{"_id":"@brokkai/release-bot-linux-arm64","_rev":"10-fdf07be0413dada805ff8d16614c95a7","name":"@brokkai/release-bot-linux-arm64","dist-tags":{"latest":"0.8.2"},"versions":{"0.2.0":{"name":"@brokkai/release-bot-linux-arm64","version":"0.2.0","license":"Apache-2.0","_id":"@brokkai/release-bot-linux-arm64@0.2.0","maintainers":[{"name":"bigslopdave","email":"david@brokk.ai"},{"name":"foundev","email":"tech@foundev.pro"}],"homepage":"https://github.com/BrokkAi/release-bot#readme","bugs":{"url":"https://github.com/BrokkAi/release-bot/issues"},"os":["linux"],"cpu":["arm64"],"dist":{"shasum":"c2b10633b1f7df09a545832c684faa2786a4cdde","tarball":"https://registry.npmjs.org/@brokkai/release-bot-linux-arm64/-/release-bot-linux-arm64-0.2.0.tgz","fileCount":5,"integrity":"sha512-Uzm63LJLhWVGBhZ4ZA9zIcfLteta+mQCi4er3Ot2pyno14Njw9gGAqZQzhx0ZvYlTvo9Kn7tQULrJiV+BmX6Hg==","signatures":[{"sig":"MEQCIENtX3Kwf13R8bY8TyWQRKknMpMmbY6VmxjkabrZPrqeAiBMPshw19Iy4uJqs6jEYgn7wBeOvBLkjvJ1wJ/HiU+cEg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":3769912},"_from":"file:/tmp/brb-npm-v0.2.0/packages/npm/brokkai-release-bot-linux-arm64-0.2.0.tgz","_npmUser":{"name":"foundev","email":"tech@foundev.pro"},"_resolved":"/tmp/brb-npm-v0.2.0/packages/npm/brokkai-release-bot-linux-arm64-0.2.0.tgz","_integrity":"sha512-Uzm63LJLhWVGBhZ4ZA9zIcfLteta+mQCi4er3Ot2pyno14Njw9gGAqZQzhx0ZvYlTvo9Kn7tQULrJiV+BmX6Hg==","repository":{"url":"git+https://github.com/BrokkAi/release-bot.git","type":"git"},"_npmVersion":"11.17.0","description":"Brokk Release Bot native binary for linux/arm64","directories":{},"_nodeVersion":"24.19.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/release-bot-linux-arm64_0.2.0_1788794950697_0.4096255463100644","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@brokkai/release-bot-linux-arm64","version":"0.3.0","license":"Apache-2.0","_id":"@brokkai/release-bot-linux-arm64@0.3.0","maintainers":[{"name":"bigslopdave","email":"david@brokk.ai"},{"name":"foundev","email":"tech@foundev.pro"}],"homepage":"https://github.com/BrokkAi/release-bot#readme","bugs":{"url":"https://github.com/BrokkAi/release-bot/issues"},"os":["linux"],"cpu":["arm64"],"dist":{"shasum":"5437e92f5d5c92de62b5d41f51b315daed1af9db","tarball":"https://registry.npmjs.org/@brokkai/release-bot-linux-arm64/-/release-bot-linux-arm64-0.3.0.tgz","fileCount":5,"integrity":"sha512-wv829Bjd/ZJDIUFiu1PqYOsZYbq+7NWuB3aYuDgBaXh/lcjOXcjAhsBywfbKluCpdR9kH0pu7kIffSahhTKqYA==","signatures":[{"sig":"MEUCIHKdBlJ2gInGcBFI/jU+R/KBWV4aAyOe36bDy5swzmuKAiEAstWhdh2siVL6ydceH5v4BQCYERoo4R3dzjW2NJlL3DU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQCHrIq28oyFmRBT+4fn3S2tL0z0cUVsFz9+cW2pYNDn8QIgJfTLXhJvmaTykvBaAAdP4U8+rjJwMmZI0FeK69fXHmA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brokkai%2frelease-bot-linux-arm64@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3836930},"_from":"file:/home/runner/work/release-bot/release-bot/dist/packages/npm/brokkai-release-bot-linux-arm64-0.3.0.tgz","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d2854226-e4a1-4ff6-b906-d9a30a5abbbc"}},"_resolved":"/home/runner/work/release-bot/release-bot/dist/packages/npm/brokkai-release-bot-linux-arm64-0.3.0.tgz","_integrity":"sha512-wv829Bjd/ZJDIUFiu1PqYOsZYbq+7NWuB3aYuDgBaXh/lcjOXcjAhsBywfbKluCpdR9kH0pu7kIffSahhTKqYA==","repository":{"url":"git+https://github.com/BrokkAi/release-bot.git","type":"git"},"_npmVersion":"11.19.0","description":"Brokk Release Bot native binary for linux/arm64","directories":{},"_nodeVersion":"24.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/release-bot-linux-arm64_0.3.0_1788797722392_0.3242942159198259","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@brokkai/release-bot-linux-arm64","version":"0.3.1","license":"Apache-2.0","_id":"@brokkai/release-bot-linux-arm64@0.3.1","maintainers":[{"name":"bigslopdave","email":"david@brokk.ai"},{"name":"foundev","email":"tech@foundev.pro"}],"homepage":"https://github.com/BrokkAi/release-bot#readme","bugs":{"url":"https://github.com/BrokkAi/release-bot/issues"},"os":["linux"],"cpu":["arm64"],"dist":{"shasum":"185d8591f134f28cda5131904c70da5c177a8f6c","tarball":"https://registry.npmjs.org/@brokkai/release-bot-linux-arm64/-/release-bot-linux-arm64-0.3.1.tgz","fileCount":5,"integrity":"sha512-rIKkfHhPTprWpF61Xq/Wg1/dkom7K23gdXExgrLo4DLeTiou8F9jgaPvsw1hBMmoGzAjcWfZDoAJ2ce/gx2JeA==","signatures":[{"sig":"MEQCIFQ20Gues8ao+cyTDi0Hv7b0ev9ZY4VeXOHl8JMQqHMXAiACWdnmUpmK7iw41fqI2PUfee1VcEBU663jI32yyY8PwA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIDAC6abXFcxxVzKwSsNcSb4D9fO7yUEtDt0bMjw+Yys9AiEAxhMuYaeXYbS3eOyMrtOjWBn3s/lOeaaE0hJsazD3uro=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brokkai%2frelease-bot-linux-arm64@0.3.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":3903337},"_from":"file:/home/runner/work/release-bot/release-bot/dist/packages/npm/brokkai-release-bot-linux-arm64-0.3.1.tgz","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d2854226-e4a1-4ff6-b906-d9a30a5abbbc"}},"_resolved":"/home/runner/work/release-bot/release-bot/dist/packages/npm/brokkai-release-bot-linux-arm64-0.3.1.tgz","_integrity":"sha512-rIKkfHhPTprWpF61Xq/Wg1/dkom7K23gdXExgrLo4DLeTiou8F9jgaPvsw1hBMmoGzAjcWfZDoAJ2ce/gx2JeA==","repository":{"url":"git+https://github.com/BrokkAi/release-bot.git","type":"git"},"_npmVersion":"11.19.0","description":"Brokk Release Bot native binary for linux/arm64","directories":{},"_nodeVersion":"24.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/release-bot-linux-arm64_0.3.1_1788852372483_0.08512404601585866","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@brokkai/release-bot-linux-arm64","version":"0.4.0","license":"Apache-2.0","_id":"@brokkai/release-bot-linux-arm64@0.4.0","maintainers":[{"name":"bigslopdave","email":"david@brokk.ai"},{"name":"foundev","email":"tech@foundev.pro"}],"homepage":"https://github.com/BrokkAi/release-bot#readme","bugs":{"url":"https://github.com/BrokkAi/release-bot/issues"},"os":["linux"],"cpu":["arm64"],"dist":{"shasum":"d3e538d9ca704b34f7514a10da77102bfeb98430","tarball":"https://registry.npmjs.org/@brokkai/release-bot-linux-arm64/-/release-bot-linux-arm64-0.4.0.tgz","fileCount":5,"integrity":"sha512-gb6Oyjo5z+CWVa73wBNan3LnR4JMfuyWjpJ4CVWrC0tIJgk/K85AJb+G3EjCCyKGd96ju7IWDQu8rDkDE1hrAQ==","signatures":[{"sig":"MEUCIQCMeR9I+cR0PBHBqkIiBwBxhY5m8gW9auKYuAk4BEUZRAIgGuR0Q6kOC1hEFr3rMaoh5R64z0mglKEwaPq2O+6F2og=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIGnAD6O/nP5jwhESc+xDKEiWTrZDOpD+rsDLzbx7rpuAAiAOAQ1vqVLfHrr5g1iRAyRGMFk+xIUjj95mamsMIB4CSQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brokkai%2frelease-bot-linux-arm64@0.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":4232984},"_from":"file:/home/runner/work/release-bot/release-bot/dist/packages/npm/brokkai-release-bot-linux-arm64-0.4.0.tgz","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d2854226-e4a1-4ff6-b906-d9a30a5abbbc"}},"_resolved":"/home/runner/work/release-bot/release-bot/dist/packages/npm/brokkai-release-bot-linux-arm64-0.4.0.tgz","_integrity":"sha512-gb6Oyjo5z+CWVa73wBNan3LnR4JMfuyWjpJ4CVWrC0tIJgk/K85AJb+G3EjCCyKGd96ju7IWDQu8rDkDE1hrAQ==","repository":{"url":"git+https://github.com/BrokkAi/release-bot.git","type":"git"},"_npmVersion":"11.19.0","description":"Brokk Release Bot native binary for linux/arm64","directories":{},"_nodeVersion":"24.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/release-bot-linux-arm64_0.4.0_1788860506060_0.876005944130279","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@brokkai/release-bot-linux-arm64","version":"0.5.0","license":"Apache-2.0","_id":"@brokkai/release-bot-linux-arm64@0.5.0","maintainers":[{"name":"jbellis","email":"jbellis@gmail.com"},{"name":"bigslopdave","email":"david@brokk.ai"},{"name":"foundev","email":"tech@foundev.pro"}],"homepage":"https://github.com/BrokkAi/release-bot#readme","bugs":{"url":"https://github.com/BrokkAi/release-bot/issues"},"os":["linux"],"cpu":["arm64"],"dist":{"shasum":"aa121be69f9f83a299129b205275fa90a846d8b8","tarball":"https://registry.npmjs.org/@brokkai/release-bot-linux-arm64/-/release-bot-linux-arm64-0.5.0.tgz","fileCount":7,"integrity":"sha512-lVSSvO6WyFeenay9y12vxaBxc95Ebc9ZnYsuXoZ0JawB8PqDsESfs9hvPaLC0nVmpfbHWRbPC/eIY6sqt6UqcQ==","signatures":[{"sig":"MEYCIQDRlYoGBx9mi60NLf40SeapjL8/mPPtNCLbnfbGoDAmXgIhANdrONe+gQx6yDPK0aStrKc8FQXlZFLOoEmGSX70zYOp","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIAP3HT5eFLq7ynCZNhSszGL4/dyUAD5gkH5qT+qGGTLGAiEAvY/TlBAlzrgWgwxDiNSx53usXbrCM35i8zS8yLlLrps=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brokkai%2frelease-bot-linux-arm64@0.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7471004},"_from":"file:/home/runner/work/release-bot/release-bot/dist/packages/npm/brokkai-release-bot-linux-arm64-0.5.0.tgz","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d2854226-e4a1-4ff6-b906-d9a30a5abbbc"}},"_resolved":"/home/runner/work/release-bot/release-bot/dist/packages/npm/brokkai-release-bot-linux-arm64-0.5.0.tgz","_integrity":"sha512-lVSSvO6WyFeenay9y12vxaBxc95Ebc9ZnYsuXoZ0JawB8PqDsESfs9hvPaLC0nVmpfbHWRbPC/eIY6sqt6UqcQ==","repository":{"url":"git+https://github.com/BrokkAi/release-bot.git","type":"git"},"_npmVersion":"11.19.0","description":"Brokk Release Bot native binary for linux/arm64","directories":{},"_nodeVersion":"24.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/release-bot-linux-arm64_0.5.0_1789375117597_0.953934540524769","host":"s3://npm-registry-packages-npm-production"}},"0.5.1":{"name":"@brokkai/release-bot-linux-arm64","version":"0.5.1","license":"Apache-2.0","_id":"@brokkai/release-bot-linux-arm64@0.5.1","maintainers":[{"name":"jbellis","email":"jbellis@gmail.com"},{"name":"bigslopdave","email":"david@brokk.ai"},{"name":"foundev","email":"tech@foundev.pro"}],"homepage":"https://github.com/BrokkAi/release-bot#readme","bugs":{"url":"https://github.com/BrokkAi/release-bot/issues"},"os":["linux"],"cpu":["arm64"],"dist":{"shasum":"36e162f06ee83388fc526e2d042e38d041f00634","tarball":"https://registry.npmjs.org/@brokkai/release-bot-linux-arm64/-/release-bot-linux-arm64-0.5.1.tgz","fileCount":7,"integrity":"sha512-QOnCi1dVcHtuQmVwIKO0Rwykf9DNT+EXo0W7mnV5BAoYjBHVQIDDORyClKvx4PzS0E6eeD/HJzEQMKJXhrDrDA==","signatures":[{"sig":"MEYCIQDCW6o/iVIEcm+BmzcdpmOH7iqPOG10ZybNSnUsFSEA8QIhAPa+Ceu7WMQ1mzhzpGM2IxbSHR/xaOAWPlZgAjyLPyb8","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQDfwC+VsqMsgeZXoHDJEFfYKNrm9pfrMbOBxnLb1c/vbwIhANd0YO8q78WT2jtFdkL8rGr+swAChBn2Icm4wdKI3Tp1","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brokkai%2frelease-bot-linux-arm64@0.5.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7471004},"_from":"file:/home/runner/work/release-bot/release-bot/dist/packages/npm/brokkai-release-bot-linux-arm64-0.5.1.tgz","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d2854226-e4a1-4ff6-b906-d9a30a5abbbc"}},"_resolved":"/home/runner/work/release-bot/release-bot/dist/packages/npm/brokkai-release-bot-linux-arm64-0.5.1.tgz","_integrity":"sha512-QOnCi1dVcHtuQmVwIKO0Rwykf9DNT+EXo0W7mnV5BAoYjBHVQIDDORyClKvx4PzS0E6eeD/HJzEQMKJXhrDrDA==","repository":{"url":"git+https://github.com/BrokkAi/release-bot.git","type":"git"},"_npmVersion":"11.19.0","description":"Brokk Release Bot native binary for linux/arm64","directories":{},"_nodeVersion":"24.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/release-bot-linux-arm64_0.5.1_1789377401867_0.37847610506938856","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@brokkai/release-bot-linux-arm64","version":"0.6.0","license":"Apache-2.0","_id":"@brokkai/release-bot-linux-arm64@0.6.0","maintainers":[{"name":"jbellis","email":"jbellis@gmail.com"},{"name":"bigslopdave","email":"david@brokk.ai"},{"name":"foundev","email":"tech@foundev.pro"}],"homepage":"https://github.com/BrokkAi/release-bot#readme","bugs":{"url":"https://github.com/BrokkAi/release-bot/issues"},"os":["linux"],"cpu":["arm64"],"dist":{"shasum":"3a86540b2337f894effd3b0dea413bf314342682","tarball":"https://registry.npmjs.org/@brokkai/release-bot-linux-arm64/-/release-bot-linux-arm64-0.6.0.tgz","fileCount":7,"integrity":"sha512-2dK8GdAGrrXsupNGJnD+kHzjmdNphYBvFyFFhnYKNb/udws60QcvzTjGAJiwUQy/y4ORMkExHQ50JPcc8ZSmLA==","signatures":[{"sig":"MEQCIC2eugKxA1ONPs8pvGfM8aCYhxRseUv8KcGzZROHJlwcAiBmlJ5o70nUimnG7zBGlFJY3g+8WJxSaYRR8LzhPL0qIg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQDWa7c1T0+nAyuJ+/O17zNRKV0MNyyf0FNjnjhqbNJQIQIgB1fBIQLTI3g8U4s9foNbMhzAu6+ghMSh687nB+prF2o=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brokkai%2frelease-bot-linux-arm64@0.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7473153},"_from":"file:/home/runner/work/release-bot/release-bot/dist/packages/npm/brokkai-release-bot-linux-arm64-0.6.0.tgz","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d2854226-e4a1-4ff6-b906-d9a30a5abbbc"}},"_resolved":"/home/runner/work/release-bot/release-bot/dist/packages/npm/brokkai-release-bot-linux-arm64-0.6.0.tgz","_integrity":"sha512-2dK8GdAGrrXsupNGJnD+kHzjmdNphYBvFyFFhnYKNb/udws60QcvzTjGAJiwUQy/y4ORMkExHQ50JPcc8ZSmLA==","repository":{"url":"git+https://github.com/BrokkAi/release-bot.git","type":"git"},"_npmVersion":"11.19.0","description":"Brokk Release Bot native binary for linux/arm64","directories":{},"_nodeVersion":"24.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/release-bot-linux-arm64_0.6.0_1789475653851_0.47778675634001955","host":"s3://npm-registry-packages-npm-production"}},"0.6.1":{"name":"@brokkai/release-bot-linux-arm64","version":"0.6.1","license":"Apache-2.0","_id":"@brokkai/release-bot-linux-arm64@0.6.1","maintainers":[{"name":"jbellis","email":"jbellis@gmail.com"},{"name":"bigslopdave","email":"david@brokk.ai"},{"name":"foundev","email":"tech@foundev.pro"}],"homepage":"https://github.com/BrokkAi/release-bot#readme","bugs":{"url":"https://github.com/BrokkAi/release-bot/issues"},"os":["linux"],"cpu":["arm64"],"dist":{"shasum":"38a2a9a2e29cc3294b531a2552f3eb808c0a1b8b","tarball":"https://registry.npmjs.org/@brokkai/release-bot-linux-arm64/-/release-bot-linux-arm64-0.6.1.tgz","fileCount":7,"integrity":"sha512-QSRKATa0mpbWLk9dQsYVhxcXqm0myxay35fgebV41nXS1NTuVYxLtbJ2aiFdcELyWiVAkd5edHSySMRnSupJ8w==","signatures":[{"sig":"MEUCIQCrkydYVdGqOBJ7lPhgcU6oeJ72omT4RxHI9LboWOPKZQIgBStvbAmIhYc/lB1T0VxtFbPYH85Fp02G6G7ynZ6O3PY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIDsN3lhmAZok4XwSp8jB1vLTk0qqowRT66/9RhypzTAsAiBzg6zTvAvV1mvMbL/zsmV9mKSZjJw+4q1y2XG0dgq5ow==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brokkai%2frelease-bot-linux-arm64@0.6.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7670481},"_from":"file:/home/runner/work/release-bot/release-bot/dist/packages/npm/brokkai-release-bot-linux-arm64-0.6.1.tgz","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d2854226-e4a1-4ff6-b906-d9a30a5abbbc"}},"_resolved":"/home/runner/work/release-bot/release-bot/dist/packages/npm/brokkai-release-bot-linux-arm64-0.6.1.tgz","_integrity":"sha512-QSRKATa0mpbWLk9dQsYVhxcXqm0myxay35fgebV41nXS1NTuVYxLtbJ2aiFdcELyWiVAkd5edHSySMRnSupJ8w==","repository":{"url":"git+https://github.com/BrokkAi/release-bot.git","type":"git"},"_npmVersion":"11.19.0","description":"Brokk Release Bot native binary for linux/arm64","directories":{},"_nodeVersion":"24.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/release-bot-linux-arm64_0.6.1_1789478837077_0.20596308625681314","host":"s3://npm-registry-packages-npm-production"}},"0.8.2":{"os":["linux"],"_id":"@brokkai/release-bot-linux-arm64@0.8.2","cpu":["arm64"],"bugs":{"url":"https://github.com/BrokkAi/brokk-town/issues"},"dist":{"shasum":"70b32e123bb91f22de307fe7a7af0d86ca2f97c8","tarball":"https://registry.npmjs.org/@brokkai/release-bot-linux-arm64/-/release-bot-linux-arm64-0.8.2.tgz","fileCount":7,"integrity":"sha512-GE1e5RscN5VY7v1BZxUhwVZJQsKvAPjbm7BvhgJJxs9VckZzzLWFJnLXhsixMn8gMR3JZLCLqX+nXWRdyE6+Sg==","signatures":[{"sig":"MEQCIDGU0jRTjPnii3GzL4AiJROlIbTbaBDAr+yiwJKsObjHAiAdCmsJY6A/vjJ2NzS5B1kyxFWga6R2UR2+aE32xRkILQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQD6ygDi5PDcXYkoEcUxfvcDtUeNxo96yldy/YpVHetWGgIgGLXuFKMqpWRt9nU0W2kZtCX71/N1zGDp6ANr07ICIeE="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@brokkai%2frelease-bot-linux-arm64@0.8.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":7677475},"name":"@brokkai/release-bot-linux-arm64","_from":"file:/home/runner/work/brokk-town/brokk-town/bots/release-bot/dist/release/packages/npm/brokkai-release-bot-linux-arm64-0.8.2.tgz","license":"Apache-2.0","version":"0.8.2","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:55eacdb3-5359-4305-aa8e-4d4950db4493"}},"homepage":"https://github.com/BrokkAi/brokk-town#readme","_resolved":"/home/runner/work/brokk-town/brokk-town/bots/release-bot/dist/release/packages/npm/brokkai-release-bot-linux-arm64-0.8.2.tgz","_integrity":"sha512-GE1e5RscN5VY7v1BZxUhwVZJQsKvAPjbm7BvhgJJxs9VckZzzLWFJnLXhsixMn8gMR3JZLCLqX+nXWRdyE6+Sg==","repository":{"url":"git+https://github.com/BrokkAi/brokk-town.git","type":"git"},"_npmVersion":"11.19.0","description":"Brokk Release Bot native binary for linux/arm64","directories":{},"maintainers":[{"name":"jbellis","email":"jbellis@gmail.com"},{"name":"bigslopdave","email":"david@brokk.ai"},{"name":"foundev","email":"tech@foundev.pro"}],"_nodeVersion":"24.21.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/release-bot-linux-arm64_0.8.2_1790417457852_0.12406959291758346"}}},"time":{"created":"2026-09-07T15:29:10.567Z","modified":"2026-09-26T10:10:58.395Z","0.2.0":"2026-09-07T15:29:10.832Z","0.3.0":"2026-09-07T16:15:22.584Z","0.3.1":"2026-09-08T07:26:12.596Z","0.4.0":"2026-09-08T09:41:46.232Z","0.5.0":"2026-09-14T08:38:37.763Z","0.5.1":"2026-09-14T09:16:42.015Z","0.6.0":"2026-09-15T12:34:14.042Z","0.6.1":"2026-09-15T13:27:17.285Z","0.8.2":"2026-09-26T10:10:58.023Z"},"bugs":{"url":"https://github.com/BrokkAi/brokk-town/issues"},"license":"Apache-2.0","homepage":"https://github.com/BrokkAi/brokk-town#readme","repository":{"url":"git+https://github.com/BrokkAi/brokk-town.git","type":"git"},"description":"Brokk Release Bot native binary for linux/arm64","maintainers":[{"name":"jbellis","email":"jbellis@gmail.com"},{"name":"bigslopdave","email":"david@brokk.ai"},{"name":"foundev","email":"tech@foundev.pro"}],"readme":"# Brokk Release Bot\n\nThis standalone project now lives in [`BrokkAi/brokk-town/bots/release-bot`](https://github.com/BrokkAi/brokk-town/tree/master/bots/release-bot). Build and test from this directory; see [RELEASING.md](RELEASING.md) for its independent suffix-tag releases.\n\nAn autonomous release daemon in Go. It monitors one repository, drives a configurable coding agent over Agent Client Protocol (ACP), and verifies publication before recording a successful release. Codex through `codex-acp` is the default agent.\n\nThe bot uses the shared [acp-go](https://github.com/BrokkAi/acp-go) module for ACP v1 transport, process/session lifecycle, client filesystem and terminal tools, transcripts, and model/effort selection. The library was extracted from this project and is also used by [issue-bot](https://github.com/BrokkAi/issue-bot). It uses only Go's standard library and includes types generated from the official ACP JSON Schemas. This project has no HTTP server.\n\n## Install\n\nThe command is **`brb`**. Choose one installation method; supported platforms are Linux and macOS on amd64 and arm64.\n\n**Go** (Go 1.27.1 or newer):\n\n```sh\ngo install github.com/BrokkAi/release-bot/cmd/brb@latest\n```\n\nGo installs `brb` into `GOBIN`, or `$(go env GOPATH)/bin` by default. Add that directory to your `PATH`. Replace `@latest` with a release tag such as `@v0.2.0` to pin a version. See the [Go installation reference](https://go.dev/ref/mod#go-install). From a source checkout, use `go install ./cmd/brb`, or `make build` to produce `bin/brb`.\n\n**curl** (prebuilt binary, no Go required):\n\n```sh\ncurl -fsSL https://raw.githubusercontent.com/BrokkAi/release-bot/master/install.sh | sh\nexport PATH=\"$HOME/.local/bin:$PATH\"\n```\n\nThe installer downloads the latest stable GitHub release, verifies its SHA-256 checksum, and installs `brb` in `~/.local/bin`. Add the PATH line to your shell profile to keep it across sessions. Rerun to upgrade. To select a release and destination:\n\n```sh\ncurl -fsSL https://raw.githubusercontent.com/BrokkAi/release-bot/master/install.sh | INSTALL_DIR=\"$HOME/.local/bin\" sh -s -- v0.2.0\n```\n\n**npm** (Node.js 18 or newer; [published package](https://www.npmjs.com/package/@brokkai/release-bot)):\n\n```sh\nnpm install -g @brokkai/release-bot\nbrb --help\n```\n\nThe npm package installs the matching native binary through an optional platform dependency. Keep optional dependencies enabled. For a one-off invocation, use `npx --yes @brokkai/release-bot --help`. Rerun the install command with `@latest` to upgrade, or append a version such as `@0.2.0` to pin it.\n\n**uv** (Python 3.10 or newer; PyPI publication pending):\n\nUse Go, curl, or npm for now. Once the first PyPI release is published:\n\n```sh\nuv tool install brokk-release-bot\nbrb --help\n```\n\nFor a one-off invocation, use `uvx --from brokk-release-bot brb --help`. The Python package downloads its exact native release on first use and checks archive and binary hashes embedded in the package. Later launches use the verified cache under `$XDG_CACHE_HOME/brokk-release-bot` or `~/.cache/brokk-release-bot`; `BROKK_RELEASE_BOT_CACHE_DIR` overrides it. Use `uv tool upgrade brokk-release-bot` to upgrade, or install `brokk-release-bot==0.2.0` to pin it. Run `uv tool update-shell` if the tool directory is missing from your PATH.\n\nGo, curl, and npm installation are available now. See [RELEASING.md](RELEASING.md) for release procedures, npm trusted publishing, and the remaining PyPI publisher setup.\n\n## Run\n\nStart it in the repository you want released:\n\n```sh\ncd /path/to/your-repo\nbrb\n```\n\nNo configuration file is needed. The bot detects `origin` (or the only remote) and the repository's default branch, sets up its own checkout, and starts checking for releases. It works from subdirectories too. The agent reads the repository's instructions and discovers release workflows, destinations and publishability checks. Your existing working tree and uncommitted edits are left alone; releases use the remote branch's committed history.\n\nIf the repository has no release process, the agent is instructed to create it: build/package scripts, GitHub CI and release workflows, publishability checks, and `RELEASING.md`. It commits the setup, runs non-publishing validation, repairs failures, and then attempts the first release. Missing credentials or account permissions produce a specific blocked report before publication; missing workflows alone do not require manual setup.\n\nYou can also point it at a repository directly:\n\n```sh\nbrb /path/to/repo\nbrb https://github.com/OWNER/REPO.git\nbrb --branch main --once\nbrb --agent your-acp-agent --agent-arg=--stdio\nbrb --model YOUR_MODEL_ID\nbrb --model YOUR_MODEL_ID --effort low\nbrb status\nbrb version\n```\n\n`--once` performs one scheduled check or recovery attempt and exits. It can publish a release. `--once --force` skips cadence checks but still requires new commits. `status` shows progress without launching an agent. `retry` resets the pending release's attempt budget and resumes work; stop an already-running daemon before using it. Brokk Town lifts the same budget through the worker service's `POST /v1/retry` call. Existing `run` and `once` subcommands also work. Flags can appear before or after the repository argument. Use `--help` for options.\n\n`brb version` prints the embedded release tag. Local builds report `dev`; binaries installed with `go install ...@version` report the module version.\n\nThe default workspace lives under `$XDG_STATE_HOME/release-bot` or `~/.local/state/release-bot`, with separate checkout/state directories keyed by remote and branch. New workspaces use a Git worktree backed by the bot's own bare repository at `state/repository.git`. Your checkout and other bots' worktrees do not share its index, local branches, tags or Git configuration. Existing managed clones continue working in place, including unfinished jobs.\n\nEach new release starts on a unique `brb/release-...` branch. The preparation agent makes its fixes there, opens or reuses that job's PR, incorporates concurrent changes from the watched `master`/`main` branch, resolves conflicts, and follows the PR through merge. It then checks out the exact merged commit in its private worktree for validation and publication. Changes other bots push during publication remain eligible for the next release. The bot never resets another checkout or another bot's branch. Overlapping code changes can still require PR conflict resolution or human review; workspace isolation prevents local interference.\n\nYou can leave `brb` running in the background while other bots work. Restarting reuses the workspace and pending PR/job, including unfinished edits. The checkout and state directories are locked against duplicate local daemons, and the OS releases locks after crashes. Run only one release bot per remote/branch across machines; there is no distributed lock. A manually configured directory must be a standalone clone or this bot's private worktree, not a linked worktree sharing another repository's Git metadata.\n\n## Terminal dashboard\n\nInteractive runs show the same live dashboard as bug-bot. It fits the current\nterminal or tmux pane and adjusts when resized. Each pane runs one repository.\n\n```sh\nbrb /path/to/repo           # live dashboard\nbrb /path/to/repo --plain   # scrolling logs and agent transcript\nbrb /path/to/repo --json    # structured logs\n```\n\nThe overview shows the repository, branch and commit, preparation/validation/\npublication/verification stage, active tool, uptime, attempt budget, and next\npoll countdown. Larger panes also show model, reasoning effort, and unreleased\nand recent commit counts from the latest cadence check.\n\nThe release browser shows the last verified receipt and the pending job. Details\ninclude the prepared commit and tag, destinations, validation evidence,\nworkflows, attempt budget, failures, retry eligibility, and publication link.\nA receipt remains pending until independent verification succeeds. Run counters\ntrack releases verified during this invocation, attempts, agent starts, tools,\nand error log events; they are not lifetime release totals.\n\n- `1`, `2`, `3` or `Tab`: switch overview, releases, and activity.\n- `↑` / `↓` or `k` / `j`: browse results or scroll activity.\n- `Enter`: inspect the selected result. `Esc`: return to the list.\n- `Page Up` / `Page Down`: scroll details. `g` / `G`: jump to start/end;\n  `G` resumes following live activity.\n- `q` or `Ctrl+C`: stop the bot and its agent, save progress, and restore the terminal.\n\nActivity keeps recent output; full agent transcripts remain in the state\ndirectory. On exit, a summary and changed result links stay in the terminal.\n`once` exits when its check or attempt finishes.\n\nPiped input, redirected stderr, and `TERM=dumb` automatically use scrolling\noutput. `--plain` and `--json` disable the dashboard and are mutually exclusive.\n`NO_COLOR` disables colors. `status`, `version`, and help retain their existing\noutput and never open the dashboard.\n\n## Local release history\n\n`brb history` lists the latest 100 bot-verified receipts, oldest verification\nfirst. Equal timestamps sort by tag, then commit; unknown legacy times appear\nfirst. Use `brb history --tag v1.2.3` for the exact commit, publication URL and\nsaved destination plan, including versions, publishing environments, check\ncommands, agent-supplied evidence and required workflows. All receipts matching\nthe exact tag are returned if different commits used that tag.\n\n```sh\nbrb history --config /path/to/release-bot.json\nbrb history --config /path/to/release-bot.json --tag v1.2.3\nbrb history --config /path/to/release-bot.json --json\n```\n\nJSON output contains `meaning` and a `receipts` array, with each receipt's\n`verified_at` and saved `result`; `--tag` filters that array. An unknown tag is\nan error. With explicit local configuration these commands only read local\nconfiguration and state: they do not launch an agent, query GitHub, run checks\nor modify state. Without configuration, normal repository discovery applies.\n\nReceipts describe historical successful daemon verification, not current\npublication health. Result detail and plan check evidence are agent-supplied\ntext, separate from that recorded verification outcome. These are private local\ndiagnostics, not tamper-proof audit evidence. No live reverification or transcript\narchive is included.\n\nHistory is scoped to the workspace's repository/branch identity, deduplicated\nby tag and commit, and saved atomically with baseline advancement only after\nsuccessful verification (including reconciliation). Partial publication adds no\nreceipt. Older state remains readable: only its available successful LastResult\nis seeded, using its saved release time or explicitly showing an unknown time\n(`verified_at` omitted in JSON). Reading does not persist migration. Older lost\nreceipts cannot be reconstructed. Retain the state directory across restarts;\nreceipts beyond the latest 100 are discarded. The dashboard and `status` still\nshow the last verified receipt and pending job.\n\n## Runtime requirements and optional configuration\n\nRuntime requirements are Linux/macOS, Git, Codex (or another authenticated ACP agent), and `gh` for GitHub repositories. Existing agent, Git and registry credentials are used. If `codex-acp` is installed, the bot uses it. Otherwise it automatically launches the maintained [Codex ACP adapter](https://github.com/agentclientprotocol/codex-acp) through `npx --yes @agentclientprotocol/codex-acp`; Node.js must be installed and the first launch may download the adapter.\n\nAdvanced settings are optional: `brb --config /path/to/release-bot.json` uses an explicit configuration, with paths relative to that file. The [example](release-bot.example.json) shows available settings. A config file is not auto-created or implicitly loaded. Use `--json` for machine-readable logs and status. Explicit agent commands are used exactly as configured.\n\nSelect a model with a flag:\n\n```sh\nbrb --model YOUR_MODEL_ID\n```\n\nThe flag works with Codex and other agents that advertise ACP model selection. The bot selects and confirms it before sending each preparation or publication prompt. Unknown model IDs report the agent's available choices; unsupported selection fails explicitly. Without the flag, the agent's default applies. An optional `agent.model` config value persists the choice; `--model` overrides it.\n\nSet reasoning effort with `--effort low` (or another value advertised by your agent, such as `medium` or `high`). It can be used with or without `--model`. The bot selects effort after the model and confirms it before every preparation or publication prompt. Unsupported effort values report the available choices; agents without effort selection fail explicitly. Omitting the option keeps the agent's configured default. Set `\"effort\": \"low\"` inside the config's `agent` object to persist it; `--effort` overrides that value.\n\n## Cadence and recovery\n\nBy default the bot polls every five minutes and aims to release every 24 hours when there are unreleased commits. It may release earlier after 5 unreleased commits within two hours, provided two hours have elapsed since the last successful release and the branch has been quiet for 15 minutes. The daily deadline ignores the quiet period so continuous commits cannot starve releases. Override the commit threshold at startup with `--burst 3`, for example `./bin/brb --model gpt-5.6-luna --effort xhigh --burst 3`. The flag overrides `burst` in a configuration file; omitting it preserves the configured value. Use `--burst 0` (or configure `burst` as zero) to disable earlier releases.\n\nBetween those rules, the agent decides. When unreleased commits exist but neither the daily deadline nor a commit burst is due, the bot runs a short read-only triage session using the embedded [triage skill](skills/triage.md). The agent inspects the unreleased range and answers whether it contains changes users need promptly, such as security, crash, data-loss or regression fixes, or work the maintainers marked as a hotfix. A \"release\" answer starts a normal release job immediately, with the same publishability gate as any other release; a \"wait\" answer defers to the regular cadence. Triage reassesses after the quiet period whenever the local release head or the watched remote branch head changes, inspects both histories, ignores the minimum gap, and reuses its decision while both heads and the released baseline are unchanged. A failed triage session is retried after `retry_delay` and never blocks the daily deadline; a session that edits the checkout has its decision discarded. Disable it with `--triage=false` or `\"triage\": false`; `triage_timeout` (10 minutes by default) bounds each session.\n\nAdjust the early-release delays with `--minimum-gap 10m --quiet 1m`. Both accept durations such as `30s`, `5m`, or `1h` and override the corresponding configuration values (`minimum_gap` and `quiet`). Set either to `0` to disable that delay. Omitting the flags preserves configured values, or the defaults of two hours and 15 minutes. The commit threshold, burst window, and polling interval still apply.\n\nTo keep changes that are not release deliverables from starting a release, list them in `release_trigger_ignore`. Each entry is a repository-relative path: a literal file (`\"NOTES.md\"` matches only that file at the repository root) or a directory prefix ending in `/` (`\"docs/internal/\"` matches everything below `docs/internal`, but not `docs/internal-api/`). Matching is exact and case-sensitive. A submodule is reported as its bare path, so ignore its bumps with a file entry such as `\"vendor/sub\"`; `\"vendor/sub/\"` does not match it. Globs, absolute paths, backslashes, surrounding whitespace, empty entries and `.` or `..` segments are rejected. The default is empty, because documentation can itself be a deliverable. Before starting a new automatic job, the bot compares the last release with both the watched branch head and the managed checkout's local head; if the combined set of changed paths is nonempty and every path is ignored, it keeps monitoring, reports the reason, and starts neither triage nor preparation, even at the daily deadline or after a commit burst. Deletions count, and a rename counts both its old and new paths, so moving a file across an ignored boundary is release-relevant. Any change outside the ignored paths restores the normal cadence for the whole unreleased range, including the previously deferred commits. The release baseline never moves while changes are deferred. The policy applies only once there is a release with a recorded time; a first release, a pending job's recovery and publication, and a range whose net diff is empty behave as before. A failed Git comparison pauses the check with an error instead of deferring. `--once --force` bypasses the policy but still requires unreleased commits and every publication gate. The setting is only read from a configuration file; Brokk Town does not pass it to the worker.\n\n```json\n\"release_trigger_ignore\": [\"docs/internal/\", \"NOTES.md\"]\n```\n\nStartup checks immediately: if the last release is at least `daily` old (24 hours by default), or there has never been a release, the bot starts release preparation on that first check. It does not wait for a polling interval, a quiet period, or another day after startup. Restarting does not reset the deadline. Existing releases still require unreleased commits, and every attempt must pass publishability checks before publishing.\n\nOn first startup, GitHub repositories use the most recently published release whose tag is reachable from the watched branch as their baseline. Existing release records are trusted for this initial baseline; an arbitrary local tag is not used. `initial_ref` explicitly overrides the baseline. Without an existing release or an explicit baseline, all commits are unreleased and the first check is immediately eligible. Non-GitHub repositories can set `initial_ref` to a known released commit/tag.\n\nA release job records its target before starting the agent. Failed jobs preserve local work and failure evidence, then retry after 15 minutes. Each attempt has a two-hour budget shared by preparation, publishability validation, and publication. After three failed release attempts, the daemon exits with the final failure and leaves the job pending for operator inspection and `retry`. Restarting still reconciles saved publication evidence before enforcing the exhausted budget. A stored publication receipt is rechecked before asking the agent to act again, including after the attempt budget is exhausted. When that recheck fails with exactly the failure recorded by the previous attempt, the next attempt starts with the preparation agent instead of the publisher: an unchanged verification failure after the retry delay needs a source, script or workflow repair, which only preparation may make. Preparation receives the failure as repair context and may keep the same plan or produce a replacement release. If the publisher lost its connection before returning a receipt, the daemon first tries to verify publication directly from the saved publication plan. This can reconcile a release whose asynchronous checks eventually pass.\n\nRecovery instructions tell the agent to inspect existing tags, workflow runs and published artifacts before taking action. There is no atomic transaction spanning Git and external registries, so exactly-once publication cannot be guaranteed after a crash before the agent returns its receipt. Reconciliation reduces this risk. The baseline advances only to the verified tagged commit; later commits remain eligible for the next release.\n\nUnpushed commits in the bot's managed checkout also count as unreleased work, including on topic branches or a detached HEAD. Polling counts both local and remote commits when their histories diverge. When the normal release cadence is due, preparation preserves those commits and, on GitHub, opens or reuses a PR, fixes its checks, and follows it through merge before preparing a new version. The publication gate requires the prepared commit to be on the remote release branch; squash and rebase merges use the resulting commit. Required human approvals remain blockers until satisfied. The bot never force-pushes or overwrites divergent history or unfinished edits. Commits in a separate development checkout are not imported automatically.\n\nRestarting immediately resumes a pending job, even if its saved retry timer has not elapsed. The failure budget still applies to actual failures. Ctrl+C or SIGTERM preserves unfinished work, records the stop reason, and does not consume an attempt or impose a retry delay. Ordinary polling after an actual failure retains the configured backoff until the attempt limit is reached.\n\nAgent setup failures (including an unknown model or unsupported effort) exit immediately before any prompt and do not consume release attempts or impose a retry delay. Correct the command-line/config setting and restart normally; the new invocation supplies the agent settings. Setup errors are recorded separately from release failures. For state saved by older versions, startup recognizes the old unknown-model/effort error and refunds that last setup attempt once, allowing corrected settings to run even if the saved budget was exhausted. Earlier release failures remain counted.\n\n## Outcome notifications\n\nAn optional `notify` command lets an unattended daemon tell an existing desktop notifier or monitoring script when a release is verified or automatic retries have stopped. It is disabled by default and is read only from a configuration file; Brokk Town does not pass it to the worker. `notify_timeout` is required with a command and must be positive.\n\n```json\n\"notify\": [\"/opt/release-checks/notify\", \"--channel\", \"releases\"],\n\"notify_timeout\": \"30s\"\n```\n\nThe command runs directly as an argument array, with no shell expansion, in `state_directory` (outside the managed checkout), with the bot account's OS permissions and environment. It is not a sandbox. A relative command path resolves from `state_directory`; prefer an absolute path. Each invocation receives one JSON object on stdin:\n\n```json\n{\"version\":1,\"event\":\"verified\",\"time\":\"2026-09-23T12:00:00Z\",\"repository\":\"org/repo\",\"branch\":\"master\",\"job\":\"job:brb/release-abc:0123…\",\"release\":\"release:v1.2.0\",\"target\":\"0123…\",\"commit\":\"4567…\",\"tag\":\"v1.2.0\",\"attempts\":1,\"max_attempts\":3}\n```\n\n- `verified` is sent once, after the verified receipt and new baseline are saved, whether the release was just published or reconciled later (including at startup). The hook can read the updated receipt with `brb history --config … --json` or from `state.json` in its working directory. Partial publication sends nothing.\n- `exhausted` is sent once per `run` or `once` invocation, just before the daemon exits because the attempt budget is spent: after the final failed attempt or on startup with an already exhausted pending job whose publication evidence still fails verification. It carries the target commit and, when a plan exists, the prepared commit and tag.\n- Retry backoff, ordinary failures, agent setup errors and Ctrl+C/SIGTERM send nothing.\n\n`repository` is present for GitHub repositories. `job` is stable for a pending release across restarts. The payload omits failure text, command output, transcripts, environment values, configuration and local paths; use `status` or the logs for details.\n\nDelivery is best effort. There is no queue or replay: an event is lost if the daemon crashes or is stopped before the command runs, and restarting an exhausted job without `retry` sends `exhausted` again. Deduplicate on `event` and `job`. A missing executable, nonzero exit or timeout is logged as a warning with bounded stderr and never changes the release baseline, attempts, retry timing or exit status, and never causes republication. On timeout, the command's whole process group is killed. Stdout is discarded.\n\n## Publishability before publication\n\nA new release starts with a separate preparation session using the embedded [preflight skill](skills/preflight.md). That session can prepare code and validation infrastructure, but its instructions prohibit tags, public releases and registry uploads. It must enumerate every intended publication destination and return a plan containing:\n\n- The exact prepared commit and proposed tag.\n- Each destination's version and actual publishing identity/environment.\n- Reproducible non-publishing commands checking build/package validity, version availability and publishing authorization for each destination.\n- A post-publication verification command for each destination.\n\nThe daemon checks the plan's completeness, requires a clean checkout at the prepared commit, runs the preflight commands itself, and checks the tree again. Successful build checks are saved individually, so an interruption during a later check preserves completed work. Only then does it start a separate publication session. A failed command or missing check prevents publication. Publication must report the approved commit and tag.\n\nRetries reuse the saved plan when the checkout is clean at the planned commit and no gate failure or blocked publication requires preparation repairs. Successful build checks are reused only for the identical plan, target and check; changed commands, destinations or commits invalidate that evidence, as does an observed dirty checkout. Authorization, version availability, other check kinds and the operator preflight always run again before another publication session. Keep mutable prerequisites out of build checks. Cached build success establishes validation, not the continued presence of local build outputs; the publication procedure must produce missing artifacts as needed. Older state files without checkpoints run the checks once to establish them.\n\nThe publication agent receives the plan and the time the daemon completed its gate. Its instructions limit it to reconciliation, publication and a prompt receipt, using the existing validation evidence. Code or workflow repairs return to preparation with the specific failure. The daemon still independently verifies all published destinations. GitHub waiting instructions use bounded polling with status changes and occasional heartbeats instead of repeatedly printing the full job table.\n\nFor crates.io, `cargo publish --dry-run` checks packaging; it is not evidence of remote publish authorization. The skill requires separate checks of the actual publisher's ownership, token scope/expiry, or trusted-publisher configuration. When publishing through GitHub Actions, local credentials and secret names are insufficient: the checks must establish rights in the publishing workflow's environment. Unknown rights must block publication. The same principle applies to npm, PyPI, containers, signing and other destinations.\n\nThe agent discovers the repository-specific checks. Their correctness and destination coverage depend on the repository procedure and available registry capabilities; the daemon does not contain universal registry permission adapters. For an additional operator-maintained gate, configure `preflight` to a verifier outside the checkout. It runs after the destination checks, with `RELEASE_COMMIT`, `RELEASE_TAG`, `RELEASE_TARGET` and `RELEASE_PLAN_JSON` in the environment, and must exit nonzero if any destination is not demonstrably publishable.\n\n```json\n\"preflight\": [\"/opt/release-checks/publishability\"]\n```\n\nAfter publishing, every destination's verification command must pass as well as the built-in GitHub checks and optional operator verifier. Destination and operator commands run in a temporary detached worktree at the exact released commit, checked for the expected revision and a clean tree before and after each command. Recovery preserves the preparation workspace and unfinished edits, including when the attempt budget is exhausted. Missing registry artifacts keep the job pending even if its GitHub release exists. Preflight prevents foreseeable partial releases; network failures and non-transactional registries can still fail mid-publication. The publication skill directs the agent to stage privately where possible, publish the final release/announcement last, and reconcile partial artifacts on retry. The phase boundary is an agent instruction and daemon orchestration rule, not an OS/network sandbox.\n\n## GitHub is built in\n\nThe [GitHub skill](skills/github.md) is embedded into every GitHub release prompt for every configured agent. It covers repository/workflow discovery, `gh run list`, failed job logs, reruns, dispatch, PR checks, publication and assets. The [release skill](skills/release.md) instructs the agent to follow repository instructions, repair failures and finish the release.\n\nThe daemon also independently verifies with `gh api`:\n\n- The remote tag points to the reported full commit, includes the job target, and is reachable from the watched branch.\n- Actions runs belong to that exact tagged commit. The latest run/attempt in every observed workflow/event/ref context must finish with `success`.\n- Every required workflow has a run. The agent discovers workflow names/paths from the repository and records them in the publication plan; the daemon requires this list when none is configured. Optional `github.workflows` entries add operator requirements. Entries match workflow names, paths, or filenames.\n- A published, non-draft GitHub release exists for that tag. Uploaded assets must be nonempty and complete. Every `github.assets` glob must match at least one asset.\n\nPending or missing runs are polled within `verification_timeout`; failed, cancelled or skipped runs cause repair feedback. A passing branch run cannot mask a failed tag run. The verifier paginates API results and refuses incomplete histories. Destination-specific commands in the validated plan check package registries and artifact contents; an optional operator `verify` command can enforce additional requirements.\n\nGitHub HTTPS/SSH remotes are detected automatically. For an enterprise host set `github.host`; for a local mirror set `github.repo` to `OWNER/REPO`. The `gh` process uses its own inherited authentication, independent of the agent's environment overrides.\n\n```json\n\"github\": {\n  \"host\": \"github.com\",\n  \"workflows\": [\"ci.yml\", \"release.yml\"],\n  \"assets\": [\"*-linux-amd64.tar.gz\", \"checksums.txt\"]\n}\n```\n\n## Other agents and release destinations\n\nSet `agent.command` to an executable and argument array. `agent.environment` supplies additional environment variables, `agent.auth_method` optionally selects an advertised protocol-driven login method, and `agent.mode` optionally selects a session mode. Authenticate interactive agents before starting the daemon. ACP v1 stdio agents with their own tools or client filesystem/terminal tools are supported; draft ACP v2 is not supported.\n\n```json\n\"agent\": {\n  \"command\": [\"your-acp-agent\", \"--stdio\"],\n  \"environment\": {\"YOUR_AGENT_SETTING\": \"value\"}\n}\n```\n\n`verify` is an optional extra command for any Git host. The agent already supplies mandatory destination-specific verification commands in its plan. An operator verifier runs directly as an argument array, in the isolated verification worktree, with `RELEASE_TAG`, `RELEASE_COMMIT`, `RELEASE_TARGET`, `RELEASE_URL`, `RELEASE_REMOTE`, and `RELEASE_BRANCH` in its environment. Exit zero only when the exact release's checks, artifacts and registry publication have succeeded. Keep the verifier outside the agent's writable checkout. There is no shell expansion unless you explicitly configure a shell.\n\n```json\n\"verify\": [\"/opt/release-checks/verify-publication\"]\n```\n\n## Execution and diagnostics\n\nStarting the bot authorizes unattended code edits, command execution, commits, pushes and publication for the configured repository. ACP permission requests are approved automatically and recorded. Instructions require focused fixes and respect for branch protections. Client file operations use `os.Root` to prevent paths and symlinks escaping the checkout. Shell commands and the external agent run with the bot account's OS permissions: this is not a sandbox. Run it as a dedicated account or in a container with the credentials and tools required for that repository.\n\nReadable progress goes to stderr; `--json` selects structured logs. Private JSONL session transcripts, including tool updates and agent diagnostics, live under `state_directory/sessions`. The workspace location is printed at startup. State writes use fsync and atomic replacement. Retain state across deployments. Configure log retention externally; transcripts may include repository contents or command output.\n\n## Development and protocol scope\n\nThe live transcript is shown by default: agent messages and thought updates, tool output, completion/failure status, and agent stderr appear as they arrive. Text fragments are joined into readable lines. `--json` keeps these as structured stream events. Session transcripts also include a `session_end` record with the phase, error, context cancellation cause (when available), and transport failure, so a future interruption can be diagnosed from disk.\n\nThis repository's [release instructions](RELEASING.md) describe its CI and release workflows. CI runs on pushes and pull requests; the release workflow builds Linux/macOS archives, checks publisher access, and verifies staged assets before publication.\n\n```sh\nmake check\n```\n\nTo test your real ACP adapter and model with a read-only fixture, without running a release:\n\n```sh\nRELEASE_BOT_LIVE_SMOKE=1 RELEASE_BOT_LIVE_MODEL=gpt-5.6-sol go test -run '^TestLiveACP$' -v .\n```\n\nThe ACP implementation includes newline JSON-RPC framing, bidirectional requests, ordered notifications, request errors and cancellation, initialization/version checks, session creation, optional authentication/modes, prompt completion, permission decisions, file reads/writes, and the full terminal lifecycle. Generic `Call`/`Notify` methods allow extension methods. Optional session history, MCP configuration, elicitation and v2 are not advertised. Protocol references are recorded in [docs/protocol.md](docs/protocol.md).\n\nTests use in-memory protocol peers, real subprocess pipes, temporary Git remotes and simulated registry checks. They cover permission failures, incomplete plans, partial publication, recovery, concurrent commits, scheduling, locking, path confinement and cancellation. They do not exercise real Codex credentials or publish to live registries.\n\n## Automatic releases of this project\n\nPushing a new version tag starts the complete **Publish packages** workflow:\nCI and native GitHub publication, followed automatically by all five npm packages\nat the same tag and commit. No separate package dispatch is needed. Branch\npushes do not publish. PyPI remains an explicit manual option until configured.\n\nNative checksums, local installer tests, package hashes and upload errors remain\nrelease gates. Successful npm uploads do not wait for the public version index or\nrun immediate public-install checks. Manual package dispatch and the explicit\nregistry verification command remain available for recovery and later checks.\nSee [RELEASING.md](RELEASING.md).\n\n## Contributing\n\nSee [CONTRIBUTING.md](CONTRIBUTING.md) and our\n[Code of Conduct](CODE_OF_CONDUCT.md). Report vulnerabilities privately using\n[SECURITY.md](SECURITY.md).\n\n## License\n\nLicensed under [Apache-2.0](LICENSE). See [NOTICE](NOTICE) for project\nattribution and [licenses/README.md](licenses/README.md) for dependency terms,\nthird-party notices, and the license review process.\n\n## Brokk Town worker service\n\n`brb worker --socket PATH` serves one-shot release check operations to Brokk\nTown over a private Unix-domain socket. The socket is mode `0600`; the endpoint is\nprivate to the local service, and the process exits after Town requests shutdown.\n\nWorker protocol v1 uses standard-library HTTP with JSON messages:\n\n- `GET /v1/initialize` returns the protocol range, bot identity, release version,\n  and capabilities. Town requires `release` as well as common `run` and\n  `progress` capabilities.\n- `POST /v1/runs` accepts one strict JSON task and responds with contiguous\n  newline-delimited JSON events: `progress`, optional typed `result`,\n  and `error`, `canceled`, or `complete`.\n- `POST /v1/retry` accepts the same strict JSON task, resets the pending\n  release's attempt budget in that workspace and returns `{\"retry\":\"scheduled\"}`\n  without starting an agent. It is the `brb retry` command for Town: a\n  workspace without a pending release answers 409 with the reason. Workers\n  advertising the `retry` capability support it.\n- `POST /v1/shutdown` asks the service to stop after the current stream.\n\nVersion and capability negotiation happen before work starts. Town does not read\nthis bot's private state files; issue and review outcomes are explicit protocol\nresults when applicable, while GitHub remains the durable source for receipts.\nThe schemas are independent of the Unix HTTP transport, allowing an authenticated\nTLS transport to be added later without changing worker semantics.\n","readmeFilename":"README.md"}