{"_id":"@anatomytool/validate","_rev":"2-f6886415d07ac6a418e2afbcb4675d3d","name":"@anatomytool/validate","dist-tags":{"latest":"1.1.0"},"versions":{"1.0.0":{"name":"@anatomytool/validate","version":"1.0.0","license":"MIT","_id":"@anatomytool/validate@1.0.0","maintainers":[{"name":"0xhayd3n","email":"haydenseymour02@gmail.com"}],"dist":{"shasum":"fca352422c02fe6e628995e6f77a6143b4cbd8ba","tarball":"https://registry.npmjs.org/@anatomytool/validate/-/validate-1.0.0.tgz","fileCount":156,"integrity":"sha512-A+e6unSIYPxpkoU5bx9q8bDh34w05eZHevYsj5Hd7Z4w9Br4RJEnXZm92lu3Jwtg3Mszzn+TAsST1XS7aJ0LNQ==","signatures":[{"sig":"MEUCIQCZGiQcOj0XVGsZflMp8EIkk1IePYBCwSxuJRbELwnl6QIgJxN0oOslwh+bia8e1wfN99R4oR88G3RhgMIxILCdJq8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":474318},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=22"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"d7704efab8bec9a3bbbba5d26b7aa01bd41ec56e","scripts":{"test":"vitest run","build":"tsc","prepare":"npm run build","pretest":"node scripts/prebuild.mjs","prebuild":"node scripts/prebuild.mjs","test:watch":"vitest"},"_npmUser":{"name":"0xhayd3n","email":"haydenseymour02@gmail.com"},"_npmVersion":"11.11.0","description":"Validator for .anatomy and .anatomy-memory files. Routes wire versions 0.1, 0.2, 0.4–0.15, and 1.0 (v1.0 == v0.15 structurally; the 0→1 bump is a stability commitment) + v0.3 cascading semantics. Identity-integrity is version-aware (v0.7+ flat-pillar fing","directories":{},"_nodeVersion":"22.17.0","dependencies":{"ajv":"^8.17.0","smol-toml":"^1.3.0","ajv-formats":"^3.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^2.0.0","typescript":"^5.5.0","@types/node":"^22.0.0","json-schema-to-typescript":"^15.0.4"},"optionalDependencies":{"@ast-grep/napi":"^0.42.0"},"_npmOperationalInternal":{"tmp":"tmp/validate_1.0.0_1779025319322_0.06260372552566751","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@anatomytool/validate","version":"1.1.0","description":"Validator for .anatomy and .anatomy-memory files. Routes wire versions 0.1, 0.2, 0.4–0.15, and 1.0 (v1.0 == v0.15 structurally; the 0→1 bump is a stability commitment) + v0.3 cascading semantics. Identity-integrity is version-aware (v0.7+ flat-pillar fing","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"}},"engines":{"node":">=22"},"license":"MIT","publishConfig":{"access":"public"},"scripts":{"prepare":"npm run build","prebuild":"node scripts/prebuild.mjs","pretest":"node scripts/prebuild.mjs","build":"tsc","test":"vitest run","test:coverage":"vitest run --coverage","test:watch":"vitest"},"dependencies":{"ajv":"^8.17.0","ajv-formats":"^3.0.0","smol-toml":"^1.3.0"},"optionalDependencies":{"@ast-grep/napi":"^0.42.0"},"devDependencies":{"@types/node":"^22.0.0","@vitest/coverage-v8":"^2.1.9","json-schema-to-typescript":"^15.0.4","typescript":"^5.5.0","vitest":"^2.0.0"},"gitHead":"e79063d9ea7d0d22a2de1bfb4f3d66f62507b16a","_id":"@anatomytool/validate@1.1.0","_nodeVersion":"22.17.0","_npmVersion":"11.11.0","dist":{"integrity":"sha512-FU18Ry/v/XMRmH2bQwvOQDW9qjUOvre/BC807BcpD1SYvzzLrl1+71ZxGDKsTo2EZ6RgkVApOVLQL6dXCSuPug==","shasum":"9f9481ce07db4f91f1c18a29709fd05c3b9635cb","tarball":"https://registry.npmjs.org/@anatomytool/validate/-/validate-1.1.0.tgz","fileCount":161,"unpackedSize":499098,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIFXJsPTyCSC4IHTDcWqgHqQUnKGfva7KhnpxdZcCAeT4AiBRzXiCCKwUTAa6gD13hiTwbediFHzCHuue6jcOfH2h8w=="}]},"_npmUser":{"name":"0xhayd3n","email":"haydenseymour02@gmail.com"},"directories":{},"maintainers":[{"name":"0xhayd3n","email":"haydenseymour02@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/validate_1.1.0_1783334032709_0.84884799529006"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-17T13:41:59.195Z","modified":"2026-07-06T10:33:52.949Z","1.0.0":"2026-05-17T13:41:59.476Z","1.1.0":"2026-07-06T10:33:52.840Z"},"license":"MIT","description":"Validator for .anatomy and .anatomy-memory files. Routes wire versions 0.1, 0.2, 0.4–0.15, and 1.0 (v1.0 == v0.15 structurally; the 0→1 bump is a stability commitment) + v0.3 cascading semantics. Identity-integrity is version-aware (v0.7+ flat-pillar fing","maintainers":[{"name":"0xhayd3n","email":"haydenseymour02@gmail.com"}],"readme":"# `@anatomytool/validate`\n\nTypeScript validator for `.anatomy` and `.anatomy-memory` files. Routes by declared wire version (v0.1, v0.2, v0.4–v0.15, and v1.0) and supports v0.3 cascading semantics for repos with multiple `.anatomy` files.\n\n## Install\n\n```bash\nnpm install @anatomytool/validate\n```\n\nRequires Node.js ≥ 22.\n\n## Usage\n\n### Single file\n\n```typescript\nimport { validate } from \"@anatomytool/validate\";\nimport { readFileSync } from \"node:fs\";\n\nconst text = readFileSync(\".anatomy\", \"utf8\");\nconst result = validate(text, { repoRoot: process.cwd() });\n\nif (result.ok) {\n  console.log(\"Valid:\", result.value.identity);\n  for (const w of result.warnings) console.warn(w.code, w.message);\n} else {\n  for (const e of result.errors) console.error(e.code, e.pointer, e.message);\n}\n```\n\n### Cascading tree\n\n```typescript\nimport { validateTree } from \"@anatomytool/validate\";\n\nconst tree = validateTree(repoRoot);\n// tree.results: Map<path, ValidateResult>\n// tree.crossFile: warnings spanning multiple .anatomy files (e.g. duplicate-fingerprint-in-tree)\n```\n\n### Memory file\n\n```typescript\nimport { validateMemory } from \"@anatomytool/validate\";\n\nconst result = validateMemory(memoryText, {\n  anatomyFingerprint: parsedAnatomy.identity.fingerprint,\n  repoRoot,\n});\n```\n\n## What it checks\n\n### `.anatomy` (single file)\n\n- **TOML syntax** — parse error → `toml-parse` error.\n- **Schema conformance** — version-routed against `spec/{0.1, 0.2, 0.4–0.15, 1.0}/schema.json`. Unknown `anatomy_version` → `unsupported-anatomy-version`.\n- **Identity integrity** — version-aware:\n  - **v0.7–v1.0:** flat 4-string identity + single fingerprint via `fingerprintFromPillars(stack, form, domain, function)` = `Crockford-base32(SHA-256(stack\\0form\\0domain\\0function))[:20]`.\n  - **v0.1–v0.6:** per-pillar `hash = canonicalHash(id)`; `fingerprint = concat(stack.hash, form.hash, domain.hash, function.hash)`.\n- **Path checks** — `structure.entries[].path`, `entry_points[].path` — soft-warn if missing on disk; nested-path-escape error for paths that climb above `repoRoot/anatomyDir`.\n- **Interface↔form match (v0.7–v0.8)** — `[interface.exports]` requires a library-shaped form; `[interface.subcommands]` requires a CLI-shaped form; etc.\n- **Soft warnings** — `description-too-long`, `entry-point-description-deprecated` (v0.2 alias), `commands-no-test` (v0.4+: `[operation.commands]` without a `test` key).\n\n### `.anatomy-memory` (paired file)\n\n- **Schema conformance** — version-routed against `spec/memory/{0.1, 0.2}/schema.json`.\n- **Paired-fingerprint integrity** — `repo_fingerprint` must match the paired `.anatomy`'s fingerprint (`memory-fingerprint-mismatch`).\n- **Supersession integrity** — no cycles (`memory-supersedes-cycle`), no dangling targets (`memory-supersedes-not-found`).\n- **Reference soundness** — entry `refs` pointing to nonexistent files → `memory-dangling-ref` warning.\n- **v0.2 verification field hygiene** — `verified_by` items match the attribution regex (`memory-verified-by-malformed`); `verified_by` array bounded at 5 (`memory-verified-by-too-many` warning if exceeded by hand-edits); `last_verified_at` not earlier than the entry's creation `at` (`memory-last-verified-before-at` warning).\n\n### Rule verification (v0.12+)\n\nEach `[[rules]]` entry may carry an optional `verify` field that declares how to check the rule against actual source. Four kinds:\n\n- `glob_exists` — assert files matching a glob exist (or, with `should_not=true`, don't exist).\n- `glob_only` — assert files matching one glob all live inside another.\n- `ast_pattern` — ast-grep pattern + `expect_in` or `forbid_in` glob. Requires the optional `@ast-grep/napi` dependency.\n- `semgrep` (v0.13+) — Semgrep rule + `expect_in` or `forbid_in` glob, for pattern combinators, taint mode, and non-JS-family languages. Requires the optional `semgrep` CLI on `PATH`.\n\nExample:\n\n```toml\n[[rules]]\nrule = \"Tests live in tests/\"\nverify = { kind = \"glob_exists\", path = \"tests/*.test.ts\" }\n\n[[rules]]\nrule = \"No fetch() outside src/api/\"\nverify = { kind = \"ast_pattern\", lang = \"ts\", pattern = \"fetch($_)\", forbid_in = \"src/!(api)/**/*.ts\" }\n```\n\nVerify clauses run during `validate()` when `repoRoot` is provided. Violations surface as warnings; under `anatomy validate --strict` (the default), the relevant warning codes elevate to errors.\n\n**`validate()` is async as of v0.12.** Earlier versions returned a sync object; callers must now `await`.\n\n## Cascading (v0.3 ecosystem)\n\nFor repos with multiple `.anatomy` files (one at root, plus per-package overrides):\n\n```typescript\nimport { findAnatomyForPath, discoverAllAnatomies } from \"@anatomytool/validate\";\n\nconst nearest = findAnatomyForPath(repoRoot, \"packages/server/src/index.ts\");\nconst all = discoverAllAnatomies(repoRoot);\n```\n\nCross-file checks include `duplicate-fingerprint-in-tree` (sibling files sharing a fingerprint).\n\n## Public API\n\n| Export | What |\n|---|---|\n| `validate(text, options)` | Single-file validation; returns `{ ok, value?, errors, warnings }`. |\n| `validateTree(repoRoot, options)` | Cascading tree validation. |\n| `validateMemory(text, options)` | `.anatomy-memory` single-file validation. (No tree-mode equivalent yet — call validateMemory once per discovered memory file.) |\n| `findAnatomyForPath(repoRoot, queryPath)` | Locate the nearest `.anatomy` for a given file path. |\n| `discoverAllAnatomies(repoRoot, options)` | Walk and parse every `.anatomy` in a tree. |\n| `canonicalize(s)` / `hash(c)` / `canonicalHash(s)` / `fingerprintFromPillars(stack, form, domain, fn)` | Re-exported canonical-form helpers. |\n| `supportedVersions` | Frozen tuple of supported wire versions. |\n| `ECOSYSTEM_VERSION` | Currently `\"0.3\"`. |\n| Types: `AnatomyDoc`, `ValidationError`, `Warning`, `ValidateOptions`, `ValidateResult`, `ErrorCode`, `WarningCode` |\n\n## License\n\nMIT\n","readmeFilename":"README.md"}