{"_id":"@attalabs/vinaya","_rev":"47-8a81431cea94faabedb8eacf304d2c68","name":"@attalabs/vinaya","dist-tags":{"latest":"0.36.0"},"versions":{"0.1.0":{"name":"@attalabs/vinaya","version":"0.1.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"AGPL-3.0-only","_id":"@attalabs/vinaya@0.1.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"92ccef357ea0cb8b88cd3c39014ad19ba44b5062","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.1.0.tgz","fileCount":5,"integrity":"sha512-UqnYy5MUHVbQObGNG2DH+EhhS9NVvXhFqKWAQbdnasKxlH14w+wCO/Ck63RfHFurXBxi6+EiG/dU+GEcNd6soA==","signatures":[{"sig":"MEQCIBNHfuuVmJ+aYaUhWX9dkoMCw8PGUy8Cwy9aytbRuP9aAiBW9vLgLxMGkYCwPcR7KEiLe++5XPHn1/QhaI3XYm6Aow==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":156435},"type":"module","engines":{"node":">=20"},"scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/vinaya/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@atta/aeg-core":"workspace:*","@atta/vinaya-sources":"workspace:*","@atta/typescript-config":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.1.0_1785324106282_0.45313983750286857","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@attalabs/vinaya","version":"0.1.1","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.1.1","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"150afd9cf54ee6c464c367aa4d4c0a9dcb3171b3","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.1.1.tgz","fileCount":5,"integrity":"sha512-LHca4bJs63dmvk70cOYxhdlmcc9znfoJsGrj2g5DwFStPcK4msYqVHt8ZMhVVLghgxEUw0S0pYF1DT1cxhqddg==","signatures":[{"sig":"MEUCIQCbRBrbHknbXJdezCGdNgJsWAHZhZOkbCtvNtlPYcvljwIgSydRaE7/5x10Kvrfxzd3bUPdmkwdECLjC27jOX0QGWI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":174665},"type":"module","engines":{"node":">=20"},"gitHead":"dc8434e9781ad951c997996091c9e54064219e61","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts","typecheck":"tsc --noEmit","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/vinaya/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@atta/aeg-core":"workspace:*","@atta/vinaya-sources":"workspace:*","@atta/typescript-config":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.1.1_1786085674628_0.4399802767486345","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@attalabs/vinaya","version":"0.1.2","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.1.2","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"033c7d2655bad3a0cb7433a9b0e0580db4df80e1","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.1.2.tgz","fileCount":47,"integrity":"sha512-AfqC0hkNfBmDW9fMXu/g3jgI+v9cbUd6vfMK3cvNaS4U7l7RZMB8dex9KDs3EulSENkJfSXXypLsAHtZVhF/2g==","signatures":[{"sig":"MEUCIQDNb7KMbArliqICzi41Z0746KxhyFcM66J1ZLau0KVz2AIgaF8CMksG/2p4qM3RVnTYGyzD145p9SNaqRn7ynDBCUc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2359849},"type":"module","engines":{"node":">=20"},"gitHead":"279a979e7155e0666e30e2df66db35eef04e5402","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts","typecheck":"tsc --noEmit","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/vinaya/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@atta/aeg-core":"workspace:*","@atta/vinaya-sources":"workspace:*","@atta/typescript-config":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.1.2_1786115714604_0.8108673695156368","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@attalabs/vinaya","version":"0.1.3","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.1.3","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"48c938428783345b267e29c65b9aabccaf9a385a","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.1.3.tgz","fileCount":47,"integrity":"sha512-Ys7YhabSoN+WjWxKNlgksmILOToDMqi1cYZK8WjM5+MgbZxzfKELmxUsCOcMf6YpVzSnwu/9bio1yi5JvTMrHw==","signatures":[{"sig":"MEUCIQC04HqxJs1GwOsp5s3Ww/nBaIDIpZyv55FaXQyOQTePZgIgdEY5EX7MddizD5jmf/mGdN9F19+WZBjv3IHIH9TLFJ4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2359919},"type":"module","engines":{"node":">=20"},"gitHead":"0f326b50fa60748ac984e1e25db578110d966186","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts","typecheck":"tsc --noEmit","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/vinaya/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@atta/aeg-core":"workspace:*","@atta/vinaya-sources":"workspace:*","@atta/typescript-config":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.1.3_1786121400155_0.0073609768464091285","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@attalabs/vinaya","version":"0.2.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.2.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"9d2f5dd7040d5eba239c6cd68b76d3b384ff54e7","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.2.0.tgz","fileCount":47,"integrity":"sha512-uGCGcZZNvmoVK3meDmidwKOQj06jjChjSmnoY1d+wtt9F8ikVjSW0nuRevqo5qf5B6h7lxisJXXSLaciw0i7ZA==","signatures":[{"sig":"MEQCIEk0oxO9QEkeLXfeKc08jycdgvU1SkReZ019Y7m/QfjsAiAVYdvwulVhHF1Tl8Zy2/Ujmeep9EQ4uKL1ZYfECuKm0Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2369958},"type":"module","engines":{"node":">=20"},"gitHead":"54e33c1d8bf5ff2d1e9b28885ce07290c1147c70","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts","typecheck":"tsc --noEmit","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/vinaya/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@atta/aeg-core":"workspace:*","@atta/vinaya-sources":"workspace:*","@atta/typescript-config":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.2.0_1786162835639_0.1309372538515805","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@attalabs/vinaya","version":"0.3.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.3.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"8d241eeff343b956485bc1f448d9461b15f0d37a","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.3.0.tgz","fileCount":47,"integrity":"sha512-ex5QQxCDsK4eZxejc7bbnTHCmdAoSMcsrs/XIIFXXVAmVLUhDZ0qFAN4I/a55YcMJH/zv+gxzEK2+Ij92XbvNQ==","signatures":[{"sig":"MEUCIQDammPCbJbTeqTDOoLD2cYmnKbmw5Ai6tlyQyc0KDOkigIgVS16eW/xCBcb+VV4eRU/p6zQK4ThRqWAFLvWbgY5mqo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2418434},"type":"module","engines":{"node":">=20"},"gitHead":"904a5df665ee48edace85281869083c1316a4ac0","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts","typecheck":"tsc --noEmit","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/vinaya/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@atta/aeg-core":"workspace:*","@atta/vinaya-sources":"workspace:*","@atta/typescript-config":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.3.0_1786188287424_0.42909034955059777","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@attalabs/vinaya","version":"0.4.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.4.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"23a17865dd15a227928924650f15f536fd741ad0","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.4.0.tgz","fileCount":47,"integrity":"sha512-7AgOGawGTHGIhSCj0p2T03R0Df8yOHLw4sYqsaJBGM5wTWt+igiVl0T0hhXKJHDtTcvyg3BeAZTXtELpK+ip9Q==","signatures":[{"sig":"MEUCIEupf9iHEF6SOkqedxOKRRg27YylbkII1E4QeqvEqvXVAiEA++Qruel/2+XJ9629xUcFWYtXAF0RlP2JUKBz70noR80=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2441651},"type":"module","engines":{"node":">=20"},"gitHead":"915f1ba8c39e3eb1f9119107fa82fc63d5057f6c","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts","typecheck":"tsc --noEmit","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/vinaya/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@atta/aeg-core":"workspace:*","@atta/vinaya-sources":"workspace:*","@atta/typescript-config":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.4.0_1786267221525_0.7268198207665835","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"@attalabs/vinaya","version":"0.4.1","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.4.1","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"bbaba2b1be7e18db6de73e05ff7854a103d8c85e","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.4.1.tgz","fileCount":47,"integrity":"sha512-AJjwX+B9m4DW/Tga+0tm43y+oEcz0IpaPaxPsiI1NOSamF/7suWP6hjULQgvulIa9Hc8NF5Ljxghw2ZSDRjykA==","signatures":[{"sig":"MEQCIA8neIgsjnEOPkFYs++uOZoTNcjGDI3n9RpSvIJI5xgaAiAKWiF+VQI6fd+7Xj/SGD4SZHHTKNDGeFi7/c47I3dOlw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2441879},"type":"module","engines":{"node":">=20"},"gitHead":"2e68ba06e54a2387e9aedf857b41c4cd75755b1e","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts","typecheck":"tsc --noEmit","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/vinaya/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@atta/aeg-core":"workspace:*","@atta/vinaya-sources":"workspace:*","@atta/typescript-config":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.4.1_1786268521001_0.23217541111953355","host":"s3://npm-registry-packages-npm-production"}},"0.4.2":{"name":"@attalabs/vinaya","version":"0.4.2","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.4.2","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"1f34cf13c1c0e11c4a79ba8e2e0879eee7430e8a","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.4.2.tgz","fileCount":1861,"integrity":"sha512-m/kc4QU7KYL19BFnSmFVSWfqJXJhRmMumw3+xT7UYJ0VZ3vQZ52fbTuuwweESjdsMgss+NT4UJOcdXDwFNW+fQ==","signatures":[{"sig":"MEUCIQCBJMy/hVzUJXlYKJsghi/uInkRw3O21o/X2IE3l2uzwgIgTfHXzcXOd3W+XO5TjtCNDD3TeV1YTOcf957aNYjB7Dk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":87283869},"type":"module","engines":{"node":">=20"},"gitHead":"d54c841909398a242cae9b7639449d9f282f4b55","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/vinaya/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@atta/aeg-core":"workspace:*","@atta/vinaya-sources":"workspace:*","@atta/typescript-config":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.4.2_1786420369026_0.7039436365338438","host":"s3://npm-registry-packages-npm-production"}},"0.4.3":{"name":"@attalabs/vinaya","version":"0.4.3","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.4.3","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"dae7b0be33d6706fd38e59962604eaaa10ed07b8","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.4.3.tgz","fileCount":2355,"integrity":"sha512-PloimWH+iTaj93xUO31CP63rt9VoNgsW2zBnEtwAtyxgPnEfY5Uq6aGGntM5MjvTbyQswOxjfM2emHXBMzz08g==","signatures":[{"sig":"MEUCIQCMMqsfet2H0L6t4IoM0/0txiNuwhQKjm0eIbe3IuvldAIgVv2UmJqyIyWiwAOubTJIQUs1dHcvFJbidvK93n4AnZY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":99596292},"type":"module","engines":{"node":">=20"},"gitHead":"1a86ce8692fbe1e925b6e028805b64a73a2c4b61","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/vinaya/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@atta/aeg-core":"workspace:*","@atta/vinaya-sources":"workspace:*","@atta/typescript-config":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.4.3_1786437261973_0.1811676980633179","host":"s3://npm-registry-packages-npm-production"}},"0.4.4":{"name":"@attalabs/vinaya","version":"0.4.4","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.4.4","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"5429105a870b89db1b00a4b3df0aa16339b53927","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.4.4.tgz","fileCount":2447,"integrity":"sha512-zZHE8PtRgKAtO1E4hxkoolNtFsrKPK78bDWuBgWaEftGGi9uMBgFHcbm+Cnh/hQrv7dfQfLfXUdxgYqsG9DcPg==","signatures":[{"sig":"MEYCIQDB+pWXo7CgLwSsq7Kew9+Ei43SqmBRaOxtYL98+ypR2QIhAMitk+Ob0JwOC8Y+AUac8P5+huIAzb+J+UqJyQ3XWaQp","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":101487848},"type":"module","engines":{"node":">=20"},"gitHead":"90d51903a074f7c4879f1329ecefa9623855dbd6","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/vinaya/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@atta/aeg-core":"workspace:*","@atta/vinaya-sources":"workspace:*","@atta/typescript-config":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.4.4_1786521129502_0.48528022826262784","host":"s3://npm-registry-packages-npm-production"}},"0.4.5":{"name":"@attalabs/vinaya","version":"0.4.5","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.4.5","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"9f88009bfb0968899ad6c86695cb6b39243b347e","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.4.5.tgz","fileCount":2539,"integrity":"sha512-38uV9MDlcj8t5XmVENuN9yKg8rnEY2rEP3sXEjkUJlQDkh4CaAX2vTGhbCydW4IcpC05j6meLsn38SPx5qbvhQ==","signatures":[{"sig":"MEUCIQD9SE9Va+Sul9I1SlM9n+ev+Xny9CagjTtkINxGbtxQZQIgHppjKghjVh28e3ocVjpBew8pSCMLtUCFSlqcernZ6gc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":103382260},"type":"module","engines":{"node":">=20"},"gitHead":"6c8b8841224b0aa0a30eab2ff25ee4b251be977b","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/vinaya/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@atta/aeg-core":"workspace:*","@atta/vinaya-sources":"workspace:*","@atta/typescript-config":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.4.5_1786586298615_0.9451294688025738","host":"s3://npm-registry-packages-npm-production"}},"0.4.6":{"name":"@attalabs/vinaya","version":"0.4.6","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.4.6","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"dfee75063d3c75a05f5a0c76f61bdf671bae30cb","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.4.6.tgz","fileCount":1788,"integrity":"sha512-R5Cw//KpxwAb8pwqASUaZ3NXADGDHaLXx3/sByosm/7Xb0kq3qRtHpQWBlh7D7/rmQEb97tZ3XBai9x8/hUK0Q==","signatures":[{"sig":"MEYCIQDqCRXWrecp87nBRBprvt3IPwwPux+WIKRqTPhppSxD+wIhAOmdJG6qm8J1HrUmDZr0zZg4D0yCiYhf7xnpY01FyWue","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":85713172},"type":"module","engines":{"node":">=20"},"scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/vinaya/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@atta/aeg-core":"workspace:*","@atta/vinaya-sources":"workspace:*","@atta/typescript-config":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.4.6_1786601394088_0.06306100044317331","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@attalabs/vinaya","version":"0.5.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.5.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"48b74f7d23a6e8e374ec580881debd975bbc66b8","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.5.0.tgz","fileCount":47,"integrity":"sha512-gre7/ckzpbLFHUE2se4DqNPoqrK7/2833mAaMfCYcVYBIrbsDEFpiIYyu41oi2i2p2OJA8t254/xkdmKh49d1A==","signatures":[{"sig":"MEQCIEwrM/SUtpeAewYsAm9S9f2vykqnbQHfOhdBjTe/qvT9AiAj3sWvQk4u1hCzkP1QoGr9ZPivOo9F8er+cb61nEZPGw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2581244},"type":"module","engines":{"node":">=20"},"gitHead":"d4bca05d6ec94d42601364472ed1dbf17194cde9","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts","typecheck":"tsc --noEmit","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/vinaya/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@atta/aeg-core":"workspace:*","@atta/vinaya-sources":"workspace:*","@atta/typescript-config":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.5.0_1786769723764_0.9414091776074403","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@attalabs/vinaya","version":"0.6.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.6.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"1b654f5341aa0854e8dd01ff4abf8cf9af5b860c","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.6.0.tgz","fileCount":47,"integrity":"sha512-RXGtviUoUBaz9rgPGjr2uNdssOlbIhPKK3BIWKP0UolStsJIluVKNz9WMgbTB5yg9pAiwS0SMtb6q9gkw2Hk+Q==","signatures":[{"sig":"MEQCICmdhQyKZTkPNayPnOJsgq8sNy078O20+iQrmyX/m6JgAiAKbY7tHAAWqsmNtnfQEqfUvNQ9Ypr+OyIDMzQpbMOBkg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2608005},"type":"module","engines":{"node":">=20"},"gitHead":"4bcec0694c291c9642895f75ba0c4962dd8fc757","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts","typecheck":"tsc --noEmit","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/vinaya/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@atta/aeg-core":"workspace:*","@atta/vinaya-sources":"workspace:*","@atta/typescript-config":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.6.0_1786856524470_0.982213937615755","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@attalabs/vinaya","version":"0.7.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.7.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"ec453316760071d509284c894c2f58c46ed41136","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.7.0.tgz","fileCount":47,"integrity":"sha512-3MwZNy+o5gaPcM4HHysYRAesIBYUTF4vw7PpxyuTp11UgTjdq0d5EAhldxnNPAg6mNKDTQXhNMa1WJOCzprCew==","signatures":[{"sig":"MEUCIESKmdXr78onQuuH4yZWFcH+mhyrRdN5qNfcjJsuAlVAAiEAjgKtqFU8THRWXAyczyoa/UlJ+X9aCDZBT6Zw6oU9sFo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2615548},"type":"module","engines":{"node":">=20"},"gitHead":"edc17a2cb734d11c54109b354012fd77e41c40e0","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts","typecheck":"tsc --noEmit","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/vinaya/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@atta/aeg-core":"workspace:*","@atta/vinaya-sources":"workspace:*","@atta/typescript-config":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.7.0_1786869921345_0.7829810578685206","host":"s3://npm-registry-packages-npm-production"}},"0.7.1":{"name":"@attalabs/vinaya","version":"0.7.1","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.7.1","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"db9469cd9a2146c8df84e6d1adadfbb837193896","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.7.1.tgz","fileCount":48,"integrity":"sha512-rgsQrbmpwLrA6gS++ivZgKWKQk/B+FiMOWlcaL6LYtrv4NVr/N/THKH89FlabSLTZ+zw0qAYbvD5g1DdUbceoQ==","signatures":[{"sig":"MEUCIQCOIhZh8j8e3uN06xEbovD3wT0GdCpN/BaqDZbC/YmzHgIganhxlmdCUYkUIYuGvad4ETcQvHqG94ywEg2d3FzsuNI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2634024},"type":"module","engines":{"node":">=20"},"gitHead":"fb0a0c5479c71add2ab8cef8258512112284f828","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts","typecheck":"tsc --noEmit","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/vinaya/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@atta/aeg-core":"workspace:*","@atta/vinaya-sources":"workspace:*","@atta/typescript-config":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.7.1_1786881703332_0.17335815839436797","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@attalabs/vinaya","version":"0.8.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.8.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"cd11a69acb6498154b6b5a5c2f711a694ee129b9","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.8.0.tgz","fileCount":48,"integrity":"sha512-1hWEbiTFErc0qTJPZaZcAOb27/yRYktG2APvVh2VXth5ixrAaCPl0p19/wrGC8HtkJ6A2Ajy8W0/Ly/Qq/RnzA==","signatures":[{"sig":"MEQCID3woeoP7E+yHPG5UR2Sow20TZsvykvdt/Dg8ZO3TzMJAiAE6QIMP1umIBtIEezRilqBQX59oeBQH4c9NhQkGlE2rA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2640934},"type":"module","engines":{"node":">=20"},"gitHead":"82d3fe59d4ea8316c7f325cf947898c45d7e5491","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/vinaya/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@atta/aeg-core":"workspace:*","@atta/vinaya-sources":"workspace:*","@atta/aeg-forge-state":"workspace:*","@atta/typescript-config":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.8.0_1786889494567_0.19778701626813677","host":"s3://npm-registry-packages-npm-production"}},"0.8.1":{"name":"@attalabs/vinaya","version":"0.8.1","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.8.1","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"97c7eea237b58f5ceec8568310e756d3e1666885","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.8.1.tgz","fileCount":48,"integrity":"sha512-HrmPWpR0vfwneWuaDCWSOs1f4bc5Co3SD//bsWe2ZPasRx98TdJO9FeGNyJCOW8BNmGjOrhY7Z7mAX/6VjlWlw==","signatures":[{"sig":"MEYCIQCDvS3tXpAVfGNfuXhyTJYw8NGghXWyYxy1m+vMWi1DkQIhAOukmg00fWU5sVPh6P/kcqvxcXcv77dbecc7GJIDoX3B","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2677616},"type":"module","engines":{"node":">=20"},"gitHead":"4ca5e034c57cd92bf38885270361239fc57d4942","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/vinaya/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.8.1_1786934368817_0.14151490919522058","host":"s3://npm-registry-packages-npm-production"}},"0.8.2":{"name":"@attalabs/vinaya","version":"0.8.2","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.8.2","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"a221688c1977576b6f75d0275d0d81f6781c44e1","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.8.2.tgz","fileCount":48,"integrity":"sha512-hahWcPVb91GWQKmYwat0b7DJQgs8sn11xMWuD9CNyOMz7n/ioJyIMNXljWMWyuTJ40YVVTPXAbWw+4hUSzVdVA==","signatures":[{"sig":"MEUCIQCnveeQpaTnjPpBLngOQiaXcjKHMVVJ6r1QWT6nljdc5wIgBUKG0N0o5T5AXqwlMrg3sf5dbUiLTwjYrsg/qZVouSE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2678418},"type":"module","engines":{"node":">=20"},"gitHead":"d9e995bddcca4baff5e03159ca4dfb5131ac704c","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/vinaya/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.8.2_1786944645399_0.21707179126275178","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"@attalabs/vinaya","version":"0.9.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.9.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"c11ad75beaaf2cc14db0a8b07168b1f1f0a35712","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.9.0.tgz","fileCount":1472,"integrity":"sha512-eLdson8dOkQe0Vk9pogSO8qwX9mXz7NET7jv0oYhAHqtrNmi5tQfBak2HWPKhYUULmvyaa7CLAxgYtJTrcZWTA==","signatures":[{"sig":"MEQCIEkP3FIq+PL+UDgmiE7crUpfjFYXq4ve5oZOPWVAQGZHAiBcz/gNzskZMli/MbzqcE+IaEi92aPWbuOVLUSszz74GA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":81860299},"type":"module","engines":{"node":">=20"},"gitHead":"2f1802f08164382b1e994f0876105af881f651bf","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.9.0_1786964191442_0.35990448134543795","host":"s3://npm-registry-packages-npm-production"}},"0.12.0":{"name":"@attalabs/vinaya","version":"0.12.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.12.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"20e9b70f0d535a337736409218119158393d8ebe","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.12.0.tgz","fileCount":1472,"integrity":"sha512-GOaDpB+KxmQMOqCoP9pIF4y9BewI4WgVOqgiVbw74WVBu8x18LnGm+sp0O5u0bQdCRoBwYYQDJD1wvGt68E2QQ==","signatures":[{"sig":"MEUCIQC+VC+ypFXH9VK9U33Fah2T1gAcElPWf1InQZyJMwiHDAIgX3xnArggkzw6w5ZVL1dhr8R/AwyxjbRRKB2cC7YgU7U=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":82088330},"type":"module","engines":{"node":">=20"},"gitHead":"5d26e20d76516ae5362b16beafefbe98697bfd07","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.12.0_1787051245575_0.7123832688461971","host":"s3://npm-registry-packages-npm-production"}},"0.16.0":{"name":"@attalabs/vinaya","version":"0.16.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.16.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"a40e47965afc0674d4630ee0dacab36999f0d812","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.16.0.tgz","fileCount":1472,"integrity":"sha512-qs1FdjvbCqzIfOo5kWBehY+TxYpuIBu/WIIJmo1s1qblxJ3/0TuIFpybdYlo+hTTf6FkctecBgE/j9MHJ34Iyg==","signatures":[{"sig":"MEQCIGLHN0wWvL7dNysitpy4OXr4kWv4URC0AK8Ye9L+i4I3AiAPAk3KNncb/MYYbZxhdW1wNmjBakSKmDaTz7AvXMxk7g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":82144819},"type":"module","engines":{"node":">=20"},"gitHead":"6b512b379ab2e95186cb27a9ef45c4f586a1854a","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.16.0_1787119158308_0.6812770809698612","host":"s3://npm-registry-packages-npm-production"}},"0.17.0":{"name":"@attalabs/vinaya","version":"0.17.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.17.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"cfbe254d993d410eb218a68ea8afd5ddbcc8adc3","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.17.0.tgz","fileCount":1473,"integrity":"sha512-zFGSBerEx0eYbqOexRaqLx/R2Vlu/MXI7yFNP4rQayM5rQ4Na/h25JWDDMaCDJ5+IMU4sbmN6IeGRO+U9ZaEJA==","signatures":[{"sig":"MEQCIH5FrH0AOiRGgkqXxt5LtwwKBsYLiqY92D4KF0fjtDfjAiB8ZgW8jRl5gQ15yIj3l+MVdOTQk67al2+8bwWVqjQBvQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIDT5uAJPWc16yAozjkvWR73XfLxY7F2YmZE++aoUon5bAiAzN+trGzrUNhvV6v4TvB8o3aP23zzTcFSvAa7D5AD/JQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":82321503},"type":"module","engines":{"node":">=20"},"gitHead":"0584f82bd4fcb9413bcfd8dc0abaeabc43bec7a3","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.17.0_1787375333455_0.7122377995136162","host":"s3://npm-registry-packages-npm-production"}},"0.17.1":{"name":"@attalabs/vinaya","version":"0.17.1","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.17.1","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"75aa73b83ed2b0d583e4d75bb276a1dd97db0035","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.17.1.tgz","fileCount":1473,"integrity":"sha512-IB5vmNem+SilbUBzpz+bc/IUsle27OwZX9y45Dus3+TKj1d/ptB39OpYgRVatHHzIr35vxkfKmhzEIQ8MNAu/w==","signatures":[{"sig":"MEYCIQCIvzEL3YE5FreBbSnkBHiVVd+92P0bbMu5Yojr/dsMtwIhALWmukpQymzhJxzBBH/bg7woi+SHf9Npdam02LmTNORv","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIC8eNNQt8xMxUjKMktg+VDcyqr8GKfb/CN1yU6aYPgzoAiBMFeyTIy591UXoq50iiJOtiNA3iC1xIHdpk9idPB4+AQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":82321503},"type":"module","engines":{"node":">=20"},"gitHead":"51f978ecda281f66e89f4dfbdf2b614d8d943e69","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.17.1_1787375989879_0.611131823305312","host":"s3://npm-registry-packages-npm-production"}},"0.18.0":{"name":"@attalabs/vinaya","version":"0.18.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.18.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"e098e2c5d6814c45dc8923393be314fb307e813a","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.18.0.tgz","fileCount":1473,"integrity":"sha512-2vTGG3LZXFC2sGAsKl6j0VmPjfeFtWD4cpBW7JLeLf2FXnyhnXH/NTpOQkvm387GBNU2WDdYWMJn51dVrpT65Q==","signatures":[{"sig":"MEQCIFFjZ/1jgIacBhAYoO7b0plgVRGS5016IeqerCZKiTgeAiA0ylqpcd4PQpU8Z3NPrkOJ1yrs/+JMRQcMF5gtycksrQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIGmuppKxSoZ71hRMC5mQF7NCC0dF1SwANU9UtbPU0xl2AiEA8kUJn6UoYRiNvzFqKFoZiUwThusjmw0ml34V13anKO4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":82332877},"type":"module","engines":{"node":">=20"},"gitHead":"f7f92c5724c99d27064eaf4d6148021abbe319ec","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.18.0_1787488164829_0.32637372586096514","host":"s3://npm-registry-packages-npm-production"}},"0.19.0":{"name":"@attalabs/vinaya","version":"0.19.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.19.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"a680115e8261b6a93be83e17785e6f1b48620385","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.19.0.tgz","fileCount":1475,"integrity":"sha512-42Nxe2og/8+0XqA16wET6QwuYS/9uKWsVJxDaN0oP1NfRpA0X2MUJKb2Zue7XezAdlgoluQyVeCG0s3/qa/sHg==","signatures":[{"sig":"MEYCIQC7fVPWzLmrgzO11y5W7kRA8boVqOf9KjJTj2pM4no8YAIhAM5T+toedLYN4rMaFwFPPYL3U0fwbdRBfnjVkJiN7X4v","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIFXgdLN6ek/u9mSJ6qgVJ4gOfoq5f4rh9paiTDJ8Ab52AiEAwsATk+PMMeHFVmNhZl3XPJf+z1iFqgHQokxU6nUJ034=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":82413861},"type":"module","engines":{"node":">=20"},"gitHead":"7d6be52f090b4b8f7c853ad86200e1cfa2bb4fa2","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.19.0_1787555507486_0.2557932676970234","host":"s3://npm-registry-packages-npm-production"}},"0.19.1":{"name":"@attalabs/vinaya","version":"0.19.1","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.19.1","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"1737953b326aabbec09051736ac24452fd3f6d9d","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.19.1.tgz","fileCount":1478,"integrity":"sha512-zx8hrW0zPL9Zv2l4G0xnyQlfHTaNLcZkhC5YT8X9Xwiizv1qTt84AVmLgDOGNoYu8w73sPulhGW7y/iq1pHnRg==","signatures":[{"sig":"MEUCIQD5M/qENyFgnXQ9yNXagwrJqHOoGvUGQpmRt95RHWqytgIgbtAAbd5nUhzGp7Gg2NIOpJN67K9+yuKP17d495lMTM0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQC55EYOiyjE19no8vN1paZXQFsIrkX/WCahnLcUzz1uRAIhAKnFA387C5cRKr5jonGpkx2EbH3+c0l+gDdy4FpLIzfC","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":82675391},"type":"module","engines":{"node":">=20"},"gitHead":"f66fa81788307307704d955f5966f6057c1aba6e","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.19.1_1787621000383_0.7429753587549062","host":"s3://npm-registry-packages-npm-production"}},"0.19.2":{"name":"@attalabs/vinaya","version":"0.19.2","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.19.2","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"8eb8c7aa853a5f6163ae0ac1156b3711aa5640bb","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.19.2.tgz","fileCount":1480,"integrity":"sha512-0VSM4wCaANuC82o15kDWQyAVcb18p8CXo4Y8awTfgH8yqqSs8zFNtcB2Sp9RMmB8ruFQnqrJc2BeL26uNZgn2A==","signatures":[{"sig":"MEUCIBWKkdjys6XlM18NeXcGwH1loq1ea8vApljl/hbAFAYBAiEAgoBD5i1GxQK/taQ1hOW+ZYB7JtwfJpJUcM1b11HoFj8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQCzP3hPhTjPE9mNZ8woHy8Las6U2ztLM/5J5IWBKgwKmAIgGlJVTYGEnZLf/agbexOTBI6o9aG4Gg+cgD61L3s5/UI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":82691063},"type":"module","engines":{"node":">=20"},"gitHead":"21afd0987c90f2ebfebd362ab5d1f82b9451f185","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.19.2_1787655679302_0.3974219613409953","host":"s3://npm-registry-packages-npm-production"}},"0.19.3":{"name":"@attalabs/vinaya","version":"0.19.3","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.19.3","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"115cd9b786060ab16c9d0cdcb7e2600657d6fac1","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.19.3.tgz","fileCount":1406,"integrity":"sha512-jAbP/nwdiUYEJurs8A+69Z5mBfiVkqXCW5lXuzyDKgMJ1iB4NbmpcI6A5PoZrp7ZQBhdTQINQ/xARCYUv9XpRA==","signatures":[{"sig":"MEUCIQDF1FlfJKK/zv0xy1c4hm7GNljuhqZLgMOIaBDDP63kqgIgF1WKAWWTkLw9i9f/DAaLC3mWwM04MVzS85JbqpuWQp0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQDLoO+qpWjJaMK86dPLizc4pLE9jzv9U8eGh0x8JFLStgIgNCwcC1VXuaxNLRcnlsawUvOzvirzLSmO1NIGtd5J4R8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":90273252},"type":"module","engines":{"node":">=20"},"gitHead":"f7c89ad08918bc5e677826251a30c68e386ab35f","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.19.3_1787818774074_0.9904545456854845","host":"s3://npm-registry-packages-npm-production"}},"0.20.1":{"name":"@attalabs/vinaya","version":"0.20.1","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.20.1","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"3596e79e0a13942e1abaf96033d6f00afebef7a9","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.20.1.tgz","fileCount":1407,"integrity":"sha512-IMpud5ecK7K/GhwIfuQHHjZ1N+5EIBLah2BW5U7hjL5av0KdlqWrA4ivw/g/Zi+cuW+HdKWhSqwb56tXbXX21A==","signatures":[{"sig":"MEYCIQDeNcvNV93lxB+LgNiNpyjLIBs8jcqmwDQxHgQ3hkeaegIhAMaV1mlrkgdif4lYosgCG8db2mX9mtPDbJAOdFJz+8Ly","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIA6NCN7EQliJsa2INLe4PefTvhQ4ndjy6Fz1TL7DseulAiEA6v7IT3kOD9sgB5ve4uSfJOXFt1tjkDTfS5DT+4XfKCU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":90759268},"type":"module","engines":{"node":">=20"},"gitHead":"1b45fe47f74a51adf30a4c3bff509449bb830b51","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.20.1_1788001816815_0.8291135258488007","host":"s3://npm-registry-packages-npm-production"}},"0.21.0":{"name":"@attalabs/vinaya","version":"0.21.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.21.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"19aa286dc38fc3b6ecfb4e0c266d3e6a3f59a346","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.21.0.tgz","fileCount":1410,"integrity":"sha512-ahs0RP5svtPW2mqQu7aMaQqlDBdPOIzPiaA3wGk17c+OE0jJEWzNI5EWOUrXnkExoIsV2keeiIiITA+QuIzowg==","signatures":[{"sig":"MEYCIQCG04nveoCJuR33bVSbxipO7gH1TMs+MQC39SGsxHE0PwIhAL59862w7r+OL7y1x/5ydTMcDqxvc61b4IPev+aWVwzj","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCICnu4hy3q7HJmDKKhQP3miWQyy8IBtgmwBxGh9YYGU6kAiBz8g1FT5BUnfu8/RcryXKRdjwEoiL06OnakPqU0uml8A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":91560311},"type":"module","engines":{"node":">=20"},"gitHead":"032fd7d4f924b499bdc52196e3e518eb7da0173d","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.21.0_1788243868409_0.12858111204969003","host":"s3://npm-registry-packages-npm-production"}},"0.22.0":{"name":"@attalabs/vinaya","version":"0.22.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.22.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"6a5bc3de8097e347dcbdbcc2eedca66f2eb7cfc0","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.22.0.tgz","fileCount":1411,"integrity":"sha512-utti7KTWEoja8VXp80MuLlvZmmS+eNbo7ht8sBzTGQ56Vza0GliETU8jeldysWj9aoLuwsdwYWuLbTgpdkWzzg==","signatures":[{"sig":"MEUCIEF9fIrn3TTsMMxN8B7PHzK781V9zLxMxpJtWE5ukz06AiEA520lMNnU0GmG8ZaxuYZGM/fAXt7yFW5mDpD90T/PtXI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIDsSBIZYUiH6nMGeFrIIhJHyjmilw5n9cmvjQg1MFXHhAiBwVMmng+uAJTvi3L5NK7nv5f5kLKu5tbOnnlxk3ZAaUw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":91818273},"type":"module","engines":{"node":">=20"},"gitHead":"4a03bef52fa203dd2352d73cdfb67f5b604eafce","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.22.0_1788283372175_0.443638348002078","host":"s3://npm-registry-packages-npm-production"}},"0.23.0":{"name":"@attalabs/vinaya","version":"0.23.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.23.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"64d2ad47480be81cb30d9ae02da5d8afc1c15c5d","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.23.0.tgz","fileCount":1485,"integrity":"sha512-8AKqzdma204uhy7s5pSrUxGwOjkFAkzT+9qaEF0G02EjP6TqOKbZsSN0DKlzkEBz1skNiOtahHdhOB6bflFiBw==","signatures":[{"sig":"MEUCIQDtlvX1icpUX0t7muBbgV9zRo+3mP2mZY+R5rshX7IzGwIgFwdqDg6eHW7DL8hgVBfg9mqIgGvYEa3ION1ymWe9UHY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQC7I3z5O8kzXmSEZlBdCEzC7FpLE4RxFE2cbnaSwa06dgIgFJhr3YOR3vHpeTqUzgaCdSXQ5BAvmRlE0oW+0jwCmis=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":93620049},"type":"module","engines":{"node":">=20"},"gitHead":"23b6edf24339af336ca63029d5876be336adb308","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.23.0_1788511217623_0.026919065740560022","host":"s3://npm-registry-packages-npm-production"}},"0.24.0":{"name":"@attalabs/vinaya","version":"0.24.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.24.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"54a0398ec7c65a096ad166a1304c0503bd9598ca","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.24.0.tgz","fileCount":1490,"integrity":"sha512-1yiSVa8EnnjcTX3ZjbSWY+xgsHpFg9h4qliLvYdGUeew7wLVPYYbE42I//rceeMeNIU+2z+qYzPiqg8Gge6Quw==","signatures":[{"sig":"MEYCIQDm/mCk4qS+iV0NLFGkRBaFWSvW5m66egbXDJLdXO1pUQIhAPLCoRzHp7MaQ7w0GU5DazpVpjyAUMSNgFHO7kbd5zoh","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIAdoxv7DrRpCIyhVEvBbzSvdw5T/7dLr07CnLPY1upNSAiBjfE+CRhwGh85a0af4ZD2pUEWk1OtLq0ES3XPCPyM0JA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":93741272},"type":"module","engines":{"node":">=20"},"gitHead":"7d3cc56b1bc570e734dcfd48031ea864ea3b31bb","scripts":{"lint":"biome check src tests scripts","test":"bun test","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.24.0_1788524867475_0.9823104672309884","host":"s3://npm-registry-packages-npm-production"}},"0.24.1":{"name":"@attalabs/vinaya","version":"0.24.1","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.24.1","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"76b1fbe23ab545dd2076c69a85429fd9d503b08a","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.24.1.tgz","fileCount":1490,"integrity":"sha512-57edUL7qBKtmTMK2kZyRKGAew8lXZ4KF6Ltyc24imCnV59HBdBoB0HpNw1Hb05zRYIuYoN/I7GzAReIIYkM09A==","signatures":[{"sig":"MEUCIE9oJ1F6rKE2/GoTmVIscDPQKeNBWQuRCuHD4vJG37VhAiEA5v+aJTnUhUX912yKC/M8GgP5/DsCAqmqPz0rP1+qWkE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQDZ4ohaq6mPbIhDD1lSueDetfvN9NAP54o9NPccJbH3nQIhALUqxaohqpmlrh1ZzgoZeB0fdAxCvGRg2hSXb9Hr47Yc","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":93744926},"type":"module","engines":{"node":">=20"},"gitHead":"b032bc2f91244eb4e85fcf2a55d67e42d1bc81c0","scripts":{"lint":"biome check src tests scripts","test":"bun test --timeout=30000","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.24.1_1788538186395_0.45042047498548743","host":"s3://npm-registry-packages-npm-production"}},"0.25.0":{"name":"@attalabs/vinaya","version":"0.25.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.25.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"384e9122cffa44d03ff0b6a08827270a72596077","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.25.0.tgz","fileCount":1490,"integrity":"sha512-VdsSqbjGr7JqmQwLVmdEImjspWEby6456IcuC3sJM/yxENSyqZd26ZKpBpCRYlZkWQiQtJQUJtyHRB945y5EDQ==","signatures":[{"sig":"MEUCIQCv6rBQxv4Kl/2m2mSZbhryje1L6yptQFW8QnUt1xSCKAIgDUZH0ykokcxY2MbhRUf8fTJo/KACsuuKKeW4Q3e/zXo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCHx+6jvSE2O7piDrDetMeGyN84GwNJtScgHg0vYrExKICIQC7zr7J7PdouyTZUMrDHrqRq317C5osAF4rFgLIrZAkRA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":94536503},"type":"module","engines":{"node":">=20"},"gitHead":"7e3f64cb0bb7672b1838fa36d69e2ac984f980e3","scripts":{"lint":"biome check src tests scripts","test":"bun test --timeout=30000","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.25.0_1788831921330_0.34403475320861765","host":"s3://npm-registry-packages-npm-production"}},"0.26.0":{"name":"@attalabs/vinaya","version":"0.26.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.26.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"95b0a3efb98ab8c869480efb4e2dc3c43ed62fa0","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.26.0.tgz","fileCount":1489,"integrity":"sha512-9bQKVbrjgn1fLL9VD+hAZUX/ZweRWQ2sRBTuvRZk9Iaz7i3mzgNAO9Pfi1cYdvMB2bCJnoQpAHicRBGIr7OmLA==","signatures":[{"sig":"MEUCIAKmjd4IMq6O9aoQ5ws7IylQiCDGGFZK6heScmx+RGXQAiEA3GWD1Shq1TjryoV2W+LK/Q6iMmj0QaiMtjwRYwjQHd4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQDxE2PdsRppMnQsLSJ/B468GmSvuERZnDJzlMq6YEfeVQIhAIuWoO8xlsFIX+COS2vr1qHEAZslLp34XxrRKnUSNsWt","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":95535381},"type":"module","engines":{"node":">=20"},"gitHead":"4232cf89fa4e80eea4a703bb0ef5d68334d7dbd1","scripts":{"lint":"biome check src tests scripts","test":"bun test --timeout=30000","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.26.0_1788955532693_0.5955897090308084","host":"s3://npm-registry-packages-npm-production"}},"0.27.0":{"name":"@attalabs/vinaya","version":"0.27.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.27.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js"},"dist":{"shasum":"b410fb46ac9136c6986cfddae498fd6d044bb805","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.27.0.tgz","fileCount":1489,"integrity":"sha512-mIyYIVoeRhgoQ3OjSn8rnZ4hbX5mp6uBg8XuofEfV/iIrTVzS2azbRaKV8cdNfJKDSDHbJQfVaJ258OzHpdopw==","signatures":[{"sig":"MEUCIQCXPoq9b71FqpjWYr+UfcHUenWzW7VJZLxnM8L6soilfwIgKRa63w4wFVfuSz1sLnD1kuilIIrnYcy3pUsLLtmGp1w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIC1AEQXJAHpvBCwoXq6T+yJlIjOTChYAFojS5OsK+8AmAiBqLItY0jrXulmR5SYI43zZwpFyWgdDmmqSsNuztKUolQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":95768141},"type":"module","engines":{"node":">=20"},"gitHead":"d6adecef0cd250479546e9ef78d9db43dcfcebcb","scripts":{"lint":"biome check src tests scripts","test":"bun test --timeout=30000","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.27.0_1789059284620_0.8634723574967067","host":"s3://npm-registry-packages-npm-production"}},"0.28.0":{"name":"@attalabs/vinaya","version":"0.28.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.28.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js","vinaya-select-tests":"dist/lib/pre-push-select-tests.js","vinaya-changed-files":"dist/lib/pre-push-changed-files.js"},"dist":{"shasum":"1ca0a9320dcedd08fc3722a93d47802b9412b1d2","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.28.0.tgz","fileCount":1497,"integrity":"sha512-oomIdZWcWc+kUqyxEuNwIVuP/6dCWVEfogJl+fBfwpRmpXwR/Zq/srIZFyY1fwupcS+ZcwxY/wffL+do0Ci9YA==","signatures":[{"sig":"MEUCIQDsw/iVsY/xk/hQmOEYxAOc7rFhe1rO06U4yIC1zFDvyAIgBXzvC7sLkl7uB3cwdIKgMd7WpNAEawYv6SOXH0wqV2E=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQCV1PcGAn57MqkblytnpQn/GctnrSdqU8v1E3XPu+2yYQIgXJChhvZ90w+gWd6lG1F6naOK+o99OaCR64irukE2xtY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":98340130},"type":"module","engines":{"node":">=20"},"gitHead":"eee8bb34f16cf7fa40d1df8d6967d695bc4f5aeb","scripts":{"lint":"biome check src tests scripts","test":"bun test --timeout=30000","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.28.0_1789363566051_0.4581265456439081","host":"s3://npm-registry-packages-npm-production"}},"0.29.0":{"name":"@attalabs/vinaya","version":"0.29.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.29.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js","vinaya-select-tests":"dist/lib/pre-push-select-tests.js","vinaya-changed-files":"dist/lib/pre-push-changed-files.js"},"dist":{"shasum":"f1c46dd0570447fb4d56fd6325a65eeafe00c969","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.29.0.tgz","fileCount":1505,"integrity":"sha512-VBt1SOHfCQMzRfwWJRxkJgnSlB/DhhYNr9TNG/LAnN3sU7K1wsUGfWk/MvzYTBHKoaGjFeFQmDwgXh3Bv6ui4g==","signatures":[{"sig":"MEQCICxpp3GnX/b0SQg8OxhiHfHm/P1IkaMQPa9xqfV0Z1XcAiBdAmM664FJeUFJicJEVb5HcrPAwnyx3bMdLi5dIOSUFA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQCvmlDd0w/kV0ZU6bhGHsSH6OvaHQH5nGHEdQNmfzlP4wIhAKkwhJ5nzXCzV1gvSxtXUlwSVX+6bp9r5tw7vJnaPDy3","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":99339006},"type":"module","engines":{"node":">=20"},"gitHead":"2e8be5488067eeb77ac7878aa226bfd38b1cee78","scripts":{"lint":"biome check src tests scripts","test":"bun test --timeout=30000","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.29.0_1789524189213_0.45837434586012615","host":"s3://npm-registry-packages-npm-production"}},"0.31.0":{"name":"@attalabs/vinaya","version":"0.31.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.31.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js","vinaya-select-tests":"dist/lib/pre-push-select-tests.js","vinaya-changed-files":"dist/lib/pre-push-changed-files.js"},"dist":{"shasum":"182729eadda99f0bd05244545747e25494522773","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.31.0.tgz","fileCount":1498,"integrity":"sha512-0BVOeZVnpyjKCdCOL+5P4z1T0SwXvf8Lw1L+1u3Jx6u7sXI3Jz7wkBd07i4MF+cHt5YpAqEcEtdVqXP9p+Q1zg==","signatures":[{"sig":"MEUCIQCuGQQ13XfrSxVSc9dX0iIKHVS3hNu73JJLvwS8HtxUjAIgH6l0+YxG5KILP6ScgJpQ85tdRh4NRmAwtG+E/29Gzok=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQD33cIY1yBHE64MvF64w2gEMvDwdbkVdSBOS3vr7gUyPAIhAL04TlTlc4zCl/Sp6waHLp+INbj6lbTzOK84TGhHO/60","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":107045842},"type":"module","engines":{"node":">=20"},"gitHead":"f3ca80d90b4f96993a85731dc4faa051d571cb40","scripts":{"lint":"biome check src tests scripts","test":"bun test --timeout=30000","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.31.0_1790012703191_0.89480025637664","host":"s3://npm-registry-packages-npm-production"}},"0.32.0":{"name":"@attalabs/vinaya","version":"0.32.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.32.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js","vinaya-select-tests":"dist/lib/pre-push-select-tests.js","vinaya-changed-files":"dist/lib/pre-push-changed-files.js","vinaya-cache-test-run":"dist/lib/pre-push-cache-test-run.js"},"dist":{"shasum":"f87056caf80f855315f11dbd10307b0e3f506a2c","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.32.0.tgz","fileCount":1500,"integrity":"sha512-AQ9+j2BjmIgbRoV5loIFXNXWb2v1A+uqiW0gbwPaGuJq2C3BAeww6/AZQjY/298vcnPcxsaDh1V6wtpT1dKV6Q==","signatures":[{"sig":"MEUCIQD6ADStc2Fl3HXBp0rXdizygt3Z19DXo09KCkRT11gN8gIgJO4wVG7BjDUUIfraJfuvFM0WU6cA4G8TXjDjvvbVpew=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCICPtw7xKqLwK/JRiRCkUbqo0vqqnUPoqz+JrGarHr5dlAiBi6fYO8nqxdC00NQfdt4tDsKhCxGd+XAQCN/t1rS+gWw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":107462006},"type":"module","engines":{"node":">=20"},"gitHead":"235367c35fe75979933cfb6ca83a8066a7dd6373","scripts":{"lint":"biome check src tests scripts","test":"bun test --timeout=30000","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.32.0_1790247592044_0.4409895332368976","host":"s3://npm-registry-packages-npm-production"}},"0.33.0":{"name":"@attalabs/vinaya","version":"0.33.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.33.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js","vinaya-select-tests":"dist/lib/pre-push-select-tests.js","vinaya-changed-files":"dist/lib/pre-push-changed-files.js","vinaya-cache-test-run":"dist/lib/pre-push-cache-test-run.js"},"dist":{"shasum":"bf599c3d7bdeea239be71d661941453e7f762032","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.33.0.tgz","fileCount":1523,"integrity":"sha512-1N5aY/u2ZcQxF4z0+0QUL1J/XXQHZ9VgSQsNNXLhN+fIlj2uKum2DsmVTeVWYZc4PgHdMZ+w2AyFmrmxb9SFcw==","signatures":[{"sig":"MEUCIQDcl6os2xkP07bHl9tDqZGzYRMCyLz5mp1gr8Zv9WH80gIgegDt72O8UUT0H1DsB4q49idH7fCYHUu7SMK7eh7XG4w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIFGJuq6C7TWSWYbyFEGOf5gqdzXfB/F5TFAGJekzUDe0AiEA6Y1OAYrJr3tmdN2sbUpNznxJfXZwUa1saf7HvfWVaeY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":108338963},"type":"module","engines":{"node":">=20"},"gitHead":"de6e83ac12ddc03314411a0985d364bad43da759","scripts":{"lint":"biome check src tests scripts","test":"bun test --timeout=30000","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.33.0_1790498298012_0.6622336457918305","host":"s3://npm-registry-packages-npm-production"}},"0.34.0":{"name":"@attalabs/vinaya","version":"0.34.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"Apache-2.0","_id":"@attalabs/vinaya@0.34.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js","vinaya-select-tests":"dist/lib/pre-push-select-tests.js","vinaya-changed-files":"dist/lib/pre-push-changed-files.js","vinaya-cache-test-run":"dist/lib/pre-push-cache-test-run.js"},"dist":{"shasum":"e2b49fcafe343d23a67caaddbaa2cba5ecf7d58e","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.34.0.tgz","fileCount":1524,"integrity":"sha512-kLTl0Q0TA9xhsJXIRFbny4Ns930AgtgWUt6XYUXH0vBtmwVUPFMSdyIvj5slyLG1DPnGoJBPY4zLxgi9qBpC0w==","signatures":[{"sig":"MEUCIQCaQCKAKF83VvUz5y9oXxhOLUPQYjRWUiPHX8k6S4T/qwIgP3wEczE3M5nBogC3TI8vndEh1xPTZ/8wOJVzWsKB2kw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIAK/nQRvUgPQ8PFcV5q6evTzs2pRC7r+6LkvP0yJHN6xAiEArqIXmrOAz/HDApGUrNsMyP9InEPQGQ7YaWxwQZuz2Sk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":108636732},"type":"module","engines":{"node":">=20"},"gitHead":"2b48f5c9634d1feb454f665fb30b11284598d413","scripts":{"lint":"biome check src tests scripts","test":"bun test --timeout=30000","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.34.0_1790530994258_0.4884186124579437","host":"s3://npm-registry-packages-npm-production"}},"0.35.0":{"name":"@attalabs/vinaya","version":"0.35.0","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"author":{"name":"Daniel Estevez"},"license":"FSL-1.1-ALv2","_id":"@attalabs/vinaya@0.35.0","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"homepage":"https://vinaya.attalabs.dev","bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"bin":{"vinaya":"dist/index.js","vinaya-select-tests":"dist/lib/pre-push-select-tests.js","vinaya-changed-files":"dist/lib/pre-push-changed-files.js","vinaya-cache-test-run":"dist/lib/pre-push-cache-test-run.js"},"dist":{"shasum":"2a9aee5b281c5c3fc6e1363298a5756ebc79ce3d","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.35.0.tgz","fileCount":1526,"integrity":"sha512-gcrFsc6d7Abuo7NdJbfPiqlmp3Kva+SplYy6p50iM1l0PUXkPMzc0OCjnREiiIIvLgcqVuk9+YZ74oRaPOjFig==","signatures":[{"sig":"MEUCIQDRrVBDyjlQIwGPklNGAUJlbhjZ/K6835nf8jz/XXRmQwIgIT37E2z2HMCPAWOxcp3/z7X1J7YQM17PnFdJoo8tm3g=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCICbcYIMe6/E1ZHCI749GNjEZ3ip4al4rGHiIBOq50h1LAiEAgW5ZemFCZZuf/DoxYtOaA1tXtWhoK5pxdaO9+VkJztQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":108714962},"type":"module","engines":{"node":">=20"},"gitHead":"cfd45b8cb15e8c2176406b80efcd2926d5c1ce32","scripts":{"lint":"biome check src tests scripts","test":"bun test --timeout=30000","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"tmp":"tmp/vinaya_0.35.0_1790583323408_0.6919441445057564","host":"s3://npm-registry-packages-npm-production"}},"0.36.0":{"_id":"@attalabs/vinaya@0.36.0","bin":{"vinaya":"dist/index.js","vinaya-select-tests":"dist/lib/pre-push-select-tests.js","vinaya-changed-files":"dist/lib/pre-push-changed-files.js","vinaya-cache-test-run":"dist/lib/pre-push-cache-test-run.js"},"bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"dist":{"shasum":"a9855db442f2f4ee53bff692987d1f6ba5208cf7","tarball":"https://registry.npmjs.org/@attalabs/vinaya/-/vinaya-0.36.0.tgz","fileCount":1526,"integrity":"sha512-whJ6ZHq4lJ2TeLZX8AzqW6Ypv4v5/mTrHxUy/bwBZ6+Pg2COjmagLfBsmQjnZPeN4hvo+VNx9T8rmDv7YZoPfg==","signatures":[{"sig":"MEYCIQD4uPmm38M/1n77PTKOlj1bnixJ8pbbvD+xySJJ8suiyQIhAPrTNIcTE0IFGp/EUAVfZ4d0O1hp+GkX+w26dD/NRamk","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIDUmk4siVXU+bIleCJhZxJGh2+FefAvZ7lw/jlS51lw1AiBP9B9F6pEJZ4GRILJL1JGxQaQYYTYyKxTWyBRcexUYjA=="}],"unpackedSize":108992526},"name":"@attalabs/vinaya","type":"module","author":{"name":"Daniel Estevez"},"engines":{"node":">=20"},"gitHead":"d86835e003c3aa17c91f32380133a68a9b5a5c26","license":"FSL-1.1-ALv2","scripts":{"lint":"biome check src tests scripts","test":"bun test --timeout=30000","build":"bun scripts/build.ts","prepack":"bun scripts/build.ts && bun scripts/bundle-doctrine.ts && bun scripts/bundle-studio.ts","typecheck":"tsc --noEmit","bundle-studio":"bun scripts/bundle-studio.ts","bundle-doctrine":"bun scripts/bundle-doctrine.ts","verify-published-lifecycle":"bun scripts/verify-published-lifecycle.ts"},"version":"0.36.0","_npmUser":{"name":"daniboomerang","email":"estevez.dani@gmail.com"},"homepage":"https://vinaya.attalabs.dev","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"_npmVersion":"10.9.2","description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","directories":{},"maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"_nodeVersion":"22.14.0","dependencies":{"zod":"3.25.76","gray-matter":"^4.0.3"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"latest","typescript":"^5.5.0","@attalabs/aeg-core":"workspace:*","@atta/typescript-config":"workspace:*","@attalabs/vinaya-sources":"workspace:*","@attalabs/aeg-forge-state":"workspace:*"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/vinaya_0.36.0_1790654387114_0.11230937819892817"}}},"time":{"created":"2026-07-29T11:21:46.104Z","modified":"2026-09-29T03:59:47.855Z","0.1.0":"2026-07-29T11:21:46.446Z","0.1.1":"2026-08-07T06:54:34.755Z","0.1.2":"2026-08-07T15:15:14.783Z","0.1.3":"2026-08-07T16:50:00.343Z","0.2.0":"2026-08-08T04:20:35.826Z","0.3.0":"2026-08-08T11:24:47.598Z","0.4.0":"2026-08-09T09:20:21.704Z","0.4.1":"2026-08-09T09:42:01.242Z","0.4.2":"2026-08-11T03:52:49.509Z","0.4.3":"2026-08-11T08:34:22.443Z","0.4.4":"2026-08-12T07:52:09.967Z","0.4.5":"2026-08-13T01:58:19.107Z","0.4.6":"2026-08-13T06:09:54.576Z","0.5.0":"2026-08-15T04:55:23.939Z","0.6.0":"2026-08-16T05:02:04.666Z","0.7.0":"2026-08-16T08:45:21.529Z","0.7.1":"2026-08-16T12:01:43.520Z","0.8.0":"2026-08-16T14:11:34.745Z","0.8.1":"2026-08-17T02:39:29.013Z","0.8.2":"2026-08-17T05:30:45.622Z","0.9.0":"2026-08-17T10:56:32.011Z","0.12.0":"2026-08-18T11:07:26.065Z","0.16.0":"2026-08-19T05:59:18.793Z","0.17.0":"2026-08-22T05:08:53.901Z","0.17.1":"2026-08-22T05:19:50.318Z","0.18.0":"2026-08-23T12:29:25.285Z","0.19.0":"2026-08-24T07:11:47.915Z","0.19.1":"2026-08-25T01:23:20.797Z","0.19.2":"2026-08-25T11:01:19.707Z","0.19.3":"2026-08-27T08:19:34.719Z","0.20.1":"2026-08-29T11:10:17.299Z","0.21.0":"2026-09-01T06:24:28.968Z","0.22.0":"2026-09-01T17:22:52.696Z","0.23.0":"2026-09-04T08:40:18.095Z","0.24.0":"2026-09-04T12:27:47.957Z","0.24.1":"2026-09-04T16:09:46.910Z","0.25.0":"2026-09-08T01:45:21.859Z","0.26.0":"2026-09-09T12:05:33.354Z","0.27.0":"2026-09-10T16:54:45.093Z","0.28.0":"2026-09-14T05:26:06.516Z","0.29.0":"2026-09-16T02:03:09.947Z","0.31.0":"2026-09-21T17:45:03.813Z","0.32.0":"2026-09-24T10:59:52.508Z","0.33.0":"2026-09-27T08:38:18.515Z","0.34.0":"2026-09-27T17:43:14.951Z","0.35.0":"2026-09-28T08:15:23.903Z","0.36.0":"2026-09-29T03:59:47.648Z"},"bugs":{"url":"https://github.com/daniboomerang/attalabs/issues"},"author":{"name":"Daniel Estevez"},"license":"FSL-1.1-ALv2","homepage":"https://vinaya.attalabs.dev","keywords":["cli","ai-agents","agentic-engineering","governance","checks","git-hooks","code-review"],"repository":{"url":"git+https://github.com/daniboomerang/attalabs.git","type":"git","directory":"apps/cli"},"description":"Vinaya — Agentic Engineering Harness. Deterministic checks every AI coding agent must satisfy before merge.","maintainers":[{"name":"daniboomerang","email":"estevez.dani@gmail.com"}],"readme":"# @attalabs/vinaya\n\nThe `vinaya` bin — Vinaya's npm-distributed CLI, published to the public npm registry as `@attalabs/vinaya`. The installed command is `vinaya`; only the package name carries the scope. This package ships the command router, the hierarchical config loader, the versioned `--json` output envelope, the check engine (`vinaya check` / `vinaya new check`), the install lifecycle (`init` / `doctor` / `upgrade` / `eject`), and validated forge writes (`pr` / `issue` / `review post`).\n\n## Install\n\nThe published artifact is a Node-executable bundle — plain Node ≥ 20 is enough, through any package manager:\n\n```bash\nnpx @attalabs/vinaya init        # or: pnpm dlx / yarn dlx / bunx\n```\n\n## Commands\n\n<!-- AEG:CLAIM: packages/aeg-core/src/verdict-extraction.ts contains:function firstFiveLines(comment: string): string { -->\n<!-- AEG:CLAIM: apps/cli/src/commands/review-post.ts contains:export function renderEscalationComment(input: EscalationInput): string { -->\n<!-- AEG:CLAIM: apps/cli/src/commands/review-post.ts contains:export function checkRenderedComment(body: string, expectation: RenderExpectation): RenderCheckResult { -->\n<!-- AEG:CLAIM: packages/aeg-core/src/brief-render.ts contains:export function renderBrief(facts: BriefFacts, template: string): RenderResult { -->\n<!-- AEG:CLAIM: apps/cli/src/commands/brief.ts contains:refuse(`cannot render — missing fact(s): -->\n\n| Command | Description |\n|---------|-------------|\n| `vinaya help` | Usage text |\n| `vinaya version` | Print the installed CLI version (`--json` for the enveloped machine form) |\n| `vinaya doctrine [--role <name>] [--print]` | Print the absolute path of the bundled doctrine's front door (`aeg-root/skills/aeg/SKILL.md`) on this machine. The committed root `VINAYA.md` pointer names the package, never a filesystem path — this command is the read-time resolution step it hands the reader. `--role <name>` resolves straight to a specific role's doctrine instead (`aeg-root/roles/<name>.md`, under the same resolved root), validated against the role names actually enumerated under `roles/*.md` at request time — an unknown name fails cleanly and lists the valid names, never a silent bad path. `--print` emits the resolved file's body (frontmatter stripped) instead of its path — the one-hop mode every generated skill and slash command invokes, so an agent never has to read a second file to get its instructions; a role file whose frontmatter carries an `ack-token` emits that token as the output's own first line. Without `--print`, the bare path output is unchanged — a shell composing `\"$(vinaya doctrine)\"` still works exactly as before. `--json` for the enveloped `{ root, entry }` form (mutually exclusive with `--print`). |\n| `vinaya check <name> \\| --all` | Run one check, or every registered check (core + `vinaya.config.json`-registered). `--json` for the enveloped `{ checks: CheckOutcome[] }` form; `--diff-only` scopes `scope: 'diff'` checks to changed files; `--parallel[=n]` caps concurrency (default: cpu-derived). Findings always print as the check contract's JSON lines on stderr, regardless of `--json`. Exit 0 iff every check passed. |\n| `vinaya new check <yourname>/<id>` | Scaffold a self-contained custom check into `./scripts/vinaya-checks/<id>.ts`, ready to register in `vinaya.config.json` under that namespaced key |\n| `vinaya brief render <tranche> <n> --surfaces <glob,...> [--out <path>]` | Emit the twelve-section brief skeleton from the task Issue and the tree, with every mechanically-derivable section filled: the header `Project:`/`Tier:`/`Closes #N`, the Step 0 worktree line, the dispatch-gate status as the pre-flight line, §4's file list (with consumer packages and a `sha256` premise pin per file, and Out of surface from the Issue's own `## Surface` `out:` list), §6 from the Issue's `## Parts`, §7 from the `.vinaya/doc-owners` derivation, §9 from the Issue's `## Test plan`, §10 from the Issue's `## Stop conditions` plus the rationale's Stop-and-escalate field, and every remaining section from the Issue's eight-field Planner rationale. Refuses, naming the missing section, when a section cannot be derived: no Issue, the dispatch gate not clear, a `--surfaces` glob matching no tracked file, or the Issue missing/malformed `## Surface`/`## Parts`/`## Test plan`/`## Stop conditions` — never a bracketed placeholder. Never writes under `aeg-root/` or to the Issue — stdout, or `--out <path>`, only; a brief is pasted to the Developer, never committed. |\n| `vinaya task brief <tranche> <n>` \\| `vinaya task brief --issue <n>` | Preparation only: render the same brief `brief render` renders, then post it once as a frozen Issue comment (first line `<!-- aeg:brief:v1 -->`, second line `Brief hash: <sha256>` over everything below it) — refusing outright, naming the existing comment's URL, if the Issue already carries one. Before freezing, runs the SAME Issue write gate `issue create`/`issue edit` already enforce over the Issue's live body — a defect that gate would refuse (a bad title, a blast-radius violation, a whole-suite Test plan line, …) is refused here too, naming every finding together, never silently frozen into a brief just because the Issue itself predates the gate or was never written through `issue create`/`edit`. `--issue <n>` names a backlog Issue directly — one carrying no `vinaya/tranche:*` label — and renders its brief from that Issue's own `## Objectives`/`## Surface`/`## Parts`/`## Test plan`/`## Stop conditions` sections, no tranche or Milestone involved. `--supersede --reason <text> [--surface-in <glob,...>]` posts a new, higher-versioned frozen brief naming its predecessor and the reason, instead of refusing on the one already there; `--surface-in`, only meaningful with `--supersede`, widens the frozen Issue's `## Surface` `in:` list with the given comma-separated globs (union with what is already there, never a narrowing) — the one self-serve way to broaden a Surface once frozen, since `issue edit` itself locks `## Surface` the moment a brief is frozen. The widened body is graded by the same write gate before it is written, then the brief is re-rendered from it (never the pre-widen text, which would otherwise ship a stale Technical surface map) before the superseding comment posts — one command, one write. Starts no agent under any circumstances — there is no `--agent` flag. Principal-only: refuses before any render, forge read, or post when the authenticated `gh` identity is not on the Principal allowlist. The successor to `task dispatch` for the preparation step; `task run` is the full unattended run. |\n| `vinaya task dispatch <tranche> <n> [--agent claude \\| codex \\| gemini] [--model <name>]` | **Deprecated** — prefer `task brief` (preparation only) or `task run` (the full unattended loop). Renders the same brief `brief render` renders, then posts it once as a frozen Issue comment (first line `<!-- aeg:brief:v1 -->`, second line `Brief hash: <sha256>` over everything below it) — refusing outright, naming the existing comment's URL, if the Issue already carries one. With `--agent`, starts the Developer through `dispatchRole` (`apps/cli/src/lib/dispatch.ts`) when that function is available; otherwise prints the rendered brief and the manual dispatch instruction and exits `0` — a soft dependency, never a hard block. `--model <name>` names the model to run, passed through to `dispatchRole` and always taking precedence over any class-derived resolution; without it, the task's own Issue rationale is read for its \"Suggested agent-class\" (`high`/`mid`/`fast`) and resolved through the chosen vendor's own class-to-model table, falling through to that vendor's default when neither resolves. Principal-only, with or without `--agent`: refuses before any render, forge read, or post when the authenticated `gh` identity is not on the Principal allowlist. |\n| `vinaya task run <tranche> <n> --agent <claude \\| codex \\| gemini>` \\| `vinaya task run --issue <n> --agent …` | One command from a planned Issue to a reviewed pull request, exactly one developer started. `--issue <n>` runs a backlog Issue — no `vinaya/tranche:*` label, no Milestone — through the identical unattended path on branch `task/issue-<n>`, same brief, same loop, same gate. Composes `task brief`'s own preparation (starts no agent) with `dev-review-loop` (whose own round 1 reads the frozen brief off the Issue and is the only place a developer is ever dispatched from a fresh task) — nothing else. A brief already frozen on the Issue is reused, not re-posted; a task whose Issue refuses preparation is refused before any agent starts, with nothing posted; a frozen brief whose developer branch already has an open pull request refuses a second start. Exit `0` with the PR URL on a published, reviewed pull request; exit `1` with the exact `vinaya dev-review-loop --resume <pr>` command on a pause; exit `2` on a usage/argv error (an unrecognized flag, a missing `--agent`); exit `3` on any other failure (a refused preparation, an open-PR refusal) — never sharing `1` with a pause, so an unattended host tells the two apart from the exit code alone. The loop's own existing `--resume` flag is how a paused run continues, never a flag on this command. **Known gap:** a backlog Issue's run state (`running`/`paused`/`published`) does not yet appear on Vinaya Studio's backlog page — that reader lives in the separate `apps/vinaya-studio` checkout (attalabs monorepo, out of this repository's own Surface) and has not been updated for the `task/issue-<n>` shape; `vinaya task status --issue <n>` is the reader in the meantime. |\n| `vinaya task status [<tranche> <n>] [--json]` | Every open task Issue carrying a frozen brief, its pull request, and whether its dev-review-loop is `running` (naming the driver pid, `review-validity-v1` task 7's pid record), `paused` (naming the reason from the pause record), `published` (the newest round's reviewer and security verdict effect markers both read `posted`), or has `no driver` — read from the outbox (`<outboxRoot>/dev-review-loop/<task>/`) and the forge, never from a `ps` scan and never by re-parsing posted verdict comments. Read-only: no write, no change to any loop. `vinaya task status <tranche> <n>` narrows to one task and adds the last round's held or published verdict lines plus the exact `vinaya dev-review-loop --resume <pr>` command when paused. `--json` for the enveloped machine form (schema: 1). `vinaya task status <tranche> <n> --follow` (and `--issue <n> --follow` for a backlog Issue) tails that task's per-driver log (`~/.vinaya/loops/<owner>-<repo>/<issue>.log`) live, `tail -f` style — every driver (`task run`, `dev-review-loop`) tees its own role-prefixed stream there regardless of where it was launched, so the state of any run is one command away with no path to remember. |\n| `vinaya task sweep [--include-legacy] [--json]` | Removes the folder of every task whose Issue is closed or whose pull request is merged or closed, printing each folder removed or kept with the reason — an open pull request, a live driver, or a pause all keep a folder, and a forge read failure removes nothing for that folder rather than guessing. Idempotent, and called by the driver itself (`dev-review-loop`/`task run`) at the start of every run, before it dispatches anyone; a sweep failure there is reported and ignored, never a reason the run stops. Always also lists the eight top-level folders an earlier, pre-`tasks-execution` layout (or, for `drivers`, an operator's own hand) left under the Vinaya home (`dispatch-output`, `dispatch-resume`, `dispatch-settings`, `task-start`, `task-resume`, `control-store`, `loops`, `drivers`), plus the even-older `outbox/dev-review-loop/<task>/` tree nested inside the telemetry outbox root itself, each attributed to this repository only through its own path or its own record content naming it — a bare task number alone is never enough, since task numbers repeat across repositories. `--include-legacy` removes only what it can both attribute this way and classify finished; everything else there is reported `unattributable` and kept. Never removes the telemetry outbox or the machine-wide files under the Vinaya home (the configuration and the token trust file). `--json` for the enveloped machine form (schema: 1). |\n| `vinaya pr create --body-file <path> --title <title> [--label ...] [--validate-only] [--json]` | Open a pull request after full brief-schema validation of the body against `vinaya.config.json`'s configured sections — never a body containing the retired `<!-- aeg:brief:start -->`/`<!-- aeg:brief:end -->` markers, refused outright: the brief lives on the task Issue's `aeg:brief:v1` comment now (`vinaya task dispatch`), never split out of or pasted into the PR body. Every gate — the legacy-marker check, the configured brief-schema sections (including the title grammar), the whole-body bare-digit scan, the Premise-own-additions check, and the PR-body registry's own `validates: 'body'` checks — grades the same bytes in one pass and refuses ONCE with every failing finding together, never stopping at the first; `--validate-only` runs the identical union and reports PASS without opening anything; `--json` for the enveloped machine form. |\n| `vinaya pr edit <pr> [--body-file <path>] [--title <title>] [--validate-only] [--json]` | Edit an open pull request's body and/or title through the same union of gates `pr create` applies (minus the legacy-marker and Premise-own-additions checks, which only apply to a fresh open) — refuses once with every failing finding together. With no `--body-file`/`--body`, only the title is graded and changed. `--validate-only` runs the gates and reports PASS without writing; `--json` for the enveloped machine form. |\n| `vinaya issue objectives edit <n> --add \"<sentence>\" \\| --drop O<k> \\| --replace O<k> \"<sentence>\" --reason \"<text>\"` | Rewrite a task Issue's `## Objectives` section by command — the Principal's way to change a task's scope mid-flight, findable and versioned rather than a silent hand-edit. Exactly one of `--add`/`--drop`/`--replace` plus a non-empty `--reason` is required; the edit runs through the same validated `issue edit` write path (`writeValidatedIssueEdit`) as `vinaya issue edit` itself. `--drop` never renumbers the survivors — a drop that leaves the list non-contiguous from `O1` is refused with `objectivesOf`'s own parser message, since task 1's contiguous-from-O1 grammar and this command's never-renumber rule can genuinely contradict on a real drop, and that contradiction is reported rather than papered over. Splices the rendered section back in place, leaving every other byte of the body untouched, then posts one comment marked `<!-- aeg:objectives:v<k> -->` carrying the previous list, the new list, the reason, and the new version hash — `k` counted on the forge at post time, never from a local file. |\n| `vinaya pr report [--write <body-file> \\| --push <pr>] [--phase <phase>] [--role <role>] [--model <id>] [--transcript <path>]` | Emit two generated, never-hand-typed blocks a PR body carries: `AEG:EVIDENCE` (the head sha, the width-invariant `git diff --numstat` against `origin/main`'s merge-base, the result of `vinaya check --all --diff-only`, and — Group C, task 12, #387 — every command in the body's §9 fenced Test Plan list, re-run from the PR head with its actual output; a command whose result was reused from an earlier green run at this exact head, working tree and machine — the pre-push hook's own run, or an earlier report's — carries a note after its own fence naming that run: when it was recorded, which run recorded it, and, for a per-file match, how many files it covered, every digit of it inside an inline code span so the report never refuses the body it has just generated on `body-bare-digits`) and `AEG:TOKENS` (real usage figures collected the same way `vinaya tokens` collects them, rendered into the `## Token report` heading's table). Without `--write`/`--push`, prints the Evidence block to stdout. With `--write <body-file>`, replaces the Evidence block in place but APPENDS a new row to the Tokens block on every run — a re-entry after `CHANGES_REQUESTED` reports again, and a second report is a second row, never a sum or an overwrite. With `--push <pr>`, does the same splice directly against the PR's LIVE body — fetched from the forge, never a local file — and pushes it via `gh pr edit`, then re-reads the live body and refuses (restoring the pre-edit body) unless it agrees with the pre-push body outside the two anchored regions; refuses before writing anything on a live body with no real `AEG:EVIDENCE` pair (never appends one, unlike `--write`), a divergent anchor resolution, or a `<pr>` value that isn't a bare number. When the live body has no real `AEG:TOKENS` pair, the token splice is skipped rather than creating one (same reasoning, softer outcome — `AEG:EVIDENCE` alone is still pushed). `--write` and `--push` are mutually exclusive. `--phase`/`--role` default to `<n>: develop`/`Developer` (`<n>` parsed off a `task/<tranche>/<n>` branch) but accept any role/phase pair — a Planner (`--role Planner --phase \"<n>: plan\"`) or Reviewer (`--role Reviewer --phase \"<n>: review\"`) turn appends its own row into the same block alongside the Developer's, and each round-trips through `parseTokenReportEntries` into its own distinct ledger row; no role's figures ever collapse into another's. `--transcript` names a session transcript directly, skipping Stop-hook pointer-file resolution. The two incapable classes are kept apart, and never fabricate a `0/0/—`: a session whose own wiring — a pointer whose id matches, or one at this project's own pointer path — was reached and the figures still could not be (`pointer-unusable`, the pointer cannot be read or parsed; `transcript-unreadable`; or `transcript-empty`, it resolves to zero usage records) gets an all-`—` row carrying the probe's reason inline in the Agent/Model cell; a session that resolved no transcript at all — no Stop-hook pointer, or one that cannot be corroborated as this session's — gets **no row and a refusal on stderr** naming `--transcript` and `vinaya tokens --in/--out`, because nothing there established that the host cannot meter, and a blank row would claim it did. The `AEG:EVIDENCE` block is still written/pushed in that case; only the row is withheld. Exits non-zero when any gate in Group B fails, or when the token row was refused. |\n| `vinaya review status <pr>` | Print the review loop's own state for a PR. Line one is `CONTINUE`, `PAUSE: <reason>[ <id>]` for `reappearance` (an id a round marked `resolved` came back `reproduced`), `zero-deaths` (a round resolved nothing it inherited and still raised something new) or `max-rounds` — or, for `stale` (the newest verdict judged a superseded head and no Developer round comment followed), the actionable fact itself: `push after verdict — re-review required`. Line two reads `behind main by <n> — merge first` when the branch is behind its base, or `behind main: unknown — fetch origin/<base> first` when git cannot measure the distance at all; it is absent only when the branch is measurably not behind. Rounds are derived from the PR's own verdict comments — one round per `Judged head:` value, read through the same extractors `review-gate` blocks merges with, and only from comments an allowlisted principal authored; a Developer round comment is recognised by its `<!-- aeg:developer:round-<n> -->` marker at that fixed position, never by scanning its prose. Exit `0` only when the state is `CONTINUE` and the branch is not behind; `1` otherwise, so a script can gate on the exit code without parsing the text. |\n| `vinaya review post --role code-reviewer \\| security --pr <n> [--verdict <v>] [--escalate <class> --summary <text>] ...` | Render, post, and self-verify a code-reviewer or security-review verdict comment on a PR from structured flags (findings, per-field text) instead of a hand-typed comment. The verdict is DERIVED from the findings file (REQUEST_CHANGES/FAIL iff a BLOCKER/CRITICAL-or-HIGH finding is present) — `--verdict` is optional and refused before posting anything when it disagrees with the derivation, naming the derived value. `--escalate authority \\| strategy \\| product --summary <text>` posts an `ESCALATE:` comment instead of a verdict — its own outcome, refused together with `--verdict` or with a blocking finding present. When the PR already carries a same-role verdict comment, a new findings file must carry every prior `F<n>` id with a state (`open`/`fix-claimed`/`reproduced`/`resolved` — a `resolved` finding keeps its severity for the record but no longer drives the verdict), and a non-blocking finding outside the diff since that comment's `Judged head:` is refused. `--scope-evidence-file <path>` (code-reviewer only) renders the file's contents as a fenced block directly below the verdict block, backing the `SCOPE:` claim. `--objectives-file <path>` (`O<n>|MET|<evidence>` or `O<n>|NOT MET|<evidence>` per line) renders an `OBJECTIVES:` block after `SPEC CONFORMANCE:`/before `CONFIG SCAN:` and an `Objectives version:` line at line 5 — resolved from the closed Issue's `## Objectives` list, or the PR body's own section when it closes none; required whenever that resolution finds a list to judge, its ids must cover the list exactly, a clean verdict is refused alongside any `NOT MET`, and a re-review must restate every prior objective; an Issue below the objectives cutover renders neither line at all (never together with `--escalate`). Resolves the PR's real head itself (`gh pr view --json headRefOid`); renders every structural `VERDICT:`/`ESCALATE:`/`Judged head:`/`Objectives version:` line from validated inputs, never from caller-supplied text; before posting, runs the exact `extractCodeReviewVerdict`/`extractSecurityReviewVerdict` functions the merge gate calls over its own rendered text and refuses (exit `2`) unless exactly the intended verdict extracts and the other role extracts none (an escalation: both extract none) — those extractors read only a comment's first five lines, and a code-review/security render's caller-supplied fields never open one of those lines, but an escalation's `--summary` can (pre-cutover, it becomes line 5 unprefixed); this pre-post re-parse, not the render's construction, is what catches that case before anything is posted; and after posting, re-fetches the comment and refuses to exit 0 unless the same re-parse holds against the live forge state, including the objectives version. A `doc-correctness` finding is refused before posting unless its description ends with a `Search: <pattern>` carrying no path filter (`--`), so the claim, not the anchored line, is the unit of the finding. `--print-only` renders and self-checks the comment exactly like a real post, then prints it and returns — never calling `gh pr comment`, never re-fetching to self-verify a write that never happened (closes atta-labs/vinaya#184). `--json` for the enveloped machine form. |\n| `vinaya pr rule <pr> --file <ruling.md>` | Post the Principal's ruling on a PR as its own marked, versioned comment (`<!-- aeg:principal:ruling:<pr>-<k> -->`) — never mistaken for a code-review or security verdict. Refuses before posting when the file's first line reads as an escalation (`ESCALATE:`), or when the file carries verdict grammar anywhere `extractCodeReviewVerdict`/`extractSecurityReviewVerdict` would treat as a candidate — a `VERDICT:` line sitting past the extractor's own first-five-line read window still counts, since it's the whole-body candidate test that disqualifies the file, not merely a clean read; a blockquoted mention of `VERDICT:` is unaffected, since the extractors ignore it too. `k` is counted on the forge at post time from `gh pr view --json comments`, never derived from a local file. |\n| `vinaya tokens --phase <phase> --role <role> [--model <id>] [--transcript <path> \\| --in <n> --out <n>]` | Print a role's `Tokens: …` report line — the portable front door over the token-report collection adapter, resolving `@attalabs/aeg-core`'s `resolveMeteringCapability`/`summarizeTranscript`/`formatTokensLine` from the installed package rather than a repo-relative path, so it works in an adopter checkout with no local `packages/`. `--transcript <path>` reads a session transcript directly; omitted, it resolves via the Stop-hook pointer file where one is installed. `--in <n> --out <n>` bypasses transcript resolution entirely for a host whose figures arrive by some other means. Refuses rather than emitting `0/0/—` when no transcript resolves, a resolved one can't be read, or it summarizes to zero usage records — the same capability probe backs a `vinaya doctor` finding when it reports incapable. |\n| `vinaya archive [--merge-sha <sha>]` | Post-merge Archivist: resolves the merged PR from a merge SHA (`HEAD` by default), assembles and posts the `### AEG provenance` comment via `@attalabs/aeg-core`'s `buildProvenanceBlock`, then closes the PR's `Closes #N` Issue. Idempotent — a PR that already carries the block (`hasProvenance`) is skipped, posting nothing new. Appends its own one-line `Tokens: …` report to that same comment, collected via the same metering adapter `vinaya tokens` uses: the sanctioned all-`—` line on an incapable host, or — when the probe reports capable but summarized to zero tokens — the line is omitted and flagged `DANGLING (tokens): …` instead, since a capable host's blank is never licensed to read as `—`. Provenance and Issue-closure always proceed regardless of that outcome; a missing token row never withholds either. `vinaya archive tranche <slug> [--yes]` closes a tranche's legacy Milestone once every `vinaya/tranche:<slug>`-labeled Issue is closed. `rings.ring2_asyncAudits: true` skips this command's work entirely (see Config below). |\n| `vinaya studio` | Launch Vinaya Studio. Inside a checkout that carries Studio's source (`apps/vinaya-studio/web` — it lives in the attalabs monorepo, not this repository) it runs the dev app; a published install runs its bundled standalone server instead, fetched from attalabs' published release artifact at publish time. `--port <n>` binds an exact port — see below. |\n| `vinaya milestone create --title <title> --body-file <path>` | Create a GitHub Milestone from a validated body. The title is free text, never parsed for a version — the description's optional `Release:` field is the sole authority for one. Refuses before any `gh` write when the goal is absent, `Release:` is present but malformed, or an `### Tranche intents` section (`- <slug>: <intent text>`) doesn't parse. `--validate-only` runs every check without writing; `--json` for the enveloped machine form. |\n| `vinaya milestone adopt --target <title> --slug <slug> [--slug <slug> ...]` | Move one or more existing tranches into a target Milestone: reattaches every Issue carrying each `vinaya/tranche:<slug>` label to `--target`, then closes (never deletes) each slug's old tranche-Milestone. Every fact is gathered and refused-or-passed as ONE batch before any write — an unknown slug, a slug whose label carries no Issues, a target that does not exist or is closed, or a slug already adopted into a different Milestone refuses the whole invocation, not just its own slug. `--validate-only` runs every check without writing; `--json` for the enveloped machine form. |\n| `vinaya milestone edit <n> --body-file <path>` | Edit an existing Milestone's description after the same `checkMilestoneShape` gate `create` runs — the gated replacement for a raw `gh api PATCH` against a Milestone. Only the description changes; the title is untouched. `--validate-only` runs every check without writing; `--json` for the enveloped machine form. |\n| `vinaya milestone close --slug <slug>` | Close a tranche's Milestone — the gated replacement for the raw `gh api .../milestones/<n> -X PATCH -f state=closed` recipe the Tranche Archivist used to run on faith. Resolves the target Milestone the same legacy-or-intent-declared way Issue create auto-attach does, then refuses to close on any mismatch between the label's Issues and the Milestone's natively attached Issues — naming each unattached or foreign Issue and its repair path (`gh issue edit <n> --milestone <title>`, or `vinaya milestone adopt`) — before the PATCH ever reaches the forge. `--validate-only` verifies attachment without closing; `--json` for the enveloped machine form. |\n| `vinaya quickstart [--yes] [--dry-run]` | Guided wizard that runs `init` → optional doc-owners bind → optional project registration → commit → `demo break` → `doctor` → `push` in sequence, prompting between steps. `--yes` forwards straight through to `init` and answers every one of quickstart's own prompts with its documented default (skip the two optional steps, run the refusal-then-fix proof, push) — no prompt is opened at all, so the command completes with no human at the keyboard rather than merely with stdin closed. `--dry-run` also forwards to `init` and stops immediately after its preview — nothing is installed, so no later step runs against an uninstalled repo. |\n| `vinaya release [--dry-run] [--allow-any-commit]` | Run this repo's own publish sequence in one command (`apps/cli/specs/self-hosting.md`, \"How the published version is produced\"). Refuses unless HEAD is the default branch, the tree is clean, HEAD equals `origin/<default>` (after `git fetch origin`), HEAD's commit subject starts with `Chore(release): Version packages` (unless `--allow-any-commit`), and `npm whoami` exits `0` — each its own refusal naming the fix. Then streams `bun install --frozen-lockfile`, `bun run build`, `bun run changeset:publish`, and a real `git push origin --tags`, so the repo's own generated pre-push hook sees the push exactly as any other push would. Afterward prints `npm view <pkg> version` for every tag now on HEAD, noting registry lag on `@attalabs/vinaya` (observed ~20 minutes) when it still shows the previous version. `--dry-run` stops after the preconditions and prints the plan; publishes nothing. |\n| `vinaya dispatch <role> --agent claude \\| codex \\| gemini --prompt-file <path> [--task <n> \\| --pr <n>] [--round <n>] [--resume <id>] [--model <name>]` | Start a role's headless agent session, attributed: `VINAYA_RUN_ID`/`VINAYA_ROLE`/`VINAYA_TASK`/`VINAYA_ROUND` are set on the CHILD's environment only, never on this process's own — a role started this way is what makes its later `vinaya` calls (the Stop hook, a nested dispatch) attributable instead of `unattributed`. The prompt is read from `--prompt-file` and sent on the child's stdin, never argv. `--model <name>` is passed to the chosen vendor through that vendor's own model flag, and the dispatch log's `model` field never records the vendor name; omitted, no model flag reaches the vendor and its own default decides, exactly as before this flag existed. A model shaped as another vendor's own (e.g. a Claude alias passed to `codex`) is refused by name before any spawn, naming the vendor and what it accepts. Before the vendor produces any output, and for any dispatch that never completes, the log records the requested value as a marked `requested:<name>` label (or `default` when none was named) — never presented as a confirmed observation. Once the vendor's own headless output actually reports which model ran (Claude's `modelUsage` object key, Gemini's `stats.models` object key(s) — Codex emits no such receipt in any event), that bare, unprefixed model name is recorded instead, even when it differs from what was requested or when no model was requested at all. Refuses by name, before any spawn, when the named vendor binary is absent from `PATH` or present but not executable. Every line this command and the loop it can drive print to the terminal is prefixed with its role (e.g. `[developer]`) and colour-coded per role, with the coordinator/loop's own lines in a distinct colour from every role — colour is applied only on a live TTY and is disabled entirely, prefix kept, when `NO_COLOR` (https://no-color.org) is set to any value. While the child runs, its raw stdout/stderr bytes are teed (never taken from the same stream the outcome parser reads) to a machine-local file under `~/.vinaya/dispatch-output/<effect-id>.log` — never inside the repo tree — whose path is printed once to this process's own stderr so an operator can `tail -f` it; a heartbeat line reporting elapsed time prints there every minute so a working agent is distinguishable from a hung one without inspecting processes by hand. A wall-time ceiling (`dispatch.timeoutMs` in config, default four hours) sends `SIGTERM` then, after a grace window, `SIGKILL`; a warning prints before the ceiling fires (at most 5 minutes ahead, sooner for a shorter configured ceiling) so a timeout is an expected, visible event rather than a silent disappearance. Records `dispatched`/`outcome_received`/`dispatch_failed` through the Vinaya Log's `dispatch` family (`apps/cli/specs/log.md`), delivered live to its configured `logs` destination as each is logged — never a tracker comment, and this command runs no flush of its own. A successful dispatch's own vendor session/thread identifier is returned as `resumeId` (printed alongside the other fields); passing that value back as `--resume <id>` on a later call swaps in that vendor's own resume invocation instead of starting a fresh session. That id is also durably recorded — never only printed — at `~/.vinaya/dispatch-resume/<owner>-<repo>|unresolved/<role>-<agent>-<issue<n>\\|pr<n>\\|unscoped>.json` (the repo segment keeps two different repos' own same-numbered task from overwriting each other's record on this one machine-wide home), overwritten by each dispatch's own outcome; a run that stops with a question is answered by reading the id from that file (or from the run's own printed output, if that terminal is still open) and running `vinaya dispatch <role> --agent <vendor> --resume <id> --prompt-file <answer-file>` — the same session continues from where it stopped, rather than being killed and re-dispatched fresh. There is no live channel: an unattended dispatch never blocks on a read waiting for an answer, so a stop condition always degrades to record-and-exit, and the resume path above is how it is answered afterward. |\n| `vinaya dev-review-loop --task <n> --agent claude \\| codex \\| gemini [--json]` / `vinaya dev-review-loop --resume <pr> --agent … [--json]` | `--issue <n>` is `--task <n>`'s exact synonym — the loop's own `task` field is already the Issue number, tranche or not, so a backlog Issue (no `vinaya/tranche:*` label) needs no separate flag, only the naming that matches `task run --issue <n>`. Dispatch the developer through `dispatchRole` with the brief read from the task Issue's frozen `aeg:brief:v1` comment, wait for the PR it opens, then run rounds by calling `assessRound` (`@attalabs/aeg-core`) — the entire policy — with observations read from the forge (`git ls-remote` for the head, the check-runs API for CI, `<!-- aeg:principal:ruling:<pr>-<k> -->`-marked comments for rulings) until it returns `publish` or `pause`. Each round's reviewer and security verdicts are dispatched fresh (never resumed), rendered through `review post`'s own render functions, and held as local files under the outbox — nothing is posted to the PR (`gh pr comment`) before `publish`. At `publish`, the two held verdicts and a `renderSummary` comment are posted, in order, each re-read back through the same extractors the merge gate uses, each idempotent across a rerun. At `pause`, one comment marked `<!-- aeg:loop:paused:<reason> -->` is posted (carrying the exact `--resume <pr>` command) and the process exits non-zero; `--resume <pr>` reads that held state and a since-posted Principal ruling off the same PR and continues. Full account: `apps/cli/specs/loop.md`. The developer's own session IS resumed every round via `dispatchRole`'s `resumeId`; a round whose resume fails for a vendor that resumed successfully the round before stops the loop rather than falling back to a fresh session. |\n\nThe one-lib-function-per-command rule, and where a command's own dated exemption lives when it calls more than that one today: `apps/cli/specs/surface.md`. Each exempt command declares its own exemption as a `SURFACE_EXEMPTIONS` export in its own file (`apps/cli/src/lib/surface-exemption.ts`), enforced against the real source tree by `apps/cli/tests/surface-index.test.ts` — there is no central per-command listing to read instead.\n\nThe typed event log's header, families and outbox: `apps/cli/specs/log.md`.\n\n## Config\n\nHierarchical, file-level precedence:\n\n1. Repo-local `vinaya.config.json` (walked up from `cwd`, stopping at the enclosing repository's root — or the filesystem root when run outside a git repository)\n2. Global `~/.vinaya/config.json`\n3. `null` if neither exists\n\nWhichever file resolves first is used in full — there is no field-by-field merge across the two files.\n\nToday the schema carries one surface:\n\n```json\n{\n  \"rings\": {\n    \"ring1_forgeWriteInterception\": true,\n    \"ring2_asyncAudits\": false\n  }\n}\n```\n\nBoth `rings` fields are plain booleans — no conditional logic. Ring 0 (git hooks) and the CI/branch-protection guarantee are never represented in this schema, by design — they are not configurable.\n\nBoth fields are additive, never disabling: `false` (the default — every `vinaya init` starter config reads `false` for both) is a no-op, leaving the underlying mechanism running exactly as it does with no config at all. `true` is the opt-in accelerator — the only value that changes behavior — and skips it. `ring1_forgeWriteInterception: true` skips `pr`/`issue create|edit`'s `briefSchema` validation entirely; `ring2_asyncAudits: true` skips `vinaya archive`'s provenance work and `vinaya audit`'s dead-branch-push notification, exiting `0` without doing anything for those two — it does **not** skip `vinaya audit`'s direct-main-push detection, which stays unconditional on purpose: that check is a real pass/fail catching a branch-protection bypass, and gating a security-relevant detection behind a flag readable from ordinary PR content would let the bypass silently disable the check that catches it.\n\n### Blast-radius collision domains\n\n`checkBlastRadiusScope` (the AEG task-Issue gate that refuses an under-declared blast radius) needs a list of shared collision domains — paths that couple work across project boundaries. It works out of the box, with **zero adopter file**:\n\n- Every `packages/*` workspace member is derived live at check time — from `package.json`'s `workspaces` array, or `pnpm-workspace.yaml`'s `packages:` list on a pnpm repo (pnpm does not read `package.json`'s `workspaces` key at all) — a shared package is a collision domain by construction, so this needs no declaration. A leading `!` negates an entry, same as npm/yarn/pnpm's own workspace-glob syntax.\n- A built-in default set covers the common cross-cutting paths by presence-check: whichever lockfile exists (`bun.lock`/`package-lock.json`/`pnpm-lock.yaml`/`yarn.lock`), `turbo.json`, `biome.json`, `tsconfig.json`, `.github/workflows`, `.husky`.\n\nTo declare a domain beyond those two — a `migrations/` folder, a codegen output directory — add it to `vinaya.config.json`:\n\n```json\n{\n  \"blastRadius\": {\n    \"extraDomains\": [\"migrations\", \"packages/generated\"]\n  }\n}\n```\n\n**`.aeg/packages`** (the legacy static collision-domain file some repos still carry) is **not read** by `checkBlastRadiusScope` here — no backward-compatibility path, since `apps/cli` has no adopter depending on it. `vinaya doctor` still diagnoses a present file purely as a migration checklist: it names exactly which of its entries (if any) aren't already covered by live derivation, the built-in defaults, or `blastRadius.extraDomains`, so you know what to fold into those before deleting it — but the file itself contributes nothing to the live check.\n\n`checkBlastRadiusScope` is one of three content checks `vinaya issue create`/`vinaya issue edit` run automatically on a task Issue (any `vinaya/tranche:*` label) — unconditional, not something `vinaya.config.json`'s `briefSchema` opts into or out of. The other two: `checkNoBriefContent` refuses an Issue body carrying a brief-shaped section (`## References`, `Technical surface map`, `Premise`, `Step 0`, `Test Plan` — those belong in the brief, not the Issue); `checkRationaleNamesDocs` refuses a rationale whose \"Docs to keep coherent\"/\"Traps\" fields name no concrete doc/skill path, unless it carries the explicit `no-doc-surface` sentinel. All three grade what the eight-field Planner rationale (`checkIssueRationale`) *says*, once that gate has confirmed the fields exist.\n\n### Config-native project metadata (`projects`)\n\n`vinaya init product <name>` has always appended a row to `.vinaya/projects.md` (the project registry). It now *also* appends an entry to `vinaya.config.json`'s `projects` array — a second, config-native home for the same declared fact, alongside the registry file rather than instead of it:\n\n```json\n{\n  \"projects\": [\n    { \"name\": \"mobile\", \"path\": \"apps/mobile\", \"description\": \"The mobile client\" }\n  ]\n}\n```\n\n`name` is required (the dedup key, matching the registry row's own `Project` column); `description` and `path` are optional. This key is display metadata only — no gate or resolver reads it, and single-project repos rightly have none. `vinaya doctor` reports, at `info` severity, when a registry row and a `projects` entry name the same project but only one of the two exists — never an error, since keeping only the registry file is a fully supported shape.\n\n### Token-usage collection for non-Claude-Code hosts (`tokens.collect`)\n\n`vinaya tokens` ships one collection adapter, for Claude Code — it reads that host's own session transcript. A repo whose coding-agent host is something else (Codex, Grok build, or any other harness) has no route to a real `Tokens:` line without declaring one:\n\n```json\n{\n  \"tokens\": {\n    \"collect\": \"node scripts/collect-usage.js\"\n  }\n}\n```\n\n**`tokens.collect` must be exactly `\"<interpreter> <repo-relative-script-path>\"`** — two whitespace-separated tokens, nothing else: no flags, no extra arguments, no shell syntax (`&&`/`|`/`;`), no quoting. `vinaya tokens` spawns the interpreter directly with the script as its one argument — never through a shell — whenever it is declared and `--in`/`--out` are not given, and parses its stdout as a JSON object shaped:\n\n```json\n{\n  \"inputTokens\": 0,\n  \"outputTokens\": 0,\n  \"cacheCreationInputTokens\": 0,\n  \"cacheReadInputTokens\": 0,\n  \"model\": \"your-model-id-or-null\"\n}\n```\n\nAbsent, `vinaya tokens` falls back to the shipped Claude Code transcript adapter unchanged — this key only adds a second route, never removes the first, and a Claude Code adopter continues to get working enforcement on `vinaya upgrade` having declared nothing. When declared, a command that exits non-zero or prints output that doesn't parse into that shape fails loudly rather than silently falling back to the transcript route or emitting a plausible `0/0/—`.\n\nThis is an opt-in collection route, not a capability declaration: whether a host is treated as capable of metering itself is always *probed*, never read from this key — there is no `tokens.metering` field.\n\nRead from the repo-root config only, same trust class as `checks`/`principals`/`releaseActor`: a value that decides what command runs on this turn must come from the reviewed, committed per-repo file, never a machine-wide personal config — a global `~/.vinaya/config.json`'s `tokens` key is stripped at load time with a loud stderr warning, never resolved.\n\nUnlike `ci.setup` — which only ever executes inside a generated, reviewed CI workflow step, under the runner's own isolation — a declared `tokens.collect` script executes IN-PROCESS, unsandboxed, on whatever machine runs the ordinary `vinaya tokens` command. Three layers close that gap:\n\n- **Rigid grammar.** The `\"<interpreter> <script>\"` restriction above is not a style preference — it is what makes the content pin below rigorous rather than heuristic. Because a declaration can only ever mean one file, `vinaya tokens` never has to guess which token of an open-ended shell string \"looks like a path\".\n- **Trust gate, content-pinned.** `vinaya tokens` refuses to run `tokens.collect` at all until a human has explicitly approved this exact interpreter/script declaration, AT the script's exact current content, for this repo, on this machine: run `vinaya tokens --trust-collect` once. Approval is keyed to this repo's git common directory, not to any one worktree, so it survives a fresh `git worktree add` of the same repo; a different interpreter, a different script path, or so much as one byte of script content changing — committed or not — needs its own fresh approval. Approvals live in `~/.vinaya/tokens-collect-trust.json`, machine-local and never read from any committed file, so a pull request can no more grant itself trust than it can add itself to `principals`.\n- **Printed audit trail.** Once trusted, `vinaya tokens` still prints the exact interpreter/script to stderr immediately before every run, so nothing executes invisibly even after approval.\n\nThis is a trust-then-verify design, not a blocking interactive prompt — the unattended-agent path this key exists for keeps working once a human has approved the script's content a single time. Editing only the script, never `vinaya.config.json`, requires that same fresh approval again — this is the specific gap two earlier, less rigid designs left open (security review, PR #303), and the reason the grammar above is fixed rather than an arbitrary shell string.\n\n## Where the git hooks live\n\n`vinaya init` installs the ring-0 hooks (`pre-commit`, `pre-push`, `commit-msg`) into a **tracked** `.vinaya/hooks/` directory and points git at it with `git config core.hooksPath .vinaya/hooks` — commit that directory. Raw `.git/hooks` is never versioned by git, so hooks installed there exist only on the installing machine; tracked hooks travel with the repo into every clone and every linked worktree checkout.\n\nOne thing git cannot version is the config itself: **each fresh clone runs `git config core.hooksPath .vinaya/hooks` once** to arm the hooks (linked worktrees inherit it — the config is shared, the path is relative). `vinaya doctor` reports an unarmed clone as an error naming that exact command; `vinaya init` and `vinaya upgrade` also set it.\n\nTwo shapes deviate: a repo already using **husky** keeps its `.husky/` directory (husky's `prepare` script owns per-clone wiring), and a repo with its own active raw hooks in `.git/hooks` stays on the legacy append-a-managed-block layout there — re-routing `core.hooksPath` would silently disable the adopter's own hooks. On that legacy layout `vinaya doctor` warns that clones have no hooks, and `vinaya upgrade` migrates to the tracked layout as soon as nothing foreign would be disabled.\n\nOn that legacy `.git/hooks` layout, note where the hook actually lives: hooks are never per-worktree, so its real home is the main checkout's shared hooks directory (`git rev-parse --git-common-dir`), which from a linked worktree is outside that worktree's own root. `vinaya eject` follows the hook there and bounds the removal to that directory's `hooks/` subtree, rather than to the worktree root — so ejecting from a linked worktree strips the hook instead of leaving it armed. A canonically spelled block path resolving anywhere else is refused, and the refusal is whole-run: `eject` removes nothing at all rather than making a partial destructive pass. (The `.git/` test is byte-exact, so a non-canonical spelling takes the working-tree branch instead — nothing vinaya generates produces one.)\n\n## Claude Code Stop hook (transcript pointer)\n\nWhen `--agents` includes `claude` (the default), `vinaya init`/`vinaya upgrade` also install a Claude Code `Stop` hook — `.claude/hooks/track-transcript.sh`, registered in `.claude/settings.json` — that records each session's transcript pointer (session id and transcript path, tab-separated) to `${TMPDIR:-/tmp}/claude-transcript-<sanitized-project-dir>-<sha256-of-project-dir>.txt`. Appending a full `SHA-256` digest of the (uncollapsed) project directory keeps two project directories whose paths differ only in non-alphanumeric characters (e.g. `/a/b` vs `/a-b`) from sharing one pointer file — the sanitized prefix alone would collapse both to the same name (`#315`). The reader falls back to the pre-`#315`, digest-less filename when the new one is absent, so a pointer an older hook already wrote stays readable. This is the pointer `packages/aeg-core/bin/report-tokens.ts`'s token-report adapter reads, so a fresh Claude Code adopter's token-report obligation resolves without an operator naming a transcript by hand, and without falling back to scanning `~/.claude/projects/` for the newest file (which grabs the wrong session's transcript when two worktrees run concurrently). The adapter reads both the primary and legacy pointer names through the same hardened, symlink-and-FIFO-safe I/O every other metering call site uses (`hardenedMeteringDeps()`, `packages/aeg-core/src/metering-io-guard.ts`), never a hand-rolled `existsSync`/`readFileSync` pair.\n\nThe script follows the same never-clobber discipline as the git hooks above: it is a marker-delimited managed block, appended onto an adopter's existing file at that path rather than overwritten. `.claude/settings.json`, by contrast, is refuse-if-foreign (created only when absent) — strict JSON has no comment syntax the marker convention could use, so an adopter's existing `settings.json` is left untouched; wire the hook in by hand (see the install diff's REFUSE guidance) if you already have one.\n\n## Agent-native entry points (`--agents`)\n\n`vinaya init` writes three agent-native entry points by default, one per vendor: `.agents/skills/vinaya-<role>/SKILL.md` (Agent skills, below), `.claude/commands/vinaya.md` (Claude Code command), and `.gemini/commands/vinaya.toml` (Gemini CLI command). Each one is a thin pointer that shells out to `vinaya doctrine --role <role> --print` at read time — one hop: the pointer's own output IS the role's doctrine, never a path the agent has to read a second time. There is exactly one source of role doctrine, never a copy baked into any of these files.\n\n`vinaya init --agents=<comma-list|all|none>` controls which of the three get written — `all` (the default) writes all three, `none` writes none, and a comma-separated list (e.g. `--agents=claude,gemini`) writes exactly the named vendors. There is no interactive prompt: `init` is scriptable/CI-safe today, and prompting would break that. The selection is persisted into `vinaya.config.json`'s `managed.agents` — `vinaya upgrade`/`vinaya doctor` read it back rather than re-deriving a default, so a repo initialized with a narrowed selection never has a later flagless `vinaya upgrade` silently add the other vendors' files, nor silently drop the recorded selection; a vendor left out is simply invisible to `vinaya doctor` rather than reported as \"not installed\". `vinaya eject` removes whichever of the three are actually owned, the same way it removes every other vinaya-managed artifact.\n\nA repo whose `vinaya.config.json` predates this feature entirely (no `managed.agents` key at all — never `--agents=none`, which persists a real empty array) is treated as every vendor, the same default a fresh `vinaya init` gives everyone else: the next `vinaya upgrade` writes all three files without anyone ever needing to re-run `init` by hand. Only an *explicit* selection — narrower or empty — is ever respected as a standing choice.\n\n## Agent skills\n\nGenerates skill pointers under `.agents/skills/vinaya-<role>/SKILL.md`, for tools natively scanning `.agents/skills/` (Codex, Antigravity, Grok Build) — one file per role discovered under `aeg-root/roles/*.md`, excluding `principal` (the one seat this doctrine never grants an agent). Each file is a 3-line pointer delegating to `vinaya doctrine --role <role> --print` at read time — one hop: the printed output is the role's doctrine itself. A role that declares an `allowed-tools` grant (today, only the Operator) carries it into the generated skill's own frontmatter, the same grant the router enforces. A role that declares `denied-tools` (every agent role but the Operator — the verbs its own prose already forbids) carries them as a plain body line instead, never a frontmatter grant: `disallowed-tools` is a Claude-Code-only frontmatter extension, absent from the portable Agent Skills spec this file's own target hosts implement, and Claude Code itself never reads this file at all (it gets its own `.claude/commands/vinaya.md` instead) — so no host this file reaches has a confirmed mechanism to enforce the denial from a frontmatter field, and the body line keeps it visible rather than silently dropped.\n\n## Gemini CLI command\n\nGenerates `.gemini/commands/vinaya.toml`, Gemini CLI's own custom-command surface. It emits ONE parameterized command, invoked `/vinaya <role>`, whose `prompt` field embeds `!{vinaya doctrine --role {{args}} --print}`: Gemini CLI substitutes the typed role into `{{args}}`, shell-escaping it automatically, before running the shell block — and it always prompts the user to confirm the exact resolved command first, with no documented bypass. Role-argument validation stays in `vinaya doctrine --role` alone (`commands/doctrine.ts`), not duplicated here.\n\n## Claude Code command\n\nGenerates a single parameterized `.claude/commands/vinaya.md`, invoked `/vinaya <role>`. The file uses Claude Code's `$ARGUMENTS` substitution to shell out to `vinaya doctrine --role \"$ARGUMENTS\" --print` at read time, scoped by `allowed-tools: Bash(vinaya doctrine *)` so it runs without a permission prompt.\n\n**Security note:** Claude Code substitutes `$ARGUMENTS` into the command as a raw, pre-shell text splice — the substitution happens before bash parses the line, so the role token can carry live shell syntax. Double-quoting (`\"$ARGUMENTS\"`) closes the `;`/`|`/`&&` class the substitution's own documented apostrophe bug demonstrates, but — verified empirically, not assumed — it does **not** close `$(...)`/backtick command substitution (still executes inside double quotes), and no quote character can be made airtight against this kind of splice at all: an attacker's token can always contain that same quote character, close it early, inject a command, then reopen a matching quote so the rest of the line still parses. `vinaya doctrine --role`'s own handling (`doctrine.ts`) validates whatever argument it actually receives against the exact set of role names live-discovered from `aeg-root/roles/*.md` and refuses anything else — that gate is real and load-bearing for its own scope, but an injected `$(...)` or quote-breakout command never reaches it as an argument; it runs at the shell level first. The actual remaining backstop is Claude Code's own `allowed-tools: Bash(vinaya doctrine *)` permission matcher refusing to auto-run a chained/injected command — a platform property outside this repo's control, unverified as of this writing. Do not describe this as fully closed in any future edit here or in the emitter; it is reduced, not closed.\n\nCustom checks register under `checks`, one entry per check. **Every key must be namespaced `<yourname>/<id>`** — exactly one `/`, both segments matching `[a-z0-9][a-z0-9-]*`, with `vinaya` reserved as a prefix:\n\n```json\n{\n  \"checks\": {\n    \"myteam/my-check\": {\n      \"run\": \"./scripts/my-check.ts\",\n      \"scope\": \"diff\",\n      \"include\": [\"src/**/*.ts\"],\n      \"timeoutMs\": 30000\n    }\n  }\n}\n```\n\nThe one exception is a key that exactly matches a **core** check id: that is an override, and it **replaces** the core check — the core one stops running. Anything else — a bare, un-namespaced key matching no core id — is rejected, and `vinaya check` then refuses the **entire** run (exit 1, nothing executes) rather than running a partial ruleset. Note that a prefix alone is not always enough: if the bare name already breaks the segment grammar (`my_check`, `QALint`), it still breaks it after prefixing and needs a real rename. Run `vinaya check --plan` to see exactly how your config resolves before it runs, and `vinaya doctor` to diagnose a config that is being refused.\n\nGlob scoping (`include`) is permitted; conditional logic (`if`/`unless`/`except`) is **never** part of this grammar — see the check-contract quick reference below for the full grammar and the error contract every registered `run` executable must honor.\n\n## Roles config\n\nPer-role override and additive-role registration works the same way `checks` does, under `vinaya.config.json`'s own `roles` key — one entry per role, each naming a `contract`: a markdown file, structurally validated against the same shape a bundled role doc carries (`role_id`, `description`, `actor`, `performs`, `refuses_when`, `summary` in frontmatter, plus `title` and `order`, plus a non-empty `## The short version` body section):\n\n```json\n{\n  \"roles\": {\n    \"security\": { \"contract\": \"./roles/custom-security.md\" },\n    \"acme/qa-lead\": { \"contract\": \"./roles/qa-lead.md\" }\n  }\n}\n```\n\nA key that exactly matches a **core** role id (`developer`, `security`, and the rest of the bundled doctrine roles) is an override — a **complete replacement**, never a frontmatter patch — whose contract's own `role_id` must equal that key exactly. Any other key must be namespaced `<yourname>/<id>`, same grammar as `checks`, and is additive — its contract's own `role_id` must equal the key's post-`/` segment exactly, and that render id must not collide with a core role id or another additive role's render id. Unlike `checks`, there is no grace period here: a malformed entry (a shape violation, a `role_id` mismatch, a collision, a bare unnamespaced key) fails closed immediately, since `roles` config has no legacy population a warn window would need to keep working. `contract` is a path, resolved relative to `vinaya.config.json`'s own directory — a bare filename with no `/` is rejected at load, the same discipline `checks.run`'s executable path does not need but a file **read** benefits from. Only registrable from a repo-local `vinaya.config.json`; a global `~/.vinaya/config.json`'s `roles` key is stripped at load time, since a role contract becomes agent-facing doctrine (`vinaya doctrine --role` hands it to a third-party agent tool as operating instructions).\n\nRun `vinaya check --plan` to see the resolved role registry before anything renders from it — a `RENDERS AS` column (the registry key and the role's own `role_id` differ once an additive entry is namespaced) and a `GATING` column (`core` for a `default`/`overridden` role, `inert` for an `additive` one — no core `ACTIONS` wiring exists for a render id core doctrine never declared).\n\n## Check contract — quick reference\n\nFull field-by-field reference: [vinaya.attalabs.dev/docs/cli](https://vinaya.attalabs.dev/docs/cli). The short version — what an executable must do to be a valid check:\n\n- Exit `0` to pass, `1` to report findings. Any other exit code reads as `status: 'error'` to the runner.\n- Emit findings as JSON lines on stderr, one per line: `{ schema: 1, check, severity: 'error' | 'warning', message, agent_recovery_prompt, file?, line?, pending? }`.\n- `pending: true` marks a finding that is \"has not happened yet\", not \"is wrong\" — a gate reading an artefact a later step of the same turn produces. A report renders it as a wait rather than an error, instead of guessing that distinction back out of the message text.\n- `agent_recovery_prompt` is a corrective **instruction**, not a restated diagnosis — it tells the model what to do, not what is wrong (that's `message`'s job).\n- Never self-enforce a timeout — the runner does that (`vinaya.config.json`'s `timeoutMs`, or the runner's default).\n- Never reach the network unless explicitly declared as an exception (today: none of the custom-check surface; the core `coherence`/`dispatch-readiness` checks are the only declared exceptions).\n- `token-collection-wired` (ring 0, part of `vinaya check --all --local`'s managed hooks) is a worked example of this contract's narrowest shape: it consults only local `fs`/`process.env` — no PR body, no network — and refuses a commit only when the host's token-metering probe (`resolveMeteringCapability`, `@attalabs/aeg-core`) found a transcript pointer that is this session's on one of two grounds — its recorded id matches ours and the transcript it named could not be reached, or its id could not be read at all yet the file sits at this project's own pointer path owned by this user, which is broken wiring whoever wrote it. A host never wired to meter passes, and so does one holding only a pointer that provably belongs to another session — a plain human terminal carrying an earlier session's leftover, or a second agent session whose Stop hook has not fired yet. Both are the sanctioned operator-metered case, not a wiring defect.\n- `token-report` (ring 1, `requiresOpenPr`) is a worked example of the CI-only shape: it reads `PR_BODY` and re-runs the same `resolveMeteringCapability` probe fresh in its own process, then fails only when the host is metering-capable AND the PR body's \"Token report\" section is missing, or carries a blank/non-numeric Tokens in/out cell — an incapable host, or an empty `PR_BODY` (no PR yet), both pass silently. It proves presence and shape only, never that the reported figures are true — a check has no transcript of its own to recompute them against. A probe that itself throws (as opposed to cleanly reporting incapable) is never caught into a false pass: left uncaught, it surfaces as `status: 'error'` through the runner's own malformed-stderr path, never a silent `status: 'pass'`.\n- `exec-bits` (ring 0, part of `vinaya check --all --local`'s managed hooks) is a worked example of a diff-scoped local check: for every changed file that lives under a `checks/bin/` directory or begins with a `#!` line, it reads the mode git has in the INDEX (`git ls-files -s`) and fails on anything but `100755`. The index, never the working tree — a `chmod +x` on disk changes nothing git ships, so the exec bit is the one property that can be right locally and wrong for everyone who checks the repo out. A check bin is spawned directly, never through a shell, so a bin committed `100644` cannot start at all.\n\n`vinaya new check <yourname>/<id>` scaffolds a worked, self-contained example that honors this contract out of the box, and prints the exact — namespaced — registration to paste.\n\n## JSON output envelope\n\nEvery machine-readable (`--json`) output is wrapped in `{ schema: 1, data: ... }`. The `schema` field is a public-surface commitment — no code path in this package emits unversioned machine output.\n\n## Generated CI in a repo that vendors this CLI\n\n`init` and `upgrade` normally generate workflows that invoke the published package at the exact version that generated them, `npx --yes @attalabs/vinaya@<version>` — the same pin the generated git hooks carry, so CI's version is a committed fact rather than whatever the runner happens to resolve. (An unpinned `npx` would not mean \"latest\". If you declare `ci.setup`, the workflow installs your dependencies first, so a repo carrying this CLI as a devDependency silently runs *that* copy; if you declare no `ci.setup`, no install step is generated and a bare spec resolves whatever the registry serves that day. `vinaya upgrade` re-pins; `vinaya doctor` reports a stale pin as drift.) In a repo whose own `workspaces` include a member named `@attalabs/vinaya`, that invocation cannot work: npm matches the name against the workspace member *before* reading any version spec, resolves that member's `bin`, and execs a file nothing has built — `sh: vinaya: command not found`. Pinning a version does not help, because the name is matched first.\n\nSo `init` detects that case and generates a different shape for it: install, build the vendored member, and invoke its built `bin` by path. The detection is exact — a workspace member whose `package.json` `name` is `@attalabs/vinaya`, which is precisely the condition npm itself branches on. Every other repo keeps the published invocation unchanged.\n\nTwo things that shape puts into your CI, stated plainly because this is the only place you can read them:\n\n- **A third-party action.** `oven-sh/setup-bun`, pinned to a commit rather than a mutable tag, is added to the jobs that build. It is the only non-`actions/*` action this tool writes into a repository, and it is emitted **only** in the vendored shape — an ordinary adopter's workflows contain none.\n- **`bun install --ignore-scripts`.** The install runs against your pull request's own manifest, so the flag blocks the PR-controlled surface: your repo's root and workspace lifecycle scripts, plus anything a PR adds to `trustedDependencies`. If your install genuinely needs those scripts, this shape will fail at the build step rather than run them.\n\nA repo on the vendored shape runs the CLI **from its own working tree**, so its CI exercises the code in the pull request rather than a published copy predating it. The consequence is worth stating plainly: a pull request that edits this package's check sources changes the checks that judge it.\n\nThe generated command embeds the member's directory and `bin` path. Both com","readmeFilename":"README.md"}