{"_id":"@ariada-org/vpat-html-renderer","name":"@ariada-org/vpat-html-renderer","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@ariada-org/vpat-html-renderer","version":"0.1.0","description":"Renders VPAT 2.5 INT JSON reports into self-contained, WCAG 2.2 AA-conformant, print-friendly HTML for procurement, regulatory audit, and vendor-website publication.","license":"EUPL-1.2","type":"module","sideEffects":false,"main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"devDependencies":{"@types/node":"^22.10.2","rimraf":"^6.0.1","typescript":"^5.7.2","vitest":"^4.1.0"},"engines":{"node":">=22"},"repository":{"type":"git","url":"git+https://github.com/ariada-org/ariada.git","directory":"packages/ariada-vpat-html-renderer"},"scripts":{"build":"tsc -p tsconfig.json","typecheck":"tsc -p tsconfig.typecheck.json","lint":"eslint src tests","test":"vitest run","test:watch":"vitest","clean":"rimraf dist coverage"},"_id":"@ariada-org/vpat-html-renderer@0.1.0","bugs":{"url":"https://github.com/ariada-org/ariada/issues"},"homepage":"https://github.com/ariada-org/ariada#readme","_integrity":"sha512-z5cWwuQwciPphy8jnvMOeUu1lEieEcgm148AdSlgbUVLuxcijtqV/X9rARPe8/U2dXpEHqZWNLkpBuAMfzxG1Q==","_resolved":"/tmp/870e7b6595b23f623fe90422f7ae8f6f/ariada-org-vpat-html-renderer-0.1.0.tgz","_from":"file:ariada-org-vpat-html-renderer-0.1.0.tgz","_nodeVersion":"22.22.3","_npmVersion":"10.9.8","dist":{"integrity":"sha512-z5cWwuQwciPphy8jnvMOeUu1lEieEcgm148AdSlgbUVLuxcijtqV/X9rARPe8/U2dXpEHqZWNLkpBuAMfzxG1Q==","shasum":"cfb7113122d0a4aea03c67327dc6c9891f20abc8","tarball":"https://registry.npmjs.org/@ariada-org/vpat-html-renderer/-/vpat-html-renderer-0.1.0.tgz","fileCount":86,"unpackedSize":179625,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@ariada-org%2fvpat-html-renderer@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCGoJrvuHieQiXRFc1p6KVnkbQKLHeHYL/DkOxAbxcPGQIhAOXSDJLrctOpBwdPkJanJWzbPn0TxEW+MYA7Sk/6Sm+1"}]},"_npmUser":{"name":"agonist","email":"ab@agonist.ai"},"directories":{},"maintainers":[{"name":"agonist","email":"ab@agonist.ai"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/vpat-html-renderer_0.1.0_1781537794642_0.7357708695386787"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-15T15:36:34.406Z","0.1.0":"2026-06-15T15:36:34.813Z","modified":"2026-06-15T15:36:35.290Z"},"maintainers":[{"name":"agonist","email":"ab@agonist.ai"}],"description":"Renders VPAT 2.5 INT JSON reports into self-contained, WCAG 2.2 AA-conformant, print-friendly HTML for procurement, regulatory audit, and vendor-website publication.","homepage":"https://github.com/ariada-org/ariada#readme","repository":{"type":"git","url":"git+https://github.com/ariada-org/ariada.git","directory":"packages/ariada-vpat-html-renderer"},"bugs":{"url":"https://github.com/ariada-org/ariada/issues"},"license":"EUPL-1.2","readme":"<!-- SPDX-FileCopyrightText: 2025-2026 Agonist Development AB -->\n<!-- SPDX-License-Identifier: CC-BY-SA-4.0 -->\n\n# @ariada-org/vpat-html-renderer\n\nPure-function renderer that transforms a VPAT (Voluntary Product Accessibility\nTemplate) 2.5 INT (International) JSON report into a single, self-contained,\nWCAG (Web Content Accessibility Guidelines) 2.2 AA-conformant, print-friendly\nHTML document suitable for:\n\n- Email attachment to procurement teams (EU TED — Tenders Electronic Daily,\n  US GSA — General Services Administration, enterprise RFPs — Requests for\n  Proposal)\n- Vendor-website publication at `/accessibility/vpat`\n- Regulatory submission (DIGG Sweden — Myndigheten för digital förvaltning,\n  BFSG Germany — Barrierefreiheitsstärkungsgesetz, and 11 EAA-aligned\n  jurisdictions — European Accessibility Act, Directive (EU) 2019/882)\n- Print-to-PDF for archival via headless Chromium\n\n| Field            | Value                                                        |\n| ---------------- | ------------------------------------------------------------ |\n| Package name     | `@ariada-org/vpat-html-renderer`                             |\n| Version          | 0.1.0                                                        |\n| Licence          | EUPL-1.2 (European Union Public Licence)                     |\n| Runtime          | ECMAScript 2023, ES Modules                                  |\n| Runtime deps     | none — pure string templating                                |\n| Node engines     | `>= 22`                                                      |\n| REUSE-compliant  | yes — `REUSE.toml` + per-file SPDX headers                   |\n| Self-audit (axe) | 0 critical, 0 serious WCAG 2.2 AA violations (axe-core 4.11) |\n| Schema pinned to | VPAT 2.5 INT (`schemaVersion: \"2.5\"`)                        |\n\n## Why HTML and not PDF / DOCX\n\n- Every browser renders HTML; print-to-PDF is one keyboard shortcut away.\n- Single-file checksums travel cleanly through email + procurement portals.\n- HTML can be made accessible at the source; PDF accessibility is famously\n  brittle and DOCX accessibility depends on Word version.\n- A `@media print` stylesheet handles print-to-PDF fidelity without a\n  separate PDF generation pipeline.\n\n## Input schema\n\nThe renderer consumes a `VpatReport` JSON shape conforming to the ITI\n(Information Technology Industry Council) VPAT 2.5 INT template:\n\n- ITI VPAT 2.5 INT template — <https://www.itic.org/policy/accessibility/vpat>\n- JSON Schema URI — `https://schemas.ariada.org/vpat/2.5.json`\n\nThe renderer **strictly pins** `schemaVersion === \"2.5\"` and throws on any\nother value. When the upstream emitter package bumps the schema, this\nrenderer must release a coordinated major version.\n\n## Public API\n\n```ts\nimport { renderVpatHtml } from \"@ariada-org/vpat-html-renderer\";\nimport type {\n  VpatReport,\n  RenderOptions,\n  BrandOptions,\n} from \"@ariada-org/vpat-html-renderer\";\n\nconst report: VpatReport = JSON.parse(/* vpat-2.5.json */);\nconst html: string = renderVpatHtml(report, { locale: \"en\" });\n// → write to disk, HTTP response body, or stdout\n```\n\n### Options\n\n```ts\ninterface RenderOptions {\n  /** BCP 47 locale code. MVP-supported: 'en', 'sv', 'de'. Default 'en'. */\n  locale?: string;\n  /** Vendor brand overrides (logo SVG, primary colour, contact). */\n  brand?: BrandOptions;\n  /** Include AAA-level rows even when 'Not Evaluated'. Default false. */\n  includeAAA?: boolean;\n  /** Warn if evaluationDate older than this many days. Default 365. */\n  freshnessWarningDays?: number;\n  /** Fixed generation timestamp (ISO 8601) → reproducible builds. */\n  generationTimestamp?: string;\n  /** Optional source-JSON URL embedded in JSON-LD + footer. */\n  sourceJsonUrl?: string;\n  /** Soft-warning hook (locale fallback, etc.). */\n  onWarn?: (msg: string) => void;\n}\n\ninterface BrandOptions {\n  vendorName?: string;\n  /** Inline SVG string. Sanitised against scripts/event-handlers. */\n  logoSvg?: string;\n  /** CSS colour literal. Must pass colour-grammar allowlist. */\n  primaryColor?: string;\n  contactEmail?: string;\n  contactUrl?: string;\n}\n```\n\n## Procurement use case — end to end\n\nA Swedish SaaS responding to a Malmö municipality tender. The buyer's\nprocurement officer needs a human-readable VPAT to verify\nDOS-lagen + EN 301 549 + WCAG 2.2 AA conformance before shortlisting.\n\n```ts\nimport { readFileSync, writeFileSync } from \"node:fs\";\nimport { renderVpatHtml } from \"@ariada-org/vpat-html-renderer\";\n\n// 1. Load the JSON VPAT emitted by the scanner / evidence-emitter.\nconst report = JSON.parse(readFileSync(\"./vpat-2.5.json\", \"utf-8\"));\n\n// 2. Render with vendor branding for the cover page.\nconst html = renderVpatHtml(report, {\n  locale: \"sv\",\n  brand: {\n    vendorName: \"Acme SaaS AB\",\n    primaryColor: \"#0b3d91\",\n    contactEmail: \"accessibility@acme.example\",\n  },\n  // Fixed timestamp → reproducible builds → procurement reviewer can\n  // re-render from JSON and verify the file checksum matches.\n  generationTimestamp: \"2026-05-19T00:00:00Z\",\n  // Cite the source JSON URL so DIGG auditors can spot-check.\n  sourceJsonUrl: \"https://acme.example/accessibility/vpat-2026.json\",\n});\n\n// 3. Publish at vendor-website.com/accessibility/vpat-2026.html\n//    or attach to the RFP / TED tender-response email.\nwriteFileSync(\"./public/accessibility/vpat-2026.html\", html, \"utf-8\");\n```\n\nThe rendered HTML:\n\n- opens correctly without network access (offline-friendly for procurement\n  laptops);\n- self-passes axe-core 4.11 WCAG 2.2 AA scans (zero critical / serious\n  violations across 45+ rules);\n- exposes stable anchors (`#wcag-1-1-1`, …) for citation in audit memos;\n- carries a `@media print` stylesheet so Ctrl+P (or Chromium\n  `page.pdf({ format: 'A4' })`) produces an archival PDF with repeating\n  table headers and page numbers;\n- embeds schema.org `TechArticle` + custom `ariada:vpatReport` JSON-LD\n  for vendor-website SEO and machine re-extraction;\n- carries a `<meta name=\"ariada-locale-fallback\">` tag when the requested\n  locale falls back to the default, for telemetry.\n\n## Schema-version rejection\n\nThe renderer is strict about VPAT version drift:\n\n```ts\nimport { renderVpatHtml } from \"@ariada-org/vpat-html-renderer\";\n\nrenderVpatHtml({ schemaVersion: \"2.4\" /* … */ });\n// → Error: Unsupported VPAT schema version: 2.4. Expected 2.5.\n```\n\nWhen ITI publishes VPAT 2.6, the renderer will release a coordinated\nmajor version that pins to the new schema. Old JSON should continue to\nrender via the previous major.\n\n## Layout\n\n```\nsrc/\n  index.ts                       — public exports\n  render-vpat-html.ts            — orchestrator (pure function)\n  types.ts                       — VpatReport + RenderOptions schema\n  escape.ts                      — HTML-escape helper\n  sanitise-svg.ts                — brand-logo SVG sanitiser\n  fpc-mapping.ts                 — FPC ← WCAG SC heuristic mapping\n  locales.ts                     — locale loader with BCP 47 fallback\n  locales/{en,sv,de}.json        — MVP locale dictionaries\n  sections/                      — per-section renderers\n  styles/base.ts                 — inline CSS (light + dark + print)\ntests/\n  *.test.ts                      — Vitest unit + snapshot + self-audit\n  fixtures/                      — sample VpatReport JSON inputs\n  __snapshots__/                 — golden HTML fixtures (en/sv/de)\n```\n\n## Verification (one-shot)\n\n```sh\npnpm install\npnpm -F @ariada-org/vpat-html-renderer build\npnpm -F @ariada-org/vpat-html-renderer test\npnpm -F @ariada-org/vpat-html-renderer typecheck\n```\n\nAll three commands must exit zero before any change ships.\n\n## Licence\n\nEUPL-1.2 — see `LICENSE`. Per-file SPDX (Software Package Data Exchange)\nheaders + `REUSE.toml` keep machine-readable metadata in sync. The EUPL-1.2\nincludes a royalty-free patent grant under §2 to the extent necessary to\nuse the rights granted under the Licence.\n\nTrademark rights are **not** granted by the EUPL. See `TRADEMARK.md`.\n\n## Security\n\nVulnerability reports →\n<https://github.com/ariada-org/ariada/security/advisories/new> or\n`security@ariada.org`. See `SECURITY.md`.\n\n## References\n\n- ITI VPAT 2.5 INT template — <https://www.itic.org/policy/accessibility/vpat>\n- W3C WCAG 2.2 Recommendation — <https://www.w3.org/TR/WCAG22/>\n- ETSI EN 301 549 v3.2.1 — <https://www.etsi.org/deliver/etsi_en/301500_301599/301549/03.02.01_60/en_301549v030201p.pdf>\n- US Section 508 ICT Final Rule (36 CFR 1194) — <https://www.section508.gov>\n- European Accessibility Act, Directive (EU) 2019/882 — <https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32019L0882>\n","readmeFilename":"README.md","_rev":"1-13d839c73e06fbf0cee3b4a070950e0e"}