公开记录
软件健康报告模式 0.27.0 · 指标 1.13.0 · 2026-07-29 03:51 UTC

wbd2023 / Quill

A reproducible style-policy compiler and linter orchestrator with built-in semantic checks, secure tool installation, requirement coverage, safe fixes and locally installable third-party packs.

GoApache-2.0★ 0 星标⑂ 0 复刻始于 2026年7月在 GitHub 上查看 ↗

wbd2023/Quill 的健康指数为 100 分中的 58 分,处于「中等」区间。 其得分最高的类别是Engineering Quality(78/100),最低的是Community & Adoption(36/100)。 最近一次更新在 1 天前。 近期的大部分工作由 1 位贡献者完成。

58
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

58
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

William Duong个人账户
0 关注者4 个公开仓库始于 2024年7月

该仓库由个人账户拥有。相较于组织支持的项目,单一所有者项目的延续性风险更高。

软件包生态系统

注册表软件包版本月下载量版本数最近发布
Gogithub.com/wbd2023/quillv0.1.0-18 天前

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

71良好 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 1 天前
8.3/36提交节奏 — 52 周中有 12 周有提交
18/18提交量 — 最近一年 135 次提交
0/10OpenSSF Scorecard:Maintained — project was created within the last 90 days. Please review its contents carefully
所用输入
commits_last_year135
human_commit_share1
days_since_last_push1
active_weeks_last_year12

发布纪律

84良好
评分方式
27/27有发布版本 — 已发布 1 个发布版本
36/36发布时效 — 最近一次发布版本于 8 天前
12.6/27发布节奏 — 节奏未知(仅一次发布)
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count1
latest_release_tagv0.1.0
releases_from_tags
days_since_latest_release8
mean_days_between_releases
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

36存在风险 · 占总体的 18%
评分方式
0/60星标 — 0 个星标
0/25复刻 — 0 个复刻
0/15关注者 — 0 位关注者
所用输入
forks0
stars0
watchers0
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

77良好
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(Apache-2.0)
18/18CONTRIBUTING 指南
0/13.5行为准则
0/7.2议题模板
6.3/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

44存在风险 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
0/22.5提交分布 — 头号贡献者编写了 100% 的提交
1.4/13.5贡献者广度 — 1 位贡献者
0/10OpenSSF Scorecard:Contributors — project has 0 contributing companies or organizations -- score normalized to 0
所用输入
bus_factor1
contributors_sampled1
top_contributor_share1
评分方式
0/46.8议题解决 — 没有议题或无数据
38.2/38.3PR 接受 — 已裁定的 PR 中 2/2 已合并
0/15OpenSSF Scorecard:Code-Review — Found 0/30 approved changesets -- score normalized to 0
所用输入
merged_prs2
open_issues0
closed_issues0
issue_closed_ratio
closed_unmerged_prs0
已排除计分(无数据或不适用):议题解决。 其余权重已重新归一化。
评分方式
10/30所有权背书 — 个人(用户)账户
0/20已验证域名 — 不适用于个人账户
0/25所有者影响力 — wbd2023 有 0 位关注者
9.1/25既往记录 — 4 个公开仓库,账户约 2 年
所用输入
followers0
owner_typeUser
is_verified
owner_loginwbd2023
public_repos4
account_age_days731
已排除计分(无数据或不适用):已验证域名。 其余权重已重新归一化。
评分方式
25/25已发布且可解析 — go 上有 1 个软件包
35/35发布时效 — 最近一次发布于 8 天前
4/20版本历史 — 1 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesgithub.com/wbd2023/quill
ecosystemsgo
any_deprecated
min_days_since_publish8

工程质量

基础的工程与文档实践是否到位?

78良好 · 占总体的 20%

工程实践

80良好
评分方式
24/24CI 工作流 — 2 个工作流
24/24存在测试
16/16Linter 配置 — .golangci.yml
0/9.6Pre-commit 钩子
0/6.4.editorconfig
0/20OpenSSF Scorecard:CI-Tests — 无数据
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config
已排除计分(无数据或不适用):OpenSSF Scorecard:CI-Tests。 其余权重已重新归一化。

文档

75良好
评分方式
30/30README
25/25文档目录
0/15文档 / 主页站点
10/10仓库描述
0/10主题标签
10/10Wiki
所用输入
topics
has_wiki
homepage
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

59中等 · 占总体的 16%

安全态势

49存在风险
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
2.2/7.5Branch-Protection — branch protection is not maximal on development and all release branches
0/2.5CI-Tests — 无数据
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
0/7.5Code-Review — Found 0/30 approved changesets -- score normalized to 0
0/2.5Contributors — project has 0 contributing companies or organizations -- score normalized to 0
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
0/7.5Maintained — project was created within the last 90 days. Please review its contents carefully
0/5Packaging — 无数据
5/5Pinned-Dependencies — all dependencies are pinned
0/5SAST — no SAST tool detected
2/5Security-Policy — security policy file detected
0/7.5Signed-Releases — 无数据
7.5/7.5Token-Permissions — GitHub workflow tokens follow principle of least privilege
7.5/7.5Vulnerabilities — 0 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated15
scorecard_versionv5.5.0
checks_inconclusive3
scorecard_aggregate4.9
已排除计分(无数据或不适用):ci_tests, packaging, signed_releases。 其余权重已重新归一化。
评分方式
35/35直接依赖不含已知公告 — 没有直接依赖携带已知公告
0/25间接依赖不含已知公告 — 在此范围内,传递依赖集合无法与开发和测试依赖区分
0/40没有长期未处理的公告 — 没有公告带有发布日期
所用输入
sourceosv
advisories0
affected_packages0
assessed_packages7
unassessed_packages0
affected_by_severitynone
direct_affected_packages0
已排除计分(无数据或不适用):间接依赖不含已知公告, 没有长期未处理的公告。 其余权重已重新归一化。 已将 7 个已解析依赖与 OSV 比对。 该仓库未发布任何索引可解析的软件包,因此改为评估仓库依赖图。该图将开发与测试版本固定同交付的依赖混在一起,因此仅对声明的运行时依赖计分;传递性发现仅作为背景信息列出,不计入评分。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

70良好 · 占总体的 0%
评分方式
0/45代理指令 — 没有 CLAUDE.md / AGENTS.md / 编辑器规则
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 100 次人类提交中有 98 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.98
agent_instruction_files
agent_instruction_max_bytes
评分方式
18/18一条命令的引导启动 — Makefile
22/22自动化测试
11/11Lint / 格式化配置 — .golangci.yml
11/11静态类型检查 — Go(静态类型)
10/10可复现环境 — lockfile
0/10已体现的代理实践 — 最近 100 次提交中没有代理编写的提交
0/8自动化维护 — 未观察到自动依赖更新
10/10OpenSSF Scorecard:Pinned-Dependencies — all dependencies are pinned
所用输入
has_nix
has_tests
lockfilesgo.sum
has_dockerfile
typed_language
bootstrap_filesMakefile
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0
toolchain_manifestsgo.mod
dependency_bot_commit_share0
评分方式
45/45可类型检查的代码 — Go(静态类型)
55/55可控的文件大小 — 采样的 509 个源文件中有 0 个超过 60KB
所用输入
primary_languageGo
largest_source_bytes11,518
source_files_sampled509
oversized_source_files0

关键数据

0GitHub 星标
1贡献者
135最近 12 个月提交数
1距最近推送天数
1发布版本数
1巴士系数(bus factor)
0开放议题
Go软件包生态系统数

更多细节

OpenSSF Scorecard 4.9 / 10
4.9综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-29 03:51 UTC

10Binary-Artifactsno binaries found in the repo
3Branch-Protectionbranch protection is not maximal on development and all release branches
不适用CI-Testsno pull request found
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
0Code-ReviewFound 0/30 approved changesets -- score normalized to 0
0Contributorsproject has 0 contributing companies or organizations -- score normalized to 0
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
0Maintainedproject was created within the last 90 days. Please review its contents carefully
不适用Packagingpackaging workflow not detected
10Pinned-Dependenciesall dependencies are pinned
0SASTno SAST tool detected
4Security-Policysecurity policy file detected
不适用Signed-Releasesno releases found
10Token-PermissionsGitHub workflow tokens follow principle of least privilege
10Vulnerabilities0 existing vulnerabilities detected
直接依赖 5
注册表软件包版本约束清单文件
Gogithub.com/BurntSushi/tomlv1.5.0go.mod
Gogithub.com/google/go-cmpv0.6.0go.mod
Gogithub.com/ulikunitz/xzv0.5.15go.mod
Gogithub.com/yuin/goldmarkv1.8.2go.mod
Gogolang.org/x/toolsv0.42.0go.mod
全部依赖 7

来自 GitHub 依赖图的完整解析依赖集合:5 个直接依赖与 2 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
Gogithub.com/burntsushi/tomlv1.5.0直接
Gogithub.com/google/go-cmpv0.6.0直接
Gogithub.com/ulikunitz/xzv0.5.15直接
Gogithub.com/yuin/goldmarkv1.8.2直接
Gogolang.org/x/toolsv0.42.0直接
Gogolang.org/x/modv0.33.0间接
Gogolang.org/x/syncv0.19.0间接
依赖安全公告 0

该仓库未发布可被索引解析的包,因此评估的是其自身的依赖图——共 7 个包,其中也包含从不交付的开发与测试版本固定:0 个存在已知公告,0 个为直接依赖。

没有已知公告影响已评估的依赖。

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [],
      "is_fork": false,
      "size_kb": 1263,
      "has_wiki": true,
      "homepage": null,
      "languages": {
        "Go": 916763,
        "Makefile": 737
      },
      "pushed_at": "2026-07-27T22:51:04Z",
      "created_at": "2026-07-20T11:46:24Z",
      "owner_type": "User",
      "updated_at": "2026-07-27T22:51:24Z",
      "description": "A reproducible style-policy compiler and linter orchestrator with built-in semantic checks, secure tool installation, requirement coverage, safe fixes and locally installable third-party packs.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "Apache-2.0",
      "default_branch": "main",
      "license_spdx_raw": "Apache-2.0",
      "primary_language": "Go",
      "significant_languages": [
        "Go"
      ]
    },
    "owner": {
      "blog": null,
      "name": "William Duong",
      "type": "User",
      "login": "wbd2023",
      "company": null,
      "location": "Sydney",
      "followers": 0,
      "avatar_url": "https://avatars.githubusercontent.com/u/176765682?v=4",
      "created_at": "2024-07-27T16:37:54Z",
      "is_verified": null,
      "public_repos": 4,
      "account_age_days": 731
    },
    "license": {
      "state": "standard",
      "spdx_id": "Apache-2.0",
      "raw_spdx": "Apache-2.0",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-07-20T13:21:32Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "483e8cc2a76680d4b81ae76ad6284080459054ce",
          "body": null,
          "is_bot": false,
          "headline": "fix(text): complete rebased Markdown line checks",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-27T16:54:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "341ac11daa46028393ce4c70185178de55da6324",
          "body": null,
          "is_bot": false,
          "headline": "docs: defer Australian English prose audit",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-27T16:46:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ddcd399aa95f0e280e2636f7781e8df721e3d47a",
          "body": null,
          "is_bot": false,
          "headline": "docs: define CLI-first product contract",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-27T16:46:51Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f3b132330998c095fc367da1cad3f6293fbf0322",
          "body": null,
          "is_bot": false,
          "headline": "feat(release): publish verified cross-platform binaries",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-27T16:46:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d2cdee86330bd69a58b8c47c496377d76bf438f4",
          "body": null,
          "is_bot": false,
          "headline": "feat: complete CLI-first release foundation",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-27T16:45:20Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "acf0eea25a82e18247f3d76d152a9b8803b79e21",
          "body": null,
          "is_bot": false,
          "headline": "fix(text): allow valid Markdown reference destinations",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-23T08:25:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ac9f7bbb05ce16fd69de8e25ed9c216e5ff9f3dc",
          "body": null,
          "is_bot": false,
          "headline": "docs(legal): update contributor agreement process",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-22T16:42:24Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "fe52ae60679ee23d454b413a65c83e6ad2397326",
          "body": "Revert \"Update README.md\"",
          "is_bot": false,
          "headline": "Merge pull request #2 from wbd2023/revert-1-test-cla-assistant",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-21T03:17:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1f44daaa75ec62c4c36337ce968c0d5da499c061",
          "body": null,
          "is_bot": false,
          "headline": "Revert \"Update README.md\"",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-21T03:10:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1df754e41ecde3fead88ecf837e6feeee27b8daa",
          "body": "Update README.md",
          "is_bot": false,
          "headline": "Merge pull request #1 from wbd2023/test-cla-assistant",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-21T03:04:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "be3d70f9407f4676d172e952f7e73bc689bb4a3f",
          "body": null,
          "is_bot": false,
          "headline": "Update README.md",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-20T16:52:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3df8bc51ccfb798851377cccb9f0ba170542cbec",
          "body": null,
          "is_bot": false,
          "headline": "feat: extract quill into standalone repository",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-20T12:18:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e951fb757b8d3410dfde4bd8d6679a030d31e477",
          "body": "The architect review identified that context.Context was decorative -\npassed to PackProvider.Load but never reaching process.RunCommand,\nexecutors, HTTP downloads, or tool inspection. Cancellation was\nimpossible.\n\nChanges (bottom-up):\n- process.RunCommand now accepts ctx, uses exec.CommandContext wi\n[…]\nContext in function signatures.\n\nAddresses architect findings P1-2 (context decorative) and partially\nP1-3 (WithCommandRunner still needs to affect all execution).\n\nGate: 32/32 passed. All tests pass.",
          "is_bot": false,
          "headline": "feat(execution): thread context.Context through entire execution path",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-17T06:31:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3cecb277e80803271277531c454942294dbf9b9b",
          "body": "Avoids naming conflict with context.Context when threading Go's standard\ncontext through the execution path. The architect noted 'Context is easily\nconfused with context.Context; RunContext is clearer.'\n\nMechanical rename:\n- type Context -> RunContext\n- constructor NewContext -> NewRunContext\n- all references updated across execution/, engine/, driver tests\n\nGate: 32/32 passed.",
          "is_bot": false,
          "headline": "refactor(execution): rename Context to RunContext",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-17T05:42:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c899680b765f85e89f594356e2ab02c0a0856fbc",
          "body": "The lock command was the last CLI operation that bypassed the engine,\nduplicating profile loading and pack resolution in cli/context.go.\n\nEngine.Lock follows the same pattern as Install: prepareRunnerContext\ngets the tools, installer.Resolve resolves platform archives.\n\nCLI changes:\n- command_lock.g\n[…]\nine)\n- Removed unused errUnknownScope from flag_parsing.go\n- Removed section headers from flag_parsing.go (now < 100 lines)\n\nAddresses architect finding P1-6: Engine.Lock missing.\n\nGate: 32/32 passed.",
          "is_bot": false,
          "headline": "feat(engine): add Engine.Lock, complete facade coverage",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-17T05:34:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "da49b60ab1115926a41c731b361c8dc1aa4c91f4",
          "body": "…utor\n\nruntimebinding/ was named when the package imported 'runtime'; after\nthe runtime->process split the name became misleading. Renamed to\ndriverkit/ to clearly describe its role: the shared types and helpers\nfor writing execution drivers.\n\nDriver -> Executor: the function type that executes one \n[…]\nped: latest oracle consultation recommended keeping pack/ and\nchecks/ as names. 123 files for marginal naming improvement is not\nworth the risk; will let architect review confirm.\n\nGate: 32/32 passed.",
          "is_bot": false,
          "headline": "refactor(drivers): rename runtimebinding to driverkit, Driver to Exec…",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-16T18:50:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ca5fa3b1d03a2a3965f6b6d84ee240d11a469866",
          "body": "The name 'runner' was confusing next to 'engine' — both suggest the\nthing that runs things. Oracle (GPT 5.6 Sol) recommended renaming to\n'execution' because the package boundary prevents circular imports:\nengine constructs DriverSet, drivers need execution.Context, so they\ncannot be the same package\n[…]\nshadowed the package name in command/file.go and scan/text.go\n- Updated architecture boundary tests\n- Renamed boundary_runner_drivers_test.go -> boundary_execution_drivers_test.go\n\nGate: 32/32 passed.",
          "is_bot": false,
          "headline": "refactor(arch): rename runner to execution for clarity",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-16T18:13:49Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7e293e9fa3ea7da604f35302d84f2d2febfe38fa",
          "body": "The profile/internal/effective and profile/internal/validation\nsub-packages existed only to serve thin wrapper functions in profile/.\nThe indirection added complexity without benefit: each was a set of\nimplementation details hidden behind a single function call.\n\nMerged all 26 files into profile/, e\n[…]\nile/) because it\nis the system-wide declarative vocabulary imported by 80+ files.\n\nArchitecture boundary tests updated: removed test cases for the\ndeleted sub-package directories.\n\nGate: 32/32 passed.",
          "is_bot": false,
          "headline": "refactor(profile): merge effective and validation into profile package",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-16T17:59:36Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "3580b46f18fc5cbe8ddfce79615bd5354c84bdc2",
          "body": "The runtime package mixed two unrelated concerns: command execution\n(CommandRequest, CommandResult, RunCommand) and filesystem layout\n(Layout, NewLayout). It also shadowed the standard library runtime\npackage, forcing the goruntime alias workaround.\n\nSplit into two focused packages:\n- workspace: Lay\n[…]\nitecture boundary tests: split the single 'runtime avoids\npolicy' test case into workspace and process variants, updated all\nforbidden import lists to reference both new packages.\n\nGate: 32/32 passed.",
          "is_bot": false,
          "headline": "refactor(arch): split runtime into workspace and process packages",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-16T17:44:46Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b77b73fbca3ca69802cfa667855a531c047c098",
          "body": "Create engine package as the composition root that encapsulates the full\nstyle-checking pipeline. Validated against GPT 5.6 Sol oracle review.\n\nEngine API (oracle-designed):\n- New(repoRoot, options...) with functional options\n- Check(ctx, CheckOptions) -> CheckResult with per-rule outcomes\n- Fix(ctx\n[…]\n)\n\nDead code removed:\n- selectedRules, fixableRules, statusForRuleResult (moved to engine)\n- inspectToolchain, selectTools (moved to engine)\n- loadCoverageReport (moved to engine)\n\nGate: 32/32 passed.",
          "is_bot": false,
          "headline": "refactor(engine): add Engine facade, slim CLI to rendering only",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-16T17:25:50Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "411feb083b6aba165832d7a075efdb17ada841ee",
          "body": "Invert dependencies to flow inward only (hexagonal architecture):\n\n1. toolchain -> runtime: define CommandRunner port in toolchain,\n   inject into InspectTools/IsInstalled/DetectByCommand. runtime.Runner\n   implements it structurally (no import needed).\n\n2. runner -> lockfile: Context.Lockfile was d\n[…]\nlkConfig with\n   ExcludedDirectories and GeneratedMarker. Callers resolve scope roots\n   and construct WalkConfig at the boundary. filewalk has zero imports of\n   policy or style.\n\nGate: 32/32 passed.",
          "is_bot": false,
          "headline": "refactor(arch): fix 5 dependency direction violations",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-16T16:54:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8df4d6130ffb8a6652e87a3ac9f01a4f5c4ba19d",
          "body": "EffectiveConfig -> Plan. The type represents a compiled execution plan\nwith bound rules, not 'effective configuration.' The name Plan clearly\ncommunicates the lifecycle stage: pack definitions compiled into an\nexecutable plan.\n\nPhases 3 (named composition) and 4 (move Definitions) evaluated and\nskip\n[…]\npe. Both pack (creator)\n  and profile (consumer) already import style. Moving it creates\n  backwards dependency direction (application -> adapter) with no\n  benefit.\n\nGate: 32 passed, all tests green.",
          "is_bot": false,
          "headline": "refactor(style): rename EffectiveConfig to Plan",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-16T15:18:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b226b306d679471b10149b8d5d30ceaeb9e684bc",
          "body": "The single ExecutionSpec type served two lifecycle stages: unbound pack\ndeclarations and bound runner jobs. This conflated declaration with\nexecution and required WithTargets to mutate specs in place.\n\nNew design separates the stages:\n\nTemplate (unbound, pack-created):\n- Sealed interface with descri\n[…]\nmplate\n- Profile compiler uses Describe() then Bind()\n- All drivers type-assert directly on Job\n\nMigration: 35 files changed across pack, profile, runner, cli, style.\nGate: 32 passed, all tests green.",
          "is_bot": false,
          "headline": "refactor(style): split ExecutionSpec into Template + Job lifecycle",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-16T15:12:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "0ff3564173055d689aa1ce0e954b8207a65e206b",
          "body": "Add blank-line separation between logical field groups:\n\nExecutionResult: findings | command output | execution flags\nDiagnostic: what (Code, Message) | where (File, Line, Column)\nRule: identity | binding | execution\nRuleDefinition: identity | execution\nFileCommandExecution: target | arguments | config\nTargetCommandExecution: tools | scope | targets\nTargetCheckExecution: tools | scope | targets\n\nGate: 32 passed, all tests green.",
          "is_bot": false,
          "headline": "refactor(style): logical field groupings in all structs",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-16T13:51:41Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3458408967cdd2a80445d486baffa26beaced0bb",
          "body": "Empty() no longer checks Output == \"\". Output is auxiliary debugging\ntext; a command that exits 0 with no findings but produces output is\nstill a clean pass. The check caused rule_status to compute the wrong\nstatus for such results.\n\nAll type doc comments standardised to 'represents' verb (stdlib\nco\n[…]\ne ('validates',\n'runs') to representational ('represents a check that validates').\nExecutionDetail doc drops 'sealed interface' mechanics. CheckMode\nconstants use 'means' not 'runs'.\n\nGate: 32 passed.",
          "is_bot": false,
          "headline": "refactor(style): fix Empty() bug, standardise doc comments",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-16T13:43:32Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cf8fc8c679f565f41a5404a28625beccbf20c008",
          "body": "Drop IDScheme abstraction (finding 5):\n- Remove IDScheme type, SectionSlug constant from style package\n- ParseRequirementID(value) no longer takes a scheme parameter\n- Remove id_scheme from TOML config (policy.StyleGuideConfig, styleguide.Config)\n- Remove scheme threading through profile validation \n[…]\non removed\n- style.CommandResult naming collision with runtime.CommandResult eliminated\n\nAlso: slices.Clone replaces append([]string{}, ...) in execution.go queries.\n\nGate: 32 passed, all tests green.",
          "is_bot": false,
          "headline": "refactor(style): drop IDScheme, accessor methods, style.CommandResult",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-16T13:32:20Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "53cc68befba71c6a5df8da72f426decad1a5ba97",
          "body": "Layout API redesign:\n- Exported fields (RepositoryRoot, StateDirectory) replace unexported\n  fields + getter methods\n- CacheDirectory() and BinaryDirectory() are methods (derived from\n  StateDirectory, always consistent)\n- ToolBinaryDirectory -> BinaryDirectory\n- Option type + WithStateDirectory rem\n[…]\n.go merged into command.go\n- File reordered: constants -> types -> RunCommand -> ResolveCommandPath\n  -> helpers\n\nCallers updated across ecosystem, cli, installer, runner, toolchain.\n\nGate: 32 passed.",
          "is_bot": false,
          "headline": "refactor(runtime): layout API redesign, command polish, BuildPath method",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-16T12:51:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f69e78955a4f15f6070da781111d0c019fc629cb",
          "body": "…cutionResult\n\nCommandError no longer carries CommandResult. The output that\ncommand_fix.go needed is now propagated through style.ExecutionResult\n(a new Output field), accessed from RunFix's return value instead of\nmined from the error via errors.As.\n\nChanges:\n- style/diagnostics.go: added Output s\n[…]\n: go_lint checks result.ExitCode from commandrun\nreturn (chain 1), command_fix checks fixResult.Output from RunFix\nreturn (chain 2). No caller mines CommandError for structured data.\n\nGate: 32 passed.",
          "is_bot": false,
          "headline": "refactor: drop Result from CommandError, propagate Output through Exe…",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-16T11:15:10Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "540922ca06b357484820e057d62c6aea12d2d2dc",
          "body": "Removed the compact-small-switches requirement (1.8.compact-small-switches)\nfrom STYLE.md, style.toml, and the switch_case_spacing check. Blank lines\nbetween cases are now always acceptable. Non-trivial switches still require\nblank lines (1.8.blank-lines-between-switch-cases).\n\nChanged:\n- switch_cas\n[…]\nr-spaced' test with\n  'allows spaced small switches' test.\n- command_error.go: restored blank lines between cases.\n- STYLE.md, style.toml: removed compact-small-switches requirement.\n\nGate: 32 passed.",
          "is_bot": false,
          "headline": "style: allow blank lines between switch cases regardless of switch size",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-16T11:06:40Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "855cb2c004c070cfeb474371836bbfd9fe32faee",
          "body": "Runtime package (5 files):\n- command.go: types + RunCommand + helpers\n- command_error.go: CommandError + methods + formatCommand\n- command_path.go: ResolveCommandPath + isExecutable + anyExecutePermission\n- command_buffer.go: limitedBuffer\n- layout.go: Layout + SearchPath\n\nChanges:\n- CommandRequest \n[…]\nToolByID and Output return CommandResult instead of string\n- go_lint checks result.ExitCode directly instead of mining CommandError\n- Chain 2 (command_fix -> RunFix) deferred to TODO\n\nGate: 32 passed.",
          "is_bot": false,
          "headline": "refactor(runtime): polish naming, file split, commandrun propagation",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-16T11:02:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8e38e560ff4d5560ab7104d0ecc5659863b350b3",
          "body": "…g, docs\n\nInstall functions: extracted private command() builder (pure, testable),\ndropped the separate install parameter (5 -> 4 params), inlined\nnpmArguments (eliminated the standalone function).\n\nTest files: both packages now have environment_test.go + install_test.go,\neach testing a pure functio\n[…]\n Environment docs (factual, no jargon or leaked details).\n\nsearchPath parameter renamed to path throughout; local binary path\nvariable renamed from path to binary to avoid collision.\n\nGate: 32 passed.",
          "is_bot": false,
          "headline": "refactor(ecosystem): polish install functions, symmetric tests, namin…",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-16T10:08:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e12f103a8e1aaafc85084519f692156d54001b3d",
          "body": "…al to binary\n\nThe Environment and Install functions received the PATH env var value as\n'searchPath', which was overspecified - it maps directly to the PATH key.\nRenamed to 'path' throughout. The local 'path' variable in Install\n(the installed binary's path) is renamed to 'binary' to avoid collision.\n\nGate: 32 passed.",
          "is_bot": false,
          "headline": "refactor(ecosystem): rename searchPath param to path, binary path loc…",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-16T09:33:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0df7f77a48faabb354e87d0750d2e4769da5fd18",
          "body": "…ecosystem\n\nEcosystem-specific knowledge (path derivation, env composition, install\nlogic) was scattered across runtime (Layout methods), cli/context.go,\nand installer (install_go.go, install_node.go) with 3-way env\nduplication. This co-locates all Go-specific and Node-specific knowledge\ninto per-ec\n[…]\nyDirectory instead of Layout methods.\n- architecture/boundary_platform_test.go: added recursive boundary case\n  for ecosystem/ (imports only runtime + toolchain, no cross-ecosystem).\n\nGate: 32 passed.",
          "is_bot": false,
          "headline": "refactor(ecosystem): co-locate ecosystem paths, env, and install per-…",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-16T07:33:25Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "6c9cc3916bd6e25b50aaa41855c4875b5a6e419f",
          "body": "Same shallow name-restating pattern as the command.go fix; brings command_error.go in line.",
          "is_bot": false,
          "headline": "refactor(runtime): descriptive doc comment for CommandError",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-15T20:42:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dfc88f909aa5d12e749bc5c0b1baf410badb645a",
          "body": "Layout is a path-layout struct; building environment maps (GOCACHE, GOMODCACHE, GOPATH) mixed Go-specific knowledge into it. Each consumer now builds its own env from Layout's path methods, adding its specific vars: cli/context adds GOLANGCI_LINT_CACHE for the checker, installer adds GOBIN for go in\n[…]\nhe smear where GOCACHE/GOMODCACHE/GOPATH were built in two places (Layout.GoEnvironment + installer.goEnvironment) and GOLANGCI_LINT_CACHE was added in three (cli + 2 test contexts).\n\nGate: 32 passed.",
          "is_bot": false,
          "headline": "refactor(runtime): remove Go-env building from Layout",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-15T20:41:22Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "d7eb8fd3354457e187a402bafe2a6f2ca5a82422",
          "body": "Replaces the shallow name-restating comments on the constants block, CommandRequest, CommandResult, and RunCommand with descriptions of what each does. Brings command.go up to the doc quality of command_path.go and layout.go.\n\nGate: 32 passed.",
          "is_bot": false,
          "headline": "refactor(runtime): descriptive doc comments for command execution",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-15T20:34:53Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "804ecb2c218afa35fd6030765c6123d1692d1ec3",
          "body": "…tors\n\nReplaces the sealed VersionMethod interface and its four marker types\n(GoVersion, ModuleVersion, PrefixedLineVersion, FirstTokenVersion) with a\nsingle function type, following the stdlib convention for simple strategy\nsets (image.RegisterFormat uses functions for simple strategies). The\ndetec\n[…]\nnce split\nalready exists (Capability vs profile pin); the 1:1 pin assumption is\nisolated for the future multi-coexistence and version-constraint features.\n\nGate: 32 passed, 0 failed. Tools tests pass.",
          "is_bot": false,
          "headline": "refactor(style): VersionMethod as a function type with named construc…",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-15T17:16:28Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "70d49d1d9840c5670908f212ad625d3f9d77ee2f",
          "body": "validatePackToolDefinitions compared tool definitions across packs with\nreflect.DeepEqual to catch conflicts, but every tool instance comes from\nthe canonical tool.BuildAll() catalogue, so duplicates are always\nidentical and the check could never fire. buildRegistry already dedupes\ntools by ID indep\n[…]\nectsConflictingToolDefinitions).\n\nThis dissolves the comparability requirement on VersionMethod, un-blocking\nthe function-type restructure that follows.\n\nGate: tools build + pack/toolchain tests pass.",
          "is_bot": false,
          "headline": "refactor(style): remove dead cross-pack tool conflict guard",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-15T17:08:14Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5e7f87dab327772da020c815b78e7d7b41138eb2",
          "body": "…ith environment\n\nversion.go polish:\n- parsePrefixedLineVersion and parseSingleTokenVersion now use the Seq\n  iterators (strings.SplitSeq / strings.FieldsSeq), matching\n  parseGoVersion and the deleted originals; the file no longer mixes\n  iterator styles.\n- Detection parameters now lead with enviro\n[…]\ns path -> method for consistency.\n- Updated the detectVersion switch calls, the inspection.go call site,\n  and the version_test.go call site to match.\n\nGate: 32 passed, 0 failed. Toolchain tests pass.",
          "is_bot": false,
          "headline": "refactor(style): unify version parser iterators and lead parameters w…",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-15T15:23:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "109424a6059132b2aa91f0d9d9c1d9f7bb61a773",
          "body": "…ution\n\nCollapses the split style.Tool + toolchain.Capability (plus the\ncapabilities map threaded through installer/resolve/install) into a\nsingle toolchain.Tool that carries its version detection and install\nmethod. One representation where there were two; removes the map\nindirection.\n\n- toolchain:\n[…]\nves here (command execution owns it).\n- profile/effective, pack, runner/drivers, cli, report: updated for the\n  unified Tool and the renamed sealed types.\n\nGate: 39 passed, 0 failed. Tools tests pass.",
          "is_bot": false,
          "headline": "refactor(style): unify toolchain Tool model and decouple command exec…",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-15T14:58:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "33e8aa3ecbe55594281c17c4c72ecb0a921f2679",
          "body": "Reorganises capability.go to match STYLE.md §3.9.file-order and the\nExecutionDetail precedent in the style package:\n\n- All type declarations grouped under Types (Capability first as the\n  load-bearing exported type, then VersionSpec + variants, then\n  InstallSpec + variants, then ArchiveSpec). Previ\n[…]\n\n\n§3.9 says 'exported types first, then internal types' and lists markers\n(methods) after types. The old ordering interleaved them.\n\nGate: 33 passed required, 32 passed tools, 34 packages, 0 failures.",
          "is_bot": false,
          "headline": "refactor(style): reorder capability.go to §3.9 file-order",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-08T04:53:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "646a940b8485c461b2b8d2a2f3a6f5f298f266ee",
          "body": "…ve enum\n\nReplaces flat string enums (VersionKind, InstallKind) with sealed\ninterfaces (VersionSpec, InstallSpec), matching the ExecutionDetail\nprecedent in the style package. Variant data now lives on variants\ninstead of being overloaded onto flat fields on Capability.\n\nVersion side:\n- VersionKindG\n[…]\nhe same problem\nshape.\n\nVerified end-to-end: style install passes all 7 tools, style lock\nregenerates quill.lock deterministically.\n\nGate: 33 passed required, 32 passed tools, 34 packages, 0 failures.",
          "is_bot": false,
          "headline": "refactor(style): sealed Version/Install specs, drop speculative archi…",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-08T04:45:08Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "f3bccbe5443ab1414abb5352572cb64755ad1944",
          "body": "Batch 1 - doc comments + doc.go:\nRewrote every 'X is X.' comment (CommandRequest, CommandRunner, Status,\nResolveCommandPath, AreAllToolsValid, ExplainToolIssues, SortedUniqueToolIDs)\nto describe what + mechanism, matching the style package's shape. Fixed\n'tool i ds' typo in SortedUniqueToolIDs. Adde\n[…]\n the dispatch\n  entry point for detection, so it belongs with the detection logic, not in\n  a separate file. version.go is deleted.\n\nGate: 33 passed required, 32 passed tools, 34 packages, 0 failures.",
          "is_bot": false,
          "headline": "refactor(style): toolchain doc quality and dead-code cleanup",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-08T03:43:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "afe020e7faa3b413bfc3c1c1c344aaf50dba6ecf",
          "body": "Maps the RunToolCommand coupling to termination: the wrappers forced the\ninstaller to construct synthetic {ID,Name} values that runtime never read,\nand runtime imported style solely for the wrapper signatures and the\nBuildStyleCommandResult projection.\n\nThree changes, traced end to end:\n\n1. Installe\n[…]\nknowledge lives entirely in the\nchecker layer where it belongs.\n\nVerified end-to-end: 'style install' installs all tools, all PASS.\n\nGate: 33 passed required, 32 passed tools, 34 packages, 0 failures.",
          "is_bot": false,
          "headline": "refactor(style): decouple runtime from style.Tool/Capability",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-08T03:17:18Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b742076d5bec2e359cd3705c674f3288c5419cb8",
          "body": "Address review findings across the lockfile feature:\n\nDeterminism bug (verified): Encode iterated a map[string]Archive to build\nthe TOML slice; map iteration is unordered, so 2+ archive tools produced\nspurious git diffs on each 'style lock' run. Encode now sorts archives by\ntool ID. Verified determi\n[…]\nrap was decorative)\n- installArchive: nil-check now precedes the deref (was a latent panic);\n  deref pattern matches resolveArchive\n\nGate: 33 passed required, 32 passed tools, 34 packages, 0 failures.",
          "is_bot": false,
          "headline": "refactor(style): fix review findings in lockfile + resolver",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-08T02:47:33Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8943a8e45c6b950876232c3e1bef1aa298afd587",
          "body": "Phase 4 of the lockfile + archive strategy generalisation.\n\nThe resolver downloads every platform archive for each archive-installed\ntool in the profile, hashes each one, and writes quill.lock atomically.\nThis makes version bumps painless: bump style.toml, run 'style lock',\ncommit the regenerated qu\n[…]\nchive.hashes] as a table block instead of inline dotted keys.\nBoth decode identically; the table format is cleaner for many hashes.\n\nGate: 33 passed required, 32 passed tools, 34 packages, 0 failures.",
          "is_bot": false,
          "headline": "feat(style): add 'style lock' resolver command",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-07T23:39:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e5d3141b9c21232d4f0f9e9efe4b621a6895209c",
          "body": "Phase 3 of the lockfile + archive strategy generalisation.\n\nIntroduces quill.lock, the resolved-state file for archive-installed tools.\nstyle.toml declares intent (which version); quill.lock records what was\nverified (per-platform SHA-256 hashes). The version is the join key between\nthe two files - \n[…]\nanually editing quill.lock (the same maintenance shape as\ntoday's source-pinned hashes, but in a data file instead of source code).\n\nGate: 33 passed required, 32 passed tools, 34 packages, 0 failures.",
          "is_bot": false,
          "headline": "refactor(style): introduce quill.lock for archive-tool integrity",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-07T23:25:30Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "ece4744708496de7426bb3e2f41a603d7a34dff9",
          "body": "Phase 2 of the lockfile + archive strategy generalisation.\n\nReplaces InstallKindShellcheckArchive (a kind named after one tool) with\nInstallKindArchive (a strategy). shellcheck becomes one instance of the\nstrategy; adding a second archive tool no longer requires a new InstallKind\nor a new install fu\n[…]\nhree generic ones. The dispatch switch is now a closed set of mechanisms\n(go, npm, archive), not a hybrid of mechanisms + one tool.\n\nGate: 33 passed required, 32 passed tools, 33 packages, 0 failures.",
          "is_bot": false,
          "headline": "refactor(style): generalise archive install strategy",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-07T22:51:55Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "fba0283dd57a1c09236910bf5a22501cc1dfd7ee",
          "body": "Phase 1 of the lockfile + archive strategy generalisation.\n\nIntroduces the ArchiveSpec type on toolchain.Capability, populated for\nshellcheck. No behaviour change yet: the installer still reads the old\nhardcoded constants in shellcheck_assets.go. Phase 2 will switch it.\n\nThe spec carries four fields\n[…]\n field-by-field\ncomparison on the 7 identity fields; the Archive spec is trusted\nconsistent because it comes from the same builder.\n\nGate: 33 passed required, 32 passed tools, 33 packages, 0 failures.",
          "is_bot": false,
          "headline": "refactor(style): add ArchiveSpec type for archive-installed tools",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-07T22:37:13Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "5f90a8d92efb6a04e017c81a83d2cf4cdc1d224a",
          "body": "Installer cleanup across files, naming, and behaviour:\n\nStructure:\n- Fold installed.go into install.go (install flow in one coherent file)\n- Move copyFile/writeFile to files.go (proper home for generic I/O helpers)\n- Merge shellcheck_archive_entries.go into shellcheck_archive.go\n\nNaming:\n- copyFile/\n[…]\neletions:\n- installTool switch-case blank lines normalised\n- Stale doc comments removed (existence-justification = commit material)\n\nGate: 33 passed required, 32 passed tools, 33 packages, 0 failures.",
          "is_bot": false,
          "headline": "refactor(style): clean up installer package structure and naming",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-07T21:37:07Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "74a798bd89e39a9e5a39584d40a8aa637890226a",
          "body": "…lumbing\n\nThe installer assumed a specific consumer directory layout: it sourced\npackage.json + package-lock.json from <repoRoot>/tools/toolchain/npm/\nand used toolsDirectory as the working directory for go install. This\nonly worked for ciphera's monorepo layout; a polyrepo or standalone\nconsumer ha\n[…]\nted by the deleted prepareLockedNodeInstall function).\n\nNet: -1410 lines, +28 lines. The installer works on monorepo, polyrepo,\nor any directory with a writable state directory and toolchains on PATH.",
          "is_bot": false,
          "headline": "refactor(style): make installer layout-agnostic, eliminate lockfile p…",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-05T02:53:15Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7eb7aa3fe662c82fb393cf11b3dd465ef35ee1f7",
          "body": "…paths\n\nLayout shrinks from 11 stored fields to 2 inputs (repositoryRoot +\nstateDirectory) with all paths derived as methods. This removes the\nhardcoded .cache/style/ directory tree and makes the engine's state\nlocation configurable.\n\nChanges:\n- NewLayout(repositoryRoot, ...Option) replaces LayoutFo\n[…]\nment builder is a follow-up\n  (TODO: environment extraction).\n\nThe unexported fields (repositoryRoot, stateDirectory) enforce\nconstruction via NewLayout, preventing the drift that stored fields\nallow.",
          "is_bot": false,
          "headline": "refactor(style): redesign Layout to configurable struct with derived …",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-05T01:50:04Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "cd6116b7ddc82048ebd47c01fd63c1fa1b30667c",
          "body": "…solvePath\n\nSTYLE.md 3.3 prefer-full-variable-words and expand-common-abbreviations\nsay to prefer full words over abbreviations. 'abs' for 'absolute'\nviolates this. The right name is 'absolute' - full word (not abs), not\nover-qualified (not absolutePath per avoid-overqualified-local-names).\n\nAlso renames the absPath function to resolvePath: 'abs' is an\nabbreviation, and the function resolves a path to its absolute form\n(wrapping filepath.Abs).",
          "is_bot": false,
          "headline": "fix(style): expand abs abbreviation to absolute, rename absPath to re…",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-04T00:34:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a67ad6387bc8e4ce1837e1c5b018ebc2e403d184",
          "body": "…ed value' comments\n\nTwo quick wins from the codebase quality scan:\n\n1. Replace absolutePath with abs/resolved in 3 files (5 instances).\n   STYLE.md 3.3 avoid-overqualified-local-names: the context\n   (filepath.Abs call right there) makes the shorter name clear.\n   Files: cli/repo_root.go, checks/go\n[…]\nwhat each function does. These were the worst\n   shallow-comment pattern: literally meaningless. Files: installer,\n   coverage, testutil/profiles (3), pack/shipped/tool, cli,\n   toolchain, commandrun.",
          "is_bot": false,
          "headline": "fix(style): fix over-qualified names and shallow 'returns the request…",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-04T00:27:45Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "548d2000952a30bf96e672c415c07bb00bc67198",
          "body": "…adFile",
          "is_bot": false,
          "headline": "fix(style): use consistent joined naming in testutil WriteFile and Re…",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-07-04T00:18:16Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f6a8475d8d8537f91c11b68536a7c6c7d93284e7",
          "body": "Collapse WriteFile/WriteFileAt/WriteExecutable into WriteFile +\nWriteExecutable. Both take root + path; the absolute-path variant is\ngone because every caller can pass root + relative path.\n\nWriteFileAt's single caller (writeSourceFile in scenario_harness_test)\nnow calls WriteFile with an empty root\n[…]\ners (the file is under 80 lines; the density\ncheck says short files should not have headers) and renames the return\nvariable from absolutePath to joined (STYLE.md 3.3\navoid-overqualified-local-names).",
          "is_bot": false,
          "headline": "refactor(style): simplify testutil write helpers to two functions",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-29T20:23:44Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "17bf57746778ea305ff5b3b50b18d15ea2d88a90",
          "body": "Three fixes to tools/internal/testutil/write_file.go:\n\n1. testExecutableMode 0o700 -> 0o755. The old value was directory\n   permissions on a file. 0o755 matches the production installer\n   convention (executableMode in installer/install.go) and the actual\n   meaning of an executable file.\n\n2. WriteP\n[…]\nns it uses, and when to use it\n   vs the alternatives.\n\nAlso added os.FileMode type annotations to the constants, matching the\ncodebase convention (installer/install.go types its file-mode constants).",
          "is_bot": false,
          "headline": "refactor(style): clean up testutil write helpers",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-29T20:06:00Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "8232ca1839cb445e909bbb69483e2b98d54c3d85",
          "body": "The fix loop bound 'result' but never read it on the success path, and\non the error path it extracted tool output from CommandError directly.\nInline the RunFix call into the if-statement and drop the _ = result\nsuppression.",
          "is_bot": false,
          "headline": "fix(style): remove unused result binding in command_fix",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-29T19:49:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c296bff4c74a3b20a1f14921fe50f444a31e36c6",
          "body": "ExecutionResult.Output carried three meanings: tool findings (text),\nprofile-check messages, and command error detail. This was the same\ndisease as the deleted sentinel: one channel, three meanings. A JSON\nconsumer could not distinguish parseable lint output from a missing\nMakefile target from a fai\n[…]\nt into 4 registration functions with section\n  headers (the file grew past 100 lines)\n\nExecutionResult is now {Diagnostics, Command} - the x/tools/go/analysis\nshape. No text-blob escape hatch remains.",
          "is_bot": false,
          "headline": "refactor(style): eliminate Output overload via FileInterpreter registry",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-29T19:26:48Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "036c5d5a6f2da25296c5f0605c65cc34f7b6a4e7",
          "body": "…vers\n\nTwo correctness fixes that complete the findings-as-data refactor\n(commit 31ec5ba):\n\n1. File-command non-zero exits as findings (not errors).\n   The findings-as-data refactor fixed golangci-lint's exit-1-as-findings\n   but left the generic file-command driver treating ALL non-zero exits as\n  \n[…]\nivers populates only 2 of 6 slots)\n   was silently reported as success. Now it returns an error naming the\n   rule and the unsupported detail type, so CheckStatus classifies it as\n   CheckStatusError.",
          "is_bot": false,
          "headline": "fix(style): treat file-command findings as data, error on missing dri…",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-28T17:32:11Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "7b4e971bace7ecc7d44c7a0ee25e44c19f35b688",
          "body": "Replace the sentinel-error model with findings-as-data. Previously,\nchecks returned style.ViolationsFound() (a non-nil error) to signal\n'found violations'. The error was never inspected with errors.Is - it\nwas a non-nil signal consumed by CheckStatus's default branch. Five\nduplicate sentinels existe\n[…]\ns the only place that translated that clean\ndata back into an error. It also matches x/tools/go/analysis, staticcheck,\nand every respected Go linter: findings are data, errors are for 'could\nnot run'.",
          "is_bot": false,
          "headline": "refactor(style): treat findings as data, not errors",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-28T16:43:34Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e5d8699b3b696a24b9b469ed88159831b73cdf97",
          "body": "Rewraps multi-line // doc-comment paragraphs across the app and style\ntool to fill toward the project's 100-character limit (STYLE.md 1.2)\ninstead of the ~80-col default. Single-line comments, lists, and\npreformatted godoc blocks are preserved; only genuine multi-line\nprose paragraphs were joined an\n[…]\ned.\n\nA Go-aware reflower handled // prefixes, counted tabs as 4 columns\n(matching the line-length check), preserved blank-comment-line\nparagraph breaks, and skipped preformatted/indented godoc blocks.",
          "is_bot": false,
          "headline": "docs: rewrap Go doc comments to 100-char limit",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-28T07:58:58Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "a4d8f38b49c5e36d55dc5ed601563c53b4dee48e",
          "body": "Rewraps README, SECURITY, STYLE, tools/README, tools/CONTEXT,\nCONTRIBUTING, and the shipped-declarations ADR to the project's\n100-character limit (STYLE.md 1.2), replacing the ~80-col mid-sentence\nwrapping that wasted horizontal space and created unnecessary breaks.\n\nIn STYLE.md this was high-risk: \n[…]\n0 == 320\n  reason=      160 == 160\n  id=          154 == 154\n  code fences   44 ==  44\n\nThe only changes are plain prose paragraphs and tight list items being\njoined and re-wrapped to fill toward 100.",
          "is_bot": false,
          "headline": "docs: rewrap prose to 100-char limit across all markdown",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-28T07:58:51Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "29fcdc77f0160121b28ab7c6821758dcef01064d",
          "body": "…e switches\n\nThe version-detection and install-strategy dispatch each built a closed\nmap[Kind]handler fresh on every call, with forwarding wrappers and\nconstants duplicated across toolchain and pack/shipped/tool. This was the\nsame anti-pattern as the removed ExecutionKind/DriverRegistry: a closed\nst\n[…]\nfour goCommandVersion/etc.\n  forwarding wrappers, skipInstall no-op\n- Delete pack/shipped/tool/version_kinds.go and install_kinds.go\n  (the constant re-export layer); builders use toolchain.* directly",
          "is_bot": false,
          "headline": "refactor(style): replace version/install handler registries with valu…",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-26T16:56:35Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "4e36980927fbb2abf1a2b53e8f4e0df4e077c77d",
          "body": "Remove the redundant ExecutionKind string constants and DriverRegistry\nmap. The sealed ExecutionDetail interface already provides type-safe\ndispatch; the string kind was a second representation of the same fact\nwith an entire validation layer to cross-check them.\n\nChanges:\n- Delete ExecutionKind typ\n[…]\nuct (6 typed fields) and driverFor type-switch\n- Update all driver registries to return Driver directly\n- Remove Kind: lines from all Pack declarations\n- Net ~70 lines deleted, zero functionality lost",
          "is_bot": false,
          "headline": "refactor(style): replace ExecutionKind map dispatch with type-switch",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-26T13:43:19Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "b768459da7ca9d6095c7e3c4bdbd90a8015da0b0",
          "body": null,
          "is_bot": false,
          "headline": "docs(todo): add type-switch dispatch item and profile execution rename",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-21T11:44:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c097dce06b8e287cc5596aee2709b0e34a332253",
          "body": "Rewrap all doc comments from the previous 80-column wrapping to the\nproject's 100-character limit. Reduces unnecessary line breaks while\nstaying within the style gate.",
          "is_bot": false,
          "headline": "docs(style): rewrap doc comments to 100 character limit",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-21T04:57:50Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1a071434bf48a5bf0d79845e657a6992dca0688e",
          "body": "Add doc comments to the remaining 49 undocumented exported declarations\n(const blocks and edge cases). Coverage reaches 100% across all 398\nexported declarations under tools/internal.",
          "is_bot": false,
          "headline": "docs(style): complete doc coverage for all exported declarations",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-20T14:24:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "93dea3096547e7e71e9583cbc220f91b8a7fc1c9",
          "body": "Add doc comments to 198 previously undocumented exported declarations\nacross all packages under tools/internal. Coverage rises from 36% to\n88%. The remaining 49 are const-block entries and a few edge cases\nthat need group-level comments rather than per-declaration docs.",
          "is_bot": false,
          "headline": "docs(style): add doc comments to exported declarations",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-20T14:10:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "aa9dd3d641d01cefdea3d21397206c531b7e5333",
          "body": "- Vocabulary pack policy switches to a preferred -> [shorthands] map\n  (Repository=[Repo], Service=[Svc], Config=[Cfg], Manager=[Mgr]),\n  uniformly across Go type suffixes, Go identifier suffixes, and Bash\n  variable names. Diagnostic messages use sentence form aligned with\n  the rest of the style t\n[…]\nl-identifier-suffixes binding to vocabulary/project-terms.\n- tools/README.md reframed as a general style-checking engine, with a\n  Status note documenting the planned extraction to its own repository.",
          "is_bot": false,
          "headline": "refactor(style): reshape vocabulary pack policy and naming rules",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-19T12:17:24Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "e417c1ed79a2f3ff86949603928ded4d4ebdaab3",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): document tooling layout",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-14T04:42:12Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af5b1cd2f3a578ee2d073d7c5b35f0eebcb47244",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): split rule execution validation",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-12T20:18:04Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "d12bc811035221f07c9f0b5dc8b791addd79abe8",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): remove package name stutter",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-12T19:16:13Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "2f3f7054e6a6c65b6d291bf6c81b38e0ff98545e",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): name report output files",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-12T18:28:18Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "06a417cdc86fb7a26fafd4e2be7d72771f496fde",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): split profile fixtures by role",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-12T17:41:25Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "49c05293fce1265dceb90e63ce33769a3d8e02cd",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): name go check engine files",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-12T16:50:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "e56363ee21c7705723c66d9f61ace1dc2db3d5e0",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): name helper files by role",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-12T15:56:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4323af3b9cd0e094f1afefce132def03810586b9",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): name driver pack config files",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-12T15:09:11Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ead457285add288f4481f5312b29e0bd37e43760",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): name test helper files",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-12T14:22:55Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "343338080472c0cabc06e20d9700efc5dffd56fa",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): name test support package",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-12T12:55:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "479465e2109a3e74591e58bdaa67113f269aa79c",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): clarify profile toml schema files",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-12T10:58:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "af9a199790ad473fe1ac357d916155da481f5fa8",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): split report output helpers",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-12T09:55:14Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "df04fd4bc8222549f18526c9983dd521038f6c2a",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): localise report declarations",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-12T09:04:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "abb313db1e8da8efcd6481cedb288daaf745e589",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): align pack policy filenames",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-12T06:45:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62f4429620f137eae3b71ceb94ad358377974b56",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): name profile fixtures",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-12T05:45:35Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "f83b38641b1e3b418064e5cf060df8c9c5785689",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): clarify driver facade files",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-12T04:41:44Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "88db40a1663e8f7f427d27bbfd635ce850add11d",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): name pack policy packages",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-12T03:31:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "74e3d75c06fe138065ffe0c836886e94be31341a",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): clarify runtime binding layout",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-12T01:59:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c9192e71cd867841686c728a195b5e390dcfa0c6",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): refine style tool layout",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-11T18:02:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ffd7e8ba89d6369ab9eed6f697db818290486b09",
          "body": "Extend retired-path coverage for the old contract, builtin pack, and root shipped tool files.\n\nClean up post-refactor lint issues around section headers, long lines, and shipped tool install-kind assertions.",
          "is_bot": false,
          "headline": "test(style): tighten architecture guardrails",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-09T18:34:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0a14fa150894d36cd4c5eb00e4db538bbafa8a56",
          "body": "Rename the core contract package to style and rename builtin packs to shipped packs.\n\nMove concrete check implementations under checks, split shipped tool declarations from shipped runtime bindings, and move tool inspection/version logic into toolchain.",
          "is_bot": false,
          "headline": "refactor(style): realign style tool architecture",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-09T02:34:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c4e011fa3d8714c68f37cc0f21b9edce825f69b8",
          "body": null,
          "is_bot": false,
          "headline": "test(style): split scan driver support helpers",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-05T17:46:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8148042889822be5841cd92188f06fc78ef59a99",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): simplify scanner dispatch tables",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-05T12:14:37Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c56bccd1f4fbfb9075a3d846798eaf94a7409d1b",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): centralise scan pack config decoding",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-04T21:24:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "671a4ab16a6fe008b77d79810ac7d0dee1377a50",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): align scanner helper names",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-04T19:39:40Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7d30174ba4add28544c827a008bbadb97f46fe6a",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): tighten scan driver registry",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-04T18:14:23Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "25dbc6bca8741369dac0e5124dacb7f167d0d827",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): split runner drivers by execution family",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-03T22:18:32Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "95a5a1beaca22308f6eb08936dba15fc16445ec8",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): align runner driver terminology",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-03T21:59:08Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b2c42949d888a333913ca630073666131dbd07f9",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): hide profile compilation internals",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-02T12:02:28Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3fca155a91a4a43cbc6c933545798386514bd38c",
          "body": null,
          "is_bot": false,
          "headline": "refactor(style): tighten Go syntax rule semantics",
          "author_name": "William Duong",
          "author_login": "wbd2023",
          "committed_at": "2026-06-02T09:36:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        }
      ],
      "releases_count": 1,
      "commits_last_year": 135,
      "latest_release_at": "2026-07-20T13:21:32Z",
      "latest_release_tag": "v0.1.0",
      "releases_from_tags": false,
      "days_since_last_push": 1,
      "active_weeks_last_year": 12,
      "days_since_latest_release": 8,
      "mean_days_between_releases": null
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 85,
      "has_issue_template": false,
      "has_code_of_conduct": false,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "github.com/wbd2023/quill",
          "exists": true,
          "license": null,
          "keywords": [],
          "ecosystem": "go",
          "matches_repo": true,
          "registry_url": "https://pkg.go.dev/github.com/wbd2023/quill",
          "is_deprecated": false,
          "latest_version": "v0.1.0",
          "repository_url": "https://github.com/wbd2023/quill",
          "versions_count": 1,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": null,
          "monthly_downloads": null,
          "first_published_at": null,
          "latest_published_at": "2026-07-20T12:18:14Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 8
        }
      ]
    },
    "popularity": {
      "forks": 0,
      "stars": 0,
      "watchers": 0,
      "fork_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_forks": 0
      },
      "star_history": {
        "days": [],
        "complete": true,
        "collected": 0,
        "total_stars": 0,
        "collected_at": null
      },
      "open_issues_and_prs": 0
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [],
      "has_llms_txt": false,
      "has_dockerfile": false,
      "has_mcp_signal": false,
      "bootstrap_files": [
        "Makefile"
      ],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [
        "go.mod"
      ],
      "largest_source_bytes": 11518,
      "source_files_sampled": 509,
      "oversized_source_files": 0,
      "agent_instruction_files": [],
      "agent_instruction_max_bytes": null
    },
    "dependencies": {
      "manifests": [
        "go.mod"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {},
        "advisory_count": 0,
        "affected_count": 0,
        "assessed_count": 7,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 0
      },
      "ecosystems": [
        "go"
      ],
      "dependencies": [
        {
          "name": "github.com/BurntSushi/toml",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.5.0"
        },
        {
          "name": "github.com/google/go-cmp",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.6.0"
        },
        {
          "name": "github.com/ulikunitz/xz",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.5.15"
        },
        {
          "name": "github.com/yuin/goldmark",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v1.8.2"
        },
        {
          "name": "golang.org/x/tools",
          "manifest": "go.mod",
          "ecosystem": "go",
          "version_constraint": "v0.42.0"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "github.com/burntsushi/toml",
            "direct": true,
            "version": "v1.5.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/google/go-cmp",
            "direct": true,
            "version": "v0.6.0",
            "ecosystem": "go"
          },
          {
            "name": "github.com/ulikunitz/xz",
            "direct": true,
            "version": "v0.5.15",
            "ecosystem": "go"
          },
          {
            "name": "github.com/yuin/goldmark",
            "direct": true,
            "version": "v1.8.2",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/tools",
            "direct": true,
            "version": "v0.42.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/mod",
            "direct": false,
            "version": "v0.33.0",
            "ecosystem": "go"
          },
          {
            "name": "golang.org/x/sync",
            "direct": false,
            "version": "v0.19.0",
            "ecosystem": "go"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 7,
        "direct_count": 5,
        "indirect_count": 2
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 0,
        "merged_prs": 2,
        "open_issues": 0,
        "closed_ratio": null,
        "closed_issues": 0,
        "closed_unmerged_prs": 0
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "wbd2023",
          "commits": 135,
          "avatar_url": "https://avatars.githubusercontent.com/u/176765682?v=4"
        }
      ],
      "contributors_sampled": 1,
      "top_contributor_share": 1
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "ci.yml",
        "release.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [
        ".golangci.yml"
      ],
      "has_editorconfig": false,
      "has_linter_config": true,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "go.sum"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 3,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": null,
            "reason": "no pull request found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 0,
            "reason": "Found 0/30 approved changesets -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 0,
            "reason": "project has 0 contributing companies or organizations -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 0,
            "reason": "project was created within the last 90 days. Please review its contents carefully",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": null,
            "reason": "packaging workflow not detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 10,
            "reason": "all dependencies are pinned",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "no SAST tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 4,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 10,
            "reason": "GitHub workflow tokens follow principle of least privilege",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 10,
            "reason": "0 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "483e8cc2a76680d4b81ae76ad6284080459054ce",
        "ran_at": "2026-07-29T03:51:30Z",
        "aggregate_score": 4.9,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": true,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-27T22:53:00Z",
      "oldest_open_prs": [],
      "last_merged_pr_at": "2026-07-21T03:17:59Z",
      "ci_last_conclusion": "FAILURE",
      "oldest_open_issues": []
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/wbd2023/Quill",
    "host": "github.com",
    "name": "Quill",
    "owner": "wbd2023"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 58,
      "inputs": {
        "security": 59,
        "vitality": 71,
        "community": 36,
        "governance": 44,
        "engineering": 78
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "good",
        "name": "Vitality",
        "value": 71,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "moderate",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 62,
            "inputs": {
              "commits_last_year": 135,
              "human_commit_share": 1,
              "days_since_last_push": 1,
              "active_weeks_last_year": 12
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 1 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 1
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "12/52 weeks with commits",
                "points": 8.3,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 12
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "135 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 135
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "good",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 84,
            "inputs": {
              "releases_count": 1,
              "latest_release_tag": "v0.1.0",
              "releases_from_tags": false,
              "days_since_latest_release": 8,
              "mean_days_between_releases": null
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "1 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 8 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "cadence unknown (single release)",
                "points": 12.6,
                "status": "partial",
                "details": [
                  {
                    "code": "release_cadence_unknown",
                    "params": {}
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "at_risk",
        "name": "Community & Adoption",
        "value": 36,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "critical",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 1,
            "inputs": {
              "forks": 0,
              "stars": 0,
              "watchers": 0,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "0 stars",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "0 forks",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "0 watchers",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 0
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "good",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": false,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (Apache-2.0)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "Apache-2.0"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "at_risk",
        "name": "Sustainability & Governance",
        "value": 44,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "critical",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 10,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 1,
              "top_contributor_share": 1
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 100% of commits",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 100
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "1 contributors",
                "points": 1.4,
                "status": "partial",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": "Excluded from scoring (no data or not applicable): Issue resolution. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "issue_resolution"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 72,
            "inputs": {
              "merged_prs": 2,
              "open_issues": 0,
              "closed_issues": 0,
              "issue_closed_ratio": null,
              "closed_unmerged_prs": 0
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "no issues or no data",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_issues_or_data",
                    "params": {}
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "2/2 decided PRs merged",
                "points": 38.2,
                "status": "met",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 2,
                      "decided": 2
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "critical",
            "name": "Ownership & stewardship",
            "note": "Excluded from scoring (no data or not applicable): Verified domain. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "verified_domain"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 24,
            "inputs": {
              "followers": 0,
              "owner_type": "User",
              "is_verified": null,
              "owner_login": "wbd2023",
              "public_repos": 4,
              "account_age_days": 731
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "personal (user) account",
                "points": 10,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_personal",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": "not applicable to user accounts",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_applicable_to_user_accounts",
                    "params": {}
                  }
                ],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "0 followers of wbd2023",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 0,
                      "login": "wbd2023"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "4 public repos, account ~2 yr old",
                "points": 9.1,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 4
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 2
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "good",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 84,
            "inputs": {
              "packages": [
                "github.com/wbd2023/quill"
              ],
              "ecosystems": "go",
              "any_deprecated": false,
              "min_days_since_publish": 8
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on go",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "go"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 8 days ago",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "1 published versions",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "good",
        "name": "Engineering Quality",
        "value": 78,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "good",
            "name": "Engineering practices",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: CI-Tests. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_ci_tests"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 80,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": true,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "2 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 2
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": ".golangci.yml",
                "points": 16,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "good",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 75,
            "inputs": {
              "topics": [],
              "has_wiki": true,
              "homepage": null,
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 59,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "at_risk",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): CI-Tests, Packaging, Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "ci_tests",
                    "packaging",
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 49,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 15,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 3,
              "scorecard_aggregate": 4.9
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "no pull request found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "Found 0/30 approved changesets -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 0 contributing companies or organizations -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "project was created within the last 90 days. Please review its contents carefully",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow not detected",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "no SAST tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 2,
                "status": "partial",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "GitHub workflow tokens follow principle of least privilege",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "0 existing vulnerabilities detected",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "excellent",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories, No advisories left outstanding. Remaining weights renormalized. Matched 7 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories",
                    "no_advisories_left_outstanding"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 7
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "source": "osv",
              "advisories": 0,
              "affected_packages": 0,
              "assessed_packages": 7,
              "unassessed_packages": 0,
              "affected_by_severity": "none",
              "direct_affected_packages": 0
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "no direct dependency carries a known advisory",
                "points": 35,
                "status": "met",
                "details": [
                  {
                    "code": "no_direct_advisories",
                    "params": {}
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory carries a publication date",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_no_publication_date",
                    "params": {}
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 7,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 2
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "good",
        "name": "AI Readiness",
        "value": 70,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "at_risk",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.98,
              "agent_instruction_files": [],
              "agent_instruction_max_bytes": null
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "no CLAUDE.md / AGENTS.md / editor rules",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_instructions",
                    "params": {}
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "98 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 98,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "good",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 82,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "go.sum"
              ],
              "has_dockerfile": false,
              "typed_language": true,
              "bootstrap_files": [
                "Makefile"
              ],
              "has_devcontainer": false,
              "has_linter_config": true,
              "typecheck_configs": [],
              "agent_commit_share": 0,
              "toolchain_manifests": [
                "go.mod"
              ],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": "Makefile",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Makefile"
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": ".golangci.yml",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": ".golangci.yml"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": "Go (statically typed)",
                "points": 11,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "no agent-authored commits among the last 100",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_agent_authored_commits",
                    "params": {
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "all dependencies are pinned",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "excellent",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "primary_language": "Go",
              "largest_source_bytes": 11518,
              "source_files_sampled": 509,
              "oversized_source_files": 0
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "Go (statically typed)",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "statically_typed_language",
                    "params": {
                      "language": "Go"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "0/509 source files over 60KB",
                "points": 55,
                "status": "met",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 509,
                      "oversized": 0
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [],
  "report_type": "repository",
  "generated_at": "2026-07-29T03:51:34.893448Z",
  "schema_version": "0.27.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/w/wbd2023/Quill.svg",
  "full_name": "wbd2023/Quill",
  "license_state": "standard",
  "license_spdx": "Apache-2.0"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.27.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计Go.