MCP SSH Server: 37 tools for remote SSH management | Claude Code & OpenAI Codex | DevOps automation, backups, database operations, health monitoring
A deterministic 0–100 hygiene score — README, license, CI, tests, docs, and freshness.
Who ships this repo — author concentration and the bus factor across the last 300 mainline commits.
How welcoming this repo is to contributors — issue throughput, close time, responsiveness, and good-first-issue count.
What this project is built on — dependency count by ecosystem, the license mix, and anything worth a legal look before you adopt it.
Whether this project's CI can be trusted — pass rate, run times, flaky runs, and which workflow is the weak link.
Grounded in mcp-ssh-manager's README, structure, and recent commits — answers won't invent code they haven't seen.
A Monday email with what shipped, in plain English — no account needed.
Showing raw commit titles for the newest commits. Sign in to generate AI summaries.
Fix CI workflow environment variable
Fixed a GitHub Actions workflow error by replacing an unavailable `runner.temp` context variable in the job-level environment with the `$RUNNER_TEMP` environment variable that's available at runtime. The notarization key file path is now correctly resolved using the plain environment variable instead of a context expression that GitHub couldn't parse.
Fixed macOS signing to actually run
The macOS code signing and notarization steps were silently skipped due to environment variable conditions being checked at the wrong scope, and the notarization key was written to the wrong path. Both issues are now fixed by moving secrets to job-level environment variables and using the correct path resolver, and verification now checks all CPU architectures instead of just one.
Add desktop release workflow
Added a new CI workflow that builds macOS and Windows desktop applications from tagged releases, signs and notarizes the macOS version, and attaches the built artifacts to GitHub Releases. The workflow runs manually on demand and includes a dry-run mode that builds and signs without creating a release.
fix(security): close three command-injection advisories (GHSA-qwwm/796j/m793)
ci(security): least-privilege tokens, pin the setup script, keep LOG_LEVELS public
fix(security): pin detect-secrets, harden test temp files, drop dead import
A floor, not a guess: counts only commits whose author, co-author trailer, or message explicitly credits an AI tool (Claude, Copilot, Cursor, aider, Codex…). Based on 30 mainline commits. Unattributed AI code isn't counted here — the full audit estimates that separately.