{
  "$schema": "https://verifymcp.io/schemas/changelog.json",
  "server": "trackly-app-trackly",
  "component": "trackly-cli",
  "generated_at": "2026-09-20T13:54:08.863Z",
  "tracking_since": "2026-07-27",
  "counts": {
    "critical": 0,
    "security": 61,
    "functional": 0,
    "cosmetic": 0
  },
  "events": [
    {
      "id": "chg_01a0bded-637f-7c17-9875-32172b5c7fd1",
      "kind": "check.verdict",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.building_history",
      "to_code": "stability.stable",
      "from_value": "0.97",
      "to_value": "pass",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-20",
      "occurred_at": "2026-09-20 08:27:26.169241+00",
      "observed_since": "2026-09-19",
      "source": "scan",
      "summary": "Stability (0.97 → pass)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a0bded-637f-7c17-9875-32172b5c7fd1"
    },
    {
      "id": "chg_01a0ba9c-913c-7267-a50e-79c305d8a619",
      "kind": "check.unverifiable",
      "family": "tool-safety-injection",
      "subject_kind": "check",
      "subject": "tool-safety-injection",
      "subject_child": "",
      "from_code": "toolsafety.injection_clean",
      "to_code": "toolsafety.sandbox_pending",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "version_superseded"
      },
      "occurred_on": "2026-09-19",
      "occurred_at": "2026-09-19 17:00:18.00669+00",
      "observed_since": "2026-09-18",
      "source": "scan",
      "summary": "Tool safety (pass → unverified)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a0ba9c-913c-7267-a50e-79c305d8a619"
    },
    {
      "id": "chg_01a0ba9c-9137-7b46-8eb4-9c9906d7aa80",
      "kind": "check.unverifiable",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.building_history",
      "to_code": "stability.sandbox_pending",
      "from_value": "0.93",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "version_superseded"
      },
      "occurred_on": "2026-09-19",
      "occurred_at": "2026-09-19 17:00:18.00669+00",
      "observed_since": "2026-09-18",
      "source": "scan",
      "summary": "Stability (0.93 → unverified)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a0ba9c-9137-7b46-8eb4-9c9906d7aa80"
    },
    {
      "id": "chg_01a0b891-dd54-7c06-bf58-55e2b3b2a426",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "vendor_not_cached"
      },
      "occurred_on": "2026-09-19",
      "occurred_at": "2026-09-19 07:29:22.118092+00",
      "observed_since": "2026-09-18",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a0b891-dd54-7c06-bf58-55e2b3b2a426"
    },
    {
      "id": "chg_01a0a954-0951-789c-b5d5-bd4f70a958ef",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-16",
      "occurred_at": "2026-09-16 08:27:31.851479+00",
      "observed_since": "2026-09-15",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a0a954-0951-789c-b5d5-bd4f70a958ef"
    },
    {
      "id": "chg_01a0a767-e1eb-715b-aedf-39f54ac7cd83",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "vendor_not_cached"
      },
      "occurred_on": "2026-09-15",
      "occurred_at": "2026-09-15 23:29:58.055763+00",
      "observed_since": "2026-09-14",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a0a767-e1eb-715b-aedf-39f54ac7cd83"
    },
    {
      "id": "chg_01a0a42e-7414-7ac3-b86c-b13636fba84a",
      "kind": "check.verdict",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.building_history",
      "to_code": "stability.stable",
      "from_value": "0.97",
      "to_value": "pass",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-15",
      "occurred_at": "2026-09-15 08:28:22.601047+00",
      "observed_since": "2026-09-14",
      "source": "scan",
      "summary": "Stability (0.97 → pass)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a0a42e-7414-7ac3-b86c-b13636fba84a"
    },
    {
      "id": "chg_01a094b8-5347-7cc7-9ec0-c8272ae6fdd9",
      "kind": "check.verdict",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.version_churn",
      "to_code": "stability.stable",
      "from_value": "fail",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-12",
      "occurred_at": "2026-09-12 08:25:02.944339+00",
      "observed_since": "2026-09-11",
      "source": "scan",
      "summary": "Stability (fail → pass)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a094b8-5347-7cc7-9ec0-c8272ae6fdd9"
    },
    {
      "id": "chg_01a08f93-9653-7b6b-9077-845213bd794b",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-11",
      "occurred_at": "2026-09-11 08:26:49.05664+00",
      "observed_since": "2026-09-10",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a08f93-9653-7b6b-9077-845213bd794b"
    },
    {
      "id": "chg_01a087ce-fbce-7a92-bc71-26b183cff2a8",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "vendor_no_verdict"
      },
      "occurred_on": "2026-09-09",
      "occurred_at": "2026-09-09 20:14:44.127272+00",
      "observed_since": "2026-09-08",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a087ce-fbce-7a92-bc71-26b183cff2a8"
    },
    {
      "id": "chg_01a08544-2f0e-7d78-beb2-d9a64a5638cd",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-84365",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-84365",
        "severity": "medium"
      },
      "occurred_on": "2026-09-09",
      "occurred_at": "2026-09-09 08:23:53.266531+00",
      "observed_since": "2026-09-08",
      "source": "scan",
      "summary": "CVE-2026-84365 affects this package (medium)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a08544-2f0e-7d78-beb2-d9a64a5638cd"
    },
    {
      "id": "chg_01a08544-2f13-79b4-b79d-35d496ad5160",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.none",
      "to_code": "cve.direct",
      "from_value": "pass",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "hono",
        "refs": "[\"CVE-2026-84363\",\"CVE-2026-84364\",\"CVE-2026-84365\"]",
        "seen": "102",
        "direct": "1",
        "package": "hono",
        "version": "4.13.0",
        "assessed": "103",
        "resolved": "102",
        "severity": "medium",
        "vulnerable": "[{\"name\":\"hono\",\"version\":\"4.13.0\",\"depth\":1,\"path\":[\"hono\"],\"refs\":[\"CVE-2026-84363\",\"CVE-2026-84364\",\"CVE-2026-84365\"]}]",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-09-09",
      "occurred_at": "2026-09-09 08:23:53.266531+00",
      "observed_since": "2026-09-08",
      "source": "scan",
      "summary": "Known CVEs (pass → fail)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a08544-2f13-79b4-b79d-35d496ad5160"
    },
    {
      "id": "chg_01a08544-2f12-7475-96d1-fcee2f64affb",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-84364",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-84364",
        "severity": "medium"
      },
      "occurred_on": "2026-09-09",
      "occurred_at": "2026-09-09 08:23:53.266531+00",
      "observed_since": "2026-09-08",
      "source": "scan",
      "summary": "CVE-2026-84364 affects this package (medium)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a08544-2f12-7475-96d1-fcee2f64affb"
    },
    {
      "id": "chg_01a08544-2f11-7b4f-8e6b-af5e2b489444",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-84363",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-84363",
        "severity": "medium"
      },
      "occurred_on": "2026-09-09",
      "occurred_at": "2026-09-09 08:23:53.266531+00",
      "observed_since": "2026-09-08",
      "source": "scan",
      "summary": "CVE-2026-84363 affects this package (medium)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a08544-2f11-7b4f-8e6b-af5e2b489444"
    },
    {
      "id": "chg_01a07af6-243d-7ea3-9335-fa8392743248",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-07",
      "occurred_at": "2026-09-07 08:22:26.177419+00",
      "observed_since": "2026-09-06",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a07af6-243d-7ea3-9335-fa8392743248"
    },
    {
      "id": "chg_01a075cd-db54-7310-8a63-9da8402af6b5",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-09-06",
      "occurred_at": "2026-09-06 08:20:20.334451+00",
      "observed_since": "2026-09-05",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a075cd-db54-7310-8a63-9da8402af6b5"
    },
    {
      "id": "chg_01a070c5-64e5-7d2b-bec4-f3d182236994",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-76172",
      "subject_child": "",
      "from_code": "cve.direct",
      "to_code": "cve.none",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-76172"
      },
      "occurred_on": "2026-09-05",
      "occurred_at": "2026-09-05 08:52:59.428331+00",
      "observed_since": "2026-09-04",
      "source": "scan",
      "summary": "CVE-2026-76172 no longer affects this package",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a070c5-64e5-7d2b-bec4-f3d182236994"
    },
    {
      "id": "chg_01a070c5-64e6-7486-a9cb-46c4b60d0d0f",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.direct",
      "to_code": "cve.none",
      "from_value": "fail",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "102",
        "assessed": "103",
        "resolved": "102",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-09-05",
      "occurred_at": "2026-09-05 08:52:59.428331+00",
      "observed_since": "2026-09-04",
      "source": "scan",
      "summary": "Known CVEs (fail → pass)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a070c5-64e6-7486-a9cb-46c4b60d0d0f"
    },
    {
      "id": "chg_01a070c5-64e2-71a6-a1eb-d131b66692f7",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "vendor_not_cached"
      },
      "occurred_on": "2026-09-05",
      "occurred_at": "2026-09-05 08:52:59.428331+00",
      "observed_since": "2026-09-04",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a070c5-64e2-71a6-a1eb-d131b66692f7"
    },
    {
      "id": "chg_01a070c5-64e4-77a2-bf17-157fca6d6cc6",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-75931",
      "subject_child": "",
      "from_code": "cve.direct",
      "to_code": "cve.none",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-75931"
      },
      "occurred_on": "2026-09-05",
      "occurred_at": "2026-09-05 08:52:59.428331+00",
      "observed_since": "2026-09-04",
      "source": "scan",
      "summary": "CVE-2026-75931 no longer affects this package",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a070c5-64e4-77a2-bf17-157fca6d6cc6"
    },
    {
      "id": "chg_01a070c5-64e3-7757-ab9b-1f519e796817",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-75975",
      "subject_child": "",
      "from_code": "cve.direct",
      "to_code": "cve.none",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-75975"
      },
      "occurred_on": "2026-09-05",
      "occurred_at": "2026-09-05 08:52:59.428331+00",
      "observed_since": "2026-09-04",
      "source": "scan",
      "summary": "CVE-2026-75975 no longer affects this package",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a070c5-64e3-7757-ab9b-1f519e796817"
    },
    {
      "id": "chg_01a070c5-64e5-7813-9c64-c78ac5ba758e",
      "kind": "advisory.resolved",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-75899",
      "subject_child": "",
      "from_code": "cve.direct",
      "to_code": "cve.none",
      "from_value": "high",
      "to_value": null,
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-75899"
      },
      "occurred_on": "2026-09-05",
      "occurred_at": "2026-09-05 08:52:59.428331+00",
      "observed_since": "2026-09-04",
      "source": "scan",
      "summary": "CVE-2026-75899 no longer affects this package",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a070c5-64e5-7813-9c64-c78ac5ba758e"
    },
    {
      "id": "chg_01a0665c-ad12-7d3e-a387-987e77f6d1c3",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.none",
      "to_code": "cve.direct",
      "from_value": "pass",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "fast-uri",
        "refs": "[\"CVE-2026-75931\",\"CVE-2026-75975\",\"CVE-2026-75899\",\"CVE-2026-76172\"]",
        "seen": "103",
        "direct": "1",
        "package": "fast-uri",
        "version": "3.1.5",
        "assessed": "104",
        "resolved": "103",
        "severity": "high",
        "vulnerable": "[{\"name\":\"fast-uri\",\"version\":\"3.1.5\",\"depth\":1,\"path\":[\"fast-uri\"],\"refs\":[\"CVE-2026-75931\",\"CVE-2026-75975\",\"CVE-2026-75899\",\"CVE-2026-76172\"]}]",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-09-03",
      "occurred_at": "2026-09-03 08:22:24.713468+00",
      "observed_since": "2026-09-02",
      "source": "scan",
      "summary": "Known CVEs (pass → fail)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a0665c-ad12-7d3e-a387-987e77f6d1c3"
    },
    {
      "id": "chg_01a0665c-ad13-7db5-9a3e-15ab55194fb1",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-75931",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-75931",
        "severity": "high"
      },
      "occurred_on": "2026-09-03",
      "occurred_at": "2026-09-03 08:22:24.713468+00",
      "observed_since": "2026-09-02",
      "source": "scan",
      "summary": "CVE-2026-75931 affects this package (high)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a0665c-ad13-7db5-9a3e-15ab55194fb1"
    },
    {
      "id": "chg_01a0665c-ad13-786b-beca-8f3c603be701",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-76172",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-76172",
        "severity": "high"
      },
      "occurred_on": "2026-09-03",
      "occurred_at": "2026-09-03 08:22:24.713468+00",
      "observed_since": "2026-09-02",
      "source": "scan",
      "summary": "CVE-2026-76172 affects this package (high)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a0665c-ad13-786b-beca-8f3c603be701"
    },
    {
      "id": "chg_01a0665c-ad11-77ca-90da-52fe5a065db2",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-75975",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-75975",
        "severity": "high"
      },
      "occurred_on": "2026-09-03",
      "occurred_at": "2026-09-03 08:22:24.713468+00",
      "observed_since": "2026-09-02",
      "source": "scan",
      "summary": "CVE-2026-75975 affects this package (high)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a0665c-ad11-77ca-90da-52fe5a065db2"
    },
    {
      "id": "chg_01a0665c-ad13-72f3-bd15-4e87eb763e25",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-75899",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.direct",
      "from_value": null,
      "to_value": "high",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-75899",
        "severity": "high"
      },
      "occurred_on": "2026-09-03",
      "occurred_at": "2026-09-03 08:22:24.713468+00",
      "observed_since": "2026-09-02",
      "source": "scan",
      "summary": "CVE-2026-75899 affects this package (high)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a0665c-ad13-72f3-bd15-4e87eb763e25"
    },
    {
      "id": "chg_01a04782-1bb4-75fb-8443-b6f7a5c7df37",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.none",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "103",
        "assessed": "104",
        "resolved": "103",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-08-28",
      "occurred_at": "2026-08-28 08:35:03.990219+00",
      "observed_since": "2026-08-27",
      "source": "scan",
      "summary": "Known CVEs (unverified → pass)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a04782-1bb4-75fb-8443-b6f7a5c7df37"
    },
    {
      "id": "chg_01a04782-1bb2-74b8-bc11-302001dd77ab",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-28",
      "occurred_at": "2026-08-28 08:35:03.990219+00",
      "observed_since": "2026-08-27",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a04782-1bb2-74b8-bc11-302001dd77ab"
    },
    {
      "id": "chg_01a04264-351e-7382-9240-bd2008588409",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "vendor_not_cached"
      },
      "occurred_on": "2026-08-27",
      "occurred_at": "2026-08-27 08:44:18.555989+00",
      "observed_since": "2026-08-26",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a04264-351e-7382-9240-bd2008588409"
    },
    {
      "id": "chg_01a04264-351f-7ab5-9d73-e3a4c5a29982",
      "kind": "check.unverifiable",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.none",
      "to_code": "cve.inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "root_version_missing"
      },
      "occurred_on": "2026-08-27",
      "occurred_at": "2026-08-27 08:44:18.555989+00",
      "observed_since": "2026-08-26",
      "source": "scan",
      "summary": "Known CVEs (pass → unverified)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a04264-351f-7ab5-9d73-e3a4c5a29982"
    },
    {
      "id": "chg_01a0288d-f942-7c67-ac77-d1adbf660a2e",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-22",
      "occurred_at": "2026-08-22 08:19:48.10232+00",
      "observed_since": "2026-08-21",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a0288d-f942-7c67-ac77-d1adbf660a2e"
    },
    {
      "id": "chg_01a024ca-faa0-79b9-96f0-9efcce9b11ed",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "vendor_not_cached"
      },
      "occurred_on": "2026-08-21",
      "occurred_at": "2026-08-21 14:47:56.963563+00",
      "observed_since": "2026-08-20",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a024ca-faa0-79b9-96f0-9efcce9b11ed"
    },
    {
      "id": "chg_01a0191d-0798-7bb2-8c67-9bba98db90a7",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-19",
      "occurred_at": "2026-08-19 08:22:07.853803+00",
      "observed_since": "2026-08-18",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a0191d-0798-7bb2-8c67-9bba98db90a7"
    },
    {
      "id": "chg_01a013f4-4275-75d2-87c2-8659a04df436",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-18",
      "occurred_at": "2026-08-18 08:19:29.943031+00",
      "observed_since": "2026-08-17",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a013f4-4275-75d2-87c2-8659a04df436"
    },
    {
      "id": "chg_01a010d7-103e-768f-b261-fbc7b2c3194c",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "vendor_not_cached"
      },
      "occurred_on": "2026-08-17",
      "occurred_at": "2026-08-17 17:48:44.865235+00",
      "observed_since": "2026-08-16",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a010d7-103e-768f-b261-fbc7b2c3194c"
    },
    {
      "id": "chg_01a00bbb-3a3b-73c0-9c74-dd519f0cdab7",
      "kind": "check.unverifiable",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.version_churn",
      "to_code": "stability.sandbox_pending",
      "from_value": "fail",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "version_superseded"
      },
      "occurred_on": "2026-08-16",
      "occurred_at": "2026-08-16 18:00:14.563504+00",
      "observed_since": "2026-08-15",
      "source": "scan",
      "summary": "Stability (fail → unverified)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a00bbb-3a3b-73c0-9c74-dd519f0cdab7"
    },
    {
      "id": "chg_01a00bbb-3a3c-7393-a13b-5b18883f0dac",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-16",
      "occurred_at": "2026-08-16 18:00:14.563504+00",
      "observed_since": "2026-08-15",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_01a00bbb-3a3c-7393-a13b-5b18883f0dac"
    },
    {
      "id": "chg_019ffa6b-c244-7896-833b-0a103936ab27",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "vendor_no_verdict"
      },
      "occurred_on": "2026-08-13",
      "occurred_at": "2026-08-13 09:19:53.903077+00",
      "observed_since": "2026-08-12",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019ffa6b-c244-7896-833b-0a103936ab27"
    },
    {
      "id": "chg_019ffa35-7258-7cab-88e2-c453e0fcc27e",
      "kind": "check.unverifiable",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.none",
      "to_code": "cve.inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "root_version_missing"
      },
      "occurred_on": "2026-08-13",
      "occurred_at": "2026-08-13 08:20:34.502814+00",
      "observed_since": "2026-08-12",
      "source": "scan",
      "summary": "Known CVEs (pass → unverified)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019ffa35-7258-7cab-88e2-c453e0fcc27e"
    },
    {
      "id": "chg_019ffa35-7259-79a3-b69d-becb71fcca18",
      "kind": "check.verdict",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.building_history",
      "to_code": "stability.version_churn",
      "from_value": "0.23",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "to": "0.14.0",
        "days": "8",
        "from": "0.13.3",
        "added": "6",
        "breaks": "2",
        "removed": "0"
      },
      "occurred_on": "2026-08-13",
      "occurred_at": "2026-08-13 08:20:34.502814+00",
      "observed_since": "2026-08-12",
      "source": "scan",
      "summary": "Stability (0.23 → fail)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019ffa35-7259-79a3-b69d-becb71fcca18"
    },
    {
      "id": "chg_019fdb5d-9784-79f6-9ecd-4a715e0f73c3",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.tree_partial",
      "to_code": "cve.none",
      "from_value": "partial",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "97",
        "assessed": "98",
        "resolved": "97",
        "tree_source": "registry",
        "tree_status": "resolved"
      },
      "occurred_on": "2026-08-07",
      "occurred_at": "2026-08-07 08:36:11.759918+00",
      "observed_since": "2026-08-06",
      "source": "scan",
      "summary": "Known CVEs (partial → pass)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019fdb5d-9784-79f6-9ecd-4a715e0f73c3"
    },
    {
      "id": "chg_019fd3b6-1838-7667-a6df-1311b8d1ff37",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_failed",
      "to_code": "stability.insufficient_history",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-05",
      "occurred_at": "2026-08-05 20:55:54.143139+00",
      "observed_since": "2026-08-04",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: not enough scan history yet (needs a 30-day window).)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019fd3b6-1838-7667-a6df-1311b8d1ff37"
    },
    {
      "id": "chg_019fd100-4f07-77a4-a17a-21453efec34e",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.tree_partial",
      "from_value": "unverified",
      "to_value": "partial",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "99",
        "assessed": "96",
        "resolved": "95",
        "unresolved": "4",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-08-05",
      "occurred_at": "2026-08-05 08:18:06.156899+00",
      "observed_since": "2026-08-04",
      "source": "scan",
      "summary": "Known CVEs (unverified → partial)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019fd100-4f07-77a4-a17a-21453efec34e"
    },
    {
      "id": "chg_019fcbfc-a234-723f-8d41-46fec07b261a",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 08:55:59.258852+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019fcbfc-a234-723f-8d41-46fec07b261a"
    },
    {
      "id": "chg_019fcbfc-a237-70e5-8e47-9640a8f31746",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.tree_partial",
      "from_value": "unverified",
      "to_value": "partial",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "99",
        "assessed": "96",
        "resolved": "95",
        "unresolved": "4",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 08:55:59.258852+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "Known CVEs (unverified → partial)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019fcbfc-a237-70e5-8e47-9640a8f31746"
    },
    {
      "id": "chg_019fcbfc-a237-7a71-a45c-274ae0c73188",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_pending",
      "to_code": "stability.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "status": "unreachable"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 08:55:59.258852+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: our sandbox run of this package did not complete, so we have no schema to compare.)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019fcbfc-a237-7a71-a45c-274ae0c73188"
    },
    {
      "id": "chg_019fc7b5-ea78-75be-a0b6-9b32c5ef0ea4",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-03",
      "occurred_at": "2026-08-03 13:00:15.823941+00",
      "observed_since": "2026-08-02",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019fc7b5-ea78-75be-a0b6-9b32c5ef0ea4"
    },
    {
      "id": "chg_019fc534-8c7d-771e-988e-4b8e697d2779",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_failed",
      "to_code": "stability.sandbox_pending",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-03",
      "occurred_at": "2026-08-03 01:19:43.161193+00",
      "observed_since": "2026-08-02",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019fc534-8c7d-771e-988e-4b8e697d2779"
    },
    {
      "id": "chg_019fc534-8c7a-7b30-bf87-b9f19bab0ecb",
      "kind": "check.unverifiable",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.tree_partial",
      "to_code": "cve.inconclusive",
      "from_value": "partial",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "root_version_missing"
      },
      "occurred_on": "2026-08-03",
      "occurred_at": "2026-08-03 01:19:43.161193+00",
      "observed_since": "2026-08-02",
      "source": "scan",
      "summary": "Known CVEs (partial → unverified)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019fc534-8c7a-7b30-bf87-b9f19bab0ecb"
    },
    {
      "id": "chg_019fc47a-8954-7e94-b4d1-644bceac47b7",
      "kind": "provenance.repo_changed",
      "family": "build-provenance",
      "subject_kind": "package",
      "subject": "repo",
      "subject_child": "",
      "from_code": "provenance.inconclusive",
      "to_code": "provenance.verified",
      "from_value": null,
      "to_value": "trackly-app/trackly-cli",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "to": "trackly-app/trackly-cli",
        "from": ""
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 21:56:32.699479+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "The attested source repository moved (trackly-app/trackly-cli)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019fc47a-8954-7e94-b4d1-644bceac47b7"
    },
    {
      "id": "chg_019fc47a-8952-77d0-8137-8e75b95b7ad4",
      "kind": "check.reverified",
      "family": "install-scripts",
      "subject_kind": "check",
      "subject": "install-scripts",
      "subject_child": "",
      "from_code": "installscript.inconclusive",
      "to_code": "installscript.none",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "tier": "none"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 21:56:32.699479+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Install scripts (unverified → pass)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019fc47a-8952-77d0-8137-8e75b95b7ad4"
    },
    {
      "id": "chg_019fc47a-8953-7856-9b76-6353352884ff",
      "kind": "check.reverified",
      "family": "build-provenance",
      "subject_kind": "check",
      "subject": "build-provenance",
      "subject_child": "",
      "from_code": "provenance.inconclusive",
      "to_code": "provenance.verified",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "repo": "trackly-app/trackly-cli"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 21:56:32.699479+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Provenance (unverified → pass)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019fc47a-8953-7856-9b76-6353352884ff"
    },
    {
      "id": "chg_019fc47a-8953-7dab-8793-7752070e3baf",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.tree_partial",
      "from_value": "unverified",
      "to_value": "partial",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "99",
        "assessed": "96",
        "resolved": "95",
        "unresolved": "4",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 21:56:32.699479+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Known CVEs (unverified → partial)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019fc47a-8953-7dab-8793-7752070e3baf"
    },
    {
      "id": "chg_019fc47a-8954-7337-a85e-b6dedae2cecc",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_pending",
      "to_code": "stability.sandbox_failed",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "status": "unreachable"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 21:56:32.699479+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: our sandbox run of this package did not complete, so we have no schema to compare.)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019fc47a-8954-7337-a85e-b6dedae2cecc"
    },
    {
      "id": "chg_019fc310-a4ab-7218-8346-a18a9a3bbb9f",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 15:21:15.66854+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019fc310-a4ab-7218-8346-a18a9a3bbb9f"
    },
    {
      "id": "chg_019fbf1b-bfb1-77e5-9a7c-ab7cc0ccb180",
      "kind": "check.reason",
      "family": "stability",
      "subject_kind": "check",
      "subject": "stability",
      "subject_child": "",
      "from_code": "stability.sandbox_failed",
      "to_code": "stability.sandbox_pending",
      "from_value": "unverified",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-01",
      "occurred_at": "2026-08-01 20:54:54.62838+00",
      "observed_since": "2026-07-31",
      "source": "scan",
      "summary": "Stability (Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019fbf1b-bfb1-77e5-9a7c-ab7cc0ccb180"
    },
    {
      "id": "chg_019fbbf9-1b0d-71a8-ac39-ebf4ddcbecc8",
      "kind": "check.unverifiable",
      "family": "build-provenance",
      "subject_kind": "check",
      "subject": "build-provenance",
      "subject_child": "",
      "from_code": "provenance.verified",
      "to_code": "provenance.inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-01",
      "occurred_at": "2026-08-01 06:18:12.605863+00",
      "observed_since": "2026-07-31",
      "source": "scan",
      "summary": "Provenance (pass → unverified)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019fbbf9-1b0d-71a8-ac39-ebf4ddcbecc8"
    },
    {
      "id": "chg_019fbbf9-1b0e-714b-8871-890afa86d5a7",
      "kind": "check.unverifiable",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.tree_partial",
      "to_code": "cve.inconclusive",
      "from_value": "partial",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "resolver_unavailable"
      },
      "occurred_on": "2026-08-01",
      "occurred_at": "2026-08-01 06:18:12.605863+00",
      "observed_since": "2026-07-31",
      "source": "scan",
      "summary": "Known CVEs (partial → unverified)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019fbbf9-1b0e-714b-8871-890afa86d5a7"
    },
    {
      "id": "chg_019fbbf9-1b0e-76ca-9286-58e171d6f261",
      "kind": "check.unverifiable",
      "family": "install-scripts",
      "subject_kind": "check",
      "subject": "install-scripts",
      "subject_child": "",
      "from_code": "installscript.none",
      "to_code": "installscript.inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-01",
      "occurred_at": "2026-08-01 06:18:12.605863+00",
      "observed_since": "2026-07-31",
      "source": "scan",
      "summary": "Install scripts (pass → unverified)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019fbbf9-1b0e-76ca-9286-58e171d6f261"
    },
    {
      "id": "chg_019fbbf9-1b0e-7c8f-aa3a-f47bd4516e9e",
      "kind": "provenance.repo_changed",
      "family": "build-provenance",
      "subject_kind": "package",
      "subject": "repo",
      "subject_child": "",
      "from_code": "provenance.verified",
      "to_code": "provenance.inconclusive",
      "from_value": "trackly-app/trackly-cli",
      "to_value": null,
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "to": "",
        "from": "trackly-app/trackly-cli"
      },
      "occurred_on": "2026-08-01",
      "occurred_at": "2026-08-01 06:18:12.605863+00",
      "observed_since": "2026-07-31",
      "source": "scan",
      "summary": "The attested source repository moved (trackly-app/trackly-cli)",
      "link": "https://verifymcp.io/servers/trackly-app-trackly/trackly-cli#chg-chg_019fbbf9-1b0e-7c8f-aa3a-f47bd4516e9e"
    }
  ],
  "days": [
    {
      "date": "2026-09-20",
      "total": 94,
      "delta": 1,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-19",
      "total": 93,
      "delta": 0,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 8
    },
    {
      "date": "2026-09-18",
      "total": 93,
      "delta": -1,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-16",
      "total": 94,
      "delta": 15,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-15",
      "total": 79,
      "delta": -14,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 3
    },
    {
      "date": "2026-09-13",
      "total": 93,
      "delta": -1,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-12",
      "total": 94,
      "delta": 1,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-09-11",
      "total": 93,
      "delta": 15,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    }
  ]
}