",
"is_bot": false,
"headline": "fix(bun-plugin): inject request context into dynamic-route <script se…",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-03T02:07:00Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "78f1f88f75f2338bed3b3708e64620fb2bb85c6c",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.75",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-03T01:43:00Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "80ac187d7e1080a857028723ea1dbb24ad561131",
"body": "Extends the ambient-context mechanism added for `host` (activeServeHost)\nwith two more per-request signals `<script server>` blocks can read:\n\n- `cookies` — parsed Cookie header, always an object (never undefined)\n so `cookies.foo` reads cleanly with no truthy-guard. Lets a page gate\n content per-\n[…]\nvia the existing bun-plugin-stx and stx serve/server test\nsuites (29 tests passing, no regressions), root-level\n`bun --bun tsc --noEmit` (clean), and `bun run format:check` (clean,\n212 files scanned).",
"is_bot": false,
"headline": "feat(bun-plugin): expose cookies + client IP to <script server> blocks",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-03T01:42:42Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b3c153c79c4ed7fa845db932d57c3efcfb6d5e58",
"body": "CI's format:check job started failing on the push that landed the\nHost-header feature (0e3daef812) — traced it to a pre-existing\nindentation mismatch on the proxyRules type annotation (unrelated to\nthat commit's actual diff, confirmed via `git show` against the parent\ncommit: the bad indentation was\n[…]\nbefore since nothing had touched this file recently enough to\nre-run format:check against it. `pickier --format --write` fixes it;\n`bun run format:check` now passes clean across all 212 scanned files.",
"is_bot": false,
"headline": "chore(bun-plugin): fix pre-existing format:check violation in serve.ts",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-03T01:07:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "ec4dc100fa2026270fcfdbba491087f216a019b8",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.74",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-03T01:06:06Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "0e3daef812f14eb3ef69a00fcf8361f062618163",
"body": "Adds a `host` ambient variable to server scripts, mirroring the existing\n`__stxServeSearch` (query string) mechanism: `activeServeHost` is set\nfrom `req.headers.get('host')` per-request and injected into the render\ncontext via `injectServeRequestContext`, so a static-route page (e.g.\nindex.stx) can \n[…]\nd test added for the new ambient variable itself —\nverified end-to-end in the consuming app instead (a real multi-tenant\nstatus-page app resolving StatusPage.customDomain via the new `host`\nvariable).",
"is_bot": false,
"headline": "feat(bun-plugin): expose request Host header to <script server> blocks",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-07-03T01:02:31Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "d985c5bb5d46d4daaae5436af4e62081dc63ea17",
"body": null,
"is_bot": false,
"headline": "chore: wip",
"author_name": "glennmichael123",
"author_login": "glennmichael123",
"committed_at": "2026-07-02T16:52:34Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "9729d11f45cba0328f196acf99d43c0c6e989a6b",
"body": "…765)\n\nTwo Nuxt-config parity gaps (surfaced mapping a real Nuxt app to stx):\n\n1. config `app.head` (script/meta/link/headRaw) now injects into a page that\n ALREADY rendered its own <html><head> — layout-based pages and SSG/static\n builds. Previously ensureDocumentShell only populated head when \n[…]\ns the parity gap vs\n Nuxt's vite.server.proxy / nitro.devProxy.\n\nAdds test/shell/config-head-existing-shell.test.ts. Full suite green (9465).\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "feat: config app.head on already-shelled pages + dev-server proxy (#1…",
"author_name": "Glenn Michael Torregosa",
"author_login": "glennmichael123",
"committed_at": "2026-07-02T13:33:49Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "eca8cb6f9fc05fc62f0908f5826c03dccfeb392b",
"body": null,
"is_bot": false,
"headline": "chore: release v0.2.73",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-06-30T00:37:07Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "f070614e4ab424ffc8ee66b4c3125fb3d6d78233",
"body": "<script client> reactive state can now be seeded directly from <script\nserver> (and frontmatter) values at build time, with no runtime fetch.\nAny top-level, JSON-serializable context value that the client script\nreferences but does not itself declare is serialized into the client\nbundle as a `var` b\n[…]\nder) plus processClientScript.\n\nCovers the signals/SFC path specifically: the bridge is injected into\nthe merged __stx_setup_ body before the user's signal declarations.\n\nFull suite green (7775 pass).",
"is_bot": false,
"headline": "feat(stx): add server -> client data bridge for reactive seeding",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-06-30T00:35:07Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "3d7bdcac240bde4f5f70226018b9ab19fbb56534",
"body": null,
"is_bot": false,
"headline": "fix: make stx plugin install framework deps",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-06-28T17:51:24Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "1201e11f8cfbd41de7fd6a52a623d0c48f5c2f43",
"body": null,
"is_bot": false,
"headline": "chore: wip",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-06-18T03:30:30Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "6af36e5c882cef057465a53690abe38e4f6da259",
"body": "Adds three no-dependency options to the WebView screenshot helper + CLI:\n- fullPage / --full-page: measures the document scrollHeight via WebView.evaluate\n and re-renders at full height (WebView has no resize), so long pages\n (dashboards, docs) are captured whole instead of clipped to the viewport\n[…]\n, font swaps).\n- --timeout: exposes the existing timeoutMs navigation cap on the CLI.\nDimensions clamp to WebView's 16384px ceiling. Tests cover full-page\n(PNG height > 3x viewport) and wait-selector.",
"is_bot": false,
"headline": "feat(screenshot): full-page capture, wait-for-selector, and --timeout",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-06-17T23:02:28Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "b3e1c80b369d0fec40e28b72e010d834184141e3",
"body": "Render a built HTML file, a file://http(s) URL, or every *.html in a\ndist directory to PNG/JPEG/WebP using Bun's headless WebView (system\nWebKit on macOS) — zero external dependencies, no browser to install.\n\n stx screenshot dist --out screenshots --width 1440 --height 2200",
"is_bot": false,
"headline": "feat(cli): add screenshot command powered by Bun's native WebView",
"author_name": "Chris",
"author_login": "chrisbbreuer",
"committed_at": "2026-06-17T22:43:21Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "d77bb9c1514e8f3305287800603d552e99aa853f",
"body": "Relocate to the conventional config/ directory; stx resolves config/stx.ts via bunfig (it searches ./config), so config loading is unchanged. Fix up imageoptim's relative imports for the deeper path.\n\nAlso extend story findConfigFile() to search config/ and .config/ (matching bunfig's resolution ord\n[…]\n dev/story config-change watcher keeps working after configs move out of the project root. getConfigModifiedTime() benefits via findConfigFile(). Adds a unit test covering root and config/ resolution.",
"is_bot": false,
"headline": "chore(config): move stx.config.ts to config/stx.ts",
"author_name": "glennmichael123",
"author_login": "glennmichael123",
"committed_at": "2026-06-17T16:04:03Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "41b71100a13f4c724ed1dac74541a4924d09916c",
"body": "Relocate to the conventional config/ directory. bunfig already resolves config/crosswind.ts (it searches ./config), so crosswind config loading is unchanged.",
"is_bot": false,
"headline": "chore(config): move crosswind.config.ts to config/crosswind.ts",
"author_name": "glennmichael123",
"author_login": "glennmichael123",
"committed_at": "2026-06-17T15:51:43Z",
"body_truncated": false,
"is_coding_agent": false
},
{
"oid": "308ce736d13987770c0a77a7645bf12f88ee30fb",
"body": "The bun-plugin dev server (`stx-serve`, `bun .../serve.js`) sourced its config\nfrom bunfig's loadConfig (the raw object) and omitted `analytics` from the\nprocessDirectives options allowlist — so injectAnalytics never ran there.\nA plugin's setup() can mutate the loaded config (e.g. an analytics plugi\n[…]\nth native providers (fathom/GA/…) and\nplugin-injected trackers inject on this serve path, matching the SSG and\n`stx dev`/`stx serve` CLI paths.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(bun-plugin): forward analytics config on the serve path (#1760)",
"author_name": "Glenn Michael Torregosa",
"author_login": "glennmichael123",
"committed_at": "2026-06-17T09:31:58Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "ff2ef9ee6867ce477d110c1b2fd5875a55cb9595",
"body": "…ables for components\n\nSTX_AUTO_IMPORTS is the symbol list the compiler scans a component <script client>\nagainst to decide which window.stx helpers to destructure into the generated mount\nscope. It omitted useReactiveProp (plus useFetch, useLocalStorage, useSessionStorage,\nuseCookie, useWebSocket, \n[…]\ne data-stx-scope preamble.\n- includes.ts: add the component-API + composables to the wrapClientScript preamble.\n\nAll added names are real keys on the window.stx runtime object assembled in signals.ts.",
"is_bot": false,
"headline": "fix(client-script): destructure useReactiveProp + storage/head compos…",
"author_name": "glennmichael123",
"author_login": "glennmichael123",
"committed_at": "2026-06-15T16:38:52Z",
"body_truncated": true,
"is_coding_agent": false
},
{
"oid": "c571492f80c9ee75ec37c707d5e73812f75597ba",
"body": "…own signals (#1759)\n\nA partial's <script> is stripped before its body expressions are\nprocessed (includes.ts ~L925), so processExpressions' usesSignalsInScript\ngate couldn't see the partial's own state()/derived() and evaluated\n`{{ signalCall() }}` server-side (undefined → emptied), consuming the\nm\n[…]\nDirectives regression test (3 cases: signal\npartial preserves, server partial evaluates, signal-free partial not\nover-preserved).\n\nFixes #1758.\n\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>",
"is_bot": false,
"headline": "fix(includes): preserve {{ }} in @include partials that define their …",
"author_name": "Glenn Michael Torregosa",
"author_login": "glennmichael123",
"committed_at": "2026-06-15T10:55:58Z",
"body_truncated": true,
"is_coding_agent": true
},
{
"oid": "0bb61e7848c3095ab7b94b41674f01b6d680d7b8",
"body": "Also reconciles the lockfile's drifted @stacksjs/* entries (0.2.71 -> 0.2.72)\nthat bun install resolved alongside the crosswind bump.",
"is_bot": false,
"headline": "chore(deps): upgrade @cwcss/crosswind to 0.2.6",
"author_name": "glennmichael123",
"author_login": "glennmichael123",
"committed_at": "2026-06-13T12:05:27Z",
"body_truncated": false,
"is_coding_agent": false
}
],
"releases_count": 72,
"commits_last_year": 1323,
"latest_release_at": "2026-07-19T23:06:11Z",
"latest_release_tag": "v0.2.99",
"releases_from_tags": false,
"days_since_last_push": 0,
"active_weeks_last_year": 45,
"days_since_latest_release": 5,
"mean_days_between_releases": 0.6
},
"community": {
"has_readme": true,
"has_license": true,
"has_description": true,
"has_contributing": true,
"health_percentage": 75,
"has_issue_template": false,
"has_code_of_conduct": true,
"has_pull_request_template": false
},
"ecosystem": {
"packages": [
{
"name": "bun-plugin-stx",
"exists": true,
"license": "MIT",
"keywords": [
"blade",
"css",
"bun",
"stx",
"plugin",
"generation",
"typescript",
"stacks"
],
"ecosystem": "npm",
"matches_repo": true,
"registry_url": "https://www.npmjs.com/package/bun-plugin-stx",
"is_deprecated": false,
"latest_version": "0.2.99",
"repository_url": "https://github.com/stacksjs/stx",
"versions_count": 83,
"total_downloads": null,
"dependents_count": null,
"deprecation_note": null,
"maintainers_count": 1,
"monthly_downloads": 207105,
"first_published_at": "2025-04-30T21:52:58.940000Z",
"latest_published_at": "2026-07-19T23:05:00.283000Z",
"latest_version_yanked": null,
"days_since_latest_publish": 5
}
]
},
"popularity": {
"forks": 2,
"stars": 19,
"watchers": 1,
"fork_history": {
"days": [
{
"date": "2025-11-06",
"count": 1
},
{
"date": "2026-01-30",
"count": 1
}
],
"complete": true,
"collected": 2,
"total_forks": 2
},
"star_history": null,
"open_issues_and_prs": 27
},
"ai_readiness": {
"has_nix": false,
"example_dirs": [
"examples"
],
"has_llms_txt": false,
"has_dockerfile": false,
"has_mcp_signal": false,
"bootstrap_files": [],
"api_schema_files": [],
"has_devcontainer": false,
"typecheck_configs": [
"packages/bun-plugin/tsconfig.json"
],
"toolchain_manifests": [],
"largest_source_bytes": 1042457,
"source_files_sampled": 60608,
"oversized_source_files": 89,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 58471
},
"dependencies": {
"manifests": [
"package.json"
],
"advisories": {
"error": null,
"scope": "published_package",
"source": "osv",
"findings": [],
"collected": true,
"malicious": [],
"truncated": false,
"by_severity": {},
"advisory_count": 0,
"affected_count": 0,
"assessed_count": 22,
"malicious_count": 0,
"assessed_package": "npm:bun-plugin-stx@0.2.99",
"unassessed_count": 0,
"direct_affected_count": 0
},
"ecosystems": [
"npm"
],
"dependencies": [
{
"name": "@cwcss/crosswind",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.2.6"
},
{
"name": "very-happy-dom",
"manifest": "package.json",
"ecosystem": "npm",
"version_constraint": "^0.1.9"
},
{
"name": "@stacksjs/stx",
"manifest": "packages/bun-plugin/package.json",
"ecosystem": "npm",
"version_constraint": "^0.2.72"
},
{
"name": "stx-router",
"manifest": "packages/bun-plugin/package.json",
"ecosystem": "npm",
"version_constraint": "^0.2.72"
}
],
"all_dependencies": {
"error": null,
"source": "github-sbom",
"packages": [
{
"name": "@cwcss/crosswind",
"direct": true,
"version": "^0.2.6",
"ecosystem": "npm"
},
{
"name": "@stacksjs/stx",
"direct": true,
"version": "^0.2.72",
"ecosystem": "npm"
},
{
"name": "stx-router",
"direct": true,
"version": "^0.2.72",
"ecosystem": "npm"
},
{
"name": "very-happy-dom",
"direct": true,
"version": "^0.1.9",
"ecosystem": "npm"
},
{
"name": "@11ty/eleventy",
"direct": false,
"version": "^3.1.5",
"ecosystem": "npm"
},
{
"name": "@capacitor/android",
"direct": false,
"version": "^8.3.0",
"ecosystem": "npm"
},
{
"name": "@capacitor/app",
"direct": false,
"version": "^8.1.0",
"ecosystem": "npm"
},
{
"name": "@capacitor/cli",
"direct": false,
"version": "^8.3.0",
"ecosystem": "npm"
},
{
"name": "@capacitor/core",
"direct": false,
"version": "^8.3.0",
"ecosystem": "npm"
},
{
"name": "@capacitor/haptics",
"direct": false,
"version": "^8.0.2",
"ecosystem": "npm"
},
{
"name": "@capacitor/ios",
"direct": false,
"version": "^8.3.0",
"ecosystem": "npm"
},
{
"name": "@capacitor/keyboard",
"direct": false,
"version": "^8.0.2",
"ecosystem": "npm"
},
{
"name": "@capacitor/splash-screen",
"direct": false,
"version": "^8.0.1",
"ecosystem": "npm"
},
{
"name": "@capacitor/status-bar",
"direct": false,
"version": "^8.0.2",
"ecosystem": "npm"
},
{
"name": "@iconify-json/f7",
"direct": false,
"version": "^1.2.2",
"ecosystem": "npm"
},
{
"name": "@iconify/json",
"direct": false,
"version": "^2.2.463",
"ecosystem": "npm"
},
{
"name": "@stacksjs/clapp",
"direct": false,
"version": "^0.2.0",
"ecosystem": "npm"
},
{
"name": "@stacksjs/ts-cloud",
"direct": false,
"version": "^0.7.26",
"ecosystem": "npm"
},
{
"name": "@stacksjs/ts-i18n",
"direct": false,
"version": "^0.1.11",
"ecosystem": "npm"
},
{
"name": "@types/bun",
"direct": false,
"version": "^1.3.11",
"ecosystem": "npm"
},
{
"name": "@types/bun",
"direct": false,
"version": "latest",
"ecosystem": "npm"
},
{
"name": "@types/dompurify",
"direct": false,
"version": "^3.2.0",
"ecosystem": "npm"
},
{
"name": "@types/marked",
"direct": false,
"version": "^6.0.0",
"ecosystem": "npm"
},
{
"name": "@types/sanitize-html",
"direct": false,
"version": "^2.16.1",
"ecosystem": "npm"
},
{
"name": "@types/vscode",
"direct": false,
"version": "^1.110.0",
"ecosystem": "npm"
},
{
"name": "@types/ws",
"direct": false,
"version": "^8.18.1",
"ecosystem": "npm"
},
{
"name": "@vscode/vsce",
"direct": false,
"version": "^3.7.2-12",
"ecosystem": "npm"
},
{
"name": "better-dx",
"direct": false,
"version": "^0.2.15",
"ecosystem": "npm"
},
{
"name": "bun-plugin-dtsx",
"direct": false,
"version": "^0.21.17",
"ecosystem": "npm"
},
{
"name": "bunfig",
"direct": false,
"version": "^0.15.15",
"ecosystem": "npm"
},
{
"name": "dompurify",
"direct": false,
"version": "^3.3.3",
"ecosystem": "npm"
},
{
"name": "ejs",
"direct": false,
"version": "^5.0.1",
"ecosystem": "npm"
},
{
"name": "gray-matter",
"direct": false,
"version": "^4.0.3",
"ecosystem": "npm"
},
{
"name": "handlebars",
"direct": false,
"version": "^4.7.9",
"ecosystem": "npm"
},
{
"name": "happy-dom",
"direct": false,
"version": "^20.8.9",
"ecosystem": "npm"
},
{
"name": "isomorphic-dompurify",
"direct": false,
"version": "^3.7.1",
"ecosystem": "npm"
},
{
"name": "js-yaml",
"direct": false,
"version": "^4.1.1",
"ecosystem": "npm"
},
{
"name": "jsdom",
"direct": false,
"version": "^29.0.1",
"ecosystem": "npm"
},
{
"name": "liquidjs",
"direct": false,
"version": "^10.25.2",
"ecosystem": "npm"
},
{
"name": "markdown-it",
"direct": false,
"version": "^14.1.1",
"ecosystem": "npm"
},
{
"name": "marked",
"direct": false,
"version": "^17.0.5",
"ecosystem": "npm"
},
{
"name": "mitata",
"direct": false,
"version": "^1.0.34",
"ecosystem": "npm"
},
{
"name": "nunjucks",
"direct": false,
"version": "^3.2.4",
"ecosystem": "npm"
},
{
"name": "pickier",
"direct": false,
"version": "^0.1.35",
"ecosystem": "npm"
},
{
"name": "prettier",
"direct": false,
"version": "^3.8.1",
"ecosystem": "npm"
},
{
"name": "pug",
"direct": false,
"version": "^3.0.4",
"ecosystem": "npm"
},
{
"name": "remark",
"direct": false,
"version": "^15.0.1",
"ecosystem": "npm"
},
{
"name": "remark-html",
"direct": false,
"version": "^16.0.1",
"ecosystem": "npm"
},
{
"name": "sanitize-html",
"direct": false,
"version": "^2.17.2",
"ecosystem": "npm"
},
{
"name": "showdown",
"direct": false,
"version": "^2.1.0",
"ecosystem": "npm"
},
{
"name": "tinybench",
"direct": false,
"version": "^6.0.0",
"ecosystem": "npm"
},
{
"name": "ts-broadcasting",
"direct": false,
"version": "^0.0.8",
"ecosystem": "npm"
},
{
"name": "ts-images",
"direct": false,
"version": "^0.1.9",
"ecosystem": "npm"
},
{
"name": "ts-syntax-highlighter",
"direct": false,
"version": "^0.2.1",
"ecosystem": "npm"
},
{
"name": "typescript",
"direct": false,
"version": "^7.0.2",
"ecosystem": "npm"
},
{
"name": "vscode-html-languageservice",
"direct": false,
"version": "^5.6.2",
"ecosystem": "npm"
},
{
"name": "vscode-languageclient",
"direct": false,
"version": "^9.0.1",
"ecosystem": "npm"
},
{
"name": "vscode-languageserver-textdocument",
"direct": false,
"version": "^1.0.12",
"ecosystem": "npm"
},
{
"name": "vscode-languageserver-types",
"direct": false,
"version": "^3.17.5",
"ecosystem": "npm"
},
{
"name": "ws",
"direct": false,
"version": "^8.20.0",
"ecosystem": "npm"
},
{
"name": "xss",
"direct": false,
"version": "^1.0.15",
"ecosystem": "npm"
}
],
"collected": true,
"truncated": false,
"total_count": 61,
"direct_count": 4,
"indirect_count": 57
}
},
"maintainership": {
"issues": {
"open_prs": 14,
"merged_prs": 67,
"open_issues": 13,
"closed_ratio": 0.866,
"closed_issues": 84,
"closed_unmerged_prs": 1603
},
"bus_factor": 2,
"bot_contributors": 2,
"top_contributors": [
{
"type": "User",
"login": "glennmichael123",
"commits": 650,
"avatar_url": "https://avatars.githubusercontent.com/u/29087513?v=4"
},
{
"type": "User",
"login": "chrisbbreuer",
"commits": 638,
"avatar_url": "https://avatars.githubusercontent.com/u/6228425?v=4"
},
{
"type": "User",
"login": "iamzjohn",
"commits": 146,
"avatar_url": "https://avatars.githubusercontent.com/u/20513587?v=4"
},
{
"type": "User",
"login": "fingersandmind",
"commits": 24,
"avatar_url": "https://avatars.githubusercontent.com/u/37568966?v=4"
}
],
"contributors_sampled": 4,
"top_contributor_share": 0.446
},
"quality_signals": {
"has_ci": true,
"has_tests": true,
"ci_workflows": [
"buddy-bot.yml",
"ci.yml",
"release.yml"
],
"has_docs_dir": true,
"linter_configs": [],
"has_editorconfig": true,
"has_linter_config": false,
"has_precommit_config": false
},
"security_signals": {
"lockfiles": [],
"scorecard": null,
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": false
},
"contribution_flow": {
"collected": true,
"ci_last_run_at": "2026-07-25T23:00:01Z",
"oldest_open_prs": [
{
"number": 1662,
"created_at": "2026-04-05T06:42:45Z",
"last_comment_at": "2026-04-05T06:42:51Z",
"last_comment_author": "netlify"
},
{
"number": 1663,
"created_at": "2026-04-06T20:27:26Z",
"last_comment_at": "2026-04-06T20:27:32Z",
"last_comment_author": "netlify"
},
{
"number": 1665,
"created_at": "2026-04-07T06:50:22Z",
"last_comment_at": "2026-04-07T06:54:31Z",
"last_comment_author": "netlify"
},
{
"number": 1691,
"created_at": "2026-04-30T18:53:42Z",
"last_comment_at": "2026-04-30T18:53:47Z",
"last_comment_author": "netlify"
},
{
"number": 1724,
"created_at": "2026-05-26T07:41:07Z",
"last_comment_at": "2026-05-26T07:41:14Z",
"last_comment_author": "netlify"
},
{
"number": 1750,
"created_at": "2026-06-03T11:55:27Z",
"last_comment_at": "2026-06-03T11:55:36Z",
"last_comment_author": "netlify"
},
{
"number": 1751,
"created_at": "2026-06-04T00:33:10Z",
"last_comment_at": "2026-06-04T00:33:14Z",
"last_comment_author": "netlify"
},
{
"number": 1755,
"created_at": "2026-06-08T17:29:14Z",
"last_comment_at": "2026-06-08T18:01:14Z",
"last_comment_author": "netlify"
},
{
"number": 1761,
"created_at": "2026-06-18T15:34:40Z",
"last_comment_at": "2026-06-18T15:34:46Z",
"last_comment_author": "netlify"
},
{
"number": 1762,
"created_at": "2026-06-20T18:53:02Z",
"last_comment_at": "2026-06-20T18:53:07Z",
"last_comment_author": "netlify"
},
{
"number": 1763,
"created_at": "2026-06-20T18:56:43Z",
"last_comment_at": "2026-06-20T18:56:49Z",
"last_comment_author": "netlify"
},
{
"number": 1764,
"created_at": "2026-06-23T15:25:17Z",
"last_comment_at": "2026-06-23T15:25:22Z",
"last_comment_author": "netlify"
},
{
"number": 1774,
"created_at": "2026-07-07T14:17:04Z",
"last_comment_at": "2026-07-07T14:17:10Z",
"last_comment_author": "netlify"
},
{
"number": 1779,
"created_at": "2026-07-16T13:21:18Z",
"last_comment_at": "2026-07-16T13:21:25Z",
"last_comment_author": "netlify"
}
],
"last_merged_pr_at": "2026-07-10T15:34:25Z",
"ci_last_conclusion": null,
"oldest_open_issues": [
{
"number": 1,
"created_at": "2025-02-03T21:58:44Z",
"last_comment_at": "2026-05-20T11:09:40Z",
"last_comment_author": "glennmichael123"
},
{
"number": 325,
"created_at": "2025-10-22T14:33:17Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1753,
"created_at": "2026-06-08T12:43:02Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1754,
"created_at": "2026-06-08T12:43:23Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1757,
"created_at": "2026-06-13T13:25:04Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1766,
"created_at": "2026-07-02T16:46:13Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1771,
"created_at": "2026-07-07T09:22:41Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1772,
"created_at": "2026-07-07T11:18:57Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1773,
"created_at": "2026-07-07T11:22:26Z",
"last_comment_at": "2026-07-07T11:41:53Z",
"last_comment_author": "glennmichael123"
},
{
"number": 1775,
"created_at": "2026-07-07T14:27:10Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1777,
"created_at": "2026-07-09T17:19:19Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1780,
"created_at": "2026-07-18T12:32:12Z",
"last_comment_at": null,
"last_comment_author": null
},
{
"number": 1781,
"created_at": "2026-07-18T12:54:04Z",
"last_comment_at": null,
"last_comment_author": null
}
]
}
},
"config": {
"disabled_metrics": [],
"disabled_categories": [],
"disabled_components": {}
},
"source": {
"url": "https://github.com/stacksjs/stx",
"host": "github.com",
"name": "stx",
"owner": "stacksjs"
},
"metrics": {
"overall": {
"key": "overall",
"band": "excellent",
"name": "Overall health",
"note": "The weighted overall 71 is calibrated to 84 on the published index scale (record calibration 2026-08-02).",
"notes": [
{
"code": "overall_calibration",
"params": {
"raw": 71,
"calibrated": 84,
"calibration": "2026-08-02"
}
}
],
"value": 84,
"inputs": {
"security": 52,
"vitality": 97,
"community": 60,
"governance": 64,
"calibration": "2026-08-02",
"engineering": 77,
"ai_readiness": 64,
"weighted_overall_raw": 71
},
"components": []
},
"categories": [
{
"key": "vitality",
"band": "exceptional",
"name": "Vitality",
"value": 97,
"weight": 0.21,
"metrics": [
{
"key": "development_activity",
"band": "exceptional",
"name": "Development activity",
"note": null,
"notes": [],
"value": 95,
"inputs": {
"commits_last_year": 1323,
"human_commit_share": 1,
"days_since_last_push": 0,
"active_weeks_last_year": 45
},
"components": [
{
"key": "push_recency",
"name": "Push recency",
"detail": "last push 0 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "push_recency",
"params": {
"days": 0
}
}
],
"max_points": 36
},
{
"key": "commit_cadence",
"name": "Commit cadence",
"detail": "45/52 weeks with commits",
"points": 31.2,
"status": "partial",
"details": [
{
"code": "commit_cadence_weeks",
"params": {
"weeks": 45
}
}
],
"max_points": 36
},
{
"key": "commit_volume",
"name": "Commit volume",
"detail": "1323 commits in the last year",
"points": 18,
"status": "met",
"details": [
{
"code": "commits_last_year",
"params": {
"count": 1323
}
}
],
"max_points": 18
},
{
"key": "openssf_scorecard_maintained",
"name": "OpenSSF Scorecard: Maintained",
"detail": "OpenSSF Scorecard unavailable",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "release_discipline",
"band": "exceptional",
"name": "Release discipline",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"releases_count": 72,
"latest_release_tag": "v0.2.99",
"releases_from_tags": false,
"days_since_latest_release": 5,
"mean_days_between_releases": 0.6
},
"components": [
{
"key": "ships_releases",
"name": "Ships releases",
"detail": "72 releases published",
"points": 27,
"status": "met",
"details": [
{
"code": "releases_published",
"params": {
"count": 72
}
}
],
"max_points": 27
},
{
"key": "release_recency",
"name": "Release recency",
"detail": "latest release 5 days ago",
"points": 36,
"status": "met",
"details": [
{
"code": "release_recency",
"params": {
"days": 5
}
}
],
"max_points": 36
},
{
"key": "release_cadence",
"name": "Release cadence",
"detail": "a release every ~0.6 days",
"points": 27,
"status": "met",
"details": [
{
"code": "release_cadence",
"params": {
"gap": 0.6
}
}
],
"max_points": 27
},
{
"key": "openssf_scorecard_signed_releases",
"name": "OpenSSF Scorecard: Signed-Releases",
"detail": "OpenSSF Scorecard unavailable",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "abandonment",
"band": "exceptional",
"name": "Abandonment",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"cap": null,
"state": "maintained",
"guards": [],
"signals": [],
"red_flag": false,
"multiplier_pct": 100,
"declared_reason": null,
"unverified_reason": null,
"unanswered_open_prs": null,
"unanswered_open_issues": null,
"days_since_last_merged_pr": null,
"days_since_last_human_commit": 8,
"days_since_last_human_commit_is_floor": false
},
"components": [
{
"key": "project_is_still_maintained",
"name": "Project is still maintained",
"detail": "last human commit 8 days ago",
"points": 100,
"status": "met",
"details": [
{
"code": "abandonment_maintained",
"params": {
"days": 8
}
}
],
"max_points": 100
}
]
}
],
"description": "Is the project alive — is code being written and are releases shipping?"
},
{
"key": "community",
"band": "moderate",
"name": "Community & Adoption",
"value": 60,
"weight": 0.17,
"metrics": [
{
"key": "popularity",
"band": "at_risk",
"name": "Popularity & adoption",
"note": null,
"notes": [],
"value": 20,
"inputs": {
"forks": 2,
"stars": 19,
"watchers": 1,
"growth_state": "unverified",
"growth_factor_pct": 100,
"growth_unverified_reason": "no_history"
},
"components": [
{
"key": "stars",
"name": "Stars",
"detail": "19 stars",
"points": 20.4,
"status": "partial",
"details": [
{
"code": "stars",
"params": {
"count": 19
}
}
],
"max_points": 60
},
{
"key": "forks",
"name": "Forks",
"detail": "2 forks",
"points": 0,
"status": "missed",
"details": [
{
"code": "forks",
"params": {
"count": 2
}
}
],
"max_points": 25
},
{
"key": "watchers",
"name": "Watchers",
"detail": "1 watchers",
"points": 0,
"status": "missed",
"details": [
{
"code": "watchers",
"params": {
"count": 1
}
}
],
"max_points": 15
}
]
},
{
"key": "community_health",
"band": "excellent",
"name": "Community health",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_readme": true,
"has_license": true,
"readme_badges": null,
"has_contributing": true,
"has_issue_template": false,
"has_code_of_conduct": true,
"readme_badge_services": [],
"has_pull_request_template": false
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 22.5,
"status": "met",
"details": [],
"max_points": 22.5
},
{
"key": "license",
"name": "License",
"detail": "recognized license (MIT)",
"points": 22.5,
"status": "met",
"details": [
{
"code": "license_standard",
"params": {}
},
{
"code": "license_spdx",
"params": {
"spdx": "MIT"
}
}
],
"max_points": 22.5
},
{
"key": "contributing_guide",
"name": "CONTRIBUTING guide",
"detail": null,
"points": 18,
"status": "met",
"details": [],
"max_points": 18
},
{
"key": "code_of_conduct",
"name": "Code of conduct",
"detail": null,
"points": 13.5,
"status": "met",
"details": [],
"max_points": 13.5
},
{
"key": "issue_template",
"name": "Issue template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 7.2
},
{
"key": "pr_template",
"name": "PR template",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 6.3
}
]
},
{
"key": "ecosystem_adoption",
"band": "excellent",
"name": "Ecosystem adoption (downloads)",
"note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"registry_dependents"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 89,
"inputs": {
"packages": [
"bun-plugin-stx"
],
"dependents": null,
"ecosystems": "npm",
"total_downloads": null,
"monthly_downloads": 207105
},
"components": [
{
"key": "monthly_downloads",
"name": "Monthly downloads",
"detail": "207,105 downloads/month across npm",
"points": 70.9,
"status": "partial",
"details": [
{
"code": "downloads_monthly",
"params": {
"count": 207105,
"ecosystems": "npm"
}
}
],
"max_points": 80
},
{
"key": "registry_dependents",
"name": "Registry dependents",
"detail": "not reported by this ecosystem",
"points": 0,
"status": "excluded",
"details": [
{
"code": "not_reported_by_this_ecosystem",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
},
{
"key": "governance",
"band": "moderate",
"name": "Sustainability & Governance",
"value": 64,
"weight": 0.23,
"metrics": [
{
"key": "maintainer_resilience",
"band": "weak",
"name": "Maintainer resilience (bus factor)",
"note": null,
"notes": [],
"value": 48,
"inputs": {
"bus_factor": 2,
"contributors_sampled": 4,
"top_contributor_share": 0.446
},
"components": [
{
"key": "bus_factor",
"name": "Bus factor",
"detail": "2 contributor(s) cover half of all commits",
"points": 25.2,
"status": "partial",
"details": [
{
"code": "bus_factor",
"params": {
"count": 2
}
}
],
"max_points": 54
},
{
"key": "commit_distribution",
"name": "Commit distribution",
"detail": "top contributor authored 45% of commits",
"points": 12.5,
"status": "partial",
"details": [
{
"code": "top_contributor_share",
"params": {
"share": 45
}
}
],
"max_points": 22.5
},
{
"key": "contributor_breadth",
"name": "Contributor breadth",
"detail": "4 contributors",
"points": 5.4,
"status": "partial",
"details": [
{
"code": "contributors_sampled",
"params": {
"count": 4
}
}
],
"max_points": 13.5
},
{
"key": "openssf_scorecard_contributors",
"name": "OpenSSF Scorecard: Contributors",
"detail": "OpenSSF Scorecard unavailable",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "responsiveness",
"band": "moderate",
"name": "Issue & PR responsiveness",
"note": "Excluded from scoring (no data or not applicable): Newcomer PR acceptance. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"newcomer_pr_acceptance"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 52,
"inputs": {
"merged_prs": 67,
"open_issues": 13,
"closed_issues": 84,
"prs_merged_7d": null,
"prs_decided_7d": null,
"prs_merged_30d": null,
"prs_decided_30d": null,
"issue_closed_ratio": 0.866,
"closed_unmerged_prs": 1603,
"first_time_authors_30d": null,
"first_time_prs_merged_30d": null,
"first_time_prs_decided_30d": null
},
"components": [
{
"key": "issue_resolution",
"name": "Issue resolution",
"detail": "87% of issues closed",
"points": 36.4,
"status": "partial",
"details": [
{
"code": "issues_closed_share",
"params": {
"share": 87
}
}
],
"max_points": 42
},
{
"key": "pr_acceptance",
"name": "PR acceptance",
"detail": "67/1670 decided PRs merged",
"points": 1.2,
"status": "partial",
"details": [
{
"code": "decided_prs_merged",
"params": {
"merged": 67,
"decided": 1670
}
}
],
"max_points": 30
},
{
"key": "newcomer_pr_acceptance",
"name": "Newcomer PR acceptance",
"detail": "no first-time contributor's PR decided in 30d",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_newcomer_prs",
"params": {
"days": 30
}
}
],
"max_points": 13
},
{
"key": "openssf_scorecard_code_review",
"name": "OpenSSF Scorecard: Code-Review",
"detail": "OpenSSF Scorecard unavailable",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 15
}
]
},
{
"key": "stewardship",
"band": "good",
"name": "Ownership & stewardship",
"note": null,
"notes": [],
"value": 66,
"inputs": {
"followers": 119,
"owner_type": "Organization",
"is_verified": null,
"owner_login": "stacksjs",
"public_repos": 153,
"account_age_days": 1395
},
"components": [
{
"key": "ownership_backing",
"name": "Ownership backing",
"detail": "organization-owned",
"points": 30,
"status": "met",
"details": [
{
"code": "owner_organization",
"params": {}
}
],
"max_points": 30
},
{
"key": "verified_domain",
"name": "Verified domain",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "owner_reach",
"name": "Owner reach",
"detail": "119 followers of stacksjs",
"points": 14.9,
"status": "partial",
"details": [
{
"code": "owner_followers",
"params": {
"count": 119,
"login": "stacksjs"
}
}
],
"max_points": 25
},
{
"key": "track_record",
"name": "Track record",
"detail": "153 public repos, account ~3 yr old",
"points": 20.6,
"status": "partial",
"details": [
{
"code": "public_repos",
"params": {
"count": 153
}
},
{
"code": "account_age_years",
"params": {
"years": 3
}
}
],
"max_points": 25
}
]
},
{
"key": "package_maintenance",
"band": "exceptional",
"name": "Package maintenance",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"packages": [
"bun-plugin-stx"
],
"ecosystems": "npm",
"any_deprecated": false,
"min_days_since_publish": 5
},
"components": [
{
"key": "published_resolvable",
"name": "Published & resolvable",
"detail": "1 package(s) on npm",
"points": 25,
"status": "met",
"details": [
{
"code": "packages_published",
"params": {
"count": 1,
"ecosystems": "npm"
}
}
],
"max_points": 25
},
{
"key": "publish_recency",
"name": "Publish recency",
"detail": "latest publish 5 days ago",
"points": 35,
"status": "met",
"details": [
{
"code": "publish_recency",
"params": {
"days": 5
}
}
],
"max_points": 35
},
{
"key": "version_history",
"name": "Version history",
"detail": "83 published versions",
"points": 20,
"status": "met",
"details": [
{
"code": "published_versions",
"params": {
"count": 83
}
}
],
"max_points": 20
},
{
"key": "not_deprecated",
"name": "Not deprecated",
"detail": "active, not deprecated or yanked",
"points": 20,
"status": "met",
"details": [
{
"code": "package_not_deprecated",
"params": {}
}
],
"max_points": 20
}
]
}
],
"description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
},
{
"key": "engineering",
"band": "good",
"name": "Engineering Quality",
"value": 77,
"weight": 0.19,
"metrics": [
{
"key": "engineering_practices",
"band": "good",
"name": "Engineering practices",
"note": null,
"notes": [],
"value": 68,
"inputs": {
"has_ci": true,
"has_tests": true,
"has_editorconfig": true,
"has_linter_config": false,
"has_precommit_config": false
},
"components": [
{
"key": "ci_workflows",
"name": "CI workflows",
"detail": "3 workflow(s)",
"points": 24,
"status": "met",
"details": [
{
"code": "ci_workflows",
"params": {
"count": 3
}
}
],
"max_points": 24
},
{
"key": "tests_present",
"name": "Tests present",
"detail": null,
"points": 24,
"status": "met",
"details": [],
"max_points": 24
},
{
"key": "linter_config",
"name": "Linter config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 16
},
{
"key": "pre_commit_hooks",
"name": "Pre-commit hooks",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 9.6
},
{
"key": "editorconfig",
"name": ".editorconfig",
"detail": null,
"points": 6.4,
"status": "met",
"details": [],
"max_points": 6.4
},
{
"key": "openssf_scorecard_ci_tests",
"name": "OpenSSF Scorecard: CI-Tests",
"detail": "OpenSSF Scorecard unavailable",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 20
}
]
},
{
"key": "documentation",
"band": "excellent",
"name": "Documentation",
"note": null,
"notes": [],
"value": 90,
"inputs": {
"topics": [
"bun",
"components",
"css",
"html",
"templating-engine",
"blade",
"stacks"
],
"has_wiki": false,
"homepage": "https://stacks-stx.netlify.app",
"has_readme": true,
"has_docs_dir": true,
"has_description": true
},
"components": [
{
"key": "readme",
"name": "README",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "documentation_directory",
"name": "Documentation directory",
"detail": null,
"points": 25,
"status": "met",
"details": [],
"max_points": 25
},
{
"key": "documentation_homepage_site",
"name": "Documentation / homepage site",
"detail": "https://stacks-stx.netlify.app",
"points": 15,
"status": "met",
"details": [],
"max_points": 15
},
{
"key": "repository_description",
"name": "Repository description",
"detail": null,
"points": 10,
"status": "met",
"details": [],
"max_points": 10
},
{
"key": "topics",
"name": "Topics",
"detail": "7 topics",
"points": 10,
"status": "met",
"details": [
{
"code": "topics_count",
"params": {
"count": 7
}
}
],
"max_points": 10
},
{
"key": "wiki",
"name": "Wiki",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
}
]
}
],
"description": "Are baseline engineering and documentation practices in place?"
},
{
"key": "security",
"band": "moderate",
"name": "Security",
"value": 52,
"weight": 0.16,
"metrics": [
{
"key": "security_posture",
"band": "weak",
"name": "Security posture",
"note": "Excluded from scoring (no data or not applicable): Dependency lockfiles. Remaining weights renormalized.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"dependency_lockfiles"
]
}
},
{
"code": "weights_renormalized",
"params": {}
}
],
"value": 40,
"inputs": {
"source": "file_signals",
"lockfiles": [],
"manifests": [
"package.json"
],
"has_codeql_workflow": false,
"has_security_policy": true,
"has_dependabot_config": false
},
"components": [
{
"key": "security_policy_security_md",
"name": "Security policy (SECURITY.md)",
"detail": null,
"points": 30,
"status": "met",
"details": [],
"max_points": 30
},
{
"key": "dependabot_config",
"name": "Dependabot config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 25
},
{
"key": "dependency_lockfiles",
"name": "Dependency lockfiles",
"detail": "published library — lockfiles are an application concern, not expected",
"points": 0,
"status": "excluded",
"details": [
{
"code": "lockfiles_not_expected",
"params": {}
}
],
"max_points": 25
},
{
"key": "codeql_workflow",
"name": "CodeQL workflow",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
}
]
},
{
"key": "dependency_advisories",
"band": "exceptional",
"name": "Dependency advisories",
"note": "Excluded from scoring (no data or not applicable): No advisories left outstanding. Remaining weights renormalized. Matched the npm:bun-plugin-stx@0.2.99 runtime dependency closure — what installing the published package pulls in — 22 packages. Reachability is not analyzed.",
"notes": [
{
"code": "excluded_no_data",
"params": {
"components": [
"no_advisories_left_outstanding"
]
}
},
{
"code": "weights_renormalized",
"params": {}
},
{
"code": "advisories_scope_published",
"params": {
"package": "npm:bun-plugin-stx@0.2.99",
"assessed": 22
}
},
{
"code": "advisories_reachability",
"params": {}
}
],
"value": 100,
"inputs": {
"source": "osv",
"advisories": 0,
"affected_packages": 0,
"assessed_packages": 22,
"unassessed_packages": 0,
"affected_by_severity": "none",
"direct_affected_packages": 0
},
"components": [
{
"key": "direct_dependencies_free_of_known_advisories",
"name": "Direct dependencies free of known advisories",
"detail": "no direct dependency carries a known advisory",
"points": 35,
"status": "met",
"details": [
{
"code": "no_direct_advisories",
"params": {}
}
],
"max_points": 35
},
{
"key": "indirect_dependencies_free_of_known_advisories",
"name": "Indirect dependencies free of known advisories",
"detail": "no indirect dependency carries a known advisory",
"points": 25,
"status": "met",
"details": [
{
"code": "no_indirect_advisories",
"params": {}
}
],
"max_points": 25
},
{
"key": "no_advisories_left_outstanding",
"name": "No advisories left outstanding",
"detail": "no advisory carries a publication date",
"points": 0,
"status": "excluded",
"details": [
{
"code": "advisories_no_publication_date",
"params": {}
}
],
"max_points": 40
}
]
},
{
"key": "malicious_dependencies",
"band": "exceptional",
"name": "Malicious dependencies",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"source": "osv",
"meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
"packages": [],
"red_flag": false,
"assessed_packages": 22,
"malicious_packages": 0,
"direct_malicious_packages": 0,
"withdrawn_malicious_packages": 0,
"installable_malicious_packages": 0
},
"components": [
{
"key": "no_dependency_reported_as_a_malicious_package",
"name": "No dependency reported as a malicious package",
"detail": "no dependency is reported as a malicious package",
"points": 100,
"status": "met",
"details": [
{
"code": "no_malicious_dependencies",
"params": {}
}
],
"max_points": 100
}
]
},
{
"key": "high_risk_jurisdiction_exposure",
"band": "exceptional",
"name": "High-Risk Jurisdiction Exposure",
"note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
"notes": [
{
"code": "jurisdiction_evidence_limits",
"params": {}
}
],
"value": 100,
"inputs": {
"meaning": "self-published location evidence; not nationality or citizenship",
"red_flag": false,
"exposures": [],
"policy_countries": [
"Russia",
"Iran",
"North Korea"
],
"commit_weight_rule": {
"min_commits": 50,
"min_commit_share": 0.1
},
"review_only_matches": 0,
"below_threshold_exposures": [],
"assessed_self_published_locations": 8
},
"components": [
{
"key": "policy_exposure_multiplier",
"name": "Policy exposure multiplier",
"detail": "no confirmed policy-scope location match",
"points": 100,
"status": "met",
"details": [
{
"code": "jurisdiction_no_match",
"params": {}
}
],
"max_points": 100
}
]
}
],
"description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
},
{
"key": "ai_readiness",
"band": "moderate",
"name": "AI Readiness",
"value": 64,
"weight": 0.04,
"metrics": [
{
"key": "ai_agent_context",
"band": "excellent",
"name": "Agent context & guidance",
"note": null,
"notes": [],
"value": 85,
"inputs": {
"has_llms_txt": false,
"legible_history_share": 1,
"agent_instruction_files": [
"CLAUDE.md"
],
"agent_instruction_max_bytes": 58471
},
"components": [
{
"key": "agent_instructions",
"name": "Agent instructions",
"detail": "CLAUDE.md",
"points": 45,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "CLAUDE.md"
}
}
],
"max_points": 45
},
{
"key": "machine_readable_docs_llms_txt",
"name": "Machine-readable docs (llms.txt)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 15
},
{
"key": "legible_commit_history",
"name": "Legible commit history",
"detail": "100 of 100 human commits state their intent (structured subject or explanatory body)",
"points": 40,
"status": "met",
"details": [
{
"code": "legible_history",
"params": {
"legible": 100,
"sampled": 100
}
}
],
"max_points": 40
}
]
},
{
"key": "ai_verify_loop",
"band": "weak",
"name": "Verify loop (build / test / typecheck)",
"note": null,
"notes": [],
"value": 43,
"inputs": {
"has_nix": false,
"has_tests": true,
"lockfiles": [],
"has_dockerfile": false,
"typed_language": true,
"bootstrap_files": [],
"has_devcontainer": false,
"has_linter_config": false,
"typecheck_configs": [
"packages/bun-plugin/tsconfig.json"
],
"agent_commit_share": 0.03,
"toolchain_manifests": [],
"dependency_bot_commit_share": 0
},
"components": [
{
"key": "one_command_bootstrap",
"name": "One-command bootstrap",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 18
},
{
"key": "automated_tests",
"name": "Automated tests",
"detail": null,
"points": 22,
"status": "met",
"details": [],
"max_points": 22
},
{
"key": "lint_format_config",
"name": "Lint / format config",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 11
},
{
"key": "static_type_checking",
"name": "Static type checking",
"detail": "packages/bun-plugin/tsconfig.json",
"points": 11,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "packages/bun-plugin/tsconfig.json"
}
}
],
"max_points": 11
},
{
"key": "reproducible_environment",
"name": "Reproducible environment",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 10
},
{
"key": "demonstrated_agent_practice",
"name": "Demonstrated agent practice",
"detail": "3 of the last 100 commits agent-authored or agent-credited",
"points": 6,
"status": "partial",
"details": [
{
"code": "agent_authored_commits",
"params": {
"count": 3,
"sampled": 100
}
}
],
"max_points": 10
},
{
"key": "automated_maintenance",
"name": "Automated maintenance",
"detail": "no automated dependency updates observed",
"points": 0,
"status": "missed",
"details": [
{
"code": "no_dependency_automation",
"params": {}
}
],
"max_points": 8
},
{
"key": "openssf_scorecard_pinned_dependencies",
"name": "OpenSSF Scorecard: Pinned-Dependencies",
"detail": "OpenSSF Scorecard unavailable",
"points": 0,
"status": "excluded",
"details": [
{
"code": "no_data",
"params": {}
}
],
"max_points": 10
}
]
},
{
"key": "ai_code_legibility",
"band": "exceptional",
"name": "Code legibility for models",
"note": null,
"notes": [],
"value": 100,
"inputs": {
"primary_language": "TypeScript",
"largest_source_bytes": 1042457,
"source_files_sampled": 60608,
"oversized_source_files": 89
},
"components": [
{
"key": "type_checkable_code",
"name": "Type-checkable code",
"detail": "TypeScript (statically typed)",
"points": 45,
"status": "met",
"details": [
{
"code": "statically_typed_language",
"params": {
"language": "TypeScript"
}
}
],
"max_points": 45
},
{
"key": "manageable_file_sizes",
"name": "Manageable file sizes",
"detail": "89/60608 source files over 60KB",
"points": 54.9,
"status": "partial",
"details": [
{
"code": "oversized_source_files",
"params": {
"kb": 60,
"sampled": 60608,
"oversized": 89
}
}
],
"max_points": 55
}
]
},
{
"key": "ai_interfaces",
"band": "weak",
"name": "Machine-readable interfaces",
"note": null,
"notes": [],
"value": 40,
"inputs": {
"example_dirs": [
"examples"
],
"has_mcp_signal": false,
"api_schema_files": []
},
"components": [
{
"key": "api_schema_openapi_graphql_proto",
"name": "API schema (OpenAPI/GraphQL/proto)",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 40
},
{
"key": "mcp_server",
"name": "MCP server",
"detail": null,
"points": 0,
"status": "missed",
"details": [],
"max_points": 20
},
{
"key": "runnable_examples",
"name": "Runnable examples",
"detail": "examples",
"points": 40,
"status": "met",
"details": [
{
"code": "file_list",
"params": {
"files": "examples"
}
}
],
"max_points": 40
}
]
}
],
"description": "How well is the repo equipped to be developed and maintained with AI coding agents? Carries a deliberately small weight: agent tooling is a real maintenance signal, but its absence must never gate the top of the scale (calibration saturates at raw 91, so 100/100 remains reachable with AI Readiness at zero)."
}
],
"classification": {
"labels": [
"library"
],
"scores": {
"plugin": 2,
"library": 6
},
"primary": "library",
"evidence": [
{
"tier": "distribution",
"label": "library",
"source": "registry:npm",
"weight": 6
},
{
"tier": "tags",
"label": "plugin",
"source": "tag:plugin",
"weight": 2
}
],
"artifacts": [],
"confidence": "medium",
"host_extension": false,
"runs_as_process": false,
"consumed_by_code": true
},
"metrics_version": "2.3.1"
},
"warnings": [
"Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
"File tree truncated by GitHub API; file-based signals may be incomplete",
"OpenSSF Scorecard timed out after 240s; skipping Scorecard checks"
],
"report_type": "repository",
"generated_at": "2026-07-25T23:07:10.806004Z",
"schema_version": "0.27.0",
"badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/s/stacksjs/stx.svg",
"full_name": "stacksjs/stx",
"license_state": "standard",
"license_spdx": "MIT"
}