{
  "$schema": "https://verifymcp.io/schemas/changelog.json",
  "server": "penny4nonsense-mcp-pymupdf",
  "component": "mcp-pymupdf",
  "generated_at": "2026-09-24T14:02:45.628Z",
  "tracking_since": "2026-07-27",
  "counts": {
    "critical": 0,
    "security": 28,
    "functional": 0,
    "cosmetic": 0
  },
  "events": [
    {
      "id": "chg_01a0c7a7-99fb-7852-bd11-3eacfb8548df",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "vendor_no_verdict"
      },
      "occurred_on": "2026-09-22",
      "occurred_at": "2026-09-22 05:47:24.845318+00",
      "observed_since": "2026-09-21",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_01a0c7a7-99fb-7852-bd11-3eacfb8548df"
    },
    {
      "id": "chg_01a0c1c9-b2a6-7ef1-a041-6aa118fc244a",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-21",
      "occurred_at": "2026-09-21 02:26:56.185439+00",
      "observed_since": "2026-09-20",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_01a0c1c9-b2a6-7ef1-a041-6aa118fc244a"
    },
    {
      "id": "chg_01a0b2fb-38e6-700c-ab1c-8ccd34e9c22b",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "vendor_no_verdict"
      },
      "occurred_on": "2026-09-18",
      "occurred_at": "2026-09-18 05:26:43.524639+00",
      "observed_since": "2026-09-17",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_01a0b2fb-38e6-700c-ab1c-8ccd34e9c22b"
    },
    {
      "id": "chg_01a0ad2d-e1fd-76c4-9ade-80d7b5435ff6",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-17",
      "occurred_at": "2026-09-17 02:24:20.340541+00",
      "observed_since": "2026-09-16",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_01a0ad2d-e1fd-76c4-9ade-80d7b5435ff6"
    },
    {
      "id": "chg_01a09e71-af4a-70d5-83d9-293da92849d9",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "vendor_no_verdict"
      },
      "occurred_on": "2026-09-14",
      "occurred_at": "2026-09-14 05:44:05.518864+00",
      "observed_since": "2026-09-13",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_01a09e71-af4a-70d5-83d9-293da92849d9"
    },
    {
      "id": "chg_01a07ed6-0c96-7ac6-904a-38d986d0b663",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2025-68146",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2025-68146",
        "severity": "medium"
      },
      "occurred_on": "2026-09-08",
      "occurred_at": "2026-09-08 02:25:52.06444+00",
      "observed_since": "2026-09-07",
      "source": "scan",
      "summary": "CVE-2025-68146 affects this package (medium)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_01a07ed6-0c96-7ac6-904a-38d986d0b663"
    },
    {
      "id": "chg_01a07ed6-0c9d-751f-b46c-fbbc6f4fc18f",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.tree_partial",
      "to_code": "cve.transitive",
      "from_value": "partial",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "hatch > virtualenv > filelock",
        "refs": "[\"CVE-2026-22701\",\"CVE-2025-68146\",\"CVE-2026-22701\",\"CVE-2025-68146\"]",
        "seen": "88",
        "package": "filelock",
        "version": "3.19.1",
        "assessed": "89",
        "resolved": "88",
        "severity": "medium",
        "transitive": "1",
        "vulnerable": "[{\"name\":\"filelock\",\"version\":\"3.19.1\",\"depth\":3,\"path\":[\"hatch\",\"virtualenv\",\"filelock\"],\"refs\":[\"CVE-2026-22701\",\"CVE-2025-68146\",\"CVE-2026-22701\",\"CVE-2025-68146\"]}]",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-09-08",
      "occurred_at": "2026-09-08 02:25:52.06444+00",
      "observed_since": "2026-09-07",
      "source": "scan",
      "summary": "Known CVEs (partial → fail)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_01a07ed6-0c9d-751f-b46c-fbbc6f4fc18f"
    },
    {
      "id": "chg_01a07ed6-0c9e-703d-ab48-175fc9ba2eb3",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-22701",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-22701",
        "severity": "medium"
      },
      "occurred_on": "2026-09-08",
      "occurred_at": "2026-09-08 02:25:52.06444+00",
      "observed_since": "2026-09-07",
      "source": "scan",
      "summary": "CVE-2026-22701 affects this package (medium)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_01a07ed6-0c9e-703d-ab48-175fc9ba2eb3"
    },
    {
      "id": "chg_01a079b1-367f-77aa-8b94-b9adff40bf82",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-22701",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.tree_partial",
      "from_value": "medium",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-22701"
      },
      "occurred_on": "2026-09-07",
      "occurred_at": "2026-09-07 02:27:32.014045+00",
      "observed_since": "2026-09-06",
      "source": "scan",
      "summary": "CVE-2026-22701 no longer affects this package",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_01a079b1-367f-77aa-8b94-b9adff40bf82"
    },
    {
      "id": "chg_01a079b1-3682-7c6f-b5b4-72513d985023",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.tree_partial",
      "from_value": "fail",
      "to_value": "partial",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "82",
        "assessed": "53",
        "resolved": "52",
        "unresolved": "30",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-09-07",
      "occurred_at": "2026-09-07 02:27:32.014045+00",
      "observed_since": "2026-09-06",
      "source": "scan",
      "summary": "Known CVEs (fail → partial)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_01a079b1-3682-7c6f-b5b4-72513d985023"
    },
    {
      "id": "chg_01a079b1-3683-713c-a1b5-cceb44d3563f",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2025-68146",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.tree_partial",
      "from_value": "medium",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2025-68146"
      },
      "occurred_on": "2026-09-07",
      "occurred_at": "2026-09-07 02:27:32.014045+00",
      "observed_since": "2026-09-06",
      "source": "scan",
      "summary": "CVE-2025-68146 no longer affects this package",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_01a079b1-3683-713c-a1b5-cceb44d3563f"
    },
    {
      "id": "chg_01a01d05-a066-733b-b9a5-524265a77199",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-20",
      "occurred_at": "2026-08-20 02:35:03.049143+00",
      "observed_since": "2026-08-19",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_01a01d05-a066-733b-b9a5-524265a77199"
    },
    {
      "id": "chg_01a017ce-0f82-7ade-93ca-906818fa9065",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "vendor_no_verdict"
      },
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 02:16:15.362625+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_01a017ce-0f82-7ade-93ca-906818fa9065"
    },
    {
      "id": "chg_01a012bb-db17-7b3c-967f-41c992c64121",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-18",
      "occurred_at": "2026-08-18 02:38:16.272306+00",
      "observed_since": "2026-08-17",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_01a012bb-db17-7b3c-967f-41c992c64121"
    },
    {
      "id": "chg_019ff8e7-4fb5-7b7c-8d69-2ef5a775518e",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "vendor_no_verdict"
      },
      "occurred_on": "2026-08-13",
      "occurred_at": "2026-08-13 02:15:36.572161+00",
      "observed_since": "2026-08-12",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_019ff8e7-4fb5-7b7c-8d69-2ef5a775518e"
    },
    {
      "id": "chg_019ff3d4-e563-7b93-9f40-9048b71cb22d",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-12",
      "occurred_at": "2026-08-12 02:37:23.660143+00",
      "observed_since": "2026-08-11",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_019ff3d4-e563-7b93-9f40-9048b71cb22d"
    },
    {
      "id": "chg_019fdf3c-08dd-738a-b808-3e4850cff2ba",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "vendor_no_verdict"
      },
      "occurred_on": "2026-08-08",
      "occurred_at": "2026-08-08 02:38:01.303629+00",
      "observed_since": "2026-08-07",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_019fdf3c-08dd-738a-b808-3e4850cff2ba"
    },
    {
      "id": "chg_019fda00-e026-79d0-bbdf-3dca8a3cdeab",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-07",
      "occurred_at": "2026-08-07 02:15:18.268549+00",
      "observed_since": "2026-08-06",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_019fda00-e026-79d0-bbdf-3dca8a3cdeab"
    },
    {
      "id": "chg_019fd4e0-1913-7a3e-96e7-4da41d31a6a2",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-06",
      "occurred_at": "2026-08-06 02:21:24.080055+00",
      "observed_since": "2026-08-05",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_019fd4e0-1913-7a3e-96e7-4da41d31a6a2"
    },
    {
      "id": "chg_019fcfb6-f8ad-75a9-97b1-0f4c7fb54f15",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-05",
      "occurred_at": "2026-08-05 02:18:22.728533+00",
      "observed_since": "2026-08-04",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_019fcfb6-f8ad-75a9-97b1-0f4c7fb54f15"
    },
    {
      "id": "chg_019fcb81-33f2-7484-ab5d-18653a7205a7",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2025-68146",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2025-68146",
        "severity": "medium"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 06:41:10.114226+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "CVE-2025-68146 affects this package (medium)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_019fcb81-33f2-7484-ab5d-18653a7205a7"
    },
    {
      "id": "chg_019fcb81-33f3-7e3c-bdb2-e7981d607935",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.transitive",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "hatch > virtualenv > filelock",
        "refs": "[\"CVE-2026-22701\",\"CVE-2025-68146\",\"CVE-2026-22701\",\"CVE-2025-68146\"]",
        "seen": "87",
        "package": "filelock",
        "version": "3.19.1",
        "assessed": "88",
        "resolved": "87",
        "severity": "medium",
        "transitive": "1",
        "vulnerable": "[{\"name\":\"filelock\",\"version\":\"3.19.1\",\"depth\":3,\"path\":[\"hatch\",\"virtualenv\",\"filelock\"],\"refs\":[\"CVE-2026-22701\",\"CVE-2025-68146\",\"CVE-2026-22701\",\"CVE-2025-68146\"]}]",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 06:41:10.114226+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "Known CVEs (unverified → fail)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_019fcb81-33f3-7e3c-bdb2-e7981d607935"
    },
    {
      "id": "chg_019fcb81-33f4-780b-8c4f-7410b33bdb68",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-22701",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-22701",
        "severity": "medium"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 06:41:10.114226+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "CVE-2026-22701 affects this package (medium)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_019fcb81-33f4-780b-8c4f-7410b33bdb68"
    },
    {
      "id": "chg_019fc4de-31af-75c0-bc45-53b6f4f70fc3",
      "kind": "check.reverified",
      "family": "build-provenance",
      "subject_kind": "check",
      "subject": "build-provenance",
      "subject_child": "",
      "from_code": "provenance.inconclusive",
      "to_code": "provenance.none",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:45:23.872791+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Provenance (unverified → fail)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_019fc4de-31af-75c0-bc45-53b6f4f70fc3"
    },
    {
      "id": "chg_019fc4de-31b0-7775-b520-8ff4065fec5b",
      "kind": "check.reverified",
      "family": "install-scripts",
      "subject_kind": "check",
      "subject": "install-scripts",
      "subject_child": "",
      "from_code": "installscript.inconclusive",
      "to_code": "installscript.allowlisted",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "hook": "build_backend",
        "tier": "allowlisted",
        "tool": "hatchling.build",
        "hooks": "build_backend"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:45:23.872791+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Install scripts (unverified → pass)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_019fc4de-31b0-7775-b520-8ff4065fec5b"
    },
    {
      "id": "chg_019fc4de-31b0-7bc8-b6dd-b14f3926896d",
      "kind": "installscript.hooks_changed",
      "family": "install-scripts",
      "subject_kind": "package",
      "subject": "hooks",
      "subject_child": "",
      "from_code": "installscript.inconclusive",
      "to_code": "installscript.allowlisted",
      "from_value": null,
      "to_value": "build_backend",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "to": "build_backend",
        "from": ""
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 23:45:23.872791+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "The scripts that run when this package is installed changed (build_backend)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_019fc4de-31b0-7bc8-b6dd-b14f3926896d"
    },
    {
      "id": "chg_019fc222-e53b-7e94-9f2c-be0f232389a8",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 11:01:34.637707+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_019fc222-e53b-7e94-9f2c-be0f232389a8"
    },
    {
      "id": "chg_019fc222-e53c-7805-9291-f25b57479832",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_failed",
      "to_code": "stability.sandbox_pending",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 11:01:34.637707+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.)",
      "link": "https://verifymcp.io/servers/penny4nonsense-mcp-pymupdf/mcp-pymupdf#chg-chg_019fc222-e53c-7805-9291-f25b57479832"
    }
  ],
  "days": [
    {
      "date": "2026-09-22",
      "total": 22,
      "delta": -15,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-21",
      "total": 37,
      "delta": 15,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-18",
      "total": 22,
      "delta": -15,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-17",
      "total": 37,
      "delta": 15,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-14",
      "total": 22,
      "delta": -15,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-12",
      "total": 37,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-11",
      "total": 37,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-08",
      "total": 37,
      "delta": 2,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 4
    }
  ]
}