{"_id":"@atlasent/safeguard-manifest","_rev":"2-357094b910dd42b11cede2d9fae26d82","name":"@atlasent/safeguard-manifest","dist-tags":{"latest":"1.0.1"},"versions":{"1.0.0":{"name":"@atlasent/safeguard-manifest","version":"1.0.0","license":"MIT","_id":"@atlasent/safeguard-manifest@1.0.0","maintainers":[{"name":"bettyc","email":"betty@atlasent.io"}],"dist":{"shasum":"e5599bfd09ec31c5180bc04805de7faca117598a","tarball":"https://registry.npmjs.org/@atlasent/safeguard-manifest/-/safeguard-manifest-1.0.0.tgz","fileCount":6,"integrity":"sha512-UDrYzs3wyvg925NE3aRI/L3Hkkf6nDs/hCGRQ+n40L34kaTpsgzxO8+nbGf4wfr8OmfpoJTA+5Tn35Bvt8Vl2Q==","signatures":[{"sig":"MEUCIHRNaqktPcXObVksk0kSiFUvcIh3lAzxadoL/KdIZlkcAiEAupTj+sonx7p7aR8qkGIj0OaSWY+KGwxhCBECr7bbpsM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25971},"main":"./index.js","types":"./index.d.ts","exports":{".":{"types":"./index.d.ts","default":"./index.js"},"./schema":"./safeguard-manifest.schema.json","./safeguard-manifest.json":"./safeguard-manifest.json"},"gitHead":"8a870053213943ffe4fe7a9ef2a87d05a91c985c","scripts":{"check":"python3 ../../scripts/generate-safeguard-manifest.py --check","generate":"python3 ../../scripts/generate-safeguard-manifest.py"},"_npmUser":{"name":"bettyc","email":"betty@atlasent.io"},"_npmVersion":"10.9.3","description":"Versioned, deterministic projection of the authoritative AtlaSent safeguard package into the design/EXPECTED facts (owner, authority, expected evidence sources, expected gates) for the console SafeguardMap. Carries no runtime observed state. Zero-build, z","directories":{},"_nodeVersion":"22.19.0","publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/safeguard-manifest_1.0.0_1783886214534_0.793213231230897","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"_id":"@atlasent/safeguard-manifest@1.0.1","bugs":{"url":"https://github.com/Atlasent/atlasent/issues"},"dist":{"shasum":"21fa9955fce48b3b5554006b9dae3b481d85bf9b","tarball":"https://registry.npmjs.org/@atlasent/safeguard-manifest/-/safeguard-manifest-1.0.1.tgz","fileCount":6,"integrity":"sha512-ptGaZpA2YdKOGKhL32ozO66KaXkg28LFq2+SP8SR2zzt+buqPWietvpCaN437kRvYMrPiqov8t+7TpAAVLqAOg==","signatures":[{"sig":"MEUCIDAO2y77bZn5jgRLBBb0+BPNsS7tOtCAAJzjAStVQgRtAiEAn2HI1GYRpuliXeuRTNecWDQlw/l52D/Wv3RSKPs8bnI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIFHxomp7yh9SsRMXTl04lQR+VPVS3kL9Pdi1g8SN4mwEAiBXXaa9Qs0rmODEC+86t3P0yraS7coUwZ1wQ8cSIK6vqw=="}],"unpackedSize":25263},"main":"./index.js","name":"@atlasent/safeguard-manifest","types":"./index.d.ts","exports":{".":{"types":"./index.d.ts","default":"./index.js"},"./schema":"./safeguard-manifest.schema.json","./safeguard-manifest.json":"./safeguard-manifest.json"},"gitHead":"89e268e01fc74ed2092f3dedf5f60bd6e70a452c","license":"MIT","scripts":{"check":"python3 ../../scripts/generate-safeguard-manifest.py --check","generate":"python3 ../../scripts/generate-safeguard-manifest.py"},"version":"1.0.1","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:38de2363-57a0-4a95-af68-f5ce89fcbe29"}},"homepage":"https://github.com/Atlasent/atlasent#readme","repository":{"url":"git+https://github.com/Atlasent/atlasent.git","type":"git","directory":"packages/safeguard-manifest"},"_npmVersion":"11.20.0","description":"Versioned, deterministic projection of the authoritative AtlaSent safeguard package into the design/EXPECTED facts (owner, authority, expected evidence sources, expected gates) for the console SafeguardMap. Carries no runtime observed state. Zero-build, z","directories":{},"maintainers":[{"name":"bettyc","email":"betty@atlasent.io"}],"_nodeVersion":"20.20.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/safeguard-manifest_1.0.1_1790304440870_0.4672746929793894"}}},"time":{"created":"2026-07-12T19:56:54.378Z","modified":"2026-09-25T02:47:21.127Z","1.0.0":"2026-07-12T19:56:54.667Z","1.0.1":"2026-09-25T02:47:20.968Z"},"license":"MIT","description":"Versioned, deterministic projection of the authoritative AtlaSent safeguard package into the design/EXPECTED facts (owner, authority, expected evidence sources, expected gates) for the console SafeguardMap. Carries no runtime observed state. Zero-build, z","maintainers":[{"name":"bettyc","email":"betty@atlasent.io"}],"readme":"# @atlasent/safeguard-manifest\n\nVersioned, deterministic projection of the **authoritative safeguard package**\n(`contract/safeguard-pack/`) into the **design / EXPECTED facts** a consumer needs\nto render the console **SafeguardMap** — per protected action: owner, authority,\nexpected evidence sources, and expected gates.\n\n## What this is (and is NOT)\n\n- **IS:** expected/design truth. What each safeguard is *designed to require*.\n- **IS NOT:** runtime observed state. It carries **no** enforcement mode in\n  effect, verification status, coverage, or observed gaps. Those stay live in the\n  runtime and are joined by the consumer.\n\nThe manifest exists so the console never hand-maintains a semantic copy that can\ndrift from the Canon / package. This is the single authoritative feed.\n\n## The three states it enables\n\nThe consumer joins this manifest with live runtime facts to produce a\nreconciliation view over three distinct states:\n\n| State | Source |\n|---|---|\n| **Expected** | this manifest (versioned safeguard package) |\n| **Configured** | runtime — current configuration (enforcement mode, bound bundle) |\n| **Proven** | runtime — execution + verification evidence (verification_events, coverage) |\n\nA safeguard is **not \"covered\"** merely because it is in the package (Expected) or\nconfigured in runtime (Configured) — coverage requires observed runtime + acceptance\nevidence (Proven). Where Expected and Configured/Proven disagree, the consumer\ndisplays the discrepancy as a **gap**; it must not reconcile or reinterpret it.\n\n## Regeneration & determinism\n\nThe JSON is generated by `scripts/generate-safeguard-manifest.py` (in the repo\nroot) from the authoritative YAML. It is **deterministic** — same inputs produce\nbyte-identical output, so CI fails on any unexpected regeneration diff:\n\n```bash\npython3 scripts/generate-safeguard-manifest.py           # regenerate\npython3 scripts/generate-safeguard-manifest.py --check    # CI: fail if stale\n```\n\n**Do not hand-edit `safeguard-manifest.json`.** Change the authoritative\n`contract/safeguard-pack/*` YAML and regenerate.\n\n## Provenance\n\n- `provenance.source_files[]` records the SHA-256 of each authoritative input —\n  identifying the exact inputs deterministically (no volatile git SHA / timestamp\n  in the artifact, so `--check` stays stable).\n- Release/commit provenance is bound **at publish time** via npm `--provenance`\n  (Sigstore keyless, same trust model as the other AtlaSent published packages).\n\n## Distribution & pinning\n\nPublished through the existing packages release path (`v1_1-release.yml` packs +\ncosign-signs every non-private `packages/*` on a version tag). **Consumers pin an\nexplicit `manifest_version` / package version** — never silently consume \"latest\"\n— and validate the manifest against `safeguard-manifest.schema.json`\n(`schema_version` + provenance) before use.\n\n## Usage\n\n```ts\nimport {\n  safeguardManifest,\n  getSafeguardAction,\n  SAFEGUARD_MANIFEST_VERSION,\n} from \"@atlasent/safeguard-manifest\";\n\nconst deploy = getSafeguardAction(\"production.deploy\");\ndeploy?.owner_role;                 // expected owner (design)\ndeploy?.expected_evidence_sources;  // expected evidence sources (design)\n```\n","readmeFilename":"README.md","homepage":"https://github.com/Atlasent/atlasent#readme","repository":{"url":"git+https://github.com/Atlasent/atlasent.git","type":"git","directory":"packages/safeguard-manifest"},"bugs":{"url":"https://github.com/Atlasent/atlasent/issues"}}