{"_id":"@abdelrahmannasr/sdlc-workflow","_rev":"9-9b75001581b3825559328bd143cfe69f","name":"@abdelrahmannasr/sdlc-workflow","dist-tags":{"latest":"1.3.2"},"versions":{"0.1.0":{"name":"@abdelrahmannasr/sdlc-workflow","version":"0.1.0","keywords":["sdlc","bmad","workflow","cli","spec-driven-development"],"author":{"name":"AbdelRahman Nasr"},"license":"MIT","_id":"@abdelrahmannasr/sdlc-workflow@0.1.0","maintainers":[{"name":"abdelrahmannasr","email":"a.nasr.yocto@gmail.com"}],"homepage":"https://github.com/abdelrahmannasr/sdlc-workflow#readme","bugs":{"url":"https://github.com/abdelrahmannasr/sdlc-workflow/issues"},"bin":{"sdlc":"bin/sdlc.mjs"},"dist":{"shasum":"6b118134043091d6c20a5baf60c4bc549d2f9e45","tarball":"https://registry.npmjs.org/@abdelrahmannasr/sdlc-workflow/-/sdlc-workflow-0.1.0.tgz","fileCount":64,"integrity":"sha512-M1sPg3NHZ1NVjQqef7DST9k7QKDTvd9rrRmAsUbHKNgjLKnqV5EPI0GdoYeolILjSbN5R85CL0GD2QNmciygkw==","signatures":[{"sig":"MEQCIBN30dy3jcllFIZE9UMPltn5OEsaJjYQhD5WMQMBee6jAiATILkNnnmyjltmWgvR7LVJTsHvTiZAma/aWT3qLqM/lA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":309364},"type":"module","engines":{"node":">=18"},"gitHead":"5f1b3d33b4124938009d944d2b7341b085768e56","scripts":{"sdlc":"node bin/sdlc.mjs","test":"node --test cli/test.mjs","prepublishOnly":"npm test"},"_npmUser":{"name":"abdelrahmannasr","email":"a.nasr.yocto@gmail.com"},"repository":{"url":"git+https://github.com/abdelrahmannasr/sdlc-workflow.git","type":"git"},"_npmVersion":"10.8.2","description":"Guided setup & maintenance CLI for the gated, team, multi-repo SDLC Workflow module.","directories":{},"_nodeVersion":"20.19.5","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"semantic-release":"^24.2.3","@semantic-release/git":"^10.0.1","@semantic-release/changelog":"^6.0.3"},"_npmOperationalInternal":{"tmp":"tmp/sdlc-workflow_0.1.0_1780958838111_0.7777361964509808","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed — install 'yadflow' instead (same CLI, same repo)."},"1.0.2":{"name":"@abdelrahmannasr/sdlc-workflow","version":"1.0.2","keywords":["sdlc","bmad","workflow","cli","spec-driven-development"],"author":{"name":"AbdelRahman Nasr"},"license":"MIT","_id":"@abdelrahmannasr/sdlc-workflow@1.0.2","maintainers":[{"name":"abdelrahmannasr","email":"a.nasr.yocto@gmail.com"}],"homepage":"https://github.com/abdelrahmannasr/sdlc-workflow#readme","bugs":{"url":"https://github.com/abdelrahmannasr/sdlc-workflow/issues"},"bin":{"sdlc":"bin/sdlc.mjs"},"dist":{"shasum":"0a7d1449f9fc3c61def1d4bcbca4861cd2610530","tarball":"https://registry.npmjs.org/@abdelrahmannasr/sdlc-workflow/-/sdlc-workflow-1.0.2.tgz","fileCount":65,"integrity":"sha512-QRs8BkgA4jfretwc9gf4AfZFN1xDqFp1KwaOQeM+XW2Xz8mNFOK6ldh7jhHwRRxW4KDHmdT/OiwgL41GVvJIEQ==","signatures":[{"sig":"MEYCIQCCoEGvBZsyeDym9oPBL9IgnS3hy4p0OjMnxtjO7vBlugIhAPsh7oH7CIPapGDmALVutAQmP7sn/fYFH5N5BdO4BuO3","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@abdelrahmannasr%2fsdlc-workflow@1.0.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":313973},"type":"module","engines":{"node":">=18"},"gitHead":"491177359e6d2af291375884be3f86b3ac359f97","scripts":{"sdlc":"node bin/sdlc.mjs","test":"node --test cli/test.mjs","prepublishOnly":"npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:79dea4cd-4f5c-401b-b67a-040b27f6478b"}},"repository":{"url":"git+https://github.com/abdelrahmannasr/sdlc-workflow.git","type":"git"},"_npmVersion":"11.16.0","description":"Guided setup & maintenance CLI for the gated, team, multi-repo SDLC Workflow module.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"semantic-release":"^25.0.3","@semantic-release/changelog":"^6.0.3"},"_npmOperationalInternal":{"tmp":"tmp/sdlc-workflow_1.0.2_1780960839761_0.555386801933951","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed — install 'yadflow' instead (same CLI, same repo)."},"1.0.3":{"name":"@abdelrahmannasr/sdlc-workflow","version":"1.0.3","keywords":["sdlc","bmad","workflow","cli","spec-driven-development"],"author":{"name":"AbdelRahman Nasr"},"license":"MIT","_id":"@abdelrahmannasr/sdlc-workflow@1.0.3","maintainers":[{"name":"abdelrahmannasr","email":"a.nasr.yocto@gmail.com"}],"homepage":"https://github.com/abdelrahmannasr/sdlc-workflow#readme","bugs":{"url":"https://github.com/abdelrahmannasr/sdlc-workflow/issues"},"bin":{"sdlc":"bin/sdlc.mjs"},"dist":{"shasum":"84de37bdfb8e492422a39d289873719ff4c7fc87","tarball":"https://registry.npmjs.org/@abdelrahmannasr/sdlc-workflow/-/sdlc-workflow-1.0.3.tgz","fileCount":65,"integrity":"sha512-H0w4/FvuNdKFA2VC7XDg3uqrSS45yoSgkA47hlxTwdxKhJ+OUrrE/XBrbfakGgN0QCGNTaFmHh+QcZXcggapBw==","signatures":[{"sig":"MEQCIGV1clacesYitRw+3haQ1ColLoUJyL/C/e4GO3huLO0LAiBQ4tDku/w8oq7H45gNu/g6/BErb2RzOZTQa0uwppKd0A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@abdelrahmannasr%2fsdlc-workflow@1.0.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":320952},"type":"module","engines":{"node":">=18"},"gitHead":"b968cbe0be0259746a332a10c5b79ffaf08a87be","scripts":{"sdlc":"node bin/sdlc.mjs","test":"node --test cli/test.mjs","prepublishOnly":"npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:43b51219-49ed-461f-96f7-4d08177c5e33"}},"repository":{"url":"git+https://github.com/abdelrahmannasr/sdlc-workflow.git","type":"git"},"_npmVersion":"11.16.0","description":"Guided setup & maintenance CLI for the gated, team, multi-repo SDLC Workflow module.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"semantic-release":"^25.0.3","@semantic-release/changelog":"^6.0.3"},"_npmOperationalInternal":{"tmp":"tmp/sdlc-workflow_1.0.3_1780961572095_0.8085443086201136","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed — install 'yadflow' instead (same CLI, same repo)."},"1.1.0":{"name":"@abdelrahmannasr/sdlc-workflow","version":"1.1.0","keywords":["sdlc","bmad","workflow","cli","spec-driven-development"],"author":{"name":"AbdelRahman Nasr"},"license":"MIT","_id":"@abdelrahmannasr/sdlc-workflow@1.1.0","maintainers":[{"name":"abdelrahmannasr","email":"a.nasr.yocto@gmail.com"}],"homepage":"https://github.com/abdelrahmannasr/sdlc-workflow#readme","bugs":{"url":"https://github.com/abdelrahmannasr/sdlc-workflow/issues"},"bin":{"sdlc":"bin/sdlc.mjs"},"dist":{"shasum":"7a6012f42e53d12a601f9332668a90ead0300468","tarball":"https://registry.npmjs.org/@abdelrahmannasr/sdlc-workflow/-/sdlc-workflow-1.1.0.tgz","fileCount":71,"integrity":"sha512-sxOFb97RixbLK5QgcCNRIna7nhHhEq9m2ACNqIq6OThhTcj1SGQxhOBpruvuA/yngt/pnFr2HLUxZAmo8sVdBw==","signatures":[{"sig":"MEYCIQC2qXBM3c2W28InrFaAO4H95qEHR+scSc2I3vvVCiHqsgIhAOcLNcwmOka/0lHhuwCQ+/52lsjvnZ5ydrRlzj6lHKcX","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@abdelrahmannasr%2fsdlc-workflow@1.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":372307},"type":"module","engines":{"node":">=18"},"gitHead":"cc4331903b2052b9835b0a6e3f21e148c809914c","scripts":{"sdlc":"node bin/sdlc.mjs","test":"node --test cli/test.mjs","prepublishOnly":"npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:43b51219-49ed-461f-96f7-4d08177c5e33"}},"repository":{"url":"git+https://github.com/abdelrahmannasr/sdlc-workflow.git","type":"git"},"_npmVersion":"11.16.0","description":"Guided setup & maintenance CLI for the gated, team, multi-repo SDLC Workflow module.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"semantic-release":"^25.0.3","@semantic-release/changelog":"^6.0.3"},"_npmOperationalInternal":{"tmp":"tmp/sdlc-workflow_1.1.0_1781014159798_0.793217953349941","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed — install 'yadflow' instead (same CLI, same repo)."},"1.1.1":{"name":"@abdelrahmannasr/sdlc-workflow","version":"1.1.1","keywords":["sdlc","bmad","workflow","cli","spec-driven-development"],"author":{"name":"AbdelRahman Nasr"},"license":"MIT","_id":"@abdelrahmannasr/sdlc-workflow@1.1.1","maintainers":[{"name":"abdelrahmannasr","email":"a.nasr.yocto@gmail.com"}],"homepage":"https://github.com/abdelrahmannasr/sdlc-workflow#readme","bugs":{"url":"https://github.com/abdelrahmannasr/sdlc-workflow/issues"},"bin":{"sdlc":"bin/sdlc.mjs"},"dist":{"shasum":"75c9b3c80abfe6ece14459e3660c48809bfd645e","tarball":"https://registry.npmjs.org/@abdelrahmannasr/sdlc-workflow/-/sdlc-workflow-1.1.1.tgz","fileCount":71,"integrity":"sha512-rgM+pxyHNn+ImnArdSPRuXcJNwnDOIQMMTIjtoGVz8XmYyzaRCBhSk7eSXM2BAdTCLyeNSvHCd/DeiLG7h3BKg==","signatures":[{"sig":"MEYCIQD5vp0kWDxftrfYrMhxHWZvfdL59WJq/bbI4x+iOpA3cwIhAOf9XaCRmZ0FZq4PehNBqsvKrujvY/2wt7ZGY6EZv2qB","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@abdelrahmannasr%2fsdlc-workflow@1.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":375830},"type":"module","engines":{"node":">=18"},"gitHead":"2d328628612dc906dcd28d78afa2183813cc1bc8","scripts":{"sdlc":"node bin/sdlc.mjs","test":"node --test cli/test.mjs","prepublishOnly":"npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:43b51219-49ed-461f-96f7-4d08177c5e33"}},"repository":{"url":"git+https://github.com/abdelrahmannasr/sdlc-workflow.git","type":"git"},"_npmVersion":"11.16.0","description":"Gated, team, multi-repo SDLC workflow: author → review → build with a PR-driven review gate and a zero-dependency CLI (setup, gate, commit, open-pr, repo). A BMAD module + 17 skills.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"semantic-release":"^25.0.3","@semantic-release/changelog":"^6.0.3"},"_npmOperationalInternal":{"tmp":"tmp/sdlc-workflow_1.1.1_1781017082244_0.9216806858246807","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed — install 'yadflow' instead (same CLI, same repo)."},"1.2.0":{"name":"@abdelrahmannasr/sdlc-workflow","version":"1.2.0","keywords":["sdlc","bmad","workflow","cli","spec-driven-development"],"author":{"name":"AbdelRahman Nasr"},"license":"MIT","_id":"@abdelrahmannasr/sdlc-workflow@1.2.0","maintainers":[{"name":"abdelrahmannasr","email":"a.nasr.yocto@gmail.com"}],"homepage":"https://github.com/abdelrahmannasr/sdlc-workflow#readme","bugs":{"url":"https://github.com/abdelrahmannasr/sdlc-workflow/issues"},"bin":{"sdlc":"bin/sdlc.mjs"},"dist":{"shasum":"87d2a3b4c1d8e19ebd86b73edfe142c7ffb71a66","tarball":"https://registry.npmjs.org/@abdelrahmannasr/sdlc-workflow/-/sdlc-workflow-1.2.0.tgz","fileCount":74,"integrity":"sha512-Aq7Z7Zm/b6ANUuP+xAaqefXcD0CzDHs/O+Rq6Do4VcL/IU+1gmom2flRU2sBpHHDGItsIqUBD87ooxOutt7iRw==","signatures":[{"sig":"MEUCIQDW0gh4cZZhG1QXAAkU0hck4TTlkw27EIgiOi2/7BG+7AIgRNhsfPikamh/N09gkSdzuIJCBypwlexqfMbCLuwzytU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@abdelrahmannasr%2fsdlc-workflow@1.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":402212},"type":"module","engines":{"node":">=18"},"gitHead":"e0adbd512a016af5688c828702af73b20d953087","scripts":{"sdlc":"node bin/sdlc.mjs","test":"node --test cli/test.mjs","prepublishOnly":"npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:43b51219-49ed-461f-96f7-4d08177c5e33"}},"repository":{"url":"git+https://github.com/abdelrahmannasr/sdlc-workflow.git","type":"git"},"_npmVersion":"11.16.0","description":"Gated, team, multi-repo SDLC workflow: author → review → build with a PR-driven review gate and a zero-dependency CLI (setup, gate, commit, open-pr, repo). A BMAD module + 17 skills.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"semantic-release":"^25.0.3","@semantic-release/changelog":"^6.0.3"},"_npmOperationalInternal":{"tmp":"tmp/sdlc-workflow_1.2.0_1781116353708_0.915218766729913","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed — install 'yadflow' instead (same CLI, same repo)."},"1.3.1":{"name":"@abdelrahmannasr/sdlc-workflow","version":"1.3.1","keywords":["sdlc","bmad","workflow","cli","spec-driven-development"],"author":{"name":"AbdelRahman Nasr"},"license":"MIT","_id":"@abdelrahmannasr/sdlc-workflow@1.3.1","maintainers":[{"name":"abdelrahmannasr","email":"a.nasr.yocto@gmail.com"}],"homepage":"https://github.com/abdelrahmannasr/sdlc-workflow#readme","bugs":{"url":"https://github.com/abdelrahmannasr/sdlc-workflow/issues"},"bin":{"sdlc":"bin/sdlc.mjs"},"dist":{"shasum":"f495c91a5b11a86051e99d0620655c05b5a8f12a","tarball":"https://registry.npmjs.org/@abdelrahmannasr/sdlc-workflow/-/sdlc-workflow-1.3.1.tgz","fileCount":77,"integrity":"sha512-DYql2x7iTa5xyEhFg7qePIlTD4N9Zto9cnhckdlHeh3E+lNKkhhN+ZNrWmai2lNjb3kCpd1Z4LIu3PZFuCd6bg==","signatures":[{"sig":"MEQCIHXL0KOyaI2pK7fX8NbJH2ts+j81jpkGPruGlosp0/4SAiAQMERwuL7j8/V4I1JXsEV0TUrVAklh+Vsx2snWNdsKNA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@abdelrahmannasr%2fsdlc-workflow@1.3.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":417343},"type":"module","engines":{"node":">=18"},"gitHead":"ad92e525c1539a191cd3caffb12c4dc97e80b861","scripts":{"sdlc":"node bin/sdlc.mjs","test":"node --test cli/test.mjs","prepublishOnly":"npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:43b51219-49ed-461f-96f7-4d08177c5e33"}},"repository":{"url":"git+https://github.com/abdelrahmannasr/sdlc-workflow.git","type":"git"},"_npmVersion":"11.16.0","description":"Gated, team, multi-repo SDLC workflow: author → review → build with a PR-driven review gate and a zero-dependency CLI (setup, gate, commit, open-pr, repo). A BMAD module + 17 skills.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"semantic-release":"^25.0.3","@semantic-release/changelog":"^6.0.3"},"_npmOperationalInternal":{"tmp":"tmp/sdlc-workflow_1.3.1_1781117001708_0.3247605215340317","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed — install 'yadflow' instead (same CLI, same repo)."},"1.3.2":{"name":"@abdelrahmannasr/sdlc-workflow","version":"1.3.2","keywords":["sdlc","bmad","workflow","cli","spec-driven-development"],"author":{"name":"AbdelRahman Nasr"},"license":"MIT","_id":"@abdelrahmannasr/sdlc-workflow@1.3.2","maintainers":[{"name":"abdelrahmannasr","email":"a.nasr.yocto@gmail.com"}],"homepage":"https://github.com/abdelrahmannasr/sdlc-workflow#readme","bugs":{"url":"https://github.com/abdelrahmannasr/sdlc-workflow/issues"},"bin":{"sdlc":"bin/sdlc.mjs"},"dist":{"shasum":"821356a58b1d4cee42eb7dd602236ebb0ec03922","tarball":"https://registry.npmjs.org/@abdelrahmannasr/sdlc-workflow/-/sdlc-workflow-1.3.2.tgz","fileCount":77,"integrity":"sha512-TD3yjGSpCrCzhBgCTy8g9eRWrZ/NTkiHhYhz0cRx0YHb1kQ/JQCXxfKAYSAD2DocEpUIAqgiCXFy/4FP5KUWQw==","signatures":[{"sig":"MEUCIEj9ZHWTgVdZHm0tAA6U7IYxOUt5mfXlt5AWMLWXpvo4AiEAmRuVD1Y6X8iEvxSYmp33HlFyq7H/kOGrVfX6Ah9ldiY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@abdelrahmannasr%2fsdlc-workflow@1.3.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":425928},"type":"module","engines":{"node":">=18"},"gitHead":"71d17735400b056ac666bbc75b55b13551032114","scripts":{"sdlc":"node bin/sdlc.mjs","test":"node --test cli/test.mjs","prepublishOnly":"npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:43b51219-49ed-461f-96f7-4d08177c5e33"}},"repository":{"url":"git+https://github.com/abdelrahmannasr/sdlc-workflow.git","type":"git"},"_npmVersion":"11.16.0","description":"Gated, team, multi-repo SDLC workflow: author → review → build with a PR-driven review gate and a zero-dependency CLI (setup, gate, commit, open-pr, repo). A BMAD module + 17 skills.","directories":{},"_nodeVersion":"22.22.3","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"semantic-release":"^25.0.3","@semantic-release/changelog":"^6.0.3"},"_npmOperationalInternal":{"tmp":"tmp/sdlc-workflow_1.3.2_1781127018475_0.5587750222725827","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Renamed — install 'yadflow' instead (same CLI, same repo)."}},"time":{"created":"2026-06-08T22:47:17.944Z","modified":"2026-06-12T17:31:21.714Z","0.1.0":"2026-06-08T22:47:18.297Z","1.0.2":"2026-06-08T23:20:39.941Z","1.0.3":"2026-06-08T23:32:52.233Z","1.1.0":"2026-06-09T14:09:19.950Z","1.1.1":"2026-06-09T14:58:02.411Z","1.2.0":"2026-06-10T18:32:33.836Z","1.3.1":"2026-06-10T18:43:21.837Z","1.3.2":"2026-06-10T21:30:18.680Z"},"bugs":{"url":"https://github.com/abdelrahmannasr/sdlc-workflow/issues"},"author":{"name":"AbdelRahman Nasr"},"license":"MIT","homepage":"https://github.com/abdelrahmannasr/sdlc-workflow#readme","keywords":["sdlc","bmad","workflow","cli","spec-driven-development"],"repository":{"url":"git+https://github.com/abdelrahmannasr/sdlc-workflow.git","type":"git"},"description":"Gated, team, multi-repo SDLC workflow: author → review → build with a PR-driven review gate and a zero-dependency CLI (setup, gate, commit, open-pr, repo). A BMAD module + 17 skills.","maintainers":[{"name":"abdelrahmannasr","email":"a.nasr.yocto@gmail.com"}],"readme":"# SDLC Workflow — gated, team, multi-repo SDLC on top of BMAD\n\n[![npm version](https://img.shields.io/npm/v/@abdelrahmannasr/sdlc-workflow?logo=npm)](https://www.npmjs.com/package/@abdelrahmannasr/sdlc-workflow)\n[![CI](https://github.com/abdelrahmannasr/sdlc-workflow/actions/workflows/ci.yml/badge.svg)](https://github.com/abdelrahmannasr/sdlc-workflow/actions/workflows/ci.yml)\n[![provenance](https://img.shields.io/badge/npm-provenance-blue?logo=npm)](https://docs.npmjs.com/generating-provenance-statements)\n\nA custom BMAD module that turns BMAD from a solo tool into a **team, gated, file-driven SDLC\nengine**. Every step does its work, writes its output to a file, and **waits at a gate**. Who\nadvances the gate (human now; machine later) is a per-step setting. All state lives in files —\nnothing hidden, no database.\n\nThis repo is the **first deliverable** (see `docs/claude-code-build-plan.md` §10): verified research,\na scaffolded module that installs cleanly, and a working **team review gate** you run by hand.\n\n## The workflow at a glance\n\nThe whole lifecycle, from an empty project to shipped code. Setup is one-time; the **front half**\nis human-gated and runs once per epic in the product hub; the **build half** runs once per story\nper code repo; **automation** is opt-in and earned. `sdlc-status` reads it all; `sdlc-hub-bridge`\nmirrors front-half reviews to real PR/MRs.\n\n```mermaid\nflowchart TD\n    classDef gated fill:#fdebd0,stroke:#ca6f1e,color:#000\n    classDef earns fill:#d6eaf8,stroke:#2471a3,color:#000\n    classDef locked fill:#eaecee,stroke:#566573,color:#000,stroke-dasharray:5 3\n    classDef artifact fill:#fcf3cf,stroke:#b7950b,color:#000\n    classDef sentinel fill:#d5f5e3,stroke:#1e8449,color:#000\n\n    subgraph SETUP[\"0 · One-time setup (per project)\"]\n      direction TB\n      inst[\"install.sh<br/>copy sdlc-* skills into IDE dirs\"]\n      wire[\"wire each repo:<br/>sdlc-checks · sdlc-pr-template · sdlc-review-comments\"]\n      conn[\"sdlc-connect-repos<br/>repos.json + cached code-map\"]\n      phub[\"optional: hub on a platform<br/>detect-hub · roster\"]\n      inst --> wire --> conn --> phub\n    end\n\n    subgraph FRONT[\"A · Front half — product hub · human-gated · once per epic\"]\n      direction TB\n      an[\"sdlc-author-analysis<br/>optional → analysis.md\"]:::artifact\n      ep[\"sdlc-author-epic<br/>epic.md · assigns EP-&lt;slug&gt;\"]:::artifact\n      ar[\"sdlc-author-architecture<br/>architecture.md + locked contract.md\"]:::artifact\n      ui[\"sdlc-author-ui<br/>ui-design.md + DESIGN.md\"]:::artifact\n      st[\"sdlc-author-stories<br/>repo-tagged stories/EP-&lt;slug&gt;-S0N.md\"]:::artifact\n      gAn{{\"gate · analysis\"}}:::gated\n      gEp{{\"gate · epic<br/>base: owner + reviewer\"}}:::gated\n      gAr{{\"gate · architecture<br/>escalated: + repo domain owners\"}}:::gated\n      gUi{{\"gate · UI · base\"}}:::gated\n      gSt{{\"gate · stories<br/>per-repo domain owners\"}}:::gated\n      rfb([\"currentStep: ready-for-build\"]):::sentinel\n      an --> gAn --> ep --> gEp --> ar --> gAr --> ui --> gUi --> st --> gSt --> rfb\n    end\n\n    subgraph BUILD[\"B · Build half — per story, per code repo\"]\n      direction TB\n      sp[\"sdlc-spec<br/>Spec Kit ceremony → specs/&lt;story&gt;/\"]\n      im[\"sdlc-implement<br/>1 task = 1 branch = 1 commit\"]:::earns\n      ck[\"sdlc-checks<br/>spec-link · contract-check · build/test/lint\"]:::earns\n      prm[\"open PR/MR + sdlc-pr-template route\"]\n      shp[\"sdlc-ship<br/>AI review (advisory)\"]\n      eng{{\"engineer review<br/>human · never automated\"}}:::locked\n      merged([\"merge → build-log.json\"]):::sentinel\n      sp --> im --> ck --> prm --> shp --> eng --> merged\n    end\n\n    subgraph AUTO[\"C · Automation — earned & reversible\"]\n      direction TB\n      run[\"sdlc-run<br/>reads automation dial + trust-log.json\"]:::earns\n      kill[\"kill switch → everything human_approve\"]\n      run --- kill\n    end\n\n    phub --> an\n    rfb --> sp\n    run -. drives earned back steps .-> im\n    bridge[\"sdlc-hub-bridge<br/>review PR/MR ↔ file ledger\"]:::gated\n    bridge -. syncs approvals .-> gEp\n    status[\"sdlc-status<br/>read-only view over all of it\"]\n    status -. observes .-> FRONT\n    status -. observes .-> BUILD\n```\n\n**Legend.** <span>🟨</span> **artifact** = an author step writes a file and stops; <span>🟧</span>\n**gate** = a human review that must pass (`open → comment → approve → advance`); <span>🟦</span>\n**earns automation** = a back step that can be set to `machine_advance` once it proves itself;\n<span>⬜ dashed</span> **locked** = the engineer review and every front state, **permanently\nhuman**. Detailed walkthroughs for each phase follow below.\n\n## What's here\n\n| Path | What it is |\n|------|-----------|\n| `RESEARCH-NOTES.md` | Verified Phase 0 facts about BMAD, Spec Kit, Repomix, Impeccable + deviations. |\n| `skills/sdlc/` | Module source of truth (`config.yaml`, `module-help.csv`, `install.sh`). Survives BMAD updates. |\n| `bin/`, `cli/` | The `sdlc` setup/update CLI (published to npm as `@abdelrahmannasr/sdlc-workflow`). |\n| `skills/sdlc-author-analysis/` | Optional front state 1: pressure-test the idea with the analyst into `analysis.md` (skippable). |\n| `skills/sdlc-author-epic/` | Front state 1: author an epic with AI assist, assign its `EP-<slug>` ID, seed state. |\n| `skills/sdlc-author-architecture/` | Front state 3: author `architecture.md` + the locked `contract.md`; hash-lock the contract surface. |\n| `skills/sdlc-author-ui/` | Front state 5: author `ui-design.md` + `DESIGN.md` (Impeccable slash-commands, or graceful fallback). |\n| `skills/sdlc-author-stories/` | Front state 7: break the epic into repo-tagged stories with stable `EP-<slug>-S0N` IDs. |\n| `skills/sdlc-connect-repos/` | Connect code repos to the hub (GitHub/GitLab, local-user auth); cache a Repomix pack + **code-map** per repo so the front phases are code-aware. |\n| `skills/sdlc-review-gate/` | The reusable **team review + approve gate** (used for all four reviews). |\n| `skills/sdlc-spec/` | Build Step A: run the Spec Kit ceremony once per story per repo → `specs/<story-id>/`. |\n| `skills/sdlc-implement/` | Build Step B: implement ONE atomic task as a small diff on its own branch. |\n| `skills/sdlc-checks/` | Build Step C: wire + run the CI gates (spec-link, contract-check, build/test/lint, verified-commits). |\n| `skills/sdlc-pr-template/` | Build Step D: install the platform PR/MR template + risk routing (code repos **and** the hub). |\n| `skills/sdlc-review-comments/` | Install platform-matched PR/MR review-comment scaffolds (code repos and the hub). |\n| `skills/sdlc-hub-bridge/` | The templated PR/MR **review bridge**: open a review PR/MR on the hub and sync platform approvals/comments into the file ledger. |\n| `skills/sdlc-ship/` | Build Step E: AI review (advisory) → engineer review → ship + record in the build log. |\n| `skills/sdlc-backfill/` | Generate a human-verified spec for already-built code (Repomix), gated per touched feature. |\n| `skills/sdlc-run/` | Phase 4 orchestrator: drive a story's back half on the `automation` dial; kill switch. |\n| `skills/sdlc-status/` | Read-only view: front chain, build-half dials, trust record, fleet roll-up. |\n| `epics/EP-istifta-inquiries/` | A worked demo epic run **end to end** (front half + build half + automation). |\n| `demo-repos/` | Throwaway code repos for the build half (separate git repos; regenerable — see `demo-repos/README.md`). |\n| `docs/` | The phased build plans (`phase-2`…`phase-5`) and the original workflow design. |\n| [`CONTRIBUTING.md`](CONTRIBUTING.md) | Commit & PR/MR title convention (Conventional Commits, lowercase after the type). |\n\n## The `sdlc` CLI (install, update, reconcile)\n\nThe module ships a zero-dependency CLI, published to npm as\n[`@abdelrahmannasr/sdlc-workflow`](https://www.npmjs.com/package/@abdelrahmannasr/sdlc-workflow). Run it\nwith `npx` from your **product hub** repo — no clone needed.\n\n| Command | What it does |\n|---------|--------------|\n| `npx @abdelrahmannasr/sdlc-workflow setup` | Guided first-run wizard (the steps below). |\n| `npx @abdelrahmannasr/sdlc-workflow check` | Read-only report: what is **missing** / **outdated** (drifted) / **stale** (code-context) vs the bundled manifest. |\n| `npx @abdelrahmannasr/sdlc-workflow check --fix` | Reconcile: fill what is missing **and** update what changed — touches nothing already correct. |\n| `npx @abdelrahmannasr/sdlc-workflow update` | Apply drift only (alias for `check --fix --scope=changed`). |\n| `sdlc gate open <epic> <artifact>` | Open the front-half **review PR/MR** for an artifact and mark the step `in_review`. |\n| `sdlc gate sync <epic> [artifact]` | Pull the PR/MR's reviews + comment threads into the file ledger; **auto-advance** the step when approvals are satisfied, all threads are resolved, and the PR is merged. |\n| `sdlc gate comments <epic> [artifact]` | Fetch the unresolved review comments to address (then reply on the PR; reviewers resolve their threads). |\n| `sdlc gate status <epic>` | Show each review step and its recorded approvals. |\n| `sdlc gate ci [--branch <head>] [--pr <n>]` | The CI entry the hub workflow calls on review/merge events: derive the epic/artifact from the `review/EP-*` branch, run the same sync, and commit **only the ledger** to the hub default branch (sweep every open review PR when no `--branch`). |\n| `sdlc commit --type <t> -m <subject>` | Commit by the SDLC convention — Conventional subject, `Task`/`Contract-Change`/`Co-Authored-By` trailers, atomic-file guard. |\n| `sdlc open-pr [--repo <name>]` | Open a code-repo **task** PR/MR from the repo's platform template (build half). |\n| `sdlc repo list` / `sdlc repo refresh [name]` | List connected repos as **fresh / stale**, and re-pack a stale one — staleness is now an explicit human decision, never an automatic skill side-effect. |\n| `npx @abdelrahmannasr/sdlc-workflow --version` | Print the installed CLI version. |\n\nFlags: `--dir <path>` targets a project other than the cwd; `--force` re-copies unchanged files (or\nbypasses the commit atomic guard). Commit flags: `--type`, `-m/--message`, `--task`, `--ai\n<claude\\|copilot\\|cursor\\|coderabbit\\|none>`, `--contract-change`, `--dry-run`. `open-pr` flags:\n`--repo`, `--risk <low\\|medium\\|high>`, `--contract-change`.\n\n### The PR-driven review gate\n\nThe front-half gate now rides the **PR/MR you open per step** (`sdlc gate open`). Reviewers approve and\ncomment on the platform; `sdlc gate sync` maps that state into the file ledger (`approvals.json`,\n`comments.json`, `reviews/*.md`) — which stays the source of truth — and the step **auto-advances on\nmerge** once three things hold: the reviewer rule is satisfied (owner + 1 reviewer, plus a domain-owner\nper touched repo on escalated steps), every comment thread is resolved, and the review PR/MR is merged.\nThe merge click is the human approval act, so front steps still never `machine_advance`. Approvals are\n**revoked when the reviewed artifact actually changes** (re-hash), giving reviewers a fresh pass. With no\nhub platform / no `gh`/`glab`, the gate degrades to file-only with no error.\n\n**Event-driven sync.** Wire the hub once (`sdlc check --fix` installs `.github/workflows/sdlc-gate-sync.yml`,\nor the GitLab fragment + schedule) and every **approval, change request, and merge** on a review PR/MR\ntriggers `sdlc gate ci` in the hub's own CI: the ledger updates land directly on the hub's default branch\n— no manual `sdlc gate sync` needed (it stays valid as the fallback). CI never approves and never merges;\nthe human keeps the merge click. GitLab caveat: approvals are only picked up by the ~15-min scheduled\nsweep (GitLab fires no pipeline on approval) — details in `skills/sdlc-hub-bridge/references/bridge.md`.\nConcurrency caveat: on GitHub the workflow's `concurrency` group serializes runs repo-wide and every\nsync re-reads the full platform state, so racing reviewer events lose nothing. Outside that group —\na manual `sdlc gate sync` racing CI, or GitLab pipelines — two simultaneous syncs serialize their\n*commits* via the rebase retry but each works from the state it read at start, so the rarer of two\nsimultaneous advancements can be lost; the next event or scheduled sweep re-syncs and converges.\n\n### What `setup` walks you through (7 steps)\n\n1. **Preflight** — confirm the hub is a git repo (offers `git init`); check `git`/`node`/`npx`.\n2. **Install the module** — copy all 17 `sdlc-*` skills into the IDE skill dirs you pick\n   (`.claude/`, `.agents/`, `.zencoder/`, `.opencode/`) and register `_bmad/sdlc/`.\n3. **Hub platform & roster** — detect GitHub/GitLab from the remote; record reviewers → `.sdlc/hub.json`.\n4. **Connect code repos** — register each repo into `.sdlc/repos.json` and cache a Repomix pack.\n5. **Wire each repo** — CI gates, PR/MR template, and review-comment scaffold.\n6. **AI review** — optionally write `.coderabbit.yaml`.\n7. **Done** — stamp `.sdlc/cli-version.json` and hand off the AI-only steps (code-maps; first epic).\n\nThe deterministic file work runs automatically; the AI-only steps are handed to the Claude Code skills\nwith a printed next-action. Re-run `… check --fix` any time the workflow updates — it never re-asks for\ninput you already gave.\n\n**Releases:** automated via semantic-release on merge to `main` (Conventional Commits → npm, with\nprovenance). See [`RELEASING.md`](RELEASING.md).\n\n**Maintainers / no-CLI fallback:** the underlying copy is still a single script —\n`bash skills/sdlc/install.sh` — which the CLI's install step is a port of. The **source** stays in\n`skills/`, which a `bmad-method` update does not touch, so after any BMAD update just re-run the CLI\n(`… check --fix`) or the script.\n\n> **Releases are automated.** A `feat:`/`fix:` commit merged to `main` triggers\n> [semantic-release](https://semantic-release.gitbook.io/): it computes the version from the\n> [Conventional Commits](CONTRIBUTING.md), publishes to npm with build provenance (tokenless OIDC),\n> ships the `CHANGELOG.md` in the tarball, and cuts a GitHub release. No manual `npm publish`. See\n> [`RELEASING.md`](RELEASING.md).\n\n## Agent skills (all 17)\n\nThe CLI **installs and wires** the module; the skills below are the **agents you invoke by name** in your\nAI IDE (e.g. *“run `sdlc-author-epic`”*) to actually do the work. State lives in files you can also edit\ndirectly. Each skill stops at a gate and never auto-advances unless a step has *earned* automation.\n\n### Setup & code-awareness\n\n- **`sdlc-connect-repos`** — Connects code repos to the product hub so the front/\"brain\" phases are\n  code-aware. Registers N code repos (GitHub or GitLab, local-user auth, no stored tokens) into\n  `.sdlc/repos.json`, then caches an AI-readable picture of each — a compressed Repomix pack and a\n  lightweight code-map (existing endpoints/events/data-models/modules), secret-scanned. Idempotent and\n  refreshable; staleness tracked by HEAD sha.\n\n### Front half — author the \"thinking\" (once per epic, human-gated)\n\n- **`sdlc-author-analysis`** — *Optional* front state 1. With the analyst, pressure-test a feature idea\n  and write the discovery brief into `analysis.md`. Assigns the `EP-<slug>` ID and seeds `.sdlc/` state\n  (the 10-step chain that puts analysis before epic). If skipped, the epic step does this shaping inline.\n- **`sdlc-author-epic`** — The epic front state. Shape the idea with the analyst (or read `analysis.md`\n  when it already ran), then write the epic with the pm into `epic.md`. The entry point when analysis is\n  skipped: assigns the `EP-<slug>` ID and seeds `.sdlc/` state.\n- **`sdlc-author-architecture`** — Front state 3. With the architect, author `architecture.md` and the\n  locked `contract.md` (the shared cross-repo surface), then hash-lock the contract surface into\n  `.sdlc/contract-lock.json`. Reads `epic.md`; escalates on the contract risk tag.\n- **`sdlc-author-ui`** — Front state 5. With the ux-designer, author `ui-design.md` and `DESIGN.md`,\n  driving Impeccable as harness slash-commands (document/extract/craft) when installed, or authoring\n  directly when not. Reads epic + architecture.\n- **`sdlc-author-stories`** — Front state 7. With the pm, break the approved epic into user stories, each\n  tagged with the repos that must implement it. Assigns zero-padded `EP-<slug>-S0N` IDs, one file per\n  story under `stories/`. Reads epic + architecture + contract + UI.\n\n### The review gate (cross-cutting — used by every review)\n\n- **`sdlc-review-gate`** — The reusable team review + approve gate. Shares an authored artifact, records\n  reviewer comments and approvals as files, enforces the **owner + 1 reviewer** rule (escalating to\n  domain owners on contract/auth/payments), and advances the epic state **only** when approval is\n  recorded.\n- **`sdlc-hub-bridge`** — The templated PR/MR bridge for the front-half gate. When the hub has a platform\n  (`.sdlc/hub.json`), it opens a review PR/MR per artifact, sets the required reviewers/labels, and\n  provides the read-only `gh`/`glab` recipes that sync platform comments + approvals back into the file\n  ledger. The file ledger stays the source of truth; degrades to a file-only gate with no platform.\n- **`sdlc-review-comments`** — Installs platform-matched PR/MR review-comment scaffolds so reviewers\n  leave structured, attributable feedback that maps cleanly into the file ledger.\n\n### Build half — turn stories into shipped code (once per story, per repo)\n\n- **`sdlc-spec`** — Step A. For one ready-for-build story and one of its repos, run the Spec Kit ceremony\n  once (specify → clarify → plan → analyze → checklist → tasks) → `specs/<story-id>/`. Drives `/speckit.*`\n  when installed; references the locked contract — never re-invents the surface.\n- **`sdlc-implement`** — Step B. With the dev lens, implement **one** atomic task as a small diff\n  (≤3 files) on its own branch. The diff stays inside the files the task declared (flag and STOP if it\n  would grow). Commit ends with the task ID; `Contract-Change: yes` only if it touches the locked\n  contract surface.\n- **`sdlc-checks`** — Step C, the production-safety gates. Wire and run three CI gates: **spec-link**\n  (every change links a real story/spec), **contract-check** (a contract-surface diff without a\n  re-locked contract FAILS), and **build/test/lint**. CI-agnostic bash for GitHub Actions and GitLab CI.\n- **`sdlc-pr-template`** — Step D. Detect the repo's platform and commit the matching PR/MR template with\n  an Impact & Risk block; high risk (or a contract/auth/payments surface) routes the review to domain\n  owners. Includes `risk-route.sh`.\n- **`sdlc-ship`** — Step E. AI review (CodeRabbit, advisory) → engineer review (the human gate, owner +\n  1 reviewer with the same escalation) → on merge, record the ship in the epic build-log and update the\n  story state so the epic → story → task → PR chain stays traceable.\n- **`sdlc-backfill`** — Step G. Generate specs for already-built features in an existing repo so new work\n  doesn't break them: pack one feature at a time with Repomix, write a DRAFT spec, require human approval\n  before it counts. A change is blocked only until the features it touches have approved specs.\n\n### Automation & status\n\n- **`sdlc-run`** — The Phase 4 orchestrator. Drives a story's back-half loop (spec → tasks → implement →\n  checks) on each step's automation dial, recording every run in the trust log. A clean `checks` pass\n  auto-advances to engineer-review; any failure, scope overrun, or contract-surface touch HALTS for a\n  human. Also sets a step's dial (gated by trust evidence) and flips the system-wide kill switch.\n- **`sdlc-status`** — Read-only view of an epic: the current step, each step's dials (assistance/\n  automation) and status, which approvals are still required, per-story back-half trust records, the\n  kill-switch state, and a fleet roll-up across epics.\n\n## The two dials (per step, build plan §2)\n\n- **assistance:** `none` | `review` | `heavy` — how much AI helps.\n- **automation:** `human_approve` | `machine_advance` — who advances the step.\n\nDefaults: every step starts `human_approve`. The four **front** authoring steps (epic, architecture,\nUI, stories) and their reviews are **locked** — they may not be set to `machine_advance` in this\nversion. A front state advances only on a **human act** — recording an approval and `advance`, or\nmerging the approved, fully-resolved review PR — never on a machine.\n\nAs of **Phase 4a** the `automation` dial is no longer inert: the orchestrator `sdlc-run` reads it and,\nfor the safe **back** steps, advances on its own when a step is set to `machine_advance` (and has\n*earned* it — see \"Run the back half on the dial\" below). The engineer review and all four front\nstates stay `human_approve` forever.\n\n## Using the workflow end to end (all the steps, in order)\n\nThis is the full path from nothing to shipped code. Each numbered step names the skill to invoke; the\ndetailed sections below expand every phase. Invoke a skill by name in your agent/IDE (e.g. *“run\n`sdlc-author-epic`”*); state lives in files you can also edit directly.\n\n### 0 — One-time setup\n\n> **Shortcut:** `npx @abdelrahmannasr/sdlc-workflow setup` walks through steps 1, 4, 5 and 6 below\n> interactively (module install, hub detect + roster, connect repos, wire each repo). Run\n> `… check --fix` any time afterwards to reconcile. The manual steps below are the long-hand\n> equivalent and still work.\n\n1. **Install the module:** `bash skills/sdlc/install.sh` (re-run after any BMAD update).\n2. **Have your code repo(s).** They are **separate git repos** (one `.git` each). For the demo they\n   live under `demo-repos/<repo>/` — regenerate from `demo-repos/README.md`.\n3. **Optional tools** (the workflow degrades gracefully and records it if any are absent): **Spec Kit**\n   (`/speckit.*`), **Impeccable** (`/impeccable …`), **Repomix** (`npx repomix`, used by\n   `sdlc-connect-repos` and `sdlc-backfill`), **CodeRabbit** (advisory AI review).\n4. **Wire each code repo once:** `sdlc-checks repo:<repo> action: wire` (installs the CI gates —\n   *merges* with any existing CI, never clobbers), `sdlc-pr-template repo:<repo> action: wire` (PR/MR\n   template + risk routing), `sdlc-review-comments repo:<repo> action: wire` (review-comment scaffold).\n5. **Connect each code repo to the hub** (so the front phases see what's already built):\n   `sdlc-connect-repos action: connect repo:<repo> path:<path-or-git_url> domain_owner:<who>`. It\n   registers the repo in `.sdlc/repos.json` and caches a Repomix pack + a lightweight **code-map**\n   (existing endpoints/events/data-models/modules, secret-scanned). Clones/fetches as the **local user**\n   (SSH or credential helper; GitHub or GitLab; no stored tokens). Re-run for any new repo. Freshness is a\n   **human decision**: `sdlc repo list` shows fresh/stale, `sdlc repo refresh [name]` re-packs a moved repo\n   (skills flag staleness and point here — they never silently re-pack). Greenfield → skip it.\n6. **(Optional) Put the hub on a platform** so the front-half review runs through real PRs:\n   `sdlc-connect-repos action: detect-hub`, then `action: roster` once per reviewer (login → SDLC\n   name + role), and `sdlc-pr-template repo:hub action: wire` / `sdlc-review-comments repo:hub action:\n   wire` / `sdlc-checks repo:hub action: wire`. With no hub platform the front gate just runs file-only.\n7. **Conventions:** commits and PR/MR titles follow Conventional Commits (lowercase after the type), the\n   human author owns each commit with an optional per-commit `Co-Authored-By` AI trailer — see\n   [`CONTRIBUTING.md`](CONTRIBUTING.md).\n\n### A — Front half (human-authored, once per epic)\nEach author step writes its artifact, sets itself `done`, moves `currentStep` to its review, and\n**stops at the gate**. Run every gate with **`sdlc-review-gate`** — or, when the hub is on a platform,\ndrive it deterministically with the **`sdlc gate`** CLI (`open → sync → … → merge`): the review rides\nthe per-step PR/MR and the step **auto-advances on merge** once approvals are satisfied and all comment\nthreads are resolved. Details: **“Run the full front half by hand”** below.\n\n6. `sdlc-author-epic` → `epic.md` (assigns `EP-<slug>`, seeds state) → review (base rule).\n7. `sdlc-author-architecture` → `architecture.md` + locked `contract.md` → review (**escalated**: contract).\n8. `sdlc-author-ui` → `ui-design.md` + `DESIGN.md` → review (base rule).\n9. `sdlc-author-stories` → repo-tagged `stories/EP-<slug>-S0N.md` → review (**per-repo**).\n   → `state.json` reaches `currentStep: ready-for-build`.\n\n### B — Build half (per story, per repo)\nFrom a `ready-for-build` story, for **each** repo the story is tagged with. Details: **“Run the full\nbuild half by hand”** below.\n\n10. `sdlc-spec story:<id> repo:<repo>` → writes `specs/<story-id>/` (spec/plan/tasks + `link.md`).\n11. `sdlc-implement story:<id> repo:<repo> task:<T0N>` → one atomic task = one branch = one commit\n    (repeat per task). Commit by convention with **`sdlc commit --type <t> -m <subject> [--ai <tool>]`**\n    (Task/Contract-Change/Co-Authored-By trailers, atomic-file guard).\n12. `sdlc-checks repo:<repo> action: run` → spec-link, contract-check, build/test/lint, and\n    verified-commits (platform-Verified signature + roster-allowlisted author) must pass.\n13. Open the PR/MR from the wired template with **`sdlc open-pr --repo <repo> [--risk <level>]`**;\n    `sdlc-pr-template repo:<repo> action: route` prints the required reviewers from the Impact & Risk block.\n14. `sdlc-ship` → `ai-review` (advisory) → `approve` (the human engineer gate) → `ship` (merge, record\n    in `build-log.json`, update story status to `in-build`/`shipped`).\n    - **Multi-repo:** repeat 10–14 in each repo, all from the **one** locked contract.\n    - **Existing code:** `sdlc-backfill` first, to produce a human-verified spec for a built feature.\n\n### C — Automation (optional, earned over time)\n15. After a back step accumulates trust evidence, earn it:\n    `sdlc-run action: set-dial step:<step> to: machine_advance` (refused if evidence is short or for a\n    front state / the engineer review).\n16. Drive a story's back half on the dials: `sdlc-run story:<id> repo:<repo>` — it auto-advances\n    earned steps and stops for a human otherwise, always halting at the engineer review.\n17. **Kill switch any time:** `sdlc-run action: kill` (everything → manual) / `action: unkill`.\nDetails: **“Run the back half on the dial”** below.\n\n### Any time\n- **`sdlc-status [EP-<slug>]`** — read-only: the front chain, each build step's dial + status, the\n  trust record, and (across epics) the fleet roll-up. Start here to see what's blocking.\n\n## Run the full front half by hand\n\nThe front half walks **epic → review → architecture+contract → review → UI design → review → stories\n→ review → `ready-for-build`**. It is all files under `epics/EP-<slug>/`. The skills below guide you,\nbut you can also edit the files directly — that's the point.\n\nEach authoring step is the same shape: an author skill produces an artifact, sets its step `done`,\nmoves `currentStep` to the matching review, and **stops at the gate**. Then **`sdlc-review-gate`**\n(one gate, reused for all four reviews) takes `open → comment → approve → advance`. When the hub is on a\nplatform, the **`sdlc gate`** CLI runs that gate over a real PR/MR — `open` raises the review PR, `sync`\npulls approvals + comment threads into the ledger, and the step **auto-advances when the approved,\nfully-resolved PR is merged** (the merge is the human approval act).\n\n**Code-aware (when repos are connected).** If you ran `sdlc-connect-repos` in setup, each author step\nfirst loads the connected repos' **code-maps** (from `.sdlc/code-context/<repo>/`) so it considers what\nalready exists: the epic references existing behaviour, **the architecture cross-checks the contract\nsurface against existing endpoints/events/entities before hash-locking it**, the UI reuses existing\ncomponents, and stories anchor to real modules. Each artifact stamps what it read in its `code-context:`\nfrontmatter; a repo that has moved since connect triggers a staleness warning — the step **flags it and\nstops**, pointing you at `sdlc repo refresh <repo>` (refreshing is a human decision, never an automatic\nside-effect). With no repos connected the steps proceed exactly as before (greenfield-safe).\n\n### Author steps\n1. **`sdlc-author-epic`** (state 1) → `epic.md`; assigns the stable `EP-<slug>` ID; seeds\n   `.sdlc/state.json` (all `human_approve`, front steps locked) + empty `.sdlc/approvals.json`.\n2. **`sdlc-author-architecture`** (state 3) → `architecture.md` + the locked `contract.md`; writes the\n   contract-surface SHA-256 to `.sdlc/contract-lock.json`.\n3. **`sdlc-author-ui`** (state 5) → `ui-design.md` + `DESIGN.md` (drives Impeccable\n   `document|extract|craft` slash-commands when installed; otherwise authors directly).\n4. **`sdlc-author-stories`** (state 7) → one file per story `stories/EP-<slug>-S0N.md`, each tagged\n   with the `repos` it implements.\n\n### The one gate (every review)\n\nEvery review is the same loop — author writes, reviewers comment (which never advances), approvals\naccumulate, and the step moves forward only when the rule is met. **File-only** ends in an explicit\n`advance`; **PR-driven** (hub on a platform) ends when the approved, fully-resolved review PR is\n**merged**:\n\n```mermaid\nflowchart LR\n    a[\"author writes<br/>artifact\"] --> o[\"open<br/>raise review PR/MR\"]\n    o --> c[\"comment<br/>reviewers leave notes\"]\n    c -->|owner addresses,<br/>edits in place| c\n    c --> ap[\"approve<br/>+ resolve threads\"]\n    ap --> adv{\"rule met,<br/>threads resolved,<br/>merged?\"}\n    adv -->|no — names who's missing| o\n    adv -->|yes| nxt([\"next step\"])\n```\n\n**File-only** — invoke **`sdlc-review-gate`** with `open` (present the artifact; reviewers comment in\n`reviews/<artifact>--<date>--comments.md`), `approve` (name + role → `.sdlc/approvals.json`), and\n`advance` (moves **only if** the rule is satisfied, else it names the missing approval).\n\n**PR-driven** — when the hub is on a platform, the **`sdlc gate`** CLI runs the same gate over a PR/MR:\n- `sdlc gate open <epic> <artifact>` — raise the review PR/MR; mark the step `in_review`.\n- `sdlc gate sync <epic> [artifact]` — pull approvals + comment threads into the **same** ledger (your\n  own `gh`/`glab`, no stored tokens) and **auto-advance on merge** once the rule is met and every thread\n  is resolved. Approvals are **revoked when the reviewed artifact changes** (re-hash), so reviewers get\n  a fresh pass. Unresolved comments hold the step `in_review`.\n- `sdlc gate comments <epic>` fetches the open threads to address; `sdlc gate status <epic>` shows\n  approvals (counting only the non-stale ones). The file ledger stays the source of truth; with no\n  platform / no CLI it degrades to file-only.\n\n**The gate rule, by review:**\n- **Base** (epic, UI): `owner + 1 reviewer`.\n- **Escalated** (architecture+contract — `risk_tags: [\"contract\"]`): base **plus a domain owner for\n  every repo in `epic.repos`**. The contract-surface hash must still match `.sdlc/contract-lock.json`\n  (a changed surface invalidates approvals).\n- **Per-repo** (stories): base **plus a domain owner (the repo's engineer) for every repo that appears\n  in any story's `repos`**.\n\n### Check status anytime\nInvoke **`sdlc-status`** (read-only) to see the full 8-step chain, every step's dials/status, the\ncontract lock, story repo tags, and which approvals the active gate still needs.\n\n## Worked example (already in this repo)\n\n`epics/EP-istifta-inquiries/` shows the **whole front half** walked end to end:\n- `epic.md` authored + approved (epic gate, base rule) — 2026-06-04.\n- `architecture.md` + `contract.md` authored; contract surface hash-locked in\n  `.sdlc/contract-lock.json`. Architecture gate **escalated** (contract): owner *alice* + reviewer\n  *bob* + domain owners *carol* (backend) and *dave* (mobile).\n- `ui-design.md` + `DESIGN.md` authored (Impeccable not installed → graceful fallback). UI gate base\n  rule (alice + bob).\n- Five repo-tagged stories `stories/EP-istifta-inquiries-S01..S05.md`. Stories gate **per-repo**: base\n  rule + a domain owner for each touched repo (carol/backend, dave/mobile).\n- `state.json` now reads `currentStep: ready-for-build`, every front step `done` — the Phase 3\n  handoff point.\n\nInspect it:\n```bash\ncat epics/EP-istifta-inquiries/.sdlc/state.json\ncat epics/EP-istifta-inquiries/.sdlc/approvals.json\ncat epics/EP-istifta-inquiries/.sdlc/contract-lock.json\nls  epics/EP-istifta-inquiries/reviews/\nls  epics/EP-istifta-inquiries/stories/\n# re-verify the contract surface still matches its lock:\nawk '/CONTRACT-SURFACE:BEGIN/{f=1;next} /CONTRACT-SURFACE:END/{f=0} f' \\\n  epics/EP-istifta-inquiries/contract.md | shasum -a 256\n```\n\n## Run the full build half by hand (Phase 3)\n\nFrom a `ready-for-build` story, the **build half** turns one atomic task into shipped code through\ngates that protect production. Per-repo specs live in each code repo; the contract stays singular in\nthe product repo. Code repos are **separate git repos** under `demo-repos/<repo>/` (gitignored;\n`demo-repos/README.md` explains regeneration). **Nothing auto-advances** — every gate is human-owned.\n\n1. **Spec** — `sdlc-spec` runs the heavy Spec Kit ceremony **once per story per repo**\n   (`specify`→`clarify`→`plan`→`analyze`→`checklist`→`tasks`), writing `specs/<story-id>/` and a\n   `link.md` back to the story (drives `/speckit.*` when installed, else degrades). It **quotes** the\n   locked contract; it never widens it.\n2. **Implement** — `sdlc-implement` (the `dev` step): one atomic task = one branch\n   (`feat/<story>-<task>-…`) = one PR. The diff stays inside the files the task declared. Commit with\n   **`sdlc commit`** — it builds the conventional subject, derives the `Task:` trailer from the branch\n   (add `--contract-change` only if the locked surface is touched), appends an optional `--ai` co-author,\n   and refuses a non-atomic stage. Open the PR with **`sdlc open-pr --repo <repo>`** (template prefilled).\n3. **Check gates** — `sdlc-checks` wires three CI gates (GitHub + GitLab) that must pass before merge:\n   **spec-link** (links a real story/spec), **contract-check** (a contract-surface change without\n   `Contract-Change` + a re-locked contract FAILS, routing back to the architecture gate),\n   **build/test/lint**. They fail closed on a bad base ref.\n4. **PR/MR template + risk routing** — `sdlc-pr-template` drops the platform-matched template with an\n   Impact & Risk block; `high` risk (or a contract/auth/payments surface) routes the review to domain\n   owners (`risk-route.sh`), the same escalation as the gate.\n5. **AI review → engineer review → ship** — `sdlc-ship`: CodeRabbit is an advisory first pass (never\n   the authority); a human engineer approves (owner + 1 reviewer, escalating to domain owners); on\n   merge the ship is recorded in `.sdlc/build-log.json` and the story state becomes `in-build` →\n   `shipped`. The epic → story → task → PR → mergeCommit chain is traceable both ways.\n\n**Multi-repo:** a story tagged `repos: [backend, mobile]` runs the above in each repo independently from\nthe **one** locked contract; the contract-check blocks a surface bypass in either repo.\n\n**Backfill existing code:** `sdlc-backfill` packs one feature with **Repomix** (`npx repomix`, secret-scan\nby default), drafts an *unverified* spec (\"describe what exists, do not invent\"), a human approves it,\nand `backfill-check.sh` blocks a change to that feature until its spec is approved — gated per touched\nfeature, never the whole repo.\n\nThe build half is walked end to end on the worked epic: story **S01** shipped (`status: shipped`,\nthree tasks in `build-log.json`), **S03** built across backend + mobile, and a `health` feature\nbackfilled. The code repos are regenerable from `demo-repos/README.md`.\n\n## Run the back half on the dial (Phase 4 — automation, earned)\n\nPhase 4 is **automation, earned with evidence and reversible in one move**. Phase 4a made the\n`automation` dial real and earned the safest step (the check-gate advance); Phase 4b added the\n`implement → check` hand-off and the `spec`/`tasks` trust hooks. The engine is `sdlc-run`; the\nevidence lives in two new files per epic under `.sdlc/`: `build-state/<story-id>.json` (the back steps\nwith their dials, per repo) and `trust-log.json` (every run's verdict). See\n`docs/phase-4-build-plan.md` and `docs/phase-4b-build-plan.md`.\n\n- **Drive a story's back half:** `sdlc-run {story} {repo}` walks `spec → tasks → implement → checks`,\n  reading each step's dial. On `machine_advance` it advances on its own; on `human_approve` it stops\n  for a human; on any FAIL, scope overrun, or contract-surface touch it **halts and pulls in a human**.\n  It always stops at the engineer review (`sdlc-ship`), which is never automated.\n- **Read the trust log:** `sdlc-status {epic}` shows each back step's dial, status, and trust record —\n  runs, % `approved-unchanged`, and whether that clears the threshold (`automation.trust_threshold` in\n  `config.yaml`, default ≥5 runs and ≥80% unchanged). The engineer review records each run's verdict\n  (a diff merged as-authored is `approved-unchanged`; one edited first is `approved-with-edits`; a\n  failed one is `rejected`).\n- **Earn automation for a step:** once a step's trust record clears the threshold,\n  `sdlc-run action: set-dial step: checks to: machine_advance` flips it. The setter **refuses** if the\n  evidence is short, or for any front state / the engineer review. Reverting\n  (`to: human_approve`) is always allowed — automation is reversible in one move.\n- **Kill switch:** `sdlc-run action: kill` forces every step back to `human_approve` system-wide\n  instantly (no code change, no per-step edits); `sdlc-run action: unkill` restores earned automation.\n\n**Earned so far:** `checks` (Step B, Phase 4a) and `implement` (Step D, Phase 4b — the\n`implement → check` hand-off; the scope/contract halts and the engineer review still gate the merge).\n`tasks` (Step C) and `spec` have their dials + trust hooks but stay `human_approve` until their own\nruns clear the threshold — there is no historical signal to seed them from, so they are earned only on\ngenuine runs (never fabricated). See `docs/phase-4b-build-plan.md`.\n\n## What's intentionally NOT built yet\n\n**Phase 4b Step C** (the remaining automation): `tasks` generation advance — gated until real\n`tasks`/`spec` trust evidence accrues. The hook that records that evidence is built; the dial flips\nonly once the threshold is genuinely met. The scope guard and contract-surface halt always override\nthe dial, and **front states and the engineer review stay `human_approve`, permanently.**\n\n**Phase 5 (conditional):** the optional service layer (watch repos, run earned-automation steps\nunattended, read-only dashboards), built only when the CLI genuinely can't keep up, with git remaining\nthe source of truth. It is **trigger-gated** — `docs/phase-5-build-plan.md` is the build plan: its\nthree parts (read-index, unattended runner, dashboard) each ship only when *their* bottleneck is\nmeasured, with the hard rules they inherit and the instrumentation (already shipped in `sdlc-status`)\nthat makes the decision data-driven. See also `docs/claude-code-build-plan.md` §8.\n","readmeFilename":"README.md"}