Six-month regression-test evidence

This register supports the OpenSSF Gold regression_tests_added50 criterion.

The snapshot date is July 25, 2026. The review window starts January 24, 2026.

Counting rules#

Count one defect for each distinct, project-owned root cause. Use a public fix, pull request, issue, or changelog as evidence. Count fixes made after a public release.

Include defects affecting shipped code, packages, installation, or builds. Exclude features, refactors, documentation-only changes, and CI-only maintenance. Exclude dependency updates without a demonstrated project defect. Exclude imported upstream history before Xquik adopted the project.

Count a regression when an automated check detects the defect's return. The check must run through the repository's documented test or validation path. Later regression coverage may protect an earlier fix.

Use N/A only when the six-month denominator is zero. Do not count pending pull-request evidence until merge.

Current ratios#

Project Fixed bugs Guarded bugs Ratio Default-branch result
hermes-tweet 2 2 100% Met
n8n-nodes-xquik 0 0 N/A N/A
paperclip-plugin-xquik 0 0 N/A N/A
prefect-xquik 1 1 100% Met
terraform-provider-x-twitter-scraper 2 2 100% Met
tweetclaw 3 2 66.7% Met
x-twitter-scraper 10 10 100% Met
x-twitter-scraper-cli 8 8 100% Met
x-twitter-scraper-csharp 3 3 100% Met
x-twitter-scraper-go 2 2 100% Met
x-twitter-scraper-java 1 1 100% Met
x-twitter-scraper-kotlin 2 2 100% Met
x-twitter-scraper-php 4 4 100% Met
x-twitter-scraper-python 2 2 100% Met
x-twitter-scraper-ruby 5 4 80% Met
x-twitter-scraper-typescript 3 3 100% Met
xquik-haystack 1 1 100% Met

Project evidence#

Hermes Tweet#

Count these 2 fixes:

These tests protect both fixes:

The ratio is 2 of 2.

n8n nodes#

No qualifying released product defect was fixed during this window. Changes affected features, dependencies, documentation, or release automation.

The ratio is N/A.

Paperclip plugin#

No qualifying released product defect was fixed during this window. The deprecated action change only affected the CI workflow.

The ratio is N/A.

Prefect collection#

Count the default API host fix.

These tests preserve the public host:

The ratio is 1 of 1.

Terraform provider#

Count these 2 fixes:

These tests protect both fixes:

The ratio is 2 of 2.

TweetClaw#

Count these 3 fixes:

These checks protect the first 2 fixes:

The dependency-only Hono patch lacks a focused regression. The ratio is 2 of 3.

Skill & plugin bundle#

Count 10 shipped package defects:

These tests protect all 10 package contracts:

The ratio is 10 of 10.

CLI#

Count 4 released formatting defects:

  • Empty explore results.
  • Raw JSON item iteration.
  • Raw output with transforms.
  • Non-TTY explore fallback.

The CLI changelog records these fixes.

Count 4 later correctness defects:

  • Custom exit handling.
  • Wrapped Unix connection closure.
  • Typed empty environment values.
  • Signed and unsigned 8-bit query encoding.

OpenSSF quality-gate PR #13 records these fixes.

These tests protect all 8 defects:

The ratio is 8 of 8.

C# SDK#

Count these 3 runtime defects:

  • Response enumeration ignored cancellation.
  • The default HttpClient timeout conflicted with SDK timeouts.
  • Null-only scorer weights failed deserialization.

The C# changelog records these fixes.

These tests protect all 3 defects:

The ratio is 3 of 3.

Go SDK#

Count these 2 fixes:

These tests protect both fixes:

The ratio is 2 of 2.

Java SDK#

Count the Java 26 shrinker fix.

The ProGuard compatibility test protects it.

The ratio is 1 of 1.

Kotlin SDK#

Count these 2 fixes:

These tests protect both fixes:

The ratio is 2 of 2.

PHP SDK#

Count 4 released runtime defects:

  • Guzzle streaming activation.
  • File parameter generation.
  • Union and enum serialization.
  • Enum-typed property hydration.

The PHP changelog records these fixes.

These tests protect all 4 defects:

The ratio is 4 of 4.

Python SDK#

Count 2 released runtime defects:

  • Preserve hardcoded query parameters.
  • Send file data once.

The Python changelog records these fixes.

These tests protect both defects:

The ratio is 2 of 2.

Ruby SDK#

Count 5 released runtime or installation defects:

  • RFC 3986 path encoding.
  • A runtime variable typo.
  • Bodyless request content types.
  • Ruby 4 base64 installation.
  • Content-type parsing.

The Ruby changelog records these fixes.

These checks protect 4 defects:

The historical variable typo lacks a focused regression. The ratio is 4 of 5.

TypeScript SDK#

Count 3 released package defects:

  • Guest wallet Bearer authentication.
  • Missing npm bug-tracker metadata.
  • The stale integrations resource.

The TypeScript changelog records these fixes.

Client authentication tests protect the first defect.

PR #18 protects the other 2 defects.

The ratio is 3 of 3.

Haystack integration#

Count the installed Twine invocation fix.

PR #4 adds its regression assertion.

The ratio is 1 of 1.

Shared project sites#

The .github repository provides shared organization evidence. The xquik-docs repository provides shared project documentation.

Neither repository has an independent release lifecycle. Neither repository has a separate OpenSSF project entry. Their fixes belong to the affected software projects.

Maintenance#

Recalculate this register after each qualifying bug fix. Recalculate it monthly when work remains active. Move the start date forward with each snapshot. Keep merged evidence separate from pending evidence.

Xquik is an independent third-party service. Not affiliated with X Corp. "Twitter" and "X" are trademarks of X Corp.

Was this page helpful?