{"_id":"@admirhodzic/project-bootstrap","name":"@admirhodzic/project-bootstrap","dist-tags":{"beta":"2.0.0-beta.0","latest":"2.0.0-beta.0"},"versions":{"2.0.0-beta.0":{"name":"@admirhodzic/project-bootstrap","version":"2.0.0-beta.0","description":"Portable, testable workflows for AI-assisted software delivery","type":"module","private":false,"packageManager":"pnpm@10.15.1","engines":{"node":"^22.0.0 || ^24.0.0"},"bin":{"project-bootstrap":"dist/cli.js"},"repository":{"type":"git","url":"git+https://github.com/admirhodzic/project-bootstrap.git"},"bugs":{"url":"https://github.com/admirhodzic/project-bootstrap/issues"},"homepage":"https://github.com/admirhodzic/project-bootstrap#readme","license":"Apache-2.0","publishConfig":{"access":"public","provenance":true},"devDependencies":{"@eslint/js":"^10.0.1","@types/node":"^26.4.1","@vitest/coverage-v8":"^4.1.11","eslint":"^10.9.1","markdownlint-cli2":"^0.23.2","prettier":"^3.9.6","typescript":"^6.0.3","typescript-eslint":"^8.69.0","vitest":"^4.1.11"},"scripts":{"build":"tsc -p tsconfig.build.json","clean":"node scripts/clean.mjs","format":"prettier --write .","format:check":"prettier --check .","lint":"eslint . --max-warnings 0","typecheck":"tsc -p tsconfig.json --noEmit","test":"vitest run","test:coverage":"vitest run --coverage","eval":"pnpm build && node dist/eval-cli.js .","smoke:package":"node scripts/smoke-package.mjs","docs:lint":"markdownlint-cli2 \"**/*.md\" \"#node_modules\" \"#content/legacy\"","validate":"pnpm build && node dist/cli.js validate --source .","check":"pnpm format:check && pnpm lint && pnpm typecheck && pnpm test && pnpm docs:lint && pnpm validate && pnpm eval"},"_id":"@admirhodzic/project-bootstrap@2.0.0-beta.0","_integrity":"sha512-ma2Pcnt0JCCR562dVZiNH0MeiTRe3sz01oYYchFL11XJtZmkuVXq4555v8sK5IZC5Uqts1tCZgH23uR72rBYzg==","_resolved":"C:\\Users\\Admir\\AppData\\Local\\Temp\\project-bootstrap-release-3e6fdc0cfc7f42449fbb6eec839ec626\\admirhodzic-project-bootstrap-2.0.0-beta.0.tgz","_from":"file:C:/Users/Admir/AppData/Local/Temp/project-bootstrap-release-3e6fdc0cfc7f42449fbb6eec839ec626/admirhodzic-project-bootstrap-2.0.0-beta.0.tgz","_nodeVersion":"22.16.0","_npmVersion":"11.4.2","dist":{"integrity":"sha512-ma2Pcnt0JCCR562dVZiNH0MeiTRe3sz01oYYchFL11XJtZmkuVXq4555v8sK5IZC5Uqts1tCZgH23uR72rBYzg==","shasum":"6ebd6693dae36f56c8323a3e9690a539f3456085","tarball":"https://registry.npmjs.org/@admirhodzic/project-bootstrap/-/project-bootstrap-2.0.0-beta.0.tgz","fileCount":120,"unpackedSize":225295,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIGN/C3KDyKkgCNljvNurHuaae2/g+t+ssM10ufHnS+44AiB3bxoGe8n5VbnsRZj2YNUINBe7MUWuc8A4GTy6BnI37Q=="}]},"_npmUser":{"name":"admirhodzic","email":"ADMIRHODZIC@BIH.NET.BA"},"directories":{},"maintainers":[{"name":"admirhodzic","email":"ADMIRHODZIC@BIH.NET.BA"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/project-bootstrap_2.0.0-beta.0_1788596169968_0.43778389317906874"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-05T08:16:09.738Z","2.0.0-beta.0":"2026-09-05T08:16:10.116Z","modified":"2026-09-05T08:16:10.372Z"},"maintainers":[{"name":"admirhodzic","email":"ADMIRHODZIC@BIH.NET.BA"}],"description":"Portable, testable workflows for AI-assisted software delivery","homepage":"https://github.com/admirhodzic/project-bootstrap#readme","repository":{"type":"git","url":"git+https://github.com/admirhodzic/project-bootstrap.git"},"bugs":{"url":"https://github.com/admirhodzic/project-bootstrap/issues"},"license":"Apache-2.0","readme":"# Project Bootstrap\n\nPortable, testable workflows for safer AI-assisted software delivery.\n\nProject Bootstrap gives a repository a concise AI-agent contract, focused workflow skills, reusable planning templates, platform-native adapters, and a conflict-safe lifecycle CLI. It is designed for both greenfield and existing codebases and scales its process to the work: a documentation correction stays lightweight, while architecture, migrations, and security-sensitive changes receive deeper planning and review.\n\n> **Release status:** v2.0.0-beta.0 is implemented and verified locally. The npm package has not been published, and live platform pilots are still pending. Use the source-checkout instructions below today; treat npm commands as post-publication examples.\n\n## Why use it?\n\nCoding agents are most useful when they understand project conventions, preserve existing work, know their authority boundaries, and attach evidence to completion claims. Project Bootstrap makes those expectations portable without forcing every task through the same heavyweight process.\n\nIt provides:\n\n- a small, always-on `AGENTS.md` contract;\n- seven progressively loaded Agent Skills;\n- Quick, Standard, Deep, and Incident workflow profiles;\n- specification, plan, task, ADR, risk, and handoff templates;\n- least-privilege reviewer, security reviewer, test runner, and researcher profiles;\n- adapters for Codex, GitHub Copilot, Cursor, Cline, Windsurf, Claude Code, Gemini CLI, and Aider;\n- safe installation, update, drift detection, migration, and uninstall behavior;\n- deterministic behavioral evaluations that make safety and workflow claims testable.\n\nProject Bootstrap does not initialize Git, commit changes, enable hooks, configure credentials, connect remote tools, deploy software, or publish releases on a user's behalf.\n\n## Requirements\n\n- Node.js 22 LTS or 24 LTS\n- pnpm 10.15.1 for development from source\n- A target repository whose files you are authorized to modify\n\nThe CLI has no production dependencies. pnpm is needed only to build and develop this repository; an installed package exposes the `project-bootstrap` executable through Node.js.\n\n## Quick start\n\n### Option 1: Use the CLI from this checkout\n\n```sh\ngit clone https://github.com/admirhodzic/project-bootstrap.git\ncd project-bootstrap\ncorepack enable\npnpm install --frozen-lockfile\npnpm build\n```\n\nPreview installation into another project:\n\n```sh\nnode dist/cli.js init --root ../your-project --platform codex --dry-run\n```\n\nApply the reviewed plan:\n\n```sh\nnode dist/cli.js init --root ../your-project --platform codex\n```\n\nUse an explicit comma-separated list when a repository is used with several assistants:\n\n```sh\nnode dist/cli.js init --root ../your-project --platform codex,copilot,cursor\n```\n\n### Option 2: Install plain files manually\n\nThe framework remains useful without the CLI.\n\n1. Copy this repository's `AGENTS.md` to the target repository root.\n2. Copy only the relevant skill directories from `content/skills/` to `.agents/skills/`.\n3. Optionally copy templates to a location your team documents.\n4. Add the thin wrapper from `content/adapters/<platform>/` to its native platform location.\n5. Preserve existing instruction files and merge intentionally rather than overwriting them.\n\nA minimal Codex installation needs only:\n\n```text\nyour-project/\n├── AGENTS.md\n└── .agents/\n    └── skills/\n        └── implement-change/\n            └── SKILL.md\n```\n\nManual installations are not managed by the CLI unless the CLI itself later creates those files. Identical pre-existing files are deliberately not adopted into the uninstall manifest.\n\n### Option 3: npm after publication\n\nThe intended package name is `@admirhodzic/project-bootstrap`; the unscoped `project-bootstrap` name belongs to another project. After this beta is published and scope ownership is confirmed, the expected usage will be:\n\n```sh\nnpx @admirhodzic/project-bootstrap@2.0.0-beta.0 init --root . --platform codex --dry-run\nnpx @admirhodzic/project-bootstrap@2.0.0-beta.0 init --root . --platform codex\n```\n\nDo not rely on those npm commands until a release is visible in the npm registry and linked from this repository.\n\n## What gets installed\n\nEvery installation receives the canonical files below. Platform-specific files depend on `--platform`.\n\n```text\nyour-project/\n├── AGENTS.md\n├── .agents/\n│   ├── skills/\n│   │   ├── bootstrap-project/SKILL.md\n│   │   ├── specify-change/SKILL.md\n│   │   ├── plan-change/SKILL.md\n│   │   ├── implement-change/SKILL.md\n│   │   ├── review-change/SKILL.md\n│   │   ├── security-review/SKILL.md\n│   │   └── handoff/SKILL.md\n│   └── profiles/\n│       ├── reviewer.md\n│       ├── security-reviewer.md\n│       ├── test-runner.md\n│       └── researcher.md\n└── .project-bootstrap/\n    ├── manifest.json\n    └── templates/\n        ├── spec.md\n        ├── plan.md\n        ├── task.md\n        ├── adr.md\n        ├── risk-register.md\n        └── project-state.md\n```\n\nThe manifest records the package version, workflow profile, selected platforms, normalized managed paths, and SHA-256 hashes. It is the ownership record used by `doctor`, `update`, and `uninstall`; it is not a general project-state database.\n\n## Platform adapters\n\n| Platform       | Tier | Generated files                                                | Current evidence           |\n| -------------- | ---: | -------------------------------------------------------------- | -------------------------- |\n| OpenAI Codex   |    1 | `AGENTS.md`, `.agents/skills/`, `.codex/agents/*.toml`         | Documentation and fixtures |\n| GitHub Copilot |    1 | `.github/copilot-instructions.md`, `.github/agents/*.agent.md` | Documentation and fixtures |\n| Cursor         |    1 | `.cursor/rules/project-bootstrap.mdc`                          | Documentation and fixtures |\n| Cline          |    1 | `.clinerules/project-bootstrap.md`                             | Documentation and fixtures |\n| Windsurf       |    1 | `.windsurf/rules/project-bootstrap.md`                         | Documentation and fixtures |\n| Claude Code    |    2 | `CLAUDE.md`                                                    | Fixture only               |\n| Gemini CLI     |    2 | `GEMINI.md`                                                    | Fixture only               |\n| Aider          |    2 | `.aider.conf.yml`                                              | Fixture only               |\n\nTier 1 means the adapter is a primary compatibility target. Tier 2 means fixture support exists but live verification is still more limited. “Fixture” proves generated paths, content, budgets, and lifecycle behavior; it does not prove a current hosted agent interpreted every instruction correctly.\n\nAdapters are intentionally thin and refer back to canonical policy. Specialist profiles are technically read-only only when the host platform can enforce that restriction; otherwise the same constraint is explicit guidance, not claimed isolation. See the dated [compatibility matrix](docs/compatibility.md).\n\n### Platform detection\n\nWhen `--platform` is omitted, the CLI checks for common signals:\n\n| Signal            | Selected adapter |\n| ----------------- | ---------------- |\n| `.codex/`         | Codex            |\n| `.github/`        | GitHub Copilot   |\n| `.cursor/`        | Cursor           |\n| `.clinerules`     | Cline            |\n| `.windsurf/`      | Windsurf         |\n| `CLAUDE.md`       | Claude Code      |\n| `GEMINI.md`       | Gemini CLI       |\n| `.aider.conf.yml` | Aider            |\n\nIf no signal is found, Codex is selected. Because some signals—especially `.github/`—may exist for unrelated reasons, explicit `--platform` selection is recommended for reproducible installations.\n\n## Workflow profiles\n\n| Profile  | Use when                                                                                                | Typical behavior                                                                                  |\n| -------- | ------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------- |\n| Quick    | Read-only work, docs, formatting, localized safe fixes                                                  | Inspect, change if needed, run a focused check                                                    |\n| Standard | Ordinary features and bugs                                                                              | Define acceptance criteria, make a short plan, implement, verify                                  |\n| Deep     | Greenfield systems, architecture, migrations, security, sensitive data, destructive or external effects | Specify, threat-model, compare alternatives, stage rollout and rollback, seek independent review  |\n| Incident | Urgent regressions                                                                                      | Reproduce, contain, apply the smallest safe fix, run targeted regression checks, record follow-up |\n\nSelect a profile during installation:\n\n```sh\nproject-bootstrap init --root . --platform codex --profile deep\n```\n\nThe selected profile is recorded in the manifest and establishes the default workflow posture. It does not grant additional authority. Updates retain the installed profile unless another profile is explicitly supplied.\n\nRead [workflow profiles and examples](docs/workflows.md) for greenfield, brownfield, quick-fix, and security-sensitive walkthroughs.\n\n## Skills and templates\n\n| Skill               | Purpose                                                          | Avoid when                                                  |\n| ------------------- | ---------------------------------------------------------------- | ----------------------------------------------------------- |\n| `bootstrap-project` | Establish justified foundations in a new or existing repository  | The request is an ordinary localized change                 |\n| `specify-change`    | Turn ambiguity into observable outcomes and acceptance criteria  | A Quick task is already clear                               |\n| `plan-change`       | Resolve material implementation uncertainty and decompose work   | The change is one obvious step                              |\n| `implement-change`  | Deliver approved criteria with bounded edits and evidence        | The task is read-only analysis or review                    |\n| `review-change`     | Find correctness, regression, security, and verification defects | Only stylistic commentary is desired                        |\n| `security-review`   | Perform threat-driven review of sensitive surfaces               | Ordinary input handling has no meaningful security exposure |\n| `handoff`           | Leave a compact, verified continuation point                     | A trivial task is finished in the current session           |\n\nTemplates are starting points, not mandatory artifacts. Quick work should not create a specification, risk register, or backlog by default. Remove unused placeholders before treating a generated document as approved.\n\n## CLI reference\n\n```text\nproject-bootstrap <command> [options]\n```\n\n### Commands\n\n| Command     | Purpose                                                                     |           Writes files? |\n| ----------- | --------------------------------------------------------------------------- | ----------------------: |\n| `init`      | Install canonical content and selected adapters                             | Yes, unless `--dry-run` |\n| `update`    | Update only unchanged managed files and retain local customizations         | Yes, unless `--dry-run` |\n| `validate`  | Validate package content, budgets, registry entries, and skill contracts    |                      No |\n| `doctor`    | Compare installed files with the manifest and report missing/modified files |                      No |\n| `uninstall` | Remove only unchanged files owned by the manifest                           | Yes, unless `--dry-run` |\n| `migrate`   | Install v2 alongside a copied or customized v1, preserving `AGENT.md`       | Yes, unless `--dry-run` |\n\n### Options\n\n| Option              | Meaning                                                          |\n| ------------------- | ---------------------------------------------------------------- |\n| `--root <path>`     | Target project; defaults to the current directory                |\n| `--source <path>`   | Package/content root; intended for development and diagnostics   |\n| `--platform <list>` | Comma-separated adapter list                                     |\n| `--profile <name>`  | `quick`, `standard`, `deep`, or `incident`                       |\n| `--dry-run`         | Print the complete mutation plan without filesystem side effects |\n| `--json`            | Emit structured JSON for automation                              |\n| `--help`, `-h`      | Show command help                                                |\n| `--version`, `-v`   | Show the package version                                         |\n\nInvalid commands/options and malformed or unsupported manifests return exit code 2. Content-validation failures, installation drift, and unexpected operational failures return exit code 1. Successful operations return 0.\n\n## Common how-tos\n\n### Preview and initialize a repository\n\nAlways inspect a dry run first when the target contains existing agent instructions:\n\n```sh\nproject-bootstrap init --root . --platform codex,cursor --profile standard --dry-run\nproject-bootstrap init --root . --platform codex,cursor --profile standard\n```\n\nPlan actions are explicit:\n\n- `CREATE`: target does not exist and will be installed;\n- `UPDATE`: an unchanged managed file will receive new canonical content;\n- `RETAIN`: content is already current or must remain untouched;\n- `CONFLICT`: an unknown or locally modified target will not be overwritten;\n- `REMOVE`: an unchanged managed file will be removed during uninstall.\n\n### Check installation health\n\n```sh\nproject-bootstrap doctor --root .\nproject-bootstrap doctor --root . --json\n```\n\n`doctor` reports a healthy installation only when every manifest-owned file exists and still matches its recorded hash. A missing manifest is reported as not installed rather than guessed from filenames.\n\n### Update safely\n\n```sh\nproject-bootstrap update --root . --dry-run\nproject-bootstrap update --root .\n```\n\nAn update replaces a managed file only when its current hash matches the previous manifest. If a user changed the file, Project Bootstrap keeps the user's version and writes the proposed replacement to:\n\n```text\n.project-bootstrap/candidates/<original-destination>\n```\n\nReview and merge that candidate manually. Project Bootstrap never treats a conflict candidate as an automatically accepted change.\n\n### Resolve a conflict\n\n1. Compare the current file with its candidate.\n2. Merge the desired canonical changes into the current file.\n3. Remove the candidate after review if it is no longer needed.\n4. Run `update` again. If the result still reports a conflict, the current file intentionally remains user-owned or modified.\n5. Run `doctor` to see the resulting managed-file state.\n\nDo not edit the manifest hash merely to silence drift; that changes the ownership evidence without verifying content.\n\n### Uninstall without deleting customizations\n\n```sh\nproject-bootstrap uninstall --root . --dry-run\nproject-bootstrap uninstall --root .\n```\n\nOnly unchanged manifest-owned files are removed. Modified files are retained and remain recorded so the unresolved ownership state is visible. Pre-existing identical files that Project Bootstrap did not create are not claimed and therefore are not removed.\n\n### Migrate from v1\n\nV1 used a singular `AGENT.md` and a mandatory phase-heavy process. V2 uses `AGENTS.md`, adaptive profiles, and focused skills.\n\n```sh\nproject-bootstrap migrate --root . --platform codex --dry-run\nproject-bootstrap migrate --root . --platform codex\n```\n\nMigration preserves an existing `AGENT.md` and reports it for manual reconciliation. It does not delete customized v1 content or require a clean Git repository. Follow the complete [v1 migration guide](docs/migration-v1.md).\n\n### Use JSON output in automation\n\n```sh\nproject-bootstrap init --root . --platform codex --dry-run --json\nproject-bootstrap doctor --root . --json\n```\n\nJSON output mirrors the in-memory plan or diagnostic report. Automation should still fail closed on non-zero exit codes and should not apply a plan containing unresolved conflicts without human review.\n\n### Validate a source checkout\n\n```sh\npnpm validate\n# Equivalent after building:\nnode dist/cli.js validate --source .\n```\n\nValidation checks every canonical registry source, required install destination, path safety, root instruction budget, adapter budget, skill metadata, unique skill names, and required skill sections.\n\n## Safety model\n\nProject Bootstrap's file lifecycle follows these invariants:\n\n- all mutations originate from a complete in-memory plan;\n- relative destinations are normalized and cannot use absolute paths, `..`, empty segments, or drive-qualified paths;\n- the nearest existing ancestor is resolved before every write to reject symlink and Windows junction escapes;\n- writes use a temporary file and atomic rename;\n- an invocation attempts to restore touched files if a later operation fails;\n- unknown and locally modified content is never silently overwritten or deleted;\n- `--dry-run` has no filesystem side effects;\n- generated hooks are examples and are never enabled automatically;\n- no credentials or remote integrations are installed.\n\nProcess-level rollback cannot defend against every hostile concurrent filesystem writer or sudden power loss. Use normal repository backups, least-privilege execution, and review for high-trust environments. The full analysis is in the [threat model](docs/threat-model.md).\n\n## Behavioral evaluation\n\nThe repository includes 15 scenarios covering:\n\n- dirty worktrees, external writes, prompt injection, and path traversal;\n- quick fixes, localized bugs, greenfield work, dependencies, and incidents;\n- nested instruction precedence and honest delegation fallbacks;\n- stale or contradictory handoff state.\n\nRun deterministic schema and grader checks:\n\n```sh\npnpm eval\n```\n\nThe command loads all scenarios and verifies safe and intentionally unsafe fixtures against objective graders. Default CI never performs model calls.\n\nLive evaluation is a separate, explicitly authorized activity. A live runner must record platform and agent version, scenario revision, repetitions, duration, tools, interventions, and token usage when available, and must set spend, timeout, concurrency, and credential boundaries. See the [live runner contract](evals/runners/README.md) and [pilot protocol](docs/pilots.md).\n\n## Development\n\n### Install dependencies\n\n```sh\ncorepack enable\npnpm install --frozen-lockfile\n```\n\n### Run checks\n\n```sh\npnpm format:check   # Prettier\npnpm lint           # ESLint\npnpm typecheck      # TypeScript without emitting files\npnpm test           # deterministic Vitest suite\npnpm test:coverage  # suite plus enforced coverage thresholds\npnpm docs:lint      # Markdown checks\npnpm validate       # build and canonical content validation\npnpm eval           # behavioral scenario/fixture validation\npnpm check          # complete local gate\n```\n\n### Build and test the package\n\n```sh\npnpm build\npnpm pack --pack-destination .\npnpm smoke:package ./admirhodzic-project-bootstrap-2.0.0-beta.0.tgz\n```\n\nThe smoke test installs the tarball into a disposable project and exercises version output, dry-run purity, initialization, health checks, conflict generation, and customization-preserving uninstall.\n\n### Repository layout\n\n```text\nAGENTS.md                  contributor/agent contract for this repository\ncontent/\n├── skills/                canonical workflow skills\n├── templates/             reusable durable artifact templates\n├── agents/                canonical specialist definitions\n├── adapters/              platform-native thin wrappers/profiles\n├── hooks/                 opt-in deterministic examples\n└── legacy/                archived v1 instructions\nsrc/                       CLI, planner, manifest, validation, and eval code\ntests/                     deterministic unit/integration tests\nschemas/                   versioned JSON contracts\nevals/                     scenarios, fixtures, runners, and baselines\ndocs/                      architecture, security, compatibility, and status\n.github/                   CI, security analysis, release, and contribution files\n```\n\n## Continuous integration and releases\n\nPull-request CI performs the full quality gate on Node.js 24 and portability build/tests across Linux, macOS, and Windows with Node.js 22/24 coverage. GitHub Actions are pinned to immutable commit SHAs and use explicit minimal permissions. Separate workflows provide dependency review and CodeQL analysis.\n\nThe tag-driven release workflow:\n\n1. runs only in the canonical repository for `v2.*` tags;\n2. installs from the frozen lockfile;\n3. runs the complete gate;\n4. packs one reviewed tarball;\n5. generates SHA-256 checksums;\n6. publishes with npm provenance through the protected `npm` environment;\n7. creates a GitHub release from the same artifacts.\n\nThe workflow is implemented but has not published this beta. npm scope ownership, trusted publishing, protected-environment reviewers, and release authority must be confirmed first. See the [release checklist](docs/release-checklist.md) and [repository security activation checklist](docs/repository-security.md).\n\n## Security and optional integrations\n\nReport vulnerabilities through GitHub private vulnerability reporting, not a public issue. Read [SECURITY.md](SECURITY.md) for supported versions and reporting expectations.\n\nCore installation enables no Model Context Protocol servers, connectors, browser sessions, issue trackers, deployment tools, or credentials. Teams can add those integrations deliberately after reviewing scopes, exposed data, prompt-injection risk, rate limits, and destructive operations. See [optional integration guidance](docs/integrations.md) and [trusted hook guidance](docs/hooks.md).\n\n## Contributing\n\nBefore contributing:\n\n1. Read [CONTRIBUTING.md](CONTRIBUTING.md) and the root `AGENTS.md`.\n2. Keep each policy or template canonical; adapters should reference it rather than copy it.\n3. Add tests for mutation, schema, compatibility, or behavior changes.\n4. Run `pnpm check` and inspect the final diff.\n5. Update `CHANGELOG.md` for user-visible changes.\n\nAdapter contributions must declare native paths, evidence date/source, budget, feature limitations, fixtures, and maintenance ownership. Follow the [adapter contribution contract](docs/adapter-contribution.md).\n\n## Troubleshooting\n\n### `doctor` says no manifest exists\n\nThe repository may be a manual installation or initialization may not have run. Use `init --dry-run` before deciding whether to create a managed installation.\n\n### `update` reports conflicts\n\nThis is expected when installed content was edited. Your file was retained. Review its candidate under `.project-bootstrap/candidates/` and merge manually.\n\n### `doctor` reports a missing file\n\nThe manifest owns a file that no longer exists. Run `update --dry-run` to see whether it will be recreated, then apply the plan if appropriate.\n\n### `uninstall` retains files\n\nRetained files differ from their recorded hashes. This protects customizations. Delete them manually only after confirming their exact paths and contents are no longer needed.\n\n### A platform adapter is selected unexpectedly\n\nAutomatic detection uses repository signals and may infer Copilot from `.github/`. Pass an explicit `--platform` list to make the installation reproducible.\n\n### `validate` checks the wrong location\n\n`validate` checks canonical package sources, not an installed target. From a source checkout use `--source .`; use `doctor --root <target>` for an installation.\n\n### The npm command cannot find the package\n\nThe beta has not been published yet. Build and invoke `node dist/cli.js` from this checkout until an npm release is linked here.\n\n## Documentation index\n\n- [Implementation plan](docs/implementation-plan.md)\n- [Backlog and completion tracker](docs/backlog.md)\n- [Current project state](docs/project-state.md)\n- [Workflow profiles and examples](docs/workflows.md)\n- [Compatibility matrix](docs/compatibility.md)\n- [Threat model](docs/threat-model.md)\n- [Beta review record](docs/beta-review.md)\n- [V1 migration guide](docs/migration-v1.md)\n- [Spec Kit interoperability decision](docs/spec-kit-interop.md)\n- [Dependency policy](docs/dependencies.md)\n- [Optional integrations](docs/integrations.md)\n- [Optional hooks](docs/hooks.md)\n- [Pilot protocol](docs/pilots.md)\n- [Adapter contribution contract](docs/adapter-contribution.md)\n- [Repository security activation](docs/repository-security.md)\n- [Release checklist](docs/release-checklist.md)\n- [Security policy](SECURITY.md)\n- [Changelog](CHANGELOG.md)\n\n## Current status and limitations\n\nLocal implementation and verification are complete. The latest recorded evidence is:\n\n- 36 deterministic tests passing;\n- coverage of 83.54% statements, 78.13% branches, 94% functions, and 85.76% lines;\n- format, lint, typecheck, Markdown, build, and content-validation gates passing;\n- 33 canonical registry entries validated;\n- 15 behavioral scenarios and four safe/unsafe fixtures validated;\n- packed-package init, doctor, update/conflict, and uninstall lifecycle passing.\n\nStable release still requires maintainer-controlled work: confirm npm scope ownership, activate repository security settings, obtain independent beta review, run repeated Tier 1 live pilots, tune from those observations, authorize publication, and perform post-publish smoke tests. Current evidence and blockers are maintained in [project state](docs/project-state.md).\n\n## License\n\nProject Bootstrap is licensed under the [Apache License 2.0](LICENSE).\n","readmeFilename":"README.md","_rev":"1-37c0a9a98b025fdaa0d7d24e318633cb"}