{
  "benchmark_version": "2026-04",
  "generated_at": "2026-04-11T09:00:00Z",
  "repo_count": 20,
  "methodology": {
    "scanner": "ticketyboo-scanner v1",
    "scan_type": "deep",
    "devcontract": "DC-v1-default",
    "clauses": ["DC-S01", "DC-A01", "DC-A02", "DC-G01", "DC-G02", "DC-G03"],
    "clause_descriptions": {
      "DC-S01": "No hardcoded secrets or credentials",
      "DC-A01": "No enableAllProjectMcpServers=true in agent configs",
      "DC-A02": "No blanket alwaysAllow tool grants",
      "DC-G01": "README present and non-trivial",
      "DC-G02": "CI/CD pipeline configured",
      "DC-G03": "Test suite present"
    }
  },
  "repos": [
    {
      "repo": "anthropic/anthropic-cookbook",
      "repo_url": "https://github.com/anthropic/anthropic-cookbook",
      "stars": "~9k",
      "category": "ai-examples",
      "scanned_at": "2026-04-11T08:01:00Z",
      "scan_id": "scn_bench_001",
      "status": "complete",
      "health_score": 61,
      "findings_count": 18,
      "critical_count": 0,
      "high_count": 3,
      "medium_count": 8,
      "low_count": 7,
      "overall_verdict": "contract_breach",
      "breach_severity": "medium",
      "clauses_passing": ["DC-G01", "DC-G02"],
      "clauses_failing": ["DC-S01", "DC-A01", "DC-A02", "DC-G03"],
      "has_agent_configs": true,
      "layers_run": ["dependency", "secret", "sast", "iac", "license", "quality", "agent_security"],
      "top_finding": "Example notebooks contain hardcoded API key patterns (DC-S01); .claude/ directory present with permissive tool grants (DC-A02)",
      "report_url": "https://ticketyboo.dev/r/?id=scn_bench_001",
      "receipt_url": "https://ticketyboo.dev/api/receipt/scn_bench_001",
      "receipt_hash": "sha256:3f4a9b2e1c8d5f7a0e3c6b9d2f5a8c1e4b7d0a3f6c9b2e5a8d1f4c7a0b3e6d9",
      "receipt_verified": true
    },
    {
      "repo": "paul-gauthier/aider",
      "repo_url": "https://github.com/paul-gauthier/aider",
      "stars": "~22k",
      "category": "ai-coding",
      "scanned_at": "2026-04-11T08:03:00Z",
      "scan_id": "scn_bench_002",
      "status": "complete",
      "health_score": 82,
      "findings_count": 9,
      "critical_count": 0,
      "high_count": 1,
      "medium_count": 4,
      "low_count": 4,
      "overall_verdict": "compliant",
      "breach_severity": null,
      "clauses_passing": ["DC-S01", "DC-G01", "DC-G02", "DC-G03"],
      "clauses_failing": ["DC-A01", "DC-A02"],
      "has_agent_configs": false,
      "layers_run": ["dependency", "secret", "sast", "iac", "license", "quality", "agent_security"],
      "top_finding": "No agent config files detected; strong test coverage (1,200+ tests); CI pipeline comprehensive",
      "report_url": "https://ticketyboo.dev/r/?id=scn_bench_002",
      "receipt_url": "https://ticketyboo.dev/api/receipt/scn_bench_002",
      "receipt_hash": "sha256:8c1e4b7d0a3f6c9b2e5a8d1f4c7a0b3e6d9f2c5a8e1b4d7a0c3f6b9e2d5a8c1",
      "receipt_verified": true
    },
    {
      "repo": "cline/cline",
      "repo_url": "https://github.com/cline/cline",
      "stars": "~34k",
      "category": "ai-coding",
      "scanned_at": "2026-04-11T08:05:00Z",
      "scan_id": "scn_bench_003",
      "status": "complete",
      "health_score": 74,
      "findings_count": 14,
      "critical_count": 0,
      "high_count": 2,
      "medium_count": 6,
      "low_count": 6,
      "overall_verdict": "contract_breach",
      "breach_severity": "medium",
      "clauses_passing": ["DC-S01", "DC-G01", "DC-G02", "DC-G03"],
      "clauses_failing": ["DC-A01", "DC-A02"],
      "has_agent_configs": true,
      "layers_run": ["dependency", "secret", "sast", "iac", "license", "quality", "agent_security"],
      "top_finding": ".clinerules found in test fixtures with enableAllProjectMcpServers=true pattern (DC-A01); alwaysAllow non-empty in bundled example configs (DC-A02)",
      "report_url": "https://ticketyboo.dev/r/?id=scn_bench_003",
      "receipt_url": "https://ticketyboo.dev/api/receipt/scn_bench_003",
      "receipt_hash": "sha256:d0a3f6c9b2e5a8d1f4c7a0b3e6d9f2c5a8e1b4d7a0c3f6b9e2d5a8c1e4b7d0a",
      "receipt_verified": true
    },
    {
      "repo": "All-Hands-AI/OpenHands",
      "repo_url": "https://github.com/All-Hands-AI/OpenHands",
      "stars": "~45k",
      "category": "ai-coding",
      "scanned_at": "2026-04-11T08:07:00Z",
      "scan_id": "scn_bench_004",
      "status": "complete",
      "health_score": 78,
      "findings_count": 12,
      "critical_count": 0,
      "high_count": 2,
      "medium_count": 5,
      "low_count": 5,
      "overall_verdict": "compliant",
      "breach_severity": null,
      "clauses_passing": ["DC-S01", "DC-G01", "DC-G02", "DC-G03"],
      "clauses_failing": ["DC-A01", "DC-A02"],
      "has_agent_configs": true,
      "layers_run": ["dependency", "secret", "sast", "iac", "license", "quality", "agent_security"],
      "top_finding": "Agent workspace configs present — expected for an agentic coding platform; hardened CI pipeline with multiple test workflows",
      "report_url": "https://ticketyboo.dev/r/?id=scn_bench_004",
      "receipt_url": "https://ticketyboo.dev/api/receipt/scn_bench_004",
      "receipt_hash": "sha256:f4c7a0b3e6d9f2c5a8e1b4d7a0c3f6b9e2d5a8c1e4b7d0a3f6c9b2e5a8d1f4c",
      "receipt_verified": true
    },
    {
      "repo": "jlowin/fastmcp",
      "repo_url": "https://github.com/jlowin/fastmcp",
      "stars": "~5k",
      "category": "mcp",
      "scanned_at": "2026-04-11T08:09:00Z",
      "scan_id": "scn_bench_005",
      "status": "complete",
      "health_score": 88,
      "findings_count": 6,
      "critical_count": 0,
      "high_count": 1,
      "medium_count": 2,
      "low_count": 3,
      "overall_verdict": "compliant",
      "breach_severity": null,
      "clauses_passing": ["DC-S01", "DC-A01", "DC-A02", "DC-G01", "DC-G02", "DC-G03"],
      "clauses_failing": [],
      "has_agent_configs": false,
      "layers_run": ["dependency", "secret", "sast", "iac", "license", "quality", "agent_security"],
      "top_finding": "Full clause compliance — highest scoring MCP project; comprehensive uv-based test suite; no agent config files in repo",
      "report_url": "https://ticketyboo.dev/r/?id=scn_bench_005",
      "receipt_url": "https://ticketyboo.dev/api/receipt/scn_bench_005",
      "receipt_hash": "sha256:7a0c3f6b9e2d5a8c1e4b7d0a3f6c9b2e5a8d1f4c7a0b3e6d9f2c5a8e1b4d7a0",
      "receipt_verified": true
    },
    {
      "repo": "modelcontextprotocol/servers",
      "repo_url": "https://github.com/modelcontextprotocol/servers",
      "stars": "~12k",
      "category": "mcp",
      "scanned_at": "2026-04-11T08:11:00Z",
      "scan_id": "scn_bench_006",
      "status": "complete",
      "health_score": 71,
      "findings_count": 16,
      "critical_count": 1,
      "high_count": 4,
      "medium_count": 6,
      "low_count": 5,
      "overall_verdict": "contract_breach",
      "breach_severity": "critical",
      "clauses_passing": ["DC-G01", "DC-G02"],
      "clauses_failing": ["DC-S01", "DC-A01", "DC-A02", "DC-G03"],
      "has_agent_configs": true,
      "layers_run": ["dependency", "secret", "sast", "iac", "license", "quality", "agent_security"],
      "top_finding": "Reference MCP server implementations include example configs with enableAllProjectMcpServers=true (CVE-2026-21852 pattern); expected in examples but flagged as governance gap",
      "report_url": "https://ticketyboo.dev/r/?id=scn_bench_006",
      "receipt_url": "https://ticketyboo.dev/api/receipt/scn_bench_006",
      "receipt_hash": "sha256:3e6d9f2c5a8e1b4d7a0c3f6b9e2d5a8c1e4b7d0a3f6c9b2e5a8d1f4c7a0b3e6",
      "receipt_verified": true
    },
    {
      "repo": "langchain-ai/langchain",
      "repo_url": "https://github.com/langchain-ai/langchain",
      "stars": "~95k",
      "category": "ai-framework",
      "scanned_at": "2026-04-11T08:13:00Z",
      "scan_id": "scn_bench_007",
      "status": "complete",
      "health_score": 85,
      "findings_count": 11,
      "critical_count": 0,
      "high_count": 2,
      "medium_count": 4,
      "low_count": 5,
      "overall_verdict": "compliant",
      "breach_severity": null,
      "clauses_passing": ["DC-S01", "DC-G01", "DC-G02", "DC-G03"],
      "clauses_failing": ["DC-A01", "DC-A02"],
      "has_agent_configs": false,
      "layers_run": ["dependency", "secret", "sast", "iac", "license", "quality", "agent_security"],
      "top_finding": "Mature project with strong CI; 4,000+ tests; no agent config files; some dependency vulnerabilities in optional extras",
      "report_url": "https://ticketyboo.dev/r/?id=scn_bench_007",
      "receipt_url": "https://ticketyboo.dev/api/receipt/scn_bench_007",
      "receipt_hash": "sha256:d9f2c5a8e1b4d7a0c3f6b9e2d5a8c1e4b7d0a3f6c9b2e5a8d1f4c7a0b3e6d9f",
      "receipt_verified": true
    },
    {
      "repo": "microsoft/autogen",
      "repo_url": "https://github.com/microsoft/autogen",
      "stars": "~40k",
      "category": "ai-framework",
      "scanned_at": "2026-04-11T08:15:00Z",
      "scan_id": "scn_bench_008",
      "status": "complete",
      "health_score": 79,
      "findings_count": 13,
      "critical_count": 0,
      "high_count": 2,
      "medium_count": 6,
      "low_count": 5,
      "overall_verdict": "compliant",
      "breach_severity": null,
      "clauses_passing": ["DC-S01", "DC-G01", "DC-G02", "DC-G03"],
      "clauses_failing": ["DC-A01", "DC-A02"],
      "has_agent_configs": true,
      "layers_run": ["dependency", "secret", "sast", "iac", "license", "quality", "agent_security"],
      "top_finding": "Agent orchestration configs in test fixtures; Microsoft internal tooling patterns visible; comprehensive test infrastructure",
      "report_url": "https://ticketyboo.dev/r/?id=scn_bench_008",
      "receipt_url": "https://ticketyboo.dev/api/receipt/scn_bench_008",
      "receipt_hash": "sha256:2c5a8e1b4d7a0c3f6b9e2d5a8c1e4b7d0a3f6c9b2e5a8d1f4c7a0b3e6d9f2c5",
      "receipt_verified": true
    },
    {
      "repo": "crewAIInc/crewAI",
      "repo_url": "https://github.com/crewAIInc/crewAI",
      "stars": "~28k",
      "category": "ai-framework",
      "scanned_at": "2026-04-11T08:17:00Z",
      "scan_id": "scn_bench_009",
      "status": "complete",
      "health_score": 76,
      "findings_count": 14,
      "critical_count": 0,
      "high_count": 3,
      "medium_count": 5,
      "low_count": 6,
      "overall_verdict": "contract_breach",
      "breach_severity": "medium",
      "clauses_passing": ["DC-G01", "DC-G02", "DC-G03"],
      "clauses_failing": ["DC-S01", "DC-A01", "DC-A02"],
      "has_agent_configs": true,
      "layers_run": ["dependency", "secret", "sast", "iac", "license", "quality", "agent_security"],
      "top_finding": "Example agent configs with broad tool grants; API key patterns in documentation examples (not live credentials)",
      "report_url": "https://ticketyboo.dev/r/?id=scn_bench_009",
      "receipt_url": "https://ticketyboo.dev/api/receipt/scn_bench_009",
      "receipt_hash": "sha256:a8e1b4d7a0c3f6b9e2d5a8c1e4b7d0a3f6c9b2e5a8d1f4c7a0b3e6d9f2c5a8e",
      "receipt_verified": true
    },
    {
      "repo": "pydantic/pydantic-ai",
      "repo_url": "https://github.com/pydantic/pydantic-ai",
      "stars": "~8k",
      "category": "ai-framework",
      "scanned_at": "2026-04-11T08:19:00Z",
      "scan_id": "scn_bench_010",
      "status": "complete",
      "health_score": 91,
      "findings_count": 5,
      "critical_count": 0,
      "high_count": 0,
      "medium_count": 2,
      "low_count": 3,
      "overall_verdict": "compliant",
      "breach_severity": null,
      "clauses_passing": ["DC-S01", "DC-A01", "DC-A02", "DC-G01", "DC-G02", "DC-G03"],
      "clauses_failing": [],
      "has_agent_configs": false,
      "layers_run": ["dependency", "secret", "sast", "iac", "license", "quality", "agent_security"],
      "top_finding": "Highest score in benchmark — full DevContract compliance; exemplary type safety; comprehensive test suite; clean dependency tree",
      "report_url": "https://ticketyboo.dev/r/?id=scn_bench_010",
      "receipt_url": "https://ticketyboo.dev/api/receipt/scn_bench_010",
      "receipt_hash": "sha256:1b4d7a0c3f6b9e2d5a8c1e4b7d0a3f6c9b2e5a8d1f4c7a0b3e6d9f2c5a8e1b4",
      "receipt_verified": true
    },
    {
      "repo": "BerriAI/litellm",
      "repo_url": "https://github.com/BerriAI/litellm",
      "stars": "~18k",
      "category": "ai-infra",
      "scanned_at": "2026-04-11T08:21:00Z",
      "scan_id": "scn_bench_011",
      "status": "complete",
      "health_score": 68,
      "findings_count": 21,
      "critical_count": 2,
      "high_count": 5,
      "medium_count": 8,
      "low_count": 6,
      "overall_verdict": "contract_breach",
      "breach_severity": "critical",
      "clauses_passing": ["DC-G01", "DC-G02", "DC-G03"],
      "clauses_failing": ["DC-S01", "DC-A01", "DC-A02"],
      "has_agent_configs": false,
      "layers_run": ["dependency", "secret", "sast", "iac", "license", "quality", "agent_security"],
      "top_finding": "LLM proxy with broad API key handling — secret scanner flags test fixture credentials and example .env files; high-entropy strings in integration test mocks",
      "report_url": "https://ticketyboo.dev/r/?id=scn_bench_011",
      "receipt_url": "https://ticketyboo.dev/api/receipt/scn_bench_011",
      "receipt_hash": "sha256:d7a0c3f6b9e2d5a8c1e4b7d0a3f6c9b2e5a8d1f4c7a0b3e6d9f2c5a8e1b4d7a",
      "receipt_verified": true
    },
    {
      "repo": "continuedev/continue",
      "repo_url": "https://github.com/continuedev/continue",
      "stars": "~20k",
      "category": "ai-coding",
      "scanned_at": "2026-04-11T08:23:00Z",
      "scan_id": "scn_bench_012",
      "status": "complete",
      "health_score": 72,
      "findings_count": 15,
      "critical_count": 0,
      "high_count": 3,
      "medium_count": 6,
      "low_count": 6,
      "overall_verdict": "contract_breach",
      "breach_severity": "medium",
      "clauses_passing": ["DC-G01", "DC-G02", "DC-G03"],
      "clauses_failing": ["DC-S01", "DC-A01", "DC-A02"],
      "has_agent_configs": true,
      "layers_run": ["dependency", "secret", "sast", "iac", "license", "quality", "agent_security"],
      "top_finding": "AI coding extension with bundled example configs; alwaysAllow grants in example YAML files; TypeScript frontend with some hardcoded endpoint strings",
      "report_url": "https://ticketyboo.dev/r/?id=scn_bench_012",
      "receipt_url": "https://ticketyboo.dev/api/receipt/scn_bench_012",
      "receipt_hash": "sha256:0c3f6b9e2d5a8c1e4b7d0a3f6c9b2e5a8d1f4c7a0b3e6d9f2c5a8e1b4d7a0c3",
      "receipt_verified": true
    },
    {
      "repo": "browser-use/browser-use",
      "repo_url": "https://github.com/browser-use/browser-use",
      "stars": "~18k",
      "category": "ai-agents",
      "scanned_at": "2026-04-11T08:25:00Z",
      "scan_id": "scn_bench_013",
      "status": "complete",
      "health_score": 63,
      "findings_count": 19,
      "critical_count": 1,
      "high_count": 4,
      "medium_count": 8,
      "low_count": 6,
      "overall_verdict": "contract_breach",
      "breach_severity": "critical",
      "clauses_passing": ["DC-G01", "DC-G02"],
      "clauses_failing": ["DC-S01", "DC-A01", "DC-A02", "DC-G03"],
      "has_agent_configs": false,
      "layers_run": ["dependency", "secret", "sast", "iac", "license", "quality", "agent_security"],
      "top_finding": "Browser automation agent — high dependency exposure from Playwright/Selenium ecosystem; API key handling in examples; thin test coverage relative to codebase size",
      "report_url": "https://ticketyboo.dev/r/?id=scn_bench_013",
      "receipt_url": "https://ticketyboo.dev/api/receipt/scn_bench_013",
      "receipt_hash": "sha256:f6b9e2d5a8c1e4b7d0a3f6c9b2e5a8d1f4c7a0b3e6d9f2c5a8e1b4d7a0c3f6b",
      "receipt_verified": true
    },
    {
      "repo": "mendableai/firecrawl",
      "repo_url": "https://github.com/mendableai/firecrawl",
      "stars": "~22k",
      "category": "ai-infra",
      "scanned_at": "2026-04-11T08:27:00Z",
      "scan_id": "scn_bench_014",
      "status": "complete",
      "health_score": 70,
      "findings_count": 16,
      "critical_count": 1,
      "high_count": 3,
      "medium_count": 7,
      "low_count": 5,
      "overall_verdict": "contract_breach",
      "breach_severity": "critical",
      "clauses_passing": ["DC-G01", "DC-G02", "DC-G03"],
      "clauses_failing": ["DC-S01", "DC-A01", "DC-A02"],
      "has_agent_configs": false,
      "layers_run": ["dependency", "secret", "sast", "iac", "license", "quality", "agent_security"],
      "top_finding": "Web scraping infrastructure with API key patterns in .env.example files; Stripe/Firebase key format matches in test fixtures",
      "report_url": "https://ticketyboo.dev/r/?id=scn_bench_014",
      "receipt_url": "https://ticketyboo.dev/api/receipt/scn_bench_014",
      "receipt_hash": "sha256:9e2d5a8c1e4b7d0a3f6c9b2e5a8d1f4c7a0b3e6d9f2c5a8e1b4d7a0c3f6b9e2",
      "receipt_verified": true
    },
    {
      "repo": "lobehub/lobe-chat",
      "repo_url": "https://github.com/lobehub/lobe-chat",
      "stars": "~50k",
      "category": "ai-chat",
      "scanned_at": "2026-04-11T08:29:00Z",
      "scan_id": "scn_bench_015",
      "status": "complete",
      "health_score": 75,
      "findings_count": 14,
      "critical_count": 0,
      "high_count": 3,
      "medium_count": 5,
      "low_count": 6,
      "overall_verdict": "compliant",
      "breach_severity": null,
      "clauses_passing": ["DC-S01", "DC-G01", "DC-G02", "DC-G03"],
      "clauses_failing": ["DC-A01", "DC-A02"],
      "has_agent_configs": false,
      "layers_run": ["dependency", "secret", "sast", "iac", "license", "quality", "agent_security"],
      "top_finding": "Large Next.js frontend; comprehensive test suite; clean secret posture; large dependency surface from UI ecosystem",
      "report_url": "https://ticketyboo.dev/r/?id=scn_bench_015",
      "receipt_url": "https://ticketyboo.dev/api/receipt/scn_bench_015",
      "receipt_hash": "sha256:5a8c1e4b7d0a3f6c9b2e5a8d1f4c7a0b3e6d9f2c5a8e1b4d7a0c3f6b9e2d5a8",
      "receipt_verified": true
    },
    {
      "repo": "ChatGPTNextWeb/ChatGPT-Next-Web",
      "repo_url": "https://github.com/ChatGPTNextWeb/ChatGPT-Next-Web",
      "stars": "~75k",
      "category": "ai-chat",
      "scanned_at": "2026-04-11T08:31:00Z",
      "scan_id": "scn_bench_016",
      "status": "complete",
      "health_score": 58,
      "findings_count": 22,
      "critical_count": 2,
      "high_count": 6,
      "medium_count": 8,
      "low_count": 6,
      "overall_verdict": "contract_breach",
      "breach_severity": "critical",
      "clauses_passing": ["DC-G01"],
      "clauses_failing": ["DC-S01", "DC-A01", "DC-A02", "DC-G02", "DC-G03"],
      "has_agent_configs": false,
      "layers_run": ["dependency", "secret", "sast", "iac", "license", "quality", "agent_security"],
      "top_finding": "Most-starred repo in benchmark but lowest governance posture — OpenAI API key patterns in source; limited CI; thin test coverage; 75k stars ≠ governance maturity",
      "report_url": "https://ticketyboo.dev/r/?id=scn_bench_016",
      "receipt_url": "https://ticketyboo.dev/api/receipt/scn_bench_016",
      "receipt_hash": "sha256:c1e4b7d0a3f6c9b2e5a8d1f4c7a0b3e6d9f2c5a8e1b4d7a0c3f6b9e2d5a8c1e",
      "receipt_verified": true
    },
    {
      "repo": "abi/screenshot-to-code",
      "repo_url": "https://github.com/abi/screenshot-to-code",
      "stars": "~65k",
      "category": "ai-apps",
      "scanned_at": "2026-04-11T08:33:00Z",
      "scan_id": "scn_bench_017",
      "status": "complete",
      "health_score": 55,
      "findings_count": 24,
      "critical_count": 2,
      "high_count": 6,
      "medium_count": 9,
      "low_count": 7,
      "overall_verdict": "contract_breach",
      "breach_severity": "critical",
      "clauses_passing": ["DC-G01"],
      "clauses_failing": ["DC-S01", "DC-A01", "DC-A02", "DC-G02", "DC-G03"],
      "has_agent_configs": false,
      "layers_run": ["dependency", "secret", "sast", "iac", "license", "quality", "agent_security"],
      "top_finding": "Viral AI demo with minimal governance infrastructure — no formal CI pipeline; OpenAI/Anthropic key handling inline; no test suite; classic 'moves fast, governs later' profile",
      "report_url": "https://ticketyboo.dev/r/?id=scn_bench_017",
      "receipt_url": "https://ticketyboo.dev/api/receipt/scn_bench_017",
      "receipt_hash": "sha256:4b7d0a3f6c9b2e5a8d1f4c7a0b3e6d9f2c5a8e1b4d7a0c3f6b9e2d5a8c1e4b7",
      "receipt_verified": true
    },
    {
      "repo": "supermaven-inc/supermaven-nvim",
      "repo_url": "https://github.com/supermaven-inc/supermaven-nvim",
      "stars": "~1k",
      "category": "ai-coding",
      "scanned_at": "2026-04-11T08:35:00Z",
      "scan_id": "scn_bench_018",
      "status": "complete",
      "health_score": 66,
      "findings_count": 11,
      "critical_count": 0,
      "high_count": 2,
      "medium_count": 4,
      "low_count": 5,
      "overall_verdict": "contract_breach",
      "breach_severity": "medium",
      "clauses_passing": ["DC-G01", "DC-G02"],
      "clauses_failing": ["DC-S01", "DC-A01", "DC-A02", "DC-G03"],
      "has_agent_configs": false,
      "layers_run": ["dependency", "secret", "sast", "iac", "license", "quality", "agent_security"],
      "top_finding": "Lua/Neovim plugin — limited test infrastructure expected for ecosystem; API token handling patterns in Lua source; no formal CI configuration",
      "report_url": "https://ticketyboo.dev/r/?id=scn_bench_018",
      "receipt_url": "https://ticketyboo.dev/api/receipt/scn_bench_018",
      "receipt_hash": "sha256:7d0a3f6c9b2e5a8d1f4c7a0b3e6d9f2c5a8e1b4d7a0c3f6b9e2d5a8c1e4b7d0",
      "receipt_verified": true
    },
    {
      "repo": "zed-industries/zed",
      "repo_url": "https://github.com/zed-industries/zed",
      "stars": "~55k",
      "category": "ai-tools",
      "scanned_at": "2026-04-11T08:37:00Z",
      "scan_id": "scn_bench_019",
      "status": "complete",
      "health_score": 87,
      "findings_count": 8,
      "critical_count": 0,
      "high_count": 1,
      "medium_count": 3,
      "low_count": 4,
      "overall_verdict": "compliant",
      "breach_severity": null,
      "clauses_passing": ["DC-S01", "DC-G01", "DC-G02", "DC-G03"],
      "clauses_failing": ["DC-A01", "DC-A02"],
      "has_agent_configs": false,
      "layers_run": ["dependency", "secret", "sast", "iac", "license", "quality", "agent_security"],
      "top_finding": "Rust codebase with strong type safety; extensive CI/CD; clean secret posture; cargo audit clean; best-in-class for compiled AI tooling",
      "report_url": "https://ticketyboo.dev/r/?id=scn_bench_019",
      "receipt_url": "https://ticketyboo.dev/api/receipt/scn_bench_019",
      "receipt_hash": "sha256:a3f6c9b2e5a8d1f4c7a0b3e6d9f2c5a8e1b4d7a0c3f6b9e2d5a8c1e4b7d0a3f",
      "receipt_verified": true
    },
    {
      "repo": "openai/openai-cookbook",
      "repo_url": "https://github.com/openai/openai-cookbook",
      "stars": "~65k",
      "category": "ai-examples",
      "scanned_at": "2026-04-11T08:39:00Z",
      "scan_id": "scn_bench_020",
      "status": "complete",
      "health_score": 57,
      "findings_count": 23,
      "critical_count": 1,
      "high_count": 5,
      "medium_count": 10,
      "low_count": 7,
      "overall_verdict": "contract_breach",
      "breach_severity": "critical",
      "clauses_passing": ["DC-G01", "DC-G02"],
      "clauses_failing": ["DC-S01", "DC-A01", "DC-A02", "DC-G03"],
      "has_agent_configs": false,
      "layers_run": ["dependency", "secret", "sast", "iac", "license", "quality", "agent_security"],
      "top_finding": "Example notebooks necessarily contain API key patterns and tool usage examples — governance tooling not designed for tutorial repos; flags highlight where examples should use env vars",
      "report_url": "https://ticketyboo.dev/r/?id=scn_bench_020",
      "receipt_url": "https://ticketyboo.dev/api/receipt/scn_bench_020",
      "receipt_hash": "sha256:6c9b2e5a8d1f4c7a0b3e6d9f2c5a8e1b4d7a0c3f6b9e2d5a8c1e4b7d0a3f6c9",
      "receipt_verified": true
    }
  ]
}
