{
  "server": "valyay-nanostores-mcp",
  "component": "nanostores-mcp",
  "generated_at": "2026-08-04T03:44:45.512Z",
  "tracking_since": "2026-07-26",
  "counts": {
    "critical": 0,
    "security": 12,
    "functional": 0,
    "cosmetic": 0
  },
  "events": [
    {
      "id": "chg_019fca56-3965-7155-95cc-aad00bd98918",
      "kind": "check.verdict",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.tree_partial",
      "to_code": "cve.transitive",
      "from_value": "partial",
      "to_value": "fail",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "path": "@modelcontextprotocol/sdk > hono",
        "refs": "[\"CVE-2026-69207\"]",
        "seen": "135",
        "package": "hono",
        "version": "4.12.33",
        "assessed": "132",
        "resolved": "131",
        "severity": "medium",
        "transitive": "1",
        "unresolved": "4",
        "vulnerable": "[{\"name\":\"hono\",\"version\":\"4.12.33\",\"depth\":2,\"path\":[\"@modelcontextprotocol/sdk\",\"hono\"],\"refs\":[\"CVE-2026-69207\"]}]",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 01:14:36.230113+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "Known CVEs (partial → fail)",
      "link": "https://verifymcp.io/servers/valyay-nanostores-mcp/nanostores-mcp#chg-chg_019fca56-3965-7155-95cc-aad00bd98918"
    },
    {
      "id": "chg_019fca56-3964-7292-bc7d-388ed8fc2e26",
      "kind": "advisory.identified",
      "family": "vulnerabilities",
      "subject_kind": "advisory",
      "subject": "CVE-2026-69207",
      "subject_child": "",
      "from_code": null,
      "to_code": "cve.transitive",
      "from_value": null,
      "to_value": "medium",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "id": "CVE-2026-69207",
        "severity": "medium"
      },
      "occurred_on": "2026-08-04",
      "occurred_at": "2026-08-04 01:14:36.230113+00",
      "observed_since": "2026-08-03",
      "source": "scan",
      "summary": "CVE-2026-69207 affects this package (medium)",
      "link": "https://verifymcp.io/servers/valyay-nanostores-mcp/nanostores-mcp#chg-chg_019fca56-3964-7292-bc7d-388ed8fc2e26"
    },
    {
      "id": "chg_019fc47d-3b39-72cb-a832-fba8d3cea1d4",
      "kind": "check.reverified",
      "family": "build-provenance",
      "subject_kind": "check",
      "subject": "build-provenance",
      "subject_child": "",
      "from_code": "provenance.inconclusive",
      "to_code": "provenance.verified",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "repo": "Valyay/nanostores-mcp"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 21:59:29.29028+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Provenance (unverified → pass)",
      "link": "https://verifymcp.io/servers/valyay-nanostores-mcp/nanostores-mcp#chg-chg_019fc47d-3b39-72cb-a832-fba8d3cea1d4"
    },
    {
      "id": "chg_019fc47d-3b3a-732f-97fd-c476c5c1b898",
      "kind": "provenance.repo_changed",
      "family": "build-provenance",
      "subject_kind": "package",
      "subject": "repo",
      "subject_child": "",
      "from_code": "provenance.inconclusive",
      "to_code": "provenance.verified",
      "from_value": null,
      "to_value": "Valyay/nanostores-mcp",
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "to": "Valyay/nanostores-mcp",
        "from": ""
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 21:59:29.29028+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "The attested source repository moved (Valyay/nanostores-mcp)",
      "link": "https://verifymcp.io/servers/valyay-nanostores-mcp/nanostores-mcp#chg-chg_019fc47d-3b3a-732f-97fd-c476c5c1b898"
    },
    {
      "id": "chg_019fc47d-3b39-7d6c-9b3c-85b9b63f3445",
      "kind": "check.reverified",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.inconclusive",
      "to_code": "cve.tree_partial",
      "from_value": "unverified",
      "to_value": "partial",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "seen": "135",
        "assessed": "132",
        "resolved": "131",
        "unresolved": "4",
        "tree_source": "registry",
        "tree_status": "partial"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 21:59:29.29028+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Known CVEs (unverified → partial)",
      "link": "https://verifymcp.io/servers/valyay-nanostores-mcp/nanostores-mcp#chg-chg_019fc47d-3b39-7d6c-9b3c-85b9b63f3445"
    },
    {
      "id": "chg_019fc47d-3b38-70b2-b9f6-a6aaec76959a",
      "kind": "check.reverified",
      "family": "install-scripts",
      "subject_kind": "check",
      "subject": "install-scripts",
      "subject_child": "",
      "from_code": "installscript.inconclusive",
      "to_code": "installscript.none",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {
        "tier": "none"
      },
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 21:59:29.29028+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Install scripts (unverified → pass)",
      "link": "https://verifymcp.io/servers/valyay-nanostores-mcp/nanostores-mcp#chg-chg_019fc47d-3b38-70b2-b9f6-a6aaec76959a"
    },
    {
      "id": "chg_019fc22c-20d5-7bac-bb26-a8b0362bdc8f",
      "kind": "check.reverified",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_inconclusive",
      "to_code": "supplychain.malware_clean",
      "from_value": "unverified",
      "to_value": "pass",
      "materiality": "security",
      "direction": "improvement",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-08-02",
      "occurred_at": "2026-08-02 11:11:39.71404+00",
      "observed_since": "2026-08-01",
      "source": "scan",
      "summary": "Malware scan (unverified → pass)",
      "link": "https://verifymcp.io/servers/valyay-nanostores-mcp/nanostores-mcp#chg-chg_019fc22c-20d5-7bac-bb26-a8b0362bdc8f"
    },
    {
      "id": "chg_019fb1a2-35e3-70cb-8420-c1643471843f",
      "kind": "provenance.repo_changed",
      "family": "build-provenance",
      "subject_kind": "package",
      "subject": "repo",
      "subject_child": "",
      "from_code": "provenance.verified",
      "to_code": "provenance.inconclusive",
      "from_value": "Valyay/nanostores-mcp",
      "to_value": null,
      "materiality": "security",
      "direction": "neutral",
      "score_delta": null,
      "detail": {
        "to": "",
        "from": "Valyay/nanostores-mcp"
      },
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 06:07:05.685586+00",
      "observed_since": "2026-07-28",
      "source": "scan",
      "summary": "The attested source repository moved (Valyay/nanostores-mcp)",
      "link": "https://verifymcp.io/servers/valyay-nanostores-mcp/nanostores-mcp#chg-chg_019fb1a2-35e3-70cb-8420-c1643471843f"
    },
    {
      "id": "chg_019fb1a2-35e2-7b7b-8836-5f241f53316c",
      "kind": "check.unverifiable",
      "family": "install-scripts",
      "subject_kind": "check",
      "subject": "install-scripts",
      "subject_child": "",
      "from_code": "installscript.none",
      "to_code": "installscript.inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 06:07:05.685586+00",
      "observed_since": "2026-07-28",
      "source": "scan",
      "summary": "Install scripts (pass → unverified)",
      "link": "https://verifymcp.io/servers/valyay-nanostores-mcp/nanostores-mcp#chg-chg_019fb1a2-35e2-7b7b-8836-5f241f53316c"
    },
    {
      "id": "chg_019fb1a2-35e2-7678-bdee-6a687d44620b",
      "kind": "check.unverifiable",
      "family": "supplychain-malware",
      "subject_kind": "check",
      "subject": "supplychain-malware",
      "subject_child": "",
      "from_code": "supplychain.malware_clean",
      "to_code": "supplychain.malware_inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 06:07:05.685586+00",
      "observed_since": "2026-07-28",
      "source": "scan",
      "summary": "Malware scan (pass → unverified)",
      "link": "https://verifymcp.io/servers/valyay-nanostores-mcp/nanostores-mcp#chg-chg_019fb1a2-35e2-7678-bdee-6a687d44620b"
    },
    {
      "id": "chg_019fb1a2-35e1-77e4-a060-cd345ac5a22c",
      "kind": "check.unverifiable",
      "family": "build-provenance",
      "subject_kind": "check",
      "subject": "build-provenance",
      "subject_child": "",
      "from_code": "provenance.verified",
      "to_code": "provenance.inconclusive",
      "from_value": "pass",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {},
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 06:07:05.685586+00",
      "observed_since": "2026-07-28",
      "source": "scan",
      "summary": "Provenance (pass → unverified)",
      "link": "https://verifymcp.io/servers/valyay-nanostores-mcp/nanostores-mcp#chg-chg_019fb1a2-35e1-77e4-a060-cd345ac5a22c"
    },
    {
      "id": "chg_019fb1a2-35e2-70c4-b03e-5f0ca21ebf9c",
      "kind": "check.unverifiable",
      "family": "vulnerabilities",
      "subject_kind": "check",
      "subject": "vulnerabilities",
      "subject_child": "",
      "from_code": "cve.tree_partial",
      "to_code": "cve.inconclusive",
      "from_value": "partial",
      "to_value": "unverified",
      "materiality": "security",
      "direction": "regression",
      "score_delta": null,
      "detail": {
        "reason": "resolver_unavailable"
      },
      "occurred_on": "2026-07-30",
      "occurred_at": "2026-07-30 06:07:05.685586+00",
      "observed_since": "2026-07-28",
      "source": "scan",
      "summary": "Known CVEs (partial → unverified)",
      "link": "https://verifymcp.io/servers/valyay-nanostores-mcp/nanostores-mcp#chg-chg_019fb1a2-35e2-70c4-b03e-5f0ca21ebf9c"
    }
  ],
  "days": [
    {
      "date": "2026-08-04",
      "total": 78,
      "delta": -1,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 2
    },
    {
      "date": "2026-08-03",
      "total": 79,
      "delta": 1,
      "tracked": true,
      "explained": false,
      "beyond_event_horizon": false,
      "attribution": {
        "category": "Stability & Change Management",
        "from": 23,
        "to": 27,
        "delta": 4,
        "others": [],
        "accrual": {
          "code": "stability.building_history",
          "from_days": 7,
          "to_days": 8
        },
        "partial": false,
        "compared_to": "2026-08-02",
        "summary": "No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes."
      },
      "event_count": 0
    },
    {
      "date": "2026-08-02",
      "total": 78,
      "delta": 44,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 10
    },
    {
      "date": "2026-07-31",
      "total": 34,
      "delta": -5,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-07-30",
      "total": 39,
      "delta": -52,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 9
    },
    {
      "date": "2026-07-27",
      "total": 91,
      "delta": 48,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 1
    },
    {
      "date": "2026-07-26",
      "total": 43,
      "delta": null,
      "tracked": true,
      "explained": true,
      "beyond_event_horizon": false,
      "attribution": null,
      "event_count": 0
    }
  ]
}