career-ops-hq/career-ops
50.3
Adequate · 1 October 2026
152.6k
lines of production code
JavaScript
with TypeScript
2
measurements over time
What this system is
This system is a local-first, self-hosted career operations platform that automates the end-to-end job search process, from discovering roles and parsing CVs to managing applications and tracking interview progress. It features a modular architecture with an opt-in plugin system for integrating external data sources like Gmail and Notion, alongside a robust evaluation engine that scores opportunities using local AI models. The platform provides both a terminal-based TUI and an experimental web dashboard for managing pipelines, generating tailored documents, and executing follow-up communications, all while prioritizing data privacy and offline functionality.
Features
Add ATS-friendly single-column CV template pack
A new 'ATS Friendly' CV template pack has been added to the templates/ats directory, providing a single-column layout optimized for Applicant Tracking Systems. This includes the main cv-template.ats.html file and specific section partials for competencies, education, and work experience, ensuring structured, parseable output for users generating resumes.
templates/ats · high confidence
Add Gmail job-lead ingestion plugin
A new bundled Gmail plugin allows users to pull job leads from a specified Gmail label into the pipeline. It requires OAuth credentials (GMAIL\_CLIENT\_ID, GMAIL\_CLIENT\_SECRET, GMAIL\_REFRESH\_TOKEN) and configuration for the label name and lookback period. The plugin filters emails by DMARC authentication status to prevent spoofed leads, extracts clean URLs while ignoring page assets (logos, trackers), and parses job titles and companies from subject lines and ATS URLs. It maintains a local state file to avoid re-processing emails.
plugins/gmail · high confidence
Add Notion plugin to mirror application tracker
Introduces a new opt-in Notion plugin that mirrors the local application tracker to a Notion database and allows searching for job leads. The plugin exports tracker rows (company, role, status, score) to a user-specified Notion database and can search for records with job URLs. It includes a fix to correctly parse slash-formatted scores (e.g., '4.2/5') to prevent data mangling.
plugins/notion · high confidence
Add funding manifest URLs to .well-known
A new .well-known/funding-manifest-urls file has been added to the repository, listing five URLs that point to funding.json files hosted on GitHub (both in the career-ops-hq and santifer repositories). This change enables automated tools and users to discover the project's funding sources via the standard .well-known funding manifest protocol.
.well-known · high confidence
Batch runner now supports multiple agent CLIs and configurable evaluation parameters
The batch processing system has been expanded to support multiple headless agent CLIs (Claude, OpenCode, Gemini, Qwen) via the new --cli flag, allowing users to run evaluations using local or alternative models. The batch runner now accepts several new configuration flags: --limit to cap the number of processed offers, --min-score to skip PDF generation and tracker entries for low-scoring offers, --skip-pdf to disable PDF output entirely, --model to explicitly override the model selection, and --rate-limit-sleep to control adaptive retry delays for rate-limited sessions. Additionally, the system now includes a --status flag for progress monitoring and a --resume-paused flag to recover from session limits. The underlying evaluation prompt has also been updated to support language output preferences and agency confirmation gates.
batch · high confidence
Dashboard gains light theme, analytics screens, and improved error handling
The standalone Go TUI now supports a Catppuccin Latte light theme with automatic detection based on the terminal background, alongside new Progress and Stats analytics screens for viewing application metrics. The interface includes a manual refresh shortcut, a discard reason picker with a learning loop, and a celebration flow for hired statuses. Additionally, the dashboard now correctly surfaces open-command failures (such as opening URLs or cover letters) as visible UI messages instead of writing to stderr, and supports internationalization via a language toggle.
dashboard · high confidence
Declarative HTML section partials for CV templates
The templates/sections directory now uses declarative HTML partials (e.g., awards.html, certifications.html, competencies.html, education.html, experience.html, projects.html, skills.html) that render CV sections via field placeholders (such as TITLE, ORG, YEAR, LOCATION, CONTEXT, BULLETS) and conditional blocks (e.g., ORG\_BLOCK, LOCATION\_BLOCK, CONTEXT\_BLOCK). This enables users to customize the HTML structure, class names, and field order within each section’s ENTRY zone without modifying core logic, and supports optional fields like Awards/Honors, Certifications, Core Competencies, Education location, and Work Experience context.
templates/sections · high confidence
Experimental local-first web UI for career-ops
An opt-in, alpha-status web dashboard is now available in the web/ directory, providing a local-first view over the existing CLI data files (pipeline, applications, reports) without introducing a separate database or engine. The UI includes a Pipeline tracker, Explore scanner, and Apply form (which never auto-submits), along with Today, Analytics, and Config pages. The Analytics section now features a Pipeline Sankey chart to visualize application status flows. The local API is secured by a same-origin and loopback guard by default, with optional allowlists for hosts and origins via environment variables. The setup requires Node 22.6+ and uses Turbopack, with a specific configuration to pin the Turbopack root to prevent Windows postcss OOM issues.
web · high confidence
Initial i18n infrastructure for the Go TUI dashboard
This change introduces the internal internationalization (i18n) catalog for the Go-based TUI dashboard, providing a static, zero-dependency translation architecture. It adds support for English, Turkish, and Spanish locales, covering localized UI strings, status labels, table headers, and relative date formats. The implementation includes runtime language switching capabilities and is accompanied by tests verifying status label translation, time formatting, and language toggle behavior.
dashboard/internal/i18n · high confidence
Interview session transcript storage and format specification
The interview-prep module now includes a defined structure for storing machine-readable interview transcripts. A new README in the sessions directory specifies that transcripts are saved as individual Markdown files containing speaker labels, metadata (such as company, role, round type, and source), and optional competency tags. This change establishes the data format for outputs from 'debrief' and 'practice' modes, ensuring downstream analysis tools can parse interview history consistently while keeping actual session content gitignored for privacy.
interview-prep · high confidence
Introduce AI-powered web search and enhanced Explore UI
Adds an experimental AI search mode to the Explore page, allowing users to describe a role in plain language to hunt the open web for matches, complete with a live reasoning trace, cost tracking, and a mode toggle. Introduces new UI components including a natural-language search box, animated discovery states with source progress chips, and polished discovery cards with company logos and fit hints. The Explore provider now persists results across mode toggles and reloads, and the filter builder supports city/location keywords and improved paste handling.
web/src/components/explore · high confidence
Introduce Inbox Triage workflow with free filtering and shortlist scoring
The inbox now features a dedicated triage interface that allows users to filter incoming job postings using free, client-side facets (freshness, ATS source, seniority, location, and keywords) without consuming tokens. Users can save jobs to a persistent shortlist tray and choose to 'Score shortlist' only when ready, with an explicit confirmation step that displays the estimated token and dollar cost before execution. The system deduplicates postings, persists skip/shortlist states in local storage, and provides an undo mechanism for skipped items.
web/src/components/inbox · high confidence
Introduce local-first web UI with application workflow and assistant
This change introduces the new experimental local-first web UI (opt-in alpha). It adds the AppShell layout, a global AssistantConsole for conversational help, and a BackToTop floating control. The Apply workflow is now available via ApplyButton, ApplyView, and ApplyProvider, enabling users to open, review, and submit employer forms. Configuration is managed through ConfigForm, which now validates and persists the selected CLI ID against installed tools. Additional components include CompanyLogo (resolving logos by name), CvEditor, DeleteFromTracker, GeneratePdfButton, and mobile navigation, establishing the core application shell and state providers.
web/src/components · high confidence
Introduce local-first web dashboard with AI assistant and automated application support
This change introduces the core web application for the local-first career-ops dashboard. It adds an AI assistant interface that allows users to interact with their local AI CLI for career advice, CV parsing, and job evaluation. The dashboard includes an analytics page with pipeline visualization and score distribution. It also introduces a comprehensive application automation system, allowing users to open, fill, and drive application forms through a session-based API, with AI-assisted pre-filling and form interpretation. The system includes a central action registry to coordinate UI and AI actions, ensuring consistency. PDF generation for tailored CVs and cover letters is now served directly from the backend.
web/src/app · high confidence
Introduce opt-in plugin system for external integrations
Users can now extend career-ops with optional integrations that require API keys or external service access, such as the bundled Apify provider. This new layer is disabled by default; to use it, you must explicitly enable plugins in \config/plugins.yml\ and provide the necessary credentials in your \.env\. The system includes a curated registry for community plugins, integrity pinning to detect tampering, and strict security guards (SSRF prevention, egress allowlists, and mandatory human-in-the-loop) to ensure safe execution. Bundled plugins like Apify serve as reference implementations, while users can also install community plugins or create their own in the gitignored \plugins.local/\ directory.
plugins · high confidence
Introduces client-side pipeline state management and CV quality heuristics
This change adds a new React context provider for the pipeline, allowing both the main application pages and the assistant console to share and refresh inbox and application data from the /api/pipeline endpoint. It also introduces client-side logic to evaluate CV readiness based on word count and the presence of experience or skills sections, providing non-blocking hints to users while ensuring that even minimal CVs can be saved and scored.
web/src/components/pipeline, web/src/lib/cv · high confidence
Local document intake scaffold for profile updates
A new \documents/\ directory structure has been introduced to support local profile intake. This includes a \.gitkeep\ file to maintain the folder in version control and a \README.md\ that documents the expected subdirectories (\cv/\, \linkedin/\, \diplomas/\, \references/\) and explains how users can drop source documents there for the agent to process. The documentation clarifies that extraction is local, idempotent, and requires explicit user confirmation before any changes are made to profile files like \config/profile.yml\ or \cv.md\.
documents · high confidence
New 4 Day Week provider and shared infrastructure hardening
Added a new zero-auth provider for the 4 Day Week job board, which scrapes its public JSON API to aggregate reduced-hours roles. This release also introduces several shared infrastructure modules to the providers directory: a centralized HTML entity decoder (\_html-entities.mjs) to prevent code-point injection and ensure consistent decoding across all providers; a shared HTML-to-text pipeline (\_html-to-text.mjs) for safely stripping markup from job descriptions; an in-process DNS cache (\_dns-cache.mjs) to rate-limit resolver lookups and prevent DNS rebinding attacks; and an IP address guard (\_ip-guard.mjs) to block connections to private or reserved IP ranges. These changes collectively improve security posture and parsing reliability for all job-source providers.
providers · high confidence
New CV templates, CJK support, and agency licensing data
The templates area now includes five new named CV templates (Compact, Executive, Jake, Leadership, Modern) alongside a new CJK LaTeX variant that uses the tectonic engine for Chinese, Japanese, and Korean typography. The system also introduces a jurisdiction table for agency/recruiter licensing regimes (templates/agency-licensing.yml) used by the AI screening mode, a new market calibration benchmarks file (templates/benchmarks.yml), and a user-managed company blacklist (templates/blacklist.example.md) that gates scanning and application modes.
templates · high confidence
New CostBadge component for displaying cost semantics
A new CostBadge component has been added to the web UI to visually indicate cost status using specific color and icon semantics: green with a leaf icon for free/positive actions, and a muted neutral tone with a coin icon for spend (token usage). This component ensures that spend indicators do not conflict with primary action colors (orange) and maintains accessible contrast across both light and dark themes.
web/src/components/cost · high confidence
New Follow-up Tracker with logging, history, and cadence settings
Users can now manage their job application follow-ups directly in the web interface. The new FollowupsView component provides a sortable, filterable list of applications with urgency indicators and next-touch dates. You can log individual follow-up interactions (date, channel, contact, notes) via the LogDialog, which appends to the permanent history. For specific applications, the NextDateDialog allows you to pin a custom follow-up date, overriding the automatic schedule until a new interaction is logged. Additionally, the CadenceSettings component lets you configure the global timing rules (e.g., days between nudges, max follow-ups) which are saved to config/profile.yml and shared with the CLI core.
web/src/components/followups · high confidence
New H-1B Sponsor Check plugin for US role evaluation
Adds the \h1b-sponsor\ plugin, which allows career-ops users to verify an employer's actual US Department of Labor sponsorship history (LCA, PERM, and green card filings) before applying to US roles. The plugin resolves a company name to a specific DOL entity and returns a sponsorship tier (strong, moderate, staffing-shop, weak, none, or unknown) based on filing volume, recency, and green card evidence. It operates primarily via a local, offline index downloaded from public DOL data, ensuring that sensitive visa-intent queries never leave the user's machine by default; an optional HTTP backend can be enabled via the \H1B\_API\_BASE\ environment variable for remote lookups. The plugin includes a CLI (\check.mjs\) for manual checks, a companion agent skill for automated \oferta\ evaluations, and a secure installer for the local data index.
plugins/h1b-sponsor · high confidence
New UI component library for dashboard styling
Added four new UI components (Badge, Button, Card, StatCard) to the web interface. The Badge component provides semantic status pills (good/warn/bad/info/muted) with specific color coding. The Button component uses class-variance-authority to support primary, outline, ghost, and secondary variants with a minimum 44px tap target on small screens. The Card component offers optional gradient corners and elevation effects. The StatCard component displays metric values with optional serif typography for featured items, icons, and hover states.
web/src/components/ui · high confidence
New agentic form interpretation and application-file resolution logic
The Apply module now includes an agentic fallback that uses a local LLM to interpret live job-application forms when deterministic extraction fails, and introduces precise resolution for tailored cover letters and CVs tied to specific application records rather than just company names. The new \agent-interpret.ts\ captures interactive controls and asks the LLM to classify them into structured fields, while \cover.ts\ and \cv-match.mjs\ ensure that cover letters and CVs are matched to the correct application using both company and role slugs, preventing the wrong document from being attached. Additionally, \cv-selection.mjs\ updates the PDF manifest lookup to distinguish between CVs and cover letters by kind, and \diagnose.ts\ adds robust detection for blocks like captchas, login walls, and expired postings.
web/src/lib/apply · high confidence
New analytics screens and pipeline UI enhancements with comprehensive test coverage
The dashboard now includes a Progress screen for funnel and rate analytics, and a Stats screen for dimension-breakdown charts (archetypes, pay, score tiers). The pipeline view supports sorting by Location, Pay, Last-contact, and Posted date, and features a live search filter. Users can view and regenerate CV PDFs via hotkeys, and the integrated report viewer now supports cover letter opening and in-viewer status updates. Additionally, the help bar flash now sanitizes control characters to prevent terminal escape injection, and score sentinels render correctly without showing '0.0'. These changes are supported by extensive new tests covering flash sanitization, PDF key behavior, pipeline state preservation, search composition, width constraints, scroll clamping, and viewer status logic.
dashboard/internal/ui · high confidence
New automation scripts for syntax checking, ATS export, and follow-up sweeps
The repository now includes three new scripts to support development hygiene and career-ops automation. \scripts/check-syntax.mjs\ provides a zero-dependency syntax linter that runs \node --check\ on all \.mjs\ files, excluding generated and dependency directories to ensure deterministic results. \scripts/export-ats-text.mjs\ introduces a plain-text exporter for ATS forms, parsing markdown CVs and YAML profile data into structured sections (experience, education, skills, contact) while sanitizing special characters for seamless copy-pasting. Additionally, \scripts/followup-sweep.sh\ enables unattended follow-up automation via launchd or cron, using the Claude CLI to generate draft follow-up emails and LinkedIn messages based on application data, writing results to \output/\ for user review without sending anything automatically.
scripts · high confidence
New example files and documentation for career-ops data formats
Added reference examples and documentation in the \examples/\ directory to demonstrate expected data structures and conventions. This includes \cv-example.md\ and \resume-example.md\ for standard CV/resume formatting, \article-digest-example.md\ and \sample-report.md\ for evaluation pipeline outputs, and \ats-normalization-test.md\ as a regression fixture for Unicode normalization. A new \dual-track-engineer-instructor/\ folder provides a complete profile configuration (\profile.yml\) and CV (\cv.md\) for candidates with hybrid engineering and teaching roles, including guidance on configuring multiple primary archetypes and compensation ranges. Additionally, \latex-tex/\ fixtures support the new LaTeX extraction capabilities.
examples · high confidence
New local-first CV ingest and parsing workflow
Introduces a new CV ingestion component that allows users to paste text or drop files (Markdown, TXT, PDF, DOCX) for parsing. The component supports a fast path for plain-text files without requiring an external CLI, while PDF/DOCX files are sent to a local AI CLI for extraction. After parsing, users review the extracted content and save it, which automatically redirects them to the Job Explorer with pre-filled filters and triggers an initial job scan.
web/src/components/cv · high confidence
New local-first home dashboard with action queues
The home page now features a local-first UI that displays a 'Today' dashboard with three main sections: follow-ups due, applications awaiting a decision, and fresh matches from free scans. Users can mark follow-ups as logged, review decision cards, and see new matches directly from the home view. A first-run experience guides new users to upload their CV to start scanning. The dashboard ensures all interactive elements meet 44px tap-target requirements on mobile and uses proper Next.js navigation for links.
web/src/components/home · high confidence
New npx career-ops scaffolder for one-command workspace setup
Users can now run \npx career-ops init\ to automatically clone the latest release of the career-ops repository and install dependencies in a single step. The new \scaffolder/bin/cli.mjs\ script detects installed AI coding tools (such as Claude Code, Codex, Grok, and Pi) to tailor the post-installation instructions. It also includes a Windows-specific fix in \npm-command.mjs\ to reliably run \npm install\ without shell-injection risks, and \skill-entrypoints.mjs\ ensures that AI skill pointers are correctly materialized on filesystems that do not support symlinks.
scaffolder/bin · high confidence
New opt-in plugin system with governance and registry support
Users can now extend the platform using an opt-in plugin system that includes an engine, supply-chain governance, and a registry. The \plugins/\_template\ directory provides a starter kit for community plugins, defining the structure for manifests, hooks (such as ingest, export, and notify), and configuration via \config/plugins.yml\ and \.env\ secrets. The system enforces security by restricting network egress to approved hosts via \ctx.fetch\ methods and requires human-in-the-loop consent for plugin activation. A smoke test ensures plugins adhere to the declared hooks and manifest structure.
_plugins/\template · high confidence
New token usage tracking and cost estimation utility
A new \utils/token-tracker.mjs\ module has been added to centralize token counting and cost calculation for AI model interactions. This utility provides a \TokenAccumulator\ class to track token usage across pipeline steps, a \normalizeOpenAIUsage\ function to standardize usage data, and an \estimateCost\ function that applies pricing rates for models including MiniMax, OpenAI, Gemini, DeepSeek, and Anthropic. It also includes a \formatBreakdown\ function to generate human-readable reports of token consumption and estimated costs per step.
utils · high confidence
New web/lib modules for CLI security, data access, and UI helpers
This change introduces a suite of new modules in web/src/lib that establish a unified security and data-access layer for the web application. It adds cli-fencing.mjs and cli-fencing-probe.mjs to enforce a single, audited permission model across all headless AI runtimes (Claude, Codex, Grok, etc.), ensuring that write and network capabilities are strictly scoped per worker type and that CLI binaries are probed for supported flags before execution. It introduces claude-invocation.mjs to centralize Claude tool-scope definitions and argv construction, preventing permission drift. Data access is standardized via career-ops.ts, which provides a single source of truth for parsing pipeline, inbox, and tracker data, aligning web-side parsing with core logic. Additionally, it adds act-envelope.mjs to safely parse assistant console action markers, clean-chips.mjs to robustly handle keyword input, cli-launch.mjs to securely spawn CLIs on Windows without shell injection, and company-presentation.mjs/company-slug.mjs/company.ts to standardize employer identity and logo resolution.
web/src/lib · high confidence
Seed startup discovery from VC portfolios (Y Combinator, a16z)
Added a new seeding mechanism that pulls public company lists from Y Combinator and Andreessen Horowitz (a16z) to instantly cover hundreds of VC-backed startups, feeding them into the existing ATS job discovery pipeline. This provides a high-signal starting point for finding startup roles without waiting for companies to appear in public ATS directories, with support for combining these seeds alongside regular ATS sources.
seeds · high confidence
Behavioural changes
1606 commits (667 fixes) modifying (repo-wide)
A change to existing behaviour in (repo-wide) — 1606 commits (667 fixs), 201 files.
(repo-wide) · low confidence · unverified
Apply page now features a visual backdrop and tracks application origin
The Apply page now displays a full-viewport, blurred wallpaper backdrop during the session opening and prefilling phases to provide visual feedback while the form loads. Additionally, the application flow now records the specific page or path from which the user started the application, enabling a 'way back' navigation so users can return to their previous location after submitting.
web/src/components/apply · high confidence
Dashboard data layer: concurrency safety, analytics accuracy, and parsing robustness
The dashboard's data layer now enforces shared-file locking on tracker writes to prevent concurrent updates from overwriting each other, and it updates only the Status cell during status changes to avoid corrupting other columns. Analytics metrics are corrected so that 'Hired' applications correctly populate the entire funnel (Applied through Offer) and the top-stage count includes unscored rows without mislabeling them as 'Evaluated'. Un-evaluated applications now display a sentinel (e.g., '—') instead of '0.0', and the PDF resolution logic safely matches company slugs at hyphen boundaries to prevent false positives (e.g., 'Meta' matching 'Metabase'). Additionally, pay, location, and work-mode fields are derived more reliably from free-text notes using explicit currency lists and international city recognition.
dashboard/internal/data · high confidence
Enhanced bug-report diagnostics and deduplication via stable fingerprints
The in-app bug reporter now captures richer diagnostic data, including core version, API error status, and structural data-shape counts (without contents), while enforcing strict PII scrubbing of user descriptions and logs. A new client-side ring buffer captures recent errors and fetch failures, and a deterministic fingerprint (based on route, error class, and structural flags) is generated to enable click-gated deduplication of similar issues at write time. The report body format is now versioned (v1) to ensure stability for downstream triage tooling.
web/src/lib/report · high confidence
Local dashboard API restricted to same-origin and loopback by default
A new proxy middleware in web/src/proxy.ts now gates all /api requests with a same-origin and loopback check, preventing cross-site and LAN-based access by default. Users can opt-in to allow specific hosts or origins via the CAREER\_OPS\_WEB\_ALLOWED\_HOSTS and CAREER\_OPS\_ALLOWED\_ORIGINS environment variables, which is necessary for local companion clients like browser extensions that originate from chrome-extension:// URLs.
web/src · high confidence
Updated test fixtures for state v1.18 with new application tracking fields
The test fixtures in test-fixtures/upgrade have been updated to include state v1.18, introducing behavioral changes to the application tracking system. The applications tracker now includes a 'Via' column to record referral sources (e.g., 'Hays'), and job reports feature a new 'Machine Summary' section containing structured YAML data for company, role, score, and decision details. Additionally, a new 'salary-observations.tsv' file tracks salary data, and the expected state validation now accounts for these new fields.
test-fixtures · high confidence
Fixes
Added placeholder files for batch, JDS, and output directories
Added .gitkeep placeholder files to the batch/logs, jds, and output directories to ensure these directories are tracked by version control even when empty.
batch/logs, jds, output · high confidence
Beta bug reporter now signals when duplicate search fails
The beta bug reporter's duplicate-check feature now clearly distinguishes between a successful search that found no matches and a search that could not run at all. Previously, network errors or API failures (such as HTTP 422 from a repository move) were silently treated as 'no similar issues found,' hiding the error from users. The underlying search module now returns \null\ to indicate a failure state, allowing the UI to inform the user that the check could not be completed rather than falsely claiming no duplicates exist.
web/src/lib/beta · high confidence
Fixes Today queue ordering and status matching for evaluated applications
The Today page now correctly displays scored but undecided applications by using a dedicated alias table to match 'Evaluated' statuses across all supported languages, rather than relying on a fragile English prefix check that previously hid items in non-English trackers. Additionally, the queue is now explicitly sorted by recency (newest first) and then by score, ensuring a consistent and predictable order instead of relying on arbitrary data row order. This logic is extracted into reusable modules to ensure the sorting behavior is testable and stable.
web/src/lib/home · high confidence
Introduce local job tracking and improved error visibility in the web UI
The web interface now tracks job execution state locally using a new \JobsProvider\ and \WorkerCard\ components, persisting job history in \localStorage\ so that interrupted jobs are correctly marked as errors on reload. This change validates the saved CLI ID against installed versions before starting a run to prevent failures caused by missing CLIs, and displays specific, cause-aware error hints (including fencing notices) instead of generic authentication prompts when jobs fail.
web/src/components/jobs · high confidence
New shared library modules for CLI, CV, and evaluation logic
This change introduces a suite of new utility modules in the \lib/\ directory to standardize and fix core behaviors across the application. \cli-flags.mjs\ provides shared helpers for robust argument parsing, fixing issues where \--flag=value\ syntax was silently ignored and ensuring unrecognized flags fail fast. \ascii-fold.mjs\ introduces a new function to correctly fold accented names to ASCII for comparison, resolving matching failures for companies with non-Latin characters. \cv-payload-schema.mjs\ defines a strict validation contract for CV payloads, preventing silent data loss when builders encounter unknown or misspelled section keys. \context-budget.mjs\ adds token budget management and priority-based compression for LLM context windows, keeping evaluation-critical sections intact while trimming less important ones. \is-main-module.mjs\ fixes a bug where CLI scripts failed to run when accessed via symlinks by canonicalizing path comparisons. \latex-escape.mjs\ and \latex-content.mjs\ improve LaTeX CV generation by properly escaping special characters in URLs and supporting in-place tailoring of user-owned templates. \gemini-node-floor.mjs\ centralizes the Node.js version requirement for the Gemini integration, providing a clear runtime verdict. \local-today.mjs\ corrects date handling to use the local timezone, fixing issues where 'today' was incorrectly calculated for users in different time zones.
lib · high confidence
Restored and enhanced the beta bug-reporting banner
The beta banner component has been restored and updated to provide a local-first, privacy-preserving way for users to report issues. It now includes a click-gated deduplication feature that searches for similar open GitHub issues before submission, and clearly informs users when this check cannot run. The report dialog pre-fills a GitHub issue with scrubbed diagnostic data, ensuring no sensitive personal information is sent until the user explicitly confirms.
web/src/components/beta · high confidence
Web core library mirrors core checkout logic for paths, locking, and text normalization
The web application now includes a comprehensive set of core utility modules that replicate the behavior of the user's local career-ops checkout, ensuring consistency between the web UI and the CLI. This includes \data-root.mjs\ and \code-root.mjs\ to resolve the correct data and script directories, \ascii-fold.mjs\ and \normalize-text-key.mjs\ for Unicode-safe company and role matching, and \followups-lock.ts\ to prevent race conditions when writing follow-up data. Additional modules handle CV template resolution, pipeline sorting, logo caching, and atomic file writes, all designed to prevent silent data loss or incorrect behavior when the web runtime is separated from the core checkout.
web/src/lib/core · high confidence
Test coverage
Add visual regression and PDF reading-order tests for CV templates; Added test suite for web application logic; Added tests for pipeline sort tie-breaking and score parsing; Expanded provider test coverage and shared utility validation; Expanded test coverage for core application logic and CLI validation; Expanded test fixtures for job-scan deduplication and provider parsing.
Dependencies
Major dependency upgrades and scaffolder introduction
This release upgrades core dependencies across the project: the web interface now uses Next.js 16.3.4, React 19.2.5, and js-yaml 5.0.0, while the root CLI updates Playwright to 1.63.0, js-yaml to 5.3.0, and adds the Google Generative AI SDK. The Go-based dashboard bumps the Go toolchain to 1.26.0 and updates terminal libraries (charmbracelet/x/ansi, golang.org/x/sys). Additionally, a new scaffolder package (@santifer/career-ops) is introduced to provide a one-command installer for the pipeline.
(dependencies) · high confidence
Housekeeping
Creation of empty data directories
Empty placeholder files (.gitkeep) were added to the data, data/offers, and data/parser-output directories to ensure these folders are tracked by version control.
data · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 50 → 50 (+0.4)
- Rubric changed (rubric-2026.09.11 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 33 → 37 (+3.8)
- Architecture 89 → 84 (-5.2)
- Maturity 72 → 72 (-0.3)
- Readiness 74 → 62 (-11.9)
- Security 71 → 81 (+9.8)
- Accessibility 55 → 57 (+2.2)
- Performance 62 (new)
Resolved (117)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- FunctionTooLong: scan.runDiscovery (web/src/lib/core/scan.ts)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- High: security finding (details withheld)
- Hotspot: assessment-log.mjs (assessment-log.mjs)
- Hotspot: batch/aggregate-tokens.mjs (batch/aggregate-tokens.mjs)
- Hotspot: check-liveness.mjs (check-liveness.mjs)
- Hotspot: check-table-freshness.mjs (check-table-freshness.mjs)
- Hotspot: company-funded.mjs (company-funded.mjs)
- Hotspot: contacts.mjs (contacts.mjs)
- Hotspot: fingerprint-core.mjs (fingerprint-core.mjs)
- Hotspot: fix-slugs.mjs (fix-slugs.mjs)
- Hotspot: intake.mjs (intake.mjs)
- Hotspot: lib/cv-payload-schema.mjs (lib/cv-payload-schema.mjs)
- …and 97 more
New (251)
- Critical vulnerability: [GHSA redacted] (web/package-lock.json)
- Documentation: no licence statement (README.md)
- Documentation: no project overview (README.md)
- Duplicated block (10 lines × 2) (dashboard/internal/ui/screens/progress.go)
- Duplicated block (12 lines × 2) (dashboard/internal/data/pdf.go)
- Duplicated block (12–14 lines × 2) (dashboard/internal/data/career.go)
- Duplicated block (16 lines × 2) (dashboard/internal/ui/screens/pipeline.go)
- Duplicated block (16 lines × 2) (dashboard/internal/ui/screens/progress.go)
- Duplicated block (17–18 lines × 2) (dashboard/internal/data/pdf.go)
- Duplicated block (19–20 lines × 2) (dashboard/internal/ui/screens/pipeline.go)
- Duplicated block (24–28 lines × 2) (dashboard/internal/ui/screens/progress.go)
- Duplicated block (26–27 lines × 2) (dashboard/internal/ui/screens/pipeline.go)
- Duplicated block (30–31 lines × 2) (dashboard/internal/data/career.go)
- Duplicated block (5 lines × 3) (dashboard/internal/ui/screens/stats.go)
- Duplicated block (6 lines × 3) (dashboard/internal/ui/screens/progress.go)
- Duplicated block (7 lines × 2) (dashboard/internal/data/career.go)
- Duplicated block (7 lines × 3) (dashboard/internal/ui/screens/progress.go)
- Duplicated block (8 lines × 4) (dashboard/internal/ui/screens/pipeline.go)
- Duplicated block (8–10 lines × 2) (dashboard/internal/ui/screens/pipeline.go)
- Duplicated block (9 lines × 2) (dashboard/internal/data/pdf.go)
- …and 231 more
Changes since last survey
- 300 commits — 157 feature/other, 143 fixes
By area
- (root) — 179 commits
- web/src — 30 commits
- tests/providers — 9 commits
- .github/scripts — 8 commits
- docs/SUPPORTED_JOB_BOARDS.md — 8 commits
- .github/workflows — 5 commits
- dashboard/internal — 5 commits
- docs/avatar-santifer.png — 3 commits
- docs/manifesto-wall.svg — 3 commits
- modes/ko — 3 commits
- (repo) — 2 commits
- batch/README.md — 2 commits
- batch/batch-prompt.md — 2 commits
- modes/_shared.md — 2 commits
- modes/apply.md — 2 commits
- modes/zh — 2 commits
- tests/fixtures — 2 commits
- web/package-lock.json — 2 commits
- batch/batch-runner.sh — 1 commit
- config/profile.example.yml — 1 commit
Notable commits
- fix: Fix web status filters for external data roots (#4410)
- fix: fix(agents): scope onboarding and keep diagnostics read-only (#4428)
- fix: fix(analyze-patterns): validate threshold and vendor flags (#4007)
- fix: fix(application-answers): find the draft block by a trailing (draft) marker (#4432)
- fix: fix(application-answers): parse Block H when its heading is localized (#4400)
- fix: fix(apply): hand off Ashby submission to system browser (#4443)
- fix: fix(apply): the code-fence strip reached inside JSON string values (#3302)
- fix: fix(apply): validate answers against live field limits (#4442)
- fix: fix(ashby): read the salary range from compensationTiers[].components[] (#4331)
- fix: fix(avature): read article--jobs cards, titled from the h3 anchor (#4559)
- fix: fix(batch): add adaptive rate-limit backoff (#4370)
- fix: fix(batch): fail closed on no-op workers and archive the verbatim JD (#4422)
- fix: fix(batch): reject explicit zero offer limits (#4308)
- fix: fix(batch): require parent confirmation for delegated agency postings (#4371)
- fix: fix(batch): resolve batch-prompt.md placeholders to stable labels (#4517)
- fix: fix(batch-evaluate): _profile.md and tracker-additions resolve to the code root (#4347) (#4348)
- fix: fix(build-cv-html): render each project bullets item as its own block (#4300)
- fix: fix(ci): pin the upgrade gate to the main channel so it stays hermetic (#4470)
- fix: fix(ci): pr-triage workflow_run finds fork PRs by head owner:branch, skips main (#4407)
- fix: fix(cli): scan-hn.mjs delegates --help and unknown flags to lib/cli-flags.mjs (#4627)
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
career-ops-hq/career-ops was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 1 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 625a82c29ab96747355f8717dc63ce359a3c75e4 — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.