{"_id":"@bolyra/evc-conformance","_rev":"7-891758b25ffc5870a45137d49a7b50fc","name":"@bolyra/evc-conformance","dist-tags":{"latest":"0.7.0"},"versions":{"0.1.0":{"name":"@bolyra/evc-conformance","version":"0.1.0","keywords":["evc","external-verifier-contract","conformance","agent-authorization","bolyra"],"license":"Apache-2.0","_id":"@bolyra/evc-conformance@0.1.0","maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"homepage":"https://github.com/bolyra/bolyra#readme","bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"bin":{"evc-conformance":"bin.js"},"dist":{"shasum":"d0c627be328bf26ec953ce757b20d50491735ebf","tarball":"https://registry.npmjs.org/@bolyra/evc-conformance/-/evc-conformance-0.1.0.tgz","fileCount":36,"integrity":"sha512-kWnDmrKMRgNngR78Wevo8IAJsa+490DnlWstxiNfUPN2RCSTdrT30LJhUehj+BodZdfEnshLDuWw+Wq4i9uCDA==","signatures":[{"sig":"MEYCIQCQdmF1qBmMKaQ7Qx+727LRmJhjyOsQv4n0jYnTmSrs5wIhAK8QX9U0KC2Q8inXI2MGFTSrSnBRQ4+qjolNmGcrHsLd","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":127200},"engines":{"node":">=18"},"gitHead":"e3e3c320d073fa9370b68ad840afc6141bf6c387","scripts":{"sync":"node scripts/sync.js","test":"node bin.js && node scripts/sync.js --check","sync:check":"node scripts/sync.js --check","presync:check":"true"},"_npmUser":{"name":"saneguy","email":"kondojuviswanadha@gmail.com"},"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git","directory":"integrations/evc-conformance"},"_npmVersion":"11.6.2","description":"Bolyra-maintained EVC v1 host conformance vectors - prove any host implementation conforms with one command, no install","directories":{},"_nodeVersion":"24.13.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/evc-conformance_0.1.0_1787442668669_0.8198811171247831","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@bolyra/evc-conformance","version":"0.2.0","keywords":["evc","external-verifier-contract","conformance","agent-authorization","bolyra"],"license":"Apache-2.0","_id":"@bolyra/evc-conformance@0.2.0","maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"homepage":"https://github.com/bolyra/bolyra#readme","bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"bin":{"evc-conformance":"bin.js"},"dist":{"shasum":"6dcdc2e12b005545c95af7d7f13070e1de613e82","tarball":"https://registry.npmjs.org/@bolyra/evc-conformance/-/evc-conformance-0.2.0.tgz","fileCount":37,"integrity":"sha512-6taKERfvC2M65p2HkpfN79jrYoIkOHxmMXUjmwW7mz86WG9oeWnzsB8sQB++SVwuiXZYnT8bDpNtASmi4RzgRA==","signatures":[{"sig":"MEUCIQDmWmdfnFM4FmGOze2Lalq7JYNQu4YxV2ytzlNLAk79LwIgIhLgE8f4F3ICsKFHWxL1qP8fFuciYsfvKLXI3/Uyvcc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bolyra%2fevc-conformance@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":132861},"engines":{"node":">=18"},"gitHead":"030884b9f48d39770f779e6eeb6174a59ff75247","scripts":{"sync":"node scripts/sync.js","test":"node bin.js && node scripts/sync.js --check","sync:check":"node scripts/sync.js --check","presync:check":"true"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ad64f31c-d35c-4196-ab9f-c6db1afa9854"}},"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git","directory":"integrations/evc-conformance"},"_npmVersion":"11.19.0","description":"Bolyra-maintained EVC v1 host conformance vectors - prove any host implementation conforms with one command, no install","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/evc-conformance_0.2.0_1787768181677_0.9371642515589498","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@bolyra/evc-conformance","version":"0.3.0","keywords":["evc","external-verifier-contract","conformance","agent-authorization","bolyra"],"license":"Apache-2.0","_id":"@bolyra/evc-conformance@0.3.0","maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"homepage":"https://github.com/bolyra/bolyra#readme","bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"bin":{"evc-conformance":"bin.js"},"dist":{"shasum":"25e8d7f4f58bbc0bec8923c1d5cf1ecccd1a7c4d","tarball":"https://registry.npmjs.org/@bolyra/evc-conformance/-/evc-conformance-0.3.0.tgz","fileCount":38,"integrity":"sha512-R28GAsx5z9N8UhX7C+yLLLt3/pcb6leJ2mtQbmHC67w1L6V4zDYZ7GEhCW8A3gTcW0npXN9/0P0BnULCq8vjpg==","signatures":[{"sig":"MEUCIAcizXPU5JT3uMcX/eZAIfksYzGAEE4+u4uM3uh/VPplAiEA2g5TqKdvZhRgkoDAGNgW5iUwi/zD7kYJBOeyPdAVIcc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bolyra%2fevc-conformance@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":135216},"engines":{"node":">=18"},"gitHead":"9bf754441ab36ab93992ed5936d34c44a4128f92","scripts":{"sync":"node scripts/sync.js","test":"node bin.js && node scripts/sync.js --check","sync:check":"node scripts/sync.js --check","presync:check":"true"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ad64f31c-d35c-4196-ab9f-c6db1afa9854"}},"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git","directory":"integrations/evc-conformance"},"_npmVersion":"11.19.1","description":"Bolyra-maintained EVC v1 host conformance vectors - prove any host implementation conforms with one command, no install","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/evc-conformance_0.3.0_1788810088924_0.19071310398055497","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@bolyra/evc-conformance","version":"0.4.0","keywords":["evc","external-verifier-contract","conformance","agent-authorization","bolyra"],"license":"Apache-2.0","_id":"@bolyra/evc-conformance@0.4.0","maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"homepage":"https://github.com/bolyra/bolyra#readme","bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"bin":{"evc-conformance":"bin.js"},"dist":{"shasum":"092ebd12dfdd03e3f93b1810580ca716032bc980","tarball":"https://registry.npmjs.org/@bolyra/evc-conformance/-/evc-conformance-0.4.0.tgz","fileCount":39,"integrity":"sha512-b5zZrzU0/6R1iLjtj+lGp7xzT0fLbcak5GbjYUdyeacVRFNLk+SHeqH8w6puoYINs7NsXOOb0O/Cng9c1LyWMA==","signatures":[{"sig":"MEUCIQCDDoPG2fi90brpiqiLcLAr4Amb/QAopVX7LPURP5z+3AIgbqs0l6DZ0ouhSJjqoEqjw725LAn2TBptc2u3llB4cEI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bolyra%2fevc-conformance@0.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":136973},"engines":{"node":">=18"},"gitHead":"4048a23ee4750a09e900dc67aba8066d5b4f1ea7","scripts":{"sync":"node scripts/sync.js","test":"node bin.js && node scripts/sync.js --check","sync:check":"node scripts/sync.js --check","presync:check":"true"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ad64f31c-d35c-4196-ab9f-c6db1afa9854"}},"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git","directory":"integrations/evc-conformance"},"_npmVersion":"11.19.1","description":"Bolyra-maintained EVC v1 host conformance vectors - prove any host implementation conforms with one command, no install","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/evc-conformance_0.4.0_1788835951732_0.8365408484475252","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@bolyra/evc-conformance","version":"0.5.0","keywords":["evc","external-verifier-contract","conformance","agent-authorization","bolyra"],"license":"Apache-2.0","_id":"@bolyra/evc-conformance@0.5.0","maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"homepage":"https://github.com/bolyra/bolyra#readme","bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"bin":{"evc-conformance":"bin.js"},"dist":{"shasum":"743a2daa0d5c0557cc235eda0db9f350e677d462","tarball":"https://registry.npmjs.org/@bolyra/evc-conformance/-/evc-conformance-0.5.0.tgz","fileCount":39,"integrity":"sha512-fS3A+gi9t6mRYzrQ9OoT/SdfkLmOGMKf8byEkEtXgBz8Ah54wMFrexJ6V8KmlLoTo2BDD/E882HPSoCygaOO6g==","signatures":[{"sig":"MEUCIAI34CmGyAiWpXngXVjhhbcvJ1sFZiUaKEq3hjwrAq+NAiEA8adCfJws/bMy+V/P3vJAcNXr3wKgE4nB2zpAEVkMChA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bolyra%2fevc-conformance@0.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":154679},"engines":{"node":">=18"},"gitHead":"16fb8472db5f53f5be7cc89bbb2b47b4710b2e6f","scripts":{"sync":"node scripts/sync.js","test":"node bin.js && node scripts/sync.js --check","sync:check":"node scripts/sync.js --check","presync:check":"true"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ad64f31c-d35c-4196-ab9f-c6db1afa9854"}},"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git","directory":"integrations/evc-conformance"},"_npmVersion":"11.19.1","description":"Bolyra-maintained EVC v1 host conformance vectors - prove any host implementation conforms with one command, no install","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/evc-conformance_0.5.0_1788934530364_0.8742732279225858","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@bolyra/evc-conformance","version":"0.6.0","keywords":["evc","external-verifier-contract","conformance","agent-authorization","bolyra"],"license":"Apache-2.0","_id":"@bolyra/evc-conformance@0.6.0","maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"homepage":"https://github.com/bolyra/bolyra#readme","bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"bin":{"evc-conformance":"bin.js"},"dist":{"shasum":"49d355ecca735247560eb78e83602c6aeb095228","tarball":"https://registry.npmjs.org/@bolyra/evc-conformance/-/evc-conformance-0.6.0.tgz","fileCount":39,"integrity":"sha512-ZUKtdpnuVypclP6kh41zmooyYF3DO8jDFejLzatuTv9rfG0BW43yEZsOMXRyCcdizUBSy0bgSsjR+lMQCl+g9g==","signatures":[{"sig":"MEUCIDwYa/3QxjMlxzCh1dZLTy4HGJo8e4b2O6/cXOA1CTcSAiEAqc37CJSR5gvk3odopBF/4vXTVq0am6kEICJks/QBgqk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bolyra%2fevc-conformance@0.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":155692},"engines":{"node":">=18"},"gitHead":"f106b002e5f60fdad6e587bd1c4ddb02174013ba","scripts":{"sync":"node scripts/sync.js","test":"node bin.js && node scripts/sync.js --check","sync:check":"node scripts/sync.js --check","presync:check":"true"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ad64f31c-d35c-4196-ab9f-c6db1afa9854"}},"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git","directory":"integrations/evc-conformance"},"_npmVersion":"11.19.1","description":"Bolyra-maintained EVC v1 host conformance vectors - prove any host implementation conforms with one command, no install","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/evc-conformance_0.6.0_1789057633283_0.7210649650270162","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"_id":"@bolyra/evc-conformance@0.7.0","bin":{"evc-conformance":"bin.js"},"bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"dist":{"shasum":"9dbbabfd3532c8cee8881c17a1dc1c3d31d70408","tarball":"https://registry.npmjs.org/@bolyra/evc-conformance/-/evc-conformance-0.7.0.tgz","fileCount":39,"integrity":"sha512-W1qqvtszQKTGt4aFquNyb9LfEhiT1dtnocv/bxomDW89OoInKZKOzQ9LBdyxVhbb7vjtksMpexRD4Gmx7bD6Sg==","signatures":[{"sig":"MEYCIQD7kDjEOqZDR+vFjuhTwCGzQwf+Kxm9fnSkEu981ymGcwIhAPvzei9iwIoRk6+9O8znKul1e3MBbKkREmNgoy/5dhBU","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIHMD7IgJpbhyh27Amlge7j1SBH5kevGqjITyNaYK2PboAiAMtJ2kwFwq7w74xIR5NDR+tFzoaM8csRjD1o8gnLxrpA=="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bolyra%2fevc-conformance@0.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":163248},"name":"@bolyra/evc-conformance","engines":{"node":">=18"},"gitHead":"b64f0ea4a63ba62c154768d311dd7277bcd99430","license":"Apache-2.0","scripts":{"sync":"node scripts/sync.js","test":"node bin.js && node scripts/test-bin-selection.cjs && node scripts/sync.js --check","sync:check":"node scripts/sync.js --check","presync:check":"true"},"version":"0.7.0","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ad64f31c-d35c-4196-ab9f-c6db1afa9854"}},"homepage":"https://github.com/bolyra/bolyra#readme","keywords":["evc","external-verifier-contract","conformance","agent-authorization","bolyra"],"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git","directory":"integrations/evc-conformance"},"_npmVersion":"11.20.0","description":"Bolyra-maintained EVC v1 host conformance vectors - prove any host implementation conforms with one command, no install","directories":{},"maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/evc-conformance_0.7.0_1790190937184_0.48436815357554996"}}},"time":{"created":"2026-08-22T23:51:08.490Z","modified":"2026-09-23T19:15:37.929Z","0.1.0":"2026-08-22T23:51:08.815Z","0.2.0":"2026-08-26T18:16:21.819Z","0.3.0":"2026-09-07T19:41:29.068Z","0.4.0":"2026-09-08T02:52:31.872Z","0.5.0":"2026-09-09T06:15:30.496Z","0.6.0":"2026-09-10T16:27:13.419Z","0.7.0":"2026-09-23T19:15:37.380Z"},"bugs":{"url":"https://github.com/bolyra/bolyra/issues"},"license":"Apache-2.0","homepage":"https://github.com/bolyra/bolyra#readme","keywords":["evc","external-verifier-contract","conformance","agent-authorization","bolyra"],"repository":{"url":"git+https://github.com/bolyra/bolyra.git","type":"git","directory":"integrations/evc-conformance"},"description":"Bolyra-maintained EVC v1 host conformance vectors - prove any host implementation conforms with one command, no install","maintainers":[{"name":"saneguy","email":"kondojuviswanadha@gmail.com"}],"readme":"# @bolyra/evc-conformance\n\nProve an External Verifier Contract v1 **host** conforms — one command, any\nlanguage, no install.\n\n```sh\nnpx @bolyra/evc-conformance --host \"/path/to/your-host --flags\"\n```\n\nRuns the 30 `host_behavior` vectors against your host: verifier spawning,\ntimeout and output-bound enforcement, fail-closed handling of every\nmisbehaving-verifier class, closed decision schema, and reserve-before-act\nnonce semantics. Exit `0` when everything passes, `1` on any failure — drops\nstraight into CI.\n\n```sh\nnpx @bolyra/evc-conformance                  # self-test the bundled reference host\nnpx @bolyra/evc-conformance --host \"...\" --json   # machine-readable result on stdout\nnpx @bolyra/evc-conformance --verifier \"/path/to/your-verifier --flags\"\n                                                  # verifier_envelope: domain-agnostic\n                                                  # wire-envelope vectors for the\n                                                  # VERIFIER side (raw request on\n                                                  # stdin, one closed verdict on\n                                                  # stdout; no assumptions about\n                                                  # bundle semantics)\n```\n\nThe `--json` output includes the vector-set version, count, and SHA-256, so a\nCI run states exactly which vector set it passed.\n\n## What your host must do\n\nHonor the Host-Under-Test convention: read the `HUT_*` environment variables,\nspawn the verifier named in `HUT_VERIFIER_CMD`, enforce the timeout and\noutput bound, reserve nonces before acting, and emit exactly one decision\nobject on stdout. The full pass path — contract summary, failure classes,\ntroubleshooting, CI snippet — is\n[`spec/IMPLEMENTER.md`](https://github.com/bolyra/bolyra/blob/main/spec/IMPLEMENTER.md);\nthe normative contract is\n[`spec/external-verifier-contract-v1.md`](https://github.com/bolyra/bolyra/blob/main/spec/external-verifier-contract-v1.md).\n\n## Provenance\n\nThese are the Bolyra-maintained EVC v1 host conformance vectors. Everything\nunder `vendor/` is a checksummed snapshot of the monorepo's `spec/` directory\n(see `MANIFEST.json`); it is regenerated by `npm run sync` and verified by\n`npm run sync:check` in CI — never edited by hand. The full 112-vector suite\n(handshake, signature, Merkle, delegation) lives in the monorepo and tests\nthe reference implementation, not your host.\n\nIf your host goes green, open an issue on\n[bolyra/bolyra](https://github.com/bolyra/bolyra) — we would like to know,\nand we will list it.\n\n## Testing §7.1 (`internal_error` must exit non-zero)\n\n`--verifier` runs the 11 domain-agnostic `verifier_envelope` vectors. Those cannot\nreach §7.1's exit-code rule: no *request* portably induces `internal_error` in a\ncorrect verifier, so a verifier can violate §7.1 on every `internal_error` path and\nstill score 11/11.\n\nThe inducer is a **config fault** — corrupt the verifier's own trust configuration,\nthen send a request it would otherwise answer. Select that vector explicitly and\nsupply the implementation-specific setup:\n\n```sh\nVERIFIER_FAULT_CMD=\"<corrupt your trust config>\" \\\nVERIFIER_FAULT_UNDO_CMD=\"<restore it>\" \\\nVERIFIER_VALID_REQUEST=./a-request-your-verifier-allows.json \\\nnpx @bolyra/evc-conformance --verifier \"<your verifier>\" \\\n  --vector verifier-config-fault-internal-error-exits-non-zero\n```\n\nThe suite cannot supply `VERIFIER_VALID_REQUEST`: the trust check runs after root\nrecovery, so the request must carry a chain that actually verifies, and the bundle is\nopaque per spec. Each implementation supplies its own.\n\n**Not failures:** missing hooks SKIP, and a deny carrying a code other than\n`internal_error` SKIPs — nothing obliges every verifier to classify a config fault\nthat way, so it is neither a failure nor exercised §7.1 coverage. An `allow` under the\nfault always fails: a trust source that is present but unusable must never silently\ndisable trust enforcement.\n","readmeFilename":"README.md"}