{"_id":"@a11yst/policy","_rev":"3-cbd81b762ae516992d074e3f894c49f4","name":"@a11yst/policy","dist-tags":{"latest":"1.0.2"},"versions":{"1.0.0":{"name":"@a11yst/policy","version":"1.0.0","license":"MPL-2.0","_id":"@a11yst/policy@1.0.0","maintainers":[{"name":"angelabenavente","email":"ang.ben.dev@gmail.com"}],"homepage":"https://github.com/angelabenavente/a11yst#readme","bugs":{"url":"https://github.com/angelabenavente/a11yst/issues"},"dist":{"shasum":"a27a22ec0ee1743a5257c2300d36d1a12b86af3c","tarball":"https://registry.npmjs.org/@a11yst/policy/-/policy-1.0.0.tgz","fileCount":35,"integrity":"sha512-rchId5QSJKJntZjcoP2FDxLnk851ScZKWc5rn/nfzmZ47EA7Kq3R+ktjyEm3NoqCo91DmeN9WfmSHH7duttm0g==","signatures":[{"sig":"MEUCIA36SiV05G66eZOP+NPt6blogKejKw/OyfBgt0rob98fAiEA1DH1X7IaIeR43qcHGZVhCSkRgpic5uRdf2uaqPUz8p8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":52309},"main":"./dist/index.js","type":"module","_from":"file:a11yst-policy-1.0.0.tgz","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"build":"tsc -p tsconfig.json","clean":"rm -rf dist *.tsbuildinfo","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"angelabenavente","email":"ang.ben.dev@gmail.com"},"_resolved":"/private/var/folders/tf/l5jz90dj0yncc_ds04tbfs5c0000gn/T/b524bbe0107e93fd9cde790cc1e29cdc/a11yst-policy-1.0.0.tgz","_integrity":"sha512-rchId5QSJKJntZjcoP2FDxLnk851ScZKWc5rn/nfzmZ47EA7Kq3R+ktjyEm3NoqCo91DmeN9WfmSHH7duttm0g==","repository":{"url":"git+https://github.com/angelabenavente/a11yst.git","type":"git"},"_npmVersion":"10.9.0","description":"Pure CI policy evaluation for a11yst audit results","directories":{},"_nodeVersion":"22.12.0","dependencies":{"@a11yst/types":"1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.2"},"_npmOperationalInternal":{"tmp":"tmp/policy_1.0.0_1787506229664_0.12688935307237448","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@a11yst/policy","version":"1.0.1","license":"MPL-2.0","_id":"@a11yst/policy@1.0.1","maintainers":[{"name":"angelabenavente","email":"ang.ben.dev@gmail.com"}],"homepage":"https://github.com/angelabenavente/a11yst#readme","bugs":{"url":"https://github.com/angelabenavente/a11yst/issues"},"dist":{"shasum":"b919fef641ad91801bfb2d5750ec308bffc199a8","tarball":"https://registry.npmjs.org/@a11yst/policy/-/policy-1.0.1.tgz","fileCount":35,"integrity":"sha512-xkFgPp/4FfAL/rVhpA0nSwgEF4ijWIZ1hnfUC0Hap8MiVWXRTIAvYVOxW3PLONa6tbU4jZs17T/5jMugYiQegQ==","signatures":[{"sig":"MEUCIEhV+TSbyUmoWakAFxfB5pMFJ9IIzXOfxrgyEsO2383RAiEApl0khmSRX7lNKy+0tAXPZjOiC6c0gUiZH5mXS94WyeM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":52309},"main":"./dist/index.js","type":"module","_from":"file:a11yst-policy-1.0.1.tgz","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"build":"tsc -p tsconfig.json","clean":"rm -rf dist *.tsbuildinfo","typecheck":"tsc -p tsconfig.json --noEmit"},"_npmUser":{"name":"angelabenavente","email":"ang.ben.dev@gmail.com"},"_resolved":"/private/var/folders/tf/l5jz90dj0yncc_ds04tbfs5c0000gn/T/316e9204d9b7949cec3d02eab6b08765/a11yst-policy-1.0.1.tgz","_integrity":"sha512-xkFgPp/4FfAL/rVhpA0nSwgEF4ijWIZ1hnfUC0Hap8MiVWXRTIAvYVOxW3PLONa6tbU4jZs17T/5jMugYiQegQ==","repository":{"url":"git+https://github.com/angelabenavente/a11yst.git","type":"git"},"_npmVersion":"10.9.8","description":"Pure CI policy evaluation for a11yst audit results","directories":{},"_nodeVersion":"22.23.1","dependencies":{"@a11yst/types":"1.0.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.7.2"},"_npmOperationalInternal":{"tmp":"tmp/policy_1.0.1_1787508664028_0.4747975278929475","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@a11yst/policy","version":"1.0.2","description":"Pure CI policy evaluation for a11yst audit results","type":"module","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"main":"./dist/index.js","types":"./dist/index.d.ts","dependencies":{"@a11yst/types":"1.0.2"},"devDependencies":{"typescript":"^5.7.2"},"license":"MPL-2.0","repository":{"type":"git","url":"git+https://github.com/angelabenavente/a11yst.git"},"homepage":"https://www.a11yst.dev","bugs":{"url":"https://github.com/angelabenavente/a11yst/issues"},"publishConfig":{"access":"public"},"scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.json --noEmit","clean":"rm -rf dist *.tsbuildinfo"},"_id":"@a11yst/policy@1.0.2","_integrity":"sha512-dN4HCS62UMXiBJqx/7jK8bih5UEzAxAhrISSmCpC5tLNlIJnvXlyq3kGTGGg2eb01dnpkd/7xv88PrNgKn7Fhw==","_resolved":"/private/var/folders/tf/l5jz90dj0yncc_ds04tbfs5c0000gn/T/e0801aec17f8b0cb6374d1c8a5d3c14f/a11yst-policy-1.0.2.tgz","_from":"file:a11yst-policy-1.0.2.tgz","_nodeVersion":"22.23.1","_npmVersion":"10.9.8","dist":{"integrity":"sha512-dN4HCS62UMXiBJqx/7jK8bih5UEzAxAhrISSmCpC5tLNlIJnvXlyq3kGTGGg2eb01dnpkd/7xv88PrNgKn7Fhw==","shasum":"d46a6f38470aa13005d739e4f16dc634f04e7594","tarball":"https://registry.npmjs.org/@a11yst/policy/-/policy-1.0.2.tgz","fileCount":35,"unpackedSize":52625,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEMCH056sPTPZ1iUqZdtKkq/5ZvY0O4cFnDEQOFLlZQfB8ICIC9MXSLaEcfABqrK6EPmQdbKTOyMU2/wFL+a9HUA/Nss"}]},"_npmUser":{"name":"angelabenavente","email":"ang.ben.dev@gmail.com"},"directories":{},"maintainers":[{"name":"angelabenavente","email":"ang.ben.dev@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/policy_1.0.2_1787683101285_0.33934501107121773"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-23T17:30:29.457Z","modified":"2026-08-25T18:38:21.611Z","1.0.0":"2026-08-23T17:30:29.812Z","1.0.1":"2026-08-23T18:11:04.160Z","1.0.2":"2026-08-25T18:38:21.435Z"},"bugs":{"url":"https://github.com/angelabenavente/a11yst/issues"},"license":"MPL-2.0","homepage":"https://www.a11yst.dev","repository":{"type":"git","url":"git+https://github.com/angelabenavente/a11yst.git"},"description":"Pure CI policy evaluation for a11yst audit results","maintainers":[{"name":"angelabenavente","email":"ang.ben.dev@gmail.com"}],"readme":"# @a11yst/policy [![NPM version](https://img.shields.io/npm/v/@a11yst/policy.svg?style=flat)](https://www.npmjs.com/package/@a11yst/policy) [![License: MPL-2.0](https://img.shields.io/badge/License-MPL--2.0-blue.svg)](LICENSE) [![NPM total downloads](https://img.shields.io/npm/dt/@a11yst/policy.svg?style=flat)](https://www.npmjs.com/package/@a11yst/policy)\n\nPure CI policy evaluation for a11yst audit results.\n\nThis package decides whether audit findings **would fail a CI policy gate**.\nIt does not run audits, read files, or set `process.exitCode`. `@a11yst/core`\ncalls `evaluateCiPolicy` after an audit; `@a11yst/cli` maps that result through\n`getAuditExitCode`.\n\n## What it evaluates\n\n- **New findings** when `failOnNew` is enabled.\n- **Regressions** when `failOnRegression` is enabled.\n- **Expired classifications** when `failOnExpiredClassification` is enabled.\n- **Severity threshold** via `minimumSeverity` (`minor` → `critical` ordering).\n\nInputs are structured in-memory objects (`Finding[]`, `baselineUsed`, policy\nconfig). The evaluator never reads `results.json`, baseline files, or\nenvironment variables.\n\n## Defaults (backwards compatible)\n\nWhen `ci` is omitted from a11yst config, all gates are **off**:\n\n```ts\n{\n  failOnNew: false,\n  failOnRegression: false,\n  failOnExpiredClassification: false,\n  minimumSeverity: \"high\",\n}\n```\n\nWith defaults, **no findings block** and `policyEnabled` is `false`.\n\n## Dispositions\n\nThese dispositions are **excluded** from policy breaches:\n\n- `false-positive`\n- `not-applicable`\n\nThese are **not** auto-excluded and may breach when new/regressed:\n\n- `accepted-risk`\n- `third-party`\n- `manual-review`\n\n## Baseline requirement\n\nWhen any CI flag is enabled, evaluation requires `baselineUsed: true`.\nOtherwise the result is `not-evaluated` — findings are **not** treated as new.\n\n`resolved` and `not-compared` baseline entries never produce breaches.\n\n## Policy breach vs operational error\n\nOperational failures (invalid config, browser launch errors, corrupt baseline\nfiles) belong to the audit/CLI layer. This evaluator may receive audit\ndiagnostics but does **not** convert them into policy breaches.\n\n## Expiration vs regression\n\nWhen a finding regresses solely because a classification expired and both\n`failOnRegression` and `failOnExpiredClassification` are enabled, the\nevaluator emits a **single** `expired-classification` breach (not two).\n\n## Exit codes\n\n`getAuditExitCode` maps audit completion and policy evaluation for the CLI:\n\n| Code | Meaning |\n| --- | --- |\n| `0` | Audit completed; policy disabled or passed |\n| `1` | Operational/config error, audit incomplete, or policy not evaluated |\n| `2` | Audit completed; configured CI policy failed |\n\nThe package returns the code. It does not exit the process.\n\n## Public API\n\n- `evaluateCiPolicy(input)` — main evaluator\n- `isSeverityAtLeast(severity, minimum)`\n- `isPolicyEnabled(policy)`\n- `isPolicyExcludedDisposition(disposition)`\n- `dedupeFindings(findings)`\n- `mergeDuplicateFinding(existing, incoming)`\n- `resolveCiPolicyConfig({ configPolicy, cliOverrides })`\n- `isValidMinimumSeverity(value)`\n- `getAuditExitCode(input)`\n- `SEVERITY_ORDER`, `severityRank`, `compareSeverityDescending`\n","readmeFilename":"README.md"}