{"_id":"@bounded-systems/conformance-kit","_rev":"10-d3fd62680f1f035dd19bb71f46dd14ba","name":"@bounded-systems/conformance-kit","dist-tags":{"latest":"0.11.0"},"versions":{"0.2.0":{"name":"@bounded-systems/conformance-kit","version":"0.2.0","license":"MIT","_id":"@bounded-systems/conformance-kit@0.2.0","maintainers":[{"name":"bdelanghe","email":"bdelanghe@gmail.com"}],"homepage":"https://github.com/bounded-systems/conformance-kit#readme","bugs":{"url":"https://github.com/bounded-systems/conformance-kit/issues"},"bin":{"ck-gen-cid":"generators/gen-cid.mjs","ck-axe-gate":"gates/axe-gate.mjs","ck-gen-sbom":"gates/sbom/gen-sbom.mjs","ck-seo-gate":"gates/seo-gate.mjs","ck-vuln-gate":"gates/vuln-gate.mjs","ck-check-sbom":"gates/sbom/check-sbom.mjs","ck-http-probe":"integrity/http-probe.mjs","ck-verify-site":"integrity/verify-site.mjs","ck-gen-identity":"generators/gen-identity.mjs","ck-shacl-runner":"gates/shacl-runner.mjs","ck-baseline-gate":"gates/baseline-gate.mjs","ck-gen-snapshots":"generators/gen-snapshots.mjs","ck-gen-provenance":"integrity/gen-provenance.mjs","ck-structure-audit":"integrity/structure-audit/audit.mjs","ck-gen-sitemanifest":"integrity/gen-sitemanifest.mjs","ck-readability-gate":"gates/readability-gate.mjs","ck-commonmark-runner":"gates/commonmark-runner.mjs","ck-html-validator-gate":"gates/html-validator-gate.mjs"},"dist":{"shasum":"ced572dd5aca1d929a45c82d635fced82de8f83d","tarball":"https://registry.npmjs.org/@bounded-systems/conformance-kit/-/conformance-kit-0.2.0.tgz","fileCount":35,"integrity":"sha512-8mRb8i8/anqnlrbuVtcSASm1rtFJItdbIlFxlWEK3PpFz0Fhdpb134vJBkEgmLTD7AR4V/HhSilF63qdfbwJuw==","signatures":[{"sig":"MEYCIQD4vH7Pv/AO2wzoxaf4nFnQZPkP/nXLTPeQb9F/X4d3bgIhAKzZU6laDdoUOqDpIQAZ6bbYNEJ//5Qkm191sgZqRN4I","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":218557},"type":"module","exports":{"./lib/*":"./lib/*","./gates/*":"./gates/*","./emitters/*":"./emitters/*","./integrity/*":"./integrity/*","./generators/*":"./generators/*","./package.json":"./package.json","./gates/conformance/*":"./gates/conformance/*"},"gitHead":"837cc91c65f1654b3d0b5998c658d5b9f0c0abeb","scripts":{"test":"node test/run.mjs"},"_npmUser":{"name":"bdelanghe","email":"bdelanghe@gmail.com"},"repository":{"url":"git+https://github.com/bounded-systems/conformance-kit.git","type":"git"},"_npmVersion":"11.13.0","description":"Standalone, site-agnostic web-conformance toolkit: integrity tooling + build gates + provenance generators, all parameterized so a site vendors one kit instead of duplicating scripts.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"n3":"^1.17.3","jsonld":"^9.0.0","vnu-jar":"^26.6.24","axe-core":"^4.10.0","linkedom":"^0.18.0","sigstore":"^5.0.0","turndown":"^7.2.4","stylelint":"^17.14.0","@zazuko/env-node":"^2.1.5","rdf-validate-shacl":"^0.5.10","@mozilla/readability":"^0.5.0","stylelint-plugin-use-baseline":"^1.4.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/conformance-kit_0.2.0_1782698508747_0.836275932054904","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@bounded-systems/conformance-kit","version":"0.3.0","license":"MIT","_id":"@bounded-systems/conformance-kit@0.3.0","maintainers":[{"name":"bdelanghe","email":"bdelanghe@gmail.com"}],"homepage":"https://github.com/bounded-systems/conformance-kit#readme","bugs":{"url":"https://github.com/bounded-systems/conformance-kit/issues"},"bin":{"ck-gen-cid":"generators/gen-cid.mjs","ck-axe-gate":"gates/axe-gate.mjs","ck-gen-sbom":"gates/sbom/gen-sbom.mjs","ck-seo-gate":"gates/seo-gate.mjs","ck-vuln-gate":"gates/vuln-gate.mjs","ck-check-sbom":"gates/sbom/check-sbom.mjs","ck-http-probe":"integrity/http-probe.mjs","ck-jargon-gate":"gates/jargon-gate.mjs","ck-verify-site":"integrity/verify-site.mjs","ck-gen-identity":"generators/gen-identity.mjs","ck-shacl-runner":"gates/shacl-runner.mjs","ck-baseline-gate":"gates/baseline-gate.mjs","ck-gen-snapshots":"generators/gen-snapshots.mjs","ck-gen-provenance":"integrity/gen-provenance.mjs","ck-structure-audit":"integrity/structure-audit/audit.mjs","ck-gen-sitemanifest":"integrity/gen-sitemanifest.mjs","ck-readability-gate":"gates/readability-gate.mjs","ck-commonmark-runner":"gates/commonmark-runner.mjs","ck-html-validator-gate":"gates/html-validator-gate.mjs"},"dist":{"shasum":"dd1c25cbf12962f4483a6467cf5124556ee002eb","tarball":"https://registry.npmjs.org/@bounded-systems/conformance-kit/-/conformance-kit-0.3.0.tgz","fileCount":38,"integrity":"sha512-mnjxZ0ln3t0M9kzT9okbyx+dfsojE2hPgkP7+wMzf5H3QTFSu2f7K8y46NuW1D5QIYS6LJOx9X421T0bckyQKA==","signatures":[{"sig":"MEYCIQCG0Qs7bZhVYzeyS0yBiT8LMAMA+j4yWehDmPsK+51EkAIhAPoHXMErSbmicfT4OQVCDJmBOECz+gC0Z3bpFvET64vF","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":272842},"type":"module","exports":{"./lib/*":"./lib/*","./gates/*":"./gates/*","./emitters/*":"./emitters/*","./integrity/*":"./integrity/*","./generators/*":"./generators/*","./package.json":"./package.json","./gates/conformance/*":"./gates/conformance/*"},"scripts":{"test":"node test/run.mjs"},"_npmUser":{"name":"bdelanghe","email":"bdelanghe@gmail.com"},"repository":{"url":"git+https://github.com/bounded-systems/conformance-kit.git","type":"git"},"_npmVersion":"11.13.0","description":"Standalone, site-agnostic web-conformance toolkit: integrity tooling + build gates + provenance generators, all parameterized so a site vendors one kit instead of duplicating scripts.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"n3":"^1.17.3","jsonld":"^9.0.0","vnu-jar":"^26.6.24","axe-core":"^4.10.0","linkedom":"^0.18.0","sigstore":"^5.0.0","turndown":"^7.2.4","stylelint":"^17.14.0","@zazuko/env-node":"^2.1.5","rdf-validate-shacl":"^0.5.10","@mozilla/readability":"^0.5.0","an-array-of-english-words":"^2.0.0","stylelint-plugin-use-baseline":"^1.4.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/conformance-kit_0.3.0_1782701208986_0.5224427635978723","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@bounded-systems/conformance-kit","version":"0.4.0","license":"MIT","_id":"@bounded-systems/conformance-kit@0.4.0","maintainers":[{"name":"bdelanghe","email":"bdelanghe@gmail.com"}],"homepage":"https://github.com/bounded-systems/conformance-kit#readme","bugs":{"url":"https://github.com/bounded-systems/conformance-kit/issues"},"bin":{"ck-gen-cid":"generators/gen-cid.mjs","ck-axe-gate":"gates/axe-gate.mjs","ck-gen-sbom":"gates/sbom/gen-sbom.mjs","ck-seo-gate":"gates/seo-gate.mjs","ck-vuln-gate":"gates/vuln-gate.mjs","ck-check-sbom":"gates/sbom/check-sbom.mjs","ck-http-probe":"integrity/http-probe.mjs","ck-jargon-gate":"gates/jargon-gate.mjs","ck-verify-site":"integrity/verify-site.mjs","ck-gen-identity":"generators/gen-identity.mjs","ck-palette-gate":"gates/palette-gate.mjs","ck-shacl-runner":"gates/shacl-runner.mjs","ck-baseline-gate":"gates/baseline-gate.mjs","ck-gen-snapshots":"generators/gen-snapshots.mjs","ck-gen-provenance":"integrity/gen-provenance.mjs","ck-structure-audit":"integrity/structure-audit/audit.mjs","ck-gen-sitemanifest":"integrity/gen-sitemanifest.mjs","ck-readability-gate":"gates/readability-gate.mjs","ck-commonmark-runner":"gates/commonmark-runner.mjs","ck-html-validator-gate":"gates/html-validator-gate.mjs"},"dist":{"shasum":"9f21e5d908dc6755b3e3abad9a7ebfd145257a70","tarball":"https://registry.npmjs.org/@bounded-systems/conformance-kit/-/conformance-kit-0.4.0.tgz","fileCount":39,"integrity":"sha512-+/H3BgYvP5jixww3FhOdzVIUBWf2d+AxBqAmTlL3DVX9Q7pUBP4+VID21S0b38bOf/Z6cCcVjGdB2/k9hpF3rQ==","signatures":[{"sig":"MEUCIFfxB5dKCdp1zdiBo6qTDj5RwLcr0n+Mswi8vZDARZZmAiEApohjGyy1FiPUPy7RtQaRtfWm7E+Uh+J3fLYhoRONnhA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":302762},"type":"module","exports":{"./lib/*":"./lib/*","./gates/*":"./gates/*","./emitters/*":"./emitters/*","./integrity/*":"./integrity/*","./generators/*":"./generators/*","./package.json":"./package.json","./gates/conformance/*":"./gates/conformance/*"},"scripts":{"test":"node test/run.mjs"},"_npmUser":{"name":"bdelanghe","email":"bdelanghe@gmail.com"},"repository":{"url":"git+https://github.com/bounded-systems/conformance-kit.git","type":"git"},"_npmVersion":"11.13.0","description":"Standalone, site-agnostic web-conformance toolkit: integrity tooling + build gates + provenance generators, all parameterized so a site vendors one kit instead of duplicating scripts.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"n3":"^1.17.3","jsonld":"^9.0.0","vnu-jar":"^26.6.24","axe-core":"^4.10.0","linkedom":"^0.18.0","sigstore":"^5.0.0","turndown":"^7.2.4","stylelint":"^17.14.0","@zazuko/env-node":"^2.1.5","rdf-validate-shacl":"^0.5.10","@mozilla/readability":"^0.5.0","an-array-of-english-words":"^2.0.0","stylelint-plugin-use-baseline":"^1.4.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/conformance-kit_0.4.0_1782702746835_0.610221836374226","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@bounded-systems/conformance-kit","version":"0.5.0","license":"MIT","_id":"@bounded-systems/conformance-kit@0.5.0","maintainers":[{"name":"bdelanghe","email":"bdelanghe@gmail.com"}],"homepage":"https://github.com/bounded-systems/conformance-kit#readme","bugs":{"url":"https://github.com/bounded-systems/conformance-kit/issues"},"bin":{"ck-gen-cid":"generators/gen-cid.mjs","ck-axe-gate":"gates/axe-gate.mjs","ck-gen-sbom":"gates/sbom/gen-sbom.mjs","ck-seo-gate":"gates/seo-gate.mjs","ck-vuln-gate":"gates/vuln-gate.mjs","ck-check-sbom":"gates/sbom/check-sbom.mjs","ck-http-probe":"integrity/http-probe.mjs","ck-jargon-gate":"gates/jargon-gate.mjs","ck-verify-site":"integrity/verify-site.mjs","ck-gen-identity":"generators/gen-identity.mjs","ck-palette-gate":"gates/palette-gate.mjs","ck-shacl-runner":"gates/shacl-runner.mjs","ck-baseline-gate":"gates/baseline-gate.mjs","ck-gen-snapshots":"generators/gen-snapshots.mjs","ck-gen-provenance":"integrity/gen-provenance.mjs","ck-structure-audit":"integrity/structure-audit/audit.mjs","ck-gen-sitemanifest":"integrity/gen-sitemanifest.mjs","ck-readability-gate":"gates/readability-gate.mjs","ck-commonmark-runner":"gates/commonmark-runner.mjs","ck-gen-print-snapshots":"generators/gen-print-snapshots.mjs","ck-html-validator-gate":"gates/html-validator-gate.mjs"},"dist":{"shasum":"930b93e03fa863037d7419945910cd4525767576","tarball":"https://registry.npmjs.org/@bounded-systems/conformance-kit/-/conformance-kit-0.5.0.tgz","fileCount":40,"integrity":"sha512-qFNN7m1y2cxYre2LxE61pERSy/Gu7wUb/ktAew1GSo1OuZh7OA39rg3wjlnYEBlJlI4WfO9GO/q7QGbw7UeXUA==","signatures":[{"sig":"MEUCIEX4RKTEDWaTHy77nvGcVFPNssImH12t1XjCaT2kGODlAiEApsAdZ3l67A6zjpb/Tw8MNfgngpmNpjYxCWvYiCPXogY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bounded-systems%2fconformance-kit@0.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":310375},"type":"module","exports":{"./lib/*":"./lib/*","./gates/*":"./gates/*","./emitters/*":"./emitters/*","./integrity/*":"./integrity/*","./generators/*":"./generators/*","./package.json":"./package.json","./gates/conformance/*":"./gates/conformance/*"},"gitHead":"f06208ef3095a00a35cc5f9e7ce7b1488a3a560b","scripts":{"test":"node test/run.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:57a84ab2-6283-4058-8fcb-94907c1f6b04"}},"repository":{"url":"git+https://github.com/bounded-systems/conformance-kit.git","type":"git"},"_npmVersion":"11.17.0","description":"Standalone, site-agnostic web-conformance toolkit: integrity tooling + build gates + provenance generators, all parameterized so a site vendors one kit instead of duplicating scripts.","directories":{},"_nodeVersion":"22.23.0","dependencies":{"n3":"^1.17.3","jsonld":"^9.0.0","vnu-jar":"^26.6.24","axe-core":"^4.10.0","linkedom":"^0.18.0","sigstore":"^5.0.0","turndown":"^7.2.4","stylelint":"^17.14.0","@zazuko/env-node":"^2.1.5","rdf-validate-shacl":"^0.5.10","@mozilla/readability":"^0.5.0","an-array-of-english-words":"^2.0.0","stylelint-plugin-use-baseline":"^1.4.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/conformance-kit_0.5.0_1782704894678_0.19381201733664177","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@bounded-systems/conformance-kit","version":"0.6.0","license":"MIT","_id":"@bounded-systems/conformance-kit@0.6.0","maintainers":[{"name":"bdelanghe","email":"bdelanghe@gmail.com"}],"homepage":"https://github.com/bounded-systems/conformance-kit#readme","bugs":{"url":"https://github.com/bounded-systems/conformance-kit/issues"},"bin":{"ck-gen-cid":"generators/gen-cid.mjs","ck-axe-gate":"gates/axe-gate.mjs","ck-gen-sbom":"gates/sbom/gen-sbom.mjs","ck-seo-gate":"gates/seo-gate.mjs","ck-vuln-gate":"gates/vuln-gate.mjs","ck-check-sbom":"gates/sbom/check-sbom.mjs","ck-http-probe":"integrity/http-probe.mjs","ck-token-a11y":"gates/token-a11y.mjs","ck-jargon-gate":"gates/jargon-gate.mjs","ck-verify-site":"integrity/verify-site.mjs","ck-gen-identity":"generators/gen-identity.mjs","ck-palette-gate":"gates/palette-gate.mjs","ck-shacl-runner":"gates/shacl-runner.mjs","ck-baseline-gate":"gates/baseline-gate.mjs","ck-gen-snapshots":"generators/gen-snapshots.mjs","ck-likeness-gate":"gates/likeness-gate.mjs","ck-gen-provenance":"integrity/gen-provenance.mjs","ck-structure-audit":"integrity/structure-audit/audit.mjs","ck-typography-gate":"gates/typography-gate.mjs","ck-gen-sitemanifest":"integrity/gen-sitemanifest.mjs","ck-readability-gate":"gates/readability-gate.mjs","ck-target-size-gate":"gates/target-size-gate.mjs","ck-commonmark-runner":"gates/commonmark-runner.mjs","ck-pairing-extractor":"gates/pairing-extractor.mjs","ck-ai-readability-gate":"gates/ai-readability-gate.mjs","ck-gen-print-snapshots":"generators/gen-print-snapshots.mjs","ck-html-validator-gate":"gates/html-validator-gate.mjs","ck-opacity-contrast-gate":"gates/opacity-contrast-gate.mjs"},"dist":{"shasum":"2d426213f1e9cfb59d76902849a8e5e24e41e849","tarball":"https://registry.npmjs.org/@bounded-systems/conformance-kit/-/conformance-kit-0.6.0.tgz","fileCount":47,"integrity":"sha512-Uuxubn7jIBy9Z7hUVfuSFtQPKfhUyrL3g4Sa/TdOp9kZq0kdAOpfssDqOs9FiVJfWd9E3QNNAhVFRKaaT+wPxA==","signatures":[{"sig":"MEUCIBAKS8dzfkCnzWgKsX9Av3IUSkSs3ahkaVvmbR/HVTzdAiEA3qXXOg1NJyymEQCV1Gdpc7p7nuYE85hGBCkXJetBdyo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bounded-systems%2fconformance-kit@0.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":396165},"type":"module","exports":{"./lib/*":"./lib/*","./gates/*":"./gates/*","./emitters/*":"./emitters/*","./integrity/*":"./integrity/*","./generators/*":"./generators/*","./package.json":"./package.json","./gates/conformance/*":"./gates/conformance/*"},"gitHead":"ac679b043e2192f4f319680048b431969d7fddbd","scripts":{"test":"node test/run.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:57a84ab2-6283-4058-8fcb-94907c1f6b04"}},"repository":{"url":"git+https://github.com/bounded-systems/conformance-kit.git","type":"git"},"_npmVersion":"11.17.0","description":"Standalone, site-agnostic web-conformance toolkit: integrity tooling + build gates + provenance generators, all parameterized so a site vendors one kit instead of duplicating scripts.","directories":{},"_nodeVersion":"22.23.0","dependencies":{"n3":"^1.17.3","jsonld":"^9.0.0","vnu-jar":"^26.6.24","axe-core":"^4.10.0","linkedom":"^0.18.0","sigstore":"^5.0.0","turndown":"^7.2.4","stylelint":"^17.14.0","@zazuko/env-node":"^2.1.5","rdf-validate-shacl":"^0.5.10","@mozilla/readability":"^0.5.0","an-array-of-english-words":"^2.0.0","stylelint-plugin-use-baseline":"^1.4.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/conformance-kit_0.6.0_1782709267891_0.27227146557576787","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@bounded-systems/conformance-kit","version":"0.7.0","license":"MIT","_id":"@bounded-systems/conformance-kit@0.7.0","maintainers":[{"name":"bdelanghe","email":"bdelanghe@gmail.com"}],"homepage":"https://github.com/bounded-systems/conformance-kit#readme","bugs":{"url":"https://github.com/bounded-systems/conformance-kit/issues"},"bin":{"ck-gen-cid":"generators/gen-cid.mjs","ck-axe-gate":"gates/axe-gate.mjs","ck-gen-sbom":"gates/sbom/gen-sbom.mjs","ck-seo-gate":"gates/seo-gate.mjs","ck-vuln-gate":"gates/vuln-gate.mjs","ck-check-sbom":"gates/sbom/check-sbom.mjs","ck-http-probe":"integrity/http-probe.mjs","ck-token-a11y":"gates/token-a11y.mjs","ck-jargon-gate":"gates/jargon-gate.mjs","ck-verify-site":"integrity/verify-site.mjs","ck-gen-identity":"generators/gen-identity.mjs","ck-palette-gate":"gates/palette-gate.mjs","ck-shacl-runner":"gates/shacl-runner.mjs","ck-baseline-gate":"gates/baseline-gate.mjs","ck-gen-snapshots":"generators/gen-snapshots.mjs","ck-likeness-gate":"gates/likeness-gate.mjs","ck-gen-provenance":"integrity/gen-provenance.mjs","ck-structure-audit":"integrity/structure-audit/audit.mjs","ck-typography-gate":"gates/typography-gate.mjs","ck-gen-sitemanifest":"integrity/gen-sitemanifest.mjs","ck-readability-gate":"gates/readability-gate.mjs","ck-target-size-gate":"gates/target-size-gate.mjs","ck-commonmark-runner":"gates/commonmark-runner.mjs","ck-pairing-extractor":"gates/pairing-extractor.mjs","ck-ai-readability-gate":"gates/ai-readability-gate.mjs","ck-gen-print-snapshots":"generators/gen-print-snapshots.mjs","ck-html-validator-gate":"gates/html-validator-gate.mjs","ck-opacity-contrast-gate":"gates/opacity-contrast-gate.mjs"},"dist":{"shasum":"7396c40c2af062d1cb4ad97a4e3d4fff31489d88","tarball":"https://registry.npmjs.org/@bounded-systems/conformance-kit/-/conformance-kit-0.7.0.tgz","fileCount":47,"integrity":"sha512-B8Jcw+i98IMYNPAS+S0O42CnswJ6b4Qef5LHTGslFA8iDh5punuy6wA9IhkH65NLQAt5yknNJmAMysa36zf7bA==","signatures":[{"sig":"MEUCIQCxRd2tCtCBNzGh62h/a7vpFoB2ZwBeHrJq4o2e2UfDZwIgPjGvYpvXzpcIsK9go3Pc9+vmEAZTpM9BvgHlly1we9E=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bounded-systems%2fconformance-kit@0.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":400216},"type":"module","exports":{"./lib/*":"./lib/*","./gates/*":"./gates/*","./emitters/*":"./emitters/*","./integrity/*":"./integrity/*","./generators/*":"./generators/*","./package.json":"./package.json","./gates/conformance/*":"./gates/conformance/*"},"gitHead":"bb0ace7fc2022b37d98ecc695e7d15f8a43aa5db","scripts":{"test":"node test/run.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:57a84ab2-6283-4058-8fcb-94907c1f6b04"}},"repository":{"url":"git+https://github.com/bounded-systems/conformance-kit.git","type":"git"},"_npmVersion":"11.17.0","description":"Standalone, site-agnostic web-conformance toolkit: integrity tooling + build gates + provenance generators, all parameterized so a site vendors one kit instead of duplicating scripts.","directories":{},"_nodeVersion":"22.23.0","dependencies":{"n3":"^1.17.3","jsonld":"^9.0.0","vnu-jar":"^26.6.24","axe-core":"^4.10.0","linkedom":"^0.18.0","sigstore":"^5.0.0","turndown":"^7.2.4","stylelint":"^17.14.0","@zazuko/env-node":"^2.1.5","rdf-validate-shacl":"^0.5.10","@mozilla/readability":"^0.5.0","an-array-of-english-words":"^2.0.0","stylelint-plugin-use-baseline":"^1.4.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/conformance-kit_0.7.0_1782710696125_0.05999786045802158","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@bounded-systems/conformance-kit","version":"0.8.0","license":"MIT","_id":"@bounded-systems/conformance-kit@0.8.0","maintainers":[{"name":"bdelanghe","email":"bdelanghe@gmail.com"}],"homepage":"https://github.com/bounded-systems/conformance-kit#readme","bugs":{"url":"https://github.com/bounded-systems/conformance-kit/issues"},"bin":{"ck-gen-cid":"generators/gen-cid.mjs","ck-axe-gate":"gates/axe-gate.mjs","ck-gen-sbom":"gates/sbom/gen-sbom.mjs","ck-seo-gate":"gates/seo-gate.mjs","ck-vuln-gate":"gates/vuln-gate.mjs","ck-check-sbom":"gates/sbom/check-sbom.mjs","ck-http-probe":"integrity/http-probe.mjs","ck-token-a11y":"gates/token-a11y.mjs","ck-jargon-gate":"gates/jargon-gate.mjs","ck-verify-site":"integrity/verify-site.mjs","ck-gen-identity":"generators/gen-identity.mjs","ck-palette-gate":"gates/palette-gate.mjs","ck-shacl-runner":"gates/shacl-runner.mjs","ck-baseline-gate":"gates/baseline-gate.mjs","ck-gen-snapshots":"generators/gen-snapshots.mjs","ck-likeness-gate":"gates/likeness-gate.mjs","ck-gen-provenance":"integrity/gen-provenance.mjs","ck-structure-audit":"integrity/structure-audit/audit.mjs","ck-typography-gate":"gates/typography-gate.mjs","ck-gen-sitemanifest":"integrity/gen-sitemanifest.mjs","ck-readability-gate":"gates/readability-gate.mjs","ck-target-size-gate":"gates/target-size-gate.mjs","ck-commonmark-runner":"gates/commonmark-runner.mjs","ck-pairing-extractor":"gates/pairing-extractor.mjs","ck-ai-readability-gate":"gates/ai-readability-gate.mjs","ck-gen-print-snapshots":"generators/gen-print-snapshots.mjs","ck-html-validator-gate":"gates/html-validator-gate.mjs","ck-opacity-contrast-gate":"gates/opacity-contrast-gate.mjs"},"dist":{"shasum":"30468589b12933b5ef53ef45951f7025c927ddb8","tarball":"https://registry.npmjs.org/@bounded-systems/conformance-kit/-/conformance-kit-0.8.0.tgz","fileCount":47,"integrity":"sha512-4i7G3lS21VRIej09JGQ7sZ/62M+A+BAFIqTYrEFaq1Xz3GSmQnXXjKai5MvyC5IckMXCjdXEIYhB6xxxYMn+/w==","signatures":[{"sig":"MEUCIBe/LFfLl8ssoFMu9GAUl3WhqnPYYD3ckb0Iohd7GegWAiEAsilv2FQ2xvcVQlS4PR/rwzyfLI14pKzKCw6Gcj/vyOY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bounded-systems%2fconformance-kit@0.8.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":400853},"type":"module","exports":{"./lib/*":"./lib/*","./gates/*":"./gates/*","./emitters/*":"./emitters/*","./integrity/*":"./integrity/*","./generators/*":"./generators/*","./package.json":"./package.json","./gates/conformance/*":"./gates/conformance/*"},"gitHead":"ca982b8d8412877daad019b3e94733464365c69c","scripts":{"test":"node test/run.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:57a84ab2-6283-4058-8fcb-94907c1f6b04"}},"repository":{"url":"git+https://github.com/bounded-systems/conformance-kit.git","type":"git"},"_npmVersion":"11.17.0","description":"Standalone, site-agnostic web-conformance toolkit: integrity tooling + build gates + provenance generators, all parameterized so a site vendors one kit instead of duplicating scripts.","directories":{},"_nodeVersion":"22.23.0","dependencies":{"n3":"^1.17.3","jsonld":"^9.0.0","vnu-jar":"^26.6.24","axe-core":"^4.10.0","linkedom":"^0.18.0","sigstore":"^5.0.0","turndown":"^7.2.4","stylelint":"^17.14.0","@zazuko/env-node":"^2.1.5","rdf-validate-shacl":"^0.5.10","@mozilla/readability":"^0.5.0","an-array-of-english-words":"^2.0.0","stylelint-plugin-use-baseline":"^1.4.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/conformance-kit_0.8.0_1782712759136_0.6466209855246103","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"@bounded-systems/conformance-kit","version":"0.9.0","license":"MIT","_id":"@bounded-systems/conformance-kit@0.9.0","maintainers":[{"name":"bdelanghe","email":"bdelanghe@gmail.com"}],"homepage":"https://github.com/bounded-systems/conformance-kit#readme","bugs":{"url":"https://github.com/bounded-systems/conformance-kit/issues"},"bin":{"ck-gen-cid":"generators/gen-cid.mjs","ck-axe-gate":"gates/axe-gate.mjs","ck-gen-sbom":"gates/sbom/gen-sbom.mjs","ck-seo-gate":"gates/seo-gate.mjs","ck-vuln-gate":"gates/vuln-gate.mjs","ck-check-sbom":"gates/sbom/check-sbom.mjs","ck-http-probe":"integrity/http-probe.mjs","ck-token-a11y":"gates/token-a11y.mjs","ck-jargon-gate":"gates/jargon-gate.mjs","ck-verify-site":"integrity/verify-site.mjs","ck-gen-identity":"generators/gen-identity.mjs","ck-palette-gate":"gates/palette-gate.mjs","ck-shacl-runner":"gates/shacl-runner.mjs","ck-baseline-gate":"gates/baseline-gate.mjs","ck-gen-snapshots":"generators/gen-snapshots.mjs","ck-likeness-gate":"gates/likeness-gate.mjs","ck-gen-provenance":"integrity/gen-provenance.mjs","ck-css-purity-gate":"gates/css-purity-gate.mjs","ck-structure-audit":"integrity/structure-audit/audit.mjs","ck-typography-gate":"gates/typography-gate.mjs","ck-gen-sitemanifest":"integrity/gen-sitemanifest.mjs","ck-readability-gate":"gates/readability-gate.mjs","ck-target-size-gate":"gates/target-size-gate.mjs","ck-commonmark-runner":"gates/commonmark-runner.mjs","ck-focus-budget-gate":"gates/cognitive/focus-budget-gate.mjs","ck-pairing-extractor":"gates/pairing-extractor.mjs","ck-a11y-heuristic-gate":"gates/a11y-heuristic-gate.mjs","ck-ai-readability-gate":"gates/ai-readability-gate.mjs","ck-gen-print-snapshots":"generators/gen-print-snapshots.mjs","ck-html-validator-gate":"gates/html-validator-gate.mjs","ck-claim-discipline-gate":"gates/claim-discipline-gate.mjs","ck-opacity-contrast-gate":"gates/opacity-contrast-gate.mjs","ck-grammar-repetition-gate":"gates/grammar-repetition-gate.mjs"},"dist":{"shasum":"b2219f447f97923be83559c3460a7bd55688ea82","tarball":"https://registry.npmjs.org/@bounded-systems/conformance-kit/-/conformance-kit-0.9.0.tgz","fileCount":53,"integrity":"sha512-7NGa6nzcqNvBzPSMR1tQhY82j7kySoUj3h0pkRfXF2KbXF+ReVGx1orfT4D2dzH41CkM/3NjvatKpgTN4LCUnA==","signatures":[{"sig":"MEUCIHU9Wwc2gTwvPydm8c5LTqk17qTfWvY2Huaq50CgXKZrAiEAqTBb9iu5g6LAeRs3brt44KHX2aBzAAggVypaCqwqBL0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bounded-systems%2fconformance-kit@0.9.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":494760},"type":"module","exports":{"./lib/*":"./lib/*","./gates/*":"./gates/*","./emitters/*":"./emitters/*","./integrity/*":"./integrity/*","./generators/*":"./generators/*","./package.json":"./package.json","./gates/cognitive/*":"./gates/cognitive/*","./gates/conformance/*":"./gates/conformance/*"},"gitHead":"dc33dd87e8547f9d9543b1f74eef229b4d8abbc9","scripts":{"test":"node test/run.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:57a84ab2-6283-4058-8fcb-94907c1f6b04"}},"repository":{"url":"git+https://github.com/bounded-systems/conformance-kit.git","type":"git"},"_npmVersion":"11.18.0","description":"Standalone, site-agnostic web-conformance toolkit: integrity tooling + build gates + provenance generators, all parameterized so a site vendors one kit instead of duplicating scripts.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"n3":"^1.17.3","jsonld":"^9.0.0","vnu-jar":"^26.6.24","axe-core":"^4.10.0","linkedom":"^0.18.0","sigstore":"^5.0.0","turndown":"^7.2.4","stylelint":"^17.14.0","@zazuko/env-node":"^2.1.5","rdf-validate-shacl":"^0.5.10","@mozilla/readability":"^0.5.0","an-array-of-english-words":"^2.0.0","stylelint-plugin-use-baseline":"^1.4.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/conformance-kit_0.9.0_1783224336840_0.9229879695705658","host":"s3://npm-registry-packages-npm-production"}},"0.10.0":{"name":"@bounded-systems/conformance-kit","version":"0.10.0","license":"MIT","_id":"@bounded-systems/conformance-kit@0.10.0","maintainers":[{"name":"bdelanghe","email":"bdelanghe@gmail.com"}],"homepage":"https://github.com/bounded-systems/conformance-kit#readme","bugs":{"url":"https://github.com/bounded-systems/conformance-kit/issues"},"bin":{"ck-gen-cid":"generators/gen-cid.mjs","ck-axe-gate":"gates/axe-gate.mjs","ck-gen-sbom":"gates/sbom/gen-sbom.mjs","ck-seo-gate":"gates/seo-gate.mjs","ck-vuln-gate":"gates/vuln-gate.mjs","ck-check-sbom":"gates/sbom/check-sbom.mjs","ck-http-probe":"integrity/http-probe.mjs","ck-token-a11y":"gates/token-a11y.mjs","ck-jargon-gate":"gates/jargon-gate.mjs","ck-verify-site":"integrity/verify-site.mjs","ck-gen-identity":"generators/gen-identity.mjs","ck-palette-gate":"gates/palette-gate.mjs","ck-shacl-runner":"gates/shacl-runner.mjs","ck-baseline-gate":"gates/baseline-gate.mjs","ck-gen-snapshots":"generators/gen-snapshots.mjs","ck-likeness-gate":"gates/likeness-gate.mjs","ck-doc-scope-gate":"gates/doc-scope-gate.mjs","ck-gen-provenance":"integrity/gen-provenance.mjs","ck-css-purity-gate":"gates/css-purity-gate.mjs","ck-structure-audit":"integrity/structure-audit/audit.mjs","ck-typography-gate":"gates/typography-gate.mjs","ck-gen-sitemanifest":"integrity/gen-sitemanifest.mjs","ck-readability-gate":"gates/readability-gate.mjs","ck-target-size-gate":"gates/target-size-gate.mjs","ck-commonmark-runner":"gates/commonmark-runner.mjs","ck-focus-budget-gate":"gates/cognitive/focus-budget-gate.mjs","ck-pairing-extractor":"gates/pairing-extractor.mjs","ck-a11y-heuristic-gate":"gates/a11y-heuristic-gate.mjs","ck-ai-readability-gate":"gates/ai-readability-gate.mjs","ck-gen-print-snapshots":"generators/gen-print-snapshots.mjs","ck-html-validator-gate":"gates/html-validator-gate.mjs","ck-claim-discipline-gate":"gates/claim-discipline-gate.mjs","ck-opacity-contrast-gate":"gates/opacity-contrast-gate.mjs","ck-grammar-repetition-gate":"gates/grammar-repetition-gate.mjs"},"dist":{"shasum":"ba8af97dcc9b80c1178515253dc5a9edd8b6f6f9","tarball":"https://registry.npmjs.org/@bounded-systems/conformance-kit/-/conformance-kit-0.10.0.tgz","fileCount":54,"integrity":"sha512-BDjZJ1mGOPwMo4rReXXDL3Grch7MSYCG4gfofVXfzVrb2DZaV7iujKtB6etF4YwEWZR9hynNzG5sJBOQv95WQg==","signatures":[{"sig":"MEQCIHa+YrOZORdUTAsyKoHGGK5V3IL3XgQArPlSyDocrynEAiARvtSkzwHQQoTEEonYgLe6xx85DqPsg0WjoQbviABBwQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bounded-systems%2fconformance-kit@0.10.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":498930},"type":"module","exports":{"./lib/*":"./lib/*","./gates/*":"./gates/*","./emitters/*":"./emitters/*","./integrity/*":"./integrity/*","./generators/*":"./generators/*","./package.json":"./package.json","./gates/cognitive/*":"./gates/cognitive/*","./gates/conformance/*":"./gates/conformance/*"},"gitHead":"122843a1c2f0b2beebd9cec0ae4653b9d0894cf3","scripts":{"test":"node test/run.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:57a84ab2-6283-4058-8fcb-94907c1f6b04"}},"repository":{"url":"git+https://github.com/bounded-systems/conformance-kit.git","type":"git"},"_npmVersion":"11.18.0","description":"Standalone, site-agnostic web-conformance toolkit: integrity tooling + build gates + provenance generators, all parameterized so a site vendors one kit instead of duplicating scripts.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"n3":"^1.17.3","jsonld":"^9.0.0","vnu-jar":"^26.6.24","axe-core":"^4.10.0","linkedom":"^0.18.0","sigstore":"^5.0.0","turndown":"^7.2.4","stylelint":"^17.14.0","@zazuko/env-node":"^2.1.5","rdf-validate-shacl":"^0.5.10","@mozilla/readability":"^0.5.0","an-array-of-english-words":"^2.0.0","stylelint-plugin-use-baseline":"^1.4.4"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/conformance-kit_0.10.0_1783261471696_0.20145565356563488","host":"s3://npm-registry-packages-npm-production"}},"0.11.0":{"name":"@bounded-systems/conformance-kit","version":"0.11.0","description":"Standalone, site-agnostic web-conformance toolkit: integrity tooling + build gates + provenance generators, all parameterized so a site vendors one kit instead of duplicating scripts.","type":"module","license":"MIT","repository":{"type":"git","url":"git+https://github.com/bounded-systems/conformance-kit.git"},"bin":{"ck-gen-sitemanifest":"integrity/gen-sitemanifest.mjs","ck-gen-provenance":"integrity/gen-provenance.mjs","ck-verify-site":"integrity/verify-site.mjs","ck-http-probe":"integrity/http-probe.mjs","ck-structure-audit":"integrity/structure-audit/audit.mjs","ck-gen-sbom":"gates/sbom/gen-sbom.mjs","ck-check-sbom":"gates/sbom/check-sbom.mjs","ck-shacl-runner":"gates/shacl-runner.mjs","ck-seo-gate":"gates/seo-gate.mjs","ck-axe-gate":"gates/axe-gate.mjs","ck-vuln-gate":"gates/vuln-gate.mjs","ck-html-validator-gate":"gates/html-validator-gate.mjs","ck-baseline-gate":"gates/baseline-gate.mjs","ck-palette-gate":"gates/palette-gate.mjs","ck-typography-gate":"gates/typography-gate.mjs","ck-target-size-gate":"gates/target-size-gate.mjs","ck-opacity-contrast-gate":"gates/opacity-contrast-gate.mjs","ck-likeness-gate":"gates/likeness-gate.mjs","ck-pairing-extractor":"gates/pairing-extractor.mjs","ck-token-a11y":"gates/token-a11y.mjs","ck-jargon-gate":"gates/jargon-gate.mjs","ck-readability-gate":"gates/readability-gate.mjs","ck-ai-readability-gate":"gates/ai-readability-gate.mjs","ck-a11y-heuristic-gate":"gates/a11y-heuristic-gate.mjs","ck-focus-budget-gate":"gates/cognitive/focus-budget-gate.mjs","ck-css-purity-gate":"gates/css-purity-gate.mjs","ck-commonmark-runner":"gates/commonmark-runner.mjs","ck-gen-cid":"generators/gen-cid.mjs","ck-gen-identity":"generators/gen-identity.mjs","ck-gen-snapshots":"generators/gen-snapshots.mjs","ck-gen-print-snapshots":"generators/gen-print-snapshots.mjs","ck-claim-discipline-gate":"gates/claim-discipline-gate.mjs","ck-grammar-repetition-gate":"gates/grammar-repetition-gate.mjs","ck-doc-scope-gate":"gates/doc-scope-gate.mjs","ck-token-grounding-gate":"gates/token-grounding-gate.mjs"},"scripts":{"test":"node test/run.mjs"},"exports":{"./package.json":"./package.json","./gates/*":"./gates/*","./gates/conformance/*":"./gates/conformance/*","./gates/cognitive/*":"./gates/cognitive/*","./generators/*":"./generators/*","./integrity/*":"./integrity/*","./emitters/*":"./emitters/*","./lib/*":"./lib/*"},"publishConfig":{"access":"public"},"dependencies":{"@mozilla/readability":"^0.5.0","@zazuko/env-node":"^2.1.5","an-array-of-english-words":"^2.0.0","axe-core":"^4.10.0","jsonld":"^9.0.0","linkedom":"^0.18.0","n3":"^1.17.3","rdf-validate-shacl":"^0.5.10","sigstore":"^5.0.0","stylelint":"^17.14.0","stylelint-plugin-use-baseline":"^1.4.4","turndown":"^7.2.4","vnu-jar":"^26.6.24"},"gitHead":"5d74ea3eb27e701e86d04e01cba65146847e8bc0","_id":"@bounded-systems/conformance-kit@0.11.0","bugs":{"url":"https://github.com/bounded-systems/conformance-kit/issues"},"homepage":"https://github.com/bounded-systems/conformance-kit#readme","_nodeVersion":"22.23.1","_npmVersion":"11.18.0","dist":{"integrity":"sha512-OeKJVYNepLhSxpa9ZF02H4sFDHoL6PhDFij6D9esgoyOTuKEgeMrMjsoqaPIs9ElGLHCk1x87WVcBPVxAhpieg==","shasum":"d833aef61cf67a455d06445103a799879ec30cec","tarball":"https://registry.npmjs.org/@bounded-systems/conformance-kit/-/conformance-kit-0.11.0.tgz","fileCount":55,"unpackedSize":502438,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@bounded-systems%2fconformance-kit@0.11.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCbqulJwRE71hM1niQLP8TJNH0RqQ7z0uoFSyxTiG7O4QIhAPPfstGdpOLNow7bUom4Z0+NpD4lQot1HQ3SidXfy1Ac"}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:57a84ab2-6283-4058-8fcb-94907c1f6b04"}},"directories":{},"maintainers":[{"name":"bdelanghe","email":"bdelanghe@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/conformance-kit_0.11.0_1783262466002_0.5108864473025516"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-29T02:01:48.546Z","modified":"2026-07-05T14:41:06.518Z","0.2.0":"2026-06-29T02:01:48.926Z","0.3.0":"2026-06-29T02:46:49.131Z","0.4.0":"2026-06-29T03:12:26.981Z","0.5.0":"2026-06-29T03:48:14.816Z","0.6.0":"2026-06-29T05:01:08.029Z","0.7.0":"2026-06-29T05:24:56.261Z","0.8.0":"2026-06-29T05:59:19.276Z","0.9.0":"2026-07-05T04:05:37.001Z","0.10.0":"2026-07-05T14:24:31.889Z","0.11.0":"2026-07-05T14:41:06.192Z"},"bugs":{"url":"https://github.com/bounded-systems/conformance-kit/issues"},"license":"MIT","homepage":"https://github.com/bounded-systems/conformance-kit#readme","repository":{"type":"git","url":"git+https://github.com/bounded-systems/conformance-kit.git"},"description":"Standalone, site-agnostic web-conformance toolkit: integrity tooling + build gates + provenance generators, all parameterized so a site vendors one kit instead of duplicating scripts.","maintainers":[{"name":"bdelanghe","email":"bdelanghe@gmail.com"}],"readme":"# @bounded-systems/conformance-kit\n\nA standalone, **site-agnostic web-conformance toolkit**: build-integrity tooling,\nfail-closed conformance gates, and provenance generators — extracted from\n`bdelanghe/site` and `bounded-systems/site` and **generalized** so a site vendors\n**one kit** instead of duplicating scripts.\n\nEvery site value (paths, thresholds, site URL, account/repo id, issuer/DID, SHACL\nshapes, the markdown renderer, the prose corpus, the build itself) is an **INPUT**,\ninjected by the consumer via CLI args, env vars, or a passed config. Nothing here\nhardcodes `robertdelanghe.dev`, `bounded.tools`, an account, or an email.\n\n```\nintegrity/    verify-site · verify (sigstore) · gen-sitemanifest · gen-provenance · structure-audit · http-probe\ngates/        sbom (gen + completeness) · shacl-runner · seo-gate · axe-gate (axe-core a11y) · vuln-gate (npm audit) · html-validator-gate (vnu) · baseline-gate (web-features) · jargon-gate (plain-language) · readability-gate · commonmark-runner · semantic (lone)\ngates/        Token Accessibility suite (static token-level a11y → TOKEN-A11Y.md): palette · pairing-extractor · typography · target-size · opacity-contrast · likeness · token-a11y (unified runner)\ngates/conformance/  conformance-report — lone's conformance() projection (Node port of jsr:@bounded-systems/lone@0.4) + a generic HTML renderer\ngenerators/   gen-cid (IPFS UnixFS) · gen-identity (did:web + VC) · gen-snapshots (reader/markdown) · gen-print-snapshots (PDF) · openapi (static-API helper core)\nemitters/     reprDigest (RFC 9530) · securityTxt (RFC 9116) · webManifest · markdown-sibling headers\nlib/          schema-validate (zero-dep JSON Schema) · config (env/arg helpers)\nfixtures/ test/  isolated verification of the generic logic\n```\n\nDesign rules: zero-dep where the source was zero-dep; pure/offline gates read only\nthe built output; deterministic generators are a function of their inputs (no wall\nclock); fail-closed (`exit 1`) on any violation.\n\n## Install / vendor\n\nThree consumption models:\n\n1. **Vendor (recommended, matches the existing `vendor/integrity/` pattern).** Copy\n   the kit at a pinned commit into `vendor/conformance-kit/`, write a hash-pin\n   manifest (see [`vendor.example.json`](./vendor.example.json) — mirrors\n   `bdelanghe/site` `vendor/integrity/provenance.json`: `source`, `commit`,\n   `fetched`, `files{path: sha256}`), and verify against it before every use. The\n   site then `import`s / invokes the vendored copies. The kit's own\n   [`provenance.json`](./provenance.json) records which source repo + commit each\n   tool was generalized from.\n2. **npm dep.** `npm i @bounded-systems/conformance-kit` and use the `ck-*` bins\n   (see `package.json`) or `import` the library modules.\n3. **Nix flake (reproducible, runtime-bundled).** `nix run\n   github:bounded-systems/conformance-kit#ck-axe-gate -- dist`, or add the flake to\n   a `home-manager` / `nix profile`. Each `ck-*` bin is a hermetic, pinned closure;\n   the gates that shell out get their runtime bundled in — `ck-html-validator-gate`\n   carries a JRE for vnu, `ck-vuln-gate` carries npm — so no JRE/Node on `$PATH` is\n   needed. (`ck-axe-gate` still needs a browser the consumer supplies via\n   `$AXE_RUNNER`: `tezcatl` or Playwright.)\n\nRuntime deps are declared in `package.json` (only the gates that need them pull\nthem: `linkedom`/`@mozilla/readability` for structure-audit; `jsonld`/`n3`/\n`@zazuko/env-node`/`rdf-validate-shacl` for the SHACL runner; `sigstore` for the\nin-process verifier). The Deno semantic runner pins its imports in\n`gates/semantic/deno.json`.\n\n## Tools — what each does + **how a site consumes it** (the input it must supply)\n\n### integrity/\n\n| Tool | Invoke | Consumer supplies |\n|---|---|---|\n| `gen-sitemanifest.mjs` | `DIST=dist node …/gen-sitemanifest.mjs` | `$DIST` (build dir). Optional `$MANIFEST_EXCLUDE` (extra platform control files). Emits `$DIST/site.sha256`. |\n| `gen-provenance.mjs` | run at deploy after signing | GitHub Actions env (`GITHUB_*`), `$OCI_REF`/`$OCI_DIGEST`, optional `$PROVENANCE_DOC_URL`, `$DIST`. The emitted `builder.repository` becomes the identity the verifiers enforce. |\n| `verify-site.mjs` | `node …/verify-site.mjs <https://site \\| ./dist>` | A deployed site (or local dir) carrying `provenance.json` + `site.sha256` + its `.sigstore.json` bundle. Identity is read from `provenance.builder.repository` — nothing hardcoded. Shells to `cosign` if present, else SKIPs with a recipe. |\n| `verify/verify.mjs` | `node …/verify/verify.mjs <url\\|dir>` | Same inputs; verifies the Sigstore **bundle** in-process (offline) via `sigstore-js`. |\n| `structure-audit/audit.mjs` | `node …/audit.mjs <distDir> [--check]` | `<distDir>`. Optional `$STRUCTURE_ARTICLE_PREFIX` (default `blog/`), `$STRUCTURE_ERROR_PAGE` (default `404.html`), `$STRUCTURE_AUDIT_SIDECARS` (deploy-time live paths, e.g. `/resume.pdf`), `$STRUCTURE_BASELINE` (where the committed `structure.json` lives — keep it in the **consumer**, not the vendored kit). |\n| `http-probe.mjs` | `node …/http-probe.mjs <https://site> [config.json]` | A live URL **and** a probe config: `$PROBE_CONFIG`/2nd arg JSON `{htmlRoutes,typed,missing}`, or `$PROBE_HTML_ROUTES`+`$PROBE_MISSING`. Routes are NOT hardcoded. |\n\n### gates/\n\n| Tool | Invoke | Consumer supplies |\n|---|---|---|\n| `sbom/gen-sbom.mjs` | `ROOT=. DIST=dist node …/gen-sbom.mjs` | `$ROOT` (lockfiles live here), `$SBOM_LOCKFILES` (comma list, default `package-lock.json`), `$SBOM_NAME`, `$SBOM_NAMESPACE_BASE`, `$SBOM_CREATORS`. Reads `flake.lock` if present. Emits `$DIST/sbom.spdx.json`. |\n| `sbom/check-sbom.mjs` | `ROOT=. DIST=dist node …/check-sbom.mjs` | Same `$ROOT`/`$DIST`. Fails closed unless pinned-set ⊆ SBOM ⊆ pinned-set and (optionally) the in-toto attestation reconciles. |\n| `shacl-runner.mjs` | `node …/shacl-runner.mjs <shapes.ttl> <htmlDir>` | **The SHACL shapes file stays in the site** (its structured-data contract) + the built-HTML dir. Optional `$SHACL_CONTEXT` (custom offline JSON-LD context; default schema.org). Fails unless every JSON-LD block `conforms: true`. |\n| `seo-gate.mjs` | `node …/seo-gate.mjs [distDir]` | `$DIST`. Optional `$SEO_ERROR_PAGE`, `$SEO_DEPLOY_SIDECARS`. Enforces canonical/title/description uniqueness + self-consistency, robots.txt (RFC 9309), sitemap, internal links. |\n| `axe-gate.mjs` | `node …/axe-gate.mjs [distDir]` | `$DIST`. Optional `$AXE_PAGES` (comma list, default: every `*.html` in dist), `$AXE_TAGS` (default `wcag2a,wcag2aa,wcag21a,wcag21aa,wcag22aa`), `$AXE_IMPACT_THRESHOLD` (`minor`/`moderate`/`serious`/`critical`, default `serious`), `$AXE_RUNNER` (`playwright` (CI, needs `playwright` + `@axe-core/playwright` + `npx playwright install chromium`) \\| `tezcatl` (macOS WebKit, local)), `$AXE_REPORT` (write the JSON report). Serves dist over an ephemeral origin (so assets resolve), runs **axe-core** per page, and **fails closed** on any violation at/above the threshold. The emitted report's `axe: { serious, critical }` envelope is exactly what `conformance-report`'s `a11y.axe-serious-critical` criterion consumes — a clean run is what lets a site honestly assert it. |\n| `vuln-gate.mjs` | `node …/vuln-gate.mjs [projectDir]` | `$VULN_ROOT` (lockfile lives here, default `.`). Optional `$VULN_OMIT_DEV` (`true`→production deps only, default `true`), `$VULN_THRESHOLD` (highest tolerated known critical/high, default `0`), `$VULN_REPORT` (write the JSON report). Runs **`npm audit`** and **fails closed** when the known critical/high count exceeds the threshold. The report's `vulns: { knownCriticalOrHighVulns }` envelope is what `conformance-report`'s `security.no-critical-vulns` criterion consumes. |\n| `html-validator-gate.mjs` | `node …/html-validator-gate.mjs [distDir]` | `$HTML_DIST`. Optional `$HTML_PAGES` (comma list, default: every `*.html`), `$HTML_THRESHOLD` (default `0`), `$HTML_REPORT`. Runs **vnu** (the Nu Html Checker, a self-contained Java jar — needs a JRE) `--errors-only` over the built pages and **fails closed** above the threshold. The report's `htmlValidator: { errors }` envelope is what `conformance-report`'s `html.validator-clean` criterion consumes. |\n| `baseline-gate.mjs` | `node …/baseline-gate.mjs [cssGlob]` | `$BASELINE_CSS` (default `dist/**/*.css`). Optional `$BASELINE_TARGET` (`widely`/`newly`, default `widely`), `$BASELINE_REPORT`. Maps the shipped CSS to **web-features Baseline** data (via `stylelint-plugin-use-baseline` — headless, no browser) and **fails closed** when the site-wide status is below target. A feature behind an `@supports` query is a tested fallback and doesn't count against it. The report's `baseline: { status, fallbackTested }` envelope is what `conformance-report`'s `compatibility.baseline` criterion consumes. |\n| `palette-gate.mjs` | `node …/palette-gate.mjs <tokens.(json\\|css)> <pairings.json>` | **Two inputs the consumer supplies**: a token map (a DTCG `tokens.json` — primitive→semantic aliases resolved — or a `tokens.css` of `--name: #hex` custom properties) and a `pairings.json` declaring the fg/bg pairs that actually co-occur (`{ \"pairings\":[{fg,bg,kind,size?,weight?,name?}], \"categorical\":[…], \"thresholds\":{…} }`; `kind` ∈ `text`\\|`large-text`\\|`ui`, `fg`/`bg` are token names or literal `#hex`). Runs **static colour-palette analysis** — zero-dep, every primitive computed by hand: (1) **CVD-safe contrast** — simulates each colour under deuteranopia/protanopia/tritanopia (**Machado-2009** matrices), recomputes the WCAG ratio per pair under each, and flags any pair dropping below AA, plus **categorical collapse** (CIEDE2000 ΔE below `$PALETTE_COLLAPSE_DELTAE`, default 10) post-transform; (2) **APCA** — implements **APCA-W3 ~0.1.9**, reports `Lc` per text pair against a font-size/weight-aware (or baseline `$PALETTE_MIN_LC_TEXT` 60 / `$PALETTE_MIN_LC_LARGE` 45) minimum, **alongside** the WCAG-2 ratio (complement, not replacement); (3) **non-text contrast** — `kind:'ui'` pairs require ≥3:1 (WCAG 2.2 **SC 1.4.11**). Thresholds are config-driven (`pairings.json` `thresholds` ⊕ `$PALETTE_MIN_RATIO_{TEXT,LARGE,UI}`) and it **fails closed** on any failure. `$PALETTE_REPORT` writes the per-pair JSON (WCAG ratio · APCA Lc · per-CVD ratios · pass/fail per check). The report's `palette: { cvdSafe, apcaBaseline, nonTextContrast }` envelope is what a future `palette.*` criterion consumes. |\n| `jargon-gate.mjs` | `node …/jargon-gate.mjs [distDir] [--strict]` | `$JARGON_DIST`. Optional `$JARGON_ALLOWLIST` (comma list of accepted terms), `$JARGON_MIN_LENGTH` (default `3`), `$JARGON_THRESHOLD` (default `0`, for `--strict`), `$JARGON_REPORT`. Flags **undefined jargon** in the prose: words not in a 275k-word English dictionary (compounds/possessives atomized first) that the page does not **define** via `<abbr title>`, `<dfn>`, or a `<dl>` glossary — for W3C COGA / WCAG 3.1.3 Unusual Words and for AI readers. WARN-only by default; `--strict` fails closed. Report carries a `plainLanguage: { undefinedJargon, glossaryPresent }` envelope (for a future `cognitive.plain-language` criterion). |\n| `typography-gate.mjs` | `node …/typography-gate.mjs <type-tokens.(json\\|css)> [config.json]` | **Token Accessibility suite.** Type tokens (DTCG `$type:\"typography\"` recipes or `.bs-text-*` CSS) + a `config.json` declaring which styles are **body** (`{ \"body\":[\"body\"], \"thresholds\":{…} }`). Static checks, each mapped to a SC: body **line-height ≥ 1.5** (1.4.12); **text-spacing achievability** — spacing/line-height in overridable relative units, never px-pinned (1.4.12); **min font-size** — body ≥ ~16px (warn) / ≥ ~12px hard floor (error) + modular-scale sanity (1.4.4); **weight×size legibility** — thin weight (≤200) at small size → error, plus a `requiredApcaLc` cross-link to the palette gate (1.4.3/1.4.8). Fails closed on any error; `$TYPO_REPORT` writes the JSON. |\n| `target-size-gate.mjs` | `node …/target-size-gate.mjs <config.json>` | **Token Accessibility suite.** A `config.json` where the consumer **declares** which tokens are interactive targets (`{ \"targets\":[{name,width,height\\|size,exception?,reason?}], \"tokens\":{…}, \"thresholds\":{minPx,aaaPx} }`). Enforces target **≥ 24×24px** (2.5.8 AA → error below) and reports **≥ 44×44px** (2.5.5 AAA) status; honours the 2.5.8 `inline`/`essential`/`user-agent`/`spacing` exceptions with an audit `reason`. No target tokens → `coverage:\"none\"` (vacuous pass + gap note). `$TARGET_REPORT` writes the JSON. |\n| `opacity-contrast-gate.mjs` | `node …/opacity-contrast-gate.mjs <tokens.(json\\|css)> <usages.json>` | **Token Accessibility suite — the cross-cutting guard.** Token map + a `usages.json` declaring \"opacity applied to a foreground\" usages (`{ \"usages\":[{fg,bg,opacity,kind,name?}], \"opacityTokens\":{…}, \"thresholds\":{…} }`; `opacity` is 0..1 or a `{token}` ref). Composites fg over bg (Porter-Duff source-over) at the stated alpha and requires the **effective** WCAG contrast ≥ floor (4.5 text / 3 large/ui — 1.4.3/1.4.11), reporting both nominal and effective ratio so the drop is visible. Translucent-over-unknown-backdrop usages are flagged for review, not passed. Catches the bounded.tools opacity regression class. `$OPACITY_REPORT` writes the JSON. |\n| `likeness-gate.mjs` | `node …/likeness-gate.mjs <tokens.(json\\|css)> [config.json]` | **Token Accessibility suite.** Two CIEDE2000 checks over the colour tokens: **near-duplicate** tokens (ΔE < ~2 ⇒ perceptually identical ⇒ consolidate candidate — warning, escalatable) and **confusable categoricals** (consumer-declared distinct sets that collapse under normal vision *or* deuteranopia/protanopia/tritanopia — error; supports 1.4.1). Config: `{ \"categorical\":[{name,members}], \"ignore\":[…], \"thresholds\":{dupDeltaE,collapseDeltaE,dupSeverity} }`. `$LIKENESS_REPORT` writes the JSON. |\n| `pairing-extractor.mjs` | `node …/pairing-extractor.mjs <tokens.(json\\|css)> <style1.css> [style2.css …]` | **Token Accessibility suite — coverage engine.** Derives the real fg×bg pairings from **actual stylesheet usage** (resolves `var(--token)`/literal colours; pairs by same-rule co-occurrence → ancestor-selector containment → root surface, tagged `rule`/`surface`/`root` confidence), **unions** any declared `$PAIRING_DECLARED` pairings in, scores every pair through the palette check, and emits a **pairing matrix** (WCAG · APCA Lc · per-CVD ratios) to `$PAIRING_MATRIX` (Markdown) / `$PAIRING_REPORT` (JSON). No DOM ⇒ a reviewed **superset** (over-generates safely); **report-only** unless `$PAIRING_GATE=1`. Removes the hand-maintained pairings list that let the opacity bug slip. |\n| `token-a11y.mjs` | `node …/token-a11y.mjs <token-a11y.json>` | **Token Accessibility suite — unified runner** (`ck-token-a11y`). One `token-a11y.json` drives every member (palette · pairing · typography · targetSize · opacity · likeness) over one token map and **fails closed** if any fails. See [`TOKEN-A11Y.md`](./TOKEN-A11Y.md) for the standard. `$TOKEN_A11Y_REPORT` writes the aggregate JSON. |\n| `readability-gate.mjs` | `node …/readability-gate.mjs <corpus.json> [--strict]` | **The corpus is an input** the site assembles from its copy: a JSON array of `{id,text}` or an `{id:text}` map. Optional `$READABILITY_THRESHOLDS`, `$READABILITY_MIN_WORDS`, `$READABILITY_KNOWN_ACRONYMS`. WARN-only unless `--strict`. |\n| `ai-readability-gate.mjs` | `node …/ai-readability-gate.mjs [distDir]` | Re-proves lone's `semantic.ai-readability` at build time: emits `{llmsTxtPresent, linksResolve, markdownSiblings}` — checks `llms.txt` exists, its internal links resolve (and none hit `$AIR_PRIVATE` paths), and every content page has a Markdown sibling (`$AIR_SIBLING_SUFFIX`, default `.md`; `$AIR_SIBLING_IGNORE` defaults to `404`). Fail-closed (`$AIR_STRICT=0` to report only); `$AIR_REPORT` writes the evidence JSON. Static only — the `Accept: text/markdown` content-negotiation half is served-edge behaviour, probe it with `ck-http-probe`. |\n| `css-purity-gate.mjs` | `node …/css-purity-gate.mjs <a.css> [b.css …]` | **\"No inline values — always tokens.\"** A declaration-aware static scanner (no browser) that fails closed on a raw dimension (`320px`, `28px`, `999px`…) in any layout property (`width`/`margin`/`padding`/`gap`/`border-radius`/`grid-template-*`/`font-size`/…). Force every spacing/sizing/layout value through a coherent `var(--bs-*)` scale so the composition is predictable + verifiable instead of an overflow/overlap at render time — the static, shift-left counterpart to a runtime layout gate. `$PURITY_PREFIX` (default `--bs-`); `$PURITY_DIMENSIONS=0` off; `$PURITY_COLORS=1` also forbids literal colours (hex/rgb/named); `$PURITY_DIM_PROPS` overrides the property set; `$PURITY_ALLOW` / `$PURITY_HAIRLINE=1` permit specific raw values. `0`/`%`/`fr`/`ch`/`auto`/`var()`/`calc(of tokens)` always pass. |\n| `commonmark-runner.mjs` | `node …/commonmark-runner.mjs <renderer.mjs> [fixtures.json]` | **The site's markdown renderer module** (export `renderMarkdown`, or set `$COMMONMARK_RENDER_EXPORT`). Default fixtures pin a safe CommonMark subset + 4 hostile-HTML escapes; a site with a different renderer supplies its own `fixtures.json`. |\n| `semantic/gate.ts` | `deno run --allow-read --allow-net …/gate.ts` | Built HTML in `$SEMANTIC_DIR` (default `dist/blog`); `$SEMANTIC_SELECTOR` (subject node, default `article`). Imports `jsr:@bounded-systems/lone`; any error-severity finding fails CI. |\n| `conformance-report.mjs` | `import { buildConformanceReport, renderConformanceReport } from \"…/gates/conformance-report.mjs\"` | **The site's evidence** — `loneFindings` (the semantic gate's DOM findings, or `null` when no DOM was blessed → those criteria report `not-assessed`) + an external-evidence envelope whose fields it gathers from its own gates (`jsonLdShacl`, `sbom`, `contentDigests`, `slsaProvenance`, …). `renderConformanceReport(report, { evidenceHref })` → a class-based HTML fragment; the consumer wraps it in its template and supplies per-criterion evidence URLs. Zero-dep; the conformance MODEL is a Node port of `jsr:@bounded-systems/lone@0.4`'s `conformance()` in `gates/conformance/`. |\n\nThe conformance projection makes overclaim impossible by construction: the strong\ncompact claim (`COMPACT_CLAIM`) is emitted **only** when every tier-1 `required`\ncriterion has passing evidence; unsupplied criteria (manual WCAG audit, OWASP ASVS,\nfield Core Web Vitals, Baseline) are `not-assessed`, never `met` — so automation can\nnever print \"WCAG 2.2 AA\" or \"ASVS conformant\" on its own. tier-2/tier-3/cognitive\ncriteria are reported + summarised per area but never widen the headline claim.\n\n### generators/\n\n| Tool | Invoke | Consumer supplies |\n|---|---|---|\n| `gen-cid.mjs` | `DIST=dist node …/gen-cid.mjs` | `$DIST`. Walks the `site.sha256` file set (or `dist`), computes the IPFS UnixFS dir CIDv1 with no daemon, records it into `$DIST/provenance.json`. |\n| `gen-identity.mjs` | `IDENTITY_DOMAIN=… IDENTITY_REPO=owner/repo node …/gen-identity.mjs` | `$IDENTITY_DOMAIN`, `$IDENTITY_REPO` (cert-identity regexp), `$IDENTITY_SUBJECT` (the credentialSubject JSON, default `$DIST/resume.json`), optional `$IDENTITY_SUBJECT_SCHEMA`, `$IDENTITY_VC_NAME/DESCRIPTION`, `$IDENTITY_VALID_FROM_PATH`. Emits `did.json` + a W3C VC 2.0. |\n| `gen-snapshots.mjs` | `node …/gen-snapshots.mjs [distDir]` | `$SNAPSHOT_DIST` (default `dist`). Optional `$SNAPSHOT_PAGES`, `$SNAPSHOT_BASE_URL` (recorded as `source` in the front-matter), `$SNAPSHOT_SUFFIX` (default `.reader`). For every built page, runs **@mozilla/readability** (the Firefox/Safari Reader engine, via `linkedom` — headless, no browser) and writes a clean reader **`<page>.reader.html`** + an analysis-friendly **`<page>.reader.md`** (YAML front-matter + Markdown via `turndown`). The Markdown is the durable, diffable twin of the page — far easier to run NLP/LLM analysis over than scraping live HTML — and doubles as the AI-readable Markdown sibling. (The printed/PDF view needs a print-CSS renderer and is a separate generator.) |\n| `gen-print-snapshots.mjs` | `node …/gen-print-snapshots.mjs [distDir]` | `$PRINT_DIST` (default `dist`). Optional `$PRINT_PAGES`, `$PRINT_RENDERER` (default `tezcatl`, or a `\"cmd {url} {out}\"` template), `$PRINT_WAIT` (default `600`), `$PRINT_SUFFIX` (default `.print`). The print/PDF twin of `gen-snapshots`: serves `dist` over an ephemeral origin (so assets resolve) and renders each page's `@media print` view to **`<page>.print.pdf`** via **tezcatl** (macOS-native WebKit — no Chromium). A LOCAL / macOS-deploy artifact: on a host without the renderer (e.g. a Linux CI runner) it **SKIPS** with a note. |\n| `openapi.mjs` | `import { sortKeys, writeApiFile, embedSchema, jsonResponse, validateOpenapi }` | The **generic core** of a static-API generator. The per-endpoint projection of a site's contracts (profile/posts/corpus/VC, etc.) stays in the site's build; this module provides deterministic JSON output, schema embedding, and OpenAPI 3.1/3.2 well-formedness validation. Pair with `lib/schema-validate.mjs` to self-check emitted docs. |\n\n### emitters/\n\n`import { reprDigest, securityTxt, securityTxtExpires, webManifest, markdownSiblingHeaders } from \"…/emitters/index.mjs\"` — pure helpers a site's own `build.mjs` calls to emit standards-compliant artifacts (RFC 9530 `Repr-Digest`, RFC 9116 `security.txt`, the W3C web app manifest, the `_headers` Content-Type rules for `.md` siblings). All values injected; the page **content** stays in the site.\n\n## `@bounded-systems/verify` (vendored here; published elsewhere)\n\nThe in-process Sigstore verifier (`integrity/verify/verify.mjs`) is **vendored** in\nthis kit so sites can pull it into a hermetic build. It is no longer **published**\nfrom here: the canonical home of the [`@bounded-systems/verify`](https://jsr.io/@bounded-systems/verify)\nJSR package is now its own repo,\n[`bounded-systems/verify`](https://github.com/bounded-systems/verify). That repo owns\nthe package manifest (`deno.json`) and the keyless-OIDC release workflow; cut releases\nthere. The copy here is kept byte-for-byte in sync with the published source.\n\nConsumers run it straight from JSR:\n\n```sh\ndeno run -A jsr:@bounded-systems/verify https://your-site\n```\n\n## Releasing\n\nVersioning is owned by [@bounded-systems/mint](https://github.com/bounded-systems/mint) —\n**intent files in, signed release out** — replacing the old hand-edited\n`package.json` version + `publish`-branch fast-forward.\n\n1. **Per PR** — drop one intent in [`.release/`](.release/README.md):\n\n   ```markdown\n   ---\n   bump: minor   # patch | minor | major\n   ---\n   short summary of the change (becomes the changelog line)\n   ```\n\n   The `version` CI job (`mint plan`, pinned to a mint SHA) validates every intent\n   and previews the next version on each PR; it fails closed on a malformed one.\n\n2. **Cut a release** — on `main`:\n\n   ```sh\n   mint version   # bump package.json (+ lockfile), prepend CHANGELOG.md, consume intents\n   mint release   # cut the signed v<version> tag (CI keyless-signs the provenance)\n   ```\n\nThe `v<version>` tag then drives **two** independent jobs:\n\n- **`publish.yml`** — publishes `@bounded-systems/conformance-kit` to npm via OIDC\n  trusted publishing (unchanged; mint owns version + tag, not the registry push).\n- **`release.yml`** — calls mint's reusable `release-provenance.yml`: emits the\n  deterministic in-toto release Statement (tag → version plan → commit),\n  keyless-signs it (cosign/OIDC), and attaches it to the GitHub release. Verify\n  with `cosign verify-blob` — the same bundle `@bounded-systems/verify` consumes.\n\n> Migration: the `publish` branch / manual `package.json` bump is retired. The tag\n> `mint release` cuts is now the single release trigger.\n\n## Test\n\n```\nnpm install && npm test    # cases against fixtures/, in isolation\n```\n\nThe suite verifies the generic logic end-to-end: gen-sbom against a sample lockfile;\nshacl-runner against sample shapes+HTML → `conforms: true`; structure-audit / seo /\nreadability / commonmark against sample inputs; gen-sitemanifest + gen-cid + verify-site\nround-trip on a sample build; gen-identity; the emitter/openapi/schema helpers; the\nconformance projection; and the **axe-gate** (its classification/threshold/report logic\ndeterministically, plus a real end-to-end pass on the known-bad + known-good\n`fixtures/axe/` snippets when a browser engine — tezcatl or Playwright/Chromium — is on\nPATH; skipped, like the cosign step, when none is). (The Deno semantic runner is\nexercised by the consuming site, as it needs Deno + JSR.)\n\n## Provenance / determinism\n\nThe gates are pure functions of the built output; the generators are deterministic\nfunctions of their inputs (the SBOM creation date is derived from `flake.lock`, never\na wall clock; the CID re-derives from the served bytes with any IPFS implementation).\nSite-specific artifacts — SHACL shapes, the prose corpus, the markdown renderer,\nthresholds, copy, and `build.mjs` itself — are inputs, never part of the kit.\n","readmeFilename":"README.md"}