{"_id":"@ai-outfitter/link","_rev":"8-6a98bafbacf15e0e3453a571d7b9a6b5","name":"@ai-outfitter/link","dist-tags":{"latest":"1.6.0"},"versions":{"1.0.0":{"name":"@ai-outfitter/link","version":"1.0.0","keywords":["ai-outfitter","sdlc","agents","governance","report"],"license":"MIT","_id":"@ai-outfitter/link@1.0.0","maintainers":[{"name":"ncrmro","email":"ncrmro@gmail.com"}],"homepage":"https://github.com/ai-outfitter/link#readme","bugs":{"url":"https://github.com/ai-outfitter/link/issues"},"bin":{"link":"dist/cli.js"},"dist":{"shasum":"8cf721980fc270aece75c26a490e7f45046f9246","tarball":"https://registry.npmjs.org/@ai-outfitter/link/-/link-1.0.0.tgz","fileCount":26,"integrity":"sha512-REEUnAKy7fdXHzdkZo3qsjXCNOav6833EPE+0MJG7m36bxZDkUJ7YuvlIbOlADUOTXFZYlBVNKp6Hn1qR9YvKw==","signatures":[{"sig":"MEUCIQCqvRdi5ckvhvqDIWY0TyCTrZPabtAOBscvVLle459u5QIgIuCSVtfZq+v4tDMyr9orm1IL+yXv78cRy3SxH7xYmoM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":86286},"type":"module","engines":{"node":">=20.19.0"},"gitHead":"a9f59b10f4627a7f7b441904a29bebb912cc9173","scripts":{"build":"tsc -p tsconfig.build.json","report":"node dist/cli.js report","prepare":"npm run build","typecheck":"tsc -p tsconfig.build.json --noEmit"},"_npmUser":{"name":"ncrmro","email":"ncrmro@gmail.com"},"repository":{"url":"git+https://github.com/ai-outfitter/link.git","type":"git"},"_npmVersion":"11.16.0","description":"Audit organizations against the Outfitter SDLC governance baseline: a read-only scanner that rates repositories on the agentic adoption ramp.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.0.0","yaml":"^2.8.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.2","@types/node":"^22.15.0"},"_npmOperationalInternal":{"tmp":"tmp/link_1.0.0_1786389949816_0.8876160895690237","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@ai-outfitter/link","version":"1.0.2","keywords":["ai-outfitter","sdlc","agents","governance","report"],"license":"MIT","_id":"@ai-outfitter/link@1.0.2","maintainers":[{"name":"ncrmro","email":"ncrmro@gmail.com"}],"homepage":"https://github.com/ai-outfitter/link#readme","bugs":{"url":"https://github.com/ai-outfitter/link/issues"},"bin":{"link":"dist/cli.js"},"dist":{"shasum":"e9753806ebbcf5e740a55ce87966035976255d07","tarball":"https://registry.npmjs.org/@ai-outfitter/link/-/link-1.0.2.tgz","fileCount":26,"integrity":"sha512-pwb2pkks5cJ3sI03MCQpZou5NZR739muJXF6QTPOyzDB2nfQudWQ/kRVWkO8cdMkU7nghwRCnZ7d95DbE76AXQ==","signatures":[{"sig":"MEYCIQCPle8QroBoZ98rftUTVzSMynmHQV0olE7afRaQkQWShQIhAP73YUJMkOcYLtB7oLjn2VIGZ779lSTKLi0gYMDLoQhf","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":86286},"type":"module","engines":{"node":">=20.19.0"},"gitHead":"5f31c30bca9b83aae0019117a192f2e232017b22","scripts":{"build":"tsc -p tsconfig.build.json","report":"node dist/cli.js report","prepare":"npm run build","typecheck":"tsc -p tsconfig.build.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b0bae73a-cccc-4aef-ab39-81d26d26852d"}},"repository":{"url":"git+https://github.com/ai-outfitter/link.git","type":"git"},"_npmVersion":"11.16.0","description":"Audit organizations against the Outfitter SDLC governance baseline: a read-only scanner that rates repositories on the agentic adoption ramp.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.0.0","yaml":"^2.8.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.2","@types/node":"^22.15.0"},"_npmOperationalInternal":{"tmp":"tmp/link_1.0.2_1786391788257_0.25139945965137844","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@ai-outfitter/link","version":"1.1.0","keywords":["ai-outfitter","sdlc","agents","governance","report"],"license":"MIT","_id":"@ai-outfitter/link@1.1.0","maintainers":[{"name":"ncrmro","email":"ncrmro@gmail.com"}],"homepage":"https://github.com/ai-outfitter/link#readme","bugs":{"url":"https://github.com/ai-outfitter/link/issues"},"bin":{"link":"dist/cli.js"},"dist":{"shasum":"89937a32ab4780794ff85790d0a6b3ddee6656c3","tarball":"https://registry.npmjs.org/@ai-outfitter/link/-/link-1.1.0.tgz","fileCount":62,"integrity":"sha512-dmCqgf5bRHwp1jSNb1NPM1GMeyfaYkvPjCpGKazRjhktT1+sHQt12OkViahHM4TcyoQslbkjSwX9ZAP5UU4ymw==","signatures":[{"sig":"MEYCIQDnLAkffgvlU65W+LV3WM3jFnqPVXnBpsgafz2Fo79unAIhANBD/H6Wo+eevytXlJWluAEVQGr0uJVTAdWwbJk7Swdn","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1745403},"type":"module","engines":{"node":">=20.19.0"},"gitHead":"1ca66d84c46375bcac3cfe7104adf922adf7e247","scripts":{"build":"tsc -p tsconfig.build.json","report":"node dist/cli.js report","prepack":"npm run build && npm run build:web","prepare":"npm run build","build:web":"node scripts/build-web.mjs","typecheck":"tsc -p tsconfig.build.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b0bae73a-cccc-4aef-ab39-81d26d26852d"}},"repository":{"url":"git+https://github.com/ai-outfitter/link.git","type":"git"},"_npmVersion":"11.16.0","description":"Audit organizations against the Outfitter SDLC governance baseline: a read-only scanner that rates repositories on the agentic adoption ramp.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.0.0","yaml":"^2.8.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"^0.25.0","typescript":"^5.9.2","@types/node":"^22.15.0"},"_npmOperationalInternal":{"tmp":"tmp/link_1.1.0_1786394989058_0.6799908326289952","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@ai-outfitter/link","version":"1.2.0","keywords":["ai-outfitter","sdlc","agents","governance","report"],"license":"MIT","_id":"@ai-outfitter/link@1.2.0","maintainers":[{"name":"ncrmro","email":"ncrmro@gmail.com"}],"homepage":"https://github.com/ai-outfitter/link#readme","bugs":{"url":"https://github.com/ai-outfitter/link/issues"},"bin":{"link":"dist/cli.js"},"dist":{"shasum":"cfc457b631ea3a3d0b9a88caee974ba892dc54fb","tarball":"https://registry.npmjs.org/@ai-outfitter/link/-/link-1.2.0.tgz","fileCount":62,"integrity":"sha512-bCoLHmNe7brfaFyIYDZBm4d6BN7RHV+AdMGSlZaTd15ATDITMLtaugirSVPXJmI/vvBdhQ3z6CpZnRkTal1VEg==","signatures":[{"sig":"MEYCIQCdU+wLHzmcF4lLvRbXt5LWDV3QbkJi/n8wGCACoqB+QgIhALrSQqcAAorQIDxCHctTcUH/z0Gebh/zAnf9d1lo5nQV","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1746357},"type":"module","engines":{"node":">=20.19.0"},"gitHead":"2f6a348567e5e6c8029f83bdc5f0dd173d75594e","scripts":{"build":"tsc -p tsconfig.build.json","report":"node dist/cli.js report","prepack":"npm run build && npm run build:web","prepare":"npm run build","build:web":"node scripts/build-web.mjs","typecheck":"tsc -p tsconfig.build.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b0bae73a-cccc-4aef-ab39-81d26d26852d"}},"repository":{"url":"git+https://github.com/ai-outfitter/link.git","type":"git"},"_npmVersion":"11.16.0","description":"Audit organizations against the Outfitter SDLC governance baseline: a read-only scanner that rates repositories on the agentic adoption ramp.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.0.0","yaml":"^2.8.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"^0.25.0","typescript":"^5.9.2","@types/node":"^22.15.0"},"_npmOperationalInternal":{"tmp":"tmp/link_1.2.0_1786396476499_0.4239286658905237","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"@ai-outfitter/link","version":"1.3.0","keywords":["ai-outfitter","sdlc","agents","governance","report"],"license":"MIT","_id":"@ai-outfitter/link@1.3.0","maintainers":[{"name":"ncrmro","email":"ncrmro@gmail.com"}],"homepage":"https://github.com/ai-outfitter/link#readme","bugs":{"url":"https://github.com/ai-outfitter/link/issues"},"bin":{"link":"dist/cli.js"},"dist":{"shasum":"9be63a5e2d13cd1fcc23133e84838c7d5007e399","tarball":"https://registry.npmjs.org/@ai-outfitter/link/-/link-1.3.0.tgz","fileCount":62,"integrity":"sha512-6W3LhsAav43HdrmCROVyPCA07tFt1rex4BzWZtVHpEuStOZ2S5l1xO49hcDhYrmeAjLCytRHY1spWXAg585WyQ==","signatures":[{"sig":"MEUCIE5AHpsR82ZAr35lyF6bUsMiaQDdfOgJtqyO7mAl+k7XAiEA/CJ2nZCSPzxQbT9jLI9CXd010EmTPi3lxS12UwC6HFI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1747360},"type":"module","engines":{"node":">=20.19.0"},"gitHead":"4bb9fe8314a91f91bc9616e5e5b77fcd20721e52","scripts":{"build":"tsc -p tsconfig.build.json","report":"node dist/cli.js report","prepack":"npm run build && npm run build:web","prepare":"npm run build","build:web":"node scripts/build-web.mjs","typecheck":"tsc -p tsconfig.build.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b0bae73a-cccc-4aef-ab39-81d26d26852d"}},"repository":{"url":"git+https://github.com/ai-outfitter/link.git","type":"git"},"_npmVersion":"11.16.0","description":"Audit organizations against the Outfitter SDLC governance baseline: a read-only scanner that rates repositories on the agentic adoption ramp.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.0.0","yaml":"^2.8.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"^0.25.0","typescript":"^5.9.2","@types/node":"^22.15.0"},"_npmOperationalInternal":{"tmp":"tmp/link_1.3.0_1786397476768_0.5845147367937558","host":"s3://npm-registry-packages-npm-production"}},"1.4.0":{"name":"@ai-outfitter/link","version":"1.4.0","keywords":["ai-outfitter","sdlc","agents","governance","report"],"license":"MIT","_id":"@ai-outfitter/link@1.4.0","maintainers":[{"name":"ncrmro","email":"ncrmro@gmail.com"}],"homepage":"https://github.com/ai-outfitter/link#readme","bugs":{"url":"https://github.com/ai-outfitter/link/issues"},"bin":{"link":"dist/cli.js"},"dist":{"shasum":"36f4a8c9ff67c06c3ca27da19e86f02540d6c1d7","tarball":"https://registry.npmjs.org/@ai-outfitter/link/-/link-1.4.0.tgz","fileCount":62,"integrity":"sha512-aGiS7RafilKFHvdrAeG1UTK4JsRu3ngL28kekfR7vejtlqeAesUYFTpdEJjmVImGORfBysgtkOBpIjawqVOZxg==","signatures":[{"sig":"MEQCICuYqeWBUnCfMk2cU7g/pWumqsttO2mMznAtfnwFbPQRAiAnkAH7EmnszTS3dFMWjM6MdkWIN29GgSFTgvg2qO66Nw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1752312},"type":"module","engines":{"node":">=20.19.0"},"gitHead":"d44979dff5ed3d772fa2c28c55ddb8000f94e21e","scripts":{"build":"tsc -p tsconfig.build.json","report":"node dist/cli.js report","prepack":"npm run build && npm run build:web","prepare":"npm run build","build:web":"node scripts/build-web.mjs","typecheck":"tsc -p tsconfig.build.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b0bae73a-cccc-4aef-ab39-81d26d26852d"}},"repository":{"url":"git+https://github.com/ai-outfitter/link.git","type":"git"},"_npmVersion":"11.16.0","description":"Audit organizations against the Outfitter SDLC governance baseline: a read-only scanner that rates repositories on the agentic adoption ramp.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.0.0","yaml":"^2.8.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"^0.25.0","typescript":"^5.9.2","@types/node":"^22.15.0"},"_npmOperationalInternal":{"tmp":"tmp/link_1.4.0_1786399748964_0.7022443420852136","host":"s3://npm-registry-packages-npm-production"}},"1.5.0":{"name":"@ai-outfitter/link","version":"1.5.0","keywords":["ai-outfitter","sdlc","agents","governance","report"],"license":"MIT","_id":"@ai-outfitter/link@1.5.0","maintainers":[{"name":"ncrmro","email":"ncrmro@gmail.com"}],"homepage":"https://github.com/ai-outfitter/link#readme","bugs":{"url":"https://github.com/ai-outfitter/link/issues"},"bin":{"link":"dist/cli.js"},"dist":{"shasum":"3a04b86a590acaed189d427d84e2f7b4f816de9c","tarball":"https://registry.npmjs.org/@ai-outfitter/link/-/link-1.5.0.tgz","fileCount":64,"integrity":"sha512-hLnKOG150t6gZ9hUigqUbfd8uoiiTWO4lpbpGL4Hzy5z/BypDThW2XQh93uYzUh7GMsvMWoJUfGRPShtXcv9RQ==","signatures":[{"sig":"MEQCIFXhCuCup24HhoDyzuBy2UtATW4NJJp2X1o0IeqQUufkAiAxtH/OC6UdON9/VajvKhyzdJ0da1PBJJ0d1uM+RFrqOQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1825169},"type":"module","engines":{"node":">=20.19.0"},"gitHead":"861c85031fb23c5cb56c3c4145f478eaef9d837d","scripts":{"build":"tsc -p tsconfig.build.json","report":"node dist/cli.js report","prepack":"npm run build && npm run build:web","prepare":"npm run build","build:web":"node scripts/build-web.mjs","typecheck":"tsc -p tsconfig.build.json --noEmit","test:sources":"node scripts/test-sources.mjs","test:evidence":"node scripts/test-evidence.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b0bae73a-cccc-4aef-ab39-81d26d26852d"}},"repository":{"url":"git+https://github.com/ai-outfitter/link.git","type":"git"},"_npmVersion":"11.16.0","description":"Audit organizations against the Outfitter SDLC governance baseline: a read-only scanner that rates repositories on the agentic adoption ramp.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^4.0.0","yaml":"^2.8.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"esbuild":"^0.25.0","typescript":"^5.9.2","@types/node":"^22.15.0"},"_npmOperationalInternal":{"tmp":"tmp/link_1.5.0_1786645259274_0.8686247616220533","host":"s3://npm-registry-packages-npm-production"}},"1.6.0":{"name":"@ai-outfitter/link","version":"1.6.0","description":"Audit organizations against the Outfitter SDLC governance baseline: a read-only scanner that rates repositories on the agentic adoption ramp.","type":"module","license":"MIT","repository":{"type":"git","url":"git+https://github.com/ai-outfitter/link.git"},"homepage":"https://github.com/ai-outfitter/link#readme","bugs":{"url":"https://github.com/ai-outfitter/link/issues"},"keywords":["ai-outfitter","sdlc","agents","governance","report"],"bin":{"link":"dist/cli.js"},"engines":{"node":">=20.19.0"},"scripts":{"build":"tsc -p tsconfig.build.json","build:web":"node scripts/build-web.mjs","prepare":"npm run build","prepack":"npm run build && npm run build:web","typecheck":"tsc -p tsconfig.build.json --noEmit","report":"node dist/cli.js report","test:evidence":"node scripts/test-evidence.mjs","test:sources":"node scripts/test-sources.mjs"},"dependencies":{"yaml":"^2.8.1","zod":"^4.0.0"},"devDependencies":{"@types/node":"^22.15.0","esbuild":"^0.25.0","typescript":"^5.9.2"},"publishConfig":{"access":"public"},"gitHead":"d7676f730052f6166424f57b9774aac1c0bd6c3f","_id":"@ai-outfitter/link@1.6.0","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-/wHPbTt0wBq8e1dE7vdPHrH7z1R5uYAFxEmtHwVJDj4A1OkyE0e7CVDoLN/cDyjktoOETa3/EX8CMuVCBaL+pA==","shasum":"89c205c348249cf7894a275e0f613c696639da6b","tarball":"https://registry.npmjs.org/@ai-outfitter/link/-/link-1.6.0.tgz","fileCount":64,"unpackedSize":1835353,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCRH4n6ODG7h9MGKlc1BdSj39ryNmWuPSqc7JXBj0XBRgIgV/gv0ByeskVGtt5Fh40Z5rhdPN8Zh0m5wIsZQiNIsJU="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:b0bae73a-cccc-4aef-ab39-81d26d26852d"}},"directories":{},"maintainers":[{"name":"ncrmro","email":"ncrmro@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/link_1.6.0_1786651774286_0.22106949787058539"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-10T19:25:49.596Z","modified":"2026-08-13T20:09:34.659Z","1.0.0":"2026-08-10T19:25:49.976Z","1.0.2":"2026-08-10T19:56:28.409Z","1.1.0":"2026-08-10T20:49:49.247Z","1.2.0":"2026-08-10T21:14:36.764Z","1.3.0":"2026-08-10T21:31:16.958Z","1.4.0":"2026-08-10T22:09:09.156Z","1.5.0":"2026-08-13T18:20:59.563Z","1.6.0":"2026-08-13T20:09:34.469Z"},"bugs":{"url":"https://github.com/ai-outfitter/link/issues"},"license":"MIT","homepage":"https://github.com/ai-outfitter/link#readme","keywords":["ai-outfitter","sdlc","agents","governance","report"],"repository":{"type":"git","url":"git+https://github.com/ai-outfitter/link.git"},"description":"Audit organizations against the Outfitter SDLC governance baseline: a read-only scanner that rates repositories on the agentic adoption ramp.","maintainers":[{"name":"ncrmro","email":"ncrmro@gmail.com"}],"readme":"# link\n\nThe SDLC reference catalog, published with the tooling that measures adoption\nof it. The dotagents payload (agents, workflows, governance, environments,\nspec) is the [community-profiles SDLC reference\ncollection](https://github.com/ai-outfitter/community-profiles); the\n`@ai-outfitter/link` package audits organizations against the catalog's\ngovernance baseline and serves a site that renders the report and the\ndefined workflows.\n\n## Quick start\n\nRequires an authenticated `gh` CLI. The scanner is read-only: it lists\nrepositories, reads git trees, and reads effective branch rules; it changes\nnothing.\n\n```sh\nnpx @ai-outfitter/link review <org>        # a whole organization\nnpx @ai-outfitter/link review <org>/<repo> # one repository\n```\n\n`review` is the one to reach for: it scans and then opens the report, which\nis what you wanted both times. `report` does the scan alone, for scripts and\nCI, and `web` serves the last one without rescanning.\n\nEither way the scan writes `report.json` to the working directory, plus a\ncopy in `$XDG_DATA_HOME/outfitter-link/`. `--out <dir>` puts it somewhere\nelse and creates the directory — how the onboarding runbook files a dated\nbaseline into an org's `.agents` catalog:\n\n```sh\nnpx @ai-outfitter/link report my-org --out ~/repos/my-org/.agents/reports/sdlc/2026-08-10-initial\n```\n\nThe scan runs on plain node, so `npx` needs no other toolchain. With\n[Bun](https://bun.sh) installed, `bunx` works the same and starts faster.\nScanning five orgs and 80-odd repositories takes about six seconds.\n\nPin a version in automation — an unpinned run executes whatever the latest\nrelease ships:\n\n```sh\nnpx @ai-outfitter/link@1 report my-org\n```\n\nEach release is one coherent snapshot: the catalog payload and the scanner\nthat audits against it move together. See [CHANGELOG.md](CHANGELOG.md) and\nthe [releases page](https://github.com/ai-outfitter/link/releases).\n\n### Container\n\nThe image carries `gh` and `git`, so it needs only a token, and it serves the\nreport too — the container is a complete path with no toolchain on the host.\n`review` is its default command, so one run scans and then serves:\n\n```sh\ndocker run --rm -e GH_TOKEN=\"$(gh auth token)\" -v \"$PWD:/work\" -p 4321:4321 \\\n  ghcr.io/ai-outfitter/link:1 review my-org\n```\n\nThe working directory is `/work`; mount over it to keep the report, which\nlands there as `report.json` alongside `workflows.json`. A container's own\nstate does not outlive it, so that mount is what a later `web` run reads.\n\n`report` and `web` remain callable on their own when automation wants one\nwithout the other.\n\n### The site\n\n```sh\nnpx @ai-outfitter/link@1 web        # http://localhost:4321; set PORT to change it\n```\n\n`/` is the organization report; `/workflows` renders each `agent-workflow/v1`\ndefinition with its steps, `with:` handoffs, `posts-to:` targets, and YAML\nsource; `/baseline` renders the governance policy the report was audited\nagainst, rule by rule, and marks which rules a forge scan can measure. The\nreport page manages sources directly: add a GitHub org or a local folder in\nthe form and rescan — the same XDG registry the CLI uses, and the same\nscanner, run for you.\n\nThe policy travels inside `report.json`, so a report filed into an org's\n`.agents` catalog can still be read against the rules it was scored under\nafter the catalog moves on.\n\nThe site ships prebuilt and needs no toolchain of its own. Run `report` at\nleast once first: the page renders whatever the last scan wrote.\n\n## The report\n\nSources can be a GitHub org (`acme`), a single repository (`acme/widgets`),\nor a **local folder** — a single checkout, an owner folder of clones, or a\nwhole `~/repos/` root; hidden directories are included because the org/user\n`.agents` catalog is the canonical eval anchor. `link report add\n<org-or-path>` registers a source persistently in\n`$XDG_CONFIG_HOME/outfitter-link/sources.json`.\n\nRepositories group by owner, so `link report acme/one acme/two` is one\nreport covering two repositories rather than two reports. Naming an org and\none of its repositories is not a duplicate — the org listing already carries\nit.\n\nA repository-scoped scan never lists the rest of the owner, so its level\ndescribes the repositories it saw and not the organization. The report says\nexactly that in `evidence_limits`, and its `source_type` is `github-repo`\nrather than `github-org`.\n\nNamed targets scope the scan to themselves: `link report acme` reports on\nacme and nothing else, because that report gets filed into acme's own\n`.agents` catalog. A bare `link report` sweeps every registered source\ninstead. A copy of every report also lands in\n`$XDG_DATA_HOME/outfitter-link/report.json`.\n\nThe first milestone in every report is the **e2e smoke test**: does any\npath exist from an issue to an agent the org itself hosts and controls — a\nself-hosted harness in its own CI, or a resident agent with `deploy/`\nmanifests? SaaS coding agents (Copilot, vendor apps) are excluded by\ndefinition; being able to assign work to an agent whose destiny you control\nis the capability everything else builds on.\n\nEvery org report ends in a ranked **plan**, not a grade. `next_steps[]`\nlists what to do, ordered by the rung each step reaches: the smoke test\nfirst when it is unmet, then every rung still ahead — nearest first, in\nrequirement order inside each rung — then the branch-protection backlog.\nEach step carries imperative instructions, the repositories to apply them\nto, and the `blocks_level` it clears, so the site can band the plan by rung\nand a reader can see the shape of the climb rather than one step of it.\nEvery milestone carries its rung too, which makes the milestone list\nreadable as a column: where the ✗ marks start is where the ramp stops.\n\nEvery instruction names a signal the scanner reads, so following one\nchanges the next report — advice this tool cannot then measure is advice it\nhas no business giving. `gaps[]` remains, unordered, for anything that\nparses it.\n\n### Evidence gates\n\n`session-capture` and the `evidence.landing-gate` baseline rule are decided by\n**evidence-gate backends** — a small registry in `code/report/src/evidence.ts`,\nevery one of them reading the repository tree and the effective branch rules\nthe scan already fetched. No backend adds a network call.\n\n| Backend | Recognizes |\n| --- | --- |\n| `pensieve` | The [CICD-001](https://github.com/ai-outfitter/pensieve/blob/main/docs/requirements/CICD-001-evidence-gates.md) shape: a required status check under `evidence/`, the tier workflows, and `.github/pensieve.yml` |\n| `generic` | A required check named for evidence, a transcript, session capture, an audit trail, or an audit log — for an organization that built its own. Bare `audit` is not matched: a dependency audit is not a session record |\n\nBackends are plural on purpose. `link` audits organizations it does not own, so\na scanner that recognized only ai-outfitter's own evidence system would be\ngrading strangers on whether they adopted our product and calling the result a\nmaturity level.\n\nA gate is `met` only when it is **wired** — an effective branch rule requires\nthe check — and **exercised**: the check actually reported on what landed.\nWhether it ever **fired**, meaning the records exist and verify, needs a\ncredential for the evidence store, so it belongs to `pensieve verify` and the\nCI gate, not to a read-only forge scan.\n\nFour things demote a gate that looks configured, each reported by name:\n\n- **No effective rule requires the check.** A repository carrying every\n  workflow and policy file that nothing requires is `declared only` —\n  [CICD-001.1.2](https://github.com/ai-outfitter/pensieve/blob/main/docs/requirements/CICD-001-evidence-gates.md).\n  In-tree `rulesets/*.json` are import sources, not active rules.\n- **Direct pushes reach the default branch.** github.com has no pre-receive\n  hook, so requiring a pull request is the only preventive direct-push control\n  (CICD-001.9.3). Without it a commit lands having passed nothing.\n- **An actor bypasses the ruleset unconditionally.** A break-glass path may\n  exist, but it has to be recorded and produce its own evidence; a silent\n  ruleset bypass is not one (CICD-001.7.4). A pull-request-scoped bypass is\n  recorded without demoting the gate.\n- **The required check never reports.** The last ten merged pull requests are\n  sampled for a passing check. A required check that never runs leaves a\n  pending status and gates nothing — required and reporting are different\n  facts.\n\nThe bypass and sample lookups cost one request each and run only where they\nchange an answer, so a repository that neither lands agent changes nor carries\nan evidence shape is scanned exactly as cheaply as before. A bypass list that\nneeds org admin to read is reported unknown, never empty.\n\nEach repository gets maturity-ramp placement (level 0–5), tree-derived\nsignals (instruction files, `.agents/`, agent workflows), and a per-rule\naudit against `governance/sdlc-baseline.yaml`. Output is typed JSON\nvalidated with zod (`code/report/src/schema.ts`); in a checkout,\n`workflows/*.yaml` are parsed into `workflows.json` beside it for the site.\nRepositories with no push in the last 7 days are scanned and listed but\nexcluded from the org ranking and gap counts — the site collapses them\ninto a hidden section by default. Absence of evidence is recorded as\nabsence — local-only practice is invisible to a forge scan, and the report\nsays so in `evidence_limits`.\n\n## Contributing\n\nRepository layout, the development loop, the Docker build, and the release\nworkflow are in [CONTRIBUTING.md](CONTRIBUTING.md).\n","readmeFilename":"README.md"}