Every commit scored for change-risk against this repo's own history, so 'elevated' means elevated here rather than on some global curve.
Needs review
13 commits sit in this repo's top risk tercile, which is 33% of the 40scored. The cut is drawn against this codebase's own history rather than a global curve, so a quiet repo still fills its top band, and here it starts at 8.1 out of 10. What pushes a commit up is size and spread together: a large change confined to one area scores below a smaller one scattered across a dozen files.
Commit categories over time, read off the subject line. Fixes carry the accent because that is the series this chart exists to show.
How this repo's commit mix shifts over time.
Ranked by change-risk, highest first. Priority is a tercile of this repo's own distribution, so a quiet repo still fills its top band.
| # | Commit | Author | When | Lines | Risk | Top driver |
|---|---|---|---|---|---|---|
| 1 | 57b51916Fresh repo history | Regan Bell | 6d ago | +293.6K -0 | 99%Elevated | more lines added than baseline |
| 2 | 783715c7qm check: verify Fly sandbox token, SMTP credentials, and Node engine before deploy (#27) | Regan Bellclaudeassisted | 5d ago | +531 -7 | 96%Elevated | more lines added than baseline |
| 3 | 9bf77f7dImproved support for OpenRouter (#22) | Joshua Franceclaudeassisted | 6d ago | +456 -154 | 94%Elevated | more lines added than baseline |
| 4 | 35c47a3fAdd portal playground mode: anonymous browser-pinned sessions (#38) | Joshua France | 5d ago | +388 -14 | 90%Elevated | more lines added than baseline |
| 5 | a2e752f2Make the base model key a deployment secret, and document Slack sign-in (#21) | Joshua Franceclaudeassisted | 6d ago | +460 -55 | 90%Elevated | more lines added than baseline |
| 6 | bdfa74f9Fix the auth-gate lockouts found in review (#24) | Joshua France | 5d ago | +361 -73 | 86%Elevated | more lines added than baseline |
| 7 | b80f9c62Cut releases from one dispatch that tags what it published (#37) | Joshua France | 5d ago | +250 -5 | 84%Elevated | more lines added than baseline |
| 8 | 8da464cbDistinguish not-yet-deployed targets from secret drift in qm doctor (#28) | Regan Bellclaudeassisted | 5d ago | +157 -40 | 80%Elevated | more lines added than baseline |
| 9 | f23b3654Replace the web UI's sign-in form with auth-gate states (#23) | Joshua Franceclaudeassisted | 6d ago | +203 -56 | 80%Elevated | more lines added than baseline |
| 10 | 3fec30e6Add qm secrets set for safe in-place .env edits (#32) | Regan Bell | 5d ago | +124 -6 | 76%Elevated | more lines added than baseline |
| 11 | 7893008bRestrict the web-ui model picker to the org allowed-models list (#40) | Joshua Franceclaudeassisted | 4d ago | +161 -49 | 73%Elevated | more lines added than baseline |
| 12 | 771e6602Warn after fly secrets push when staged secrets are not live on running machines (#20) | Regan Bellclaudeassisted | 6d ago | +124 -0 | 73%Elevated | more lines added than baseline |
| 13 | 8ca1b120Route the first admin to onboarding instead of a 403 web UI (#29) | Regan Bellclaudeassisted | 5d ago | +150 -8 | 69%Elevated | more lines added than baseline |
| 14 | e455cba7Add an org-wide admin toggle defaulting interactive turns to fast mode (#35) | Regan Bell | 5d ago | +141 -9 | 66%Typical | more lines added than baseline |
| 15 | 2639c85fDocument playground deployments in the deployment workflow (#39) | Joshua France | 5d ago | +115 -7 | 63%Typical | more lines added than baseline |
| 16 | a44e2dd0Resolve sandbox base digests without registry reads and force amd64 base builds (#30) | Regan Bellclaudeassisted | 5d ago | +122 -11 | 63%Typical | more lines added than baseline |
| 17 | 97239303qm init: pick one email transport and scaffold only its keys (#31) | Regan Bellclaudeassisted | 5d ago | +78 -13 | 59%Typical | more lines added than baseline |
| 18 | 0da087c3Anonymize fixture names in tests (#2) | Regan Bell | 6d ago | +71 -69 | 56%Typical | more lines added than baseline |
| 19 | 57367e33Publish the deployment CLI to npm with provenance (#10) | Joshua Franceclaudeassisted | 6d ago | +70 -11 | 54%Typical | more lines added than baseline |
| 20 | d98a9142Pin real image digests into the published CLI package (#15) | Joshua Franceclaudeassisted | 6d ago | +69 -9 | 51%Typical | more lines added than baseline |
| 21 | efd41489Fix two config gaps that break a from-scratch Fly deployment (#4) | Joshua Franceclaudeassisted | 6d ago | +62 -1 | 49%Typical | more lines added than baseline |
| 22 | 3300ec42Stop a mock deployment passing as a real one (#25) | Joshua France | 5d ago | +53 -22 | 46%Typical | more lines added than baseline |
| 23 | ebc2e105Treat fast mode as opt-in so a turn that never asked for it is not billed against a tier the organization may have no quota for (#26) | BinBin He | 5d ago | +39 -3 | 43%Typical | more lines added than baseline |
| 24 | eed16ec9Make the admin onboarding view reachable (#19) | Regan Bellclaudeassisted | 6d ago | +46 -1 | 43%Typical | more lines added than baseline |
| 25 | f2e92a81Ship references/email.md from qm init (#17) | Regan Bellclaudeassisted | 6d ago | +42 -2 | 39%Typical | more lines added than baseline |
| 26 | cddf9e9fOffer a retry link on the stale sign-in link page (#18) | Regan Bellclaudeassisted | 6d ago | +30 -6 | 36%Typical | more lines added than baseline |
| 27 | f081c0bcDeployment doc: recommend cloud over docker, defuse the slug question, offer OpenRouter (#8) | Regan Bellclaudeassisted | 6d ago | +32 -12 | 34%Typical | more lines added than baseline |
| 28 | 4771de23docs: add architecture diagram (#7) | Joshua France | 6d ago | +16 -0 | 31%Below typical | more lines added than baseline |
| 29 | 07e001b6Classify the auth broker's nonce claim as a system write (#55) | Joshua Franceclaudeassisted | 6d ago | +18 -0 | 29%Below typical | more lines added than baseline |
| 30 | 2c660da8Take contributions as human-written text in adrs/ (#34) | Regan Bell | 5d ago | +19 -4 | 26%Below typical | more lines added than baseline |
| 31 | b27c78b1Stop shipping build-time caches and host identity in published images (#14) | Joshua Franceclaudeassisted | 6d ago | +14 -6 | 24%Below typical | more scattered than baseline |
| 32 | 7f2c9163Use @latest in the qm init bootstrap instead of a version placeholder (#41) | Joshua France | 4d ago | +11 -7 | 21%Below typical | more scattered than baseline |
| 33 | e00d3c05Drop the removed-features regression test (#36) | Joshua France | 5d ago | +9 -260 | 19%Below typical | fewer lines added than baseline |
| 34 | 8e614d21Disable Claude co-author trailer on commits | Regan Bell | 5d ago | +3 -0 | 15%Below typical | fewer lines added than baseline |
| 35 | 34baba82Fix MicroVM image tag parsing to read the capitalized Tags response key (#16) | Regan Bellclaudeassisted | 6d ago | +3 -3 | 15%Below typical | fewer lines added than baseline |
| 36 | 8d9370d3Publish images under a repo-nested GHCR namespace (#12) | Joshua Franceclaudeassisted | 6d ago | +3 -3 | 11%Below typical | fewer lines added than baseline |
| 37 | f9ab9dc2Prune docs/ to what the README reaches (#13) | Regan Bellclaudeassisted | 6d ago | +2 -492 | 9%Below typical | fewer lines added than baseline |
| 38 | 4622d65fDrop doc guards premised on the removed README quickstart (#9) | Regan Bellclaudeassisted | 6d ago | +0 -16 | 5%Below typical | fewer lines added than baseline |
| 39 | 50722998Remove "Run it" section (#6) | Regan Bell | 6d ago | +0 -33 | 5%Below typical | fewer lines added than baseline |
| 40 | 12014038docs: round README screenshot corners (#11) | Joshua France | 6d ago | +0 -0 | 1%Below typical | fewer lines added than baseline |
Two views of the same model: where the cuts fall, and what commit shape lands you above them.
Every scored commit, binned on the raw 0 to 10 score rather than the percentile. Percentile ranks are uniform by construction, so that axis has no shape to draw. The dashed lines are the tercile cuts behind each row's priority pill.
The 40 most recent commits, on their own recency sample rather than the feed above: that defaults to risk-sorted, so reusing it would plot only the top tercile and call it the spread. Big and scattered is what the model penalises. Click a dot to open it.
2233admin/qm has 40 commits in its history from 3 contributors, the first of them Jul 29, 2026. In the last 90 days 1,049 files were touched, 1,179 times in total, most often config.ts. Every commit is scored for change risk from its size, spread and the history of the files it touches.