1. ee5dd9c test(preflight-audit): replay-mode eval fixture exercises every classifier rule (#423) by Jarek Potiuk · 12 hours ago main
  2. 7027f95 feat(github-rollup): append helper for status-rollup comments — read/PATCH out of context (#424) by Jarek Potiuk · 12 hours ago
  3. 280d595 docs: lychee is already a hard gate — strip stale 'informational' wording (#425) by Jarek Potiuk · 12 hours ago
  4. ed62bc8 Remove dead placeholder allowlist marker (#420) by anhtnt90dev · 12 hours ago
  5. d7802a9 docs: add template setup order (#422) by anhtnt90dev · 13 hours ago
  6. b0c4d47 Fix failed hook summary extraction (#421) by anhtnt90dev · 13 hours ago
  7. cf5c417 Add --list-categories flag to validator (#405) by Nishita Matlani · 14 hours ago
  8. 46bee34 refactor: uv workspace — DRY pre-commit + CI matrix from single SoT (#419) by Jarek Potiuk · 15 hours ago
  9. 67a2d53 feat(preflight-audit): CLI to dry-run the bulk-mode classifier against real or replayed tracker state (#418) by Jarek Potiuk · 16 hours ago
  10. 1383ee2 feat(permission-audit): tools/permission-audit/ — atomic audit + edit of permissions.allow[] (#417) by Jarek Potiuk · 17 hours ago
  11. 7b41597 added --list-tags to print case tags with counts (#404) by Vandit Gupta · 17 hours ago
  12. e2b58f1 feat(security-issue-sync): tune pre-flight classifier — skill-marker detection + relaxed rules (#416) by Jarek Potiuk · 18 hours ago
  13. a316f73 feat(tools/skill-evals): add --fail-fast flag to stop on first failure (#408) by Aayush Rajput · 18 hours ago
  14. bb23c55 feat(setup-steward): verify check 8d — propose permission allow-list audit on adopt + upgrade (#415) by Jarek Potiuk · 18 hours ago
  15. 09f4288 feat(security-issue-sync): pre-flight no-op classifier skips obvious-idle trackers in bulk mode (#414) by Jarek Potiuk · 19 hours ago
  16. 3099d25 feat(setup-steward): verify check 8c — stale agent-worktrees under .claude/worktrees/ (#413) by Jarek Potiuk · 19 hours ago
  17. 9c07ea6 feat(github-body-field): tool to rewrite one issue-body field without loading the body into agent context (#412) by Jarek Potiuk · 19 hours ago
  18. 895477f docs(agents): require lychee local-run on every PR — added to Before submitting (#411) by Jarek Potiuk · 20 hours ago
  19. 5e68f26 refactor(security-issue-sync): extract 4 subdocs to slim SKILL.md 3425 → 658 lines (#410) by Jarek Potiuk · 20 hours ago
  20. 8ba93cc docs(gmail): default get_thread to MINIMAL; escalate to FULL_CONTENT only on body-parse (#409) by Jarek Potiuk · 20 hours ago
  21. 21cb9ed add good first issue skill (#353) by Justin Mclean · 34 hours ago
  22. 30a2b36 feat(security-cve-allocate): extend title-strip cascade with two patterns from session manual cleanups (#402) by Jarek Potiuk · 35 hours ago
  23. fdcc68a feat(security-issue-sync): conservative affected-versions range when uncertain (#401) by Jarek Potiuk · 35 hours ago
  24. 570cf05 chore(dependabot): collapse 9 uv entries into 1 group (#400) by Jarek Potiuk · 35 hours ago
  25. e8081e8 chore(deps-dev): bump ruff (#389) by dependabot[bot] · 35 hours ago
  26. 406485a chore(deps-dev): bump ruff (#390) by dependabot[bot] · 35 hours ago
  27. 1b47a7b chore(deps): bump https://github.com/crate-ci/typos (#391) by dependabot[bot] · 35 hours ago
  28. 855211e chore(deps-dev): bump ruff (#392) by dependabot[bot] · 35 hours ago
  29. 11097b8 chore(deps-dev): bump ruff (#393) by dependabot[bot] · 35 hours ago
  30. 98556bd chore(deps-dev): bump ruff (#394) by dependabot[bot] · 35 hours ago
  31. 729894d chore(deps-dev): bump ruff (#395) by dependabot[bot] · 35 hours ago
  32. bcc12dc chore(deps-dev): bump ruff (#396) by dependabot[bot] · 35 hours ago
  33. 31cbe2a chore(deps-dev): bump ruff (#397) by dependabot[bot] · 35 hours ago
  34. 0fe125a chore(deps): bump github/codeql-action in the github-actions group (#398) by dependabot[bot] · 35 hours ago
  35. 1b66d15 feat(security): docs lift + final scrub (PR5/5) (#399) by Jarek Potiuk · 35 hours ago
  36. 6c16c56 feat(security): CVE-authority sub-tool extract (PR4/5) (#388) by Jarek Potiuk · 36 hours ago
  37. 284dd81 feat(security): forwarder-relay + mail-archive sub-tools (PR3/5) (#387) by Jarek Potiuk · 2 days ago
  38. ec49a34 feat(security): config-driven lifts of 6 skills (PR2/5) (#386) by Jarek Potiuk · 2 days ago
  39. 70a95c5 feat(security): config schema + adapter contracts (PR1/5) (#381) by Jarek Potiuk · 2 days ago
  40. 8c3591b feat(vulnogram-api/record-update): refuse PUBLIC pushes without vendor-advisory ref (#385) by Jarek Potiuk · 2 days ago
  41. 5a2cd96 feat(generate-cve-json): emit related references for sibling CVEs (#384) by Jarek Potiuk · 2 days ago
  42. bc5b8cd feat(security-issue-sync): supersede per-CVE walk with merged bulk-proposal review (#383) by Jarek Potiuk · 2 days ago
  43. 6e73a17 docs(rm-handoff): use 'REVIEW button on Editor tab' instead of 'State dropdown on #source' (#382) by Jarek Potiuk · 2 days ago
  44. cb13312 docs(mission): sync founding-member roster with board resolution draft (#380) by Jarek Potiuk · 2 days ago
  45. e0ade0a feat(security-issue-invalidate): notification audit-trail + GHSA-write-access split (#379) by Jarek Potiuk · 2 days ago
  46. 68d76b2 feat(release-management): propose family with 14-step lifecycle and non-ASF backend abstraction (#163) by André Ahlert · 2 days ago
  47. 07fd83d feat(pr-management-stats): add deterministic HTML dashboard renderer (#348) by Yeonguk Choo · 2 days ago
  48. 7bb9035 feat(gmail/asf-relay): clickable external-ref URL + paste-ready reporter block (#375) by Jarek Potiuk · 2 days ago
  49. 0931bd8 skill-evals: field-aware grading, intersection key matching, wrap non-JSON output (#370) by Justin Mclean · 2 days ago
  50. 976620f feat(security-issue-sync): per-CVE-change pause + 6th anonymise hygiene gate (#374) by Jarek Potiuk · 2 days ago
  51. 59ece79 fix(generate-cve-json): forward-state labels keep CNA_private.state at REVIEW (#373) by Jarek Potiuk · 3 days ago
  52. 1d921a0 feat(security-issue-sync): five pre-push hygiene gates for CVE-record quality (#372) by Jarek Potiuk · 3 days ago
  53. fad7b0c fix(pr-management-triage): guard Sweep 4 against freshly-promoted PRs (#368) by Jarek Potiuk · 3 days ago
  54. e3ac5d2 feat(security-issue-sync): auto-propose backtick-wrap for Affected versions field (#367) by Jarek Potiuk · 3 days ago
  55. 3e4c7b8 fix(vulnogram/oauth-api): treat first-time affected[] population as non-change in merge-mode guard (#366) by Jarek Potiuk · 3 days ago
  56. 55568bf feat(tools/jira): add write subcommands (comment, transition, label, assign, field, attach) (#345) by Andrea Cosentino · 3 days ago
  57. d65cd69 chore(settings): allowlist read-only Gmail / Ponymail MCP + zizmor (#365) by Jarek Potiuk · 3 days ago
  58. 33eba34 docs(skills,agents): require clickable PR/<tracker> refs on every surface (#364) by Jarek Potiuk · 3 days ago
  59. 453fe32 feat(vulnogram-oauth-api): merge-mode safety nets in record-update (#363) by Jarek Potiuk · 3 days ago
  60. 845b252 fix(generate-cve-json): sanitize CWE wrapper + fail loud on unparsable versions (#362) by Jarek Potiuk · 3 days ago
  61. 680f141 feat(generate-cve-json): gate DRAFT → REVIEW on active release vote (#360) by Jarek Potiuk · 4 days ago
  62. 6cd9fcf feat(security-issue-sync): detect active RC-vote threads and propose `rc voting` label (#361) by Jarek Potiuk · 4 days ago
  63. 4e4c5d8 fix(skills): add --limit to gh list calls flagged by validator (#359) by eeeclipse · 4 days ago
  64. 2ed68dc add note to claim issue first (#356) by Justin Mclean · 4 days ago
  65. b62a159 fix: update stale skill-validator references to skill-and-tool-validator (#352) by Md Mushfiqur Rahim · 4 days ago
  66. c4ff7fd docs(gmail,security): verify draft persistence before claiming "still pending" (#355) by Jarek Potiuk · 4 days ago
  67. 8e474a7 feat(meta): add spec-validator tool (#336) by Justin Mclean · 4 days ago
  68. fcd6a15 chore(deps-dev): bump prek in the framework-deps group (#342) by dependabot[bot] · 4 days ago
  69. 249d342 default plan, update and consolidate to 1 pass (#328) by Justin Mclean · 4 days ago
  70. 8e0b526 update specs and implementation plan (#329) by Justin Mclean · 4 days ago
  71. d90cbb2 feat(evals): add eval suite for setup-isolated-setup-update skill (#330) by Justin Mclean · 4 days ago
  72. 261adb4 feat(evals): add eval suite for setup-shared-config-sync skill (#331) by Justin Mclean · 4 days ago
  73. 88e6d3c feat(evals): add eval suite for setup-isolated-setup-doctor skill (#332) by Justin Mclean · 4 days ago
  74. 52c308e feat(evals): add eval suite for setup-isolated-setup-install skill (#333) by Justin Mclean · 4 days ago
  75. 248becb feat(evals): add eval suite for setup-override-upstream skill (#334) by Justin Mclean · 4 days ago
  76. dae116f feat(evals): add eval suite for setup-steward skill (#335) by Justin Mclean · 4 days ago
  77. 5c211a4 feat(security-issue-triage): fetch-all-upfront pattern (PR #346 analogue) (#347) by Jarek Potiuk · 4 days ago
  78. 164c2e0 feat(pr-management-triage): fetch all PRs upfront, classify in batch (#346) by Jarek Potiuk · 4 days ago
  79. 52f65e1 fix(pr-management-triage): four classifier heuristic fixes from a live session (#344) by Jarek Potiuk · 4 days ago
  80. ceeeb0b feat(pr-management-triage): add session-history gist persistence (Step 6b) (#343) by Jarek Potiuk · 4 days ago
  81. 24ddd89 feat(labels): capability taxonomy + validator enforcement + sync check (#340) by Jarek Potiuk · 4 days ago
  82. 6d37cc6 chore(ci): require pytest via tests-ok umbrella job (#341) by Jarek Potiuk · 4 days ago
  83. b333922 feat(agent-isolation): add Python packaging and pytest test harness (#339) by Justin Mclean · 5 days ago
  84. d634318 add support for llama and what tests it can run (#338) by Justin Mclean · 5 days ago
  85. 5c6bd32 Add spec-driven build loop and product specs (#250) by Justin Mclean · 5 days ago
  86. 1ced54f feat(spec-loop): freshness check + branch-name collision check (#297) by Justin Mclean · 5 days ago
  87. d294802 docs(mode-economics): fix internal inconsistency and amortisation basis (#326) by André Ahlert · 5 days ago
  88. 19d08b4 feat(pairing-self-review): add pre-flight self-review skill and eval suite (#251) by Justin Mclean · 5 days ago
  89. 13c9f6d feat(spec-status-index): add deterministic spec-status index tool (#254) by Justin Mclean · 5 days ago
  90. 4e1e203 feat(mentoring): advance Mentoring mode to experimental and add intervention-selection eval suite (#272) by Justin Mclean · 5 days ago
  91. e67678e feat(evals): add eval suite for setup-isolated-setup-verify skill (#298) by Justin Mclean · 5 days ago
  92. 2e3bab8 feat(evals): add eval suite for security-tracker-stats-dashboard skill (#299) by Justin Mclean · 5 days ago
  93. b1f2305 Update `security-issue-fix` skill to check for existing PR (#325) by Vincent · 5 days ago
  94. 1218969 feat(github): add issue and PR templates aligned with CONTRIBUTING.md (#324) by Jarek Potiuk · 5 days ago
  95. ddba3c6 docs(contributing): rewrite for framework-as-a-whole audience (#323) by Jarek Potiuk · 6 days ago
  96. f20efcd docs(setup): document sync.sh extensions for memory and PATH (#300) by Jarek Potiuk · 6 days ago
  97. 5aa3d7c feat(skills): security-issue-sync — propose courtesy reply to CVE reviewer when addressing a record comment (#295) by Jarek Potiuk · 6 days ago
  98. fed8ef7 chore(agent-isolation): bump claude-code pin 2.1.141 → 2.1.150 (#294) by Jarek Potiuk · 6 days ago
  99. 339d3eb feat(hooks): sandbox-error-hint.sh — annotate sandbox-shaped error output with catalog references (#293) by Jarek Potiuk · 6 days ago
  100. 268e41d feat(skill): setup-isolated-setup-doctor — probe sandbox friction in-session (#292) by Jarek Potiuk · 6 days ago