{
  "$schema": "https://verifymcp.io/schemas/changelog.json",
  "server": "nirholas-xactions",
  "component": "xactions",
  "generated_at": "2026-09-21T01:45:22.114Z",
  "tracking_since": "2026-07-27",
  "counts": {
    "critical": 0,
    "security": 29,
    "functional": 0,
    "cosmetic": 0
  },
  "events": [
    {
      "id": "chg_01a0a355-545c-7be7-8345-4cf1571ffabf",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-82417",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.transitive",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-82417"
      },
      "occurred_on": "2026-09-15",
      "occurred_at": "2026-09-15 04:31:13.25892+00",
      "observed_since": "2026-09-14",
      "source": "scan",
      "summary": "CVE-2026-82417 no longer affects this package",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_01a0a355-545c-7be7-8345-4cf1571ffabf"
    },
    {
      "id": "chg_01a0a355-545d-7d33-ac63-ae999d8aed29",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-82562",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.transitive",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-82562"
      },
      "occurred_on": "2026-09-15",
      "occurred_at": "2026-09-15 04:31:13.25892+00",
      "observed_since": "2026-09-14",
      "source": "scan",
      "summary": "CVE-2026-82562 no longer affects this package",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_01a0a355-545d-7d33-ac63-ae999d8aed29"
    },
    {
      "id": "chg_01a06582-49cc-72ca-af43-6f0a658f1f1a",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-82417",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-82417",
        "severity": "high"
      },
      "occurred_on": "2026-09-03",
      "occurred_at": "2026-09-03 04:23:52.30844+00",
      "observed_since": "2026-09-02",
      "source": "scan",
      "summary": "CVE-2026-82417 affects this package (high)",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_01a06582-49cc-72ca-af43-6f0a658f1f1a"
    },
    {
      "id": "chg_01a06582-49cd-7616-b82c-4eb1c2ae1312",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-82562",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-82562",
        "severity": "high"
      },
      "occurred_on": "2026-09-03",
      "occurred_at": "2026-09-03 04:23:52.30844+00",
      "observed_since": "2026-09-02",
      "source": "scan",
      "summary": "CVE-2026-82562 affects this package (high)",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_01a06582-49cd-7616-b82c-4eb1c2ae1312"
    },
    {
      "id": "chg_01a01d69-9fea-7d14-a91a-650b743cb19e",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_pending",
      "to_code": "stability.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "needs_declared_env",
        "status": "unreachable"
      },
      "occurred_on": "2026-08-20",
      "occurred_at": "2026-08-20 04:24:16.488015+00",
      "observed_since": "2026-08-19",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: this server's registry entry declares environment variables (an API key or similar) that our sandbox does not supply, so we have no schema to compare.)",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_01a01d69-9fea-7d14-a91a-650b743cb19e"
    },
    {
      "id": "chg_01a01c42-5054-77ae-9ec0-a890efc12104",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "GHSA-vvjj-xcjg-gr5g",
      "subject_child": "",
      "from_code": "cve.direct",
      "to_code": "cve.transitive",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "GHSA-vvjj-xcjg-gr5g"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 23:01:42.892507+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "GHSA-vvjj-xcjg-gr5g no longer affects this package",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_01a01c42-5054-77ae-9ec0-a890efc12104"
    },
    {
      "id": "chg_01a01c42-5050-7048-9103-fe708f892b1f",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "GHSA-268h-hp4c-crq3",
      "subject_child": "",
      "from_code": "cve.direct",
      "to_code": "cve.transitive",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "GHSA-268h-hp4c-crq3"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 23:01:42.892507+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "GHSA-268h-hp4c-crq3 no longer affects this package",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_01a01c42-5050-7048-9103-fe708f892b1f"
    },
    {
      "id": "chg_01a01c42-5053-70a7-89d6-d9a2238475dd",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "GHSA-p6gq-j5cr-w38f",
      "subject_child": "",
      "from_code": "cve.direct",
      "to_code": "cve.transitive",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "GHSA-p6gq-j5cr-w38f"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 23:01:42.892507+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "GHSA-p6gq-j5cr-w38f no longer affects this package",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_01a01c42-5053-70a7-89d6-d9a2238475dd"
    },
    {
      "id": "chg_01a01c42-5053-74ed-85d6-95637f15c4de",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2025-13033",
      "subject_child": "",
      "from_code": "cve.direct",
      "to_code": "cve.transitive",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2025-13033"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 23:01:42.892507+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "CVE-2025-13033 no longer affects this package",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_01a01c42-5053-74ed-85d6-95637f15c4de"
    },
    {
      "id": "chg_01a01c42-5053-7900-a0a4-60e91c930030",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "GHSA-c7w3-x93f-qmm8",
      "subject_child": "",
      "from_code": "cve.direct",
      "to_code": "cve.transitive",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "GHSA-c7w3-x93f-qmm8"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 23:01:42.892507+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "GHSA-c7w3-x93f-qmm8 no longer affects this package",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_01a01c42-5053-7900-a0a4-60e91c930030"
    },
    {
      "id": "chg_01a01c42-5053-7d0a-b654-ca6212f9f565",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2025-14874",
      "subject_child": "",
      "from_code": "cve.direct",
      "to_code": "cve.transitive",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2025-14874"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 23:01:42.892507+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "CVE-2025-14874 no longer affects this package",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_01a01c42-5053-7d0a-b654-ca6212f9f565"
    },
    {
      "id": "chg_01a01c42-5054-7298-98b2-cba404073d28",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "GHSA-r7g4-qg5f-qqm2",
      "subject_child": "",
      "from_code": "cve.direct",
      "to_code": "cve.transitive",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "GHSA-r7g4-qg5f-qqm2"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 23:01:42.892507+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "GHSA-r7g4-qg5f-qqm2 no longer affects this package",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_01a01c42-5054-7298-98b2-cba404073d28"
    },
    {
      "id": "chg_01a01c42-5055-7543-b258-0562a7d7d389",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "GHSA-wqvq-jvpq-h66f",
      "subject_child": "",
      "from_code": "cve.direct",
      "to_code": "cve.transitive",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "GHSA-wqvq-jvpq-h66f"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 23:01:42.892507+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "GHSA-wqvq-jvpq-h66f no longer affects this package",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_01a01c42-5055-7543-b258-0562a7d7d389"
    },
    {
      "id": "chg_01a01c42-5055-7e87-9496-38540fcfbd97",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_failed",
      "to_code": "stability.sandbox_pending",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "reason": "version_superseded"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 23:01:42.892507+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.)",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_01a01c42-5055-7e87-9496-38540fcfbd97"
    },
    {
      "id": "chg_01a01c42-5056-7aa4-9e37-852d3a5011f3",
      "kind": "check.reason",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.direct",
      "to_code": "cve.transitive",
      "from_value": "fail",
      "to_value": "fail",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "path": "bull > uuid",
        "refs": "[\"CVE-2026-41907\"]",
        "seen": "749",
        "package": "uuid",
        "version": "8.3.2",
        "assessed": "401",
        "resolved": "400",
        "severity": "high",
        "transitive": "1",
        "unresolved": "349",
        "vulnerable": "[{\"name\":\"uuid\",\"version\":\"8.3.2\",\"depth\":2,\"path\":[\"bull\",\"uuid\"],\"refs\":[\"CVE-2026-41907\"]}]",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 23:01:42.892507+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "Known CVEs (CVE check failed: a known high-severity CVE affects uuid 8.3.2, reached via bull > uuid. A fixed version is available.)",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_01a01c42-5056-7aa4-9e37-852d3a5011f3"
    },
    {
      "id": "chg_019fc4c6-8faf-70ce-a870-7b510fd13d5f",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "GHSA-r7g4-qg5f-qqm2",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "GHSA-r7g4-qg5f-qqm2",
        "severity": "high"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:19:35.069288+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "GHSA-r7g4-qg5f-qqm2 affects this package (high)",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_019fc4c6-8faf-70ce-a870-7b510fd13d5f"
    },
    {
      "id": "chg_019fc4c6-8fb0-70fc-9b89-fcf4a9fbaf4c",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "GHSA-268h-hp4c-crq3",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "GHSA-268h-hp4c-crq3",
        "severity": "high"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:19:35.069288+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "GHSA-268h-hp4c-crq3 affects this package (high)",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_019fc4c6-8fb0-70fc-9b89-fcf4a9fbaf4c"
    },
    {
      "id": "chg_019fc4c6-8fb0-7763-a800-05bb50e8b573",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "GHSA-p6gq-j5cr-w38f",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "GHSA-p6gq-j5cr-w38f",
        "severity": "high"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:19:35.069288+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "GHSA-p6gq-j5cr-w38f affects this package (high)",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_019fc4c6-8fb0-7763-a800-05bb50e8b573"
    },
    {
      "id": "chg_019fc4c6-8fb0-7d18-8d3a-238f6909c844",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "GHSA-wqvq-jvpq-h66f",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "GHSA-wqvq-jvpq-h66f",
        "severity": "high"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:19:35.069288+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "GHSA-wqvq-jvpq-h66f affects this package (high)",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_019fc4c6-8fb0-7d18-8d3a-238f6909c844"
    },
    {
      "id": "chg_019fc4c6-8fb1-7363-881e-725b77f08b54",
      "kind": "check.reverified",
      "family": "build-provenance",
      "subject_kind": "check",
      "subject": "build-provenance",
      "subject_child": "",
      "from_code": "provenance.inconclusive",
      "to_code": "provenance.none",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:19:35.069288+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Provenance (unverified → fail)",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_019fc4c6-8fb1-7363-881e-725b77f08b54"
    },
    {
      "id": "chg_019fc4c6-8fb1-7843-ba92-b1f786f0dcc1",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-41907",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-41907",
        "severity": "high"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:19:35.069288+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "CVE-2026-41907 affects this package (high)",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_019fc4c6-8fb1-7843-ba92-b1f786f0dcc1"
    },
    {
      "id": "chg_019fc4c6-8fb2-7258-b3f2-354c45c6fc9a",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.direct",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "nodemailer",
        "refs": "[\"GHSA-268h-hp4c-crq3\",\"GHSA-c7w3-x93f-qmm8\",\"CVE-2025-13033\",\"GHSA-p6gq-j5cr-w38f\",\"GHSA-r7g4-qg5f-qqm2\",\"CVE-2025-14874\",\"GHSA-vvjj-xcjg-gr5g\",\"GHSA-wqvq-jvpq-h66f\",\"CVE-2026-41907\"]",
        "seen": "646",
        "direct": "1",
        "package": "nodemailer",
        "version": "6.10.1",
        "assessed": "251",
        "resolved": "250",
        "severity": "high",
        "transitive": "1",
        "unresolved": "396",
        "vulnerable": "[{\"name\":\"nodemailer\",\"version\":\"6.10.1\",\"depth\":1,\"path\":[\"nodemailer\"],\"refs\":[\"GHSA-268h-hp4c-crq3\",\"GHSA-c7w3-x93f-qmm8\",\"CVE-2025-13033\",\"GHSA-p6gq-j5cr-w38f\",\"GHSA-r7g4-qg5f-qqm2\",\"CVE-2025-14874\",\"GHSA-vvjj-xcjg-gr5g\",\"GHSA-wqvq-jvpq-h66f\"]},{\"name\":\"uuid\",\"version\":\"8.3.2\",\"depth\":2,\"path\":[\"bull\",\"uuid\"],\"refs\":[\"CVE-2026-41907\"]}]",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:19:35.069288+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Known CVEs (unverified → fail)",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_019fc4c6-8fb2-7258-b3f2-354c45c6fc9a"
    },
    {
      "id": "chg_019fc4c6-8fb2-774c-a191-2f90f15d04f0",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2025-13033",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2025-13033",
        "severity": "high"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:19:35.069288+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "CVE-2025-13033 affects this package (high)",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_019fc4c6-8fb2-774c-a191-2f90f15d04f0"
    },
    {
      "id": "chg_019fc4c6-8fb3-7381-ba02-f53b0bd07b68",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "GHSA-c7w3-x93f-qmm8",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "GHSA-c7w3-x93f-qmm8",
        "severity": "high"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:19:35.069288+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "GHSA-c7w3-x93f-qmm8 affects this package (high)",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_019fc4c6-8fb3-7381-ba02-f53b0bd07b68"
    },
    {
      "id": "chg_019fc4c6-8fb3-7800-9426-ef880c8e35a8",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "GHSA-vvjj-xcjg-gr5g",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "GHSA-vvjj-xcjg-gr5g",
        "severity": "high"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:19:35.069288+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "GHSA-vvjj-xcjg-gr5g affects this package (high)",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_019fc4c6-8fb3-7800-9426-ef880c8e35a8"
    },
    {
      "id": "chg_019fc4c6-8fb3-7ce1-a9bc-e3630d0b5595",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2025-14874",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2025-14874",
        "severity": "high"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:19:35.069288+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "CVE-2025-14874 affects this package (high)",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_019fc4c6-8fb3-7ce1-a9bc-e3630d0b5595"
    },
    {
      "id": "chg_019fc4c6-8fb4-714a-a789-ca294ce0e0bf",
      "kind": "check.reverified",
      "family": "install-scripts",
      "subject_kind": "check",
      "subject": "install-scripts",
      "subject_child": "",
      "from_code": "installscript.inconclusive",
      "to_code": "installscript.none",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "tier": "none"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:19:35.069288+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Install scripts (unverified → pass)",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_019fc4c6-8fb4-714a-a789-ca294ce0e0bf"
    },
    {
      "id": "chg_019fc2bb-10f9-7e1a-a7ab-de01d806e1cf",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_pending",
      "to_code": "stability.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "status": "failed"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 13:47:47.270936+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: our sandbox run of this package did not complete, so we have no schema to compare.)",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_019fc2bb-10f9-7e1a-a7ab-de01d806e1cf"
    },
    {
      "id": "chg_019fb72e-01a3-7ea2-9ad1-a214c11a41bd",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-07-31",
      "occurred_at": "2026-07-31 07:57:53.423417+00",
      "observed_since": "2026-07-30",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/nirholas-xactions/xactions#chg-chg_019fb72e-01a3-7ea2-9ad1-a214c11a41bd"
    }
  ],
  "days": [
    {
      "date": "2026-09-17",
      "total": 34,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-16",
      "total": 34,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-15",
      "total": 34,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 2
    },
    {
      "date": "2026-09-12",
      "total": 34,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-11",
      "total": 34,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-05",
      "total": 34,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-04",
      "total": 34,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-03",
      "total": 34,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 2
    }
  ]
}