{
  "$schema": "https://verifymcp.io/schemas/changelog.json",
  "server": "syedtaj7-kitbag-mcp",
  "component": "kitbag-mcp",
  "generated_at": "2026-09-21T22:20:17.408Z",
  "tracking_since": "2026-07-27",
  "counts": {
    "critical": 0,
    "security": 14,
    "functional": 0,
    "cosmetic": 0
  },
  "events": [
    {
      "id": "chg_01a0b8fb-6b8c-7c30-8548-eac43151035b",
      "kind": "check.verdict",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.building_history",
      "to_code": "stability.stable",
      "from_value": "0.97",
      "to_value": "pass",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-19",
      "occurred_at": "2026-09-19 09:24:39.905671+00",
      "observed_since": "2026-09-18",
      "source": "scan",
      "summary": "Stability (0.97 → pass)",
      "link": "https://verifymcp.io/servers/syedtaj7-kitbag-mcp/kitbag-mcp#chg-chg_01a0b8fb-6b8c-7c30-8548-eac43151035b"
    },
    {
      "id": "chg_01a094ef-439f-7511-b504-8639e692c2e3",
      "kind": "check.verdict",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.building_history",
      "to_code": "stability.stable",
      "from_value": "0.97",
      "to_value": "pass",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-12",
      "occurred_at": "2026-09-12 09:25:03.415227+00",
      "observed_since": "2026-09-11",
      "source": "scan",
      "summary": "Stability (0.97 → pass)",
      "link": "https://verifymcp.io/servers/syedtaj7-kitbag-mcp/kitbag-mcp#chg-chg_01a094ef-439f-7511-b504-8639e692c2e3"
    },
    {
      "id": "chg_01a08579-3394-7e1e-b929-3f999b0a4bb8",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-85063",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-85063",
        "severity": "medium"
      },
      "occurred_on": "2026-09-09",
      "occurred_at": "2026-09-09 09:21:47.899451+00",
      "observed_since": "2026-09-08",
      "source": "scan",
      "summary": "CVE-2026-85063 affects this package (medium)",
      "link": "https://verifymcp.io/servers/syedtaj7-kitbag-mcp/kitbag-mcp#chg-chg_01a08579-3394-7e1e-b929-3f999b0a4bb8"
    },
    {
      "id": "chg_01a08579-3396-7599-93d1-b4ab30d9dc04",
      "kind": "check.reason",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.transitive",
      "to_code": "cve.direct",
      "from_value": "fail",
      "to_value": "fail",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "path": "csv-parse",
        "refs": "[\"CVE-2026-85063\",\"CVE-2026-31808\"]",
        "seen": "311",
        "direct": "1",
        "package": "csv-parse",
        "version": "5.6.0",
        "assessed": "312",
        "resolved": "311",
        "severity": "medium",
        "transitive": "1",
        "vulnerable": "[{\"name\":\"csv-parse\",\"version\":\"5.6.0\",\"depth\":1,\"path\":[\"csv-parse\"],\"refs\":[\"CVE-2026-85063\"]},{\"name\":\"file-type\",\"version\":\"16.5.4\",\"depth\":4,\"path\":[\"jimp\",\"@jimp/custom\",\"@jimp/core\",\"file-type\"],\"refs\":[\"CVE-2026-31808\"]}]",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-09-09",
      "occurred_at": "2026-09-09 09:21:47.899451+00",
      "observed_since": "2026-09-08",
      "source": "scan",
      "summary": "Known CVEs (CVE check failed: a known medium-severity CVE affects csv-parse 5.6.0, a direct dependency. A fixed version is available.)",
      "link": "https://verifymcp.io/servers/syedtaj7-kitbag-mcp/kitbag-mcp#chg-chg_01a08579-3396-7599-93d1-b4ab30d9dc04"
    },
    {
      "id": "chg_01a06bb7-a998-74d5-be63-9bd387520de2",
      "kind": "check.verdict",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.building_history",
      "to_code": "stability.stable",
      "from_value": "0.97",
      "to_value": "pass",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-04",
      "occurred_at": "2026-09-04 09:19:53.585186+00",
      "observed_since": "2026-09-03",
      "source": "scan",
      "summary": "Stability (0.97 → pass)",
      "link": "https://verifymcp.io/servers/syedtaj7-kitbag-mcp/kitbag-mcp#chg-chg_01a06bb7-a998-74d5-be63-9bd387520de2"
    },
    {
      "id": "chg_019fd442-b04f-76fe-8139-58a6997bc316",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_failed",
      "to_code": "stability.insufficient_history",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-05",
      "occurred_at": "2026-08-05 23:29:28.119916+00",
      "observed_since": "2026-08-04",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: not enough scan history yet (needs a 30-day window).)",
      "link": "https://verifymcp.io/servers/syedtaj7-kitbag-mcp/kitbag-mcp#chg-chg_019fd442-b04f-76fe-8139-58a6997bc316"
    },
    {
      "id": "chg_019fc4f5-be6d-75bf-9416-bf50e6acb5bc",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-31808",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-31808",
        "severity": "medium"
      },
      "occurred_on": "2026-08-03",
      "occurred_at": "2026-08-03 00:11:07.230551+00",
      "observed_since": "2026-08-02",
      "source": "scan",
      "summary": "CVE-2026-31808 affects this package (medium)",
      "link": "https://verifymcp.io/servers/syedtaj7-kitbag-mcp/kitbag-mcp#chg-chg_019fc4f5-be6d-75bf-9416-bf50e6acb5bc"
    },
    {
      "id": "chg_019fc4f5-be6e-77cf-9161-e2dd8ca287df",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.transitive",
      "from_value": "unverified",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "jimp > @jimp/custom > @jimp/core > file-type",
        "refs": "[\"CVE-2026-31808\"]",
        "seen": "300",
        "package": "file-type",
        "version": "16.5.4",
        "assessed": "251",
        "resolved": "250",
        "severity": "medium",
        "transitive": "1",
        "unresolved": "50",
        "vulnerable": "[{\"name\":\"file-type\",\"version\":\"16.5.4\",\"depth\":4,\"path\":[\"jimp\",\"@jimp/custom\",\"@jimp/core\",\"file-type\"],\"refs\":[\"CVE-2026-31808\"]}]",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-08-03",
      "occurred_at": "2026-08-03 00:11:07.230551+00",
      "observed_since": "2026-08-02",
      "source": "scan",
      "summary": "Known CVEs (unverified → fail)",
      "link": "https://verifymcp.io/servers/syedtaj7-kitbag-mcp/kitbag-mcp#chg-chg_019fc4f5-be6e-77cf-9161-e2dd8ca287df"
    },
    {
      "id": "chg_019fc4f5-be6e-7d4f-947c-2fa931ad8ace",
      "kind": "check.reverified",
      "family": "install-scripts",
      "subject_kind": "check",
      "subject": "install-scripts",
      "subject_child": "",
      "from_code": "installscript.inconclusive",
      "to_code": "installscript.none",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "tier": "none"
      },
      "occurred_on": "2026-08-03",
      "occurred_at": "2026-08-03 00:11:07.230551+00",
      "observed_since": "2026-08-02",
      "source": "scan",
      "summary": "Install scripts (unverified → pass)",
      "link": "https://verifymcp.io/servers/syedtaj7-kitbag-mcp/kitbag-mcp#chg-chg_019fc4f5-be6e-7d4f-947c-2fa931ad8ace"
    },
    {
      "id": "chg_019fc4f5-be6f-7304-b134-11b5d18df0fd",
      "kind": "check.reverified",
      "family": "build-provenance",
      "subject_kind": "check",
      "subject": "build-provenance",
      "subject_child": "",
      "from_code": "provenance.inconclusive",
      "to_code": "provenance.verified",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "repo": "syedtaj7/Kitbag-mcp"
      },
      "occurred_on": "2026-08-03",
      "occurred_at": "2026-08-03 00:11:07.230551+00",
      "observed_since": "2026-08-02",
      "source": "scan",
      "summary": "Provenance (unverified → pass)",
      "link": "https://verifymcp.io/servers/syedtaj7-kitbag-mcp/kitbag-mcp#chg-chg_019fc4f5-be6f-7304-b134-11b5d18df0fd"
    },
    {
      "id": "chg_019fc4f5-be6f-7789-83ed-da86cad92403",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_pending",
      "to_code": "stability.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "status": "failed"
      },
      "occurred_on": "2026-08-03",
      "occurred_at": "2026-08-03 00:11:07.230551+00",
      "observed_since": "2026-08-02",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: our sandbox run of this package did not complete, so we have no schema to compare.)",
      "link": "https://verifymcp.io/servers/syedtaj7-kitbag-mcp/kitbag-mcp#chg-chg_019fc4f5-be6f-7789-83ed-da86cad92403"
    },
    {
      "id": "chg_019fc4f5-be6f-7bc6-9768-99449780f2ae",
      "kind": "provenance.repo_changed",
      "family": "build-provenance",
      "subject_kind": "package",
      "subject": "repo",
      "subject_child": "",
      "from_code": "provenance.inconclusive",
      "to_code": "provenance.verified",
      "from_value": null,
      "to_value": "syedtaj7/Kitbag-mcp",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "to": "syedtaj7/Kitbag-mcp",
        "from": ""
      },
      "occurred_on": "2026-08-03",
      "occurred_at": "2026-08-03 00:11:07.230551+00",
      "observed_since": "2026-08-02",
      "source": "scan",
      "summary": "The attested source repository moved (syedtaj7/Kitbag-mcp)",
      "link": "https://verifymcp.io/servers/syedtaj7-kitbag-mcp/kitbag-mcp#chg-chg_019fc4f5-be6f-7bc6-9768-99449780f2ae"
    },
    {
      "id": "chg_019fc388-673c-7111-8fe0-649639bada2f",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 17:32:04.257493+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/syedtaj7-kitbag-mcp/kitbag-mcp#chg-chg_019fc388-673c-7111-8fe0-649639bada2f"
    },
    {
      "id": "chg_019fb1f1-6a45-766e-9a03-da3c976a0ef6",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 07:33:36.440228+00",
      "observed_since": "2026-07-28",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/syedtaj7-kitbag-mcp/kitbag-mcp#chg-chg_019fb1f1-6a45-766e-9a03-da3c976a0ef6"
    }
  ],
  "days": [
    {
      "date": "2026-09-20",
      "total": 88,
      "delta": -2,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-19",
      "total": 90,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-18",
      "total": 90,
      "delta": 1,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": {
        "category": "Stability & Change Management",
        "from": 93,
        "to": 97,
        "delta": 4,
        "others": [],
        "accrual": {
          "code": "stability.building_history",
          "from_days": 28,
          "to_days": 29
        },
        "partial": false,
        "compared_to": "2026-09-17",
        "summary": "No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes."
      },
      "event_count": 0
    },
    {
      "date": "2026-09-15",
      "total": 89,
      "delta": 1,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-14",
      "total": 88,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-13",
      "total": 88,
      "delta": -2,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-12",
      "total": 90,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-11",
      "total": 90,
      "delta": 1,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": {
        "category": "Stability & Change Management",
        "from": 93,
        "to": 97,
        "delta": 4,
        "others": [],
        "accrual": {
          "code": "stability.building_history",
          "from_days": 28,
          "to_days": 29
        },
        "partial": false,
        "compared_to": "2026-09-10",
        "summary": "No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes."
      },
      "event_count": 0
    }
  ]
}