A self-managing pipeline ingests downloads, GitHub activity, dependency graphs, vulnerabilities and security-health metrics every day, then trains gradient-boosted models to forecast adoption momentum and dependency risk across the Python / AI ecosystem. Seven deterministic operational roles validate each run, gate model promotion, and publish the brief; Claude is optional and never participates in prediction.
Run history, error status, and the latest persisted pipeline and agent logs.
| Run | Status | Duration | Packages | Predictions | Git SHA |
|---|
Click any row for the full signal breakdown, download trajectory and model reasoning.
| Package | Category | Momentum | Risk | Δ70d | Stars | Dependents | Vulns |
|---|
Every daily run evaluates growth and risk challengers against fixed, time-aware evidence. Quality can move up or down; only a challenger that clears the validation gate and beats the current champion is promoted. This chart is the audit trail, not a promise of monotonic improvement.
| Run | Model | Version | Metric | n_train | Champion |
|---|
The growth model graded on a time-aware held-out test, recomputed every run. This is a cross-sectional ranking — Spearman is the metric that matters; the absolute R² is leak-sensitive. See the Validation tab for the honest, leak-free numbers and confidence intervals.
A statistical harness plus a 12-agent LLM statistician panel stress-tested the headline and found two data leaks and a strawman baseline. Honest verdict: a cross-sectional ranked momentum watchlist, not a time-forward forecast. Full report →
Unlike the cross-sectional growth model, the daily download series supports proper time-series work: every assumption is hypothesis-tested, and short-horizon forecasts are rolling-origin validated. Harness →
Paste your requirements.txt — get a supply-chain risk report on your dependencies:
version-aware vulnerabilities, maintenance risk, release staleness, and adoption trend. Watchlist
packages are instant; anything else is fetched live from the same sources.
==x.y.z versions get an active-CVE check. Or paste a GitHub repo URL.Seven role-scoped, deterministic agents manage the pipeline each day — they do not make predictions. They check ingestion freshness, validate data quality, retrain and gate models, write the brief, and open the daily PR. Claude may rewrite brief prose when configured; the data and scores remain deterministic.