{
  "$schema": "https://verifymcp.io/schemas/changelog.json",
  "server": "calypso-so-multimodal-rag-mcp-server",
  "component": "calypsohq-multimodal-rag-mcp-server",
  "generated_at": "2026-09-21T06:08:27.979Z",
  "tracking_since": "2026-07-27",
  "counts": {
    "critical": 0,
    "security": 43,
    "functional": 0,
    "cosmetic": 0
  },
  "events": [
    {
      "id": "chg_01a04b77-0b81-7179-b2cb-b9ef2a49f534",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.direct",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "undici",
        "refs": "[\"CVE-2026-1525\",\"CVE-2026-6733\",\"CVE-2026-1527\",\"CVE-2026-16728\",\"CVE-2026-11525\",\"CVE-2026-22036\",\"CVE-2026-15157\",\"CVE-2026-9679\",\"CVE-2026-16729\",\"CVE-2026-2229\",\"CVE-2026-1526\",\"CVE-2026-12151\"]",
        "seen": "125",
        "direct": "1",
        "package": "undici",
        "version": "5.29.0",
        "assessed": "126",
        "resolved": "125",
        "severity": "high",
        "vulnerable": "[{\"name\":\"undici\",\"version\":\"5.29.0\",\"depth\":1,\"path\":[\"undici\"],\"refs\":[\"CVE-2026-1525\",\"CVE-2026-6733\",\"CVE-2026-1527\",\"CVE-2026-16728\",\"CVE-2026-11525\",\"CVE-2026-22036\",\"CVE-2026-15157\",\"CVE-2026-9679\",\"CVE-2026-16729\",\"CVE-2026-2229\",\"CVE-2026-1526\",\"CVE-2026-12151\"]}]",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-08-29",
      "occurred_at": "2026-08-29 03:01:27.933291+00",
      "observed_since": "2026-08-28",
      "source": "scan",
      "summary": "Known CVEs (unverified → fail)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a04b77-0b81-7179-b2cb-b9ef2a49f534"
    },
    {
      "id": "chg_01a048e2-9ba8-76d3-950b-3f6d8ecfdc3e",
      "kind": "check.unverifiable",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.direct",
      "to_code": "cve.inconclusive",
      "from_value": "fail",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "root_version_missing"
      },
      "occurred_on": "2026-08-28",
      "occurred_at": "2026-08-28 15:00:04.373485+00",
      "observed_since": "2026-08-27",
      "source": "scan",
      "summary": "Known CVEs (fail → unverified)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a048e2-9ba8-76d3-950b-3f6d8ecfdc3e"
    },
    {
      "id": "chg_01a048ab-bad0-7cda-8f83-101759909881",
      "kind": "check.unverifiable",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.version_churn",
      "to_code": "stability.sandbox_pending",
      "from_value": "fail",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "version_superseded"
      },
      "occurred_on": "2026-08-28",
      "occurred_at": "2026-08-28 14:00:08.706959+00",
      "observed_since": "2026-08-27",
      "source": "scan",
      "summary": "Stability (fail → unverified)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a048ab-bad0-7cda-8f83-101759909881"
    },
    {
      "id": "chg_01a048ab-bad6-784d-a447-dc2c863a5b6f",
      "kind": "check.unverifiable",
      "family": "tool-safety-injection",
      "subject_kind": "check",
      "subject": "tool-safety-injection",
      "subject_child": "",
      "from_code": "toolsafety.injection_clean",
      "to_code": "toolsafety.sandbox_pending",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "version_superseded"
      },
      "occurred_on": "2026-08-28",
      "occurred_at": "2026-08-28 14:00:08.706959+00",
      "observed_since": "2026-08-27",
      "source": "scan",
      "summary": "Tool safety (pass → unverified)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a048ab-bad6-784d-a447-dc2c863a5b6f"
    },
    {
      "id": "chg_01a01d1d-dddd-7011-82aa-71682def602e",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-16729",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-16729",
        "severity": "high"
      },
      "occurred_on": "2026-08-20",
      "occurred_at": "2026-08-20 03:01:31.632094+00",
      "observed_since": "2026-08-19",
      "source": "scan",
      "summary": "CVE-2026-16729 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01d1d-dddd-7011-82aa-71682def602e"
    },
    {
      "id": "chg_01a01d1d-ddde-76b4-931b-85442640c026",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-15157",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-15157",
        "severity": "high"
      },
      "occurred_on": "2026-08-20",
      "occurred_at": "2026-08-20 03:01:31.632094+00",
      "observed_since": "2026-08-19",
      "source": "scan",
      "summary": "CVE-2026-15157 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01d1d-ddde-76b4-931b-85442640c026"
    },
    {
      "id": "chg_01a01d1d-ddde-7d40-ac0d-ab145a227ebb",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-22036",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-22036",
        "severity": "high"
      },
      "occurred_on": "2026-08-20",
      "occurred_at": "2026-08-20 03:01:31.632094+00",
      "observed_since": "2026-08-19",
      "source": "scan",
      "summary": "CVE-2026-22036 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01d1d-ddde-7d40-ac0d-ab145a227ebb"
    },
    {
      "id": "chg_01a01d1d-dddf-744d-aa0a-912d89cea5b5",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-1527",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-1527",
        "severity": "high"
      },
      "occurred_on": "2026-08-20",
      "occurred_at": "2026-08-20 03:01:31.632094+00",
      "observed_since": "2026-08-19",
      "source": "scan",
      "summary": "CVE-2026-1527 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01d1d-dddf-744d-aa0a-912d89cea5b5"
    },
    {
      "id": "chg_01a01d1d-dddf-7ac2-b0e0-dcdbb7447148",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-1525",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-1525",
        "severity": "high"
      },
      "occurred_on": "2026-08-20",
      "occurred_at": "2026-08-20 03:01:31.632094+00",
      "observed_since": "2026-08-19",
      "source": "scan",
      "summary": "CVE-2026-1525 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01d1d-dddf-7ac2-b0e0-dcdbb7447148"
    },
    {
      "id": "chg_01a01d1d-dde0-7143-9ed4-58e3ccdf9e96",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-1526",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-1526",
        "severity": "high"
      },
      "occurred_on": "2026-08-20",
      "occurred_at": "2026-08-20 03:01:31.632094+00",
      "observed_since": "2026-08-19",
      "source": "scan",
      "summary": "CVE-2026-1526 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01d1d-dde0-7143-9ed4-58e3ccdf9e96"
    },
    {
      "id": "chg_01a01d1d-dde0-7832-8949-49eb156a2bd6",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-11525",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-11525",
        "severity": "high"
      },
      "occurred_on": "2026-08-20",
      "occurred_at": "2026-08-20 03:01:31.632094+00",
      "observed_since": "2026-08-19",
      "source": "scan",
      "summary": "CVE-2026-11525 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01d1d-dde0-7832-8949-49eb156a2bd6"
    },
    {
      "id": "chg_01a01d1d-dde1-70eb-9ce9-79687484cb14",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.direct",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "undici",
        "refs": "[\"CVE-2026-1525\",\"CVE-2026-6733\",\"CVE-2026-1527\",\"CVE-2026-16728\",\"CVE-2026-11525\",\"CVE-2026-22036\",\"CVE-2026-15157\",\"CVE-2026-9679\",\"CVE-2026-16729\",\"CVE-2026-2229\",\"CVE-2026-1526\",\"CVE-2026-12151\"]",
        "seen": "125",
        "direct": "1",
        "package": "undici",
        "version": "5.29.0",
        "assessed": "126",
        "resolved": "125",
        "severity": "high",
        "vulnerable": "[{\"name\":\"undici\",\"version\":\"5.29.0\",\"depth\":1,\"path\":[\"undici\"],\"refs\":[\"CVE-2026-1525\",\"CVE-2026-6733\",\"CVE-2026-1527\",\"CVE-2026-16728\",\"CVE-2026-11525\",\"CVE-2026-22036\",\"CVE-2026-15157\",\"CVE-2026-9679\",\"CVE-2026-16729\",\"CVE-2026-2229\",\"CVE-2026-1526\",\"CVE-2026-12151\"]}]",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-08-20",
      "occurred_at": "2026-08-20 03:01:31.632094+00",
      "observed_since": "2026-08-19",
      "source": "scan",
      "summary": "Known CVEs (unverified → fail)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01d1d-dde1-70eb-9ce9-79687484cb14"
    },
    {
      "id": "chg_01a01d1d-dde1-7740-be8a-9b462f4f5494",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-9679",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-9679",
        "severity": "high"
      },
      "occurred_on": "2026-08-20",
      "occurred_at": "2026-08-20 03:01:31.632094+00",
      "observed_since": "2026-08-19",
      "source": "scan",
      "summary": "CVE-2026-9679 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01d1d-dde1-7740-be8a-9b462f4f5494"
    },
    {
      "id": "chg_01a01d1d-dde3-7441-beca-b0121eff0e4a",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-2229",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-2229",
        "severity": "high"
      },
      "occurred_on": "2026-08-20",
      "occurred_at": "2026-08-20 03:01:31.632094+00",
      "observed_since": "2026-08-19",
      "source": "scan",
      "summary": "CVE-2026-2229 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01d1d-dde3-7441-beca-b0121eff0e4a"
    },
    {
      "id": "chg_01a01d1d-dde3-7b09-b28f-c55f4ee2b6f7",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-6733",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-6733",
        "severity": "high"
      },
      "occurred_on": "2026-08-20",
      "occurred_at": "2026-08-20 03:01:31.632094+00",
      "observed_since": "2026-08-19",
      "source": "scan",
      "summary": "CVE-2026-6733 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01d1d-dde3-7b09-b28f-c55f4ee2b6f7"
    },
    {
      "id": "chg_01a01d1d-dde4-7767-8480-31a964a7aa69",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-16728",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-16728",
        "severity": "high"
      },
      "occurred_on": "2026-08-20",
      "occurred_at": "2026-08-20 03:01:31.632094+00",
      "observed_since": "2026-08-19",
      "source": "scan",
      "summary": "CVE-2026-16728 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01d1d-dde4-7767-8480-31a964a7aa69"
    },
    {
      "id": "chg_01a01d1d-dde4-7d3b-8353-a11ca1bb75d0",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-12151",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-12151",
        "severity": "high"
      },
      "occurred_on": "2026-08-20",
      "occurred_at": "2026-08-20 03:01:31.632094+00",
      "observed_since": "2026-08-19",
      "source": "scan",
      "summary": "CVE-2026-12151 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01d1d-dde4-7d3b-8353-a11ca1bb75d0"
    },
    {
      "id": "chg_01a01b9c-0b14-74c9-941c-359d0fe20c4c",
      "kind": "check.unverifiable",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.none",
      "to_code": "cve.inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "root_version_missing"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 20:00:05.494561+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "Known CVEs (pass → unverified)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01b9c-0b14-74c9-941c-359d0fe20c4c"
    },
    {
      "id": "chg_01a01b67-6e02-7d64-9da2-b20df5c48f7f",
      "kind": "check.verdict",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.building_history",
      "to_code": "stability.version_churn",
      "from_value": "0.77",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "to": "2.0.0",
        "days": "24",
        "from": "1.0.37",
        "added": "3",
        "breaks": "0",
        "removed": "4"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 19:02:38.098513+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "Stability (0.77 → fail)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01b67-6e02-7d64-9da2-b20df5c48f7f"
    },
    {
      "id": "chg_01a01b65-2636-7e45-956d-4b6bda2f59d6",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-16729",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-16729",
        "severity": "high"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 19:00:08.681604+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "CVE-2026-16729 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01b65-2636-7e45-956d-4b6bda2f59d6"
    },
    {
      "id": "chg_01a01b65-263a-7684-98a9-4bc2d14c419c",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-15157",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-15157",
        "severity": "high"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 19:00:08.681604+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "CVE-2026-15157 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01b65-263a-7684-98a9-4bc2d14c419c"
    },
    {
      "id": "chg_01a01b65-263a-7cdd-8632-60f8cb45f114",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-22036",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-22036",
        "severity": "high"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 19:00:08.681604+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "CVE-2026-22036 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01b65-263a-7cdd-8632-60f8cb45f114"
    },
    {
      "id": "chg_01a01b65-263c-7317-9147-a322ab8fea10",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-1527",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-1527",
        "severity": "high"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 19:00:08.681604+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "CVE-2026-1527 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01b65-263c-7317-9147-a322ab8fea10"
    },
    {
      "id": "chg_01a01b65-263c-79ca-90d8-df525da35aa2",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-1525",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-1525",
        "severity": "high"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 19:00:08.681604+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "CVE-2026-1525 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01b65-263c-79ca-90d8-df525da35aa2"
    },
    {
      "id": "chg_01a01b65-263c-7f1a-bb11-4cfbf0f21df9",
      "kind": "check.unverifiable",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.building_history",
      "to_code": "stability.sandbox_pending",
      "from_value": "0.77",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "version_superseded"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 19:00:08.681604+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "Stability (0.77 → unverified)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01b65-263c-7f1a-bb11-4cfbf0f21df9"
    },
    {
      "id": "chg_01a01b65-263d-7606-b124-84ada75c621a",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-1526",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-1526",
        "severity": "high"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 19:00:08.681604+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "CVE-2026-1526 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01b65-263d-7606-b124-84ada75c621a"
    },
    {
      "id": "chg_01a01b65-263d-7b43-9739-8c9018c11f9c",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-11525",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-11525",
        "severity": "high"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 19:00:08.681604+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "CVE-2026-11525 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01b65-263d-7b43-9739-8c9018c11f9c"
    },
    {
      "id": "chg_01a01b65-263e-7278-8099-ea10e11952e5",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-9679",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-9679",
        "severity": "high"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 19:00:08.681604+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "CVE-2026-9679 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01b65-263e-7278-8099-ea10e11952e5"
    },
    {
      "id": "chg_01a01b65-263e-7a33-aa3c-df089cb74ea2",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-2229",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-2229",
        "severity": "high"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 19:00:08.681604+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "CVE-2026-2229 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01b65-263e-7a33-aa3c-df089cb74ea2"
    },
    {
      "id": "chg_01a01b65-263f-7255-8cf6-0ef3bce8347c",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-6733",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-6733",
        "severity": "high"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 19:00:08.681604+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "CVE-2026-6733 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01b65-263f-7255-8cf6-0ef3bce8347c"
    },
    {
      "id": "chg_01a01b65-263f-787b-8a89-15eaf2d83d1c",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.none",
      "to_code": "cve.direct",
      "from_value": "pass",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "undici",
        "refs": "[\"CVE-2026-1525\",\"CVE-2026-6733\",\"CVE-2026-1527\",\"CVE-2026-16728\",\"CVE-2026-11525\",\"CVE-2026-22036\",\"CVE-2026-15157\",\"CVE-2026-9679\",\"CVE-2026-16729\",\"CVE-2026-2229\",\"CVE-2026-1526\",\"CVE-2026-12151\"]",
        "seen": "125",
        "direct": "1",
        "package": "undici",
        "version": "5.29.0",
        "assessed": "126",
        "resolved": "125",
        "severity": "high",
        "vulnerable": "[{\"name\":\"undici\",\"version\":\"5.29.0\",\"depth\":1,\"path\":[\"undici\"],\"refs\":[\"CVE-2026-1525\",\"CVE-2026-6733\",\"CVE-2026-1527\",\"CVE-2026-16728\",\"CVE-2026-11525\",\"CVE-2026-22036\",\"CVE-2026-15157\",\"CVE-2026-9679\",\"CVE-2026-16729\",\"CVE-2026-2229\",\"CVE-2026-1526\",\"CVE-2026-12151\"]}]",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 19:00:08.681604+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "Known CVEs (pass → fail)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01b65-263f-787b-8a89-15eaf2d83d1c"
    },
    {
      "id": "chg_01a01b65-263f-7ddf-a597-79945c79e4df",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-16728",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-16728",
        "severity": "high"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 19:00:08.681604+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "CVE-2026-16728 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01b65-263f-7ddf-a597-79945c79e4df"
    },
    {
      "id": "chg_01a01b65-2640-752c-89b0-979fa8e10c31",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-12151",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-12151",
        "severity": "high"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 19:00:08.681604+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "CVE-2026-12151 affects this package (high)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_01a01b65-2640-752c-89b0-979fa8e10c31"
    },
    {
      "id": "chg_019fda2a-3797-70a4-ac19-b6cab29f42b8",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.tree_partial",
      "to_code": "cve.none",
      "from_value": "partial",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "125",
        "assessed": "126",
        "resolved": "125",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-08-07",
      "occurred_at": "2026-08-07 03:00:27.629475+00",
      "observed_since": "2026-08-06",
      "source": "scan",
      "summary": "Known CVEs (partial → pass)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_019fda2a-3797-70a4-ac19-b6cab29f42b8"
    },
    {
      "id": "chg_019fcfdd-a879-75ab-bf11-3a8027351c5e",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-69207",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.tree_partial",
      "from_value": "medium",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-69207"
      },
      "occurred_on": "2026-08-05",
      "occurred_at": "2026-08-05 03:00:38.069044+00",
      "observed_since": "2026-08-04",
      "source": "scan",
      "summary": "CVE-2026-69207 no longer affects this package",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_019fcfdd-a879-75ab-bf11-3a8027351c5e"
    },
    {
      "id": "chg_019fcfdd-a87a-769e-85ee-672d297cec6a",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.tree_partial",
      "from_value": "fail",
      "to_value": "partial",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "125",
        "assessed": "125",
        "resolved": "124",
        "unresolved": "1",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-08-05",
      "occurred_at": "2026-08-05 03:00:38.069044+00",
      "observed_since": "2026-08-04",
      "source": "scan",
      "summary": "Known CVEs (fail → partial)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_019fcfdd-a87a-769e-85ee-672d297cec6a"
    },
    {
      "id": "chg_019fcab7-30a7-7314-8d18-92b0757c25b1",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-69207",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-69207",
        "severity": "medium"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 03:00:30.993523+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "CVE-2026-69207 affects this package (medium)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_019fcab7-30a7-7314-8d18-92b0757c25b1"
    },
    {
      "id": "chg_019fcab7-30a8-72f4-87ce-d42ca3d3df14",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.tree_partial",
      "to_code": "cve.transitive",
      "from_value": "partial",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "@modelcontextprotocol/sdk > hono",
        "refs": "[\"CVE-2026-69207\"]",
        "seen": "125",
        "package": "hono",
        "version": "4.12.33",
        "assessed": "125",
        "resolved": "124",
        "severity": "medium",
        "transitive": "1",
        "unresolved": "1",
        "vulnerable": "[{\"name\":\"hono\",\"version\":\"4.12.33\",\"depth\":2,\"path\":[\"@modelcontextprotocol/sdk\",\"hono\"],\"refs\":[\"CVE-2026-69207\"]}]",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 03:00:30.993523+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "Known CVEs (partial → fail)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_019fcab7-30a8-72f4-87ce-d42ca3d3df14"
    },
    {
      "id": "chg_019fc45f-cfe6-738f-9ff6-e8397297835f",
      "kind": "check.reverified",
      "family": "build-provenance",
      "subject_kind": "check",
      "subject": "build-provenance",
      "subject_child": "",
      "from_code": "provenance.inconclusive",
      "to_code": "provenance.none",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 21:27:21.300026+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Provenance (unverified → fail)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_019fc45f-cfe6-738f-9ff6-e8397297835f"
    },
    {
      "id": "chg_019fc45f-cfe9-74b2-98b9-fd7c698fa5be",
      "kind": "check.reverified",
      "family": "install-scripts",
      "subject_kind": "check",
      "subject": "install-scripts",
      "subject_child": "",
      "from_code": "installscript.inconclusive",
      "to_code": "installscript.none",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "tier": "none"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 21:27:21.300026+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Install scripts (unverified → pass)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_019fc45f-cfe9-74b2-98b9-fd7c698fa5be"
    },
    {
      "id": "chg_019fc45f-cfe9-7ba9-8a5f-47a57fc2f8ae",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.tree_partial",
      "from_value": "unverified",
      "to_value": "partial",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "125",
        "assessed": "125",
        "resolved": "124",
        "unresolved": "1",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 21:27:21.300026+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Known CVEs (unverified → partial)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_019fc45f-cfe9-7ba9-8a5f-47a57fc2f8ae"
    },
    {
      "id": "chg_019fc45f-cfea-72ac-86e3-36cea5d11001",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_pending",
      "to_code": "stability.insufficient_history",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 21:27:21.300026+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: not enough scan history yet (needs a 30-day window).)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_019fc45f-cfea-72ac-86e3-36cea5d11001"
    },
    {
      "id": "chg_019fc249-e71a-7be6-a11d-2c1c1eb80856",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 11:44:11.020809+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/calypso-so-multimodal-rag-mcp-server/calypsohq-multimodal-rag-mcp-server#chg-chg_019fc249-e71a-7be6-a11d-2c1c1eb80856"
    }
  ],
  "days": [
    {
      "date": "2026-09-19",
      "total": 76,
      "delta": -2,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": {
        "category": "Stability & Change Management",
        "from": 86,
        "to": 66,
        "delta": -20,
        "others": [],
        "accrual": null,
        "partial": false,
        "compared_to": "2026-09-18",
        "summary": "No change was recorded against any check on this day. Stability & Change Management went from 86 to 66."
      },
      "event_count": 0
    },
    {
      "date": "2026-09-17",
      "total": 78,
      "delta": 12,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": {
        "category": "Stability & Change Management",
        "from": 0,
        "to": 82,
        "delta": 82,
        "others": [],
        "accrual": null,
        "partial": false,
        "compared_to": "2026-09-16",
        "summary": "No change was recorded against any check on this day. Stability & Change Management went from 0 to 82."
      },
      "event_count": 0
    },
    {
      "date": "2026-08-29",
      "total": 66,
      "delta": 5,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 2
    },
    {
      "date": "2026-08-28",
      "total": 61,
      "delta": -5,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 12
    },
    {
      "date": "2026-08-26",
      "total": 66,
      "delta": -2,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-08-24",
      "total": 68,
      "delta": 1,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": {
        "category": "Stability & Change Management",
        "from": 13,
        "to": 17,
        "delta": 4,
        "others": [],
        "accrual": null,
        "partial": false,
        "compared_to": "2026-08-23",
        "summary": "No change was recorded against any check on this day. Stability & Change Management went from 13 to 17."
      },
      "event_count": 0
    },
    {
      "date": "2026-08-20",
      "total": 0,
      "delta": null,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 14
    },
    {
      "date": "2026-08-19",
      "total": 0,
      "delta": null,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 25
    }
  ]
}