公开记录
软件健康报告模式 0.26.0 · 指标 1.13.0 · 2026-07-22 18:55 UTC

zylos-ai / zylos-core

🐙 Give your AI a life — open-source agent infrastructure for team collaboration.

JavaScriptMIT★ 1,136 星标⑂ 119 复刻始于 2026年2月在 GitHub 上查看 ↗

zylos-ai/zylos-core 的健康指数为 100 分中的 68 分,处于「中等」区间。 其得分最高的类别是Vitality(89/100),最低的是Sustainability & Governance(55/100)。 最近一次更新在 2 天前。 近期的大部分工作由 1 位贡献者完成。

68
总分 / 100
中等

软件健康指数

指标归入加权类别,统一采用 1–100 量表。总体分先取类别加权平均;当公开证据触发高风险司法辖区政策时,评级会按政策调整,并设置 49(有风险)的上限。AI 就绪度不计入总体分。

68
优秀85-100堪称典范;基本满足所有检验标准
良好70-84健康;仅有轻微不足
中等50-69可接受,但存在明显不足;建议进行审查
存在风险30-49存在重大薄弱环节;采用时应保持审慎
危急1-29问题严重(项目被弃置、仅有单一维护者、缺乏基本工程规范)
活力社区与采用可持续性与治理工程质量安全AI 就绪度

评分画像

每条轴代表一个类别。形状比平均值更重要——健康的对象会填满整个图形,而“一峰一谷”式画像意味着某一维度的优势正掩盖另一维度的风险。

所有权

Zylos-AI组织
115 关注者36 个公开仓库始于 2026年1月

该仓库由组织支持——共同承担、可问责的托管责任,可延续于任何单一维护者之后。

软件包生态系统

注册表软件包版本月下载量版本数最近发布
npmweb-console0.0.06513998 天前

按类别列示的指标

活力

项目是否仍有生命——是否仍在编写代码,是否仍在发布版本?

89优秀 · 占总体的 22%
评分方式
36/36推送新近度 — 最近一次推送于 2 天前
16.6/36提交节奏 — 52 周中有 24 周有提交
18/18提交量 — 最近一年 588 次提交
10/10OpenSSF Scorecard:Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
所用输入
commits_last_year588
human_commit_share1
days_since_last_push2
active_weeks_last_year24

发布纪律

100优秀
评分方式
27/27有发布版本 — 已发布 50 个发布版本
36/36发布时效 — 最近一次发布版本于 8 天前
27/27发布节奏 — 约每 12 天发布一次
0/10OpenSSF Scorecard:Signed-Releases — 无数据
所用输入
releases_count50
latest_release_tagv0.6.0
releases_from_tags
days_since_latest_release8
mean_days_between_releases12
已排除计分(无数据或不适用):OpenSSF Scorecard:Signed-Releases。 其余权重已重新归一化。

社区与采用

项目是否拥有用户、下载量与关注度,并具备欢迎贡献者参与的配置?

70良好 · 占总体的 18%
评分方式
49.6/60星标 — 1,136 个星标
17.3/25复刻 — 119 个复刻
10.1/15关注者 — 66 位关注者
所用输入
forks119
stars1,136
watchers66
growth_stateunverified
growth_factor_pct100
growth_unverified_reasonno_history

社区健康

92优秀
评分方式
22.5/22.5README
22.5/22.5许可证 — 可识别的许可证(MIT)
18/18CONTRIBUTING 指南
13.5/13.5行为准则
0/7.2议题模板
6.3/6.3PR 模板
所用输入
has_readme
has_license
has_contributing
has_issue_template
has_code_of_conduct
has_pull_request_template
评分方式
24.3/80月度下载量 — npm 合计每月 65 次下载
0/20注册表被依赖数 — 该生态系统不报告此项
所用输入
packagesweb-console
dependents
ecosystemsnpm
total_downloads
monthly_downloads65
已排除计分(无数据或不适用):注册表被依赖数。 其余权重已重新归一化。

可持续性与治理

项目能否在其成员之外延续——巴士系数、响应能力、由谁支持,以及软件包的维护状况?

55中等 · 占总体的 24%
评分方式
9/54巴士系数 — 1 位贡献者贡献了半数提交
10.4/22.5提交分布 — 头号贡献者编写了 54% 的提交
13.5/13.5贡献者广度 — 19 位贡献者
3/10OpenSSF Scorecard:Contributors — project has 1 contributing companies or organizations -- score normalized to 3
所用输入
bus_factor1
contributors_sampled19
top_contributor_share0.538
评分方式
27.6/46.8议题解决 — 59% 的议题已关闭
34.5/38.3PR 接受 — 已裁定的 PR 中 374/415 已合并
15/15OpenSSF Scorecard:Code-Review — all changesets reviewed
所用输入
merged_prs374
open_issues103
closed_issues149
issue_closed_ratio0.591
closed_unmerged_prs41
评分方式
30/30所有权背书 — 组织持有
0/20已验证域名
14.8/25所有者影响力 — zylos-ai 有 115 位关注者
12.5/25既往记录 — 36 个公开仓库,账户约 0 年
所用输入
followers115
owner_typeOrganization
is_verified
owner_loginzylos-ai
public_repos36
account_age_days191
评分方式
25/25已发布且可解析 — npm 上有 1 个软件包
4/35发布时效 — 最近一次发布于 3,998 天前
4/20版本历史 — 1 个已发布版本
20/20未被弃用 — 活跃,未被弃用或撤回
所用输入
packagesweb-console
ecosystemsnpm
any_deprecated
min_days_since_publish3,998

工程质量

基础的工程与文档实践是否到位?

65中等 · 占总体的 20%

工程实践

48存在风险
评分方式
24/24CI 工作流 — 1 个工作流
24/24存在测试
0/16Linter 配置
0/9.6Pre-commit 钩子
0/6.4.editorconfig
0/20OpenSSF Scorecard:CI-Tests — 0 out of 30 merged PRs checked by a CI test -- score normalized to 0
所用输入
has_ci
has_tests
has_editorconfig
has_linter_config
has_precommit_config

文档

90优秀
评分方式
30/30README
25/25文档目录
15/15文档 / 主页站点 — https://zylos.ai
10/10仓库描述
10/10主题标签 — 6 个主题标签
0/10Wiki
所用输入
topicsai, ai-worker, own-your-data, personal-ai-assistant, self-evolving, team-collaboration
has_wiki
homepagehttps://zylos.ai
has_readme
has_docs_dir
has_description

安全

可见的安全与供应链实践是否稳固,且不存在未解决的高风险司法辖区暴露?

62中等 · 占总体的 16%

安全态势

61中等
评分方式
7.5/7.5Binary-Artifacts — no binaries found in the repo
4.5/7.5Branch-Protection — branch protection is not maximal on development and all release branches
0/2.5CI-Tests — 0 out of 30 merged PRs checked by a CI test -- score normalized to 0
0/2.5CII-Best-Practices — no effort to earn an OpenSSF best practices badge detected
7.5/7.5Code-Review — all changesets reviewed
0.8/2.5Contributors — project has 1 contributing companies or organizations -- score normalized to 3
10/10Dangerous-Workflow — no dangerous workflow patterns detected
0/7.5Dependency-Update-Tool — no update tool detected
0/5Fuzzing — project is not fuzzed
2.5/2.5许可证 — license file detected
7.5/7.5Maintained — 30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
5/5Packaging — packaging workflow detected
0/5Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
0/5SAST — SAST tool is not run on all commits -- score normalized to 0
5/5Security-Policy — security policy file detected
0/7.5Signed-Releases — 无数据
6.8/7.5Token-Permissions — detected GitHub workflow tokens with excessive permissions
2.2/7.5Vulnerabilities — 7 existing vulnerabilities detected
所用输入
sourceopenssf_scorecard
checks_evaluated17
scorecard_versionv5.5.0
checks_inconclusive1
scorecard_aggregate6.1
已排除计分(无数据或不适用):signed_releases。 其余权重已重新归一化。
评分方式
10.2/35直接依赖不含已知公告 — 3 个受影响:js-yaml 3.14.2 (high 7.5), js-yaml 4.1.1 (high 7.5), multer 2.1.1 (high 7.5)
0/25间接依赖不含已知公告 — 在此范围内,传递依赖集合无法与开发和测试依赖区分
40/40没有长期未处理的公告 — 没有公告公开超过 90 天
所用输入
sourceosv
advisories10
affected_packages7
assessed_packages413
unassessed_packages0
affected_by_severityhigh 5, low 2
direct_affected_packages3
已排除计分(无数据或不适用):间接依赖不含已知公告。 其余权重已重新归一化。 已将 413 个已解析依赖与 OSV 比对。 该仓库未发布任何索引可解析的软件包,因此改为评估仓库依赖图。该图将开发与测试版本固定同交付的依赖混在一起,因此仅对声明的运行时依赖计分;传递性发现仅作为背景信息列出,不计入评分。 未对可达性进行分析。

AI 就绪度

该仓库在多大程度上具备与 AI 编码代理协同开发与维护的条件?这是一枚独立的实验性徽章——权重为 0.0,因此单独呈现,不影响总体健康评分。

56中等 · 占总体的 0%
评分方式
45/45代理指令 — CLAUDE.md
0/15机器可读文档(llms.txt)
40/40可读的提交历史 — 100 次人类提交中有 99 次说明了意图(结构化标题或解释性正文)
所用输入
has_llms_txt
legible_history_share0.99
agent_instruction_filesCLAUDE.md
agent_instruction_max_bytes6,158
评分方式
0/18一条命令的引导启动
22/22自动化测试
0/11Lint / 格式化配置
0/11静态类型检查
10/10可复现环境 — Dockerfile, lockfile
10/10已体现的代理实践 — 最近 100 次提交中有 62 次由代理编写或署名代理
0/8自动化维护 — 未观察到自动依赖更新
0/10OpenSSF Scorecard:Pinned-Dependencies — dependency not pinned by hash detected -- score normalized to 0
所用输入
has_nix
has_tests
lockfilespackage-lock.json
has_dockerfile
typed_language
bootstrap_files
has_devcontainer
has_linter_config
typecheck_configs
agent_commit_share0.62
toolchain_manifests
dependency_bot_commit_share0
评分方式
0/45可类型检查的代码 — JavaScript,未配置类型检查
54/55可控的文件大小 — 采样的 229 个源文件中有 4 个超过 60KB
所用输入
primary_languageJavaScript
largest_source_bytes124,245
source_files_sampled229
oversized_source_files4

机器可读接口

40存在风险
评分方式
0/40API 模式(OpenAPI/GraphQL/proto)
0/20MCP 服务器
40/40可运行示例 — examples
所用输入
example_dirsexamples
has_mcp_signal
api_schema_files

关键数据

1,136GitHub 星标
19贡献者
588最近 12 个月提交数
2距最近推送天数
50发布版本数
1巴士系数(bus factor)
103开放议题
npm软件包生态系统数

数据采集警告

  • Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token
  • Could not fetch npm package 'zylos' from its registry
  • Could not fetch npm package 'zylos-scheduler-v2' from its registry
  • Could not fetch npm package 'comm-bridge' from its registry
  • Could not fetch npm package 'zylos-memory' from its registry

更多细节

Star 与 Fork 历史 0 ★ / 119 ⇿
0Star
119Fork
46发布

每颗 star 和每个 fork 的添加时间,来自 GitHub 并按天汇总。累计增长位于其构成来源——每日新增——的正上方,二者可相互对照:稳定的自然增长与短暂的突增形态截然不同。当这一差别可被衡量时,它会作为增长真实性予以报告。

02040608010012011962026-022026-042026-07
主版本 0次版本 6修订 39
OpenSSF Scorecard 6.1 / 10
6.1综合

来自开源项目 OpenSSF Scorecard 的独立、工具无关的安全评估。每项检查奖励的是安全实践本身,而非特定供应商的工具。Scorecard 无法判定的检查项标记为 不适用,并从安全评分中剔除(绝不按零分计)。Scorecard v5.5.0 · 2026-07-22 18:54 UTC

10Binary-Artifactsno binaries found in the repo
6Branch-Protectionbranch protection is not maximal on development and all release branches
0CI-Tests0 out of 30 merged PRs checked by a CI test -- score normalized to 0
0CII-Best-Practicesno effort to earn an OpenSSF best practices badge detected
10Code-Reviewall changesets reviewed
3Contributorsproject has 1 contributing companies or organizations -- score normalized to 3
10Dangerous-Workflowno dangerous workflow patterns detected
0Dependency-Update-Toolno update tool detected
0Fuzzingproject is not fuzzed
10Licenselicense file detected
10Maintained30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
10Packagingpackaging workflow detected
0Pinned-Dependenciesdependency not pinned by hash detected -- score normalized to 0
0SASTSAST tool is not run on all commits -- score normalized to 0
10Security-Policysecurity policy file detected
不适用Signed-Releasesno releases found
9Token-Permissionsdetected GitHub workflow tokens with excessive permissions
3Vulnerabilities7 existing vulnerabilities detected
直接依赖 15
注册表软件包版本约束清单文件
npmdotenv^16.4.7package.json
npmjs-yaml^4.1.1package.json
npmsmol-toml^1.6.1package.json
npmdotenv^16.6.1skills/activity-monitor/package.json
npmbetter-sqlite3^12.6.2skills/comm-bridge/package.json
npmbetter-sqlite3^12.6.2skills/scheduler/package.json
npmchrono-node^2.7.7skills/scheduler/package.json
npmcron-parser^4.9.0skills/scheduler/package.json
npmdotenv^16.6.1skills/scheduler/package.json
npmbetter-sqlite3^12.6.2skills/web-console/package.json
npmdotenv^16.6.1skills/web-console/package.json
npmexpress^4.18.2skills/web-console/package.json
npmmulter^2.1.1skills/web-console/package.json
npmws^8.20.1skills/web-console/package.json
npmdotenv^16.6.1skills/zylos-memory/package.json
全部依赖 413

来自 GitHub 依赖图的完整解析依赖集合:10 个直接依赖与 403 个间接(传递)软件包。仓库提交锁文件时,传递闭包才是完整的。

注册表软件包版本关系
npmbetter-sqlite312.6.2直接
npmchrono-node2.9.0直接
npmcron-parser4.9.0直接
npmdotenv16.6.1直接
npmexpress4.22.1直接
npmjs-yaml3.14.2直接
npmjs-yaml4.1.1直接
npmmulter2.1.1直接
npmsmol-toml1.6.1直接
npmws8.21.0直接
npm@babel/code-frame7.29.0间接
npm@babel/compat-data7.29.0间接
npm@babel/core7.29.0间接
npm@babel/generator7.29.1间接
npm@babel/helper-compilation-targets7.28.6间接
npm@babel/helper-globals7.28.0间接
npm@babel/helper-module-imports7.28.6间接
npm@babel/helper-module-transforms7.28.6间接
npm@babel/helper-plugin-utils7.28.6间接
npm@babel/helper-string-parser7.27.1间接
npm@babel/helper-validator-identifier7.28.5间接
npm@babel/helper-validator-option7.27.1间接
npm@babel/helpers7.29.2间接
npm@babel/parser7.29.2间接
npm@babel/plugin-syntax-async-generators7.8.4间接
npm@babel/plugin-syntax-bigint7.8.3间接
npm@babel/plugin-syntax-class-properties7.12.13间接
npm@babel/plugin-syntax-class-static-block7.14.5间接
npm@babel/plugin-syntax-import-attributes7.28.6间接
npm@babel/plugin-syntax-import-meta7.10.4间接
npm@babel/plugin-syntax-json-strings7.8.3间接
npm@babel/plugin-syntax-jsx7.28.6间接
npm@babel/plugin-syntax-logical-assignment-operators7.10.4间接
npm@babel/plugin-syntax-nullish-coalescing-operator7.8.3间接
npm@babel/plugin-syntax-numeric-separator7.10.4间接
npm@babel/plugin-syntax-object-rest-spread7.8.3间接
npm@babel/plugin-syntax-optional-catch-binding7.8.3间接
npm@babel/plugin-syntax-optional-chaining7.8.3间接
npm@babel/plugin-syntax-private-property-in-object7.14.5间接
npm@babel/plugin-syntax-top-level-await7.14.5间接
npm@babel/plugin-syntax-typescript7.28.6间接
npm@babel/template7.28.6间接
npm@babel/traverse7.29.0间接
npm@babel/types7.29.0间接
npm@bcoe/v8-coverage0.2.3间接
npm@emnapi/core1.9.1间接
npm@emnapi/runtime1.9.1间接
npm@emnapi/wasi-threads1.2.0间接
npm@isaacs/cliui8.0.2间接
npm@istanbuljs/load-nyc-config1.1.0间接
npm@istanbuljs/schema0.1.3间接
npm@jest/console30.3.0间接
npm@jest/core30.3.0间接
npm@jest/diff-sequences30.3.0间接
npm@jest/environment30.3.0间接
npm@jest/expect30.3.0间接
npm@jest/expect-utils30.3.0间接
npm@jest/fake-timers30.3.0间接
npm@jest/get-type30.1.0间接
npm@jest/globals30.3.0间接
npm@jest/pattern30.0.1间接
npm@jest/reporters30.3.0间接
npm@jest/schemas30.0.5间接
npm@jest/snapshot-utils30.3.0间接
npm@jest/source-map30.0.1间接
npm@jest/test-result30.3.0间接
npm@jest/test-sequencer30.3.0间接
npm@jest/transform30.3.0间接
npm@jest/types30.3.0间接
npm@jridgewell/gen-mapping0.3.13间接
npm@jridgewell/remapping2.3.5间接
npm@jridgewell/resolve-uri3.1.2间接
npm@jridgewell/sourcemap-codec1.5.5间接
npm@jridgewell/trace-mapping0.3.31间接
npm@napi-rs/wasm-runtime0.2.12间接
npm@pkgjs/parseargs0.11.0间接
npm@pkgr/core0.2.9间接
npm@sinclair/typebox0.34.48间接
npm@sinonjs/commons3.0.1间接
npm@sinonjs/fake-timers15.1.1间接
npm@tybys/wasm-util0.10.1间接
npm@types/babel__core7.20.5间接
npm@types/babel__generator7.27.0间接
npm@types/babel__template7.4.4间接
npm@types/babel__traverse7.28.0间接
npm@types/istanbul-lib-coverage2.0.6间接
npm@types/istanbul-lib-report3.0.3间接
npm@types/istanbul-reports3.0.4间接
npm@types/node25.5.0间接
npm@types/stack-utils2.0.3间接
npm@types/yargs17.0.35间接
npm@types/yargs-parser21.0.3间接
npm@ungap/structured-clone1.3.0间接
npm@unrs/resolver-binding-android-arm-eabi1.11.1间接
npm@unrs/resolver-binding-android-arm641.11.1间接
npm@unrs/resolver-binding-darwin-arm641.11.1间接
npm@unrs/resolver-binding-darwin-x641.11.1间接
npm@unrs/resolver-binding-freebsd-x641.11.1间接
npm@unrs/resolver-binding-linux-arm-gnueabihf1.11.1间接
npm@unrs/resolver-binding-linux-arm-musleabihf1.11.1间接
npm@unrs/resolver-binding-linux-arm64-gnu1.11.1间接
npm@unrs/resolver-binding-linux-arm64-musl1.11.1间接
npm@unrs/resolver-binding-linux-ppc64-gnu1.11.1间接
npm@unrs/resolver-binding-linux-riscv64-gnu1.11.1间接
npm@unrs/resolver-binding-linux-riscv64-musl1.11.1间接
npm@unrs/resolver-binding-linux-s390x-gnu1.11.1间接
npm@unrs/resolver-binding-linux-x64-gnu1.11.1间接
npm@unrs/resolver-binding-linux-x64-musl1.11.1间接
npm@unrs/resolver-binding-wasm32-wasi1.11.1间接
npm@unrs/resolver-binding-win32-arm64-msvc1.11.1间接
npm@unrs/resolver-binding-win32-ia32-msvc1.11.1间接
npm@unrs/resolver-binding-win32-x64-msvc1.11.1间接
npmaccepts1.3.8间接
npmansi-escapes4.3.2间接
npmansi-regex5.0.1间接
npmansi-regex6.2.2间接
npmansi-styles4.3.0间接
npmansi-styles5.2.0间接
npmansi-styles6.2.3间接
npmanymatch3.1.3间接
npmappend-field1.0.0间接
npmargparse1.0.10间接
npmargparse2.0.1间接
npmarray-flatten1.1.1间接
npmbabel-jest30.3.0间接
npmbabel-plugin-istanbul7.0.1间接
npmbabel-plugin-jest-hoist30.3.0间接
npmbabel-preset-current-node-syntax1.2.0间接
npmbabel-preset-jest30.3.0间接
npmbalanced-match1.0.2间接
npmbase64-js1.5.1间接
npmbaseline-browser-mapping2.10.11间接
npmbindings1.5.0间接
npmbl4.1.0间接
npmbody-parser1.20.4间接
npmbrace-expansion1.1.13间接
npmbrace-expansion2.0.3间接
npmbrowserslist4.28.1间接
npmbser2.1.1间接
npmbuffer5.7.1间接
npmbuffer-from1.1.2间接
npmbusboy1.6.0间接
npmbytes3.1.2间接
npmcall-bind-apply-helpers1.0.2间接
npmcall-bound1.0.4间接
npmcallsites3.1.0间接
npmcamelcase5.3.1间接
npmcamelcase6.3.0间接
npmcaniuse-lite1.0.30001781间接
npmchalk4.1.2间接
npmchar-regex1.0.2间接
npmchownr1.1.4间接
npmci-info4.4.0间接
npmcjs-module-lexer2.2.0间接
npmcliui8.0.1间接
npmco4.6.0间接
npmcollect-v8-coverage1.0.3间接
npmcolor-convert2.0.1间接
npmcolor-name1.1.4间接
npmconcat-map0.0.1间接
npmconcat-stream2.0.0间接
npmcontent-disposition0.5.4间接
npmcontent-type1.0.5间接
npmconvert-source-map2.0.0间接
npmcookie0.7.2间接
npmcookie-signature1.0.7间接
npmcross-spawn7.0.6间接
npmdebug2.6.9间接
npmdebug4.4.3间接
npmdecompress-response6.0.0间接
npmdedent1.7.2间接
npmdeep-extend0.6.0间接
npmdeepmerge4.3.1间接
npmdepd2.0.0间接
npmdestroy1.2.0间接
npmdetect-libc2.1.2间接
npmdetect-newline3.1.0间接
npmdunder-proto1.0.1间接
npmeastasianwidth0.2.0间接
npmee-first1.1.1间接
npmelectron-to-chromium1.5.328间接
npmemittery0.13.1间接
npmemoji-regex8.0.0间接
npmemoji-regex9.2.2间接
npmencodeurl2.0.0间接
npmend-of-stream1.4.5间接
npmerror-ex1.3.4间接
npmes-define-property1.0.1间接
npmes-errors1.3.0间接
npmes-object-atoms1.1.1间接
npmescalade3.2.0间接
npmescape-html1.0.3间接
npmescape-string-regexp2.0.0间接
npmesprima4.0.1间接
npmetag1.8.1间接
npmexeca5.1.1间接
npmexit-x0.2.2间接
npmexpand-template2.0.3间接
npmexpect30.3.0间接
npmfast-json-stable-stringify2.1.0间接
npmfb-watchman2.0.2间接
npmfile-uri-to-path1.0.0间接
npmfinalhandler1.3.2间接
npmfind-up4.1.0间接
npmforeground-child3.3.1间接
npmforwarded0.2.0间接
npmfresh0.5.2间接
npmfs-constants1.0.0间接
npmfs.realpath1.0.0间接
npmfsevents2.3.3间接
npmfunction-bind1.1.2间接
npmgensync1.0.0-beta.2间接
npmget-caller-file2.0.5间接
npmget-intrinsic1.3.0间接
npmget-package-type0.1.0间接
npmget-proto1.0.1间接
npmget-stream6.0.1间接
npmgithub-from-package0.0.0间接
npmglob10.5.0间接
npmglob7.2.3间接
npmgopd1.2.0间接
npmgraceful-fs4.2.11间接
npmhas-flag4.0.0间接
npmhas-symbols1.1.0间接
npmhasown2.0.2间接
npmhtml-escaper2.0.2间接
npmhttp-errors2.0.1间接
npmhuman-signals2.1.0间接
npmiconv-lite0.4.24间接
npmieee7541.2.1间接
npmimport-local3.2.0间接
npmimurmurhash0.1.4间接
npminflight1.0.6间接
npminherits2.0.4间接
npmini1.3.8间接
npmipaddr.js1.9.1间接
npmis-arrayish0.2.1间接
npmis-fullwidth-code-point3.0.0间接
npmis-generator-fn2.1.0间接
npmis-stream2.0.1间接
npmisexe2.0.0间接
npmistanbul-lib-coverage3.2.2间接
npmistanbul-lib-instrument6.0.3间接
npmistanbul-lib-report3.0.1间接
npmistanbul-lib-source-maps5.0.6间接
npmistanbul-reports3.2.0间接
npmjackspeak3.4.3间接
npmjest30.3.0间接
npmjest-changed-files30.3.0间接
npmjest-circus30.3.0间接
npmjest-cli30.3.0间接
npmjest-config30.3.0间接
npmjest-diff30.3.0间接
npmjest-docblock30.2.0间接
npmjest-each30.3.0间接
npmjest-environment-node30.3.0间接
npmjest-haste-map30.3.0间接
npmjest-leak-detector30.3.0间接
npmjest-matcher-utils30.3.0间接
npmjest-message-util30.3.0间接
npmjest-mock30.3.0间接
npmjest-pnp-resolver1.2.3间接
npmjest-regex-util30.0.1间接
npmjest-resolve30.3.0间接
npmjest-resolve-dependencies30.3.0间接
npmjest-runner30.3.0间接
npmjest-runtime30.3.0间接
npmjest-snapshot30.3.0间接
npmjest-util30.3.0间接
npmjest-validate30.3.0间接
npmjest-watcher30.3.0间接
npmjest-worker30.3.0间接
npmjs-tokens4.0.0间接
npmjsesc3.1.0间接
npmjson-parse-even-better-errors2.3.1间接
npmjson52.2.3间接
npmleven3.1.0间接
npmlines-and-columns1.2.4间接
npmlocate-path5.0.0间接
npmlru-cache10.4.3间接
npmlru-cache5.1.1间接
npmluxon3.7.2间接
npmmake-dir4.0.0间接
npmmakeerror1.0.12间接
npmmath-intrinsics1.1.0间接
npmmedia-typer0.3.0间接
npmmerge-descriptors1.0.3间接
npmmerge-stream2.0.0间接
npmmethods1.1.2间接
npmmime1.6.0间接
npmmime-db1.52.0间接
npmmime-types2.1.35间接
npmmimic-fn2.1.0间接
npmmimic-response3.1.0间接
npmminimatch3.1.5间接
npmminimatch9.0.9间接
npmminimist1.2.8间接
npmminipass7.1.3间接
npmmkdirp-classic0.5.3间接
npmms2.0.0间接
npmms2.1.3间接
npmnapi-build-utils2.0.0间接
npmnapi-postinstall0.3.4间接
npmnatural-compare1.4.0间接
npmnegotiator0.6.3间接
npmnode-abi3.87.0间接
npmnode-int640.4.0间接
npmnode-releases2.0.36间接
npmnormalize-path3.0.0间接
npmnpm-run-path4.0.1间接
npmobject-inspect1.13.4间接
npmon-finished2.4.1间接
npmonce1.4.0间接
npmonetime5.1.2间接
npmp-limit2.3.0间接
npmp-limit3.1.0间接
npmp-locate4.1.0间接
npmp-try2.2.0间接
npmpackage-json-from-dist1.0.1间接
npmparse-json5.2.0间接
npmparseurl1.3.3间接
npmpath-exists4.0.0间接
npmpath-is-absolute1.0.1间接
npmpath-key3.1.1间接
npmpath-scurry1.11.1间接
npmpath-to-regexp0.1.13间接
npmpicocolors1.1.1间接
npmpicomatch2.3.2间接
npmpicomatch4.0.4间接
npmpirates4.0.7间接
npmpkg-dir4.2.0间接
npmprebuild-install7.1.3间接
npmpretty-format30.3.0间接
npmproxy-addr2.0.7间接
npmpump3.0.3间接
npmpure-rand7.0.1间接
npmqs6.15.2间接
npmrange-parser1.2.1间接
npmraw-body2.5.3间接
npmrc1.2.8间接
npmreact-is18.3.1间接
npmreadable-stream3.6.2间接
npmrequire-directory2.1.1间接
npmresolve-cwd3.0.0间接
npmresolve-from5.0.0间接
npmsafe-buffer5.2.1间接
npmsafer-buffer2.1.2间接
npmsemver6.3.1间接
npmsemver7.7.3间接
npmsemver7.7.4间接
npmsend0.19.2间接
npmserve-static1.16.3间接
npmsetprototypeof1.2.0间接
npmshebang-command2.0.0间接
npmshebang-regex3.0.0间接
npmside-channel1.1.0间接
npmside-channel-list1.0.0间接
npmside-channel-map1.0.1间接
npmside-channel-weakmap1.0.2间接
npmsignal-exit3.0.7间接
npmsignal-exit4.1.0间接
npmsimple-concat1.0.1间接
npmsimple-get4.0.1间接
npmslash3.0.0间接
npmsource-map0.6.1间接
npmsource-map-support0.5.13间接
npmsprintf-js1.0.3间接
npmstack-utils2.0.6间接
npmstatuses2.0.2间接
npmstreamsearch1.1.0间接
npmstring-length4.0.2间接
npmstring-width4.2.3间接
npmstring-width5.1.2间接
npmstring_decoder1.3.0间接
npmstrip-ansi6.0.1间接
npmstrip-ansi7.2.0间接
npmstrip-bom4.0.0间接
npmstrip-final-newline2.0.0间接
npmstrip-json-comments2.0.1间接
npmstrip-json-comments3.1.1间接
npmsupports-color7.2.0间接
npmsupports-color8.1.1间接
npmsynckit0.11.12间接
npmtar-fs2.1.4间接
npmtar-stream2.2.0间接
npmtest-exclude6.0.0间接
npmtmpl1.0.5间接
npmtoidentifier1.0.1间接
npmtslib2.8.1间接
npmtunnel-agent0.6.0间接
npmtype-detect4.0.8间接
npmtype-fest0.21.3间接
npmtype-is1.6.18间接
npmtypedarray0.0.6间接
npmundici-types7.18.2间接
npmunpipe1.0.0间接
npmunrs-resolver1.11.1间接
npmupdate-browserslist-db1.2.3间接
npmutil-deprecate1.0.2间接
npmutils-merge1.0.1间接
npmv8-to-istanbul9.3.0间接
npmvary1.1.2间接
npmwalker1.0.8间接
npmwhich2.0.2间接
npmwrap-ansi7.0.0间接
npmwrap-ansi8.1.0间接
npmwrappy1.0.2间接
npmwrite-file-atomic5.0.1间接
npmy18n5.0.8间接
npmyallist3.1.1间接
npmyargs17.7.2间接
npmyargs-parser21.1.1间接
npmyocto-queue0.1.0间接
依赖安全公告 7

该仓库未发布可被索引解析的包,因此评估的是其自身的依赖图——共 413 个包,其中也包含从不交付的开发与测试版本固定:7 个存在已知公告,3 个为直接依赖。

软件包版本关系严重程度公告数修复版本
js-yaml3.14.2直接24.3.0
js-yaml4.1.1直接24.3.0
multer2.1.1直接23.0.0-alpha.2
brace-expansion1.1.13间接15.0.7
brace-expansion2.0.3间接15.0.7
@babel/core7.29.0间接18.0.0-rc.6
body-parser1.20.4间接12.3.0

公告表示依赖图中记录的版本落入某条公告的受影响范围。可达性未经分析,且依赖图包含开发与测试的版本固定——某项发现可能只涉及工具链而非交付的软件。

原始 JSON 报告 机器可读
{
  "data": {
    "repo": {
      "topics": [
        "ai",
        "ai-worker",
        "own-your-data",
        "personal-ai-assistant",
        "self-evolving",
        "team-collaboration"
      ],
      "is_fork": false,
      "size_kb": 12528,
      "has_wiki": false,
      "homepage": "https://zylos.ai",
      "languages": {
        "CSS": 13354,
        "HTML": 3332,
        "Shell": 118053,
        "Dockerfile": 7514,
        "JavaScript": 2145500
      },
      "pushed_at": "2026-07-20T10:49:20Z",
      "created_at": "2026-02-02T07:56:39Z",
      "owner_type": "Organization",
      "updated_at": "2026-07-20T19:41:16Z",
      "description": "🐙 Give your AI a life — open-source agent infrastructure for team collaboration.",
      "is_archived": false,
      "is_disabled": false,
      "license_spdx": "MIT",
      "default_branch": "main",
      "license_spdx_raw": "MIT",
      "primary_language": "JavaScript",
      "significant_languages": [
        "JavaScript"
      ]
    },
    "owner": {
      "blog": "https://zylos.ai/",
      "name": "Zylos-AI",
      "type": "Organization",
      "login": "zylos-ai",
      "company": null,
      "location": "Singapore",
      "followers": 115,
      "avatar_url": "https://avatars.githubusercontent.com/u/254429536?v=4",
      "created_at": "2026-01-12T10:12:34Z",
      "is_verified": null,
      "public_repos": 36,
      "account_age_days": 191
    },
    "license": {
      "state": "standard",
      "spdx_id": "MIT",
      "raw_spdx": "MIT",
      "file_present": true,
      "scorecard_found": true,
      "profile_has_license": true
    },
    "activity": {
      "releases": [
        {
          "tag": "v0.6.0",
          "kind": "minor",
          "published_at": "2026-07-14T14:42:51Z"
        },
        {
          "tag": "v0.5.3",
          "kind": "patch",
          "published_at": "2026-06-17T15:39:14Z"
        },
        {
          "tag": "v0.5.2",
          "kind": "patch",
          "published_at": "2026-06-01T17:10:41Z"
        },
        {
          "tag": "v0.5.1",
          "kind": "patch",
          "published_at": "2026-05-25T11:32:50Z"
        },
        {
          "tag": "v0.5.0",
          "kind": "minor",
          "published_at": "2026-05-14T09:43:51Z"
        },
        {
          "tag": "issue-520-assets",
          "kind": "other",
          "published_at": "2026-05-03T14:36:02Z"
        },
        {
          "tag": "v0.4.13",
          "kind": "patch",
          "published_at": "2026-04-11T16:43:15Z"
        },
        {
          "tag": "v0.4.12",
          "kind": "patch",
          "published_at": "2026-04-08T14:41:02Z"
        },
        {
          "tag": "v0.4.11",
          "kind": "patch",
          "published_at": "2026-04-02T12:41:45Z"
        },
        {
          "tag": "v0.4.10",
          "kind": "patch",
          "published_at": "2026-03-28T15:17:58Z"
        },
        {
          "tag": "v0.4.9",
          "kind": "patch",
          "published_at": "2026-03-27T16:35:11Z"
        },
        {
          "tag": "v0.4.8",
          "kind": "patch",
          "published_at": "2026-03-26T14:54:46Z"
        },
        {
          "tag": "v0.4.7",
          "kind": "patch",
          "published_at": "2026-03-26T14:25:47Z"
        },
        {
          "tag": "v0.4.6",
          "kind": "patch",
          "published_at": "2026-03-26T12:23:08Z"
        },
        {
          "tag": "v0.4.5",
          "kind": "patch",
          "published_at": "2026-03-25T22:08:33Z"
        },
        {
          "tag": "v0.4.4",
          "kind": "patch",
          "published_at": "2026-03-25T21:32:39Z"
        },
        {
          "tag": "v0.4.3",
          "kind": "patch",
          "published_at": "2026-03-21T16:39:31Z"
        },
        {
          "tag": "v0.4.2",
          "kind": "patch",
          "published_at": "2026-03-19T17:50:47Z"
        },
        {
          "tag": "v0.4.1",
          "kind": "patch",
          "published_at": "2026-03-19T06:48:01Z"
        },
        {
          "tag": "v0.4.0",
          "kind": "minor",
          "published_at": "2026-03-14T18:05:39Z"
        },
        {
          "tag": "v0.3.7",
          "kind": "patch",
          "published_at": "2026-03-11T09:52:13Z"
        },
        {
          "tag": "v0.3.6",
          "kind": "patch",
          "published_at": "2026-03-09T15:00:55Z"
        },
        {
          "tag": "v0.3.5",
          "kind": "patch",
          "published_at": "2026-03-06T11:01:41Z"
        },
        {
          "tag": "v0.3.4",
          "kind": "patch",
          "published_at": "2026-03-05T14:28:38Z"
        },
        {
          "tag": "v0.3.3",
          "kind": "patch",
          "published_at": "2026-03-04T15:22:55Z"
        },
        {
          "tag": "v0.3.2",
          "kind": "patch",
          "published_at": "2026-03-04T06:10:41Z"
        },
        {
          "tag": "v0.3.1",
          "kind": "patch",
          "published_at": "2026-03-04T02:41:14Z"
        },
        {
          "tag": "v0.3.0",
          "kind": "minor",
          "published_at": "2026-03-03T17:01:52Z"
        },
        {
          "tag": "v0.2.7",
          "kind": "patch",
          "published_at": "2026-02-28T15:18:38Z"
        },
        {
          "tag": "v0.2.6",
          "kind": "patch",
          "published_at": "2026-02-27T10:53:59Z"
        },
        {
          "tag": "v0.2.5",
          "kind": "patch",
          "published_at": "2026-02-26T15:25:26Z"
        },
        {
          "tag": "v0.2.4",
          "kind": "patch",
          "published_at": "2026-02-24T15:11:33Z"
        },
        {
          "tag": "v0.2.3",
          "kind": "patch",
          "published_at": "2026-02-22T09:16:04Z"
        },
        {
          "tag": "v0.2.2",
          "kind": "patch",
          "published_at": "2026-02-22T07:12:55Z"
        },
        {
          "tag": "v0.2.1",
          "kind": "patch",
          "published_at": "2026-02-22T06:31:51Z"
        },
        {
          "tag": "v0.2.0",
          "kind": "minor",
          "published_at": "2026-02-20T17:39:00Z"
        },
        {
          "tag": "v0.1.9",
          "kind": "patch",
          "published_at": "2026-02-20T16:31:14Z"
        },
        {
          "tag": "v0.1.8",
          "kind": "patch",
          "published_at": "2026-02-18T16:42:56Z"
        },
        {
          "tag": "v0.1.7",
          "kind": "patch",
          "published_at": "2026-02-18T16:42:47Z"
        },
        {
          "tag": "v0.1.6",
          "kind": "patch",
          "published_at": "2026-02-17T06:05:42Z"
        },
        {
          "tag": "v0.1.5",
          "kind": "patch",
          "published_at": "2026-02-15T15:37:18Z"
        },
        {
          "tag": "v0.1.4",
          "kind": "patch",
          "published_at": "2026-02-14T14:01:10Z"
        },
        {
          "tag": "v0.1.3",
          "kind": "patch",
          "published_at": "2026-02-13T14:01:07Z"
        },
        {
          "tag": "v0.1.2",
          "kind": "patch",
          "published_at": "2026-02-13T13:27:09Z"
        },
        {
          "tag": "v0.1.1",
          "kind": "patch",
          "published_at": "2026-02-12T16:02:56Z"
        },
        {
          "tag": "v0.1.0",
          "kind": "minor",
          "published_at": "2026-02-11T09:02:28Z"
        },
        {
          "tag": "v0.1.0-beta.18",
          "kind": "prerelease",
          "published_at": "2026-02-09T03:01:26Z"
        },
        {
          "tag": "v0.1.0-beta.17",
          "kind": "prerelease",
          "published_at": "2026-02-08T13:49:40Z"
        },
        {
          "tag": "v0.1.0-beta.9",
          "kind": "prerelease",
          "published_at": "2026-02-07T18:16:41Z"
        },
        {
          "tag": "v0.1.0-beta.8",
          "kind": "prerelease",
          "published_at": "2026-02-07T17:58:32Z"
        }
      ],
      "recent_commits": [
        {
          "oid": "7a034ca2e55457bf114d4973b7df04ca207371eb",
          "body": "…l restart (#738)\n\nupgrade.md still instructed the agent to manually run post-upgrade hooks\nand restart services, but since PR #589 (v0.5.1) the CLI already does\nboth in steps 7 and 8. Every agent-driven upgrade has been double-running\nthe post-upgrade hook since then.\n\nChanges:\n- Remove manual pre-\n[…]\ny the CLI's\n  start_service step result\"\n- Apply the same fixes to C4 mode (Step 2 and Post-Upgrade Actions)\n\nPart of #730 (PR-1).\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(docs): eliminate post-upgrade hook double-run and redundant manua…",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-15T01:55:00Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d008294751efb79e170651707fc15064a85741c8",
          "body": "Split-layer instruction architecture, migration tooling, session-start\nshard system, and 20+ fixes accumulated since v0.5.3.\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v0.6.0 (#734)",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-14T14:41:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "b59c14e04b3023ea58338594349bc267c569c387",
          "body": "The activity monitor's API error scanner missed \"API Error: 400 Output\nblocked by content filtering policy\" because the regex required\n\"APIError:\" (no space). Widen the pattern to /API\\s*Error:\\s*\\d{3}/ and\nadd a dedicated /output blocked by content filtering policy/i pattern\nso the health engine triggers a session restart on content filter blocks.\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: detect content filtering API errors for session recovery (#737)",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-14T14:34:42Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9844f3cf189bbf5b1d08c5ee29fe9648105a5c2f",
          "body": "When 90-migration-prompt.md exists (written by upgrade step7 for C-class\nmigrations), session-start-prompt.js now sends a migration-specific\nprompt that instructs the agent to execute the Required action\nimmediately, rather than the generic \"continue ongoing tasks\" prompt\nwhich the agent ignores.\n\nT\n[…]\n prompt file is cleaned up on success by\nexecuteMigrationApply and retained on failure for retry — natural\nat-least-once behavior.\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: auto-trigger pending migration on session start (#736)",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-14T13:18:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "623ae84e8c24f589f2fb951b608e4ab85ec90959",
          "body": "* fix: C-class migration prompt includes system template path for accurate diff\n\nThe migration prompt previously only provided baseline SHA-256 hashes,\nleaving the agent unable to distinguish system-managed content from user\nadditions. Now passes the installed claude-system.md path so the agent\ncan \n[…]\no lose, and the backup already\nexists for safety.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: C-class migration prompt includes system template path (#735)",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-14T12:54:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "51b3f732e574d7577bd78507f626aaed1ab63b67",
          "body": "…732)\n\n* docs: add dev plan for issue #729 (P3 upgrade-path auto-migration)\n\nStep 7 auto-migrates A/B class machines on upgrade; C class gets a\nstructured self-migration prompt file for channel-only agents.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n* docs: revise dev pla\n[…]\nhard\n\n* fix: warn against manual instruction migration\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "feat: upgrade-path auto-migration for instruction split (#729, P3) (#…",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-14T11:32:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9744c21b4a79c142527260c9b1d3fbdecf99aace",
          "body": "…2) (#728)\n\n* docs: add dev plan for issue #722 P2 (migration tool + A3 hook normalization)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n* docs: close R1 findings in #722 P2 dev plan (reachable-history corpus, provenance-gated B, no-discard conservation, A3 convergence)\n\nCo-Authored-By: \n[…]\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "feat: safe instruction migration tool + A3 hook normalization (#722 P…",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-14T06:43:45Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "29909d0ee23ee7968d634a5cc70008f28ca1457f",
          "body": "* feat: apply the approved #722 content redraft to the system templates\n\nTemplate content payload (redraft v2.5, Howard-approved section by section):\n- templates/claude-system.md / codex-system.md rewritten to the sealed\n  redraft: shared core (~162 lines) + per-runtime addon (14 / 23 lines),\n  addo\n[…]\nidge, scheduler,\nhttp, web-console, activity-monitor. Template pins repinned.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: #722 template content redraft (D8 template-only PR) (#726)",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-13T16:54:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2da71e5665e0afa472198c02e445ebb90b94bf31",
          "body": "…) (#723)\n\n* docs: add dev plan for issue #722 (split-layer instructions)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n* docs: verify two dev-plan assumptions (template corpus + pre-v0.4 path)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n* docs: close R1 findings in #722 dev \n[…]\nreview findings (#722)\n\n* fix: close split hook lifecycle gap (#722)\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "feat: ZYLOS.md/CLAUDE.md split-layer instructions (P1 mechanism, #722…",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-13T15:59:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e38759fffcf36c265320594bff9de825161daf36",
          "body": "…ons shard (#724) (#725)\n\nThe budgeted shard path no longer applies the dispatch-style per-message\n2KB spill (preview + attachment pointer): the DB stores originals, and the\nshard's whole-message newest-first budget packer already bounds the output,\nso compressing messages at session start made the \n[…]\ne orchestrator to tail-trim\n  blindly; the legacy no-budget path (no packer to bound output) is\n  unchanged\n- dispatcher delivery path untouched\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: emit original message content in the session-start c4-conversati…",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-13T01:38:22Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a12098a4ca46dc57135096196d91e597da9e3b07",
          "body": "…tart shard (#719) (#721)\n\n* docs: route machine-local standing directives to the custom session-start shard (#719)\n\nThe custom SessionStart shard (~/zylos/custom-hooks/session-start/*.md) was\nundiscoverable: ZYLOS.md's Memory System section never mentioned it, while\nthe preferences.md classificatio\n[…]\n is self-contained; the\nrepo doc remains as operator/developer documentation.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: route machine-local standing directives to the custom session-s…",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-12T13:19:07Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d0d7024ded88ed5b9eea3891cde26c17ef9cacff",
          "body": "…ict short-circuit (#717) (#718)\n\n* docs: add dev plan for issue #717\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n* docs: dev plan v2 for issue #717 — absorb plan-review R1 (cross-version visibility channel, self-upgrade test seam, ZYLOS_DIR paths, failure semantics)\n\nCo-Authored-By: Cl\n[…]\nce complete)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "fix: preserve self-upgrade conflict backups + identical-content confl…",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-12T06:41:19Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "81d10647a4cf89dd6dc7cd902d67a8ceb5957961",
          "body": "…-dir scans (#715) (#716)\n\n* fix: generate manifests from authoritative package source, never dest-dir scans (#715)\n\n- smartSync: save newManifest (package source) after successful sync instead\n  of rescanning destDir; skip manifest/originals persistence when the sync\n  recorded errors (keep last kn\n[…]\n\n* refactor: commit merge baselines at outer success boundary (#715)\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "fix: generate manifests from authoritative package source, never dest…",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-12T04:31:05Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "d29a0fa9e15c7796d62864609758d66d018c8842",
          "body": "…(#714)\n\n* fix: prevent spill-file path collision in truncateForDelivery (#713)\n\nSpill directories were named Date.now()-pid, so two large messages\nspilled by one process in the same millisecond resolved to the same\ndirectory and silently overwrote each other (observed when the\nsession-start rendere\n[…]\nt re-spill,\nid 0 as a valid id, and the fallback collision cases.\n\nFixes #713\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: prevent spill-file path collision in truncateForDelivery (#713) …",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-11T10:53:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a621828ab14a49028b3640e191cb15344498f2bc",
          "body": "… modes (#706) (#712)\n\nNon-JSON mode printed warnings but exited 0 when component checks failed,\nwhile --json exited 1 — scripts got different failure signals depending on\noutput mode. Non-JSON now sets process.exitCode = 1 on any check failure\n(exitCode, not process.exit, so prompts/upgrades/output\n[…]\nal-fail / all-fail ×\nJSON / non-JSON via upgrade --all --check (negative control verified:\nthe two non-JSON failure cases fail without the fix).\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: unify upgrade --all exit-code contract between JSON and non-JSON…",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-11T09:04:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ae4a02441cddb8dccf20296cbcf649fc34d22c85",
          "body": "…(#705) (#711)\n\nWithout a token, fetchRawFileOnce / fetchTagsJsonSync / fetchTagsJsonAsync\n(github.js) and curlDownloadOnce (download.js) re-fired the identical public\nrequest in the same retry round purely to surface an error, doubling failure\nlatency and adding rate-limit pressure. Capture and ret\n[…]\n a new recovery test proving the\nouter loop still clears transient rate limiting, and a new\ndownload-no-token.test.js pinning the download path.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: remove same-round duplicate public request in no-token fallback …",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-11T08:53:40Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "a6f9bff54c734a201905c56317e81d5d5d15f1d3",
          "body": "…08) (#710)\n\nThe two writeCodexConfig cases passed the fixed path /tmp/zylos-project as\nthe project dir. On a shared host where another user owns that directory,\nmkdirSync inside it fails and writeCodexConfig returns false, failing the\nsuite on any commit. Point the project dir inside each test's existing\nmkdtempSync root so it is unique per test and cleaned up by the existing\nrmSync teardown.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: use per-test tmpdir instead of hardcoded /tmp/zylos-project (#7…",
          "author_name": "zylos-luna-coco",
          "author_login": "zylos-luna-coco",
          "committed_at": "2026-07-11T07:28:53Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d2bc8ef9999691225df830270a35bd36f7fe76bc",
          "body": "* feat(cli): install components from local sources\n\n* fix: secure local component sources\n\n* fix: fail aggregate component checks\n\n---------\n\nCo-authored-by: Jinglever <267884994+jinglever@users.noreply.github.com>\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "feat(cli): install components from local sources (#700)",
          "author_name": "Jinglever",
          "author_login": "jinglever",
          "committed_at": "2026-07-11T05:11:33Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5fb5a45fcdc86e27c9d91b5c361d070aa358f84e",
          "body": "* fix: prefer authenticated GitHub API requests\n\n* fix: harden GitHub fallback retries\n\n---------\n\nCo-authored-by: Jinglever <267884994+jinglever@users.noreply.github.com>\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "fix: prefer authenticated GitHub API requests (#699)",
          "author_name": "Jinglever",
          "author_login": "jinglever",
          "committed_at": "2026-07-11T05:08:27Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "0051b005c9f9490d27eb65230a1d4d8f8101d52d",
          "body": "…2) (#704)\n\nstate.md is always-loaded but its rules only said \"keep it lean\", so\nMemory Sync kept accumulating completed-task narrative and run history —\na production instance grew to 19KB against the 16KB hard budget.\n\nSame structure as #697 did for references.md:\n\n- templates/ZYLOS.md: define allo\n[…]\n so memory-status.js\n  reports WARN and consolidate.js flags nearBudget, same wiring as #697\n- tests: cover the new threshold value\n\nCloses #702\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(zylos-memory): content rules + sync-time audit for state.md (#70…",
          "author_name": "FelixLin6",
          "author_login": "FelixLin6",
          "committed_at": "2026-07-10T17:26:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f5e801674c08171fb3e395f94feb86d89b81943a",
          "body": "…stom-hooks/session-start) (#703)\n\n* feat(session-start): add custom-inject core shard at chain position 2\n\nDeployment/user-provided standing directives injected right after identity:\nthe emitter reads ~/zylos/custom-inject/*.md in lexicographic order at every\nsession start (conf.d-style numeric pre\n[…]\nexicographic\nconcat, empty passthrough, content-not-code boundary) unchanged.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(session-start): custom-inject core shard at chain position 2 (cu…",
          "author_name": "FelixLin6",
          "author_login": "FelixLin6",
          "committed_at": "2026-07-10T15:33:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9ca24f9f46e68b81f775125b5157478d9e6322da",
          "body": "…red flag chain (fixes #686) (#698)\n\n* feat(session-start): shard sequencer, registry, and orchestrator --shard mode (#686)\n\nSplit the session-start injection into per-shard hook commands so each\nshard gets its own hook stdout budget instead of sharing one 10K cap:\n\n- shard-sequencer.js: flag-file s\n[…]\n registry-closure e2e (shard-mode output always\nwithin DEFAULT_SHARD_BUDGET).\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(session-start): shard injection into per-section hooks with orde…",
          "author_name": "FelixLin6",
          "author_login": "FelixLin6",
          "committed_at": "2026-07-10T15:28:48Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "61774e37dc89d78132f8a625dec31c4cee802a6e",
          "body": "…pt (#701)\n\n#675 asserted the Codex launch spec args must be empty (no retired text\nbootstrap payload). #681 then deliberately added the 'hello' kick prompt\nto launch args to trigger the SessionStart hook, but did not update this\nassertion, leaving one deterministic failure on main (expected [] vs\na\n[…]\n'hello']). Pin the assertion to exactly ['hello'] so the test\nkeeps rejecting any resurrected bootstrap payload while accepting the\nkick prompt.\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: update stale Codex launch-spec assertion for the #681 kick prom…",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-07-10T04:49:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "f94f149f8457d7297ad2bf64dc9d21ceab034397",
          "body": "… (#697)\n\nreferences.md is always-loaded but had only one narrow content rule\n(never duplicate .env values), so Memory Sync kept appending narrative\nhistory and a production instance grew to 14KB against a ~4-5KB core.\n\n- templates/ZYLOS.md: define allowed content classes (stable IDs,\n  endpoints, k\n[…]\nand budget,\n  consolidate.js report gains warnThresholds/nearBudget\n- tests: cover WARN_THRESHOLDS values and warn<budget invariant\n\nCloses #696\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(zylos-memory): content rules + sync-time audit for references.md…",
          "author_name": "FelixLin6",
          "author_login": "FelixLin6",
          "committed_at": "2026-07-09T14:42:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9568392b1bb9dd28aff962e3aa7da744b66b36cb",
          "body": "This reverts commit c5b4745535c9e75a879f8dd6ccdba12d49629588.",
          "is_bot": false,
          "headline": "Revert \"chore(release): v0.5.4 (#688)\" (#692)",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-07-03T08:22:39Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a3efb7f9097110c4e8ee86ecaf91277d6ba348e8",
          "body": "Session-handoff summaries were piggybacked on the web-console channel,\nforcing every display surface to remember an endpoint_id='session-handoff'\nspecial case (#687). Introduce a virtual 'void' channel instead:\n\n- c4-send.js: channel 'void' records the row in c4.db (endpoint mandatory,\n  carries the\n[…]\nLI),\nmigration re-tag (c4-db CLI), void exclusion on web-console routes (jest),\nupdated session-handoff prompt assertion.\n\nRefs #687, #621, #619\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(c4): first-class void channel for internal messages (#689) (#690)",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-07-03T08:11:23Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "c5b4745535c9e75a879f8dd6ccdba12d49629588",
          "body": "Co-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore(release): v0.5.4 (#688)",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-07-02T14:34:07Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "50d7f1e2debf43824a35f82512f6646a28cf0cd8",
          "body": "…(#687)\n\n* fix(web-console): hide session-handoff messages from console display\n\nSession-handoff notes (channel=web-console, endpoint=session-handoff)\nare internal continuity messages, but the console rendered every row on\nthe web-console channel, exposing task state and internal IDs to any\nclient. \n[…]\nrows from the console. IS NOT treats NULL as distinct and keeps them\nvisible.\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(web-console): hide session-handoff messages from console display …",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-07-02T14:19:37Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dadeca979d74385075bb97e5d1bc44886f788290",
          "body": "…B (#618)\n\n* docs: add dev plan for issue #618\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n* docs: update dev plan per Jinglever review — fix read-side boundaries\n\n- formatConversations() stays clean (no reply via) for c4-fetch/Memory Sync\n- Session-init and dispatcher rec\n[…]\n: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "fix(comm-bridge): store full inbound messages, strip reply-via from D…",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-07-01T16:14:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "dff7c84bf3510745fab1b5b950efc8bb952d4359",
          "body": "PR #682 introduced JSON.stringify() quoting around hook script paths,\nproducing `node \"/path/to/script.js\"` — inconsistent with #678's format\nunification which removed quoting from Codex hooks.\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: remove unnecessary path quoting in desiredClaudeHooks (#684)",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-07-01T10:14:55Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "48eac81f3c82ffe14d3f4e672da896cb6b2344a2",
          "body": "Co-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "fix: generate Claude hooks at runtime (#682)",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-07-01T09:56:22Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "dcbf438762b86c83c6da17f2072e347ffde73c49",
          "body": "…k (#681)\n\n* fix: send kick message after Codex launch to trigger SessionStart hook (#680)\n\nCodex's SessionStart hook is lazy — it only fires on the first user\nmessage, not on process start. After PR #675 moved all bootstrap\ncontext into the SessionStart hook, a PM2-restarted Codex would sit\nuniniti\n[…]\n tmux session: codex \"hello\" in the shell command\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: send kick message after Codex launch to trigger SessionStart hoo…",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-07-01T09:25:54Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "3dcfc99229af58cb9b2a29eda789099a918cefd7",
          "body": "…8) (#679)\n\n`coreSessionStartCommand()` used `JSON.stringify(script)` which wrapped\nthe path in double quotes, while dashboard hooks use unquoted paths.\nStandardize on unquoted format since zylos paths never contain spaces.\n\nCloses #678\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: unify hook command format — remove unnecessary path quoting (#67…",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-07-01T08:06:16Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0549792c75c4991da0349afea1e3ca876fa8c34b",
          "body": "fix: migrate Codex bootstrap to native SessionStart hook (#652)\n\nReplaces text-based Codex bootstrap prompt with native SessionStart hook for context injection. Core owns hook installation, trust validation (hash + version + feature flags), and session-start content delivery. Removes buildCodexBootstrapPrompt and all text-bootstrap paths.\n\nVerified: 2-person code review (Luna + zylos0t), dual trust smoke, Docker e2e (no-auth), Docker real-auth (gpt-5.5 model consumption).\n\nCloses #652",
          "is_bot": false,
          "headline": "fix: migrate Codex bootstrap to native SessionStart hook (#675)",
          "author_name": "Jinglever",
          "author_login": "jinglever",
          "committed_at": "2026-07-01T07:44:31Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "336739aa675c5c784e90cffe4444a9e3a77bdf1a",
          "body": "…truth (#674)\n\nCHECKPOINT_THRESHOLD controls both how many unsummarized messages get\ninjected verbatim at session start (all of them when under threshold) and\nwhen an early in-session Memory Sync fires. 30 was too large for the\nsession-start path — up to 30 raw messages on top of identity/state/refs\n[…]\nready used here for tmux-input-state.js). The context-monitor engine is\nalready parameter-driven and needs no change.\n\nCloses #673\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: lower Memory Sync checkpoint threshold 30→15 + single source of …",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-29T13:39:16Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "9799a87cce995560f726e829bce08cf5eca20b5f",
          "body": "…ummaries (#671)\n\n* fix: unify session-start context format + surface failures and null summaries\n\nMemory injection and C4 session init previously built their own ad-hoc\nsection framing (`=== LABEL ===` header-only vs `[Bracket Label]`), so the\ncombined session-start context read inconsistently. Int\n[…]\nANGELOG.md to match main; code changes\nunchanged.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: unify session-start context format + surface failures and null s…",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-28T18:13:57Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "e2401fe0a35fc35a46c0ce4e7dc86fdb59c7bc7b",
          "body": "These are intermediate process artifacts left in the repo, no code or doc\nreferences them:\n- docs/dev-plan-issue-651.md          (dev plan for #651)\n- docs/impl-session-start-orchestrator.md (impl design doc for #651)\n- docs/impl-tmux-launcher-clean-env.md    (older PR's impl doc)\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: remove leftover process docs from PR #668/#651 line (#672)",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-28T18:09:51Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "773b239c5ceb10c5d648c2509290973404e45738",
          "body": "…(#668)\n\n* docs: add SessionStart orchestrator design document (#651)\n\nDesign document for consolidating 4 SessionStart hooks into a single\norchestrator script with per-step error isolation and bounded runtime.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\n\n* feat: add SessionStart orches\n[…]\nden hook script path keys\n\n* test: make hook path fixtures portable\n\n---------\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "feat: consolidate SessionStart hooks into single orchestrator (#651) …",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-28T15:35:59Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "ff1c2ae59e8b718c1d7f31dce402eb7242c7b938",
          "body": "* fix(upgrade): persist pm2 dump after component upgrade restart\n\n`zylos upgrade <component>` restarted the service but never called\n`pm2 save`, so the upgraded process lived only in PM2's in-memory list.\nOn the next reboot `pm2 resurrect` restored the pre-upgrade dump, silently\ndropping the upgrade\n[…]\nntext) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: owen0x6f <owen0x6f@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.8 <noreply@anthropic.com>\nCo-authored-by: zylos <creator@zylos.ai>",
          "is_bot": false,
          "headline": "fix(upgrade): persist pm2 dump after component upgrade restart (#669)",
          "author_name": "owen0x6f",
          "author_login": "owen0x6f",
          "committed_at": "2026-06-26T13:30:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2b8c7cd7015a49d42e7c7cdf36b0c2dbd43c82bf",
          "body": "…66) (#667)\n\n- Expand RATE_LIMIT_PATTERNS to match \"session limit\", \"weekly limit\",\n  \"Opus limit\", \"Sonnet limit\" and other named limit variants\n- Support curly apostrophe (') in addition to straight (')\n- Fix reset time regex to handle date-based formats like\n  \"resets Jun 29, 3am (Asia/Singapore)\n[…]\nme\n  is not parseable\n- Add 15 unit tests covering pattern matching and time parsing\n- Export test helpers for direct unit testing\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: broaden rate limit detection patterns and reset time parsing (#6…",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-25T06:39:46Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "bbc28c672ffc983656716fc18a8a5852ec7375f9",
          "body": "…hreshold (#662)\n\nWhen upgrading older instances, syncTemplateModelSetting() would backfill\nopus[1m] without checking whether the existing new_session_threshold is\ncompatible. An instance with threshold=70 (the old default) would end up\nwith opus[1m]+70%, effectively using ~700K context per session.\n[…]\ning the threshold,\nsince there is no provenance to distinguish \"user explicitly set 70\"\nfrom \"system old default 70\".\n\nCloses #661\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: guard opus[1m] model backfill against incompatible new_session_t…",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-23T17:30:04Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "27b7bc5ea7a1cdc292328505c0cdfd34177dc079",
          "body": "revert: Composio MCP integration (#656)",
          "is_bot": false,
          "headline": "Merge pull request #657 from zylos-ai/revert/composio-mcp-integration",
          "author_name": "Luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-22T03:39:06Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "edc695310f24905b3c9c64db156daaa18095feed",
          "body": "This reverts commit 69c40e9fa564baffee8fb21f7b9347dde899d9a0.",
          "is_bot": false,
          "headline": "Revert \"feat: Composio MCP integration (Tool Router, JIT tool-scoping)\"",
          "author_name": "zylos-luna",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-22T03:32:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "69c40e9fa564baffee8fb21f7b9347dde899d9a0",
          "body": "Adds safe Composio Tool Router MCP configuration persistence for Claude and Codex runtimes.",
          "is_bot": false,
          "headline": "feat: Composio MCP integration (Tool Router, JIT tool-scoping)",
          "author_name": "FelixLin6",
          "author_login": "FelixLin6",
          "committed_at": "2026-06-21T18:56:36Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6be3db26d628d957df3244a66dc643651197430e",
          "body": "Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: bump version to 0.5.3 (#654)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-17T15:38:34Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3020a53705db61d14264eac193d14a33292ca153",
          "body": "* fix: pin process.execPath in tmux clean PATH to prevent node version mismatch (#445)\n\nWhen PM2 starts activity-monitor with a stripped PATH (no .nvm), _buildPath()\nproduced a PATH without the nvm node directory, causing tmux child processes\n(c4-control.js) to fall back to system node v18. Loading \n[…]\nux-env-execpath) already covers the verification.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: pin process.execPath in tmux clean PATH (#445) (#653)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-17T15:17:33Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "90954039d221d6ed4ef3cd99e802effc335e29d1",
          "body": "…7) (#650)\n\n* docs: add dev plan for issue #647 (real-runtime smoke + service-health)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n* docs: revise dev plan #647 per Jinglever R1 (preflight-before-build, per-skill resolve assertion)\n\nCo-Authored-By: Claude Opus 4.8 (1M contex\n[…]\nference. Drop it\nbefore merge so it doesn't ship.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test(runtime): real-smoke + service-health integration scenarios (#64…",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-17T13:20:14Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "25ba2bd119bc08342f1734856fa2dec181dda30d",
          "body": "…ios) (#645) (#646)\n\n* docs: add dev plan for issue #645\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n* docs: revise dev plan #645 per Jinglever R1 (gate semantics, no-op guard, codex creds)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n* docs: scop\n[…]\nen, zero NODE_MODULE_VERSION errors in build log.\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "test: add local runtime integration-test harness (env-injected scenar…",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-17T09:22:26Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "65e3afc9bf664a3fd1765032a689a79056e633e3",
          "body": "…te (#640) (#642)\n\n* docs: add dev plan for issue #640 (checkAuth tristate + --no-validate)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n* docs: tighten dev plan #640 per Jinglever R1 (wording + test assertion clarity)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@\n[…]\n docs: remove dev plan doc post-acceptance (#640)\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: unify runtime checkAuth into explicit tristate + add --no-valida…",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-16T13:47:06Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "48ac162466554f9a912fd76b2159f346d24bc87b",
          "body": "…aude + Codex) (#641)\n\n* fix: init Claude auth check keys off loggedIn field, not exit code\n\nisClaudeAuthenticated() previously returned `result.status === 0` from\n`claude auth status`, treating the process exit code as the auth signal.\nThat conflated several distinct outcomes — genuinely not logged\n[…]\nt afterEach drains it);\ncleaned once via after().\n\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: runtime auth checks key off explicit signals, not exit codes (Cl…",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-16T10:21:52Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1c635f556c2e57b36ae4b62d2cfda5a3e2227b09",
          "body": "…model backfill (#638)\n\nFresh installs default the provisioned Claude model to opus[1m] (latest Opus, 1M context) instead of claude-opus-4-6. The Claude new_session_threshold default is paired with the model: fresh installs and upgrade-time opus[1m] model backfills write an explicit new_session_thre\n[…]\nd; runtime fallback stays 70. Codex (codex_new_session_threshold=75) is unaffected. Not gated by current runtime. Doc wording in activity-monitor SKILL.md points to config.json as the source of truth.",
          "is_bot": false,
          "headline": "feat: default to opus[1m] and pair Claude new-session threshold with …",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-15T14:06:57Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "65585999e7c3f2e5335ef39e70c824fa07e3bc48",
          "body": "* docs: add dev plan for issue #629 (web-console attachments)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n* docs: address #629 plan review R1 (realpath allowlist, 2KB offload guard, attachment-only gates)\n\nCo-Authored-By: Claude Fable 5 <noreply@anthropic.com>\n\n* feat: add web console a\n[…]\nCo-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Fable 5 <noreply@anthropic.com>\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "feat: web-console image and file upload/display (#629) (#636)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-15T12:07:10Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "7fdf42c01c4079ef2ed18568349fb4d7a679f895",
          "body": "…e (#633)\n\nGitHub calls in the CLI (tags listing, raw file fetch, tarball\ndownload) were single-shot: an HTTP 403 (primary rate limit, 60/h\nunauthenticated per IP) or 429 (secondary limit) failed the command\nimmediately. Customer instances on shared egress IPs without a token\nhit this during onboard\n[…]\nstill\nfalls through to the authenticated endpoint before any sleep.\nNon-rate-limit failures keep failing fast. Delays are overridable\nvia ZYLOS_GH_RETRY_DELAY_MS for tests and ops tuning.\n\nCloses #632",
          "is_bot": false,
          "headline": "fix: auto-retry GitHub API calls on rate limiting in zylos add/upgrad…",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-12T10:34:38Z",
          "body_truncated": true,
          "is_coding_agent": false
        },
        {
          "oid": "2fc61cf0a72ee260679c629fa693c22275160cf3",
          "body": "* fix: raise zylos-memory state budget to 16kb\n\n* fix: align core memory budgets\n\n* docs: clarify memory consolidation trigger wording\n\n* docs: prevent Codex memory sync PM2 sidecars\n\n---------\n\nCo-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "Raise zylos-memory core file budgets to 16KB (#623)",
          "author_name": "Jinglever",
          "author_login": "jinglever",
          "committed_at": "2026-06-10T08:33:56Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "8ee9bd9007edab46f766f3574e0ad56cf69268c2",
          "body": "chore: release v0.5.2",
          "is_bot": false,
          "headline": "Merge pull request #608 from zylos-ai/chore/release-v0.5.2",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-01T17:10:09Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b2ea816635dd54c452a907bdc9e16b445af527a7",
          "body": "Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: release v0.5.2 (#608)",
          "author_name": "zylos",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-01T17:05:50Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "d51d6a00975088a469da97bda00228e7d2c63c1d",
          "body": "fix: preserve external settings in Codex config (#606)",
          "is_bot": false,
          "headline": "Merge pull request #607 from zylos-ai/fix/issue-606-config-merge",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-01T16:47:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3adc6c8791aab746bb946ab5371bf889c6e4489a",
          "body": null,
          "is_bot": false,
          "headline": "fix: add codex project managed defaults",
          "author_name": "howard_mini",
          "author_login": null,
          "committed_at": "2026-06-01T16:40:29Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "62834d8ff711f61ad81aaff0e5d6f7dd6dd2978d",
          "body": null,
          "is_bot": false,
          "headline": "refactor: use smol-toml for codex config merge",
          "author_name": "howard_mini",
          "author_login": null,
          "committed_at": "2026-06-01T16:20:30Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7610dd23195cfd580f5493f81df53c2d21dacb31",
          "body": null,
          "is_bot": false,
          "headline": "docs: remove dev plan (review complete)",
          "author_name": "zylos",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-01T15:04:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "92ac79af9b3b10e656c6ea5b93608f3f792ff20f",
          "body": null,
          "is_bot": false,
          "headline": "fix: preserve codex config ownership boundaries",
          "author_name": "howard_mini",
          "author_login": null,
          "committed_at": "2026-06-01T14:59:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "6440052c82a6bd94d9f2098a3b29c901321efb03",
          "body": null,
          "is_bot": false,
          "headline": "docs: fix dev plan issue #606 per Jinglever R1",
          "author_name": "zylos",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-01T14:51:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "871b841875482442063fc01bc66e2d4ab5197e50",
          "body": null,
          "is_bot": false,
          "headline": "docs: add dev plan for issue #606",
          "author_name": "zylos",
          "author_login": "zylos-luna",
          "committed_at": "2026-06-01T14:48:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "bd38923ee352dd26edbadd646c84b962c0c97d6b",
          "body": "Co-authored-by: linfan.lin <linfan.lin@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(caddy): show manual route config when unavailable (#602)",
          "author_name": "leslielin2025",
          "author_login": "leslielin2025",
          "committed_at": "2026-05-27T12:15:58Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "c1e7a0ac282afa2b063d1bc76d97bbe7e63d99a3",
          "body": "Co-authored-by: linfan.lin <linfan.lin@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(c4): store status cooldowns in sqlite (#604)",
          "author_name": "leslielin2025",
          "author_login": "leslielin2025",
          "committed_at": "2026-05-27T12:13:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "3bd74fe0c16dc205b3174ad36244e45dd8170ab4",
          "body": "* fix(c4): cooldown repeated status replies\n\n* fix(c4): harden status cooldown persistence\n\n* fix(c4): reserve status cooldown before notify\n\n---------\n\nCo-authored-by: linfan.lin <linfan.lin@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(c4): cooldown repeated status notices (#599)",
          "author_name": "leslielin2025",
          "author_login": "leslielin2025",
          "committed_at": "2026-05-27T07:45:59Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "33a54135eb893ac79d02075b0d8dcf46507bbcd5",
          "body": "Co-authored-by: Zylos <zylos@zylos.ai>",
          "is_bot": false,
          "headline": "chore: release v0.5.1 (#596)",
          "author_name": "zylos0t",
          "author_login": "zylos0t",
          "committed_at": "2026-05-25T11:32:01Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "39bb59928da8bcde30d4a1367725ee663b95bb05",
          "body": "Run component post-upgrade hooks from the upgrade pipeline while preserving JSON output semantics.\n\n- capture hook stdout/stderr and replay only in human mode\n- keep hook failures non-fatal with diagnostics in step metadata\n- validate hook paths, including symlink resolution, stay within the component directory\n- add focused coverage for hook success, failure, JSON isolation, and path escape cases",
          "is_bot": false,
          "headline": "feat(upgrade): run post-upgrade hook automatically",
          "author_name": "gavin",
          "author_login": "gavin09527",
          "committed_at": "2026-05-25T11:09:03Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "106fbdfdd477b5ed177d47f619dbbdd47d0a489a",
          "body": "… (#591)\n\nReplace Chinese user message catalog with English equivalents for\nbroader accessibility. Update test assertions accordingly.\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "refactor(activity-monitor): translate user-facing messages to English…",
          "author_name": "leslielin2025",
          "author_login": "leslielin2025",
          "committed_at": "2026-05-21T06:22:39Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0f23cbc68e976eedec5f14f736680eac81d81808",
          "body": "* chore: bump version to 0.5.0\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n* chore: clarify upgrade notes — restart AM after upgrade\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n* chore: upgrade notes — require AM stop for v0.4.13 and earlier\n\nCo-\n[…]\nd manifest manual copy note for v0.4.13 upgraders\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: release v0.5.0 (#587)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-05-14T09:42:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "b55cde0bd1fa8ee96cbe7b9298dd5dc3a7e69d52",
          "body": "Add health_check_enabled config gate (default: true) to the health-check\ntask, following the same pattern as daily_upgrade_enabled. Disable with\n`zylos config set health_check_enabled false`.\n\nCloses #585\n\nCo-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat(activity-monitor): add toggle for 24h health check (#586)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-05-14T08:18:26Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "0d086d2816e843fa60c2d119ec266ab8f6762863",
          "body": "* docs: implementation plan for tmux-launcher clean env\n\nBased on the approved proposal-clean-env-v2, this document details\nthe implementation approach for replacing the shell source mechanism\nwith a launcher-based pipeline (Level 1 env allowlisting).\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthro\n[…]\nale doc comment — buildCompatEnv no longer labeled as default.\n\nCo-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: tmux-launcher clean env (Level 1 allowlisting) (#576)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-05-14T07:20:28Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "6e33f49014572a6ba649b0ad9caeb1e86f7cf604",
          "body": "* fix(activity-monitor): detect image dimension limit errors\n\n* fix(runtime): add timeout to all execSync calls in runtime adapters\n\nRuntime adapter execSync calls (tmux has-session, list-panes, ps, pgrep,\nkill-session, capture-pane, etc.) lacked timeouts. When the tmux server\nbecomes unresponsive (\n[…]\no-authored-by: linfan.lin <linfan.lin@users.noreply.github.com>\nCo-authored-by: leslielin2025 <225646034+leslielin2025@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(activity-monitor): detect image dimension limit errors (#579)",
          "author_name": "leslielin2025",
          "author_login": "leslielin2025",
          "committed_at": "2026-05-11T10:22:03Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "cd9adfb6403f00500d12a5a5a1c0cb5dd11ac06b",
          "body": "Co-authored-by: zylos0t <zylos0t@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(upgrade): harden symlinked skills rollback (#577)",
          "author_name": "zylos0t",
          "author_login": "zylos0t",
          "committed_at": "2026-05-11T06:18:17Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "9834ae927396d861e0f42ad058bb720eeb47cac6",
          "body": "* feat: support component configure hooks\n\n* fix: bound configure hook execution\n\n---------\n\nCo-authored-by: Zylos <zylos@zylos.ai>",
          "is_bot": false,
          "headline": "feat: support component configure hooks (#578)",
          "author_name": "zylos0t",
          "author_login": "zylos0t",
          "committed_at": "2026-05-10T17:29:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "b6091c79570bee062aa84e4374b106f1c1bbcef8",
          "body": "…572)\n\n* fix(upgrade): run post-install steps from new package\n\n* docs(upgrade): add PM2 env retry note\n\n* fix(upgrade): avoid rollback after finalizer handoff\n\n---------\n\nCo-authored-by: linfan.lin <linfan.lin@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(upgrade): run self-upgrade post-install steps from new package (#…",
          "author_name": "leslielin2025",
          "author_login": "leslielin2025",
          "committed_at": "2026-05-08T10:52:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "83b8ee6a56f3a277ac77de9cdc5f48522835d164",
          "body": "Co-authored-by: Zylos <zylos@zylos.ai>",
          "is_bot": false,
          "headline": "fix: route handoff summaries to internal channel (#571)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-05-08T09:17:46Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "ae10a152fddb8517c8150c07410c4fc72a2de734",
          "body": "SQLite stores UTC timestamps without timezone indicator, causing the\nbrowser to interpret them as local time. Append 'Z' suffix so the\nbrowser correctly parses them as UTC, then convert to the configured\ntimezone from .env for display.\n\nCo-authored-by: Claude Opus 4.7 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(web-console): respect TZ config for timestamp display (#568)",
          "author_name": "summingyu",
          "author_login": "summingyu",
          "committed_at": "2026-05-08T09:04:46Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "2d0d0a09b64e8bf48cbd9006d7ae5c0da62f6b8f",
          "body": "Co-authored-by: linfan.lin <linfan.lin@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(upgrade): verify activity monitor env via pm2 jlist (#570)",
          "author_name": "leslielin2025",
          "author_login": "leslielin2025",
          "committed_at": "2026-05-08T08:46:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "59b2f60e433e229a8ec57e7c124612c4aeb32ba0",
          "body": "Co-authored-by: linfan.lin <linfan.lin@users.noreply.github.com>",
          "is_bot": false,
          "headline": "fix(claude): default settings model to opus 4.6 (#567)",
          "author_name": "leslielin2025",
          "author_login": "leslielin2025",
          "committed_at": "2026-05-08T07:23:34Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "1e97a173f9f100fca0403899cc675605370ea6a7",
          "body": "* docs: add Activity Monitor design doc (C4 model)\n\nNew design document for Activity Monitor as a clean-slate module design,\nstructured using the C4 model (Context/Containers/Components/Code).\nIncludes 34 key design decisions extracted from PR #501 review.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@a\n[…]\no-authored-by: leslielin2025 <225646034+leslielin2025@users.noreply.github.com>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>\nCo-authored-by: linfan.lin <linfan.lin@users.noreply.github.com>",
          "is_bot": false,
          "headline": "refactor(am): Activity Monitor v3 — modular architecture (#545)",
          "author_name": "leslielin2025",
          "author_login": "leslielin2025",
          "committed_at": "2026-05-08T04:31:15Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "34946391cd821a37472cefe7108e03abc4a21019",
          "body": "On fresh servers with empty npm cache, 120s timeout is insufficient for\ndownloading all dependencies. Bump to 300s and switch stdio from pipe\nto inherit so users see real-time npm progress.\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: increase npm install timeout and show progress (#522)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-05-04T17:29:09Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "3a807de533db0b33c0a1b13d471d180c5dd93bd9",
          "body": "Co-authored-by: howard_mini <howard@howard-minideMac-mini.local>",
          "is_bot": false,
          "headline": "fix(caddy): forward stripped route prefix (#521)",
          "author_name": "Jinglever",
          "author_login": "jinglever",
          "committed_at": "2026-05-04T16:40:57Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "5f257eebc10952b7701e7aaad4fe88583ae9886a",
          "body": "* fix(c4): treat codex exit as lifecycle control\n\n* docs(create-skill): clarify YAML frontmatter safety",
          "is_bot": false,
          "headline": "fix(c4): treat Codex /exit as lifecycle control (#517)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-28T04:58:38Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "330dd9eebd717b6d1a9bda13e01aec19fee006f4",
          "body": "PATH grows from ~17 unique entries to 189+ through a 4-layer\ncompounding cycle:\n\n1. ecosystem.config.cjs builds ENHANCED_PATH by concatenating\n   SYSTEM_PATH + process.env.PATH without dedup. Each PM2 restart\n   re-evaluates this file, and process.env.PATH already contains\n   the previous ENHANCED_P\n[…]\nM_PATH persistence, and tmux\nPATH pass-through. Preserves entry order (first occurrence wins).\n\nCo-authored-by: emma-zylos <emma-zylos@coco.xyz>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix: deduplicate PATH to prevent bloat across restarts (#499)",
          "author_name": "Daniel Zhou",
          "author_login": "danielzhou82",
          "committed_at": "2026-04-17T03:29:11Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "2167fbeab96379160a5c29f4b5c3fc515210279f",
          "body": "* feat: add claude web tool watchdog\n\n* fix: harden tool event stream recovery and remove dead api activity reader\n\n* fix(security): patch path-to-regexp ReDoS in web-console\n\n* fix: harden claude watchdog foreground detection\n\n* fix: dedupe duplicate claude tool lifecycle events\n\n* fix: ignore subagent hook events in watchdog stream",
          "is_bot": false,
          "headline": "Add Claude web tool watchdog and harden tool event recovery (#500)",
          "author_name": "Athan",
          "author_login": "athanbase",
          "committed_at": "2026-04-16T11:02:07Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "a6014bd0fd1b47fa8cf336373c17f0c62c94cc86",
          "body": "* docs: add Node.js dependency note to README\n\nHighlights that npm packages are tied to the system Node.js version.\nIf users upgrade Node.js (e.g. via nvm), globally installed packages\nincluding Zylos may disappear. Added to both EN and zh-CN READMEs.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthro\n[…]\n <noreply@anthropic.com>\n\n* docs: revert nvm to v0.40.3 to match install.sh\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: add Node.js dependency note to README (#495)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-13T15:30:30Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "8a2a293670d3eaec3c0eda88a22acc3a528c512a",
          "body": "Bump version to 0.4.13 and document C4 Claude input-box fallback\ndetection plus send-retry reduction from PR #493.\n\nCo-authored-by: Zylos <zylos@zylos.ai>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: prepare release v0.4.13 (#494)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-11T16:42:27Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "57afc1132371275745af207925250084651f9998",
          "body": "* fix(c4): add claude input fallback and reduce retry count\n\n* refactor(c4): use prompt-right 10-char window for claude fallback\n\n* refactor(c4): make claude fallback function explicit\n\n---------\n\nCo-authored-by: Zylos <zylos@zylos.ai>",
          "is_bot": false,
          "headline": "fix(c4): add Claude input fallback and reduce send retries (#493)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-11T16:24:54Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "33cb1e2a01e134b1ac904369b9a724d2365ba3f2",
          "body": "* chore: prepare release v0.4.12\n\n* docs: expand v0.4.12 changelog scope\n\n* docs: rewrite 0.4.12 changelog as synthesized summary\n\nReplace per-commit changelog entries with a consolidated summary\nthat describes the net functional changes between v0.4.11 and v0.4.12.\nAdd upgrade-strongly-recommended notice.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Zylos <zylos@zylos.ai>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "chore: prepare release v0.4.12 (#491)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-08T14:40:03Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "9fb43962e02093b8efe087a3b356e4e01c664068",
          "body": "* fix: fallback tmpdir for copyTree self-copy backups\n\n* fix: fallback tmpdir for diff3 merge workspace\n\n---------\n\nCo-authored-by: Zylos <zylos@zylos.ai>",
          "is_bot": false,
          "headline": "fix: fallback tmpdir for copyTree self-copy backups (#490)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-08T14:14:21Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "605595928b73d9dc49d73d24bd583efca10fa2d9",
          "body": "Co-authored-by: Zylos <zylos@zylos.ai>",
          "is_bot": false,
          "headline": "fix: fallback tmpdir for self-upgrade backup path (#489)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-08T12:27:19Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "32a1191e2fc84c9194a0ca807375fff9d3c7c619",
          "body": "Co-authored-by: Zylos <zylos@zylos.ai>",
          "is_bot": false,
          "headline": "fix: fallback tmpdir handling in download helpers (#488)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-08T12:19:15Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "7651bf61506a81924e4a0b1a21d86ad1ff706d1f",
          "body": "…#487)\n\n* fix: add safety checks to upgrade --temp-dir to prevent directory deletion\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\n\n* fix: const -> let for tempDirWasProvided to support fallback reassignment\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\n\n* fix: resolve symlinks\n[…]\nmessage\n\n* docs: update getAllowedTmpRoots comment\n\n---------\n\nCo-authored-by: Zylos10 <zylos10@zylos.ai>\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>\nCo-authored-by: Zylos <zylos@zylos.ai>",
          "is_bot": false,
          "headline": "fix: upgrade --temp-dir safety checks to prevent directory deletion (…",
          "author_name": "voya",
          "author_login": "voyax",
          "committed_at": "2026-04-08T08:50:38Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "1345d45ae7e978b360694eedfa32d2836dc2aa18",
          "body": "Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "docs: add PR #479 to CHANGELOG for v0.4.11 (#480)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-02T12:40:24Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "71e383501964a13d36a9767b977316ec1e9a1c72",
          "body": "…479)\n\nThe 30-min periodic probe bypassed the heartbeatEnabled config flag,\nsending heartbeat checks even when heartbeat was disabled by default.\nNow gated by engine.heartbeatEnabled like primary heartbeat polling.\n\nAlso fixes outdated comment (\"3-min\" → \"30-min\") and probe reason\nstring (\"periodic_3min\" → \"periodic_30min\").\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "fix(activity-monitor): gate periodic probe behind heartbeatEnabled (#…",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-02T12:31:15Z",
          "body_truncated": false,
          "is_coding_agent": true
        },
        {
          "oid": "30e205d3926e3362bb6506211ea2d9d90e00dafb",
          "body": "* chore: bump version to 0.4.11 and update changelog\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\n\n* chore: update release process and sync package-lock.json\n\n- Add package-lock.json step to release process in CLAUDE.md\n- Remove superseded version convention\n- Sync package-lock.json with\n[…]\nply@anthropic.com>\n\n* docs: update CHANGELOG for block-queue-until-idle fix\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>\n\n---------\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Release v0.4.11 (#478)",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-02T11:47:56Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "fd03fe998aa2872b59bb0356a1926a16c4490087",
          "body": "…y paths (#477)\n\nheartbeatEnabled=false was a full kill switch that blocked ALL heartbeat\nprocessing in processHeartbeat(), including recovery probes, rate_limited\ncooldown handling, signal acceleration, and down-check. This meant that\ndisabling periodic heartbeat polling also disabled all health re\n[…]\n All other paths (pending result processing, rate_limited→recovering,\nsignal acceleration, recovering backoff, down-check) remain fully active.\n\nCo-authored-by: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "Fix heartbeatEnabled scope: only disable primary polling, not recover…",
          "author_name": "Zylos01",
          "author_login": "zylos-luna",
          "committed_at": "2026-04-02T09:38:49Z",
          "body_truncated": true,
          "is_coding_agent": true
        },
        {
          "oid": "45685c1f4f76ffeff75bfcf805c101db5f1b1e41",
          "body": "feat: disable autoMemoryEnabled and autoDreamEnabled by default",
          "is_bot": false,
          "headline": "Merge pull request #476 from zylos-ai/feat/disable-auto-memory-dream",
          "author_name": "voya",
          "author_login": "voyax",
          "committed_at": "2026-04-01T18:29:43Z",
          "body_truncated": false,
          "is_coding_agent": false
        },
        {
          "oid": "4aecdb90b29e10b4211e19c63157cfe9aa6fd254",
          "body": "Zylos has its own memory system — Claude's built-in auto-memory and\nauto-dream should be off by default to avoid conflicts. Uses the same\nbackfill pattern as model: set on init/upgrade if absent, preserve if\nuser already configured.\n\nCo-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>",
          "is_bot": false,
          "headline": "feat: disable autoMemoryEnabled and autoDreamEnabled by default",
          "author_name": "zylos-01",
          "author_login": null,
          "committed_at": "2026-04-01T18:21:25Z",
          "body_truncated": false,
          "is_coding_agent": true
        }
      ],
      "releases_count": 50,
      "commits_last_year": 588,
      "latest_release_at": "2026-07-14T14:42:51Z",
      "latest_release_tag": "v0.6.0",
      "releases_from_tags": false,
      "days_since_last_push": 2,
      "active_weeks_last_year": 24,
      "days_since_latest_release": 8,
      "mean_days_between_releases": 12
    },
    "community": {
      "has_readme": true,
      "has_license": true,
      "has_description": true,
      "has_contributing": true,
      "health_percentage": 87,
      "has_issue_template": false,
      "has_code_of_conduct": true,
      "has_pull_request_template": true
    },
    "ecosystem": {
      "packages": [
        {
          "name": "web-console",
          "exists": true,
          "license": "BSD-3-Clause",
          "keywords": [],
          "ecosystem": "npm",
          "matches_repo": null,
          "registry_url": "https://www.npmjs.com/package/web-console",
          "is_deprecated": false,
          "latest_version": "0.0.0",
          "repository_url": null,
          "versions_count": 1,
          "total_downloads": null,
          "dependents_count": null,
          "deprecation_note": null,
          "maintainers_count": 1,
          "monthly_downloads": 65,
          "first_published_at": "2015-08-10T21:10:20.756000Z",
          "latest_published_at": "2015-08-10T21:10:20.756000Z",
          "latest_version_yanked": null,
          "days_since_latest_publish": 3998
        }
      ]
    },
    "popularity": {
      "forks": 119,
      "stars": 1136,
      "watchers": 66,
      "fork_history": {
        "days": [
          {
            "date": "2026-02-11",
            "count": 3
          },
          {
            "date": "2026-02-12",
            "count": 1
          },
          {
            "date": "2026-02-13",
            "count": 1
          },
          {
            "date": "2026-02-14",
            "count": 3
          },
          {
            "date": "2026-02-15",
            "count": 1
          },
          {
            "date": "2026-02-16",
            "count": 2
          },
          {
            "date": "2026-02-17",
            "count": 2
          },
          {
            "date": "2026-02-18",
            "count": 2
          },
          {
            "date": "2026-02-19",
            "count": 4
          },
          {
            "date": "2026-02-20",
            "count": 2
          },
          {
            "date": "2026-02-21",
            "count": 2
          },
          {
            "date": "2026-02-23",
            "count": 4
          },
          {
            "date": "2026-02-24",
            "count": 2
          },
          {
            "date": "2026-02-25",
            "count": 1
          },
          {
            "date": "2026-02-26",
            "count": 4
          },
          {
            "date": "2026-02-28",
            "count": 1
          },
          {
            "date": "2026-03-01",
            "count": 2
          },
          {
            "date": "2026-03-02",
            "count": 1
          },
          {
            "date": "2026-03-04",
            "count": 1
          },
          {
            "date": "2026-03-06",
            "count": 2
          },
          {
            "date": "2026-03-07",
            "count": 1
          },
          {
            "date": "2026-03-08",
            "count": 2
          },
          {
            "date": "2026-03-09",
            "count": 2
          },
          {
            "date": "2026-03-10",
            "count": 1
          },
          {
            "date": "2026-03-12",
            "count": 3
          },
          {
            "date": "2026-03-13",
            "count": 1
          },
          {
            "date": "2026-03-14",
            "count": 1
          },
          {
            "date": "2026-03-15",
            "count": 3
          },
          {
            "date": "2026-03-16",
            "count": 3
          },
          {
            "date": "2026-03-18",
            "count": 2
          },
          {
            "date": "2026-03-20",
            "count": 3
          },
          {
            "date": "2026-03-21",
            "count": 1
          },
          {
            "date": "2026-03-22",
            "count": 1
          },
          {
            "date": "2026-03-23",
            "count": 1
          },
          {
            "date": "2026-03-24",
            "count": 3
          },
          {
            "date": "2026-03-25",
            "count": 2
          },
          {
            "date": "2026-03-26",
            "count": 2
          },
          {
            "date": "2026-03-27",
            "count": 1
          },
          {
            "date": "2026-03-28",
            "count": 1
          },
          {
            "date": "2026-03-29",
            "count": 1
          },
          {
            "date": "2026-03-30",
            "count": 3
          },
          {
            "date": "2026-03-31",
            "count": 2
          },
          {
            "date": "2026-04-01",
            "count": 6
          },
          {
            "date": "2026-04-02",
            "count": 3
          },
          {
            "date": "2026-04-03",
            "count": 1
          },
          {
            "date": "2026-04-04",
            "count": 3
          },
          {
            "date": "2026-04-05",
            "count": 2
          },
          {
            "date": "2026-04-06",
            "count": 2
          },
          {
            "date": "2026-04-08",
            "count": 2
          },
          {
            "date": "2026-04-09",
            "count": 2
          },
          {
            "date": "2026-04-10",
            "count": 1
          },
          {
            "date": "2026-04-12",
            "count": 2
          },
          {
            "date": "2026-04-14",
            "count": 2
          },
          {
            "date": "2026-04-15",
            "count": 2
          },
          {
            "date": "2026-04-17",
            "count": 1
          },
          {
            "date": "2026-04-18",
            "count": 1
          },
          {
            "date": "2026-04-19",
            "count": 2
          },
          {
            "date": "2026-05-08",
            "count": 2
          },
          {
            "date": "2026-05-22",
            "count": 1
          },
          {
            "date": "2026-05-28",
            "count": 1
          },
          {
            "date": "2026-06-20",
            "count": 1
          },
          {
            "date": "2026-07-18",
            "count": 1
          }
        ],
        "complete": true,
        "collected": 119,
        "total_forks": 119
      },
      "star_history": null,
      "open_issues_and_prs": 137
    },
    "ai_readiness": {
      "has_nix": false,
      "example_dirs": [
        "examples"
      ],
      "has_llms_txt": false,
      "has_dockerfile": true,
      "has_mcp_signal": false,
      "bootstrap_files": [],
      "api_schema_files": [],
      "has_devcontainer": false,
      "typecheck_configs": [],
      "toolchain_manifests": [],
      "largest_source_bytes": 124245,
      "source_files_sampled": 229,
      "oversized_source_files": 4,
      "agent_instruction_files": [
        "CLAUDE.md"
      ],
      "agent_instruction_max_bytes": 6158
    },
    "dependencies": {
      "manifests": [
        "package.json"
      ],
      "advisories": {
        "error": null,
        "scope": "repository_graph",
        "source": "osv",
        "findings": [
          {
            "name": "js-yaml",
            "direct": true,
            "version": "3.14.2",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-52cp-r559-cp3m",
              "GHSA-h67p-54hq-rp68"
            ],
            "fixed_version": "4.3.0",
            "advisory_count": 2,
            "oldest_advisory_days": 37
          },
          {
            "name": "js-yaml",
            "direct": true,
            "version": "4.1.1",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-52cp-r559-cp3m",
              "GHSA-h67p-54hq-rp68"
            ],
            "fixed_version": "4.3.0",
            "advisory_count": 2,
            "oldest_advisory_days": 37
          },
          {
            "name": "multer",
            "direct": true,
            "version": "2.1.1",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-3p4h-7m6x-2hcm",
              "GHSA-72gw-mp4g-v24j"
            ],
            "fixed_version": "3.0.0-alpha.2",
            "advisory_count": 2,
            "oldest_advisory_days": 35
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "1.1.13",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-3jxr-9vmj-r5cp"
            ],
            "fixed_version": "5.0.7",
            "advisory_count": 1,
            "oldest_advisory_days": 1
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "2.0.3",
            "severity": "high",
            "ecosystem": "npm",
            "cvss_score": 7.5,
            "advisory_ids": [
              "GHSA-3jxr-9vmj-r5cp"
            ],
            "fixed_version": "5.0.7",
            "advisory_count": 1,
            "oldest_advisory_days": 1
          },
          {
            "name": "@babel/core",
            "direct": false,
            "version": "7.29.0",
            "severity": "low",
            "ecosystem": "npm",
            "cvss_score": 3.2,
            "advisory_ids": [
              "GHSA-4x5r-pxfx-6jf8"
            ],
            "fixed_version": "8.0.0-rc.6",
            "advisory_count": 1,
            "oldest_advisory_days": 37
          },
          {
            "name": "body-parser",
            "direct": false,
            "version": "1.20.4",
            "severity": "low",
            "ecosystem": "npm",
            "cvss_score": 3.7,
            "advisory_ids": [
              "GHSA-v422-hmwv-36x6"
            ],
            "fixed_version": "2.3.0",
            "advisory_count": 1,
            "oldest_advisory_days": 1
          }
        ],
        "collected": true,
        "malicious": [],
        "truncated": false,
        "by_severity": {
          "low": 2,
          "high": 5
        },
        "advisory_count": 10,
        "affected_count": 7,
        "assessed_count": 413,
        "malicious_count": 0,
        "assessed_package": null,
        "unassessed_count": 0,
        "direct_affected_count": 3
      },
      "ecosystems": [
        "npm"
      ],
      "dependencies": [
        {
          "name": "dotenv",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^16.4.7"
        },
        {
          "name": "js-yaml",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.1.1"
        },
        {
          "name": "smol-toml",
          "manifest": "package.json",
          "ecosystem": "npm",
          "version_constraint": "^1.6.1"
        },
        {
          "name": "dotenv",
          "manifest": "skills/activity-monitor/package.json",
          "ecosystem": "npm",
          "version_constraint": "^16.6.1"
        },
        {
          "name": "better-sqlite3",
          "manifest": "skills/comm-bridge/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.6.2"
        },
        {
          "name": "better-sqlite3",
          "manifest": "skills/scheduler/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.6.2"
        },
        {
          "name": "chrono-node",
          "manifest": "skills/scheduler/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.7.7"
        },
        {
          "name": "cron-parser",
          "manifest": "skills/scheduler/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.9.0"
        },
        {
          "name": "dotenv",
          "manifest": "skills/scheduler/package.json",
          "ecosystem": "npm",
          "version_constraint": "^16.6.1"
        },
        {
          "name": "better-sqlite3",
          "manifest": "skills/web-console/package.json",
          "ecosystem": "npm",
          "version_constraint": "^12.6.2"
        },
        {
          "name": "dotenv",
          "manifest": "skills/web-console/package.json",
          "ecosystem": "npm",
          "version_constraint": "^16.6.1"
        },
        {
          "name": "express",
          "manifest": "skills/web-console/package.json",
          "ecosystem": "npm",
          "version_constraint": "^4.18.2"
        },
        {
          "name": "multer",
          "manifest": "skills/web-console/package.json",
          "ecosystem": "npm",
          "version_constraint": "^2.1.1"
        },
        {
          "name": "ws",
          "manifest": "skills/web-console/package.json",
          "ecosystem": "npm",
          "version_constraint": "^8.20.1"
        },
        {
          "name": "dotenv",
          "manifest": "skills/zylos-memory/package.json",
          "ecosystem": "npm",
          "version_constraint": "^16.6.1"
        }
      ],
      "all_dependencies": {
        "error": null,
        "source": "github-sbom",
        "packages": [
          {
            "name": "better-sqlite3",
            "direct": true,
            "version": "12.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "chrono-node",
            "direct": true,
            "version": "2.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "cron-parser",
            "direct": true,
            "version": "4.9.0",
            "ecosystem": "npm"
          },
          {
            "name": "dotenv",
            "direct": true,
            "version": "16.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "express",
            "direct": true,
            "version": "4.22.1",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": true,
            "version": "3.14.2",
            "ecosystem": "npm"
          },
          {
            "name": "js-yaml",
            "direct": true,
            "version": "4.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "multer",
            "direct": true,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "smol-toml",
            "direct": true,
            "version": "1.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "ws",
            "direct": true,
            "version": "8.21.0",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/code-frame",
            "direct": false,
            "version": "7.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/compat-data",
            "direct": false,
            "version": "7.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/core",
            "direct": false,
            "version": "7.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/generator",
            "direct": false,
            "version": "7.29.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-compilation-targets",
            "direct": false,
            "version": "7.28.6",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-globals",
            "direct": false,
            "version": "7.28.0",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-module-imports",
            "direct": false,
            "version": "7.28.6",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-module-transforms",
            "direct": false,
            "version": "7.28.6",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-plugin-utils",
            "direct": false,
            "version": "7.28.6",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-string-parser",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-identifier",
            "direct": false,
            "version": "7.28.5",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helper-validator-option",
            "direct": false,
            "version": "7.27.1",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/helpers",
            "direct": false,
            "version": "7.29.2",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/parser",
            "direct": false,
            "version": "7.29.2",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-async-generators",
            "direct": false,
            "version": "7.8.4",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-bigint",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-class-properties",
            "direct": false,
            "version": "7.12.13",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-class-static-block",
            "direct": false,
            "version": "7.14.5",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-import-attributes",
            "direct": false,
            "version": "7.28.6",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-import-meta",
            "direct": false,
            "version": "7.10.4",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-json-strings",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-jsx",
            "direct": false,
            "version": "7.28.6",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-logical-assignment-operators",
            "direct": false,
            "version": "7.10.4",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-nullish-coalescing-operator",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-numeric-separator",
            "direct": false,
            "version": "7.10.4",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-object-rest-spread",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-optional-catch-binding",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-optional-chaining",
            "direct": false,
            "version": "7.8.3",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-private-property-in-object",
            "direct": false,
            "version": "7.14.5",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-top-level-await",
            "direct": false,
            "version": "7.14.5",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/plugin-syntax-typescript",
            "direct": false,
            "version": "7.28.6",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/template",
            "direct": false,
            "version": "7.28.6",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/traverse",
            "direct": false,
            "version": "7.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@babel/types",
            "direct": false,
            "version": "7.29.0",
            "ecosystem": "npm"
          },
          {
            "name": "@bcoe/v8-coverage",
            "direct": false,
            "version": "0.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "@emnapi/core",
            "direct": false,
            "version": "1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "@emnapi/runtime",
            "direct": false,
            "version": "1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "@emnapi/wasi-threads",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "@isaacs/cliui",
            "direct": false,
            "version": "8.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "@istanbuljs/load-nyc-config",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@istanbuljs/schema",
            "direct": false,
            "version": "0.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/console",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/core",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/diff-sequences",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/environment",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/expect",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/expect-utils",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/fake-timers",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/get-type",
            "direct": false,
            "version": "30.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/globals",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/pattern",
            "direct": false,
            "version": "30.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/reporters",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/schemas",
            "direct": false,
            "version": "30.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/snapshot-utils",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/source-map",
            "direct": false,
            "version": "30.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/test-result",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/test-sequencer",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/transform",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jest/types",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/gen-mapping",
            "direct": false,
            "version": "0.3.13",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/remapping",
            "direct": false,
            "version": "2.3.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/resolve-uri",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/sourcemap-codec",
            "direct": false,
            "version": "1.5.5",
            "ecosystem": "npm"
          },
          {
            "name": "@jridgewell/trace-mapping",
            "direct": false,
            "version": "0.3.31",
            "ecosystem": "npm"
          },
          {
            "name": "@napi-rs/wasm-runtime",
            "direct": false,
            "version": "0.2.12",
            "ecosystem": "npm"
          },
          {
            "name": "@pkgjs/parseargs",
            "direct": false,
            "version": "0.11.0",
            "ecosystem": "npm"
          },
          {
            "name": "@pkgr/core",
            "direct": false,
            "version": "0.2.9",
            "ecosystem": "npm"
          },
          {
            "name": "@sinclair/typebox",
            "direct": false,
            "version": "0.34.48",
            "ecosystem": "npm"
          },
          {
            "name": "@sinonjs/commons",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "@sinonjs/fake-timers",
            "direct": false,
            "version": "15.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "@tybys/wasm-util",
            "direct": false,
            "version": "0.10.1",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__core",
            "direct": false,
            "version": "7.20.5",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__generator",
            "direct": false,
            "version": "7.27.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__template",
            "direct": false,
            "version": "7.4.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/babel__traverse",
            "direct": false,
            "version": "7.28.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/istanbul-lib-coverage",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "@types/istanbul-lib-report",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/istanbul-reports",
            "direct": false,
            "version": "3.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "@types/node",
            "direct": false,
            "version": "25.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "@types/stack-utils",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@types/yargs",
            "direct": false,
            "version": "17.0.35",
            "ecosystem": "npm"
          },
          {
            "name": "@types/yargs-parser",
            "direct": false,
            "version": "21.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "@ungap/structured-clone",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-android-arm-eabi",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-android-arm64",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-darwin-arm64",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-darwin-x64",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-freebsd-x64",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-linux-arm-gnueabihf",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-linux-arm-musleabihf",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-linux-arm64-gnu",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-linux-arm64-musl",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-linux-ppc64-gnu",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-linux-riscv64-gnu",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-linux-riscv64-musl",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-linux-s390x-gnu",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-linux-x64-gnu",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-linux-x64-musl",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-wasm32-wasi",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-win32-arm64-msvc",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-win32-ia32-msvc",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "@unrs/resolver-binding-win32-x64-msvc",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "accepts",
            "direct": false,
            "version": "1.3.8",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-escapes",
            "direct": false,
            "version": "4.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-regex",
            "direct": false,
            "version": "6.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "4.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "ansi-styles",
            "direct": false,
            "version": "6.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "anymatch",
            "direct": false,
            "version": "3.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "append-field",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "argparse",
            "direct": false,
            "version": "1.0.10",
            "ecosystem": "npm"
          },
          {
            "name": "argparse",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "array-flatten",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "babel-jest",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "babel-plugin-istanbul",
            "direct": false,
            "version": "7.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "babel-plugin-jest-hoist",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "babel-preset-current-node-syntax",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "babel-preset-jest",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "balanced-match",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "base64-js",
            "direct": false,
            "version": "1.5.1",
            "ecosystem": "npm"
          },
          {
            "name": "baseline-browser-mapping",
            "direct": false,
            "version": "2.10.11",
            "ecosystem": "npm"
          },
          {
            "name": "bindings",
            "direct": false,
            "version": "1.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "bl",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "body-parser",
            "direct": false,
            "version": "1.20.4",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "1.1.13",
            "ecosystem": "npm"
          },
          {
            "name": "brace-expansion",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "browserslist",
            "direct": false,
            "version": "4.28.1",
            "ecosystem": "npm"
          },
          {
            "name": "bser",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "buffer",
            "direct": false,
            "version": "5.7.1",
            "ecosystem": "npm"
          },
          {
            "name": "buffer-from",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "busboy",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "bytes",
            "direct": false,
            "version": "3.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "call-bind-apply-helpers",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "call-bound",
            "direct": false,
            "version": "1.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "callsites",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "camelcase",
            "direct": false,
            "version": "5.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "camelcase",
            "direct": false,
            "version": "6.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "caniuse-lite",
            "direct": false,
            "version": "1.0.30001781",
            "ecosystem": "npm"
          },
          {
            "name": "chalk",
            "direct": false,
            "version": "4.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "char-regex",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "chownr",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "ci-info",
            "direct": false,
            "version": "4.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "cjs-module-lexer",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "cliui",
            "direct": false,
            "version": "8.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "co",
            "direct": false,
            "version": "4.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "collect-v8-coverage",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "color-convert",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "color-name",
            "direct": false,
            "version": "1.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "concat-map",
            "direct": false,
            "version": "0.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "concat-stream",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "content-disposition",
            "direct": false,
            "version": "0.5.4",
            "ecosystem": "npm"
          },
          {
            "name": "content-type",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "convert-source-map",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "cookie",
            "direct": false,
            "version": "0.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "cookie-signature",
            "direct": false,
            "version": "1.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "cross-spawn",
            "direct": false,
            "version": "7.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "2.6.9",
            "ecosystem": "npm"
          },
          {
            "name": "debug",
            "direct": false,
            "version": "4.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "decompress-response",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "dedent",
            "direct": false,
            "version": "1.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "deep-extend",
            "direct": false,
            "version": "0.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "deepmerge",
            "direct": false,
            "version": "4.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "depd",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "destroy",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "detect-libc",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "detect-newline",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "dunder-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "eastasianwidth",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "ee-first",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "electron-to-chromium",
            "direct": false,
            "version": "1.5.328",
            "ecosystem": "npm"
          },
          {
            "name": "emittery",
            "direct": false,
            "version": "0.13.1",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "8.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "emoji-regex",
            "direct": false,
            "version": "9.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "encodeurl",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "end-of-stream",
            "direct": false,
            "version": "1.4.5",
            "ecosystem": "npm"
          },
          {
            "name": "error-ex",
            "direct": false,
            "version": "1.3.4",
            "ecosystem": "npm"
          },
          {
            "name": "es-define-property",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "es-errors",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "es-object-atoms",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "escalade",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "escape-html",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "escape-string-regexp",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "esprima",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "etag",
            "direct": false,
            "version": "1.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "execa",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "exit-x",
            "direct": false,
            "version": "0.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "expand-template",
            "direct": false,
            "version": "2.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "expect",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "fast-json-stable-stringify",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "fb-watchman",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "file-uri-to-path",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "finalhandler",
            "direct": false,
            "version": "1.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "find-up",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "foreground-child",
            "direct": false,
            "version": "3.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "forwarded",
            "direct": false,
            "version": "0.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "fresh",
            "direct": false,
            "version": "0.5.2",
            "ecosystem": "npm"
          },
          {
            "name": "fs-constants",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "fs.realpath",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "fsevents",
            "direct": false,
            "version": "2.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "function-bind",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "gensync",
            "direct": false,
            "version": "1.0.0-beta.2",
            "ecosystem": "npm"
          },
          {
            "name": "get-caller-file",
            "direct": false,
            "version": "2.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "get-intrinsic",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-package-type",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "get-proto",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "get-stream",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "github-from-package",
            "direct": false,
            "version": "0.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "glob",
            "direct": false,
            "version": "10.5.0",
            "ecosystem": "npm"
          },
          {
            "name": "glob",
            "direct": false,
            "version": "7.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "gopd",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "graceful-fs",
            "direct": false,
            "version": "4.2.11",
            "ecosystem": "npm"
          },
          {
            "name": "has-flag",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "has-symbols",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "hasown",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "html-escaper",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "http-errors",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "human-signals",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "iconv-lite",
            "direct": false,
            "version": "0.4.24",
            "ecosystem": "npm"
          },
          {
            "name": "ieee754",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "import-local",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "imurmurhash",
            "direct": false,
            "version": "0.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "inflight",
            "direct": false,
            "version": "1.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "inherits",
            "direct": false,
            "version": "2.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "ini",
            "direct": false,
            "version": "1.3.8",
            "ecosystem": "npm"
          },
          {
            "name": "ipaddr.js",
            "direct": false,
            "version": "1.9.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-arrayish",
            "direct": false,
            "version": "0.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "is-fullwidth-code-point",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-generator-fn",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "is-stream",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "isexe",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-coverage",
            "direct": false,
            "version": "3.2.2",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-instrument",
            "direct": false,
            "version": "6.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-report",
            "direct": false,
            "version": "3.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-lib-source-maps",
            "direct": false,
            "version": "5.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "istanbul-reports",
            "direct": false,
            "version": "3.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "jackspeak",
            "direct": false,
            "version": "3.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "jest",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-changed-files",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-circus",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-cli",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-config",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-diff",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-docblock",
            "direct": false,
            "version": "30.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-each",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-environment-node",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-haste-map",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-leak-detector",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-matcher-utils",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-message-util",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-mock",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-pnp-resolver",
            "direct": false,
            "version": "1.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "jest-regex-util",
            "direct": false,
            "version": "30.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "jest-resolve",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-resolve-dependencies",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-runner",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-runtime",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-snapshot",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-util",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-validate",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-watcher",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "jest-worker",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "js-tokens",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "jsesc",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "json-parse-even-better-errors",
            "direct": false,
            "version": "2.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "json5",
            "direct": false,
            "version": "2.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "leven",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "lines-and-columns",
            "direct": false,
            "version": "1.2.4",
            "ecosystem": "npm"
          },
          {
            "name": "locate-path",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "10.4.3",
            "ecosystem": "npm"
          },
          {
            "name": "lru-cache",
            "direct": false,
            "version": "5.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "luxon",
            "direct": false,
            "version": "3.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "make-dir",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "makeerror",
            "direct": false,
            "version": "1.0.12",
            "ecosystem": "npm"
          },
          {
            "name": "math-intrinsics",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "media-typer",
            "direct": false,
            "version": "0.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "merge-descriptors",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "merge-stream",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "methods",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "mime",
            "direct": false,
            "version": "1.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "mime-db",
            "direct": false,
            "version": "1.52.0",
            "ecosystem": "npm"
          },
          {
            "name": "mime-types",
            "direct": false,
            "version": "2.1.35",
            "ecosystem": "npm"
          },
          {
            "name": "mimic-fn",
            "direct": false,
            "version": "2.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "mimic-response",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "3.1.5",
            "ecosystem": "npm"
          },
          {
            "name": "minimatch",
            "direct": false,
            "version": "9.0.9",
            "ecosystem": "npm"
          },
          {
            "name": "minimist",
            "direct": false,
            "version": "1.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "minipass",
            "direct": false,
            "version": "7.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "mkdirp-classic",
            "direct": false,
            "version": "0.5.3",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "ms",
            "direct": false,
            "version": "2.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "napi-build-utils",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "napi-postinstall",
            "direct": false,
            "version": "0.3.4",
            "ecosystem": "npm"
          },
          {
            "name": "natural-compare",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "negotiator",
            "direct": false,
            "version": "0.6.3",
            "ecosystem": "npm"
          },
          {
            "name": "node-abi",
            "direct": false,
            "version": "3.87.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-int64",
            "direct": false,
            "version": "0.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "node-releases",
            "direct": false,
            "version": "2.0.36",
            "ecosystem": "npm"
          },
          {
            "name": "normalize-path",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "npm-run-path",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "object-inspect",
            "direct": false,
            "version": "1.13.4",
            "ecosystem": "npm"
          },
          {
            "name": "on-finished",
            "direct": false,
            "version": "2.4.1",
            "ecosystem": "npm"
          },
          {
            "name": "once",
            "direct": false,
            "version": "1.4.0",
            "ecosystem": "npm"
          },
          {
            "name": "onetime",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "p-limit",
            "direct": false,
            "version": "2.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-limit",
            "direct": false,
            "version": "3.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-locate",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "p-try",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "package-json-from-dist",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "parse-json",
            "direct": false,
            "version": "5.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "parseurl",
            "direct": false,
            "version": "1.3.3",
            "ecosystem": "npm"
          },
          {
            "name": "path-exists",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "path-is-absolute",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-key",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-scurry",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "path-to-regexp",
            "direct": false,
            "version": "0.1.13",
            "ecosystem": "npm"
          },
          {
            "name": "picocolors",
            "direct": false,
            "version": "1.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "2.3.2",
            "ecosystem": "npm"
          },
          {
            "name": "picomatch",
            "direct": false,
            "version": "4.0.4",
            "ecosystem": "npm"
          },
          {
            "name": "pirates",
            "direct": false,
            "version": "4.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "pkg-dir",
            "direct": false,
            "version": "4.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "prebuild-install",
            "direct": false,
            "version": "7.1.3",
            "ecosystem": "npm"
          },
          {
            "name": "pretty-format",
            "direct": false,
            "version": "30.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "proxy-addr",
            "direct": false,
            "version": "2.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "pump",
            "direct": false,
            "version": "3.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "pure-rand",
            "direct": false,
            "version": "7.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "qs",
            "direct": false,
            "version": "6.15.2",
            "ecosystem": "npm"
          },
          {
            "name": "range-parser",
            "direct": false,
            "version": "1.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "raw-body",
            "direct": false,
            "version": "2.5.3",
            "ecosystem": "npm"
          },
          {
            "name": "rc",
            "direct": false,
            "version": "1.2.8",
            "ecosystem": "npm"
          },
          {
            "name": "react-is",
            "direct": false,
            "version": "18.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "readable-stream",
            "direct": false,
            "version": "3.6.2",
            "ecosystem": "npm"
          },
          {
            "name": "require-directory",
            "direct": false,
            "version": "2.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-cwd",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "resolve-from",
            "direct": false,
            "version": "5.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "safe-buffer",
            "direct": false,
            "version": "5.2.1",
            "ecosystem": "npm"
          },
          {
            "name": "safer-buffer",
            "direct": false,
            "version": "2.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "6.3.1",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.7.3",
            "ecosystem": "npm"
          },
          {
            "name": "semver",
            "direct": false,
            "version": "7.7.4",
            "ecosystem": "npm"
          },
          {
            "name": "send",
            "direct": false,
            "version": "0.19.2",
            "ecosystem": "npm"
          },
          {
            "name": "serve-static",
            "direct": false,
            "version": "1.16.3",
            "ecosystem": "npm"
          },
          {
            "name": "setprototypeof",
            "direct": false,
            "version": "1.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-command",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "shebang-regex",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-list",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-map",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "side-channel-weakmap",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "signal-exit",
            "direct": false,
            "version": "3.0.7",
            "ecosystem": "npm"
          },
          {
            "name": "signal-exit",
            "direct": false,
            "version": "4.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "simple-concat",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "simple-get",
            "direct": false,
            "version": "4.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "slash",
            "direct": false,
            "version": "3.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "source-map",
            "direct": false,
            "version": "0.6.1",
            "ecosystem": "npm"
          },
          {
            "name": "source-map-support",
            "direct": false,
            "version": "0.5.13",
            "ecosystem": "npm"
          },
          {
            "name": "sprintf-js",
            "direct": false,
            "version": "1.0.3",
            "ecosystem": "npm"
          },
          {
            "name": "stack-utils",
            "direct": false,
            "version": "2.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "statuses",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "streamsearch",
            "direct": false,
            "version": "1.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "string-length",
            "direct": false,
            "version": "4.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "4.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "string-width",
            "direct": false,
            "version": "5.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "string_decoder",
            "direct": false,
            "version": "1.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "6.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "strip-ansi",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-bom",
            "direct": false,
            "version": "4.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-final-newline",
            "direct": false,
            "version": "2.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "strip-json-comments",
            "direct": false,
            "version": "2.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "strip-json-comments",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "7.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "supports-color",
            "direct": false,
            "version": "8.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "synckit",
            "direct": false,
            "version": "0.11.12",
            "ecosystem": "npm"
          },
          {
            "name": "tar-fs",
            "direct": false,
            "version": "2.1.4",
            "ecosystem": "npm"
          },
          {
            "name": "tar-stream",
            "direct": false,
            "version": "2.2.0",
            "ecosystem": "npm"
          },
          {
            "name": "test-exclude",
            "direct": false,
            "version": "6.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "tmpl",
            "direct": false,
            "version": "1.0.5",
            "ecosystem": "npm"
          },
          {
            "name": "toidentifier",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "tslib",
            "direct": false,
            "version": "2.8.1",
            "ecosystem": "npm"
          },
          {
            "name": "tunnel-agent",
            "direct": false,
            "version": "0.6.0",
            "ecosystem": "npm"
          },
          {
            "name": "type-detect",
            "direct": false,
            "version": "4.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "type-fest",
            "direct": false,
            "version": "0.21.3",
            "ecosystem": "npm"
          },
          {
            "name": "type-is",
            "direct": false,
            "version": "1.6.18",
            "ecosystem": "npm"
          },
          {
            "name": "typedarray",
            "direct": false,
            "version": "0.0.6",
            "ecosystem": "npm"
          },
          {
            "name": "undici-types",
            "direct": false,
            "version": "7.18.2",
            "ecosystem": "npm"
          },
          {
            "name": "unpipe",
            "direct": false,
            "version": "1.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "unrs-resolver",
            "direct": false,
            "version": "1.11.1",
            "ecosystem": "npm"
          },
          {
            "name": "update-browserslist-db",
            "direct": false,
            "version": "1.2.3",
            "ecosystem": "npm"
          },
          {
            "name": "util-deprecate",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "utils-merge",
            "direct": false,
            "version": "1.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "v8-to-istanbul",
            "direct": false,
            "version": "9.3.0",
            "ecosystem": "npm"
          },
          {
            "name": "vary",
            "direct": false,
            "version": "1.1.2",
            "ecosystem": "npm"
          },
          {
            "name": "walker",
            "direct": false,
            "version": "1.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "which",
            "direct": false,
            "version": "2.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "7.0.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrap-ansi",
            "direct": false,
            "version": "8.1.0",
            "ecosystem": "npm"
          },
          {
            "name": "wrappy",
            "direct": false,
            "version": "1.0.2",
            "ecosystem": "npm"
          },
          {
            "name": "write-file-atomic",
            "direct": false,
            "version": "5.0.1",
            "ecosystem": "npm"
          },
          {
            "name": "y18n",
            "direct": false,
            "version": "5.0.8",
            "ecosystem": "npm"
          },
          {
            "name": "yallist",
            "direct": false,
            "version": "3.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "yargs",
            "direct": false,
            "version": "17.7.2",
            "ecosystem": "npm"
          },
          {
            "name": "yargs-parser",
            "direct": false,
            "version": "21.1.1",
            "ecosystem": "npm"
          },
          {
            "name": "yocto-queue",
            "direct": false,
            "version": "0.1.0",
            "ecosystem": "npm"
          }
        ],
        "collected": true,
        "truncated": false,
        "total_count": 413,
        "direct_count": 10,
        "indirect_count": 403
      }
    },
    "maintainership": {
      "issues": {
        "open_prs": 34,
        "merged_prs": 374,
        "open_issues": 103,
        "closed_ratio": 0.591,
        "closed_issues": 149,
        "closed_unmerged_prs": 41
      },
      "bus_factor": 1,
      "bot_contributors": 0,
      "top_contributors": [
        {
          "type": "User",
          "login": "voyax",
          "commits": 293,
          "avatar_url": "https://avatars.githubusercontent.com/u/13559404?v=4"
        },
        {
          "type": "User",
          "login": "zylos-luna",
          "commits": 163,
          "avatar_url": "https://avatars.githubusercontent.com/u/258754527?v=4"
        },
        {
          "type": "User",
          "login": "jinglever",
          "commits": 19,
          "avatar_url": "https://avatars.githubusercontent.com/u/267884994?v=4"
        },
        {
          "type": "User",
          "login": "zylos-luna-coco",
          "commits": 17,
          "avatar_url": "https://avatars.githubusercontent.com/u/300354114?v=4"
        },
        {
          "type": "User",
          "login": "zz-howard",
          "commits": 10,
          "avatar_url": "https://avatars.githubusercontent.com/u/4019224?v=4"
        },
        {
          "type": "User",
          "login": "leslielin2025",
          "commits": 9,
          "avatar_url": "https://avatars.githubusercontent.com/u/225646034?v=4"
        },
        {
          "type": "User",
          "login": "FelixLin6",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/68569236?v=4"
        },
        {
          "type": "User",
          "login": "kevinho",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/546824?v=4"
        },
        {
          "type": "User",
          "login": "eric-sss89",
          "commits": 5,
          "avatar_url": "https://avatars.githubusercontent.com/u/12973536?v=4"
        },
        {
          "type": "User",
          "login": "jessie-coco",
          "commits": 4,
          "avatar_url": "https://avatars.githubusercontent.com/u/259836333?v=4"
        }
      ],
      "contributors_sampled": 19,
      "top_contributor_share": 0.538
    },
    "quality_signals": {
      "has_ci": true,
      "has_tests": true,
      "ci_workflows": [
        "docker-publish.yml"
      ],
      "has_docs_dir": true,
      "linter_configs": [],
      "has_editorconfig": false,
      "has_linter_config": false,
      "has_precommit_config": false
    },
    "security_signals": {
      "lockfiles": [
        "package-lock.json"
      ],
      "scorecard": {
        "checks": [
          {
            "name": "Binary-Artifacts",
            "score": 10,
            "reason": "no binaries found in the repo",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#binary-artifacts"
          },
          {
            "name": "Branch-Protection",
            "score": 6,
            "reason": "branch protection is not maximal on development and all release branches",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#branch-protection"
          },
          {
            "name": "CI-Tests",
            "score": 0,
            "reason": "0 out of 30 merged PRs checked by a CI test -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#ci-tests"
          },
          {
            "name": "CII-Best-Practices",
            "score": 0,
            "reason": "no effort to earn an OpenSSF best practices badge detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#cii-best-practices"
          },
          {
            "name": "Code-Review",
            "score": 10,
            "reason": "all changesets reviewed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#code-review"
          },
          {
            "name": "Contributors",
            "score": 3,
            "reason": "project has 1 contributing companies or organizations -- score normalized to 3",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#contributors"
          },
          {
            "name": "Dangerous-Workflow",
            "score": 10,
            "reason": "no dangerous workflow patterns detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dangerous-workflow"
          },
          {
            "name": "Dependency-Update-Tool",
            "score": 0,
            "reason": "no update tool detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#dependency-update-tool"
          },
          {
            "name": "Fuzzing",
            "score": 0,
            "reason": "project is not fuzzed",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#fuzzing"
          },
          {
            "name": "License",
            "score": 10,
            "reason": "license file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#license"
          },
          {
            "name": "Maintained",
            "score": 10,
            "reason": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#maintained"
          },
          {
            "name": "Packaging",
            "score": 10,
            "reason": "packaging workflow detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#packaging"
          },
          {
            "name": "Pinned-Dependencies",
            "score": 0,
            "reason": "dependency not pinned by hash detected -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#pinned-dependencies"
          },
          {
            "name": "SAST",
            "score": 0,
            "reason": "SAST tool is not run on all commits -- score normalized to 0",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#sast"
          },
          {
            "name": "Security-Policy",
            "score": 10,
            "reason": "security policy file detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#security-policy"
          },
          {
            "name": "Signed-Releases",
            "score": null,
            "reason": "no releases found",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#signed-releases"
          },
          {
            "name": "Token-Permissions",
            "score": 9,
            "reason": "detected GitHub workflow tokens with excessive permissions",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#token-permissions"
          },
          {
            "name": "Vulnerabilities",
            "score": 3,
            "reason": "7 existing vulnerabilities detected",
            "documentation_url": "https://github.com/ossf/scorecard/blob/c395761df6afe1a69e476bc60a013a94bcbc153f/docs/checks.md#vulnerabilities"
          }
        ],
        "commit": "7a034ca2e55457bf114d4973b7df04ca207371eb",
        "ran_at": "2026-07-22T18:54:49Z",
        "aggregate_score": 6.1,
        "scorecard_version": "v5.5.0"
      },
      "has_codeql_workflow": false,
      "has_security_policy": false,
      "has_dependabot_config": false
    },
    "contribution_flow": {
      "collected": true,
      "ci_last_run_at": "2026-07-15T01:56:11Z",
      "oldest_open_prs": [
        {
          "number": 144,
          "created_at": "2026-02-23T05:38:53Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 146,
          "created_at": "2026-02-23T13:43:32Z",
          "last_comment_at": "2026-02-26T07:51:47Z",
          "last_comment_author": "zylos-luna"
        },
        {
          "number": 152,
          "created_at": "2026-02-25T10:41:03Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 277,
          "created_at": "2026-03-08T11:49:59Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 373,
          "created_at": "2026-03-20T23:07:42Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 389,
          "created_at": "2026-03-24T14:49:36Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 390,
          "created_at": "2026-03-25T06:02:28Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 420,
          "created_at": "2026-03-26T08:09:38Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 468,
          "created_at": "2026-04-01T08:11:39Z",
          "last_comment_at": "2026-04-01T19:20:24Z",
          "last_comment_author": "zylos-luna"
        },
        {
          "number": 501,
          "created_at": "2026-04-17T01:47:01Z",
          "last_comment_at": "2026-04-28T13:37:49Z",
          "last_comment_author": "leslielin2025"
        },
        {
          "number": 503,
          "created_at": "2026-04-19T05:14:48Z",
          "last_comment_at": "2026-04-19T15:45:18Z",
          "last_comment_author": "zylos-luna"
        },
        {
          "number": 505,
          "created_at": "2026-04-20T00:04:20Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 507,
          "created_at": "2026-04-20T10:45:47Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 509,
          "created_at": "2026-04-21T07:35:28Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 510,
          "created_at": "2026-04-21T13:38:34Z",
          "last_comment_at": "2026-04-27T18:07:10Z",
          "last_comment_author": "jinglever"
        },
        {
          "number": 513,
          "created_at": "2026-04-24T10:07:10Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 518,
          "created_at": "2026-04-28T13:37:38Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 530,
          "created_at": "2026-05-06T02:23:16Z",
          "last_comment_at": "2026-05-06T07:09:34Z",
          "last_comment_author": "zylos-luna"
        },
        {
          "number": 544,
          "created_at": "2026-05-06T14:33:41Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 566,
          "created_at": "2026-05-08T06:09:25Z",
          "last_comment_at": null,
          "last_comment_author": null
        }
      ],
      "last_merged_pr_at": "2026-07-15T01:55:00Z",
      "ci_last_conclusion": "SUCCESS",
      "oldest_open_issues": [
        {
          "number": 42,
          "created_at": "2026-02-07T15:56:28Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 139,
          "created_at": "2026-02-22T07:16:02Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 169,
          "created_at": "2026-02-26T15:00:50Z",
          "last_comment_at": "2026-03-19T18:15:02Z",
          "last_comment_author": "voyax"
        },
        {
          "number": 189,
          "created_at": "2026-02-28T02:43:38Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 223,
          "created_at": "2026-03-04T08:01:24Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 237,
          "created_at": "2026-03-05T03:53:26Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 243,
          "created_at": "2026-03-05T11:37:58Z",
          "last_comment_at": "2026-03-19T18:14:59Z",
          "last_comment_author": "voyax"
        },
        {
          "number": 245,
          "created_at": "2026-03-05T11:51:35Z",
          "last_comment_at": "2026-03-19T18:15:05Z",
          "last_comment_author": "voyax"
        },
        {
          "number": 246,
          "created_at": "2026-03-05T11:54:10Z",
          "last_comment_at": "2026-03-23T17:04:12Z",
          "last_comment_author": "m13v"
        },
        {
          "number": 250,
          "created_at": "2026-03-06T03:39:09Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 260,
          "created_at": "2026-03-06T16:08:27Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 262,
          "created_at": "2026-03-07T17:09:29Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 267,
          "created_at": "2026-03-08T09:12:40Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 268,
          "created_at": "2026-03-08T09:12:42Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 271,
          "created_at": "2026-03-08T09:12:49Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 272,
          "created_at": "2026-03-08T09:12:51Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 297,
          "created_at": "2026-03-10T15:48:51Z",
          "last_comment_at": "2026-03-19T18:15:01Z",
          "last_comment_author": "voyax"
        },
        {
          "number": 300,
          "created_at": "2026-03-11T03:34:28Z",
          "last_comment_at": "2026-03-11T03:35:49Z",
          "last_comment_author": "jessie-coco"
        },
        {
          "number": 305,
          "created_at": "2026-03-11T06:57:30Z",
          "last_comment_at": null,
          "last_comment_author": null
        },
        {
          "number": 320,
          "created_at": "2026-03-12T18:08:34Z",
          "last_comment_at": "2026-03-19T18:15:03Z",
          "last_comment_author": "voyax"
        }
      ]
    }
  },
  "config": {
    "disabled_metrics": [],
    "disabled_categories": [],
    "disabled_components": {}
  },
  "source": {
    "url": "https://github.com/zylos-ai/zylos-core",
    "host": "github.com",
    "name": "zylos-core",
    "owner": "zylos-ai"
  },
  "metrics": {
    "overall": {
      "key": "overall",
      "band": "moderate",
      "name": "Overall health",
      "note": null,
      "notes": [],
      "value": 68,
      "inputs": {
        "security": 62,
        "vitality": 89,
        "community": 70,
        "governance": 55,
        "engineering": 65
      },
      "components": []
    },
    "categories": [
      {
        "key": "vitality",
        "band": "excellent",
        "name": "Vitality",
        "value": 89,
        "weight": 0.22,
        "metrics": [
          {
            "key": "development_activity",
            "band": "good",
            "name": "Development activity",
            "note": null,
            "notes": [],
            "value": 81,
            "inputs": {
              "commits_last_year": 588,
              "human_commit_share": 1,
              "days_since_last_push": 2,
              "active_weeks_last_year": 24
            },
            "components": [
              {
                "key": "push_recency",
                "name": "Push recency",
                "detail": "last push 2 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "push_recency",
                    "params": {
                      "days": 2
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_cadence",
                "name": "Commit cadence",
                "detail": "24/52 weeks with commits",
                "points": 16.6,
                "status": "partial",
                "details": [
                  {
                    "code": "commit_cadence_weeks",
                    "params": {
                      "weeks": 24
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "commit_volume",
                "name": "Commit volume",
                "detail": "588 commits in the last year",
                "points": 18,
                "status": "met",
                "details": [
                  {
                    "code": "commits_last_year",
                    "params": {
                      "count": 588
                    }
                  }
                ],
                "max_points": 18
              },
              {
                "key": "openssf_scorecard_maintained",
                "name": "OpenSSF Scorecard: Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "release_discipline",
            "band": "excellent",
            "name": "Release discipline",
            "note": "Excluded from scoring (no data or not applicable): OpenSSF Scorecard: Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "openssf_scorecard_signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "releases_count": 50,
              "latest_release_tag": "v0.6.0",
              "releases_from_tags": false,
              "days_since_latest_release": 8,
              "mean_days_between_releases": 12
            },
            "components": [
              {
                "key": "ships_releases",
                "name": "Ships releases",
                "detail": "50 releases published",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "releases_published",
                    "params": {
                      "count": 50
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "release_recency",
                "name": "Release recency",
                "detail": "latest release 8 days ago",
                "points": 36,
                "status": "met",
                "details": [
                  {
                    "code": "release_recency",
                    "params": {
                      "days": 8
                    }
                  }
                ],
                "max_points": 36
              },
              {
                "key": "release_cadence",
                "name": "Release cadence",
                "detail": "a release every ~12 days",
                "points": 27,
                "status": "met",
                "details": [
                  {
                    "code": "release_cadence",
                    "params": {
                      "gap": 12
                    }
                  }
                ],
                "max_points": 27
              },
              {
                "key": "openssf_scorecard_signed_releases",
                "name": "OpenSSF Scorecard: Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 10
              }
            ]
          },
          {
            "key": "abandonment",
            "band": "excellent",
            "name": "Abandonment",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "cap": null,
              "state": "unverified",
              "guards": [],
              "signals": [],
              "red_flag": false,
              "multiplier_pct": 100,
              "declared_reason": null,
              "unverified_reason": "repository_too_young",
              "unanswered_open_prs": null,
              "unanswered_open_issues": null,
              "days_since_last_merged_pr": null,
              "days_since_last_human_commit": null,
              "days_since_last_human_commit_is_floor": false
            },
            "components": [
              {
                "key": "project_is_still_maintained",
                "name": "Project is still maintained",
                "detail": "maintenance record not established from the collected data",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "abandonment_unverified",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Is the project alive — is code being written and are releases shipping?"
      },
      {
        "key": "community",
        "band": "good",
        "name": "Community & Adoption",
        "value": 70,
        "weight": 0.18,
        "metrics": [
          {
            "key": "popularity",
            "band": "good",
            "name": "Popularity & adoption",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "forks": 119,
              "stars": 1136,
              "watchers": 66,
              "growth_state": "unverified",
              "growth_factor_pct": 100,
              "growth_unverified_reason": "no_history"
            },
            "components": [
              {
                "key": "stars",
                "name": "Stars",
                "detail": "1,136 stars",
                "points": 49.6,
                "status": "partial",
                "details": [
                  {
                    "code": "stars",
                    "params": {
                      "count": 1136
                    }
                  }
                ],
                "max_points": 60
              },
              {
                "key": "forks",
                "name": "Forks",
                "detail": "119 forks",
                "points": 17.3,
                "status": "partial",
                "details": [
                  {
                    "code": "forks",
                    "params": {
                      "count": 119
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "watchers",
                "name": "Watchers",
                "detail": "66 watchers",
                "points": 10.1,
                "status": "partial",
                "details": [
                  {
                    "code": "watchers",
                    "params": {
                      "count": 66
                    }
                  }
                ],
                "max_points": 15
              }
            ]
          },
          {
            "key": "community_health",
            "band": "excellent",
            "name": "Community health",
            "note": null,
            "notes": [],
            "value": 92,
            "inputs": {
              "has_readme": true,
              "has_license": true,
              "has_contributing": true,
              "has_issue_template": false,
              "has_code_of_conduct": true,
              "has_pull_request_template": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 22.5,
                "status": "met",
                "details": [],
                "max_points": 22.5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "recognized license (MIT)",
                "points": 22.5,
                "status": "met",
                "details": [
                  {
                    "code": "license_standard",
                    "params": {}
                  },
                  {
                    "code": "license_spdx",
                    "params": {
                      "spdx": "MIT"
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributing_guide",
                "name": "CONTRIBUTING guide",
                "detail": null,
                "points": 18,
                "status": "met",
                "details": [],
                "max_points": 18
              },
              {
                "key": "code_of_conduct",
                "name": "Code of conduct",
                "detail": null,
                "points": 13.5,
                "status": "met",
                "details": [],
                "max_points": 13.5
              },
              {
                "key": "issue_template",
                "name": "Issue template",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.2
              },
              {
                "key": "pr_template",
                "name": "PR template",
                "detail": null,
                "points": 6.3,
                "status": "met",
                "details": [],
                "max_points": 6.3
              }
            ]
          },
          {
            "key": "ecosystem_adoption",
            "band": "at_risk",
            "name": "Ecosystem adoption (downloads)",
            "note": "Excluded from scoring (no data or not applicable): Registry dependents. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "registry_dependents"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 30,
            "inputs": {
              "packages": [
                "web-console"
              ],
              "dependents": null,
              "ecosystems": "npm",
              "total_downloads": null,
              "monthly_downloads": 65
            },
            "components": [
              {
                "key": "monthly_downloads",
                "name": "Monthly downloads",
                "detail": "65 downloads/month across npm",
                "points": 24.3,
                "status": "partial",
                "details": [
                  {
                    "code": "downloads_monthly",
                    "params": {
                      "count": 65,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 80
              },
              {
                "key": "registry_dependents",
                "name": "Registry dependents",
                "detail": "not reported by this ecosystem",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "not_reported_by_this_ecosystem",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Does the project have users, downloads, attention, and a welcoming setup for contributors?"
      },
      {
        "key": "governance",
        "band": "moderate",
        "name": "Sustainability & Governance",
        "value": 55,
        "weight": 0.24,
        "metrics": [
          {
            "key": "maintainer_resilience",
            "band": "at_risk",
            "name": "Maintainer resilience (bus factor)",
            "note": null,
            "notes": [],
            "value": 36,
            "inputs": {
              "bus_factor": 1,
              "contributors_sampled": 19,
              "top_contributor_share": 0.538
            },
            "components": [
              {
                "key": "bus_factor",
                "name": "Bus factor",
                "detail": "1 contributor(s) cover half of all commits",
                "points": 9,
                "status": "partial",
                "details": [
                  {
                    "code": "bus_factor",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 54
              },
              {
                "key": "commit_distribution",
                "name": "Commit distribution",
                "detail": "top contributor authored 54% of commits",
                "points": 10.4,
                "status": "partial",
                "details": [
                  {
                    "code": "top_contributor_share",
                    "params": {
                      "share": 54
                    }
                  }
                ],
                "max_points": 22.5
              },
              {
                "key": "contributor_breadth",
                "name": "Contributor breadth",
                "detail": "19 contributors",
                "points": 13.5,
                "status": "met",
                "details": [
                  {
                    "code": "contributors_sampled",
                    "params": {
                      "count": 19
                    }
                  }
                ],
                "max_points": 13.5
              },
              {
                "key": "openssf_scorecard_contributors",
                "name": "OpenSSF Scorecard: Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 3,
                "status": "partial",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "responsiveness",
            "band": "good",
            "name": "Issue & PR responsiveness",
            "note": null,
            "notes": [],
            "value": 77,
            "inputs": {
              "merged_prs": 374,
              "open_issues": 103,
              "closed_issues": 149,
              "issue_closed_ratio": 0.591,
              "closed_unmerged_prs": 41
            },
            "components": [
              {
                "key": "issue_resolution",
                "name": "Issue resolution",
                "detail": "59% of issues closed",
                "points": 27.6,
                "status": "partial",
                "details": [
                  {
                    "code": "issues_closed_share",
                    "params": {
                      "share": 59
                    }
                  }
                ],
                "max_points": 46.75
              },
              {
                "key": "pr_acceptance",
                "name": "PR acceptance",
                "detail": "374/415 decided PRs merged",
                "points": 34.5,
                "status": "partial",
                "details": [
                  {
                    "code": "decided_prs_merged",
                    "params": {
                      "merged": 374,
                      "decided": 415
                    }
                  }
                ],
                "max_points": 38.25
              },
              {
                "key": "openssf_scorecard_code_review",
                "name": "OpenSSF Scorecard: Code-Review",
                "detail": "all changesets reviewed",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              }
            ]
          },
          {
            "key": "stewardship",
            "band": "moderate",
            "name": "Ownership & stewardship",
            "note": null,
            "notes": [],
            "value": 57,
            "inputs": {
              "followers": 115,
              "owner_type": "Organization",
              "is_verified": null,
              "owner_login": "zylos-ai",
              "public_repos": 36,
              "account_age_days": 191
            },
            "components": [
              {
                "key": "ownership_backing",
                "name": "Ownership backing",
                "detail": "organization-owned",
                "points": 30,
                "status": "met",
                "details": [
                  {
                    "code": "owner_organization",
                    "params": {}
                  }
                ],
                "max_points": 30
              },
              {
                "key": "verified_domain",
                "name": "Verified domain",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "owner_reach",
                "name": "Owner reach",
                "detail": "115 followers of zylos-ai",
                "points": 14.8,
                "status": "partial",
                "details": [
                  {
                    "code": "owner_followers",
                    "params": {
                      "count": 115,
                      "login": "zylos-ai"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "track_record",
                "name": "Track record",
                "detail": "36 public repos, account ~0 yr old",
                "points": 12.5,
                "status": "partial",
                "details": [
                  {
                    "code": "public_repos",
                    "params": {
                      "count": 36
                    }
                  },
                  {
                    "code": "account_age_years",
                    "params": {
                      "years": 0
                    }
                  }
                ],
                "max_points": 25
              }
            ]
          },
          {
            "key": "package_maintenance",
            "band": "moderate",
            "name": "Package maintenance",
            "note": null,
            "notes": [],
            "value": 53,
            "inputs": {
              "packages": [
                "web-console"
              ],
              "ecosystems": "npm",
              "any_deprecated": false,
              "min_days_since_publish": 3998
            },
            "components": [
              {
                "key": "published_resolvable",
                "name": "Published & resolvable",
                "detail": "1 package(s) on npm",
                "points": 25,
                "status": "met",
                "details": [
                  {
                    "code": "packages_published",
                    "params": {
                      "count": 1,
                      "ecosystems": "npm"
                    }
                  }
                ],
                "max_points": 25
              },
              {
                "key": "publish_recency",
                "name": "Publish recency",
                "detail": "latest publish 3998 days ago",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "publish_recency",
                    "params": {
                      "days": 3998
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "version_history",
                "name": "Version history",
                "detail": "1 published versions",
                "points": 4,
                "status": "partial",
                "details": [
                  {
                    "code": "published_versions",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 20
              },
              {
                "key": "not_deprecated",
                "name": "Not deprecated",
                "detail": "active, not deprecated or yanked",
                "points": 20,
                "status": "met",
                "details": [
                  {
                    "code": "package_not_deprecated",
                    "params": {}
                  }
                ],
                "max_points": 20
              }
            ]
          }
        ],
        "description": "Will the project survive its people — bus factor, responsiveness, who backs it, and package upkeep?"
      },
      {
        "key": "engineering",
        "band": "moderate",
        "name": "Engineering Quality",
        "value": 65,
        "weight": 0.2,
        "metrics": [
          {
            "key": "engineering_practices",
            "band": "at_risk",
            "name": "Engineering practices",
            "note": null,
            "notes": [],
            "value": 48,
            "inputs": {
              "has_ci": true,
              "has_tests": true,
              "has_editorconfig": false,
              "has_linter_config": false,
              "has_precommit_config": false
            },
            "components": [
              {
                "key": "ci_workflows",
                "name": "CI workflows",
                "detail": "1 workflow(s)",
                "points": 24,
                "status": "met",
                "details": [
                  {
                    "code": "ci_workflows",
                    "params": {
                      "count": 1
                    }
                  }
                ],
                "max_points": 24
              },
              {
                "key": "tests_present",
                "name": "Tests present",
                "detail": null,
                "points": 24,
                "status": "met",
                "details": [],
                "max_points": 24
              },
              {
                "key": "linter_config",
                "name": "Linter config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 16
              },
              {
                "key": "pre_commit_hooks",
                "name": "Pre-commit hooks",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 9.6
              },
              {
                "key": "editorconfig",
                "name": ".editorconfig",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 6.4
              },
              {
                "key": "openssf_scorecard_ci_tests",
                "name": "OpenSSF Scorecard: CI-Tests",
                "detail": "0 out of 30 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              }
            ]
          },
          {
            "key": "documentation",
            "band": "excellent",
            "name": "Documentation",
            "note": null,
            "notes": [],
            "value": 90,
            "inputs": {
              "topics": [
                "ai",
                "ai-worker",
                "own-your-data",
                "personal-ai-assistant",
                "self-evolving",
                "team-collaboration"
              ],
              "has_wiki": false,
              "homepage": "https://zylos.ai",
              "has_readme": true,
              "has_docs_dir": true,
              "has_description": true
            },
            "components": [
              {
                "key": "readme",
                "name": "README",
                "detail": null,
                "points": 30,
                "status": "met",
                "details": [],
                "max_points": 30
              },
              {
                "key": "documentation_directory",
                "name": "Documentation directory",
                "detail": null,
                "points": 25,
                "status": "met",
                "details": [],
                "max_points": 25
              },
              {
                "key": "documentation_homepage_site",
                "name": "Documentation / homepage site",
                "detail": "https://zylos.ai",
                "points": 15,
                "status": "met",
                "details": [],
                "max_points": 15
              },
              {
                "key": "repository_description",
                "name": "Repository description",
                "detail": null,
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "topics",
                "name": "Topics",
                "detail": "6 topics",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "topics_count",
                    "params": {
                      "count": 6
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "wiki",
                "name": "Wiki",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          }
        ],
        "description": "Are baseline engineering and documentation practices in place?"
      },
      {
        "key": "security",
        "band": "moderate",
        "name": "Security",
        "value": 62,
        "weight": 0.16,
        "metrics": [
          {
            "key": "security_posture",
            "band": "moderate",
            "name": "Security posture",
            "note": "Excluded from scoring (no data or not applicable): Signed-Releases. Remaining weights renormalized.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "signed_releases"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              }
            ],
            "value": 61,
            "inputs": {
              "source": "openssf_scorecard",
              "checks_evaluated": 17,
              "scorecard_version": "v5.5.0",
              "checks_inconclusive": 1,
              "scorecard_aggregate": 6.1
            },
            "components": [
              {
                "key": "binary_artifacts",
                "name": "Binary-Artifacts",
                "detail": "no binaries found in the repo",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "branch_protection",
                "name": "Branch-Protection",
                "detail": "branch protection is not maximal on development and all release branches",
                "points": 4.5,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "ci_tests",
                "name": "CI-Tests",
                "detail": "0 out of 30 merged PRs checked by a CI test -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "cii_best_practices",
                "name": "CII-Best-Practices",
                "detail": "no effort to earn an OpenSSF best practices badge detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "code_review",
                "name": "Code-Review",
                "detail": "all changesets reviewed",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "contributors",
                "name": "Contributors",
                "detail": "project has 1 contributing companies or organizations -- score normalized to 3",
                "points": 0.8,
                "status": "partial",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "dangerous_workflow",
                "name": "Dangerous-Workflow",
                "detail": "no dangerous workflow patterns detected",
                "points": 10,
                "status": "met",
                "details": [],
                "max_points": 10
              },
              {
                "key": "dependency_update_tool",
                "name": "Dependency-Update-Tool",
                "detail": "no update tool detected",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "fuzzing",
                "name": "Fuzzing",
                "detail": "project is not fuzzed",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "license",
                "name": "License",
                "detail": "license file detected",
                "points": 2.5,
                "status": "met",
                "details": [],
                "max_points": 2.5
              },
              {
                "key": "maintained",
                "name": "Maintained",
                "detail": "30 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10",
                "points": 7.5,
                "status": "met",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "packaging",
                "name": "Packaging",
                "detail": "packaging workflow detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "pinned_dependencies",
                "name": "Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "sast",
                "name": "SAST",
                "detail": "SAST tool is not run on all commits -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 5
              },
              {
                "key": "security_policy",
                "name": "Security-Policy",
                "detail": "security policy file detected",
                "points": 5,
                "status": "met",
                "details": [],
                "max_points": 5
              },
              {
                "key": "signed_releases",
                "name": "Signed-Releases",
                "detail": "no releases found",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "no_data",
                    "params": {}
                  }
                ],
                "max_points": 7.5
              },
              {
                "key": "token_permissions",
                "name": "Token-Permissions",
                "detail": "detected GitHub workflow tokens with excessive permissions",
                "points": 6.8,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              },
              {
                "key": "vulnerabilities",
                "name": "Vulnerabilities",
                "detail": "7 existing vulnerabilities detected",
                "points": 2.2,
                "status": "partial",
                "details": [],
                "max_points": 7.5
              }
            ]
          },
          {
            "key": "dependency_advisories",
            "band": "moderate",
            "name": "Dependency advisories",
            "note": "Excluded from scoring (no data or not applicable): Indirect dependencies free of known advisories. Remaining weights renormalized. Matched 413 resolved dependencies against OSV. This repository publishes no package the index resolves, so the repository dependency graph was assessed instead. That graph mixes development and test pins with shipped dependencies, so only the declared runtime dependencies are scored; transitive findings are reported as context and excluded from the score. Reachability is not analyzed.",
            "notes": [
              {
                "code": "excluded_no_data",
                "params": {
                  "components": [
                    "indirect_dependencies_free_of_known_advisories"
                  ]
                }
              },
              {
                "code": "weights_renormalized",
                "params": {}
              },
              {
                "code": "advisories_scope_repository",
                "params": {
                  "assessed": 413
                }
              },
              {
                "code": "advisories_repo_graph_caveat",
                "params": {}
              },
              {
                "code": "advisories_reachability",
                "params": {}
              }
            ],
            "value": 67,
            "inputs": {
              "source": "osv",
              "advisories": 10,
              "affected_packages": 7,
              "assessed_packages": 413,
              "unassessed_packages": 0,
              "affected_by_severity": "high 5, low 2",
              "direct_affected_packages": 3
            },
            "components": [
              {
                "key": "direct_dependencies_free_of_known_advisories",
                "name": "Direct dependencies free of known advisories",
                "detail": "3 affected: js-yaml 3.14.2 (high 7.5), js-yaml 4.1.1 (high 7.5), multer 2.1.1 (high 7.5)",
                "points": 10.2,
                "status": "partial",
                "details": [
                  {
                    "code": "advisories_affected",
                    "params": {
                      "count": 3,
                      "packages": "js-yaml 3.14.2 (high 7.5), js-yaml 4.1.1 (high 7.5), multer 2.1.1 (high 7.5)"
                    }
                  }
                ],
                "max_points": 35
              },
              {
                "key": "indirect_dependencies_free_of_known_advisories",
                "name": "Indirect dependencies free of known advisories",
                "detail": "transitive set not separable from development and test dependencies in this scope",
                "points": 0,
                "status": "excluded",
                "details": [
                  {
                    "code": "advisories_scope_not_separable",
                    "params": {}
                  }
                ],
                "max_points": 25
              },
              {
                "key": "no_advisories_left_outstanding",
                "name": "No advisories left outstanding",
                "detail": "no advisory has been public longer than 90 days",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "advisories_none_stale",
                    "params": {
                      "days": 90
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "malicious_dependencies",
            "band": "excellent",
            "name": "Malicious dependencies",
            "note": null,
            "notes": [],
            "value": 100,
            "inputs": {
              "source": "osv",
              "meaning": "reported as a malicious package by the OpenSSF corpus; the remedy is removal or moving off the compromised name, never an upgrade of the same artifact. Versions the registry has since pulled are listed but not scored",
              "packages": [],
              "red_flag": false,
              "assessed_packages": 413,
              "malicious_packages": 0,
              "direct_malicious_packages": 0,
              "withdrawn_malicious_packages": 0,
              "installable_malicious_packages": 0
            },
            "components": [
              {
                "key": "no_dependency_reported_as_a_malicious_package",
                "name": "No dependency reported as a malicious package",
                "detail": "no dependency is reported as a malicious package",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "no_malicious_dependencies",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          },
          {
            "key": "high_risk_jurisdiction_exposure",
            "band": "excellent",
            "name": "High-Risk Jurisdiction Exposure",
            "note": "Only high-confidence self-published location evidence affects this multiplier. Ambiguous matches are review-only; country evidence is not proof of nationality, citizenship, legal registration, malicious intent, or sanctions status.",
            "notes": [
              {
                "code": "jurisdiction_evidence_limits",
                "params": {}
              }
            ],
            "value": 100,
            "inputs": {
              "meaning": "self-published location evidence; not nationality or citizenship",
              "red_flag": false,
              "exposures": [],
              "policy_countries": [
                "Russia",
                "Iran",
                "North Korea"
              ],
              "review_only_matches": 0,
              "assessed_self_published_locations": 3
            },
            "components": [
              {
                "key": "policy_exposure_multiplier",
                "name": "Policy exposure multiplier",
                "detail": "no confirmed policy-scope location match",
                "points": 100,
                "status": "met",
                "details": [
                  {
                    "code": "jurisdiction_no_match",
                    "params": {}
                  }
                ],
                "max_points": 100
              }
            ]
          }
        ],
        "description": "Are visible security and supply-chain practices strong, with no malicious dependency and no unresolved high-risk jurisdiction exposure?"
      },
      {
        "key": "ai_readiness",
        "band": "moderate",
        "name": "AI Readiness",
        "value": 56,
        "weight": 0,
        "metrics": [
          {
            "key": "ai_agent_context",
            "band": "excellent",
            "name": "Agent context & guidance",
            "note": null,
            "notes": [],
            "value": 85,
            "inputs": {
              "has_llms_txt": false,
              "legible_history_share": 0.99,
              "agent_instruction_files": [
                "CLAUDE.md"
              ],
              "agent_instruction_max_bytes": 6158
            },
            "components": [
              {
                "key": "agent_instructions",
                "name": "Agent instructions",
                "detail": "CLAUDE.md",
                "points": 45,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "CLAUDE.md"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "machine_readable_docs_llms_txt",
                "name": "Machine-readable docs (llms.txt)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 15
              },
              {
                "key": "legible_commit_history",
                "name": "Legible commit history",
                "detail": "99 of 100 human commits state their intent (structured subject or explanatory body)",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "legible_history",
                    "params": {
                      "legible": 99,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          },
          {
            "key": "ai_verify_loop",
            "band": "at_risk",
            "name": "Verify loop (build / test / typecheck)",
            "note": null,
            "notes": [],
            "value": 42,
            "inputs": {
              "has_nix": false,
              "has_tests": true,
              "lockfiles": [
                "package-lock.json"
              ],
              "has_dockerfile": true,
              "typed_language": false,
              "bootstrap_files": [],
              "has_devcontainer": false,
              "has_linter_config": false,
              "typecheck_configs": [],
              "agent_commit_share": 0.62,
              "toolchain_manifests": [],
              "dependency_bot_commit_share": 0
            },
            "components": [
              {
                "key": "one_command_bootstrap",
                "name": "One-command bootstrap",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 18
              },
              {
                "key": "automated_tests",
                "name": "Automated tests",
                "detail": null,
                "points": 22,
                "status": "met",
                "details": [],
                "max_points": 22
              },
              {
                "key": "lint_format_config",
                "name": "Lint / format config",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "static_type_checking",
                "name": "Static type checking",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 11
              },
              {
                "key": "reproducible_environment",
                "name": "Reproducible environment",
                "detail": "Dockerfile, lockfile",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "Dockerfile, lockfile"
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "demonstrated_agent_practice",
                "name": "Demonstrated agent practice",
                "detail": "62 of the last 100 commits agent-authored or agent-credited",
                "points": 10,
                "status": "met",
                "details": [
                  {
                    "code": "agent_authored_commits",
                    "params": {
                      "count": 62,
                      "sampled": 100
                    }
                  }
                ],
                "max_points": 10
              },
              {
                "key": "automated_maintenance",
                "name": "Automated maintenance",
                "detail": "no automated dependency updates observed",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_dependency_automation",
                    "params": {}
                  }
                ],
                "max_points": 8
              },
              {
                "key": "openssf_scorecard_pinned_dependencies",
                "name": "OpenSSF Scorecard: Pinned-Dependencies",
                "detail": "dependency not pinned by hash detected -- score normalized to 0",
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 10
              }
            ]
          },
          {
            "key": "ai_code_legibility",
            "band": "moderate",
            "name": "Code legibility for models",
            "note": null,
            "notes": [],
            "value": 54,
            "inputs": {
              "primary_language": "JavaScript",
              "largest_source_bytes": 124245,
              "source_files_sampled": 229,
              "oversized_source_files": 4
            },
            "components": [
              {
                "key": "type_checkable_code",
                "name": "Type-checkable code",
                "detail": "JavaScript without a type-check config",
                "points": 0,
                "status": "missed",
                "details": [
                  {
                    "code": "no_typecheck_config_language",
                    "params": {
                      "language": "JavaScript"
                    }
                  }
                ],
                "max_points": 45
              },
              {
                "key": "manageable_file_sizes",
                "name": "Manageable file sizes",
                "detail": "4/229 source files over 60KB",
                "points": 54,
                "status": "partial",
                "details": [
                  {
                    "code": "oversized_source_files",
                    "params": {
                      "kb": 60,
                      "sampled": 229,
                      "oversized": 4
                    }
                  }
                ],
                "max_points": 55
              }
            ]
          },
          {
            "key": "ai_interfaces",
            "band": "at_risk",
            "name": "Machine-readable interfaces",
            "note": null,
            "notes": [],
            "value": 40,
            "inputs": {
              "example_dirs": [
                "examples"
              ],
              "has_mcp_signal": false,
              "api_schema_files": []
            },
            "components": [
              {
                "key": "api_schema_openapi_graphql_proto",
                "name": "API schema (OpenAPI/GraphQL/proto)",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 40
              },
              {
                "key": "mcp_server",
                "name": "MCP server",
                "detail": null,
                "points": 0,
                "status": "missed",
                "details": [],
                "max_points": 20
              },
              {
                "key": "runnable_examples",
                "name": "Runnable examples",
                "detail": "examples",
                "points": 40,
                "status": "met",
                "details": [
                  {
                    "code": "file_list",
                    "params": {
                      "files": "examples"
                    }
                  }
                ],
                "max_points": 40
              }
            ]
          }
        ],
        "description": "How well is the repo equipped to be developed and maintained with AI coding agents? An independent, experimental badge — weight 0.0, so it is surfaced on its own and does not affect the overall health score."
      }
    ],
    "metrics_version": "1.13.0"
  },
  "warnings": [
    "Star history unavailable: GitHub GraphQL error: Resource not accessible by personal access token",
    "Could not fetch npm package 'zylos' from its registry",
    "Could not fetch npm package 'zylos-scheduler-v2' from its registry",
    "Could not fetch npm package 'comm-bridge' from its registry",
    "Could not fetch npm package 'zylos-memory' from its registry"
  ],
  "report_type": "repository",
  "generated_at": "2026-07-22T18:55:14.976430Z",
  "schema_version": "0.26.0",
  "badge_url": "https://raw.githubusercontent.com/inspect-software/badges/main/v1/z/zylos-ai/zylos-core.svg",
  "full_name": "zylos-ai/zylos-core",
  "license_state": "standard",
  "license_spdx": "MIT"
}

评分是信号,而非担保。 评分反映的是 GitHub 上公开可见的实践——不是代码审计,也不是安全保证。

缺失数据将被剔除并重新归一化权重,绝不按零分计。方法论已版本化并公开:指标 v1.13.0、模式 v0.26.0—— 完整方法论 · 指标知识库.

单项结果在整体记录中的位置: 汇总统计npm.