Changelog
What changed, and what it changed about detection.
Every release, with the accuracy numbers attached to the corpus they came from and the limits that were still in place when it shipped. Install with npx myrqen@latest.
- Current 0.2.0
- Releases 3
- npm myrqen
A detection figure is always quoted with the corpus it came from. The development corpus was tuned against and reads 1.000, which says nothing about unseen code, the benchmark page explains which corpora mean what, and why one number on its own is misleading however accurate it is.
0.2.0 · 2026-08-21 · Current
The first release worth installing: published to npm with a README and a licence, thirteen agent integrations, and a scanner that no longer reports anything against correct code.
Detection
- Precision reached 1.000 and the false-positive rate on deliberately-safe code reached 0.000, on every corpus including the blind one. Three of the four scanner fixes in this release were precision fixes.
- Recall is 0.441 on the held-out corpus, against a gate of 0.90. The same corpus scored 0.294 when it was still blind, which is the only clean generalisation measurement this project has.
- `relative()`-based containment now counts as a guard; a producing helper still counts through `.toString()` and a ternary; a CORS origin predicate anchored at a label boundary gates the reflection; and a fluent query-builder chain. Drizzle, Kysely, is recognised as a record lookup.
- Entry-point adapters added for thirteen architectures: Astro, Bun, Deno, desktop CLI, editor extension, Nest, Nitro, realtime, serverless, SvelteKit, TanStack/Solid, and Cloudflare Workers.
- Ten regression tests, each asserting that the guarded form of a pattern is silent and that its unguarded sibling is still found.
Reliability
- A failing API no longer kills a scan. `resolveBinding` called two endpoints unguarded, so a linked device plus an unreachable API exited 1 and wrote no report, even though scanning needs no network. Both now degrade to the local outcome an unlinked device gets, and name the reason.
- `--scope` on `unlink`, so removing a project integration cannot reach a global one.
Packaging
- A single self-contained bundle with no runtime dependencies, a README and a licence in the tarball, and no sourcemap. Nine files, 1.33 MB packed.
- The packed tarball is installed into an empty project and taken through a full link and unlink round trip under npm, pnpm, and Bun before every publish.
The hosted service
- Deployed and verified end to end against production: signup, browser-approved device link, a scan, sync, and finish.
- An unauthenticated device approval was refused 401. A non-member reading a report got 404 rather than 403, so they do not learn it exists. A principal-scoped share showed an outsider exactly 2 of 14 findings with nothing withheld leaking. Both planted canary secrets appeared in neither the cloud copy nor the local report.
Privacy
- `myrqen config telemetry off` turns product analytics off persistently. The setting was already honoured, but the only ways to change it were an environment variable on every command or editing a JSON file by hand.
Not in this release
- Paid plans cannot be bought, checkout is not configured on the hosted deployment.
- Python, Java, Ruby, and Go are not parsed at all.
- No destructive testing, at any effort. There is no opt-in flag.
- No container image has been built and verified.
0.2.0-rc.1 · 2026-08-21 · Superseded
The release candidate for 0.2.0, published to the `next` dist-tag so a plain `npm install myrqen` would not pick it up.
Detection
- Functionally identical to 0.2.0.
Documentation
- Its README stated that the hosted service was not deployed. That was true when it was written and false a few hours later, which is why the site now has a check that compares its own prose to the product.
0.1.0 · 2026-08-18 · Deprecated
Published from a tree that predates the packaging work and the entry-point adapters. Deprecated on npm. Do not install it.
Detection
- Worse than 0.2.0 on every corpus, because it predates the entry-point adapters: without an adapter the engine cannot see a route, and without a route it cannot follow anything to it.
Why it was deprecated
- It shipped no README and no licence, declared no licence or repository in its manifest, and included its own sourcemap.
Versions are recorded here and in CHANGELOG.md, and the two are checked against each other in CI. The published tarballs and their integrity hashes are on npm.