{
  "$schema": "https://verifymcp.io/schemas/changelog.json",
  "server": "com-openagenda-mcp",
  "component": "openagenda-mcp",
  "generated_at": "2026-09-28T01:28:50.825Z",
  "tracking_since": "2026-07-27",
  "counts": {
    "critical": 0,
    "security": 28,
    "functional": 0,
    "cosmetic": 0
  },
  "events": [
    {
      "id": "chg_01a0b3f8-cb7b-7e5a-800c-26fad83aca62",
      "kind": "check.reason",
      "family": "tool-safety-injection",
      "subject_kind": "check",
      "subject": "tool-safety-injection",
      "subject_child": "",
      "from_code": "toolsafety.sandbox_pending",
      "to_code": "toolsafety.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "needs_declared_env",
        "status": "unreachable"
      },
      "occurred_on": "2026-09-18",
      "occurred_at": "2026-09-18 10:03:41.315545+00",
      "observed_since": "2026-09-17",
      "source": "scan",
      "summary": "Tool safety (Tool safety not yet verified: this server's registry entry declares environment variables (an API key or similar), and its server did not start in our sandbox, so we have no tool text to scan.)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_01a0b3f8-cb7b-7e5a-800c-26fad83aca62"
    },
    {
      "id": "chg_01a0b3f8-cb78-7cf8-8e8c-24cf2bff5a6f",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_pending",
      "to_code": "stability.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "needs_declared_env",
        "status": "unreachable"
      },
      "occurred_on": "2026-09-18",
      "occurred_at": "2026-09-18 10:03:41.315545+00",
      "observed_since": "2026-09-17",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: this server's registry entry declares environment variables (an API key or similar), and its server did not start in our sandbox, so we have no schema to compare.)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_01a0b3f8-cb78-7cf8-8e8c-24cf2bff5a6f"
    },
    {
      "id": "chg_01a0aed2-a05c-74f9-a417-1aa006d920fe",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-54285",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.none",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-54285"
      },
      "occurred_on": "2026-09-17",
      "occurred_at": "2026-09-17 10:03:53.674598+00",
      "observed_since": "2026-09-16",
      "source": "scan",
      "summary": "CVE-2026-54285 no longer affects this package",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_01a0aed2-a05c-74f9-a417-1aa006d920fe"
    },
    {
      "id": "chg_01a0aed2-a060-7275-bbc7-f7a89f816616",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.none",
      "from_value": "fail",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "217",
        "assessed": "218",
        "resolved": "217",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-09-17",
      "occurred_at": "2026-09-17 10:03:53.674598+00",
      "observed_since": "2026-09-16",
      "source": "scan",
      "summary": "Known CVEs (fail → pass)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_01a0aed2-a060-7275-bbc7-f7a89f816616"
    },
    {
      "id": "chg_01a0aed2-a060-7997-9fe1-04020daf319f",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-59892",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.none",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-59892"
      },
      "occurred_on": "2026-09-17",
      "occurred_at": "2026-09-17 10:03:53.674598+00",
      "observed_since": "2026-09-16",
      "source": "scan",
      "summary": "CVE-2026-59892 no longer affects this package",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_01a0aed2-a060-7997-9fe1-04020daf319f"
    },
    {
      "id": "chg_01a0aed2-a060-7f17-90de-824810ba1a8a",
      "kind": "check.reason",
      "family": "tool-safety-injection",
      "subject_kind": "check",
      "subject": "tool-safety-injection",
      "subject_child": "",
      "from_code": "toolsafety.sandbox_failed",
      "to_code": "toolsafety.sandbox_pending",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "version_superseded"
      },
      "occurred_on": "2026-09-17",
      "occurred_at": "2026-09-17 10:03:53.674598+00",
      "observed_since": "2026-09-16",
      "source": "scan",
      "summary": "Tool safety (Tool safety not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet.)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_01a0aed2-a060-7f17-90de-824810ba1a8a"
    },
    {
      "id": "chg_01a0aed2-a061-75af-bfbf-d2945b3c7cc1",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_failed",
      "to_code": "stability.sandbox_pending",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "version_superseded"
      },
      "occurred_on": "2026-09-17",
      "occurred_at": "2026-09-17 10:03:53.674598+00",
      "observed_since": "2026-09-16",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_01a0aed2-a061-75af-bfbf-d2945b3c7cc1"
    },
    {
      "id": "chg_01a09f5f-f372-76d2-95bb-5dd4ad0f530f",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-82417",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.transitive",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-82417"
      },
      "occurred_on": "2026-09-14",
      "occurred_at": "2026-09-14 10:04:20.222285+00",
      "observed_since": "2026-09-13",
      "source": "scan",
      "summary": "CVE-2026-82417 no longer affects this package",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_01a09f5f-f372-76d2-95bb-5dd4ad0f530f"
    },
    {
      "id": "chg_01a09f5f-f376-72f9-8a8d-6970e50b9ab0",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-82562",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.transitive",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-82562"
      },
      "occurred_on": "2026-09-14",
      "occurred_at": "2026-09-14 10:04:20.222285+00",
      "observed_since": "2026-09-13",
      "source": "scan",
      "summary": "CVE-2026-82562 no longer affects this package",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_01a09f5f-f376-72f9-8a8d-6970e50b9ab0"
    },
    {
      "id": "chg_01a066bb-77a9-789a-9857-df70a0092866",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-82417",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-82417",
        "severity": "high"
      },
      "occurred_on": "2026-09-03",
      "occurred_at": "2026-09-03 10:05:56.955507+00",
      "observed_since": "2026-09-02",
      "source": "scan",
      "summary": "CVE-2026-82417 affects this package (high)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_01a066bb-77a9-789a-9857-df70a0092866"
    },
    {
      "id": "chg_01a066bb-77aa-77a0-a4b1-858d29efb8fc",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-82562",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-82562",
        "severity": "high"
      },
      "occurred_on": "2026-09-03",
      "occurred_at": "2026-09-03 10:05:56.955507+00",
      "observed_since": "2026-09-02",
      "source": "scan",
      "summary": "CVE-2026-82562 affects this package (high)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_01a066bb-77aa-77a0-a4b1-858d29efb8fc"
    },
    {
      "id": "chg_019fc48f-1525-7852-8c46-dbe987956ea7",
      "kind": "check.reverified",
      "family": "build-provenance",
      "subject_kind": "check",
      "subject": "build-provenance",
      "subject_child": "",
      "from_code": "provenance.inconclusive",
      "to_code": "provenance.none",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 22:18:59.197415+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Provenance (unverified → fail)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_019fc48f-1525-7852-8c46-dbe987956ea7"
    },
    {
      "id": "chg_019fc48f-1528-7928-ad51-d8c3dd4d7f13",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.transitive",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "@opentelemetry/sdk-node > @opentelemetry/propagator-jaeger",
        "refs": "[\"CVE-2026-54285\",\"CVE-2026-59892\"]",
        "seen": "217",
        "package": "@opentelemetry/propagator-jaeger",
        "version": "2.7.1",
        "assessed": "215",
        "resolved": "214",
        "severity": "high",
        "transitive": "2",
        "unresolved": "3",
        "vulnerable": "[{\"name\":\"@opentelemetry/core\",\"version\":\"2.7.1\",\"depth\":2,\"path\":[\"@opentelemetry/exporter-logs-otlp-proto\",\"@opentelemetry/core\"],\"refs\":[\"CVE-2026-54285\"]},{\"name\":\"@opentelemetry/propagator-jaeger\",\"version\":\"2.7.1\",\"depth\":2,\"path\":[\"@opentelemetry/sdk-node\",\"@opentelemetry/propagator-jaeger\"],\"refs\":[\"CVE-2026-59892\"]}]",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 22:18:59.197415+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Known CVEs (unverified → fail)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_019fc48f-1528-7928-ad51-d8c3dd4d7f13"
    },
    {
      "id": "chg_019fc48f-152b-770e-966a-6fe8644dd666",
      "kind": "check.reverified",
      "family": "install-scripts",
      "subject_kind": "check",
      "subject": "install-scripts",
      "subject_child": "",
      "from_code": "installscript.inconclusive",
      "to_code": "installscript.none",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "tier": "none"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 22:18:59.197415+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Install scripts (unverified → pass)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_019fc48f-152b-770e-966a-6fe8644dd666"
    },
    {
      "id": "chg_019fc48f-152b-7c95-a433-4e5f12fd3933",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_pending",
      "to_code": "stability.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "status": "unreachable"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 22:18:59.197415+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: our sandbox run of this package did not complete, so we have no schema to compare.)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_019fc48f-152b-7c95-a433-4e5f12fd3933"
    },
    {
      "id": "chg_019fc3d3-4c94-7afd-ba47-9b0793fc252e",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 18:53:52.640864+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_019fc3d3-4c94-7afd-ba47-9b0793fc252e"
    },
    {
      "id": "chg_019fbedf-a2ab-74b4-bd2a-fe06a3c31fa9",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_failed",
      "to_code": "stability.sandbox_pending",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-01",
      "occurred_at": "2026-08-01 19:49:15.037156+00",
      "observed_since": "2026-07-31",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_019fbedf-a2ab-74b4-bd2a-fe06a3c31fa9"
    },
    {
      "id": "chg_019fb35a-bc50-7bcb-9a8e-6186dab77fa3",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 14:08:15.944394+00",
      "observed_since": "2026-07-29",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_019fb35a-bc50-7bcb-9a8e-6186dab77fa3"
    },
    {
      "id": "chg_019fb35a-bc51-7206-8e6d-2845f7f2591c",
      "kind": "check.unverifiable",
      "family": "build-provenance",
      "subject_kind": "check",
      "subject": "build-provenance",
      "subject_child": "",
      "from_code": "provenance.none",
      "to_code": "provenance.inconclusive",
      "from_value": "fail",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 14:08:15.944394+00",
      "observed_since": "2026-07-29",
      "source": "scan",
      "summary": "Provenance (fail → unverified)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_019fb35a-bc51-7206-8e6d-2845f7f2591c"
    },
    {
      "id": "chg_019fb35a-bc51-7650-b5ba-bd931fdd9ac2",
      "kind": "check.unverifiable",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.inconclusive",
      "from_value": "fail",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "advisories_unavailable"
      },
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 14:08:15.944394+00",
      "observed_since": "2026-07-29",
      "source": "scan",
      "summary": "Known CVEs (fail → unverified)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_019fb35a-bc51-7650-b5ba-bd931fdd9ac2"
    },
    {
      "id": "chg_019fb35a-bc51-7a63-82ec-f81b200b785e",
      "kind": "check.unverifiable",
      "family": "install-scripts",
      "subject_kind": "check",
      "subject": "install-scripts",
      "subject_child": "",
      "from_code": "installscript.none",
      "to_code": "installscript.inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 14:08:15.944394+00",
      "observed_since": "2026-07-29",
      "source": "scan",
      "summary": "Install scripts (pass → unverified)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_019fb35a-bc51-7a63-82ec-f81b200b785e"
    },
    {
      "id": "chg_019fb35a-bc51-7e1d-9e0e-ebf41bfcb3b8",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-59892",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.inconclusive",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-59892"
      },
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 14:08:15.944394+00",
      "observed_since": "2026-07-29",
      "source": "scan",
      "summary": "CVE-2026-59892 no longer affects this package",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_019fb35a-bc51-7e1d-9e0e-ebf41bfcb3b8"
    },
    {
      "id": "chg_019fb35a-bc52-728a-8fc6-0645031c21bf",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-54285",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.inconclusive",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-54285"
      },
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 14:08:15.944394+00",
      "observed_since": "2026-07-29",
      "source": "scan",
      "summary": "CVE-2026-54285 no longer affects this package",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_019fb35a-bc52-728a-8fc6-0645031c21bf"
    },
    {
      "id": "chg_019fac94-61ca-7af9-86cf-3dce161c0ef7",
      "kind": "check.reverified",
      "family": "install-scripts",
      "subject_kind": "check",
      "subject": "install-scripts",
      "subject_child": "",
      "from_code": "installscript.inconclusive",
      "to_code": "installscript.none",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "tier": "none"
      },
      "occurred_on": "2026-07-29",
      "occurred_at": "2026-07-29 06:33:53.338171+00",
      "observed_since": "2026-07-28",
      "source": "scan",
      "summary": "Install scripts (unverified → pass)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_019fac94-61ca-7af9-86cf-3dce161c0ef7"
    },
    {
      "id": "chg_019fac94-61c9-706c-ba00-c1688e0ad34b",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-54285",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-54285",
        "severity": "high"
      },
      "occurred_on": "2026-07-29",
      "occurred_at": "2026-07-29 06:33:53.338171+00",
      "observed_since": "2026-07-28",
      "source": "scan",
      "summary": "CVE-2026-54285 affects this package (high)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_019fac94-61c9-706c-ba00-c1688e0ad34b"
    },
    {
      "id": "chg_019fac94-61c9-7835-a550-7a39eb598f20",
      "kind": "check.reverified",
      "family": "build-provenance",
      "subject_kind": "check",
      "subject": "build-provenance",
      "subject_child": "",
      "from_code": "provenance.inconclusive",
      "to_code": "provenance.none",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-07-29",
      "occurred_at": "2026-07-29 06:33:53.338171+00",
      "observed_since": "2026-07-28",
      "source": "scan",
      "summary": "Provenance (unverified → fail)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_019fac94-61c9-7835-a550-7a39eb598f20"
    },
    {
      "id": "chg_019fac94-61c9-7d82-89b5-58564c18b2cb",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-59892",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-59892",
        "severity": "high"
      },
      "occurred_on": "2026-07-29",
      "occurred_at": "2026-07-29 06:33:53.338171+00",
      "observed_since": "2026-07-28",
      "source": "scan",
      "summary": "CVE-2026-59892 affects this package (high)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_019fac94-61c9-7d82-89b5-58564c18b2cb"
    },
    {
      "id": "chg_019fac94-61ca-7545-ad95-8de11d4177ec",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.transitive",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "@opentelemetry/sdk-node > @opentelemetry/propagator-jaeger",
        "refs": "[\"CVE-2026-54285\",\"CVE-2026-59892\"]",
        "seen": "217",
        "package": "@opentelemetry/propagator-jaeger",
        "version": "2.7.1",
        "assessed": "215",
        "resolved": "214",
        "severity": "high",
        "transitive": "2",
        "unresolved": "3",
        "vulnerable": "[{\"name\":\"@opentelemetry/core\",\"version\":\"2.7.1\",\"depth\":2,\"path\":[\"@opentelemetry/exporter-logs-otlp-proto\",\"@opentelemetry/core\"],\"refs\":[\"CVE-2026-54285\"]},{\"name\":\"@opentelemetry/propagator-jaeger\",\"version\":\"2.7.1\",\"depth\":2,\"path\":[\"@opentelemetry/sdk-node\",\"@opentelemetry/propagator-jaeger\"],\"refs\":[\"CVE-2026-59892\"]}]",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-07-29",
      "occurred_at": "2026-07-29 06:33:53.338171+00",
      "observed_since": "2026-07-28",
      "source": "scan",
      "summary": "Known CVEs (unverified → fail)",
      "link": "https://verifymcp.io/servers/com-openagenda-mcp/openagenda-mcp#chg-chg_019fac94-61ca-7545-ad95-8de11d4177ec"
    }
  ],
  "days": [
    {
      "date": "2026-09-26",
      "total": 39,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-25",
      "total": 39,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-18",
      "total": 39,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 5
    },
    {
      "date": "2026-09-17",
      "total": 39,
      "delta": 3,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 9
    },
    {
      "date": "2026-09-14",
      "total": 36,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 2
    },
    {
      "date": "2026-09-03",
      "total": 36,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 2
    },
    {
      "date": "2026-08-26",
      "total": 0,
      "delta": null,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-08-11",
      "total": 0,
      "delta": null,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    }
  ]
}