{"_id":"@ahoooooo/reviewready","_rev":"21-16ee16bf4eb91087bfe9e60be8541680","name":"@ahoooooo/reviewready","dist-tags":{"latest":"1.0.17"},"versions":{"1.0.2":{"name":"@ahoooooo/reviewready","version":"1.0.2","keywords":["github-actions","pull-request","code-review","policy-as-code","developer-tools","open-source","ai-agents","cli"],"license":"MIT","_id":"@ahoooooo/reviewready@1.0.2","maintainers":[{"name":"ahoooooo","email":"ahoooooooai@gmail.com"}],"homepage":"https://github.com/ahoooooooo/reviewready#readme","bugs":{"url":"https://github.com/ahoooooooo/reviewready/issues"},"bin":{"reviewready":"dist/cli.js"},"dist":{"shasum":"d8b6633551f930339585ada67808234cfc89e8a9","tarball":"https://registry.npmjs.org/@ahoooooo/reviewready/-/reviewready-1.0.2.tgz","fileCount":28,"integrity":"sha512-C+yelTnjf9FkH9gv3YlFsDL9uj3J4t6/5fXOvovBX+efW/voLYVDqf9VdHNr99WukhmcM1YPqhcFMGuJeYlXiw==","signatures":[{"sig":"MEUCIQD9OPJt86mX1nOicW/7MfRJ8D8bKidVvw0KRgr1nwJZ5gIgVsup6MW+HarwY1Ag13ZiVyiprFPqaoob63f8bSV3Ve8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":52627},"type":"module","engines":{"node":">=24"},"gitHead":"a9bbe2e996ba8838a96237966c460ece8c8bf9dd","scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -p tsconfig.build.json","check":"npm run format:check && npm run lint && npm run typecheck && npm run test:coverage && npm run bundle && npm run verify:package","bundle":"npm run build && npm run bundle:action","format":"prettier --write .","prepack":"npm run build","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","bundle:action":"ncc build src/action.ts -o dist/action --minify","test:coverage":"vitest run --coverage","prepublishOnly":"npm run check","verify:package":"node scripts/verify-package.mjs"},"_npmUser":{"name":"ahoooooo","email":"ahoooooooai@gmail.com"},"repository":{"url":"git+https://github.com/ahoooooooo/reviewready.git","type":"git"},"_npmVersion":"12.0.2","description":"Deterministic evidence checks before a pull request consumes human review time.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.4.3","yaml":"^2.9.0","micromatch":"^4.0.8","@actions/core":"^3.0.1","@actions/github":"^9.1.1"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.7.0","vitest":"^4.1.10","prettier":"^3.9.6","@eslint/js":"^10.0.1","typescript":"^6.0.3","@types/node":"^26.1.1","@vercel/ncc":"^0.44.1","@types/micromatch":"^4.0.10","typescript-eslint":"^8.65.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/reviewready_1.0.2_1786310487748_0.1505476568691726","host":"s3://npm-registry-packages-npm-production"}},"1.0.3":{"name":"@ahoooooo/reviewready","version":"1.0.3","keywords":["github-actions","pull-request","code-review","policy-as-code","developer-tools","open-source","ai-agents","cli"],"license":"MIT","_id":"@ahoooooo/reviewready@1.0.3","maintainers":[{"name":"ahoooooo","email":"ahoooooooai@gmail.com"}],"homepage":"https://github.com/ahoooooooo/reviewready#readme","bugs":{"url":"https://github.com/ahoooooooo/reviewready/issues"},"bin":{"reviewready":"dist/cli.js"},"dist":{"shasum":"849af4f87ad03db3b86cab5dc928db9208321212","tarball":"https://registry.npmjs.org/@ahoooooo/reviewready/-/reviewready-1.0.3.tgz","fileCount":28,"integrity":"sha512-DdNGVcObPX/BZDcvV7T1gUBMQDOCHx//iaWwS8fh2GIgscxZqU1oosL7+F1R1Bzj+OcHmd8vXiHk3I3u/mcHRQ==","signatures":[{"sig":"MEUCIC10Bvxb0M2t/tFVivNznmBL6ncdPVbFd9oInl4ZNXh0AiEAlKCiVIidWcznE+itHlJ8LRm7oE8iXMzs78Gi+KHBeWk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":58749},"type":"module","engines":{"node":">=22"},"gitHead":"14147f5d2084999065145f657ca36ac743e6151f","scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -p tsconfig.build.json","check":"npm run format:check && npm run lint && npm run typecheck && npm run test:coverage && npm run bundle && npm run verify:package","bundle":"npm run build && npm run bundle:action","format":"prettier --write .","prepack":"npm run build","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","bundle:action":"ncc build src/action.ts -o dist/action --minify","test:coverage":"vitest run --coverage","prepublishOnly":"npm run check","verify:package":"node scripts/verify-package.mjs"},"_npmUser":{"name":"ahoooooo","email":"ahoooooooai@gmail.com"},"repository":{"url":"git+https://github.com/ahoooooooo/reviewready.git","type":"git"},"_npmVersion":"12.0.2","description":"Deterministic evidence checks before a pull request consumes human review time.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.4.3","yaml":"^2.9.0","micromatch":"^4.0.8","@actions/core":"^3.0.1","@actions/github":"^9.1.1"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.7.0","vitest":"^4.1.10","prettier":"^3.9.6","@eslint/js":"^10.0.1","typescript":"^6.0.3","@types/node":"^26.1.1","@vercel/ncc":"^0.44.1","@types/micromatch":"^4.0.10","typescript-eslint":"^8.65.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/reviewready_1.0.3_1786345032110_0.8451446789333033","host":"s3://npm-registry-packages-npm-production"}},"1.0.4":{"name":"@ahoooooo/reviewready","version":"1.0.4","keywords":["github-actions","pull-request","code-review","policy-as-code","developer-tools","open-source","ai-agents","cli"],"license":"MIT","_id":"@ahoooooo/reviewready@1.0.4","maintainers":[{"name":"ahoooooo","email":"certify_provider375@simplelogin.com"}],"homepage":"https://github.com/ahoooooooo/reviewready#readme","bugs":{"url":"https://github.com/ahoooooooo/reviewready/issues"},"bin":{"reviewready":"dist/cli.js"},"dist":{"shasum":"7737facc197c48f127eb6087af1ff7e2bfec7098","tarball":"https://registry.npmjs.org/@ahoooooo/reviewready/-/reviewready-1.0.4.tgz","fileCount":46,"integrity":"sha512-Ts5698EQB6H2R32jR2RGfqSFbzgvDLeoOhgbUgOZEHRKZSf4j2JiaoKJZ6KQiXqZAcArphFyFLQy6tHJiKzzsA==","signatures":[{"sig":"MEUCIQCoqAFUS6QJ5M9Rk3LZ3M30mzxwmkM53InQc7aAL/zkoAIgM12KY9kIqZxXTv9Tejxg1aWxeIH41PTdez394DZqFXs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":210980},"type":"module","_from":"file:C:/Users/ASUS/AppData/Local/Temp/reviewready-release-publish-93586f06e7024b1b93d006c7b7319ccb/ahoooooo-reviewready-1.0.4.tgz","engines":{"node":">=22"},"scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -p tsconfig.build.json","check":"npm run format:check && npm run lint && npm run typecheck && npm run test:coverage && npm run bundle && npm run verify:package","bundle":"npm run build && npm run bundle:action","format":"prettier --write .","prepack":"npm run build","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","bundle:action":"ncc build src/action.ts -o dist/action --minify","test:coverage":"vitest run --coverage","prepublishOnly":"npm run check","verify:package":"node scripts/verify-package.mjs","release:preflight":"node scripts/release-preflight.mjs"},"_npmUser":{"name":"ahoooooo","email":"certify_provider375@simplelogin.com"},"_resolved":"C:\\Users\\ASUS\\AppData\\Local\\Temp\\reviewready-release-publish-93586f06e7024b1b93d006c7b7319ccb\\ahoooooo-reviewready-1.0.4.tgz","_integrity":"sha512-Ts5698EQB6H2R32jR2RGfqSFbzgvDLeoOhgbUgOZEHRKZSf4j2JiaoKJZ6KQiXqZAcArphFyFLQy6tHJiKzzsA==","repository":{"url":"git+https://github.com/ahoooooooo/reviewready.git","type":"git"},"_npmVersion":"12.0.2","description":"Deterministic evidence checks before a pull request consumes human review time.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.4.3","yaml":"^2.9.0","micromatch":"^4.0.8","@actions/core":"^3.0.1","@actions/github":"^9.1.1"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.7.0","vitest":"^4.1.10","prettier":"^3.9.6","@eslint/js":"^10.0.1","typescript":"^6.0.3","@types/node":"^26.1.1","@vercel/ncc":"^0.44.1","@types/micromatch":"^4.0.10","typescript-eslint":"^8.65.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/reviewready_1.0.4_1786480219291_0.1102994933169279","host":"s3://npm-registry-packages-npm-production"}},"1.0.5":{"name":"@ahoooooo/reviewready","version":"1.0.5","keywords":["github-actions","pull-request","code-review","policy-as-code","developer-tools","open-source","ai-agents","cli"],"license":"MIT","_id":"@ahoooooo/reviewready@1.0.5","maintainers":[{"name":"ahoooooo","email":"certify_provider375@simplelogin.com"}],"homepage":"https://github.com/ahoooooooo/reviewready#readme","bugs":{"url":"https://github.com/ahoooooooo/reviewready/issues"},"bin":{"reviewready":"dist/cli.js"},"dist":{"shasum":"3b163361d0a95b4e88883780534279f66d1990f8","tarball":"https://registry.npmjs.org/@ahoooooo/reviewready/-/reviewready-1.0.5.tgz","fileCount":50,"integrity":"sha512-2SmfXJwjf1GwH5pnAdoSsJ6s2g3oLyIBH8dUs6VmmUhAg8cqrZHSuZ2PoYlguHgvI6IFZZ+Fw0oZtkzYQ9JbLA==","signatures":[{"sig":"MEQCIFr63FLpX6L5+n1ilQbBRbkRZEfKYN/AzS3JWVmGF5UWAiBapT8AW7hwwGns6+FakRPJBtO8XiNaihnHIyFUsWlQeA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":229057},"type":"module","_from":"file:C:/Users/ASUS/AppData/Local/Temp/reviewready-publish-main-1b685663/ahoooooo-reviewready-1.0.5.tgz","engines":{"node":">=22"},"scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -p tsconfig.build.json","check":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run test:coverage && npm run verify:package","bundle":"npm run build && npm run bundle:action","format":"prettier --write .","prepack":"npm run build","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","bundle:action":"ncc build src/action.ts -o dist/action --minify --license licenses.txt","test:coverage":"vitest run --coverage","prepublishOnly":"npm run check","release:verify":"node scripts/release-preflight.mjs --provenance","verify:package":"node scripts/verify-package.mjs","release:preflight":"node scripts/release-preflight.mjs","audit:dependencies":"npm audit --audit-level=high"},"_npmUser":{"name":"ahoooooo","email":"certify_provider375@simplelogin.com"},"_resolved":"C:\\Users\\ASUS\\AppData\\Local\\Temp\\reviewready-publish-main-1b685663\\ahoooooo-reviewready-1.0.5.tgz","_integrity":"sha512-2SmfXJwjf1GwH5pnAdoSsJ6s2g3oLyIBH8dUs6VmmUhAg8cqrZHSuZ2PoYlguHgvI6IFZZ+Fw0oZtkzYQ9JbLA==","repository":{"url":"git+https://github.com/ahoooooooo/reviewready.git","type":"git"},"_npmVersion":"12.0.2","description":"Deterministic evidence checks before a pull request consumes human review time.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.4.3","yaml":"^2.9.0","micromatch":"^4.0.8","@actions/core":"^3.0.1","@actions/github":"^9.1.1"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.7.0","vitest":"^4.1.10","prettier":"^3.9.6","@eslint/js":"^10.0.1","typescript":"^6.0.3","@types/node":"^26.1.1","@vercel/ncc":"^0.44.1","@types/micromatch":"^4.0.10","typescript-eslint":"^8.65.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/reviewready_1.0.5_1786522656775_0.774218542297763","host":"s3://npm-registry-packages-npm-production"}},"1.0.6":{"name":"@ahoooooo/reviewready","version":"1.0.6","keywords":["github-actions","pull-request","code-review","policy-as-code","developer-tools","open-source","ai-agents","cli"],"license":"MIT","_id":"@ahoooooo/reviewready@1.0.6","maintainers":[{"name":"ahoooooo","email":"certify_provider375@simplelogin.com"}],"homepage":"https://github.com/ahoooooooo/reviewready#readme","bugs":{"url":"https://github.com/ahoooooooo/reviewready/issues"},"bin":{"reviewready":"dist/cli.js"},"dist":{"shasum":"53480590d40b254ef2d3eb22eca69918090154ef","tarball":"https://registry.npmjs.org/@ahoooooo/reviewready/-/reviewready-1.0.6.tgz","fileCount":50,"integrity":"sha512-QQK37eA2jJf+pdmkefEnfgzwi7yzHOPh2Sz9OWefihGRXcZVKHCceUiKoTFiqz6GUKjorGVY7P9EZzG0MRSHfQ==","signatures":[{"sig":"MEQCIFxvwY/oceWURKk/Aq9TL4WzipRvgvZwLR/UpFzajawHAiB+2K18zlfr7hFrw4N8hooSoFX3NiPxXFzHH6s0J2z+vw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@ahoooooo%2freviewready@1.0.6","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":243612},"type":"module","_from":"file:/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.6.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./package.json":"./package.json","./reviewready.schema.json":"./reviewready.schema.json","./reviewready.audit.schema.json":"./reviewready.audit.schema.json","./reviewready.result.schema.json":"./reviewready.result.schema.json"},"scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -p tsconfig.build.json","check":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run test:coverage && npm run verify:package && npm run package:smoke","bundle":"npm run build && npm run bundle:action","format":"prettier --write .","prepack":"npm run build","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","bundle:action":"ncc build src/action.ts -o dist/action --minify --license licenses.txt","package:smoke":"node scripts/package-smoke.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run check","release:verify":"node scripts/release-preflight.mjs --provenance","verify:package":"node scripts/verify-package.mjs","release:preflight":"node scripts/release-preflight.mjs","audit:dependencies":"npm audit --audit-level=high"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:12726dff-e865-4bbf-a6c1-a213c7609cb2"}},"_resolved":"/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.6.tgz","_integrity":"sha512-QQK37eA2jJf+pdmkefEnfgzwi7yzHOPh2Sz9OWefihGRXcZVKHCceUiKoTFiqz6GUKjorGVY7P9EZzG0MRSHfQ==","repository":{"url":"git+https://github.com/ahoooooooo/reviewready.git","type":"git"},"_npmVersion":"11.16.0","description":"Deterministic evidence checks before a pull request consumes human review time.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"4.4.3","yaml":"2.9.0","micromatch":"4.0.8","@actions/core":"3.0.1","@actions/github":"9.1.1"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.7.0","vitest":"^4.1.10","prettier":"^3.9.6","@eslint/js":"^10.0.1","typescript":"^6.0.3","@types/node":"^26.1.1","@vercel/ncc":"^0.44.1","@types/micromatch":"^4.0.10","typescript-eslint":"^8.65.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/reviewready_1.0.6_1786544050944_0.15255509322801952","host":"s3://npm-registry-packages-npm-production"}},"1.0.7":{"name":"@ahoooooo/reviewready","version":"1.0.7","keywords":["github-actions","pull-request","code-review","policy-as-code","developer-tools","open-source","ai-agents","cli"],"license":"MIT","_id":"@ahoooooo/reviewready@1.0.7","maintainers":[{"name":"ahoooooo","email":"certify_provider375@simplelogin.com"}],"homepage":"https://github.com/ahoooooooo/reviewready#readme","bugs":{"url":"https://github.com/ahoooooooo/reviewready/issues"},"bin":{"reviewready":"dist/cli.js"},"dist":{"shasum":"d82f119eb5775cbbede975fee35c9058ad5daa66","tarball":"https://registry.npmjs.org/@ahoooooo/reviewready/-/reviewready-1.0.7.tgz","fileCount":50,"integrity":"sha512-jfdaNA2RltDjCbYKtuNusPOKterX8Kzd8VxmN5HGCCSQp6HF9pxIEqoM+T/AfqjK6h/Rso6C5J+p+opYkStR1Q==","signatures":[{"sig":"MEQCIAOqwySuIr4BfgwvkNH+/SO9U7QE/t/xF6wzICMw2bmQAiAv92YnoqP2QhQCQVNalxIzCMQSEmoAq56I3NkrWaKRdg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@ahoooooo%2freviewready@1.0.7","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":243494},"type":"module","_from":"file:/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.7.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./package.json":"./package.json","./reviewready.schema.json":"./reviewready.schema.json","./reviewready.audit.schema.json":"./reviewready.audit.schema.json","./reviewready.result.schema.json":"./reviewready.result.schema.json"},"scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -p tsconfig.build.json","check":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run test:coverage && npm run verify:package && npm run package:smoke","bundle":"npm run build && npm run bundle:action","format":"prettier --write .","prepack":"npm run build","typecheck":"tsc --noEmit","test:watch":"vitest","format:check":"prettier --check .","bundle:action":"ncc build src/action.ts -o dist/action --minify --license licenses.txt","package:smoke":"node scripts/package-smoke.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run check","release:verify":"node scripts/release-preflight.mjs --provenance","verify:package":"node scripts/verify-package.mjs","release:preflight":"node scripts/release-preflight.mjs","audit:dependencies":"npm audit --audit-level=high"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:12726dff-e865-4bbf-a6c1-a213c7609cb2"}},"_resolved":"/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.7.tgz","_integrity":"sha512-jfdaNA2RltDjCbYKtuNusPOKterX8Kzd8VxmN5HGCCSQp6HF9pxIEqoM+T/AfqjK6h/Rso6C5J+p+opYkStR1Q==","repository":{"url":"git+https://github.com/ahoooooooo/reviewready.git","type":"git"},"_npmVersion":"11.17.0","description":"Deterministic evidence checks before a pull request consumes human review time.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"zod":"4.4.3","yaml":"2.9.0","micromatch":"4.0.8","@actions/core":"3.0.1","@actions/github":"9.1.1"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"^10.7.0","vitest":"^4.1.10","prettier":"^3.9.6","@eslint/js":"^10.0.1","typescript":"^6.0.3","@types/node":"^26.1.1","@vercel/ncc":"^0.44.1","@types/micromatch":"^4.0.10","typescript-eslint":"^8.65.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/reviewready_1.0.7_1786547900132_0.27611654211696046","host":"s3://npm-registry-packages-npm-production"}},"1.0.8":{"name":"@ahoooooo/reviewready","version":"1.0.8","keywords":["github-actions","pull-request","code-review","policy-as-code","developer-tools","open-source","ai-agents","cli"],"license":"MIT","_id":"@ahoooooo/reviewready@1.0.8","maintainers":[{"name":"ahoooooo","email":"certify_provider375@simplelogin.com"}],"homepage":"https://github.com/ahoooooooo/reviewready#readme","bugs":{"url":"https://github.com/ahoooooooo/reviewready/issues"},"bin":{"reviewready":"dist/cli.js"},"dist":{"shasum":"77c582370457093b48efdf517f940fc88c2624b6","tarball":"https://registry.npmjs.org/@ahoooooo/reviewready/-/reviewready-1.0.8.tgz","fileCount":57,"integrity":"sha512-V3Vwuqods3Pr87PaBTu2afhchdXDgT0iuz8khU8p6SVhzVC+WPGOobE/LZY88KE0FJlQK3ubVOYkkIKPtY3ngQ==","signatures":[{"sig":"MEUCIB5W6nLRyZ02cYD1wDJiUpBlocnIQJQxu95kkO26s3uxAiEA4t/2CTTw1duRUQ2pvS3Zi52Q3nmPXoB1TMxgPb8kI74=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@ahoooooo%2freviewready@1.0.8","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":503866},"type":"module","_from":"file:/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.8.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./package.json":"./package.json","./reviewready.schema.json":"./reviewready.schema.json","./reviewready.audit.schema.json":"./reviewready.audit.schema.json","./reviewready.result.schema.json":"./reviewready.result.schema.json","./reviewready.audit-evidence.schema.json":"./reviewready.audit-evidence.schema.json"},"scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -p tsconfig.build.json","check":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run verify:dist && npm run test:coverage && npm run verify:package && npm run package:smoke","bundle":"npm run build && npm run bundle:action","format":"prettier --write .","prepack":"npm run build","typecheck":"tsc --noEmit","test:watch":"vitest","verify:dist":"node scripts/verify-dist.mjs","check:compat":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run verify:dist && npm run test:coverage && npm run verify:package && npm run package:smoke","format:check":"prettier --check .","bundle:action":"ncc build src/action.ts -o dist/action --minify --license licenses.txt","package:smoke":"node scripts/package-smoke.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run check","release:verify":"node scripts/release-preflight.mjs --provenance","verify:package":"node scripts/verify-package.mjs","release:preflight":"node scripts/release-preflight.mjs","audit:dependencies":"npm audit --audit-level=high"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:12726dff-e865-4bbf-a6c1-a213c7609cb2"}},"_resolved":"/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.8.tgz","_integrity":"sha512-V3Vwuqods3Pr87PaBTu2afhchdXDgT0iuz8khU8p6SVhzVC+WPGOobE/LZY88KE0FJlQK3ubVOYkkIKPtY3ngQ==","repository":{"url":"git+https://github.com/ahoooooooo/reviewready.git","type":"git"},"_npmVersion":"11.17.0","description":"Deterministic evidence checks before a pull request consumes human review time.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"zod":"4.4.3","yaml":"2.9.0","micromatch":"4.0.8","@actions/core":"3.0.1","@actions/github":"9.1.1"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"8.20.0","eslint":"^10.7.0","vitest":"^4.1.10","prettier":"^3.9.6","@eslint/js":"^10.0.1","typescript":"^6.0.3","@types/node":"^26.1.1","@vercel/ncc":"^0.44.1","@types/micromatch":"^4.0.10","typescript-eslint":"^8.65.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/reviewready_1.0.8_1786806209641_0.8950574350092666","host":"s3://npm-registry-packages-npm-production"}},"1.0.9":{"name":"@ahoooooo/reviewready","version":"1.0.9","keywords":["github-actions","pull-request","code-review","policy-as-code","developer-tools","open-source","ai-agents","cli"],"license":"MIT","_id":"@ahoooooo/reviewready@1.0.9","maintainers":[{"name":"ahoooooo","email":"certify_provider375@simplelogin.com"}],"homepage":"https://github.com/ahoooooooo/reviewready#readme","bugs":{"url":"https://github.com/ahoooooooo/reviewready/issues"},"bin":{"reviewready":"dist/cli.js"},"dist":{"shasum":"26732f0c6e6976957ab43aad111da53b4885eac1","tarball":"https://registry.npmjs.org/@ahoooooo/reviewready/-/reviewready-1.0.9.tgz","fileCount":57,"integrity":"sha512-bEMkm6TX0Uqc9X/JC7OcZvWeZfKkae509tlw/GdL0dfnEWzZKDbBPC9zT5UXZfTzQ24MmF/4aBQOBinigkf96Q==","signatures":[{"sig":"MEYCIQDM+X6hEaNYl9CWiTlWMGpDjsXLUXKgjEiD5ZC3/9q4mQIhAP5kbwM8E3vcEmVI6Wp3aOJmhn4bSLZkOc8rnX6e9AHL","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@ahoooooo%2freviewready@1.0.9","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":504277},"type":"module","_from":"file:/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.9.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./package.json":"./package.json","./reviewready.schema.json":"./reviewready.schema.json","./reviewready.audit.schema.json":"./reviewready.audit.schema.json","./reviewready.result.schema.json":"./reviewready.result.schema.json","./reviewready.audit-evidence.schema.json":"./reviewready.audit-evidence.schema.json"},"scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -p tsconfig.build.json","check":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run verify:dist && npm run test:coverage && npm run verify:package && npm run package:smoke","bundle":"npm run build && npm run bundle:action","format":"prettier --write .","prepack":"npm run build","typecheck":"tsc --noEmit","test:watch":"vitest","verify:dist":"node scripts/verify-dist.mjs","check:compat":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run verify:dist && npm run test:coverage && npm run verify:package && npm run package:smoke","format:check":"prettier --check .","bundle:action":"ncc build src/action.ts -o dist/action --minify --license licenses.txt","package:smoke":"node scripts/package-smoke.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run check","release:verify":"node scripts/release-preflight.mjs --provenance","verify:package":"node scripts/verify-package.mjs","release:preflight":"node scripts/release-preflight.mjs","audit:dependencies":"npm audit --audit-level=high"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:12726dff-e865-4bbf-a6c1-a213c7609cb2"}},"_resolved":"/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.9.tgz","_integrity":"sha512-bEMkm6TX0Uqc9X/JC7OcZvWeZfKkae509tlw/GdL0dfnEWzZKDbBPC9zT5UXZfTzQ24MmF/4aBQOBinigkf96Q==","repository":{"url":"git+https://github.com/ahoooooooo/reviewready.git","type":"git"},"_npmVersion":"11.17.0","description":"Deterministic evidence checks before a pull request consumes human review time.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"zod":"4.4.3","yaml":"2.9.0","micromatch":"4.0.8","@actions/core":"3.0.1","@actions/github":"9.1.1"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"8.20.0","eslint":"^10.7.0","vitest":"^4.1.10","prettier":"^3.9.6","@eslint/js":"^10.0.1","typescript":"^6.0.3","@types/node":"^26.1.1","@vercel/ncc":"^0.44.1","@types/micromatch":"^4.0.10","typescript-eslint":"^8.65.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/reviewready_1.0.9_1786810202562_0.2697446412889932","host":"s3://npm-registry-packages-npm-production"}},"1.0.10":{"name":"@ahoooooo/reviewready","version":"1.0.10","keywords":["github-actions","pull-request","code-review","policy-as-code","developer-tools","open-source","ai-agents","cli"],"license":"MIT","_id":"@ahoooooo/reviewready@1.0.10","maintainers":[{"name":"ahoooooo","email":"certify_provider375@simplelogin.com"}],"homepage":"https://github.com/ahoooooooo/reviewready#readme","bugs":{"url":"https://github.com/ahoooooooo/reviewready/issues"},"bin":{"reviewready":"dist/cli.js"},"dist":{"shasum":"f1cb6622f375a228b9ac33ed8c804ed127ae3a7c","tarball":"https://registry.npmjs.org/@ahoooooo/reviewready/-/reviewready-1.0.10.tgz","fileCount":57,"integrity":"sha512-PLh5UIWOxeZ/OLntQYDUCXpFANLTMHyKfpPdl9+fcPaSL7pnIF7X/QFztM+6LHsw9aDcOFTEU9alL8gwEkZ3og==","signatures":[{"sig":"MEQCIEwY34Re2FPY/FXEcYBnij9u+lN+LOGksqY1MCzgHFWGAiAdgtXUmEhFNvgYldMfgkAp7LbtQ4v6Zmo4fThrnUchcA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@ahoooooo%2freviewready@1.0.10","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":504620},"type":"module","_from":"file:/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.10.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./package.json":"./package.json","./reviewready.schema.json":"./reviewready.schema.json","./reviewready.audit.schema.json":"./reviewready.audit.schema.json","./reviewready.result.schema.json":"./reviewready.result.schema.json","./reviewready.audit-evidence.schema.json":"./reviewready.audit-evidence.schema.json"},"scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -p tsconfig.build.json","check":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run verify:dist && npm run test:coverage && npm run verify:package && npm run package:smoke","bundle":"npm run build && npm run bundle:action","format":"prettier --write .","prepack":"npm run build","typecheck":"tsc --noEmit","test:watch":"vitest","verify:dist":"node scripts/verify-dist.mjs","check:compat":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run verify:dist && npm run test:coverage && npm run verify:package && npm run package:smoke","format:check":"prettier --check .","bundle:action":"ncc build src/action.ts -o dist/action --minify --license licenses.txt","package:smoke":"node scripts/package-smoke.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run check","release:verify":"node scripts/release-preflight.mjs --provenance","verify:package":"node scripts/verify-package.mjs","release:preflight":"node scripts/release-preflight.mjs","audit:dependencies":"npm audit --audit-level=high"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:12726dff-e865-4bbf-a6c1-a213c7609cb2"}},"_resolved":"/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.10.tgz","_integrity":"sha512-PLh5UIWOxeZ/OLntQYDUCXpFANLTMHyKfpPdl9+fcPaSL7pnIF7X/QFztM+6LHsw9aDcOFTEU9alL8gwEkZ3og==","repository":{"url":"git+https://github.com/ahoooooooo/reviewready.git","type":"git"},"_npmVersion":"11.17.0","description":"Deterministic evidence checks before a pull request consumes human review time.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"zod":"4.4.3","yaml":"2.9.0","micromatch":"4.0.8","@actions/core":"3.0.1","@actions/github":"9.1.1"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"8.20.0","eslint":"^10.7.0","vitest":"^4.1.10","prettier":"^3.9.6","@eslint/js":"^10.0.1","typescript":"^6.0.3","@types/node":"^26.1.1","@vercel/ncc":"^0.44.1","@types/micromatch":"^4.0.10","typescript-eslint":"^8.65.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/reviewready_1.0.10_1786813309940_0.2558083867166798","host":"s3://npm-registry-packages-npm-production"}},"1.0.11":{"name":"@ahoooooo/reviewready","version":"1.0.11","keywords":["github-actions","pull-request","code-review","policy-as-code","developer-tools","open-source","ai-agents","cli"],"license":"MIT","_id":"@ahoooooo/reviewready@1.0.11","maintainers":[{"name":"ahoooooo","email":"certify_provider375@simplelogin.com"}],"homepage":"https://github.com/ahoooooooo/reviewready#readme","bugs":{"url":"https://github.com/ahoooooooo/reviewready/issues"},"bin":{"reviewready":"dist/cli.js"},"dist":{"shasum":"679e81d27d129ba1a5d2ada97a1228a9e2bbd5ee","tarball":"https://registry.npmjs.org/@ahoooooo/reviewready/-/reviewready-1.0.11.tgz","fileCount":111,"integrity":"sha512-x70ceTgcISmjFS1MjPntORU9NVTyQW+EetS+Qj1gJNasATkzoQrWMI1kHzW3ALJGVnGRdUKOTAJPJPyThigZ6w==","signatures":[{"sig":"MEUCIAqffmdhyjuDnMM/qLpY+qqPbo6Tm0u4OB60ivppMOhIAiEAouUIdvrIPs4cqpWycrXr3TGLdYcEVib2lXnre7lvcbQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@ahoooooo%2freviewready@1.0.11","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":982750},"type":"module","_from":"file:/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.11.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./package.json":"./package.json","./reviewready.schema.json":"./reviewready.schema.json","./reviewready.audit.schema.json":"./reviewready.audit.schema.json","./reviewready.result.schema.json":"./reviewready.result.schema.json","./reviewready.audit-evidence.schema.json":"./reviewready.audit-evidence.schema.json"},"scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -p tsconfig.build.json","check":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run verify:dist && npm run test:coverage && npm run verify:package && npm run package:smoke","bundle":"npm run build && npm run bundle:action","format":"prettier --write .","prepack":"npm run build","typecheck":"tsc --noEmit","test:watch":"vitest","verify:dist":"node scripts/verify-dist.mjs","check:compat":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run verify:dist && npm run test:coverage && npm run verify:package && npm run package:smoke","format:check":"prettier --check .","bundle:action":"ncc build src/action.ts -o dist/action --minify --license licenses.txt","package:smoke":"node scripts/package-smoke.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run check","release:verify":"node scripts/release-preflight.mjs --provenance","verify:package":"node scripts/verify-package.mjs","release:preflight":"node scripts/release-preflight.mjs","audit:dependencies":"npm audit --audit-level=high"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:12726dff-e865-4bbf-a6c1-a213c7609cb2"}},"_resolved":"/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.11.tgz","_integrity":"sha512-x70ceTgcISmjFS1MjPntORU9NVTyQW+EetS+Qj1gJNasATkzoQrWMI1kHzW3ALJGVnGRdUKOTAJPJPyThigZ6w==","repository":{"url":"git+https://github.com/ahoooooooo/reviewready.git","type":"git"},"_npmVersion":"11.17.0","description":"Deterministic evidence checks before a pull request consumes human review time.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"zod":"4.4.3","yaml":"2.9.0","micromatch":"4.0.8","@actions/core":"3.0.1","@actions/github":"9.1.1"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"8.20.0","eslint":"^10.7.0","vitest":"^4.1.10","prettier":"^3.9.6","@eslint/js":"^10.0.1","typescript":"^6.0.3","@types/node":"^26.1.1","@vercel/ncc":"^0.44.1","@types/micromatch":"^4.0.10","typescript-eslint":"^8.65.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/reviewready_1.0.11_1786960553967_0.6092981497817351","host":"s3://npm-registry-packages-npm-production"}},"1.0.12":{"name":"@ahoooooo/reviewready","version":"1.0.12","keywords":["github-actions","pull-request","code-review","policy-as-code","developer-tools","open-source","ai-agents","cli"],"license":"MIT","_id":"@ahoooooo/reviewready@1.0.12","maintainers":[{"name":"ahoooooo","email":"certify_provider375@simplelogin.com"}],"homepage":"https://github.com/ahoooooooo/reviewready#readme","bugs":{"url":"https://github.com/ahoooooooo/reviewready/issues"},"bin":{"reviewready":"dist/cli.js"},"dist":{"shasum":"fdfdac852ee829452a6cd28d0a96fa757f8a625b","tarball":"https://registry.npmjs.org/@ahoooooo/reviewready/-/reviewready-1.0.12.tgz","fileCount":111,"integrity":"sha512-SYVi/J32lc9cWVzUJY6gvDuybZzSdFHpUFNQOFRCJLHSie9NszwqXxp/wRYg4tLXSDm1xD1nEU/+2+bb3J+u+w==","signatures":[{"sig":"MEUCIAd55jaYnKtsvY9NXCJe4vqIhmu9YSMWRSCoioCJApPsAiEA245W0XJE4+ufuHobXKg633dV1AK6uB386WtqmaeldS0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@ahoooooo%2freviewready@1.0.12","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":984558},"type":"module","_from":"file:/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.12.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./package.json":"./package.json","./reviewready.schema.json":"./reviewready.schema.json","./reviewready.audit.schema.json":"./reviewready.audit.schema.json","./reviewready.result.schema.json":"./reviewready.result.schema.json","./reviewready.audit-evidence.schema.json":"./reviewready.audit-evidence.schema.json"},"scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -p tsconfig.build.json","check":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run verify:dist && npm run test:coverage && npm run verify:package && npm run package:smoke","bundle":"npm run build && npm run bundle:action","format":"prettier --write .","prepack":"npm run build","typecheck":"tsc --noEmit","test:watch":"vitest","verify:dist":"node scripts/verify-dist.mjs","check:compat":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run verify:dist && npm run test:coverage && npm run verify:package && npm run package:smoke","format:check":"prettier --check .","bundle:action":"ncc build src/action.ts -o dist/action --minify --license licenses.txt","package:smoke":"node scripts/package-smoke.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run check","release:verify":"node scripts/release-preflight.mjs --provenance","test:promotion":"vitest run --config vitest.promotion.config.ts --configLoader runner","verify:package":"node scripts/verify-package.mjs","release:preflight":"node scripts/release-preflight.mjs","audit:dependencies":"npm audit --audit-level=high"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:12726dff-e865-4bbf-a6c1-a213c7609cb2"}},"_resolved":"/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.12.tgz","_integrity":"sha512-SYVi/J32lc9cWVzUJY6gvDuybZzSdFHpUFNQOFRCJLHSie9NszwqXxp/wRYg4tLXSDm1xD1nEU/+2+bb3J+u+w==","repository":{"url":"git+https://github.com/ahoooooooo/reviewready.git","type":"git"},"_npmVersion":"11.17.0","description":"Deterministic evidence checks before a pull request consumes human review time.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"zod":"4.4.3","yaml":"2.9.0","micromatch":"4.0.8","@actions/core":"3.0.1","@actions/github":"9.1.1"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"8.20.0","eslint":"^10.7.0","vitest":"^4.1.10","prettier":"^3.9.6","@eslint/js":"^10.0.1","typescript":"^6.0.3","@types/node":"^26.1.1","@vercel/ncc":"^0.44.1","@types/micromatch":"^4.0.10","typescript-eslint":"^8.65.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/reviewready_1.0.12_1787648428828_0.08273819247020886","host":"s3://npm-registry-packages-npm-production"}},"1.0.13":{"name":"@ahoooooo/reviewready","version":"1.0.13","keywords":["github-actions","pull-request","code-review","policy-as-code","developer-tools","open-source","ai-agents","cli"],"license":"MIT","_id":"@ahoooooo/reviewready@1.0.13","maintainers":[{"name":"ahoooooo","email":"certify_provider375@simplelogin.com"}],"homepage":"https://github.com/ahoooooooo/reviewready#readme","bugs":{"url":"https://github.com/ahoooooooo/reviewready/issues"},"bin":{"reviewready":"dist/cli.js"},"dist":{"shasum":"eecd04532ed3090bcd1083d3238f41eced8b3933","tarball":"https://registry.npmjs.org/@ahoooooo/reviewready/-/reviewready-1.0.13.tgz","fileCount":111,"integrity":"sha512-B0aPJkuKs6JX++HY/j4W+ofdJVgCmCwMRD3T8h9nYzcs5DR29Jc77SphEnVTLOyBNjMQz8aY6WkzNDrloidwNA==","signatures":[{"sig":"MEUCIApOazDs9KlbLUf84Pz81TVcJo097Xma2cQuOc0r1EGtAiEAiYzf50LucSu6/IEioQYYc3+IK5D7Vl3uxYQZA4RdsEo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@ahoooooo%2freviewready@1.0.13","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":984493},"type":"module","_from":"file:/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.13.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./package.json":"./package.json","./reviewready.schema.json":"./reviewready.schema.json","./reviewready.audit.schema.json":"./reviewready.audit.schema.json","./reviewready.result.schema.json":"./reviewready.result.schema.json","./reviewready.audit-evidence.schema.json":"./reviewready.audit-evidence.schema.json"},"scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -p tsconfig.build.json","check":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run verify:dist && npm run test:coverage && npm run verify:package && npm run package:smoke","bundle":"npm run build && npm run bundle:action","format":"prettier --write .","prepack":"npm run build","typecheck":"tsc --noEmit","test:watch":"vitest","verify:dist":"node scripts/verify-dist.mjs","check:compat":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run verify:dist && npm run test:coverage && npm run verify:package && npm run package:smoke","format:check":"prettier --check .","bundle:action":"ncc build src/action.ts -o dist/action --minify --license licenses.txt","package:smoke":"node scripts/package-smoke.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run check","release:verify":"node scripts/release-preflight.mjs --provenance","test:promotion":"vitest run --config vitest.promotion.config.ts --configLoader runner","verify:package":"node scripts/verify-package.mjs","release:preflight":"node scripts/release-preflight.mjs","audit:dependencies":"npm audit --audit-level=high"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:12726dff-e865-4bbf-a6c1-a213c7609cb2"}},"_resolved":"/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.13.tgz","_integrity":"sha512-B0aPJkuKs6JX++HY/j4W+ofdJVgCmCwMRD3T8h9nYzcs5DR29Jc77SphEnVTLOyBNjMQz8aY6WkzNDrloidwNA==","repository":{"url":"git+https://github.com/ahoooooooo/reviewready.git","type":"git"},"_npmVersion":"11.17.0","description":"Deterministic evidence checks before a pull request consumes human review time.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"zod":"4.4.3","yaml":"2.9.0","micromatch":"4.0.8","@actions/core":"3.0.1","@actions/github":"9.1.1"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"8.20.0","eslint":"^10.7.0","vitest":"^4.1.10","prettier":"^3.9.6","@eslint/js":"^10.0.1","typescript":"^6.0.3","@types/node":"^26.1.1","@vercel/ncc":"^0.44.1","@types/micromatch":"^4.0.10","typescript-eslint":"^8.65.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/reviewready_1.0.13_1787661187392_0.9934280175840411","host":"s3://npm-registry-packages-npm-production"}},"1.0.14":{"name":"@ahoooooo/reviewready","version":"1.0.14","keywords":["github-actions","pull-request","code-review","reviewready-evidence-protocol","trusted-review-intake","evidence-admission","policy-as-code","developer-tools","open-source","ai-agents","cli"],"license":"MIT","_id":"@ahoooooo/reviewready@1.0.14","maintainers":[{"name":"ahoooooo","email":"certify_provider375@simplelogin.com"}],"homepage":"https://github.com/ahoooooooo/reviewready#readme","bugs":{"url":"https://github.com/ahoooooooo/reviewready/issues"},"bin":{"reviewready":"dist/cli.js"},"dist":{"shasum":"4b87b8bd99bfd5932bce68a98aad71f0d5efa5f4","tarball":"https://registry.npmjs.org/@ahoooooo/reviewready/-/reviewready-1.0.14.tgz","fileCount":111,"integrity":"sha512-aMxtxzHtURg6QAo8g2QWy87mW6tqBkvo11nhJE64hTKb1I+QaCRnw4aYbumkSyXFqQdOzWmjhQ3Ia4VGyNua6A==","signatures":[{"sig":"MEQCIAQxuMLOMR2mvAehG7kjIx3CXB82wrYiFCZEP4eaJOioAiBL8P4CKiRHo/J4CR4dhv8GWxvCG7XbCOhOCBrsRj4vCA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@ahoooooo%2freviewready@1.0.14","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":987940},"type":"module","_from":"file:/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.14.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./package.json":"./package.json","./reviewready.schema.json":"./reviewready.schema.json","./reviewready.audit.schema.json":"./reviewready.audit.schema.json","./reviewready.result.schema.json":"./reviewready.result.schema.json","./reviewready.audit-evidence.schema.json":"./reviewready.audit-evidence.schema.json"},"scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -p tsconfig.build.json","check":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run verify:dist && npm run test:coverage && npm run verify:package && npm run verify:public-baseline && npm run package:smoke","bundle":"npm run build && npm run bundle:action","format":"prettier --write .","prepack":"npm run build","typecheck":"tsc --noEmit","test:watch":"vitest","verify:dist":"node scripts/verify-dist.mjs","check:compat":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run verify:dist && npm run test:coverage && npm run verify:package && npm run verify:public-baseline && npm run package:smoke","format:check":"prettier --check .","bundle:action":"ncc build src/action.ts -o dist/action --minify --license licenses.txt","package:smoke":"node scripts/package-smoke.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run check","release:verify":"node scripts/release-preflight.mjs --provenance","test:promotion":"vitest run --config vitest.promotion.config.ts --configLoader runner","verify:package":"node scripts/verify-package.mjs","release:preflight":"node scripts/release-preflight.mjs","audit:dependencies":"npm audit --audit-level=high","verify:public-baseline":"node scripts/verify-public-baseline.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:12726dff-e865-4bbf-a6c1-a213c7609cb2"}},"_resolved":"/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.14.tgz","overrides":{"fast-uri":"3.1.7"},"_integrity":"sha512-aMxtxzHtURg6QAo8g2QWy87mW6tqBkvo11nhJE64hTKb1I+QaCRnw4aYbumkSyXFqQdOzWmjhQ3Ia4VGyNua6A==","repository":{"url":"git+https://github.com/ahoooooooo/reviewready.git","type":"git"},"_npmVersion":"11.17.0","description":"ReviewReady Evidence Protocol: deterministic trusted review intake before human or AI review.","directories":{},"_nodeVersion":"24.19.0","dependencies":{"zod":"4.4.3","yaml":"2.9.0","micromatch":"4.0.8","@actions/core":"3.0.1","@actions/github":"9.1.1"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"8.20.0","eslint":"^10.7.0","vitest":"^4.1.10","prettier":"^3.9.6","@eslint/js":"^10.0.1","typescript":"^6.0.3","@types/node":"^26.1.1","@vercel/ncc":"^0.44.1","@types/micromatch":"^4.0.10","typescript-eslint":"^8.65.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/reviewready_1.0.14_1788505095934_0.7561929354667483","host":"s3://npm-registry-packages-npm-production"}},"1.0.15":{"name":"@ahoooooo/reviewready","version":"1.0.15","keywords":["github-actions","pull-request","code-review","reviewready-evidence-protocol","trusted-review-intake","evidence-admission","policy-as-code","developer-tools","open-source","ai-agents","cli"],"license":"MIT","_id":"@ahoooooo/reviewready@1.0.15","maintainers":[{"name":"ahoooooo","email":"certify_provider375@simplelogin.com"}],"homepage":"https://github.com/ahoooooooo/reviewready#readme","bugs":{"url":"https://github.com/ahoooooooo/reviewready/issues"},"bin":{"reviewready":"dist/cli.js"},"dist":{"shasum":"50d1788069418447566c9722cb26b02fabea1388","tarball":"https://registry.npmjs.org/@ahoooooo/reviewready/-/reviewready-1.0.15.tgz","fileCount":111,"integrity":"sha512-H8WbnESHM4HcRWR7ZuTWYEUb8AQ05VvJg2cfGFYB+lCvBCgZ/HYND+8qQ+jqOyqHQ2oeRO4OtAoDegSNAuZ77Q==","signatures":[{"sig":"MEUCIADb7505k+OQeTJuXbNxe+u01bQU7rjfC/3hYdnRZwPdAiEAubVJoDPEQIDNvODLxhE87lK+1v/lKiroTC2Z6q5nNdg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@ahoooooo%2freviewready@1.0.15","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1046357},"type":"module","_from":"file:/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.15.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./package.json":"./package.json","./reviewready.schema.json":"./reviewready.schema.json","./reviewready.audit.schema.json":"./reviewready.audit.schema.json","./reviewready.result.schema.json":"./reviewready.result.schema.json","./reviewready.audit-evidence.schema.json":"./reviewready.audit-evidence.schema.json"},"scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -p tsconfig.build.json","check":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run verify:dist && npm run test:coverage && npm run verify:package && npm run verify:public-baseline && npm run package:smoke","bundle":"npm run build && npm run bundle:action","format":"prettier --write .","prepack":"npm run build","typecheck":"tsc --noEmit","test:watch":"vitest","verify:dist":"node scripts/verify-dist.mjs","check:compat":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run verify:dist && npm run test:coverage && npm run verify:package && npm run verify:public-baseline && npm run package:smoke","format:check":"prettier --check .","bundle:action":"ncc build src/action.ts -o dist/action --minify --license licenses.txt","package:smoke":"node scripts/package-smoke.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run check","release:verify":"node scripts/release-preflight.mjs --provenance","test:promotion":"vitest run --config vitest.promotion.config.ts --configLoader runner","verify:package":"node scripts/verify-package.mjs","release:preflight":"node scripts/release-preflight.mjs","audit:dependencies":"npm audit --audit-level=high","verify:public-baseline":"node scripts/verify-public-baseline.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:12726dff-e865-4bbf-a6c1-a213c7609cb2"}},"_resolved":"/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.15.tgz","overrides":{"fast-uri":"3.1.7"},"_integrity":"sha512-H8WbnESHM4HcRWR7ZuTWYEUb8AQ05VvJg2cfGFYB+lCvBCgZ/HYND+8qQ+jqOyqHQ2oeRO4OtAoDegSNAuZ77Q==","repository":{"url":"git+https://github.com/ahoooooooo/reviewready.git","type":"git"},"_npmVersion":"11.19.0","description":"ReviewReady Evidence Protocol: deterministic trusted review intake before human or AI review.","directories":{},"_nodeVersion":"24.20.0","dependencies":{"zod":"4.5.4","yaml":"2.9.0","micromatch":"4.0.8","@actions/core":"3.0.1","@actions/github":"9.1.1"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"8.20.0","eslint":"^10.7.0","vitest":"^4.1.10","prettier":"^3.9.6","@eslint/js":"^10.0.1","typescript":"^6.0.3","@types/node":"^26.1.1","@vercel/ncc":"^0.45.0","@types/micromatch":"^4.0.10","typescript-eslint":"^8.65.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/reviewready_1.0.15_1788836820568_0.9602305533832531","host":"s3://npm-registry-packages-npm-production"}},"1.0.16":{"name":"@ahoooooo/reviewready","version":"1.0.16","keywords":["github-actions","pull-request","code-review","reviewready-evidence-protocol","trusted-review-intake","evidence-admission","policy-as-code","developer-tools","open-source","ai-agents","cli"],"license":"MIT","_id":"@ahoooooo/reviewready@1.0.16","maintainers":[{"name":"ahoooooo","email":"certify_provider375@simplelogin.com"}],"homepage":"https://github.com/ahoooooooo/reviewready#readme","bugs":{"url":"https://github.com/ahoooooooo/reviewready/issues"},"bin":{"reviewready":"dist/cli.js"},"dist":{"shasum":"e54b9503093f5777b93772b33899abad146599b6","tarball":"https://registry.npmjs.org/@ahoooooo/reviewready/-/reviewready-1.0.16.tgz","fileCount":111,"integrity":"sha512-XBvVkApZkQVinlvo/J5lQpERRO0slj57G+KnW84EpnBFMDBrka2kV+hbFQt4oUQpbBAcu+fBz/35HXFCnVOPQw==","signatures":[{"sig":"MEUCIGFByd+g5UNiSha2hUMlgfXoDpoPS36kmmjW5dAXyGpeAiEAkShLn3Pk+IcZl2lX8cUtpPuqz7n7W/my3it3P9zTlOk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@ahoooooo%2freviewready@1.0.16","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1046350},"type":"module","_from":"file:/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.16.tgz","engines":{"node":">=22"},"exports":{".":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./package.json":"./package.json","./reviewready.schema.json":"./reviewready.schema.json","./reviewready.audit.schema.json":"./reviewready.audit.schema.json","./reviewready.result.schema.json":"./reviewready.result.schema.json","./reviewready.audit-evidence.schema.json":"./reviewready.audit-evidence.schema.json"},"scripts":{"lint":"eslint .","test":"vitest run","build":"tsc -p tsconfig.build.json","check":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run verify:dist && npm run test:coverage && npm run verify:package && npm run verify:public-baseline && npm run package:smoke","bundle":"npm run build && npm run bundle:action","format":"prettier --write .","prepack":"npm run build","typecheck":"tsc --noEmit","test:watch":"vitest","verify:dist":"node scripts/verify-dist.mjs","check:compat":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run verify:dist && npm run test:coverage && npm run verify:package && npm run verify:public-baseline && npm run package:smoke","format:check":"prettier --check .","bundle:action":"ncc build src/action.ts -o dist/action --minify --license licenses.txt","package:smoke":"node scripts/package-smoke.mjs","test:coverage":"vitest run --coverage","prepublishOnly":"npm run check","release:verify":"node scripts/release-preflight.mjs --provenance","test:promotion":"vitest run --config vitest.promotion.config.ts --configLoader runner","verify:package":"node scripts/verify-package.mjs","release:preflight":"node scripts/release-preflight.mjs","audit:dependencies":"npm audit --audit-level=high","verify:public-baseline":"node scripts/verify-public-baseline.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:12726dff-e865-4bbf-a6c1-a213c7609cb2"}},"_resolved":"/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.16.tgz","overrides":{"fast-uri":"3.1.7"},"_integrity":"sha512-XBvVkApZkQVinlvo/J5lQpERRO0slj57G+KnW84EpnBFMDBrka2kV+hbFQt4oUQpbBAcu+fBz/35HXFCnVOPQw==","repository":{"url":"git+https://github.com/ahoooooooo/reviewready.git","type":"git"},"_npmVersion":"11.19.0","description":"ReviewReady Evidence Protocol: deterministic trusted review intake before human or AI review.","directories":{},"_nodeVersion":"24.20.0","dependencies":{"zod":"4.5.4","yaml":"2.9.0","micromatch":"4.0.8","@actions/core":"3.0.1","@actions/github":"9.1.1"},"publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"8.20.0","eslint":"^10.7.0","vitest":"^4.1.10","prettier":"^3.9.6","@eslint/js":"^10.0.1","typescript":"^6.0.3","@types/node":"^26.1.1","@vercel/ncc":"^0.45.0","@types/micromatch":"^4.0.10","typescript-eslint":"^8.65.0","@vitest/coverage-v8":"^4.1.10"},"_npmOperationalInternal":{"tmp":"tmp/reviewready_1.0.16_1788845510181_0.9766220419269902","host":"s3://npm-registry-packages-npm-production"}},"1.0.17":{"name":"@ahoooooo/reviewready","version":"1.0.17","description":"ReviewReady Evidence Protocol: deterministic trusted review intake before human or AI review.","homepage":"https://github.com/ahoooooooo/reviewready#readme","bugs":{"url":"https://github.com/ahoooooooo/reviewready/issues"},"repository":{"type":"git","url":"git+https://github.com/ahoooooooo/reviewready.git"},"type":"module","license":"MIT","publishConfig":{"access":"public","registry":"https://registry.npmjs.org"},"keywords":["github-actions","pull-request","code-review","reviewready-evidence-protocol","trusted-review-intake","evidence-admission","policy-as-code","developer-tools","open-source","ai-agents","cli"],"engines":{"node":">=22"},"bin":{"reviewready":"dist/cli.js"},"exports":{".":{"types":"./dist/cli.d.ts","default":"./dist/cli.js"},"./package.json":"./package.json","./reviewready.schema.json":"./reviewready.schema.json","./reviewready.audit.schema.json":"./reviewready.audit.schema.json","./reviewready.audit-evidence.schema.json":"./reviewready.audit-evidence.schema.json","./reviewready.result.schema.json":"./reviewready.result.schema.json"},"scripts":{"build":"tsc -p tsconfig.build.json","bundle:action":"ncc build src/action.ts -o dist/action --minify --license licenses.txt","bundle":"npm run build && npm run bundle:action","test":"vitest run","test:coverage":"vitest run --coverage","test:promotion":"vitest run --config vitest.promotion.config.ts --configLoader runner","test:watch":"vitest","typecheck":"tsc --noEmit","lint":"eslint .","format:check":"prettier --check .","format":"prettier --write .","audit:dependencies":"npm audit --audit-level=high","verify:package":"node scripts/verify-package.mjs","verify:dist":"node scripts/verify-dist.mjs","verify:markdown-bounds":"node scripts/verify-markdown-bounds.mjs","verify:public-baseline":"node scripts/verify-public-baseline.mjs","package:smoke":"node scripts/package-smoke.mjs","release:preflight":"node scripts/release-preflight.mjs","release:verify":"node scripts/release-preflight.mjs --provenance","check":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run verify:markdown-bounds && npm run verify:dist && npm run test:coverage && npm run verify:package && npm run verify:public-baseline && npm run package:smoke","check:compat":"npm run format:check && npm run lint && npm run typecheck && npm run bundle && npm run verify:markdown-bounds && npm run verify:dist && npm run test:coverage && npm run verify:package && npm run verify:public-baseline && npm run package:smoke","prepublishOnly":"npm run check","prepack":"npm run build"},"dependencies":{"@actions/core":"3.0.1","@actions/github":"9.1.1","micromatch":"4.0.8","yaml":"2.9.0","zod":"4.5.4"},"devDependencies":{"@eslint/js":"^10.0.1","@types/micromatch":"^4.0.10","@types/node":"^26.1.1","@vercel/ncc":"^0.45.0","@vitest/coverage-v8":"^4.1.10","ajv":"8.20.0","eslint":"^10.7.0","prettier":"^3.9.6","typescript":"^6.0.3","typescript-eslint":"^8.65.0","vitest":"^4.1.10"},"overrides":{"fast-uri":"3.1.7"},"_id":"@ahoooooo/reviewready@1.0.17","_integrity":"sha512-pRsAAFQh+kd0ELF3E5BEwFO+ZhfR2vPWi/+V5ABaI/nWheYhfktqA+EQYssME+V0pyloYqaNI8KhBpUy4ju0qQ==","_resolved":"/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.17.tgz","_from":"file:/home/runner/work/_temp/reviewready-release/ahoooooo-reviewready-1.0.17.tgz","_nodeVersion":"24.20.0","_npmVersion":"11.19.0","dist":{"integrity":"sha512-pRsAAFQh+kd0ELF3E5BEwFO+ZhfR2vPWi/+V5ABaI/nWheYhfktqA+EQYssME+V0pyloYqaNI8KhBpUy4ju0qQ==","shasum":"285a49b09d11c95354b1e2d818cc190c46a5dbdb","tarball":"https://registry.npmjs.org/@ahoooooo/reviewready/-/reviewready-1.0.17.tgz","fileCount":111,"unpackedSize":1054523,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@ahoooooo%2freviewready@1.0.17","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCID9py/uEg2KKUbami36NdKnyRhcV7MLvWUXTkB9mvcm9AiAAg42iEZUgq9EnwES2yGeMBK4Y1zdaYlSccxlURdvCOQ=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:12726dff-e865-4bbf-a6c1-a213c7609cb2"}},"directories":{},"maintainers":[{"name":"ahoooooo","email":"certify_provider375@simplelogin.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/reviewready_1.0.17_1788867048470_0.2642460591281315"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-09T21:21:27.552Z","modified":"2026-09-08T11:30:48.893Z","1.0.0":"2026-07-21T22:00:11.728Z","1.0.1":"2026-07-22T01:29:17.637Z","1.0.2":"2026-08-09T21:21:27.880Z","1.0.3":"2026-08-10T06:57:12.263Z","1.0.4":"2026-08-11T20:30:19.431Z","1.0.5":"2026-08-12T08:17:36.911Z","1.0.6":"2026-08-12T14:14:11.099Z","1.0.7":"2026-08-12T15:18:20.287Z","1.0.8":"2026-08-15T15:03:29.793Z","1.0.9":"2026-08-15T16:10:02.744Z","1.0.10":"2026-08-15T17:01:50.078Z","1.0.11":"2026-08-17T09:55:54.132Z","1.0.12":"2026-08-25T09:00:28.968Z","1.0.13":"2026-08-25T12:33:07.557Z","1.0.14":"2026-09-04T06:58:16.078Z","1.0.15":"2026-09-08T03:07:00.708Z","1.0.16":"2026-09-08T05:31:50.364Z","1.0.17":"2026-09-08T11:30:48.604Z"},"bugs":{"url":"https://github.com/ahoooooooo/reviewready/issues"},"license":"MIT","homepage":"https://github.com/ahoooooooo/reviewready#readme","keywords":["github-actions","pull-request","code-review","reviewready-evidence-protocol","trusted-review-intake","evidence-admission","policy-as-code","developer-tools","open-source","ai-agents","cli"],"repository":{"type":"git","url":"git+https://github.com/ahoooooooo/reviewready.git"},"description":"ReviewReady Evidence Protocol: deterministic trusted review intake before human or AI review.","maintainers":[{"name":"ahoooooo","email":"certify_provider375@simplelogin.com"}],"readme":"# ReviewReady\n\n**ReviewReady Evidence Protocol** — Trusted Review Intake for pull requests.\n\n[![CI](https://github.com/ahoooooooo/reviewready/actions/workflows/ci.yml/badge.svg)](https://github.com/ahoooooooo/reviewready/actions/workflows/ci.yml)\n[![npm version](https://img.shields.io/npm/v/%40ahoooooo%2Freviewready.svg)](https://www.npmjs.com/package/@ahoooooo/reviewready)\n[![npm downloads](https://img.shields.io/npm/dm/%40ahoooooo%2Freviewready.svg)](https://www.npmjs.com/package/@ahoooooo/reviewready)\n[![license: MIT](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE)\n\nReviewReady is the open-source implementation of the ReviewReady Evidence\nProtocol: a deterministic Trusted Review Intake layer for pull requests. A\nrepository declares what must be present before a particular kind of change\nconsumes human review time; ReviewReady reports what is verified and what is\nstill missing. The protocol name describes the public evidence contracts and\ntrust boundaries; it does not imply a hosted service or an authoritative merge\nprovider.\n\nIt answers one narrow question:\n\n> Does this pull request contain the evidence required to begin human review?\n\nIt does **not** review code, establish correctness, detect AI authorship, approve,\nor merge. There are no model calls, hosted service, database, or execution of\npull-request code.\n\n## Current status\n\nPackage version: `1.0.17`.\n\nVerified Action examples: `v1.0.17`.\n\nThe exact stable release coordinates, immutable source commit, stable Action\ntag, npm package, and source-versus-release policy are recorded in the [public\nbaseline](https://github.com/ahoooooooo/reviewready/blob/main/docs/public-baseline.md)\nand its [machine-readable record](https://github.com/ahoooooooo/reviewready/blob/main/docs/public-baseline.json).\n\nA source checkout can be ahead of the latest published artifact while a new\nrelease is prepared. The package version identifies this README's source or\npackaged version; it does not establish publication. Action and schema examples\nuse that same semantic-version coordinate. A checkout must not be represented as\na published tarball without the protected workflow's exact artifact, registry, provenance, and\nrelease evidence. Immutable release artifacts and historical commits are not\nrewritten.\n\nThe npm registry and GitHub Releases are authoritative for current public\nrelease coordinates. Versioned release evidence is recorded in\ndocs/release-evidence-vX.Y.Z.md and the corresponding machine-readable record\nwhen available. Publication, provenance, immutable tags, and stable refs are\ncreated only by the protected workflow; a source tree does not substitute for\nregistry and release evidence.\n\nA normal `pull_request` workflow remains advisory because the contribution can\nmodify the merge-ref workflow that evaluates it. Loading policy contents from\nthe base SHA does not by itself protect the caller workflow, Action pin, or\n`policy-path`. The checked-in trusted reference uses a metadata-only\n`pull_request_target` workflow pinned to the exact stable release commit recorded\nin the public baseline, but a\nGitHub required check still does not uniquely identify one workflow definition\nor event. This repository does not provide a production GitHub App or an\nexternal enforcement service. The checked-in trusted workflow is a\nmetadata-only reference and remains advisory; authoritative merge enforcement\nmust be provided and independently protected by the adopting repository's\nGitHub configuration. A successful named check is not a claim that ReviewReady\nis a unique enforcement provider.\n\nThe package includes bounded `audit collect` and offline `audit replay`\nevidence-bundle commands. Live audit collection fails closed when repository\ngovernance is unavailable, contradictory, or uses semantics the normalized\ncontract cannot represent; an incomplete audit is not a readiness result or a\nworkflow-authority claim. [SECURITY.md](https://github.com/ahoooooooo/reviewready/blob/main/SECURITY.md) lists the durable boundary\nand current limitations. Published package bytes and historical releases are not\nrewritten when repository documentation advances.\n\nLive backlog, pull requests, branches, commit verification, and release\nfreshness are provider state and are intentionally linked rather than frozen as\nstale counts: [issues](https://github.com/ahoooooooo/reviewready/issues),\n[pull requests](https://github.com/ahoooooooo/reviewready/pulls),\n[branches](https://github.com/ahoooooooo/reviewready/branches),\n[main commits](https://github.com/ahoooooooo/reviewready/commits/main), and\n[releases](https://github.com/ahoooooooo/reviewready/releases).\n\n## Capability and authority boundaries\n\n| Public entry        | Shipped capability                                                                                 | Authority and permission boundary                                                                                                    |\n| ------------------- | -------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------ |\n| GitHub Action       | Evaluates bounded pull-request evidence and emits `ready` or `not_ready`.                          | Advisory, read-only GitHub access; it is not a unique issuer or merge authority.                                                     |\n| CLI                 | Validates policies, evaluates normalized fixtures, and collects or replays bounded audit evidence. | Local and read-only; live collection reads only a caller-named environment variable and does not mutate GitHub.                      |\n| npm/library         | Exposes the CLI entry point and versioned schema files.                                            | The bundled App, webhook, and ingress modules are contracts/internal implementation, not a hosted service or supported provider SDK. |\n| GitHub App/provider | Not shipped in this repository.                                                                    | No production App, durable external store, external enforcement service, or external adoption claim is included.                     |\n\nThe [public baseline](https://github.com/ahoooooooo/reviewready/blob/main/docs/public-baseline.md) is the canonical summary of\nthese capabilities, live-status links, release coordinates, and deliberately\nunshipped work.\n\n## Quick start\n\nInstall the CLI from npm. Node.js 22 or newer is required:\n\n```console\nnpm install --global @ahoooooo/reviewready\n```\n\nCreate your own `.reviewready.yml` policy, using the example below, then run:\n\n```console\nreviewready validate --policy .reviewready.yml\n```\n\nThe Action can also be used in an advisory workflow:\n\n```yaml\n- uses: ahoooooooo/reviewready@v1.0.17 # v1.0.17\n```\n\nThe example selects this package's semantic-version release. GitHub release\nimmutability must lock that tag and its assets before publication can pass. Full\ncommit SHAs identify fixed source revisions; the exact audited commit is recorded\nin the versioned release evidence for users who require a SHA pin. The mutable\n`v1` alias can move only after release verification; npm `latest` is also a\nmutable registry tag. Release evidence records a historical publication\nobservation, not the aliases' live targets.\nThe advisory workflow below must not be configured as the repository's only\ntrusted merge authority unless its workflow and policy selection are protected by\nan independent repository or organization rule.\n\nVersion 1 keeps the policy, result, and exit-code contracts stable. See\n[CHANGELOG.md](https://github.com/ahoooooooo/reviewready/blob/main/CHANGELOG.md) for patch history; older release output is not\nrewritten.\n\n## How it works\n\nThe target repository owns a `.reviewready.yml` policy on its base branch:\n\n```yaml\n# yaml-language-server: $schema=./reviewready.schema.json\nversion: 1\nrules:\n  - id: source-change\n    when:\n      paths:\n        any: [\"src/**\"]\n    require:\n      - type: pr_body_section\n        heading: Testing\n      - type: linked_issue\n      - type: check\n        name: test\n        app: github-actions\n        conclusions: [success]\n      - type: human_attestation\n        text: I understand and take responsibility for this change.\n\n  - id: workflow-change\n    when:\n      paths:\n        any: [\".github/workflows/**\"]\n    require:\n      - type: pr_body_section\n        heading: Risk\n```\n\nAll matching rules apply. Equivalent requirements are checked once and attributed\nto every rule that requested them.\n\nOn GitHub, the Action fetches policy bytes from the pull request's immutable base\nSHA, then reads changed paths, completed checks, closing issue references, and\nreviews through read-only APIs. Check Runs collected for an immutable head SHA\nmust echo that SHA; nullable queued or in-progress timestamps remain pending.\nThe policy content proposed by the pull request is not used. The workflow that\ninvokes the Action is a separate trust boundary and must also be protected for\nauthoritative enforcement.\n\n### Editor schema\n\nThe npm package includes `reviewready.schema.json`. A repository that installs the\npackage as a development dependency can reference it directly:\n\n```yaml\n# yaml-language-server: $schema=./node_modules/@ahoooooo/reviewready/reviewready.schema.json\n```\n\nAction-only repositories can copy the schema into the repository or reference an\nimmutable release URL:\n\n```yaml\n# yaml-language-server: $schema=https://raw.githubusercontent.com/ahoooooooo/reviewready/v1.0.17/reviewready.schema.json\n```\n\nKeep the schema version aligned with the Action or CLI version being used. A local\nrelative schema is preferable when editor access to remote URLs is restricted.\n\n## GitHub Action\n\n### Advisory integration\n\nThe following workflow is useful for evaluation. It runs tests on the pull-request\nmerge ref and evaluates metadata with least-privilege job permissions. Because a\n`pull_request` workflow version comes from that merge ref, a pull request can also\npropose changes to this workflow. Protect the workflow and policy selection\nindependently before relying on its result for enforcement.\n\n```yaml\nname: review-ready-advisory\n\non:\n  pull_request:\n    types: [opened, synchronize, edited, reopened, labeled, unlabeled, ready_for_review]\n\njobs:\n  test:\n    runs-on: ubuntu-latest\n    permissions:\n      contents: read\n    steps:\n      - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1\n        with:\n          persist-credentials: false\n      - run: npm ci\n      - run: npm test\n\n  reviewready:\n    if: always()\n    needs: [test]\n    runs-on: ubuntu-latest\n    permissions:\n      contents: read\n      pull-requests: read\n      checks: read\n      statuses: read\n      issues: read\n    steps:\n      - uses: ahoooooooo/reviewready@v1.0.17 # v1.0.17\n```\n\nReplace the example test commands with the target repository's own verification.\nWhen a policy requires another check, schedule ReviewReady after that job with\n`needs`; otherwise the required check may still be pending and cannot count as\nevidence. Specify the expected GitHub App in the policy where provider identity\nmatters.\n\n### Authoritative enforcement\n\nA trusted deployment needs an enforcement workflow that the evaluated pull request\ncannot rewrite. Depending on repository ownership and available GitHub features,\nthat may involve:\n\n- an organization ruleset that requires a selected workflow by source repository\n  and immutable ref;\n- repository rules that independently protect the ReviewReady workflow, policy,\n  Action pin, and policy path;\n- a metadata-only `pull_request_target` workflow from the trusted base branch with\n  explicit read-only permissions and **no checkout, download, cache restore,\n  build, import, or execution of pull-request code**;\n- delegating approval freshness and required human review to GitHub branch rules\n  when review events cannot be reconciled through a trusted workflow.\n\nThe checked-in reference is pinned in a protected change to an immutable\nverified ReviewReady release commit. It is still not an authoritative merge\ngate until the workflow and policy path are independently protected, its unique\njob/check identity is required in GitHub rules, and branch freshness and review\nreconciliation are verified in repository settings. The trusted workflow uses\npull_request_target, read-only permissions, and no checkout, download, cache\nrestore, build, import, or command execution.\n\nThe reference workflow is displayed as **ReviewReady trusted evidence**, and its\njob/check remains `readiness`. The `check` and `readiness` check names must stay\naligned with the adopting repository's required-check rules. Its configured PR\nevents include new commits (`synchronize`) and body edits (`edited`). During a\nrun it waits for the latest `check` on the exact PR head, then evaluates evidence.\nThis bounded wait does not subscribe to later CI reruns. If CI alone is rerun\nafter readiness has finished or timed out, manually rerun the trusted evidence\nworkflow after CI completes and confirm its result belongs to the current PR\nhead and metadata. A previous readiness result does not prove later evidence\nwas reevaluated.\n\nThe Action writes a job summary and exports:\n\n- `status`: `ready` or `not_ready`;\n- `report-json`: the versioned deterministic result.\n\nBefore publication, the Action bounds report-json to 1,000,000 UTF-8 bytes and\nthe Markdown summary to 1 MiB. Oversized or partially publishable results fail\nclosed; the status output is written last. The publication order is summary,\nreport-json, then status. Status is the commit marker: consumers must not treat\nan earlier summary or report-json as valid readiness evidence when the status\noutput is absent.\n\nThe report-json output and CLI check --json use the same v1 shape:\noutputVersion, status, policyVersion, triggeredRules, and requirements.\nRequirement key values retain the v1 public format; internal deduplication uses\na separate structured identity so delimiter characters cannot merge unrelated\nrequirements. When no rule matches, v1 keeps status ready and an empty\nrequirement list, while text, Markdown, and explain output explicitly identify\nthat no policy rules were evaluated. Add a final paths.any: [\"**\"] rule when a\nrepository requires every ordinary changed path to enter a policy rule. A\nfuture policy/output version may define an explicit unmatched strategy without\nchanging this v1 behavior.\n\nIt fails the job when evidence is missing or cannot be loaded safely. Configure\nthe job as a required status check if it should block merging.\n\n## CLI\n\nAfter installing `reviewready` globally, or as a development dependency and\ninvoking it with `npx`, supply your own policy and normalized input files:\n\n```console\nreviewready validate --policy .reviewready.yml\nreviewready explain --policy .reviewready.yml\nreviewready check --policy .reviewready.yml --input input.json\n```\n\nThe normalized input shape and examples are documented in the\n[product specification](https://github.com/ahoooooooo/reviewready/blob/v1.0.17/docs/product-spec.md).\nThe npm package includes the CLI and schemas; it does not include `docs/` or\n`fixtures/`. The following sample commands require a repository checkout and\nrun from its root:\n\n```console\nreviewready validate --policy fixtures/basic/.reviewready.yml\nreviewready explain --policy fixtures/basic/.reviewready.yml\nreviewready check --policy fixtures/basic/.reviewready.yml --input fixtures/basic/ready.json\n```\n\nReadiness CLI exit codes:\n\n- `0`: policy valid or contribution ready;\n- `1`: contribution not ready;\n- `2`: invalid configuration, input, event, or runtime failure.\n\nThe local CLI consumes normalized JSON rather than contacting GitHub. This keeps\nthe engine reproducible and makes policies easy to test with fixtures.\nPolicy and normalized-input files are read only when they are regular files and\nare bounded at 4 MiB (4,194,304 raw bytes) before UTF-8 decoding. Missing,\nunreadable, non-regular, oversized, or otherwise incomplete reads fail with\nexit code 2. Policy text fields are limited to 500 Unicode code points; the\nsame visible-text and control/format-character contract is enforced by the\nruntime parser and reviewready.schema.json.\n\n### Repository audit\n\nThe separate audit command checks a bounded normalized repository snapshot. It\nis read-only, deterministic, and fail-closed; it does not check out or execute\nworkflow source and it does not change the readiness JSON contract. For an\ninstalled package, supply your own normalized snapshot as `audit-input.json`:\n\n```console\nreviewready audit --input audit-input.json --json\n```\n\nThe following fixture examples require a repository checkout:\n\n```console\nreviewready audit --input fixtures/audit/reviewready.json\nreviewready audit --input fixtures/audit/reviewready.json --json\nreviewready audit --input fixtures/audit/reviewready.json --sarif\n```\n\nThe checked-in `fixtures/audit/reviewready.json` is a synthetic, offline-only\nnormalized snapshot for deterministic dogfooding; it is not a live GitHub\ncapture or replayable evidence bundle. Audit exit codes are 0 for `pass`, 1 for\nfindings, and 2 for incomplete or invalid input. The audit report has its own contract, described by\n[reviewready.audit.schema.json](reviewready.audit.schema.json); it is not the\nreadiness result. The readiness JSON contract is separately documented by\n[reviewready.result.schema.json](reviewready.result.schema.json).\n\nThe CLI can also collect a live, read-only snapshot from GitHub:\n\n```console\nreviewready audit --github owner/repository --token-env GITHUB_TOKEN \\\n  --protected-workflow .github/workflows/reviewready-trusted.yml \\\n  --trusted-workflow .github/workflows/reviewready-trusted.yml --json\n```\n\nThe token is read only from the named environment variable. Live collection\nloads policy and workflow bytes at one immutable base SHA, uses bounded REST\npagination/retries/response size/deadline, and returns `incomplete` when\nsettings or the base revision are not authoritative. Protected and trusted\nworkflow roots are explicit out-of-band inputs; a check name or ordinary API\nsuccess never establishes a trust root. Each root option is bounded and must\nname an observed workflow, but it remains a caller assertion rather than\nindependent GitHub authority. Workflow and policy source are bounded to 256 KiB.\nThe live adapter also enforces a 768-attempt total request budget and requires\nthe bounded transport for every structured and raw API read. It installs that\nboundary from Octokit's configured fetch or the runtime global fetch, and fails\nclosed if neither is available. It collects inherited branch/tag/push/repository\nrulesets. Repository targets require an explicit modeled repository scope;\nunsupported conditions, enforcement states, ruleset exclusions, or\nrepository-id/property scopes fail closed; active\ntag-only rulesets are reported as incomplete rather than as branch force-push\nor deletion findings.\nThe optional `--ref` value is only a default-branch assertion: it must equal the\nrepository API's reported default branch. A non-default branch is rejected as\nincomplete rather than silently audited under default-branch semantics. The\ncollector also binds its two repository reads to GitHub's immutable numeric\nrepository ID internally; that identity is not added to the public snapshot.\nFor an exact-revision, replayable audit, use the separate evidence modes:\n\n```console\nreviewready audit collect --github owner/repository --revision FULL_COMMIT_SHA \\\n  --token-env GITHUB_TOKEN \\\n  --protected-workflow .github/workflows/reviewready-trusted.yml \\\n  --trusted-workflow .github/workflows/reviewready-trusted.yml > audit.bundle.json\nreviewready audit replay --bundle audit.bundle.json --json\n```\n\n`audit collect` requires the full default-branch commit SHA, reads the token only\nfrom the named environment variable, and writes one canonical bundle to a raw\nstdout sink without a trailing newline. It never writes a repository file,\ncontacts GitHub with the bundle, checks out code, or executes workflow source.\nThe bundle retains exact policy/workflow bytes, so review private or internal\nrepository bundles as sensitive artifacts. `audit replay` is offline, bounded\nto an 8 MiB regular file, re-derives the report, and returns the same 0/1/2\nstatus class without contacting GitHub. The evidence contract is described by\n[reviewready.audit-evidence.schema.json](reviewready.audit-evidence.schema.json)\nand is separate from both the audit report and readiness result.\n\nThe live adapter reads the `.github/workflows` directory with only the requested\nimmutable `ref`. It accepts one bounded Contents response, rejects any response\nthat advertises a `Link` header, and fails closed when the directory exceeds the\nworkflow bound; it does not fabricate pagination for that endpoint.\n\nThe legacy live command above remains report-only and is retained for\ncompatibility; it does not produce a replayable bundle. The collector\nnever checks out or executes repository code.\n\nThe GitHub App JWT/token and webhook HMAC/replay modules are internal\nimplementation contracts, not a supported public provider SDK or a deployable\nApp. ReviewReady does not include an HTTP server, secret\nmanager, durable database, or in-memory replay fallback.\n\n## Policy reference\n\n### Conditions\n\nEach rule has paths, labels, or both. Each match set supports:\n\n- `any`: at least one pattern or value must match;\n- `all`: every pattern or value must match somewhere;\n- `none`: no pattern or value may match.\n\nPaths use repository-relative POSIX globs. Labels match case-insensitively.\nAbsolute paths, traversal, literal backslashes, empty path segments, and leading\nglob negation are rejected. For renamed files, both the new path and the\nprevious path are evaluated; the Git separator is never rewritten.\n\n### Requirements\n\n- `pr_body_section`: a Markdown heading exists and has non-empty content.\n- `linked_issue`: GitHub reports at least one closing issue reference.\n- `check`: the latest logical Check Run (name plus App slug), or latest legacy\n  commit status context, has the exact name and allowed conclusion. A newer\n  failure or pending result cannot fall back to an older success.\n- `maintainer_review`: the latest review state from enough unique users with write,\n  maintain, or admin permission is approved. GitHub APPROVED,\n  CHANGES_REQUESTED, and DISMISSED reviews require valid timestamps;\n  COMMENTED may omit one. Timestamp-free local fixtures use their array order.\n  Permission association retains at most 100 distinct actionable reviewers and\n  performs at most 8 permission requests concurrently. It keeps the latest\n  timestamped opinionated state per case-insensitive login and omits pending or\n  commented reviews; unsupported or incomplete states fail closed.\n- `human_attestation`: the PR body contains the exact checked task-list text. This\n  verifies visible text only; it does not verify identity, understanding,\n  authorship, or legal responsibility.\n\nThe full editor schema is [reviewready.schema.json](reviewready.schema.json). The\nexecutable behavior for this version is specified in [docs/product-spec.md](https://github.com/ahoooooooo/reviewready/blob/v1.0.17/docs/product-spec.md).\n\nReviewReady v1 intentionally does not evaluate `merge_group`: GitHub's synthetic\nmerge commit does not carry a complete per-PR body, review, and closing-issue\ncontext. Do not make the current check a merge-queue requirement without a\nseparate trustworthy aggregation design.\n\nThe ordinary pull_request caller workflow is an advisory integration unless the\nrepository separately protects the workflow root and required result. See\n[the trusted workflow design](https://github.com/ahoooooooo/reviewready/blob/v1.0.17/docs/adr/0001-trusted-workflow-root.md) for the\nsecurity boundary and the settings that must be verified in GitHub.\n\n## Security model\n\n- Policy bytes are fetched from the base SHA, never from the proposed head.\n- The Action itself does not check out or execute pull-request code.\n- A caller workflow is authoritative only when its definition, Action pin, inputs,\n  and policy path are protected independently from the pull request.\n- User-controlled text is escaped in Markdown summaries.\n- Public error control characters are escaped before CLI or Action output.\n- Public errors omit stack traces, tokens, API response bodies, and local paths.\n- Invalid or unavailable authoritative input fails closed.\n- Bounded GitHub pagination rejects malformed or non-contiguous next links\n  instead of treating a truncated response as complete.\n- Required GitHub evidence is read twice with a bounded fingerprint so a stable\n  PR metadata snapshot cannot silently pair with changing checks or reviews;\n  the snapshot is also verified after the second evidence read.\n- The sample workflow is a normal pull_request integration and must not be\n  treated as the sole authoritative merge gate until the trusted workflow root\n  design is implemented and repository rules are verified.\n- `pull_request` is fork-safe for running untrusted CI with a read-only token,\n  but its workflow definition is not a trusted enforcement root.\n- `pull_request_target` uses a trusted base workflow, but becomes dangerous if\n  it checks out, downloads, imports, caches, or executes untrusted pull-request\n  code.\n\nSee the current [SECURITY.md](https://github.com/ahoooooooo/reviewready/blob/main/SECURITY.md) and this version's [docs/architecture.md](https://github.com/ahoooooooo/reviewready/blob/v1.0.17/docs/architecture.md) for\nthe trust model and current known limitations.\n\n## Development\n\nThese commands require a repository checkout:\n\n```console\nnpm ci\nnpm run check\n```\n\n`npm run check` enforces formatting, strict linting, TypeScript types, coverage\nthresholds, production build, generated dist parity, package privacy checks, and\nthe bundled JavaScript Action. See [CONTRIBUTING.md](https://github.com/ahoooooooo/reviewready/blob/main/CONTRIBUTING.md) for the\nred/green/regression workflow.\n\n## License\n\nMIT. See [LICENSE](LICENSE).\n","readmeFilename":"README.md"}