{"_id":"@bbk1ng/agent-orch","_rev":"14-057ebe6f799a781d2d661c65596d9cd1","name":"@bbk1ng/agent-orch","dist-tags":{"latest":"0.5.0"},"versions":{"0.2.0":{"name":"@bbk1ng/agent-orch","version":"0.2.0","keywords":["ai-agents","orchestration","code-review","cross-audit","claude","codex","cli"],"license":"PolyForm-Noncommercial-1.0.0","_id":"@bbk1ng/agent-orch@0.2.0","maintainers":[{"name":"bbk1ng","email":"bmilinkovic@gmail.com"}],"homepage":"https://github.com/bbK1ngSrb/agent-orch#readme","bugs":{"url":"https://github.com/bbK1ngSrb/agent-orch/issues"},"bin":{"orch":"bin/orch.js"},"dist":{"shasum":"9ff4d966eadfb6056c55d269c3abe9d6ae1fb2e5","tarball":"https://registry.npmjs.org/@bbk1ng/agent-orch/-/agent-orch-0.2.0.tgz","fileCount":39,"integrity":"sha512-Et3nSt01A6a06T6RPfYlztzwvHY6tsxLcCVXCNDsIGS+aGv9dPY5MbfaBvpqdvi8PJhR3ZQFKVTAU6xR6eYitg==","signatures":[{"sig":"MEYCIQCOeYaG4TgimV4T2RVRQBoYp3Vyc2lZUXaIBt6Fo43aCAIhAO4B910cArXQUlxAV3CIVn9DNfizCiZ5RN/viHg0Vqnd","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":183803},"type":"module","engines":{"node":">=18"},"gitHead":"bcfe31d5a5a5105d16267d49ac517084123a205f","scripts":{"test":"node --test","prepublishOnly":"npm test"},"_npmUser":{"name":"bbk1ng","email":"bmilinkovic@gmail.com"},"repository":{"url":"git+https://github.com/bbK1ngSrb/agent-orch.git","type":"git"},"_npmVersion":"11.14.0","description":"Run local coding agents in a cross-audit loop on any git repo — author, cross-audit, test-gate, merge. Educational; not for production.","directories":{},"_nodeVersion":"25.2.1","dependencies":{"yaml":"^2.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-orch_0.2.0_1783149978781_0.5489302085565932","host":"s3://npm-registry-packages-npm-production"}},"0.2.3":{"name":"@bbk1ng/agent-orch","version":"0.2.3","keywords":["ai-agents","orchestration","code-review","cross-audit","claude","codex","cli"],"license":"PolyForm-Noncommercial-1.0.0","_id":"@bbk1ng/agent-orch@0.2.3","maintainers":[{"name":"bbk1ng","email":"bmilinkovic@gmail.com"}],"homepage":"https://github.com/bbk1ng/agent-orch#readme","bugs":{"url":"https://github.com/bbk1ng/agent-orch/issues"},"bin":{"orch":"bin/orch.js"},"dist":{"shasum":"28cb29bf5f5af547948785c67efbec43b2801542","tarball":"https://registry.npmjs.org/@bbk1ng/agent-orch/-/agent-orch-0.2.3.tgz","fileCount":40,"integrity":"sha512-bStVb2tR/U3vKXxb7p+CnaIt1bh7WeX6cwZYosateO+syL3fD89mvv84lYrOw5hgWWIiG7GLBUDc50jWKsNLxw==","signatures":[{"sig":"MEUCIQD8xFnTG6qgHrtYFSfqJEbqyr2Bv9PNTs49pls2Nxj5mwIgedfOQPw9kV4ipGFZgDYMtfIij/ter1gGe5Tiw+ONTBI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":188256},"type":"module","engines":{"node":">=18"},"gitHead":"57254bf6357ff7b93c3539c6e68f2247593d6328","scripts":{"test":"node --test","prepublishOnly":"npm test"},"_npmUser":{"name":"bbk1ng","email":"bmilinkovic@gmail.com"},"repository":{"url":"git+https://github.com/bbk1ng/agent-orch.git","type":"git"},"_npmVersion":"11.14.0","description":"Run local coding agents in a cross-audit loop on any git repo — author, cross-audit, test-gate, merge. Educational; not for production.","directories":{},"_nodeVersion":"25.2.1","dependencies":{"yaml":"^2.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-orch_0.2.3_1783183618633_0.8434096507932529","host":"s3://npm-registry-packages-npm-production"}},"0.2.15":{"name":"@bbk1ng/agent-orch","version":"0.2.15","keywords":["ai-agents","orchestration","code-review","cross-audit","claude","codex","cli"],"license":"PolyForm-Noncommercial-1.0.0","_id":"@bbk1ng/agent-orch@0.2.15","maintainers":[{"name":"bbk1ng","email":"bmilinkovic@gmail.com"}],"homepage":"https://github.com/bbk1ng/agent-orch#readme","bugs":{"url":"https://github.com/bbk1ng/agent-orch/issues"},"bin":{"orch":"bin/orch.js"},"dist":{"shasum":"60992f2416344035d9bce53936f87bcd6a3c7bda","tarball":"https://registry.npmjs.org/@bbk1ng/agent-orch/-/agent-orch-0.2.15.tgz","fileCount":44,"integrity":"sha512-V8znESHAFIroLU9Ov9UlQasCO5acbgFS7D+Oq49DRjsjM6TS6HzUQeLdcVl00AXEa8v+olep5UwT5K9sOb75Fg==","signatures":[{"sig":"MEUCIBPMSPxwiHwaZfM6QZ4dNWLWSL28JSvtCxBsDLgbuWeSAiEAoYenBk+NPRXNU3nlm5d02tpgPleUgpNbqUcgC7eMChY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bbk1ng%2fagent-orch@0.2.15","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":203302},"type":"module","engines":{"node":">=18"},"gitHead":"1429b456d4d164b44d57791636edf70bc6499b00","scripts":{"test":"node --test","postinstall":"node bin/orch.js completion install","prepublishOnly":"npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:19ac249f-a0ed-4fa8-a930-b074f108c0a9"}},"repository":{"url":"git+https://github.com/bbk1ng/agent-orch.git","type":"git"},"_npmVersion":"11.16.0","description":"Run local coding agents in a cross-audit loop on any git repo — author, cross-audit, test-gate, merge. Educational; not for production.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"yaml":"^2.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-orch_0.2.15_1783294353900_0.7594854841739203","host":"s3://npm-registry-packages-npm-production"}},"0.2.16":{"name":"@bbk1ng/agent-orch","version":"0.2.16","keywords":["ai-agents","orchestration","code-review","cross-audit","claude","codex","cli"],"license":"PolyForm-Noncommercial-1.0.0","_id":"@bbk1ng/agent-orch@0.2.16","maintainers":[{"name":"bbk1ng","email":"bmilinkovic@gmail.com"}],"homepage":"https://github.com/bbk1ng/agent-orch#readme","bugs":{"url":"https://github.com/bbk1ng/agent-orch/issues"},"bin":{"orch":"bin/orch.js"},"dist":{"shasum":"230267a5698a4e0159cc9488c02a2ff4a6461ad9","tarball":"https://registry.npmjs.org/@bbk1ng/agent-orch/-/agent-orch-0.2.16.tgz","fileCount":44,"integrity":"sha512-WzChTj+40KrUDIK/teh3sRFZcRA23+VjlA0+nQFUdUiEbIvJJU3Ujh1hUGVu1dYQ/KUCCLmvkq5M7eIrFY449A==","signatures":[{"sig":"MEYCIQCUW2b4wmnqff3PBT5WDLY9FWy+3IrXtjj1I7AoKbjmbgIhAPtjwrNhSOhmbX0xLh3jdbCRC/AFb2rZpK0VBXOtLwNl","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bbk1ng%2fagent-orch@0.2.16","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":219489},"type":"module","engines":{"node":">=18"},"gitHead":"4a2a33a155dc3f9eb62f4add777e8d3f2e52acdc","scripts":{"test":"node --test","postinstall":"node bin/orch.js completion install","prepublishOnly":"npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:19ac249f-a0ed-4fa8-a930-b074f108c0a9"}},"repository":{"url":"git+https://github.com/bbk1ng/agent-orch.git","type":"git"},"_npmVersion":"11.16.0","description":"Run local coding agents in a cross-audit loop on any git repo — author, cross-audit, test-gate, merge. Educational; not for production.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"yaml":"^2.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-orch_0.2.16_1783302385264_0.07719892626129377","host":"s3://npm-registry-packages-npm-production"}},"0.3.11":{"name":"@bbk1ng/agent-orch","version":"0.3.11","keywords":["ai-agents","orchestration","code-review","cross-audit","claude","codex","cli"],"license":"PolyForm-Noncommercial-1.0.0","_id":"@bbk1ng/agent-orch@0.3.11","maintainers":[{"name":"bbk1ng","email":"bmilinkovic@gmail.com"}],"homepage":"https://github.com/bbk1ng/agent-orch#readme","bugs":{"url":"https://github.com/bbk1ng/agent-orch/issues"},"bin":{"orch":"bin/orch.js"},"dist":{"shasum":"0346900fa69b23acd8affd2353dfa5d1780b78a1","tarball":"https://registry.npmjs.org/@bbk1ng/agent-orch/-/agent-orch-0.3.11.tgz","fileCount":46,"integrity":"sha512-WxPpwcECdmsuynGCOSYuufbvOZagDpR/ZbS+VIxHPpsg9H2kUx7CuEmRi9TQXVaXvd64aQx416PCXmSQUBVzfg==","signatures":[{"sig":"MEUCID7aGqns5ipnqJikercVVE+XaRKT4wQDL7aeP+HbycwvAiEA7IFUi4xeE4ugaIvKSRGzv1KzqPZWYXDQEAnwM5wyyf8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bbk1ng%2fagent-orch@0.3.11","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":236468},"type":"module","engines":{"node":">=18"},"gitHead":"0e751a9b2b8df28613acfdb2b86184fd73de4de5","scripts":{"test":"node --test","postinstall":"node bin/orch.js completion install","prepublishOnly":"npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:19ac249f-a0ed-4fa8-a930-b074f108c0a9"}},"repository":{"url":"git+https://github.com/bbk1ng/agent-orch.git","type":"git"},"_npmVersion":"11.16.0","description":"Run local coding agents in a cross-audit loop on any git repo — author, cross-audit, test-gate, merge. Educational; not for production.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"yaml":"^2.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-orch_0.3.11_1783494256761_0.8023058645511287","host":"s3://npm-registry-packages-npm-production"}},"0.3.16":{"name":"@bbk1ng/agent-orch","version":"0.3.16","keywords":["ai-agents","orchestration","code-review","cross-audit","claude","codex","cli"],"license":"PolyForm-Noncommercial-1.0.0","_id":"@bbk1ng/agent-orch@0.3.16","maintainers":[{"name":"bbk1ng","email":"bmilinkovic@gmail.com"}],"homepage":"https://github.com/bbk1ng/agent-orch#readme","bugs":{"url":"https://github.com/bbk1ng/agent-orch/issues"},"bin":{"orch":"bin/orch.js"},"dist":{"shasum":"f98e78b6a822f98f39490cda901738302458b768","tarball":"https://registry.npmjs.org/@bbk1ng/agent-orch/-/agent-orch-0.3.16.tgz","fileCount":46,"integrity":"sha512-PUDI3gPNzFGIqxXqN7s9ZsNcRJJaRd7NKNk7bpyKgPO2sxIgdUFv+oio+DP0KKCXMU8uRW0l3VRWwMWPWRY1HQ==","signatures":[{"sig":"MEYCIQDuTOKie8JGiVnHCb69Exqups3YXoN0M5dOVeoXFS9puQIhAJwxf+Thna72tHM4QrHhlaGQIJ1TzHgcO4jgq7rnf7GQ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bbk1ng%2fagent-orch@0.3.16","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":245248},"type":"module","engines":{"node":">=18"},"gitHead":"9a7840f8ed1de8641802e71b2cf2a0dc87ca071b","scripts":{"test":"node --test","postinstall":"node bin/orch.js completion install","prepublishOnly":"npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:19ac249f-a0ed-4fa8-a930-b074f108c0a9"}},"repository":{"url":"git+https://github.com/bbk1ng/agent-orch.git","type":"git"},"_npmVersion":"11.16.0","description":"Run local coding agents in a cross-audit loop on any git repo — author, cross-audit, test-gate, merge. Educational; not for production.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"yaml":"^2.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-orch_0.3.16_1783524811440_0.664488757508142","host":"s3://npm-registry-packages-npm-production"}},"0.3.20":{"name":"@bbk1ng/agent-orch","version":"0.3.20","keywords":["ai-agents","orchestration","code-review","cross-audit","claude","codex","cli"],"license":"PolyForm-Noncommercial-1.0.0","_id":"@bbk1ng/agent-orch@0.3.20","maintainers":[{"name":"bbk1ng","email":"bmilinkovic@gmail.com"}],"homepage":"https://github.com/bbk1ng/agent-orch#readme","bugs":{"url":"https://github.com/bbk1ng/agent-orch/issues"},"bin":{"orch":"bin/orch.js"},"dist":{"shasum":"7baa5e181fa4ea987be7330db97ac3166996141b","tarball":"https://registry.npmjs.org/@bbk1ng/agent-orch/-/agent-orch-0.3.20.tgz","fileCount":46,"integrity":"sha512-/Ien3H60giJ5gYa9XrVYQW+KH5slwzB1W/xHL4FcRKiEk6DRTbwvhizUIKRy+Ky/yQyWsj7ASpyYVEnMOnNpBw==","signatures":[{"sig":"MEUCIGrpm2GIF87VtBA3zim7zUJn3ump4yXzEQTwwHT6f/28AiEAhy6mhEVLo0U0687gBICkth6cFoqWpToFXhgWHuUiP7I=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bbk1ng%2fagent-orch@0.3.20","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":247188},"type":"module","engines":{"node":">=18"},"gitHead":"b463102be19c356969622d1b8b239b79cde1e58c","scripts":{"test":"node --test","postinstall":"node bin/orch.js completion install","prepublishOnly":"npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:19ac249f-a0ed-4fa8-a930-b074f108c0a9"}},"repository":{"url":"git+https://github.com/bbk1ng/agent-orch.git","type":"git"},"_npmVersion":"11.16.0","description":"Run local coding agents in a cross-audit loop on any git repo — author, cross-audit, test-gate, merge. Educational; not for production.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"yaml":"^2.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-orch_0.3.20_1783629295664_0.05592711997077182","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@bbk1ng/agent-orch","version":"0.4.0","keywords":["ai-agents","orchestration","code-review","cross-audit","claude","codex","cli"],"author":{"name":"bbk1ng","email":"bmilinkovic@gmail.com"},"license":"PolyForm-Noncommercial-1.0.0","_id":"@bbk1ng/agent-orch@0.4.0","maintainers":[{"name":"bbk1ng","email":"bmilinkovic@gmail.com"}],"homepage":"https://github.com/bbk1ng/agent-orch#readme","bugs":{"url":"https://github.com/bbk1ng/agent-orch/issues"},"bin":{"orch":"bin/orch.js"},"dist":{"shasum":"5fa14ea7319ba1836ec3cd1350a90276bf6afc65","tarball":"https://registry.npmjs.org/@bbk1ng/agent-orch/-/agent-orch-0.4.0.tgz","fileCount":59,"integrity":"sha512-u05V6/fJ/lzz2kDkV+yVuxjADJtfM1uGvBq2EQXPwqrDHSoZv0hfD8IEiDCByLOuhRx8JzSo7Zbjnb+NLDXJ5g==","signatures":[{"sig":"MEUCIQDEQLc+LZg2XDD27rLh8xDOJHfEjp/GMSdU/piyNKa/BgIgSddQoVPErL36exP84kqVjSTsQVpXtWB+oIpC/+2AjmA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bbk1ng%2fagent-orch@0.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":341765},"type":"module","engines":{"node":">=18"},"gitHead":"2d7ea04a9b0c577e763f9d594fdaf7b0ea57fc5d","scripts":{"test":"node --test","postinstall":"node bin/orch.js completion install","prepublishOnly":"npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:19ac249f-a0ed-4fa8-a930-b074f108c0a9"}},"repository":{"url":"git+https://github.com/bbk1ng/agent-orch.git","type":"git"},"_npmVersion":"11.16.0","description":"Run local coding agents in a cross-audit loop on any git repo — author, cross-audit, test-gate, merge. Educational; not for production.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"yaml":"^2.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-orch_0.4.0_1783818493976_0.661674642743493","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"@bbk1ng/agent-orch","version":"0.4.1","keywords":["ai-agents","orchestration","code-review","cross-audit","claude","codex","cli"],"author":{"name":"bbk1ng","email":"bmilinkovic@gmail.com"},"license":"PolyForm-Noncommercial-1.0.0","_id":"@bbk1ng/agent-orch@0.4.1","maintainers":[{"name":"bbk1ng","email":"bmilinkovic@gmail.com"}],"homepage":"https://github.com/bbk1ng/agent-orch#readme","bugs":{"url":"https://github.com/bbk1ng/agent-orch/issues"},"bin":{"orch":"bin/orch.js"},"dist":{"shasum":"9279cba0b5e7a54e5b60153ad136590232869fb0","tarball":"https://registry.npmjs.org/@bbk1ng/agent-orch/-/agent-orch-0.4.1.tgz","fileCount":59,"integrity":"sha512-xNSBqOWy3pXBMduUA3mKBAefkkajW7ZAoG/gz6lcZch/cGWkHhFbUuBuNzZvu8/UcMoOK48Nqhp1KgcyHVVx5g==","signatures":[{"sig":"MEQCIGCIGJ3l76ga8V0z4/yA4XKk1s2hfeoer3AtFge+OkXdAiBiM0//BZ0EDI6AcxmnwzE9XDzS8+B+8Y1iwoJpcolmAA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bbk1ng%2fagent-orch@0.4.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":341764},"type":"module","engines":{"node":">=18"},"gitHead":"1e87bfbece39cca3cf57ba324388b40afed8e31e","scripts":{"test":"node --test","postinstall":"node bin/orch.js completion install","prepublishOnly":"npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:19ac249f-a0ed-4fa8-a930-b074f108c0a9"}},"repository":{"url":"git+https://github.com/bbk1ng/agent-orch.git","type":"git"},"_npmVersion":"11.16.0","description":"Run local coding agents in a cross-audit loop on any git repo — author, cross-audit, test-gate, merge. Educational; not for production.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"yaml":"^2.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-orch_0.4.1_1783820098587_0.13546756897649126","host":"s3://npm-registry-packages-npm-production"}},"0.4.200":{"name":"@bbk1ng/agent-orch","version":"0.4.200","keywords":["ai-agents","orchestration","code-review","cross-audit","claude","codex","cli"],"author":{"name":"bbk1ng","email":"bmilinkovic@gmail.com"},"license":"PolyForm-Noncommercial-1.0.0","_id":"@bbk1ng/agent-orch@0.4.200","maintainers":[{"name":"bbk1ng","email":"bmilinkovic@gmail.com"}],"homepage":"https://github.com/bbk1ng/agent-orch#readme","bugs":{"url":"https://github.com/bbk1ng/agent-orch/issues"},"bin":{"orch":"bin/orch.js"},"dist":{"shasum":"236994abef6895c257bcf78c6f8b96e4ffe032d0","tarball":"https://registry.npmjs.org/@bbk1ng/agent-orch/-/agent-orch-0.4.200.tgz","fileCount":59,"integrity":"sha512-HEEYp8hU1/KEaa4aY+9REbkFc79VnjkGuPPhNgItte2zFBU1ICckYqIi2Xzd/U7q8Cmtnrancb7CgLe8EC+CxA==","signatures":[{"sig":"MEQCIFOg7WJruPYEcIRtwptBFakA61FszpjE6C0L3nmyKVUCAiAh/LW6QAc4HYh/SovuzwwPSh+v6+c0KP6ssMvRsHtZHA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bbk1ng%2fagent-orch@0.4.200","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":345484},"type":"module","engines":{"node":">=18"},"gitHead":"06f4b673a58e3c15a0f88d3c0e31346896cb6b36","scripts":{"test":"node --test","postinstall":"node bin/orch.js completion install","prepublishOnly":"npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:19ac249f-a0ed-4fa8-a930-b074f108c0a9"}},"repository":{"url":"git+https://github.com/bbk1ng/agent-orch.git","type":"git"},"_npmVersion":"11.16.0","description":"Run local coding agents in a cross-audit loop on any git repo — author, cross-audit, test-gate, merge. Educational; not for production.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"yaml":"^2.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-orch_0.4.200_1783862570537_0.8051114950877789","host":"s3://npm-registry-packages-npm-production"}},"0.4.209":{"name":"@bbk1ng/agent-orch","version":"0.4.209","keywords":["ai-agents","orchestration","code-review","cross-audit","claude","codex","cli"],"author":{"name":"bbk1ng","email":"bmilinkovic@gmail.com"},"license":"PolyForm-Noncommercial-1.0.0","_id":"@bbk1ng/agent-orch@0.4.209","maintainers":[{"name":"bbk1ng","email":"bmilinkovic@gmail.com"}],"homepage":"https://github.com/bbk1ng/agent-orch#readme","bugs":{"url":"https://github.com/bbk1ng/agent-orch/issues"},"bin":{"orch":"bin/orch.js"},"dist":{"shasum":"7ba06f095891332d4f8589aa86fff1f75c39ad99","tarball":"https://registry.npmjs.org/@bbk1ng/agent-orch/-/agent-orch-0.4.209.tgz","fileCount":61,"integrity":"sha512-UaPjNjhboAmubdPZBd+sogbc6Pq7fEUoRmprs9HVOQtzYa7PNXjW+bHf8gz0+NQi6Lws6SK1eLC6VfBIPxSFkQ==","signatures":[{"sig":"MEUCIEbaq7dWWiFd9FZo2EqEh6KjvI5rOst9ZoFo64JvohNWAiEA79FznsUE925AsUdVc9FfTylTa8B1xRm04/Xs2OHLzHc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bbk1ng%2fagent-orch@0.4.209","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":404490},"type":"module","engines":{"node":">=18"},"gitHead":"abd8bed54a2526436468e42671c8b1d5c8741d54","scripts":{"test":"node --test","prepare":"node scripts/install-hooks.js","postinstall":"node bin/orch.js completion install","prepublishOnly":"npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:19ac249f-a0ed-4fa8-a930-b074f108c0a9"}},"repository":{"url":"git+https://github.com/bbk1ng/agent-orch.git","type":"git"},"_npmVersion":"11.16.0","description":"Run local coding agents in a cross-audit loop on any git repo — author, cross-audit, test-gate, merge. Educational; not for production.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"yaml":"^2.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-orch_0.4.209_1785140437519_0.2734701384534348","host":"s3://npm-registry-packages-npm-production"}},"0.4.211":{"name":"@bbk1ng/agent-orch","version":"0.4.211","keywords":["ai-agents","orchestration","code-review","cross-audit","claude","codex","cli"],"author":{"name":"bbk1ng","email":"bmilinkovic@gmail.com"},"license":"PolyForm-Noncommercial-1.0.0","_id":"@bbk1ng/agent-orch@0.4.211","maintainers":[{"name":"bbk1ng","email":"bmilinkovic@gmail.com"}],"homepage":"https://github.com/bbk1ng/agent-orch#readme","bugs":{"url":"https://github.com/bbk1ng/agent-orch/issues"},"bin":{"orch":"bin/orch.js"},"dist":{"shasum":"89a50394744380af7f357bdbd751395dd6e53c92","tarball":"https://registry.npmjs.org/@bbk1ng/agent-orch/-/agent-orch-0.4.211.tgz","fileCount":61,"integrity":"sha512-AWd4Fg9j+jLe/h5RsrICs60y/qdaPeX7wqLbkY8+jfrHXlRLYjtxhpYE125lZ3fdQDVCn5ne0CScVeXplsqm+w==","signatures":[{"sig":"MEYCIQCjPVoNXldRg5KT3EyOKqlAxqK3d7QiU7flZaqKfmSOXAIhAK94SwtND7KQFES9eL3hsFXvfqMKC2N4kyX5XIdfwKoc","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bbk1ng%2fagent-orch@0.4.211","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":411042},"type":"module","engines":{"node":">=18"},"gitHead":"c3a680f8142fbf336123566cbb92b9a642a9fde0","scripts":{"test":"node --test","prepare":"node scripts/install-hooks.js","postinstall":"node bin/orch.js completion install","prepublishOnly":"npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:19ac249f-a0ed-4fa8-a930-b074f108c0a9"}},"repository":{"url":"git+https://github.com/bbk1ng/agent-orch.git","type":"git"},"_npmVersion":"11.16.0","description":"Run local coding agents in a cross-audit loop on any git repo — author, cross-audit, test-gate, merge. Educational; not for production.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"yaml":"^2.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-orch_0.4.211_1785407522250_0.9247765041650049","host":"s3://npm-registry-packages-npm-production"}},"0.4.300":{"name":"@bbk1ng/agent-orch","version":"0.4.300","keywords":["ai-agents","orchestration","code-review","cross-audit","claude","codex","cli"],"author":{"name":"bbk1ng","email":"bmilinkovic@gmail.com"},"license":"PolyForm-Noncommercial-1.0.0","_id":"@bbk1ng/agent-orch@0.4.300","maintainers":[{"name":"bbk1ng","email":"bmilinkovic@gmail.com"}],"homepage":"https://github.com/bbk1ng/agent-orch#readme","bugs":{"url":"https://github.com/bbk1ng/agent-orch/issues"},"bin":{"orch":"bin/orch.js"},"dist":{"shasum":"3acbff5d9c947ddc6a200c41acbd6d4194726384","tarball":"https://registry.npmjs.org/@bbk1ng/agent-orch/-/agent-orch-0.4.300.tgz","fileCount":62,"integrity":"sha512-4hZ+oIgWkpO5DeUSqXVhyABeYiztzzpvFjAoX0ZqIFi/5vxblvlSqTvkRUYtfNjHdjPTDDOWcLteFPsSmaoZRA==","signatures":[{"sig":"MEUCIQDUG8GNN+7GQOS8xCByemSAaIAQhbnLag6oJU3c0PrDwwIgCTjHNEaLqgE29NTOfcbda+x1Qc2jSReg/5qSTB3Z/ow=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bbk1ng%2fagent-orch@0.4.300","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":442267},"type":"module","engines":{"node":">=18"},"gitHead":"3e1abdde6cf199b68bec2a4ebb7e9b0cb7ecee15","scripts":{"test":"node --test","prepare":"node scripts/install-hooks.js","postinstall":"node bin/orch.js completion install","prepublishOnly":"npm test"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:19ac249f-a0ed-4fa8-a930-b074f108c0a9"}},"repository":{"url":"git+https://github.com/bbk1ng/agent-orch.git","type":"git"},"_npmVersion":"11.16.0","description":"Run local coding agents in a cross-audit loop on any git repo — author, cross-audit, test-gate, merge. Educational; not for production.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"yaml":"^2.4.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agent-orch_0.4.300_1786576790990_0.12646034994473943","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@bbk1ng/agent-orch","version":"0.5.0","description":"Run local coding agents in a cross-audit loop on any git repo — author, cross-audit, test-gate, merge. Educational; not for production.","author":{"name":"bbk1ng","email":"bmilinkovic@gmail.com"},"type":"module","bin":{"orch":"bin/orch.js"},"engines":{"node":">=18"},"scripts":{"test":"node --require=./test/helpers/temp-cleanup.cjs --test","prepare":"node scripts/install-hooks.js","prepublishOnly":"npm test","postinstall":"node bin/orch.js completion install"},"repository":{"type":"git","url":"git+https://github.com/bbk1ng/agent-orch.git"},"homepage":"https://github.com/bbk1ng/agent-orch#readme","bugs":{"url":"https://github.com/bbk1ng/agent-orch/issues"},"keywords":["ai-agents","orchestration","code-review","cross-audit","claude","codex","cli"],"publishConfig":{"access":"public"},"license":"PolyForm-Noncommercial-1.0.0","dependencies":{"yaml":"^2.4.0"},"gitHead":"51bedf847cd951e6124720173bf7cb2a79cfa802","_id":"@bbk1ng/agent-orch@0.5.0","_nodeVersion":"24.19.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-cb0foRzoqkoJ9eNF1ID/BYQqaSrUumLeHUoMXIZXIFjHZwReR4dQK/d+qY50SoqN7OAkzVhI3TWHqnw9mDk2lg==","shasum":"4466eb987d4ecb421b96e1b9f588d2a391612bc3","tarball":"https://registry.npmjs.org/@bbk1ng/agent-orch/-/agent-orch-0.5.0.tgz","fileCount":74,"unpackedSize":805194,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bbk1ng%2fagent-orch@0.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIFYDfujyqWhbqN+bpF/fkZGDZF9AjgR92usv5SGB79CpAiBDiHU/IPja6WAHWyjYfo+fC2V7F3Si8IjtqvZaznkV7w=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:19ac249f-a0ed-4fa8-a930-b074f108c0a9"}},"directories":{},"maintainers":[{"name":"bbk1ng","email":"bmilinkovic@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/agent-orch_0.5.0_1788166433413_0.1602687052651428"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-04T07:26:18.553Z","modified":"2026-08-31T08:53:53.844Z","0.2.0":"2026-07-04T07:26:18.917Z","0.2.3":"2026-07-04T16:46:58.776Z","0.2.15":"2026-07-05T23:32:34.066Z","0.2.16":"2026-07-06T01:46:25.412Z","0.3.11":"2026-07-08T07:04:16.911Z","0.3.16":"2026-07-08T15:33:31.581Z","0.3.20":"2026-07-09T20:34:55.795Z","0.4.0":"2026-07-12T01:08:14.134Z","0.4.1":"2026-07-12T01:34:58.725Z","0.4.200":"2026-07-12T13:22:50.676Z","0.4.209":"2026-07-27T08:20:37.735Z","0.4.211":"2026-07-30T10:32:02.458Z","0.4.300":"2026-08-12T23:19:51.174Z","0.5.0":"2026-08-31T08:53:53.546Z"},"bugs":{"url":"https://github.com/bbk1ng/agent-orch/issues"},"author":{"name":"bbk1ng","email":"bmilinkovic@gmail.com"},"license":"PolyForm-Noncommercial-1.0.0","homepage":"https://github.com/bbk1ng/agent-orch#readme","keywords":["ai-agents","orchestration","code-review","cross-audit","claude","codex","cli"],"repository":{"type":"git","url":"git+https://github.com/bbk1ng/agent-orch.git"},"description":"Run local coding agents in a cross-audit loop on any git repo — author, cross-audit, test-gate, merge. Educational; not for production.","maintainers":[{"name":"bbk1ng","email":"bmilinkovic@gmail.com"}],"readme":"<p align=\"center\">\n  <img src=\"https://raw.githubusercontent.com/bbk1ng/agent-orch/main/docs/assets/orch-banner.png\" alt=\"orch — agents orchestration tool\" width=\"820\">\n</p>\n\n# agent-orch\n\n[![npm](https://img.shields.io/npm/v/%40bbk1ng%2Fagent-orch?label=npm&color=cb3837)](https://www.npmjs.com/package/@bbk1ng/agent-orch)\n[![CI](https://github.com/bbk1ng/agent-orch/actions/workflows/ci.yml/badge.svg)](https://github.com/bbk1ng/agent-orch/actions/workflows/ci.yml)\n[![license](https://img.shields.io/badge/license-PolyForm%20NC%201.0.0-blue)](LICENSE)\n[![X](https://img.shields.io/badge/X-@agentorchbot-000000?logo=x)](https://x.com/agentorchbot)\n\n> [!WARNING]\n> **License Notice**: `agent-orch` is a **Source-Available, Non-Commercial** project,\n> licensed under [PolyForm Noncommercial 1.0.0](LICENSE) for educational, research,\n> and other non-commercial use. **Commercial use is forbidden.**\n\n## 🚨 Autonomous Agent Liability Disclaimer\n`orch` operates via headless, autonomous agent loops designed to self-heal, modify codebase files, generate Pull Requests, and resolve issues dynamically. By running this software, you acknowledge that agents execute actions autonomously. The project creators accept **zero liability** for token expenses, infinite API loops, accidental data loss, or system vulnerabilities generated by autonomous actions. Always run inside a sandboxed environment.\n\nRun local coding agents (Claude, Codex, Copilot, Gemini, Grok, agy, Kimi, and Z.AI via Claude Code) in a cross-audit loop on any git repo.\nOne or more agents author a small change; another (or several) audit it; on agreement + green tests it\nmerges into a local `orch/integration` branch (and opens/updates a persistent PR\nto `main` — GitHub owns the `main` merge); on disagreement it revises (capped);\non stalemate it asks you. All compute is local.\n\n## Requirements\n- Node ≥ 18. Runs on Linux, macOS, and Windows (CI gates every change on a\n  `windows-latest` leg alongside `ubuntu-latest`).\n- At least one agent CLI installed: `claude`, `codex`, `copilot`, `gemini`, `grok`, `agy`, `kimi`, or\n  `ccr` (for local-llm models). PATH is preferred, but if the caller's PATH is degraded\n  (wrappers, cron, hooks often drop `~/.local/bin`), preflight also probes\n  `~/.local/bin` and the running node's own bin dir (covers `npm i -g` / nvm)\n  and spawns the CLI by absolute path.\n\n## Install\nThe CLI is exposed as `orch`:\n```bash\nnpm install -g @bbk1ng/agent-orch\norch <command>\n```\nOr from source:\n```bash\ngit clone https://github.com/bbk1ng/agent-orch.git\ncd agent-orch\nnpm install -g .        # puts `orch` on your PATH\n```\nPrefer not to install globally? Run the CLI in place with `node bin/orch.js <command>`\nfrom the cloned checkout.\n\nInstall/update also writes bash completion to `~/.orch/completion.bash`; enable it\nwith `source ~/.orch/completion.bash`, or print the script with `orch completion bash`.\n\n## Usage\nRun from inside the git repo you want orchestrated:\n```bash\norch init                                  # scaffold .orch/orch.yml + .orch/ORCH.md, verify agent CLIs\norch init --link                           # also wire .orch/ORCH.md into CLAUDE.md/AGENTS.md/GEMINI.md\norch config                                 # print the effective .orch/orch.yml settings\norch task \"fix the flaky login test\"       # author + cross-audit + test-gate + merge\norch task \"fix x\" --authors claude,codex --reviewers claude,codex\norch task --file wo.json                    # untrusted JSON work order (validated + fenced)\norch issue 42                               # fetch issue #42 as a work order, run the cycle, Closes #42\norch pr 42                                  # audit a GitHub PR, post verdict as a comment\norch pr 42 --until merged                   # ...and merge it via gh if agents approve\norch agent add mynewagent --build            # scaffold a missing adapter via orch's own pipeline\norch continue <sid>                         # resume an interrupted/stalled cycle from its checkpoint\norch dashboard                              # live cycle status, log tail, run history, metrics\n```\nFor running several issues in a row, see [manual §2.16](docs/orch-manual.md#216-running-several-issues-in-a-row).\nAdd `--dry` to any `task`/`issue`/`pr` run to simulate a cycle without touching git,\nagents, or tests, and without advancing the author rotation. `orch` reports the\nmachine-readable outcome through the [exit-code table](#exit-codes) below.\nFor the v0.5 command changes, see the [migration guide](docs/MIGRATION-0.5.md).\n\nAfter a `task` run merges, `orch` tidies up for you: it pushes `orch/integration`\nto GitHub and opens/updates its persistent PR to `main`, deletes the temporary\nwork branches it created, and prints a plain-English summary of what it did. Anything that\ncould lose work (e.g. a branch with unmerged commits) is explained and only removed\nafter you confirm `[y/N]`; with no terminal attached it is left untouched and noted.\nPass `--no-tidy` to skip this and leave every branch and checkout exactly as-is.\n\n`--file` takes a JSON **work order** (untrusted intake — its free text is fenced,\nnever executed as instructions). `title` and `problem` are required; the arrays\nmay be empty:\n\n```json\n{ \"title\": \"fix the flaky login test\",\n  \"problem\": \"login test fails ~1 in 5 runs under load\",\n  \"repro_steps\": [\"run npm test 5x\"],\n  \"suspected_paths\": [\"src/auth.js\"],\n  \"acceptance_criteria\": [\"test passes 20x in a row\"] }\n```\n\n`orch pr <n>` needs the [`gh`] CLI authenticated — orch checks `gh auth status`\nup front and fails fast with one clear error instead of letting a broken\nsession surface partway through a cycle. The same authenticated-`gh` check\nalso runs before `orch task`/`orch issue` whenever the repo has a remote,\nsince even the default `no-ff` path opens/updates the persistent integration\nPR after a merge. It fetches the PR head, runs an\naudit-only cycle (local `main` is never touched — GitHub owns the merge), and\nposts the verdict as a PR comment. With `--until merged` it sends GitHub a merge\nrequest pinned to the exact PR commit fetched for that audit. If the PR head\nmoves before the merge, GitHub refuses it and orch tells you to re-run\n`orch pr <n> --until merged` so the new head is audited. After a pinned merge succeeds,\norch confirms the resulting merge commit is really an ancestor of `origin/main`\nbefore reporting success — a successful API call alone isn't proof the commit\nlanded, so a false \"merged\" is refused with an error instead of printed.\n\n[`gh`]: https://cli.github.com/\n\n## Agents\n`claude`, `codex`, `copilot`, `gemini`, `grok`, `agy`, `kimi`, `zai` (when `ZAI_API_KEY` is set), and three local-llm models served via llama-swap behind\nclaude-code-router (`ccr`): `qwen3-coder-30b`, `deepseek-coder-v2-lite`,\n`glm-4.5-air`. Local models need `ccr` on PATH and `~/.claude-code-router/config.json`\ndefining a `local` provider (see `local-llm/configs/`).\n\n> **External testers:** use the `claude` / `codex` / `copilot` / `gemini` / `grok` / `agy` / `kimi` CLI agents. `llama-swap` is\n> host-specific (the maintainer's LAN proxy) and not required — the CLI-agent\n> fallback already works.\n\n## Shell completion\n`npm install -g` installs bash completion automatically via a `postinstall` hook\n(writes `~/.orch/completion.bash`). Source it manually or generate it on demand:\n```bash\norch completion install   # write ~/.orch/completion.bash\nsource <(orch completion bash)\n```\n\nPick who authors and who audits explicitly in `orch.yml`:\n```yaml\nauthor: qwen3-coder-30b   # writes the change\nreviewer: claude          # audits it\n```\nSet both or neither. Unset → the `agents:` list rotates author each cycle.\nFor a configured rotation pool with per-seat model and effort, use plural role\nspecs. One author and one reviewer run per cycle; the reviewer is chosen at\nthe matching index and advanced until it names a different agent:\n```yaml\nauthors: [\"claude claude-sonnet-5\", \"codex gpt-5.6-luna\"]\nreviewers: [\"codex gpt-5.6-sol\", \"claude claude-opus-5\"]\n```\nCLI flags override `orch.yml`: `--author/--reviewer` pins one pair, while\ncomma-separated `--authors/--reviewers` retain the parallel fan-out/panel\nbehavior. A role is a spec `\"<agent> [model] [effort]\"` — agent required, model\nand effort optional. Valid `effort` values: `minimal`, `low`,\n`medium`, `high`, `xhigh`, `max` (which ones a given agent CLI actually honors\ndepends on the agent — e.g. codex takes effort via a `-c` config override\nrather than a flag).\n\n## Quickstart\n```bash\ncd your-repo\norch init\norch task \"fix the flaky login test\"\n```\n\n### Start a new project\n[repo-template](https://github.com/bbk1ng/repo-template) is a self-bootstrapping template repository pre-wired for `orch`: a single `curl` invocation fetches the bootstrap script, clones the template, runs `orch init --link`, and gates on tests, giving you a working project scaffold with orch already integrated and ready to use.\n\n## Commands\n- `orch init [--link]` — scaffold `.orch/orch.yml` + agent-agnostic `.orch/ORCH.md` usage doc, verify agent CLIs, and print a detection summary of what's actually usable on this machine (`claude`/`codex`/`copilot`/`gemini`/`grok`/`agy`/`kimi`/`zai` resolvable via the same PATH + fallback-dir lookup preflight uses **and** not disabled, local-llm models configured for `ccr`'s `local` provider), e.g. `orch: detected: claude, glm-4.5-air — not found: codex (CLI not found: PATH + fallback dirs)`. An adapter whose CLI resolves but that preflight would reject anyway (`zai` without `ZAI_API_KEY`, `agy` always) is listed under `not found:` with its reason — `zai (disabled: ZAI_API_KEY is not set)` — so detection never recommends a config the next run refuses. `--link` appends an idempotent pointer to `.orch/ORCH.md` in the repo's `CLAUDE.md`/`AGENTS.md`/`GEMINI.md` (created for the configured agent if none exist). The `@.orch/ORCH.md` line auto-loads the doc in Claude Code; other agents read the prose pointer to it.\n- `orch config [--check] [--json]` — print the effective, validated `.orch/orch.yml` configuration and the source of each value. `--check` validates only, exiting 1 and listing every unknown or removed key.\n- `orch agent add <name> [--build]` — append a registered agent to `.orch/orch.yml`, or scaffold an unregistered adapter through orch's own author → audit → test pipeline.\n\n- `orch task \"...\"` — author + cross-audit + test-gate + merge.\n- `orch issue <n>` — fetch GitHub issue #n (title+body, treated as an untrusted work order), run the full cycle, and stamp `Closes #n` on the no-ff merge so it auto-closes once main reaches origin. Needs the [`gh`] CLI authenticated. If the cycle escalates or falls back to a PR instead of merging, orch posts a comment on the source issue (verdict, branch, reason, round count) — headless runs have no one watching stdout, so this is the only trace besides the local `.orch/reviews/<branch>/DECISION.md`.\n- Bare `task`, `issue`, and `pr` runs mean `--until ready`; use `--until once` for exactly one cycle. `continue` inherits the goal recorded for its run and accepts only an explicit `--until once` override.\n- `orch pr <number|branch> [--until once|ready|merged]` — audit a PR or branch, comment the verdict, and optionally merge the PR via `gh`; bare means `--until ready`.\n- `orch continue <sid>` — resume an interrupted or stalled cycle (crash, hard kill, usage-limit abort) from its checkpoint, reattaching the same branch/author instead of re-authoring from scratch. It inherits the recorded goal; only `--until once` may be explicitly supplied. If the saved branch is gone, stale local resume state is cleared; if it exists only as `origin/<branch>`, check it out locally first. `orch` tells you the `sid` to use when a cycle dies mid-way.\n- `orch release \"<changelog entry>\"` — run the version bump + CHANGELOG bookkeeping by hand, e.g. after a human hand-merges an escalated branch into the dedicated `.orch/integration` worktree. It reconciles that worktree with `origin/orch/integration` and commits the bump on the integration branch, so run it from your normal repo checkout; it always bumps and never consults `release.autoBump`, so it is only *recovery* in a repo that set `release.autoBump: true`; under the default `false` a clean merge writes no release commit either and there is nothing to recover. Requires a clean working tree in the integration worktree; does not create a git tag (CI tags on push). See the manual's escalation-recovery procedure.\n- `orch dashboard [--json] [--limit N] [--check-history] [--once|--plain] [--refresh-ms N]` — read-only view of live cycle status/stage, streaming log tail, run history, and success-rate metrics. In a real interactive terminal (stdout and stdin both a TTY) with no `--json`/`--once`/`--plain`, it opens a live full-screen TUI that polls and redraws every `--refresh-ms` (default `1000`). Any scriptable context — `--json`, `--once`/`--plain`, a piped/redirected stream, or a non-TTY session — instead prints the static one-shot render, byte-identical to earlier versions, so cron/CI output stays diffable. `--check-history` shows stale red history rows as resolved when their branches are gone — a view-only reconciliation that leaves the run-history file unchanged. State reads are cached in memory between polls (keyed on each file's mtime/size/inode) and log tails read only the last 16 KiB of the round file, so the 1s live refresh re-reads only what changed.\n- `orch mcp` — serve orch to AI clients over the [Model Context Protocol](https://modelcontextprotocol.io) (newline-delimited JSON-RPC on stdio), so Claude Code, Hermes Agent or any other MCP client discovers and calls the same operations instead of each embedding its own shell recipe. Tools: `orch_status`, `orch_plan` (dry run), `orch_task`, `orch_issue`, `orch_pr`, `orch_continue` — each returns JSON with the cycle id, branch, status, reason, PR URL and log paths. New cycle tools default to `ready`; `orch_continue` inherits the recorded goal and has no goal override in its MCP schema. Every tool spawns the CLI with a fixed argument list and no shell: there is no arbitrary-command tool, and `orch_pr` exposes only a fixed target plus the `once`/`ready`/`merged` enum. MCP `merged` requests are refused unless `automation.mcpMayMerge: true` is explicitly configured; when enabled, the child uses the same head-bound, CI-checked merge path as the CLI. Where a green cycle lands still follows the repo's config: under the defaults it lands on the integration branch and the standing integration PR stays a human checkpoint, while a repo that sets `integrationBranch` to its `baseBranch` has already opted every cycle out of that checkpoint. Config example for both clients: manual §2.12b.\n\n- `orch completion [bash]` / `orch completion install` — print the bash completion script or rewrite `~/.orch/completion.bash`.\n- `orch upgrade` — self-update the global install to the latest published version, detecting whichever package manager installed it. `--check` reports the latest version without installing anything. This command manages the orch binary, not the current repo.\n\n### Exit codes\n\nThe exit status is the machine-readable outcome; callers should not parse summary text.\n\n| Code | Name | Meaning | What to do |\n|---|---|---|---|\n| `0` | `OK` | The run reached its goal — agreed, green, landed (`READY`/`MERGED`). | Nothing. |\n| `1` | `ERROR` | A crash, invalid config, unusable `gh` auth, or unexpected exception. | Fix the cause and re-run. |\n| `2` | `ESCALATED` | A cycle ran but agents did not agree, or the remedy loop stopped at its cap. | Investigate the staged branch. |\n| `3` | `THROTTLED` | The concurrency cap refused the run before any cycle started. | Retry later, unchanged. |\n| `4` | `WAIT_TIMEOUT` | Asked a human and got no answer in `automation.humanWaitHours`. | Resume or re-check. |\n| `5` | `ACTION_REQUIRED` | The review succeeded and exactly one human gesture remains, such as merging an approved PR. | Perform the named action. |\n| `6` | `BLOCKED` | A policy-terminal guardrail, security, auth, or merge-rejection block. | Make a human decision; do not retry. |\n| `64` | Usage error | An invalid command, flag, positional, or value. | Fix the command line. |\n\nAdd `--reviewer name` or `--reviewers a,b` to override review agents for\n`task`/`issue`/`pr` runs. On `task`/`issue`, setting only\n`--reviewer(s)` (no `--author(s)`) is allowed and forces that reviewer while\nstill rotating the author from the `agents:` pool — the one asymmetric case;\nsetting only `--author(s)` without a reviewer is rejected the same as before.\n\nOther flags: `--cheap` forces `orch.yml`'s `cheap.role` (e.g. a local llm) for one\n`task`/`issue` run — set `cheap.paths` to auto-route matching `--file`/`orch issue`\nwork orders without the flag; `--config-file <path.yml>` layers a custom YAML file\non top of `orch.yml` for one run; `--allow-protected` runs a `task`/`issue`\nwhose work order text names a protected path\n(orch's guardrail denylist), which intake otherwise refuses before the cycle starts —\nsee the manual §2.14.\n`--allow-large-scope` explicitly sanctions a deliberately large review slice for the\ncurrent run; `orch continue <sid>` requires the flag again.\n`--from <ref>` starts a `task`/`issue` cycle from an existing local branch instead of\nthe usual base — the way to salvage work from a branch an earlier cycle escalated,\nwhich would otherwise have to be re-authored from scratch. The review surface is\nunchanged: the diff is still taken against the base, so the reviewer re-judges the\nwhole accumulated slice rather than only the new fix pass. The salvage runs as a\nfresh cycle with its own round counter.\n\n## Config (`.orch/orch.yml`, all optional)\nSee `orch.example.yml`. Most repos need no config. A bare `orch.yml` at the\nrepo root is still read for back-compat, but `.orch/orch.yml` wins if both exist.\nThe trunk orch reads from, diffs against, and opens PRs to is `baseBranch`\n(default `main`); set it to e.g. `dev` if `main` is deploy-only. Everywhere\nbelow that says `main`, read \"your `baseBranch`\".\n\n## How it decides to merge\nMerge happens only when every reviewer says `AGREE` **and** the repo's tests pass.\nNo test command detected → it refuses to auto-merge and tells you. And if the\nauthor's branch has an empty diff against the base (checked before each review\nround against the whole branch, not one revision against the previous), the\ncycle escalates with \"author produced no changes — nothing to review\" instead\nof spending review rounds on nothing.\n\nThere's a third, independent gate the LLM reviewers can't talk their way past:\nimmediately before every merge attempt — the normal local-integration path and\nthe `orch pr`/PR-bridge no-merge approval path alike — orch reads the full\nbase→branch diff and runs it through a deterministic pattern scanner\n(`scanDiff` in `src/security-review.js`) that flags added lines reading\nsecrets/env (`process.env`, `.ssh/`, `PRIVATE KEY`, ...), opening a network\nconnection, spawning a subprocess, or touching branch-protection/workflow\nfiles. Any finding escalates without merging, even if every reviewer already\nsaid `AGREE` and tests are green — an LLM reviewer can be prompted into\napproving something it shouldn't, but this check can't be argued with. If the\ndiff itself can't be read, orch fails closed (escalates) rather than assuming\nthe unseen patch is safe.\n\nIt does not scan *every* added line, and the docs say so rather than\noverselling it: markdown and `docs/**` paths are dropped before the\nadded-line content scan runs (prose can't execute a secret read). That\nexemption applies only to the content scan, though — a separate path-based\nfloor over the *changed paths* still catches the guardrail file under `docs/`:\na change to `docs/CODEOWNERS` trips a `guardrail-touch` finding today. The\n`secret-read` rule has one more, deliberately narrow carve-out: it skips an\nadded line whose trimmed content starts with `//`, since a `//` line comment\nmentioning `.orch/` or `.env` names a path instead of reading one. Only `//`\nline comments (not `#` ones in Python or YAML), only whole-line ones\n(`readFileSync(\".orch/x\") // fixture` still fires), and only lines with no\n`${` in them (inside a template literal a `//` line still evaluates its\ninterpolations, so `// note: ${readFileSync(\".orch/x\")}` fires), and only that rule —\n`env-read`, `network`, `guardrail-touch`, and the subprocess check still scan\ncomment lines. `secret-read` also asks whether a matched line *reads* the path\nor only names it: the path must be an argument to something that opens it\n(`readFile`, `open`, `createReadStream`, `require`, `import`, or a shell `cat`,\n`source`, `.`, `<`), so `readFileSync(\".orch/secrets\")` fires and an error\nstring carrying the same characters does not. That check is line-based, so a\npath read one line after it is assigned is not caught. On top of those built-in exemptions, `security.ignore` in `orch.yml`\nlets you exempt paths yourself — commented out in `orch.example.yml`, because\nexempting a path skips *every* security rule for it and belongs only on\ngenerated build artifacts, never on authored code.\n\n## Merge honesty and cost/catch-rate reporting\nPrompted by a red-team report that found orch could\nprint `merged` for a cycle whose commit never reached `origin/main`:\n\n- **Path-specific merge claims.** A normal cycle reports `merged` only after the\n  integrated worktree and local `orch/integration` ref agree on the merged SHA; if\n  the integration PR bridge fails, its reason says the content is local-only. It\n  does not claim that `origin/main` already contains that commit. `orch pr --until merged`\n  has the stronger remote verification path: its GitHub merge request is pinned to\n  the fetched-and-reviewed PR SHA, so a concurrent head update is refused instead\n  of landing code the agents never saw. After that merge succeeds, orch re-fetches\n  `origin/main` and confirms the reported merge commit is really an ancestor before\n  logging `merged ... verified on origin/main`, since a squash/rebase merge mints a\n  new SHA that a bare success response can't vouch for.\n- **Per-cycle cost.** Every cycle's summary line includes `; cost <usageSummary>` — the\n  token/$ estimate for that cycle's author + review rounds — so cost is visible next to\n  the verdict, not just in aggregate run stats.\n- **Review outcome log.** Every review round is appended to\n  `.orch/review-outcomes.jsonl` (`src/review-log.js`) with `decision` one of\n  `AGREE`, `DISAGREE` (editorial rejection), or `ERROR` (reviewer crash/stall —\n  not a code rejection). This is the raw data needed to eventually measure whether\n  cross-audit catches real defects (reviewer catch-rate) — unmeasured today, called\n  out as the project's central unproven assumption.\n\n## Crash recovery\nA killed `orch task` can leave worktrees under `.orch/wt`. Before starting, a run\nsweeps those orphans. The sweep is PID-aware: each worktree carries an ownership\nmarker (`pid\\nsid`); only worktrees whose owner process is dead are removed, so a\nlive peer's worktree is never disturbed. The branch is deleted **only** when an\norch-created marker is present **and** it carries no commits beyond `main` (a\nkilled-before-commit throwaway) — so a same-slug retry works, while a branch with a\ncommitted author result is kept for resume (see below) and a branch passed to\n`orch pr` is always preserved. `--dry` never deletes worktrees or branches.\n\n`orch pr` is admitted through the same concurrency cap and inflight registry as\nother cycles; its integration mutations use `.orch/merge.lock`, and its standing\nPR merge phase uses `.orch/standing-pr.lock`. PID-liveness logic lets a crashed\ncycle be reclaimed on the next run.\n\n**Resume after an abort or hard kill.** When an `orch task` cycle dies after the\nauthor has committed — a usage-limit abort (issue #24) *or* a hard process kill /\nSIGKILL between the commit and review (issue #27) — the committed work survives on its\nbranch, and the run is recorded in `.orch/resume/` keyed on the task text (with the\nauthor). The next run with the **same task** reattaches that branch and continues from\nthe committed work (audit → gate → merge) instead of re-authoring from scratch — so\n`harness/orch-loop.sh` resumes rather than restarts. Resume is independent of how the\nrun died and of author rotation: if the rotation pool has since advanced to a\ndifferent agent, the resuming run pins the surviving branch's original author rather\nthan authoring fresh under the next one. It restarts cleanly only if the run died\nbefore any commit (nothing to resume), and never hijacks a live peer's branch.\n\nDuring a task cycle, a checkpoint in `.orch/checkpoints/` (keyed on the run's sid)\nis first written before authoring starts (stage `\"started\"`), then updated as soon\nas the author's commit lands (stage `\"authored\"`). After that it records each\nreview round's verdict and whether the test gate has already passed — each pinned\nto the branch head commit OID at the moment it was recorded. The early write makes\na cycle that dies during authoring addressable by sid, while a `\"started\"`\ncheckpoint with no committed changes is treated like an inflight-only record and\n`orch continue <sid>` refuses the empty branch. The `\"authored\"` stage grants no\nshortcut — it carries no verdict and no green gate, so the resumed run still audits\nand still gates from round 1. A crash mid-review or between a green gate and merge doesn't\nre-audit rounds already decided or re-run tests that already passed — the resumed\ncycle picks up at the next undone step. The OID pin binds each verdict to the code\nthat earned it: the OID is captured once per review round, and that one value then\nbinds the round's cached-verdict check, checkpoint writes, security\nreads, and merge — a branch ref that moves mid-round can't launder unaudited\ncontent into a checkpoint the tests actually ran on. The match is re-verified\nwhen the cached verdict is consumed, rather than only when the checkpoint is first read:\nif the branch moved between the crash and the resume (a manual\ncommit, a rebase, another cycle's revise), the recorded shortcut no longer matches\nand that step is re-audited or re-gated instead of inheriting a verdict earned on\ndifferent content — resume still keeps the recorded round and merges if the fresh\nchecks pass. A checkpoint written by an older orch carries no OID and is treated as\nunverifiable, never as a match. The checkpoint is cleared once the cycle\nreaches a terminal status.\n\n`orch continue <sid>` also cleans up stale local resume state when the saved\nbranch no longer exists. If the branch still exists only on `origin/<branch>`,\norch refuses to guess and asks you to check it out locally before continuing.\n\n## Concurrent cycles\n\nMultiple `orch task` runs can drive the same repo directory in parallel. Launch\neach with explicit author and reviewer roles so they don't round-robin into each\nother:\n\n```bash\norch task \"migrate auth module\"   --authors claude --reviewers codex &\norch task \"add rate-limit header\" --authors codex  --reviewers claude &\n```\n\n**Concurrency cap.** Set `concurrency: 4` in `.orch/orch.yml` (default 4). An\nover-cap launch exits immediately with code 3 and logs:\n\n```\norch: concurrency cap 4 reached — 5 cycles live; skipping pr/claude/<slug>-<sid>\n```\n\nReduce the cap or wait for a live cycle to finish, then rerun.\n\n**Launching from `main`.** `main` is no longer reserved by orch. You can keep\nyour primary checkout on `main`; orch's permanent worktree checks out the\ndedicated `orch/integration` branch inside `.orch/integration` instead.\n(`main` here is the default `baseBranch`; a repo with a `dev` trunk sets\n`baseBranch: dev` and everything below tracks that branch instead.)\nUncommitted changes stay in your cwd; orch never stashes, resets, or discards\nthem.\n\n**Two-speed merge path.** When all reviewers agree and tests pass, the cycle\nmerges into `orch/integration` through `.orch/integration` under a brief\n`merge.lock`. Before merging, orch fetches `origin/orch/integration` and\nfast-forwards the local integration branch when it is behind. A fast-forward\nonly advances along existing history; it creates no merge commit. If the two\nrefs have diverged (each has commits the other lacks), orch demotes with\n`sync` rather than guessing at a merge. Orch also reconciles\n`orch/integration` against the base branch before landing: a fast-forward when\nit is merely behind, and — whenever the histories have diverged, meaning neither\nbranch is an ancestor of the other (most commonly when a human has squash-merged\nthe integration PR by hand, a deviation from orch's merge-commit model, but also\nafter a commit lands on the base branch outside orch; see the manual's\n`mergeMethod` note) — an ordinary merge commit that re-establishes the base as\nan ancestor, aborted and skipped if it conflicts (a real content conflict\nsurfaces at the cycle's own merge step instead). The branch is immediately usable\nlocally after the post-merge test gate (and the version bump, if\n`release.autoBump` is enabled). Orch then pushes `orch/integration` and opens or\nupdates one persistent PR from `orch/integration` to `main`; run\n`orch pr <number> --until merged` against that persistent `orch/integration → main` PR\nto merge it once all of its checks are green — a path for\nwhen native auto-merge stalls at `BLOCKED` because review is satisfied via a\nruleset bypass grant rather than a human approval. The merge is pinned to the\nintegration tip this cycle pushed and verified: a concurrent cycle that advances\n`orch/integration` between the push and the merge attempt gets a logged 409\n(\"integration advanced past the commit this cycle verified — the newer cycle will\nmerge it\") and owns landing the newer tip. A 405 (\"not mergeable\") stays\nswallowed so a pending check is not cycle noise; any other failure — 401/403\nfrom an expired or underprivileged token, a bad PR ref, a network error — is\nlogged rather than passed off as \"not ready yet\". The merge runs as whatever\n`gh` identity orch is authenticated as, so it only lands if that identity is\nitself in the branch's ruleset `bypass_actors` list. This is necessary because GitHub\ndoes not allow an actor to approve its own PR, so an orch-authored PR cannot\nsatisfy a required-review rule with an approval from the same bot. If you use\nthis path, the GitHub review is bypassed by ruleset configuration; orch's\nauthor -> cross-audit -> test-gate remains the governing review. Without the\nbypass grant, the merge call simply fails and retries next cycle.\n`main` is a mirror of GitHub's `main`: orch does not merge, reset, commit, or\npush it directly. After GitHub merges the PR, local `main` advances only by\nfetching origin and fast-forwarding to `origin/main`.\n\nTwo guards run while the lock is held: a file-overlap pre-check (comparing your\nchanged paths against live in-flight peers' paths — commits already landed on\n`orch/integration` are not pre-checked; a real conflict with them fails the\nmerge itself, and a semantic conflict fails the post-merge re-test) and a\npost-merge re-test against the integrated tree.\n\n**`merge-deferred`.** A cycle defers its merge (to a PR, or a local escalation) when:\n- `overlap` — your files collide with a live concurrent cycle's files\n- `dirty-merge` — the merge into `orch/integration` itself fails\n- `integration-test` — tests fail after merge into `.orch/integration`\n- `lock` — the lock was never acquired\n- `sync` — pre-landing branch reconciliation failed: local `main` from\n  `origin/main`, local `orch/integration` from `origin/orch/integration`, or\n  `orch/integration` from the base branch\n\nFor most triggers, with a git remote and `gh` CLI available the branch is\npushed and a PR is opened; without them, `.orch/reviews/<branch>/DECISION.md`\nis written and the branch is kept for manual review. **`dirty-merge` is\ndifferent:** it never opens a per-change PR against `main` (that would be a\nsecond trunk door beside the standing `orch/integration → main` PR). It\nescalates with the staged branch and conflict detail so a human can hand-merge\ninto `orch/integration` in `.orch/integration`. After that hand-merge is pushed\nto `origin/orch/integration`, a repo running `release.autoBump: true` closes the\nrecovery from any checkout with `orch release \"<entry>\"`; it first reconciles\nthe dedicated worktree so the version bump and CHANGELOG line start from the\nremote tip (finalize never ran). Release does not push that commit. Under the default `release.autoBump: false`\nthere is no bookkeeping to recover — skip it. The next\ncycle normally fast-forwards its local integration branch automatically. A\ngenuine divergence instead demotes with `sync`. Either way the reason is more\nthan the trigger name.\nThe `.orch/runs.jsonl` record stores `trigger` at the top level alongside\n`verdict: \"merge-deferred\"`, and the detailed reason carries round count, the\nbranch's base SHA (plus the integration branch's tip once that worktree has\nbeen synced — still \"unknown\" for `lock` and `sync`), the branch's changed\npaths, and trigger-specific detail (overlapping\npaths per peer cycle, the conflicting paths, the sync failure, or that the\nlock timed out) plus a one-line next action, so a human picking up the\nescalation doesn't have to re-derive context orch already had.\n\n**`overlap` deferrals usually heal themselves.** An overlap-deferred cycle is\nparked in `.orch/deferred/`, and when the cycle that blocked it lands, orch\n(on the local integration path — `landing: pr` has no shared tip to collide on)\nrebases the parked branch onto the new integration tip and **re-runs the merge\nand the post-merge test gate** — a redriven merge is gated, never trusted on\nits earlier green run. It cascades: a cycle deferred behind the one that just\nhealed gets redriven too. Each peer gets one automatic attempt; if it fails the\nrebase, the merge, or the gate, the cycle stays `merge-deferred` for a human.\nSo on `overlap`, wait for the blocking cycle to finish before fixing anything by\nhand (manual §3.4).\n\n**`landing: pr` — per-cycle PR mode.** Set `landing: pr` in `.orch/orch.yml` and an\nagreed + green cycle skips the local integration branch and `merge.lock`; it\npushes that cycle branch and opens its own PR to `main` instead. This mode is\nunchanged by the persistent `orch/integration` bridge. Needs a git remote and\nthe `gh` CLI; without them the cycle escalates locally the same way `merge-deferred`\ndoes. Run `orch pr <number> --until merged` against that PR to merge it once it is\ngreen — pinned to the exact reviewed commit OID, so a head that moved since\nreview is refused rather than merged unseen.\n\n## Version bump on merge\n\nagent-orch's own version, `x.y.z`, reads the patch field (`z`) as two\ncounters packed together: the last two digits are a **merge-bump counter**\n(`cc`, 00-99, one per merge to `main`), and the digits above that are a\n**publish-bump counter** — advanced only by an actual `npm publish`, which\nalso resets the merge counter to `00`. \"0.4.203\" means: 2 publishes have happened (z=2) and 3 merges have landed since the most recent one (cc=03). It's ordinary decimal\narithmetic, not a custom encoding — a plain merge bump is just `patch + 1`;\n`...z99 + 1` naturally carries into `(z+1)00`. If the merge counter reaches\n99 before a real publish happens, that carry happens on its own — expected,\nnot a bug: that many merges without a publish means a publish is overdue.\n\n`orch --version` displays the version with a `v` prefix\n(`v0.4.203`); `package.json#version` itself stays plain, valid semver with no\nprefix, as npm requires.\n\nWith `release.autoBump: true` in `.orch/orch.yml`, every cycle that lands via\nthe local integration path (not `landing: pr`) bumps the merge counter right\nafter the post-merge test gate passes, mirrored into `package-lock.json`'s\nroot version, and prepends a `CHANGELOG.md` entry. If the repo ships a\nGitHub Pages site at `docs/index.html`, the version shown in its header (the\n`vX.Y.Z` span) is rewritten to match — anchored to that one span so nothing\nelse moves. Commits as `chore(release): vX.Y.Z`. Best-effort: a\nmissing/unparsable `package.json` or any write/commit failure is swallowed —\nit never blocks or unwinds a merge that already landed.\n\nThe merge counter moves automatically only through orch's local integration\npath when `release.autoBump` is enabled. A landing through `landing: pr` or\noutside orch carries no version bump unless the landing includes one itself;\notherwise the package version remains unchanged until the release script is\nrun by hand.\n\nThe publish counter never bumps automatically. Run `node\nscripts/orch-release.js` by hand at actual release time — it snaps the patch\nfield to the next multiple of 100, commits, and tags, leaving the push and\nthe `npm-publish.yml` dispatch as separate deliberate steps.\n```yaml\nrelease:\n  autoBump: true   # off by default; orch never edits release files unless you opt in\n```\nWithout the flag, a merge lands with no release-file edits at all — a generic\norchestration run must not impose this repo's release policy (merge bump +\nCHANGELOG commit) on your repo by surprise.\n\n## Auto docs-update on merge\nOpt-in per repo. With `docs.autoUpdate: true` in `.orch/orch.yml`, a successful\nmerge auto-spawns a detached `orch task` that refreshes documentation:\n```yaml\ndocs:\n  autoUpdate: true   # off by default\n  prompt: \"update documentation to reflect the latest merged changes\"\n  paths: [\"*.md\", \"docs/**\", \"**/*.md\"]   # docs-only globs = loop guard\n```\n**Loop guard:** the trigger is skipped when the merged branch changed only docs\nfiles (every path matches `docs.paths`) — so the docs-update's own docs-only\nmerge never re-triggers another one — and when the merge was a no-op (empty diff:\nnothing to update, which would otherwise re-spawn forever). A mixed code+docs\nmerge triggers once.\n\n**One surface.** Local merges (`orch task`/`orch pr --until merged`) are\nhandled inside `orch`, as described above. A merge performed entirely on\nGitHub — the web UI's merge button — produces no local orch run, so nothing\nrefreshes the docs for it; that gap is deliberate. There was once a companion\nAction (`orch-docs.yml`) covering it, but it required a self-hosted runner\ncarrying the agent CLIs and their keys, and a workflow whose labels match no\nregistered runner does not fail — it queues silently until GitHub cancels it.\nOver its whole life it completed zero runs while appearing to be a working\nsafety net, so it was deleted in v0.4.211 (#402). If you merge on GitHub and\nwant the docs caught up, run a docs task locally.\n\n**Portability:** the in-tool behavior ships inside `orch` — any standalone repo\ngets it by setting `docs.autoUpdate: true`. Nothing to copy, no runner to\nprovision.\n\n## License\n[PolyForm Noncommercial 1.0.0](LICENSE) — non-commercial use only; commercial use forbidden.\n","readmeFilename":"README.md"}