{
  "$schema": "https://verifymcp.io/schemas/changelog.json",
  "server": "jagilber-org-index-server",
  "component": "jagilber-org-index-server",
  "generated_at": "2026-09-21T03:31:02.508Z",
  "tracking_since": "2026-07-27",
  "counts": {
    "critical": 0,
    "security": 19,
    "functional": 0,
    "cosmetic": 0
  },
  "events": [
    {
      "id": "chg_01a0b8f9-b9f6-769e-88d1-819353b08b49",
      "kind": "check.verdict",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.building_history",
      "to_code": "stability.stable",
      "from_value": "0.97",
      "to_value": "pass",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-19",
      "occurred_at": "2026-09-19 09:22:48.919111+00",
      "observed_since": "2026-09-18",
      "source": "scan",
      "summary": "Stability (0.97 → pass)",
      "link": "https://verifymcp.io/servers/jagilber-org-index-server/jagilber-org-index-server#chg-chg_01a0b8f9-b9f6-769e-88d1-819353b08b49"
    },
    {
      "id": "chg_01a0a988-c339-7137-b6b9-6e83a699ae0b",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-16",
      "occurred_at": "2026-09-16 09:25:07.264463+00",
      "observed_since": "2026-09-15",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/jagilber-org-index-server/jagilber-org-index-server#chg-chg_01a0a988-c339-7137-b6b9-6e83a699ae0b"
    },
    {
      "id": "chg_01a0a57c-bf38-76ba-94f9-b7ba4d2fbfea",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "vendor_not_cached"
      },
      "occurred_on": "2026-09-15",
      "occurred_at": "2026-09-15 14:33:30.913529+00",
      "observed_since": "2026-09-14",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/jagilber-org-index-server/jagilber-org-index-server#chg-chg_01a0a57c-bf38-76ba-94f9-b7ba4d2fbfea"
    },
    {
      "id": "chg_01a0a57c-bf3c-7e0a-a7b4-ddc93855f789",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-39244",
      "subject_child": "",
      "from_code": "cve.direct",
      "to_code": "cve.transitive",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-39244"
      },
      "occurred_on": "2026-09-15",
      "occurred_at": "2026-09-15 14:33:30.913529+00",
      "observed_since": "2026-09-14",
      "source": "scan",
      "summary": "CVE-2026-39244 no longer affects this package",
      "link": "https://verifymcp.io/servers/jagilber-org-index-server/jagilber-org-index-server#chg-chg_01a0a57c-bf3c-7e0a-a7b4-ddc93855f789"
    },
    {
      "id": "chg_01a0a57c-bf3e-7b22-bcdd-812981f5e33a",
      "kind": "check.reason",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.direct",
      "to_code": "cve.transitive",
      "from_value": "fail",
      "to_value": "fail",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "path": "@huggingface/transformers > sharp",
        "refs": "[\"GHSA-f88m-g3jw-g9cj\",\"GHSA-rgj7-g3m4-5g8c\"]",
        "seen": "245",
        "package": "sharp",
        "version": "0.34.5",
        "assessed": "246",
        "resolved": "245",
        "severity": "high",
        "transitive": "1",
        "vulnerable": "[{\"name\":\"sharp\",\"version\":\"0.34.5\",\"depth\":2,\"path\":[\"@huggingface/transformers\",\"sharp\"],\"refs\":[\"GHSA-f88m-g3jw-g9cj\",\"GHSA-rgj7-g3m4-5g8c\"]}]",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-09-15",
      "occurred_at": "2026-09-15 14:33:30.913529+00",
      "observed_since": "2026-09-14",
      "source": "scan",
      "summary": "Known CVEs (CVE check failed: a known high-severity CVE affects sharp 0.34.5, reached via @huggingface/transformers > sharp. A fixed version is available.)",
      "link": "https://verifymcp.io/servers/jagilber-org-index-server/jagilber-org-index-server#chg-chg_01a0a57c-bf3e-7b22-bcdd-812981f5e33a"
    },
    {
      "id": "chg_01a094ed-4116-72cc-8716-9615a62008ed",
      "kind": "check.verdict",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.building_history",
      "to_code": "stability.stable",
      "from_value": "0.97",
      "to_value": "pass",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-12",
      "occurred_at": "2026-09-12 09:22:51.71439+00",
      "observed_since": "2026-09-11",
      "source": "scan",
      "summary": "Stability (0.97 → pass)",
      "link": "https://verifymcp.io/servers/jagilber-org-index-server/jagilber-org-index-server#chg-chg_01a094ed-4116-72cc-8716-9615a62008ed"
    },
    {
      "id": "chg_01a08578-3feb-74e4-9556-78d533faf7c3",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "GHSA-rgj7-g3m4-5g8c",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "GHSA-rgj7-g3m4-5g8c",
        "severity": "high"
      },
      "occurred_on": "2026-09-09",
      "occurred_at": "2026-09-09 09:20:45.521222+00",
      "observed_since": "2026-09-08",
      "source": "scan",
      "summary": "GHSA-rgj7-g3m4-5g8c affects this package (high)",
      "link": "https://verifymcp.io/servers/jagilber-org-index-server/jagilber-org-index-server#chg-chg_01a08578-3feb-74e4-9556-78d533faf7c3"
    },
    {
      "id": "chg_01a06bc4-2259-78df-8b9d-fe85b974b9c5",
      "kind": "check.verdict",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.building_history",
      "to_code": "stability.stable",
      "from_value": "0.97",
      "to_value": "pass",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-04",
      "occurred_at": "2026-09-04 09:33:30.911044+00",
      "observed_since": "2026-09-03",
      "source": "scan",
      "summary": "Stability (0.97 → pass)",
      "link": "https://verifymcp.io/servers/jagilber-org-index-server/jagilber-org-index-server#chg-chg_01a06bc4-2259-78df-8b9d-fe85b974b9c5"
    },
    {
      "id": "chg_019fd445-0310-7a85-b42c-48fd6316b716",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_failed",
      "to_code": "stability.insufficient_history",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-05",
      "occurred_at": "2026-08-05 23:32:00.335776+00",
      "observed_since": "2026-08-04",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: not enough scan history yet (needs a 30-day window).)",
      "link": "https://verifymcp.io/servers/jagilber-org-index-server/jagilber-org-index-server#chg-chg_019fd445-0310-7a85-b42c-48fd6316b716"
    },
    {
      "id": "chg_019fc45a-1e88-74e2-a6a6-0efd6833acf4",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-39244",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-39244",
        "severity": "high"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 21:21:08.21756+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "CVE-2026-39244 affects this package (high)",
      "link": "https://verifymcp.io/servers/jagilber-org-index-server/jagilber-org-index-server#chg-chg_019fc45a-1e88-74e2-a6a6-0efd6833acf4"
    },
    {
      "id": "chg_019fc45a-1e89-7372-be85-8e1f2941dac7",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.direct",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "adm-zip",
        "refs": "[\"CVE-2026-39244\",\"GHSA-f88m-g3jw-g9cj\"]",
        "seen": "246",
        "direct": "1",
        "package": "adm-zip",
        "version": "0.5.18",
        "assessed": "245",
        "resolved": "244",
        "severity": "high",
        "transitive": "1",
        "unresolved": "2",
        "vulnerable": "[{\"name\":\"adm-zip\",\"version\":\"0.5.18\",\"depth\":1,\"path\":[\"adm-zip\"],\"refs\":[\"CVE-2026-39244\"]},{\"name\":\"sharp\",\"version\":\"0.34.5\",\"depth\":2,\"path\":[\"@huggingface/transformers\",\"sharp\"],\"refs\":[\"GHSA-f88m-g3jw-g9cj\"]}]",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 21:21:08.21756+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Known CVEs (unverified → fail)",
      "link": "https://verifymcp.io/servers/jagilber-org-index-server/jagilber-org-index-server#chg-chg_019fc45a-1e89-7372-be85-8e1f2941dac7"
    },
    {
      "id": "chg_019fc45a-1e89-78d0-9951-7ea28771dfd3",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "GHSA-f88m-g3jw-g9cj",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "GHSA-f88m-g3jw-g9cj",
        "severity": "high"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 21:21:08.21756+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "GHSA-f88m-g3jw-g9cj affects this package (high)",
      "link": "https://verifymcp.io/servers/jagilber-org-index-server/jagilber-org-index-server#chg-chg_019fc45a-1e89-78d0-9951-7ea28771dfd3"
    },
    {
      "id": "chg_019fc45a-1e8a-718e-844f-96efaa790865",
      "kind": "check.reverified",
      "family": "install-scripts",
      "subject_kind": "check",
      "subject": "install-scripts",
      "subject_child": "",
      "from_code": "installscript.inconclusive",
      "to_code": "installscript.none",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "tier": "none"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 21:21:08.21756+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Install scripts (unverified → pass)",
      "link": "https://verifymcp.io/servers/jagilber-org-index-server/jagilber-org-index-server#chg-chg_019fc45a-1e8a-718e-844f-96efaa790865"
    },
    {
      "id": "chg_019fc45a-1e8a-75b7-a62a-5f2f8fbac05e",
      "kind": "check.reverified",
      "family": "build-provenance",
      "subject_kind": "check",
      "subject": "build-provenance",
      "subject_child": "",
      "from_code": "provenance.inconclusive",
      "to_code": "provenance.verified",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "repo": "jagilber-org/index-server"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 21:21:08.21756+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Provenance (unverified → pass)",
      "link": "https://verifymcp.io/servers/jagilber-org-index-server/jagilber-org-index-server#chg-chg_019fc45a-1e8a-75b7-a62a-5f2f8fbac05e"
    },
    {
      "id": "chg_019fc45a-1e8a-7a67-a03c-d2058acdfdd8",
      "kind": "provenance.repo_changed",
      "family": "build-provenance",
      "subject_kind": "package",
      "subject": "repo",
      "subject_child": "",
      "from_code": "provenance.inconclusive",
      "to_code": "provenance.verified",
      "from_value": null,
      "to_value": "jagilber-org/index-server",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "to": "jagilber-org/index-server",
        "from": ""
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 21:21:08.21756+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "The attested source repository moved (jagilber-org/index-server)",
      "link": "https://verifymcp.io/servers/jagilber-org-index-server/jagilber-org-index-server#chg-chg_019fc45a-1e8a-7a67-a03c-d2058acdfdd8"
    },
    {
      "id": "chg_019fc382-b7fe-7cc6-9d7e-5d3d378fb3ef",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 17:25:51.729898+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/jagilber-org-index-server/jagilber-org-index-server#chg-chg_019fc382-b7fe-7cc6-9d7e-5d3d378fb3ef"
    },
    {
      "id": "chg_019fc382-b7ff-7318-98af-e6f79b6de06d",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_pending",
      "to_code": "stability.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "status": "failed"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 17:25:51.729898+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: our sandbox run of this package did not complete, so we have no schema to compare.)",
      "link": "https://verifymcp.io/servers/jagilber-org-index-server/jagilber-org-index-server#chg-chg_019fc382-b7ff-7318-98af-e6f79b6de06d"
    },
    {
      "id": "chg_019fbed2-5592-74e6-80b8-ed014330c9e4",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_failed",
      "to_code": "stability.sandbox_pending",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-01",
      "occurred_at": "2026-08-01 19:34:43.334958+00",
      "observed_since": "2026-07-31",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.)",
      "link": "https://verifymcp.io/servers/jagilber-org-index-server/jagilber-org-index-server#chg-chg_019fbed2-5592-74e6-80b8-ed014330c9e4"
    },
    {
      "id": "chg_019fb1c1-ce6a-7341-be8d-9ccc2b426c65",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 06:41:36.353164+00",
      "observed_since": "2026-07-28",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/jagilber-org-index-server/jagilber-org-index-server#chg-chg_019fb1c1-ce6a-7341-be8d-9ccc2b426c65"
    }
  ],
  "days": [
    {
      "date": "2026-09-20",
      "total": 86,
      "delta": -3,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-19",
      "total": 89,
      "delta": 1,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-17",
      "total": 88,
      "delta": 1,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": {
        "category": "Stability & Change Management",
        "from": 90,
        "to": 93,
        "delta": 3,
        "others": [],
        "accrual": {
          "code": "stability.building_history",
          "from_days": 27,
          "to_days": 28
        },
        "partial": false,
        "compared_to": "2026-09-16",
        "summary": "No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes."
      },
      "event_count": 0
    },
    {
      "date": "2026-09-16",
      "total": 87,
      "delta": 15,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-15",
      "total": 72,
      "delta": -12,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 5
    },
    {
      "date": "2026-09-13",
      "total": 84,
      "delta": -3,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-12",
      "total": 87,
      "delta": 1,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-10",
      "total": 86,
      "delta": 1,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": {
        "category": "Stability & Change Management",
        "from": 90,
        "to": 93,
        "delta": 3,
        "others": [],
        "accrual": {
          "code": "stability.building_history",
          "from_days": 27,
          "to_days": 28
        },
        "partial": false,
        "compared_to": "2026-09-09",
        "summary": "No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes."
      },
      "event_count": 0
    }
  ]
}