{
  "$schema": "https://verifymcp.io/schemas/changelog.json",
  "server": "dearlordylord-huly-mcp",
  "component": "firfi-huly-mcp",
  "generated_at": "2026-09-24T20:51:44.733Z",
  "tracking_since": "2026-07-26",
  "counts": {
    "critical": 0,
    "security": 42,
    "functional": 0,
    "cosmetic": 0
  },
  "events": [
    {
      "id": "chg_01a09d7d-be1d-79bb-942f-e9d7e7793f4e",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.transitive",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "@hcengineering/activity > @hcengineering/ui > svelte",
        "refs": "[\"CVE-2026-27125\",\"CVE-2026-27121\",\"CVE-2026-27122\",\"CVE-2026-27901\",\"CVE-2026-42599\",\"CVE-2026-42573\"]",
        "seen": "93",
        "package": "svelte",
        "version": "4.2.20",
        "assessed": "94",
        "resolved": "93",
        "severity": "medium",
        "transitive": "1",
        "vulnerable": "[{\"name\":\"svelte\",\"version\":\"4.2.20\",\"depth\":3,\"path\":[\"@hcengineering/activity\",\"@hcengineering/ui\",\"svelte\"],\"refs\":[\"CVE-2026-27125\",\"CVE-2026-27121\",\"CVE-2026-27122\",\"CVE-2026-27901\",\"CVE-2026-42599\",\"CVE-2026-42573\"]}]",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-09-14",
      "occurred_at": "2026-09-14 01:17:38.65982+00",
      "observed_since": "2026-09-13",
      "source": "scan",
      "summary": "Known CVEs (unverified → fail)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_01a09d7d-be1d-79bb-942f-e9d7e7793f4e"
    },
    {
      "id": "chg_01a0996a-5220-7df1-a892-86c921e4879f",
      "kind": "check.unverifiable",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.inconclusive",
      "from_value": "fail",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "root_version_missing"
      },
      "occurred_on": "2026-09-13",
      "occurred_at": "2026-09-13 06:17:56.863204+00",
      "observed_since": "2026-09-12",
      "source": "scan",
      "summary": "Known CVEs (fail → unverified)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_01a0996a-5220-7df1-a892-86c921e4879f"
    },
    {
      "id": "chg_01a07972-7030-7111-af64-fcb6ceb95c23",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.transitive",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "@hcengineering/activity > @hcengineering/ui > svelte",
        "refs": "[\"CVE-2026-27125\",\"CVE-2026-27121\",\"CVE-2026-27122\",\"CVE-2026-27901\",\"CVE-2026-42599\",\"CVE-2026-42573\"]",
        "seen": "93",
        "package": "svelte",
        "version": "4.2.20",
        "assessed": "94",
        "resolved": "93",
        "severity": "medium",
        "transitive": "1",
        "vulnerable": "[{\"name\":\"svelte\",\"version\":\"4.2.20\",\"depth\":3,\"path\":[\"@hcengineering/activity\",\"@hcengineering/ui\",\"svelte\"],\"refs\":[\"CVE-2026-27125\",\"CVE-2026-27121\",\"CVE-2026-27122\",\"CVE-2026-27901\",\"CVE-2026-42599\",\"CVE-2026-42573\"]}]",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-09-07",
      "occurred_at": "2026-09-07 01:18:58.031622+00",
      "observed_since": "2026-09-06",
      "source": "scan",
      "summary": "Known CVEs (unverified → fail)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_01a07972-7030-7111-af64-fcb6ceb95c23"
    },
    {
      "id": "chg_01a07449-1224-7f0c-a6bd-cd09d8483fb6",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.transitive",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "@hcengineering/activity > @hcengineering/ui > svelte",
        "refs": "[\"CVE-2026-27125\",\"CVE-2026-27121\",\"CVE-2026-27122\",\"CVE-2026-27901\",\"CVE-2026-42599\",\"CVE-2026-42573\"]",
        "seen": "93",
        "package": "svelte",
        "version": "4.2.20",
        "assessed": "94",
        "resolved": "93",
        "severity": "medium",
        "transitive": "1",
        "vulnerable": "[{\"name\":\"svelte\",\"version\":\"4.2.20\",\"depth\":3,\"path\":[\"@hcengineering/activity\",\"@hcengineering/ui\",\"svelte\"],\"refs\":[\"CVE-2026-27125\",\"CVE-2026-27121\",\"CVE-2026-27122\",\"CVE-2026-27901\",\"CVE-2026-42599\",\"CVE-2026-42573\"]}]",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-09-06",
      "occurred_at": "2026-09-06 01:15:40.879807+00",
      "observed_since": "2026-09-05",
      "source": "scan",
      "summary": "Known CVEs (unverified → fail)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_01a07449-1224-7f0c-a6bd-cd09d8483fb6"
    },
    {
      "id": "chg_01a07449-1227-73a3-b562-a846a0c18ffc",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_pending",
      "to_code": "stability.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "needs_declared_env",
        "status": "unreachable"
      },
      "occurred_on": "2026-09-06",
      "occurred_at": "2026-09-06 01:15:40.879807+00",
      "observed_since": "2026-09-05",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: this server's registry entry declares environment variables (an API key or similar) that our sandbox does not supply, so we have no schema to compare.)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_01a07449-1227-73a3-b562-a846a0c18ffc"
    },
    {
      "id": "chg_01a07449-1227-7dc4-9cd3-9d68c1fc1578",
      "kind": "check.reason",
      "family": "tool-safety-injection",
      "subject_kind": "check",
      "subject": "tool-safety-injection",
      "subject_child": "",
      "from_code": "toolsafety.sandbox_pending",
      "to_code": "toolsafety.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "needs_declared_env",
        "status": "unreachable"
      },
      "occurred_on": "2026-09-06",
      "occurred_at": "2026-09-06 01:15:40.879807+00",
      "observed_since": "2026-09-05",
      "source": "scan",
      "summary": "Tool safety (Tool safety not yet verified: this server's registry entry declares environment variables (an API key or similar) that our sandbox does not supply, so we have no tool text to scan.)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_01a07449-1227-7dc4-9cd3-9d68c1fc1578"
    },
    {
      "id": "chg_01a06ffe-8433-7a4e-950e-8373eca6bfd3",
      "kind": "check.unverifiable",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.inconclusive",
      "from_value": "fail",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "root_version_missing"
      },
      "occurred_on": "2026-09-05",
      "occurred_at": "2026-09-05 05:15:45.851822+00",
      "observed_since": "2026-09-04",
      "source": "scan",
      "summary": "Known CVEs (fail → unverified)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_01a06ffe-8433-7a4e-950e-8373eca6bfd3"
    },
    {
      "id": "chg_01a06ffe-8437-7f00-a2d1-dde3af8caf64",
      "kind": "check.reason",
      "family": "tool-safety-injection",
      "subject_kind": "check",
      "subject": "tool-safety-injection",
      "subject_child": "",
      "from_code": "toolsafety.sandbox_failed",
      "to_code": "toolsafety.sandbox_pending",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "version_superseded"
      },
      "occurred_on": "2026-09-05",
      "occurred_at": "2026-09-05 05:15:45.851822+00",
      "observed_since": "2026-09-04",
      "source": "scan",
      "summary": "Tool safety (Tool safety not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet.)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_01a06ffe-8437-7f00-a2d1-dde3af8caf64"
    },
    {
      "id": "chg_01a06ffe-8438-770a-b330-fdde80fc603d",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_failed",
      "to_code": "stability.sandbox_pending",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "version_superseded"
      },
      "occurred_on": "2026-09-05",
      "occurred_at": "2026-09-05 05:15:45.851822+00",
      "observed_since": "2026-09-04",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_01a06ffe-8438-770a-b330-fdde80fc603d"
    },
    {
      "id": "chg_01a05fae-7fbd-7dc5-95d7-84c56ad94383",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_pending",
      "to_code": "stability.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "needs_declared_env",
        "status": "unreachable"
      },
      "occurred_on": "2026-09-02",
      "occurred_at": "2026-09-02 01:14:26.555402+00",
      "observed_since": "2026-09-01",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: this server's registry entry declares environment variables (an API key or similar) that our sandbox does not supply, so we have no schema to compare.)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_01a05fae-7fbd-7dc5-95d7-84c56ad94383"
    },
    {
      "id": "chg_01a05fae-7fbf-760b-baaf-dca2ef47d305",
      "kind": "check.reason",
      "family": "tool-safety-injection",
      "subject_kind": "check",
      "subject": "tool-safety-injection",
      "subject_child": "",
      "from_code": "toolsafety.sandbox_pending",
      "to_code": "toolsafety.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "needs_declared_env",
        "status": "unreachable"
      },
      "occurred_on": "2026-09-02",
      "occurred_at": "2026-09-02 01:14:26.555402+00",
      "observed_since": "2026-09-01",
      "source": "scan",
      "summary": "Tool safety (Tool safety not yet verified: this server's registry entry declares environment variables (an API key or similar) that our sandbox does not supply, so we have no tool text to scan.)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_01a05fae-7fbf-760b-baaf-dca2ef47d305"
    },
    {
      "id": "chg_01a05d7c-bb9f-778f-983d-b0e9a80c49cc",
      "kind": "check.reason",
      "family": "tool-safety-injection",
      "subject_kind": "check",
      "subject": "tool-safety-injection",
      "subject_child": "",
      "from_code": "toolsafety.sandbox_failed",
      "to_code": "toolsafety.sandbox_pending",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "version_superseded"
      },
      "occurred_on": "2026-09-01",
      "occurred_at": "2026-09-01 15:00:50.692879+00",
      "observed_since": "2026-08-31",
      "source": "scan",
      "summary": "Tool safety (Tool safety not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet.)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_01a05d7c-bb9f-778f-983d-b0e9a80c49cc"
    },
    {
      "id": "chg_01a05d7c-bba0-7316-81bf-7ff0763fb3bd",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_failed",
      "to_code": "stability.sandbox_pending",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "version_superseded"
      },
      "occurred_on": "2026-09-01",
      "occurred_at": "2026-09-01 15:00:50.692879+00",
      "observed_since": "2026-08-31",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_01a05d7c-bba0-7316-81bf-7ff0763fb3bd"
    },
    {
      "id": "chg_019ffdd5-3345-76c8-9599-b8949add198a",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_pending",
      "to_code": "stability.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "needs_declared_env",
        "status": "unreachable"
      },
      "occurred_on": "2026-08-14",
      "occurred_at": "2026-08-14 01:13:55.743738+00",
      "observed_since": "2026-08-13",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: this server's registry entry declares environment variables (an API key or similar) that our sandbox does not supply, so we have no schema to compare.)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019ffdd5-3345-76c8-9599-b8949add198a"
    },
    {
      "id": "chg_019ffba3-9688-7b72-9e15-aac267b1ed9d",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_failed",
      "to_code": "stability.sandbox_pending",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "version_superseded"
      },
      "occurred_on": "2026-08-13",
      "occurred_at": "2026-08-13 15:00:29.940103+00",
      "observed_since": "2026-08-12",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019ffba3-9688-7b72-9e15-aac267b1ed9d"
    },
    {
      "id": "chg_019fe93b-4cf5-70cc-846f-15cb04c5b0af",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.transitive",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "@hcengineering/activity > @hcengineering/ui > svelte",
        "refs": "[\"CVE-2026-27125\",\"CVE-2026-27121\",\"CVE-2026-27122\",\"CVE-2026-27901\",\"CVE-2026-42599\",\"CVE-2026-42573\"]",
        "seen": "92",
        "package": "svelte",
        "version": "4.2.20",
        "assessed": "93",
        "resolved": "92",
        "severity": "medium",
        "transitive": "1",
        "vulnerable": "[{\"name\":\"svelte\",\"version\":\"4.2.20\",\"depth\":3,\"path\":[\"@hcengineering/activity\",\"@hcengineering/ui\",\"svelte\"],\"refs\":[\"CVE-2026-27125\",\"CVE-2026-27121\",\"CVE-2026-27122\",\"CVE-2026-27901\",\"CVE-2026-42599\",\"CVE-2026-42573\"]}]",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-08-10",
      "occurred_at": "2026-08-10 01:13:25.455412+00",
      "observed_since": "2026-08-09",
      "source": "scan",
      "summary": "Known CVEs (unverified → fail)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fe93b-4cf5-70cc-846f-15cb04c5b0af"
    },
    {
      "id": "chg_019fe7e5-8bf7-7765-8535-589488902744",
      "kind": "check.unverifiable",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.inconclusive",
      "from_value": "fail",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "root_version_missing"
      },
      "occurred_on": "2026-08-09",
      "occurred_at": "2026-08-09 19:00:08.277292+00",
      "observed_since": "2026-08-08",
      "source": "scan",
      "summary": "Known CVEs (fail → unverified)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fe7e5-8bf7-7765-8535-589488902744"
    },
    {
      "id": "chg_019fc4df-466e-75d9-a6cf-c0a3b6852ed5",
      "kind": "check.reverified",
      "family": "build-provenance",
      "subject_kind": "check",
      "subject": "build-provenance",
      "subject_child": "",
      "from_code": "provenance.inconclusive",
      "to_code": "provenance.none",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:46:34.71701+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Provenance (unverified → fail)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fc4df-466e-75d9-a6cf-c0a3b6852ed5"
    },
    {
      "id": "chg_019fc4df-466f-7797-bf1d-890206273188",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.transitive",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "@hcengineering/activity > @hcengineering/ui > svelte",
        "refs": "[\"CVE-2026-27125\",\"CVE-2026-27121\",\"CVE-2026-27122\",\"CVE-2026-27901\",\"CVE-2026-42599\",\"CVE-2026-42573\"]",
        "seen": "88",
        "package": "svelte",
        "version": "4.2.20",
        "assessed": "89",
        "resolved": "88",
        "severity": "medium",
        "transitive": "1",
        "vulnerable": "[{\"name\":\"svelte\",\"version\":\"4.2.20\",\"depth\":3,\"path\":[\"@hcengineering/activity\",\"@hcengineering/ui\",\"svelte\"],\"refs\":[\"CVE-2026-27125\",\"CVE-2026-27121\",\"CVE-2026-27122\",\"CVE-2026-27901\",\"CVE-2026-42599\",\"CVE-2026-42573\"]}]",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:46:34.71701+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Known CVEs (unverified → fail)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fc4df-466f-7797-bf1d-890206273188"
    },
    {
      "id": "chg_019fc4df-4670-74bc-9e4f-31bdcd09eb78",
      "kind": "check.reverified",
      "family": "install-scripts",
      "subject_kind": "check",
      "subject": "install-scripts",
      "subject_child": "",
      "from_code": "installscript.inconclusive",
      "to_code": "installscript.none",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "tier": "none"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:46:34.71701+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Install scripts (unverified → pass)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fc4df-4670-74bc-9e4f-31bdcd09eb78"
    },
    {
      "id": "chg_019fc2cf-d378-778a-919b-ba1a169b9164",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_failed",
      "to_code": "stability.sandbox_pending",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 14:10:27.812281+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fc2cf-d378-778a-919b-ba1a169b9164"
    },
    {
      "id": "chg_019fc1f1-b0a9-7664-832c-b919c02fa81d",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 10:07:49.909143+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fc1f1-b0a9-7664-832c-b919c02fa81d"
    },
    {
      "id": "chg_019fbc94-b05f-7bfc-8bcd-c2da261dedda",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_pending",
      "to_code": "stability.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "status": "unreachable"
      },
      "occurred_on": "2026-08-01",
      "occurred_at": "2026-08-01 09:08:08.912553+00",
      "observed_since": "2026-07-31",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: our sandbox run of this package did not complete, so we have no schema to compare.)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fbc94-b05f-7bfc-8bcd-c2da261dedda"
    },
    {
      "id": "chg_019fb201-73e7-7ec9-ab9c-406a280274fd",
      "kind": "check.unverifiable",
      "family": "build-provenance",
      "subject_kind": "check",
      "subject": "build-provenance",
      "subject_child": "",
      "from_code": "provenance.none",
      "to_code": "provenance.inconclusive",
      "from_value": "fail",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 07:51:07.48696+00",
      "observed_since": "2026-07-29",
      "source": "scan",
      "summary": "Provenance (fail → unverified)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fb201-73e7-7ec9-ab9c-406a280274fd"
    },
    {
      "id": "chg_019fb201-73e8-774c-8a51-938b4a8571b5",
      "kind": "check.unverifiable",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.inconclusive",
      "from_value": "fail",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "resolver_unavailable"
      },
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 07:51:07.48696+00",
      "observed_since": "2026-07-29",
      "source": "scan",
      "summary": "Known CVEs (fail → unverified)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fb201-73e8-774c-8a51-938b4a8571b5"
    },
    {
      "id": "chg_019fb201-73e8-7f2a-8848-2817ea170612",
      "kind": "check.unverifiable",
      "family": "install-scripts",
      "subject_kind": "check",
      "subject": "install-scripts",
      "subject_child": "",
      "from_code": "installscript.none",
      "to_code": "installscript.inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 07:51:07.48696+00",
      "observed_since": "2026-07-29",
      "source": "scan",
      "summary": "Install scripts (pass → unverified)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fb201-73e8-7f2a-8848-2817ea170612"
    },
    {
      "id": "chg_019fb201-73e9-7587-84a2-60c828dfb0f8",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-27125",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.inconclusive",
      "from_value": "medium",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-27125"
      },
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 07:51:07.48696+00",
      "observed_since": "2026-07-29",
      "source": "scan",
      "summary": "CVE-2026-27125 no longer affects this package",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fb201-73e9-7587-84a2-60c828dfb0f8"
    },
    {
      "id": "chg_019fb201-73e9-79c8-9418-003ea2727a7f",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-42599",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.inconclusive",
      "from_value": "medium",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-42599"
      },
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 07:51:07.48696+00",
      "observed_since": "2026-07-29",
      "source": "scan",
      "summary": "CVE-2026-42599 no longer affects this package",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fb201-73e9-79c8-9418-003ea2727a7f"
    },
    {
      "id": "chg_019fb201-73e9-7f14-8544-70754215e09c",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-27121",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.inconclusive",
      "from_value": "medium",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-27121"
      },
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 07:51:07.48696+00",
      "observed_since": "2026-07-29",
      "source": "scan",
      "summary": "CVE-2026-27121 no longer affects this package",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fb201-73e9-7f14-8544-70754215e09c"
    },
    {
      "id": "chg_019fb201-73ea-741b-a609-a880b9f2f6b7",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-27901",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.inconclusive",
      "from_value": "medium",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-27901"
      },
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 07:51:07.48696+00",
      "observed_since": "2026-07-29",
      "source": "scan",
      "summary": "CVE-2026-27901 no longer affects this package",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fb201-73ea-741b-a609-a880b9f2f6b7"
    },
    {
      "id": "chg_019fb201-73ea-788c-a52b-1b289a01e3c2",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-42573",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.inconclusive",
      "from_value": "medium",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-42573"
      },
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 07:51:07.48696+00",
      "observed_since": "2026-07-29",
      "source": "scan",
      "summary": "CVE-2026-42573 no longer affects this package",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fb201-73ea-788c-a52b-1b289a01e3c2"
    },
    {
      "id": "chg_019fb201-73ea-7d57-9671-206e13caa0a4",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-27122",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.inconclusive",
      "from_value": "medium",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-27122"
      },
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 07:51:07.48696+00",
      "observed_since": "2026-07-29",
      "source": "scan",
      "summary": "CVE-2026-27122 no longer affects this package",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fb201-73ea-7d57-9671-206e13caa0a4"
    },
    {
      "id": "chg_019fa652-a8d7-7bb5-a0c2-6d9cefae3175",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-27901",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-27901",
        "severity": "medium"
      },
      "occurred_on": "2026-07-28",
      "occurred_at": "2026-07-28 01:24:22.863314+00",
      "observed_since": "2026-07-27",
      "source": "scan",
      "summary": "CVE-2026-27901 affects this package (medium)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fa652-a8d7-7bb5-a0c2-6d9cefae3175"
    },
    {
      "id": "chg_019fa652-a8d8-723b-af41-5efd95c6e208",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-27122",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-27122",
        "severity": "medium"
      },
      "occurred_on": "2026-07-28",
      "occurred_at": "2026-07-28 01:24:22.863314+00",
      "observed_since": "2026-07-27",
      "source": "scan",
      "summary": "CVE-2026-27122 affects this package (medium)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fa652-a8d8-723b-af41-5efd95c6e208"
    },
    {
      "id": "chg_019fa652-a8d8-75fd-8415-a23d4c2acb0f",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-42573",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-42573",
        "severity": "medium"
      },
      "occurred_on": "2026-07-28",
      "occurred_at": "2026-07-28 01:24:22.863314+00",
      "observed_since": "2026-07-27",
      "source": "scan",
      "summary": "CVE-2026-42573 affects this package (medium)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fa652-a8d8-75fd-8415-a23d4c2acb0f"
    },
    {
      "id": "chg_019fa652-a8d8-7a0d-87d8-b7871c366198",
      "kind": "check.reverified",
      "family": "build-provenance",
      "subject_kind": "check",
      "subject": "build-provenance",
      "subject_child": "",
      "from_code": "provenance.inconclusive",
      "to_code": "provenance.none",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-07-28",
      "occurred_at": "2026-07-28 01:24:22.863314+00",
      "observed_since": "2026-07-27",
      "source": "scan",
      "summary": "Provenance (unverified → fail)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fa652-a8d8-7a0d-87d8-b7871c366198"
    },
    {
      "id": "chg_019fa652-a8d9-760e-b63e-7cb50aea68d8",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-27125",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-27125",
        "severity": "medium"
      },
      "occurred_on": "2026-07-28",
      "occurred_at": "2026-07-28 01:24:22.863314+00",
      "observed_since": "2026-07-27",
      "source": "scan",
      "summary": "CVE-2026-27125 affects this package (medium)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fa652-a8d9-760e-b63e-7cb50aea68d8"
    },
    {
      "id": "chg_019fa652-a8d9-7bbf-aaa8-742c2330b1ca",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.transitive",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "@hcengineering/activity > @hcengineering/ui > svelte",
        "refs": "[\"CVE-2026-27125\",\"CVE-2026-27121\",\"CVE-2026-27122\",\"CVE-2026-27901\",\"CVE-2026-42599\",\"CVE-2026-42573\"]",
        "seen": "87",
        "package": "svelte",
        "version": "4.2.20",
        "assessed": "88",
        "resolved": "87",
        "severity": "medium",
        "transitive": "1",
        "vulnerable": "[{\"name\":\"svelte\",\"version\":\"4.2.20\",\"depth\":3,\"path\":[\"@hcengineering/activity\",\"@hcengineering/ui\",\"svelte\"],\"refs\":[\"CVE-2026-27125\",\"CVE-2026-27121\",\"CVE-2026-27122\",\"CVE-2026-27901\",\"CVE-2026-42599\",\"CVE-2026-42573\"]}]",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-07-28",
      "occurred_at": "2026-07-28 01:24:22.863314+00",
      "observed_since": "2026-07-27",
      "source": "scan",
      "summary": "Known CVEs (unverified → fail)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fa652-a8d9-7bbf-aaa8-742c2330b1ca"
    },
    {
      "id": "chg_019fa652-a8da-717b-857f-e4d9c42484b9",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-42599",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-42599",
        "severity": "medium"
      },
      "occurred_on": "2026-07-28",
      "occurred_at": "2026-07-28 01:24:22.863314+00",
      "observed_since": "2026-07-27",
      "source": "scan",
      "summary": "CVE-2026-42599 affects this package (medium)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fa652-a8da-717b-857f-e4d9c42484b9"
    },
    {
      "id": "chg_019fa652-a8db-7ce2-9c5f-6fca1af730d7",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-27121",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-27121",
        "severity": "medium"
      },
      "occurred_on": "2026-07-28",
      "occurred_at": "2026-07-28 01:24:22.863314+00",
      "observed_since": "2026-07-27",
      "source": "scan",
      "summary": "CVE-2026-27121 affects this package (medium)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fa652-a8db-7ce2-9c5f-6fca1af730d7"
    },
    {
      "id": "chg_019fa652-a8dc-722a-ade1-87f9c0f99225",
      "kind": "check.reverified",
      "family": "install-scripts",
      "subject_kind": "check",
      "subject": "install-scripts",
      "subject_child": "",
      "from_code": "installscript.inconclusive",
      "to_code": "installscript.none",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "tier": "none"
      },
      "occurred_on": "2026-07-28",
      "occurred_at": "2026-07-28 01:24:22.863314+00",
      "observed_since": "2026-07-27",
      "source": "scan",
      "summary": "Install scripts (unverified → pass)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fa652-a8dc-722a-ade1-87f9c0f99225"
    },
    {
      "id": "chg_019fa18f-087b-75ae-ac2f-e45228808857",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-07-27",
      "occurred_at": "2026-07-27 03:12:13.412727+00",
      "observed_since": "2026-07-26",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/dearlordylord-huly-mcp/firfi-huly-mcp#chg-chg_019fa18f-087b-75ae-ac2f-e45228808857"
    }
  ],
  "days": [
    {
      "date": "2026-09-22",
      "total": 38,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-14",
      "total": 38,
      "delta": 10,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 2
    },
    {
      "date": "2026-09-13",
      "total": 28,
      "delta": -10,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 3
    },
    {
      "date": "2026-09-07",
      "total": 38,
      "delta": 10,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 2
    },
    {
      "date": "2026-09-06",
      "total": 28,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 10
    },
    {
      "date": "2026-09-05",
      "total": 28,
      "delta": -10,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 8
    },
    {
      "date": "2026-09-02",
      "total": 38,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 5
    },
    {
      "date": "2026-09-01",
      "total": 38,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 6
    }
  ]
}