{
  "$schema": "https://verifymcp.io/schemas/changelog.json",
  "server": "hugolsramos01-bit-mcp-agentic-server",
  "component": "mcp-agentic-server",
  "generated_at": "2026-09-28T16:19:32.995Z",
  "tracking_since": "2026-07-27",
  "counts": {
    "critical": 0,
    "security": 21,
    "functional": 0,
    "cosmetic": 0
  },
  "events": [
    {
      "id": "chg_01a0dbfa-4844-7413-9297-7e98898cef05",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-16729",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.tree_partial",
      "from_value": null,
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-16729"
      },
      "occurred_on": "2026-09-26",
      "occurred_at": "2026-09-26 04:30:07.821274+00",
      "observed_since": "2026-09-25",
      "source": "scan",
      "summary": "CVE-2026-16729 no longer affects this package",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_01a0dbfa-4844-7413-9297-7e98898cef05"
    },
    {
      "id": "chg_01a0dbfa-4845-7794-92d4-91fd7860371f",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-13697",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.tree_partial",
      "from_value": null,
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-13697"
      },
      "occurred_on": "2026-09-26",
      "occurred_at": "2026-09-26 04:30:07.821274+00",
      "observed_since": "2026-09-25",
      "source": "scan",
      "summary": "CVE-2026-13697 no longer affects this package",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_01a0dbfa-4845-7794-92d4-91fd7860371f"
    },
    {
      "id": "chg_01a0dbfa-4846-7008-afd6-db091b7e9df5",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-15157",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.tree_partial",
      "from_value": null,
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-15157"
      },
      "occurred_on": "2026-09-26",
      "occurred_at": "2026-09-26 04:30:07.821274+00",
      "observed_since": "2026-09-25",
      "source": "scan",
      "summary": "CVE-2026-15157 no longer affects this package",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_01a0dbfa-4846-7008-afd6-db091b7e9df5"
    },
    {
      "id": "chg_01a0dbfa-4846-78ab-9210-ed13bbd3eb43",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-16728",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.tree_partial",
      "from_value": null,
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-16728"
      },
      "occurred_on": "2026-09-26",
      "occurred_at": "2026-09-26 04:30:07.821274+00",
      "observed_since": "2026-09-25",
      "source": "scan",
      "summary": "CVE-2026-16728 no longer affects this package",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_01a0dbfa-4846-78ab-9210-ed13bbd3eb43"
    },
    {
      "id": "chg_01a0dbfa-4847-7021-9a26-d999954e52be",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-14643",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.tree_partial",
      "from_value": null,
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-14643"
      },
      "occurred_on": "2026-09-26",
      "occurred_at": "2026-09-26 04:30:07.821274+00",
      "observed_since": "2026-09-25",
      "source": "scan",
      "summary": "CVE-2026-14643 no longer affects this package",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_01a0dbfa-4847-7021-9a26-d999954e52be"
    },
    {
      "id": "chg_01a0dbfa-4848-7310-8c41-78a61e74dee7",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.tree_partial",
      "from_value": "unverified",
      "to_value": "partial",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "342",
        "assessed": "342",
        "resolved": "341",
        "unresolved": "1",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-09-26",
      "occurred_at": "2026-09-26 04:30:07.821274+00",
      "observed_since": "2026-09-25",
      "source": "scan",
      "summary": "Known CVEs (unverified → partial)",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_01a0dbfa-4848-7310-8c41-78a61e74dee7"
    },
    {
      "id": "chg_01a0d9f0-afaa-707e-a584-9684a694f38f",
      "kind": "check.unverifiable",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.inconclusive",
      "from_value": "fail",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "root_version_missing"
      },
      "occurred_on": "2026-09-25",
      "occurred_at": "2026-09-25 19:00:22.909457+00",
      "observed_since": "2026-09-24",
      "source": "scan",
      "summary": "Known CVEs (fail → unverified)",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_01a0d9f0-afaa-707e-a584-9684a694f38f"
    },
    {
      "id": "chg_019fcb03-4b8d-757f-a06d-d80285780ba5",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.tree_partial",
      "to_code": "cve.transitive",
      "from_value": "partial",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "@earendil-works/pi-coding-agent > undici",
        "refs": "[\"CVE-2026-13697\",\"CVE-2026-16728\",\"CVE-2026-14643\",\"CVE-2026-15157\",\"CVE-2026-16729\"]",
        "seen": "367",
        "package": "undici",
        "version": "8.5.0",
        "assessed": "251",
        "resolved": "250",
        "severity": "high",
        "transitive": "1",
        "unresolved": "117",
        "vulnerable": "[{\"name\":\"undici\",\"version\":\"8.5.0\",\"depth\":2,\"path\":[\"@earendil-works/pi-coding-agent\",\"undici\"],\"refs\":[\"CVE-2026-13697\",\"CVE-2026-16728\",\"CVE-2026-14643\",\"CVE-2026-15157\",\"CVE-2026-16729\"]}]",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 04:23:38.62176+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "Known CVEs (partial → fail)",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_019fcb03-4b8d-757f-a06d-d80285780ba5"
    },
    {
      "id": "chg_019fcb03-4b8e-75d7-9648-1bf4dcca7ad2",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-13697",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-13697",
        "severity": "high"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 04:23:38.62176+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "CVE-2026-13697 affects this package (high)",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_019fcb03-4b8e-75d7-9648-1bf4dcca7ad2"
    },
    {
      "id": "chg_019fcb03-4b8e-79f4-ab8d-3e5c8d6c7877",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-14643",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-14643",
        "severity": "high"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 04:23:38.62176+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "CVE-2026-14643 affects this package (high)",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_019fcb03-4b8e-79f4-ab8d-3e5c8d6c7877"
    },
    {
      "id": "chg_019fcb03-4b8e-7ea2-ae0c-a18cfc37b951",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-16728",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-16728",
        "severity": "high"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 04:23:38.62176+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "CVE-2026-16728 affects this package (high)",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_019fcb03-4b8e-7ea2-ae0c-a18cfc37b951"
    },
    {
      "id": "chg_019fcb03-4b8f-72c1-b144-29757db1434e",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-15157",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-15157",
        "severity": "high"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 04:23:38.62176+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "CVE-2026-15157 affects this package (high)",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_019fcb03-4b8f-72c1-b144-29757db1434e"
    },
    {
      "id": "chg_019fcb03-4b8f-76cc-bfd2-d28b0d04f8c8",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-16729",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-16729",
        "severity": "high"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 04:23:38.62176+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "CVE-2026-16729 affects this package (high)",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_019fcb03-4b8f-76cc-bfd2-d28b0d04f8c8"
    },
    {
      "id": "chg_019fc50b-4769-7111-b325-2763d403dbee",
      "kind": "check.reverified",
      "family": "install-scripts",
      "subject_kind": "check",
      "subject": "install-scripts",
      "subject_child": "",
      "from_code": "installscript.inconclusive",
      "to_code": "installscript.unreviewed",
      "from_value": "unverified",
      "to_value": "partial",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "hook": "postinstall",
        "tier": "unreviewed",
        "hooks": "postinstall",
        "command": "node scripts/fix-node-pty-permissions.mjs"
      },
      "occurred_on": "2026-08-03",
      "occurred_at": "2026-08-03 00:34:38.55224+00",
      "observed_since": "2026-08-02",
      "source": "scan",
      "summary": "Install scripts (unverified → partial)",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_019fc50b-4769-7111-b325-2763d403dbee"
    },
    {
      "id": "chg_019fc50b-4768-7466-a855-8265d6e11c68",
      "kind": "check.reverified",
      "family": "build-provenance",
      "subject_kind": "check",
      "subject": "build-provenance",
      "subject_child": "",
      "from_code": "provenance.inconclusive",
      "to_code": "provenance.none",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-03",
      "occurred_at": "2026-08-03 00:34:38.55224+00",
      "observed_since": "2026-08-02",
      "source": "scan",
      "summary": "Provenance (unverified → fail)",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_019fc50b-4768-7466-a855-8265d6e11c68"
    },
    {
      "id": "chg_019fc50b-4769-772f-aa1f-cccd95e155cf",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.tree_partial",
      "from_value": "unverified",
      "to_value": "partial",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "367",
        "assessed": "251",
        "resolved": "250",
        "unresolved": "117",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-08-03",
      "occurred_at": "2026-08-03 00:34:38.55224+00",
      "observed_since": "2026-08-02",
      "source": "scan",
      "summary": "Known CVEs (unverified → partial)",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_019fc50b-4769-772f-aa1f-cccd95e155cf"
    },
    {
      "id": "chg_019fc50b-4769-7cc0-b292-b791473f79ba",
      "kind": "installscript.hooks_changed",
      "family": "install-scripts",
      "subject_kind": "package",
      "subject": "hooks",
      "subject_child": "",
      "from_code": "installscript.inconclusive",
      "to_code": "installscript.unreviewed",
      "from_value": null,
      "to_value": "postinstall",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "to": "postinstall",
        "from": ""
      },
      "occurred_on": "2026-08-03",
      "occurred_at": "2026-08-03 00:34:38.55224+00",
      "observed_since": "2026-08-02",
      "source": "scan",
      "summary": "The code this package runs automatically changed (postinstall)",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_019fc50b-4769-7cc0-b292-b791473f79ba"
    },
    {
      "id": "chg_019fc50b-476a-7240-a0b4-e3859bfcb233",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_pending",
      "to_code": "stability.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "status": "failed"
      },
      "occurred_on": "2026-08-03",
      "occurred_at": "2026-08-03 00:34:38.55224+00",
      "observed_since": "2026-08-02",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: our sandbox run of this package did not complete, so we have no schema to compare.)",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_019fc50b-476a-7240-a0b4-e3859bfcb233"
    },
    {
      "id": "chg_019fc144-04c7-7155-9344-cc68d1770aa9",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 06:58:08.130693+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_019fc144-04c7-7155-9344-cc68d1770aa9"
    },
    {
      "id": "chg_019fc144-04cb-7580-ac32-19a1f71316fb",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_failed",
      "to_code": "stability.sandbox_pending",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 06:58:08.130693+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.)",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_019fc144-04cb-7580-ac32-19a1f71316fb"
    },
    {
      "id": "chg_019fbd53-2bf8-7037-925e-bf4ad441f892",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_pending",
      "to_code": "stability.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "status": "failed"
      },
      "occurred_on": "2026-08-01",
      "occurred_at": "2026-08-01 12:36:12.384539+00",
      "observed_since": "2026-07-31",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: our sandbox run of this package did not complete, so we have no schema to compare.)",
      "link": "https://verifymcp.io/servers/hugolsramos01-bit-mcp-agentic-server/mcp-agentic-server#chg-chg_019fbd53-2bf8-7037-925e-bf4ad441f892"
    }
  ],
  "days": [
    {
      "date": "2026-09-28",
      "total": 37,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-26",
      "total": 37,
      "delta": 11,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 7
    },
    {
      "date": "2026-09-25",
      "total": 26,
      "delta": -9,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 4
    },
    {
      "date": "2026-09-23",
      "total": 35,
      "delta": 1,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-21",
      "total": 34,
      "delta": -1,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-08-26",
      "total": 0,
      "delta": null,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-08-25",
      "total": 0,
      "delta": null,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-08-13",
      "total": 0,
      "delta": null,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    }
  ]
}