{"_id":"@delegance/cadence","_rev":"6-8243dca183db7614d3fc98d85ca8c241","name":"@delegance/cadence","dist-tags":{"latest":"8.4.0"},"versions":{"8.0.0":{"name":"@delegance/cadence","version":"8.0.0","keywords":["cadence","claude-autopilot","autopilot","claude-code","ai-agent","code-review","llm","sarif","cli","pipeline","coding-agent","devin-alternative","cursor-alternative","autonomous-coding","multi-model","codex","mit-license","local-first","developer-tools","ci-cd"],"license":"MIT","_id":"@delegance/cadence@8.0.0","maintainers":[{"name":"axledbetter01","email":"axledbetter01@gmail.com"},{"name":"scottmccaskill","email":"scott.mccaskill@hotmail.com"}],"homepage":"https://github.com/axledbetter/cadence#readme","bugs":{"url":"https://github.com/axledbetter/cadence/issues"},"bin":{"cadence":"bin/cadence.js","guardrail":"bin/guardrail.js","claude-autopilot":"bin/claude-autopilot.js"},"dist":{"shasum":"de9b65ee6d5718355b17e8ced0b7c5ee98f3a587","tarball":"https://registry.npmjs.org/@delegance/cadence/-/cadence-8.0.0.tgz","fileCount":511,"integrity":"sha512-IhExjD5cwss9C7JrmZwG7hoVmYYaPcjlG6k1rTdZrTCYMmXNgGXirsXuzs5E8DMlsS/nvw3XdJ7z+LifoQz6QA==","signatures":[{"sig":"MEUCICyezHpH+E/SsyHkmGlAD8I1RRM/FyAo7P/vxnfgNqDHAiEAw7txjD0Y0TEjYK5m24pbCt7BBbbKkfErI21k+R57wOM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2224654},"type":"module","types":"./dist/src/index.d.ts","engines":{"node":">=22.0.0"},"exports":{".":{"types":"./dist/src/index.d.ts","default":"./dist/src/index.js"},"./package.json":"./package.json","./bin/cadence.js":"./bin/cadence.js","./bin/guardrail.js":"./bin/guardrail.js","./concurrent-dispatch":{"types":"./dist/src/core/concurrent-dispatch/index.d.ts","default":"./dist/src/core/concurrent-dispatch/index.js"},"./bin/claude-autopilot.js":"./bin/claude-autopilot.js","./run-state/sameness-detector":{"types":"./dist/src/core/run-state/sameness-detector.d.ts","default":"./dist/src/core/run-state/sameness-detector.js"}},"gitHead":"840e855e6bbe27fe37594b1f16bb4dd6d65a8f25","scripts":{"test":"node scripts/test-runner.mjs","build":"tsc -p tsconfig.build.json && node scripts/post-build-rewrite-imports.mjs","db:stop":"bash scripts/db/stop-supabase.sh","db:reset":"bash scripts/db/reset-supabase.sh","db:start":"bash scripts/db/start-supabase.sh","test:rls":"node --test --import=tsx tests/rls/*.test.ts","typecheck":"tsc --noEmit","audit:supabase":"tsx scripts/audit-supabase-imports.ts","prepublishOnly":"npm run audit:supabase && npm run build && npm test","test:adapters:live":"node --test --import=tsx tests/adapters/live/vercel.cert.ts tests/adapters/live/fly.cert.ts tests/adapters/live/render.cert.ts"},"_npmUser":{"name":"axledbetter01","email":"axledbetter01@gmail.com"},"repository":{"url":"git+https://github.com/axledbetter/cadence.git","type":"git"},"workspaces":["apps/*","packages/*"],"_npmVersion":"11.10.0","description":"Cadence — autonomous development pipeline for Claude Code: brainstorm → spec → plan → implement → migrate → validate → PR → review → merge. Multi-model, local-first, every phase a skill you can intervene in. (Formerly @delegance/claude-autopilot.)","directories":{},"_nodeVersion":"22.14.0","dependencies":{"ajv":"^8","tsx":">=4","ulid":"^3.0.2","dotenv":">=16","js-yaml":"^4","minimatch":">=9","ajv-formats":"^3.0.1","shell-quote":"^1.8.3","canonicalize":"^3.0.0","proper-lockfile":"^4.1.2"},"publishConfig":{"tag":"latest"},"_hasShrinkwrap":false,"devDependencies":{"supabase":"^2.20.0","typescript":"^6","@types/node":"^25","@types/js-yaml":"^4","@types/shell-quote":"^1.7.5","@types/proper-lockfile":"^4.1.4"},"peerDependencies":{"superpowers":"*"},"optionalDependencies":{"openai":">=4","@anthropic-ai/sdk":"^0.96.0","@google/generative-ai":"^0.24.1","@supabase/supabase-js":"^2.97.0","@modelcontextprotocol/sdk":"^1.29.0"},"peerDependenciesMeta":{"superpowers":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/cadence_8.0.0_1779744702383_0.892866573369584","host":"s3://npm-registry-packages-npm-production"}},"8.1.0":{"name":"@delegance/cadence","version":"8.1.0","keywords":["cadence","claude-autopilot","autopilot","claude-code","ai-agent","code-review","llm","sarif","cli","pipeline","coding-agent","devin-alternative","cursor-alternative","autonomous-coding","multi-model","codex","mit-license","local-first","developer-tools","ci-cd"],"license":"MIT","_id":"@delegance/cadence@8.1.0","maintainers":[{"name":"axledbetter01","email":"axledbetter01@gmail.com"},{"name":"scottmccaskill","email":"scott.mccaskill@hotmail.com"}],"homepage":"https://github.com/axledbetter/cadence#readme","bugs":{"url":"https://github.com/axledbetter/cadence/issues"},"bin":{"cadence":"bin/cadence.js","guardrail":"bin/guardrail.js","claude-autopilot":"bin/claude-autopilot.js"},"dist":{"shasum":"8a494c17fc7e1cc5b71789885ec7624ce12b199d","tarball":"https://registry.npmjs.org/@delegance/cadence/-/cadence-8.1.0.tgz","fileCount":519,"integrity":"sha512-ugqHxUTGACeU6usTq/BzezNdo3vUcQ9eGu9yXbnuYqOF7dmNwZ/7n/AS+30eqBuHl0sw4jxqh1eIudItl5GYLw==","signatures":[{"sig":"MEUCIQDqKh5+pjLjO/hoqGZLGIKQ5Zy7wB5VCvfHDuk84F+prAIgEyiE3WM1s29VqDcKd6a1xZOL89geNBRk00U6ts4JDso=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2263738},"type":"module","types":"./dist/src/index.d.ts","engines":{"node":">=22.0.0"},"exports":{".":{"types":"./dist/src/index.d.ts","default":"./dist/src/index.js"},"./package.json":"./package.json","./bin/cadence.js":"./bin/cadence.js","./bin/guardrail.js":"./bin/guardrail.js","./concurrent-dispatch":{"types":"./dist/src/core/concurrent-dispatch/index.d.ts","default":"./dist/src/core/concurrent-dispatch/index.js"},"./bin/claude-autopilot.js":"./bin/claude-autopilot.js","./run-state/sameness-detector":{"types":"./dist/src/core/run-state/sameness-detector.d.ts","default":"./dist/src/core/run-state/sameness-detector.js"}},"gitHead":"b027ac9257708536c76b06a8f61e750df75d40ae","scripts":{"test":"node scripts/test-runner.mjs","build":"tsc -p tsconfig.build.json && node scripts/post-build-rewrite-imports.mjs","db:stop":"bash scripts/db/stop-supabase.sh","db:reset":"bash scripts/db/reset-supabase.sh","db:start":"bash scripts/db/start-supabase.sh","test:rls":"node --test --import=tsx tests/rls/*.test.ts","typecheck":"tsc --noEmit","audit:supabase":"tsx scripts/audit-supabase-imports.ts","prepublishOnly":"npm run audit:supabase && npm run build && npm test","test:adapters:live":"node --test --import=tsx tests/adapters/live/vercel.cert.ts tests/adapters/live/fly.cert.ts tests/adapters/live/render.cert.ts"},"_npmUser":{"name":"axledbetter01","email":"axledbetter01@gmail.com"},"repository":{"url":"git+https://github.com/axledbetter/cadence.git","type":"git"},"workspaces":["apps/*","packages/*"],"_npmVersion":"11.10.0","description":"Cadence — autonomous development pipeline for Claude Code: brainstorm → spec → plan → implement → migrate → validate → PR → review → merge. Multi-model, local-first, every phase a skill you can intervene in. (Formerly @delegance/claude-autopilot.)","directories":{},"_nodeVersion":"22.14.0","dependencies":{"ajv":"^8","tsx":">=4","ulid":"^3.0.2","dotenv":">=16","js-yaml":"^4","minimatch":">=9","ajv-formats":"^3.0.1","shell-quote":"^1.8.3","canonicalize":"^3.0.0","proper-lockfile":"^4.1.2"},"publishConfig":{"tag":"latest"},"_hasShrinkwrap":false,"devDependencies":{"supabase":"^2.20.0","typescript":"^6","@types/node":"^25","@types/js-yaml":"^4","@types/shell-quote":"^1.7.5","@types/proper-lockfile":"^4.1.4"},"peerDependencies":{"superpowers":"*"},"optionalDependencies":{"openai":">=4","cohere-ai":"^7.15.0","@anthropic-ai/sdk":"^0.96.0","@google/generative-ai":"^0.24.1","@supabase/supabase-js":"^2.97.0","@modelcontextprotocol/sdk":"^1.29.0","@aws-sdk/client-bedrock-runtime":"^3.700.0"},"peerDependenciesMeta":{"superpowers":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/cadence_8.1.0_1779745799323_0.19343553748720232","host":"s3://npm-registry-packages-npm-production"}},"8.1.1":{"name":"@delegance/cadence","version":"8.1.1","keywords":["cadence","claude-autopilot","autopilot","claude-code","ai-agent","code-review","llm","sarif","cli","pipeline","coding-agent","devin-alternative","cursor-alternative","autonomous-coding","multi-model","codex","mit-license","local-first","developer-tools","ci-cd"],"license":"MIT","_id":"@delegance/cadence@8.1.1","maintainers":[{"name":"axledbetter01","email":"axledbetter01@gmail.com"},{"name":"scottmccaskill","email":"scott.mccaskill@hotmail.com"}],"homepage":"https://github.com/axledbetter/cadence#readme","bugs":{"url":"https://github.com/axledbetter/cadence/issues"},"bin":{"cadence":"bin/cadence.js","guardrail":"bin/guardrail.js","claude-autopilot":"bin/claude-autopilot.js"},"dist":{"shasum":"514b1825e917f8e7e2655837bdb0089177b7fadd","tarball":"https://registry.npmjs.org/@delegance/cadence/-/cadence-8.1.1.tgz","fileCount":525,"integrity":"sha512-KctV4RC2ISEf4PVsBZVSZa2fWTWJnw3WHltKwsH7YGNP6MXVLPAYQfHIvcSiaLPv3MGXjB5aqcNlxqfKz7lFuQ==","signatures":[{"sig":"MEQCIBw7sd9NJh0uIZRu8KolVC7FQ5iB5NWU838T+cxnB52mAiBq3QF6lq6s4oNRXlkUKxKSzGU7tnHIs3e4cJjLmEkcdg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2315584},"type":"module","types":"./dist/src/index.d.ts","engines":{"node":">=22.0.0"},"exports":{".":{"types":"./dist/src/index.d.ts","default":"./dist/src/index.js"},"./package.json":"./package.json","./bin/cadence.js":"./bin/cadence.js","./bin/guardrail.js":"./bin/guardrail.js","./concurrent-dispatch":{"types":"./dist/src/core/concurrent-dispatch/index.d.ts","default":"./dist/src/core/concurrent-dispatch/index.js"},"./bin/claude-autopilot.js":"./bin/claude-autopilot.js","./run-state/sameness-detector":{"types":"./dist/src/core/run-state/sameness-detector.d.ts","default":"./dist/src/core/run-state/sameness-detector.js"}},"gitHead":"1b3e4d3c16ef75afb7309a94fba32a2e571a841b","scripts":{"test":"node scripts/test-runner.mjs","build":"tsc -p tsconfig.build.json && node scripts/post-build-rewrite-imports.mjs","db:stop":"bash scripts/db/stop-supabase.sh","db:reset":"bash scripts/db/reset-supabase.sh","db:start":"bash scripts/db/start-supabase.sh","test:rls":"node --test --import=tsx tests/rls/*.test.ts","typecheck":"tsc --noEmit","audit:supabase":"tsx scripts/audit-supabase-imports.ts","prepublishOnly":"npm run audit:supabase && npm run build && npm test","test:adapters:live":"node --test --import=tsx tests/adapters/live/vercel.cert.ts tests/adapters/live/fly.cert.ts tests/adapters/live/render.cert.ts"},"_npmUser":{"name":"axledbetter01","email":"axledbetter01@gmail.com"},"repository":{"url":"git+https://github.com/axledbetter/cadence.git","type":"git"},"workspaces":["apps/*","packages/*"],"_npmVersion":"11.10.0","description":"Cadence — autonomous development pipeline for Claude Code: brainstorm → spec → plan → implement → migrate → validate → PR → review → merge. Multi-model, local-first, every phase a skill you can intervene in. (Formerly @delegance/claude-autopilot.)","directories":{},"_nodeVersion":"22.14.0","dependencies":{"ajv":"^8","tsx":">=4","ulid":"^3.0.2","dotenv":">=16","js-yaml":"^4","minimatch":">=9","ajv-formats":"^3.0.1","shell-quote":"^1.8.3","canonicalize":"^3.0.0","proper-lockfile":"^4.1.2"},"publishConfig":{"tag":"latest"},"_hasShrinkwrap":false,"devDependencies":{"supabase":"^2.20.0","typescript":"^6","@types/node":"^25","@types/js-yaml":"^4","@types/shell-quote":"^1.7.5","@types/proper-lockfile":"^4.1.4"},"peerDependencies":{"superpowers":"*"},"optionalDependencies":{"openai":">=4","cohere-ai":"^7.15.0","@anthropic-ai/sdk":"^0.96.0","@google/generative-ai":"^0.24.1","@supabase/supabase-js":"^2.97.0","@modelcontextprotocol/sdk":"^1.29.0","@aws-sdk/client-bedrock-runtime":"^3.700.0"},"peerDependenciesMeta":{"superpowers":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/cadence_8.1.1_1779765222470_0.6325186900258679","host":"s3://npm-registry-packages-npm-production"}},"8.2.0":{"name":"@delegance/cadence","version":"8.2.0","keywords":["cadence","claude-autopilot","autopilot","claude-code","ai-agent","code-review","llm","sarif","cli","pipeline","coding-agent","devin-alternative","cursor-alternative","autonomous-coding","multi-model","codex","mit-license","local-first","developer-tools","ci-cd"],"license":"MIT","_id":"@delegance/cadence@8.2.0","maintainers":[{"name":"axledbetter01","email":"axledbetter01@gmail.com"},{"name":"scottmccaskill","email":"scott.mccaskill@hotmail.com"}],"homepage":"https://github.com/axledbetter/cadence#readme","bugs":{"url":"https://github.com/axledbetter/cadence/issues"},"bin":{"cadence":"bin/cadence.js","guardrail":"bin/guardrail.js","claude-autopilot":"bin/claude-autopilot.js"},"dist":{"shasum":"811e38d3dc8285f42fa15158efc5e38318c82304","tarball":"https://registry.npmjs.org/@delegance/cadence/-/cadence-8.2.0.tgz","fileCount":534,"integrity":"sha512-x8My0TsRvYuTyNr1AzRWyAhVy0D4oD48cWMSWAApljlLS1iwqXiDBoQjQ7Wfb3iKWQK9JKeyVwpfQg1FoEN24A==","signatures":[{"sig":"MEUCIQDZwkc5HHdjehvhFDPtV5Bwonu+43MzhtzGMuIbydSuwgIgHnx2Motz/JYz9XIQzrtWleif05axaMtwD+WA0mmrudo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2329674},"type":"module","types":"./dist/src/index.d.ts","engines":{"node":">=22.0.0"},"exports":{".":{"types":"./dist/src/index.d.ts","default":"./dist/src/index.js"},"./package.json":"./package.json","./bin/cadence.js":"./bin/cadence.js","./bin/guardrail.js":"./bin/guardrail.js","./concurrent-dispatch":{"types":"./dist/src/core/concurrent-dispatch/index.d.ts","default":"./dist/src/core/concurrent-dispatch/index.js"},"./bin/claude-autopilot.js":"./bin/claude-autopilot.js","./run-state/sameness-detector":{"types":"./dist/src/core/run-state/sameness-detector.d.ts","default":"./dist/src/core/run-state/sameness-detector.js"}},"gitHead":"86aed730e9500f6164051e0f07ae97079c6078bd","scripts":{"test":"node scripts/test-runner.mjs","build":"tsc -p tsconfig.build.json && node scripts/post-build-rewrite-imports.mjs","db:stop":"bash scripts/db/stop-supabase.sh","db:reset":"bash scripts/db/reset-supabase.sh","db:start":"bash scripts/db/start-supabase.sh","test:rls":"node --test --import=tsx tests/rls/*.test.ts","typecheck":"tsc --noEmit","audit:supabase":"tsx scripts/audit-supabase-imports.ts","prepublishOnly":"npm run audit:supabase && npm run build && npm test","test:adapters:live":"node --test --import=tsx tests/adapters/live/vercel.cert.ts tests/adapters/live/fly.cert.ts tests/adapters/live/render.cert.ts"},"_npmUser":{"name":"axledbetter01","email":"axledbetter01@gmail.com"},"repository":{"url":"git+https://github.com/axledbetter/cadence.git","type":"git"},"workspaces":["apps/*","packages/*"],"_npmVersion":"11.10.0","description":"Cadence — autonomous development pipeline for Claude Code: brainstorm → spec → plan → implement → migrate → validate → PR → review → merge. Multi-model, local-first, every phase a skill you can intervene in. (Formerly @delegance/claude-autopilot.)","directories":{},"_nodeVersion":"22.14.0","dependencies":{"ajv":"^8","tsx":">=4","ulid":"^3.0.2","dotenv":">=16","js-yaml":"^4","minimatch":">=9","ajv-formats":"^3.0.1","shell-quote":"^1.8.3","canonicalize":"^3.0.0","proper-lockfile":"^4.1.2"},"publishConfig":{"tag":"latest"},"_hasShrinkwrap":false,"devDependencies":{"supabase":"^2.20.0","typescript":"^6","@types/node":"^25","@types/js-yaml":"^4","@types/shell-quote":"^1.7.5","@types/proper-lockfile":"^4.1.4"},"peerDependencies":{"superpowers":"*"},"optionalDependencies":{"openai":">=4","cohere-ai":"^7.15.0","@anthropic-ai/sdk":"^0.96.0","@google/generative-ai":"^0.24.1","@supabase/supabase-js":"^2.97.0","@modelcontextprotocol/sdk":"^1.29.0","@aws-sdk/client-bedrock-runtime":"^3.700.0"},"peerDependenciesMeta":{"superpowers":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/cadence_8.2.0_1779765285314_0.034064044291264306","host":"s3://npm-registry-packages-npm-production"}},"8.3.0":{"name":"@delegance/cadence","version":"8.3.0","keywords":["cadence","claude-autopilot","autopilot","claude-code","ai-agent","code-review","llm","sarif","cli","pipeline","coding-agent","devin-alternative","cursor-alternative","autonomous-coding","multi-model","codex","mit-license","local-first","developer-tools","ci-cd"],"license":"MIT","_id":"@delegance/cadence@8.3.0","maintainers":[{"name":"axledbetter01","email":"axledbetter01@gmail.com"},{"name":"scottmccaskill","email":"scott.mccaskill@hotmail.com"}],"homepage":"https://github.com/axledbetter/cadence#readme","bugs":{"url":"https://github.com/axledbetter/cadence/issues"},"bin":{"cadence":"bin/cadence.js","guardrail":"bin/guardrail.js","claude-autopilot":"bin/claude-autopilot.js"},"dist":{"shasum":"b9131154b8e52d1499dcdf59bec5dc900514181a","tarball":"https://registry.npmjs.org/@delegance/cadence/-/cadence-8.3.0.tgz","fileCount":536,"integrity":"sha512-rXlo9kibbJ7DuJkk05LEEaBfam//Biq+PhSZF+OHZmhrMang8CFCVAfaSb1U9duGSo7oPpkWanOcM3Yo55XETA==","signatures":[{"sig":"MEYCIQCDyO4hyYPiv7gXGmEyxu4w9jsb3I08311HUzefVqNh4wIhAJOZPZoV34N4NIWKOCEw/cmUCs6HsPsVYRACcNL7a8kv","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":2355542},"type":"module","types":"./dist/src/index.d.ts","engines":{"node":">=22.0.0"},"exports":{".":{"types":"./dist/src/index.d.ts","default":"./dist/src/index.js"},"./package.json":"./package.json","./bin/cadence.js":"./bin/cadence.js","./bin/guardrail.js":"./bin/guardrail.js","./concurrent-dispatch":{"types":"./dist/src/core/concurrent-dispatch/index.d.ts","default":"./dist/src/core/concurrent-dispatch/index.js"},"./bin/claude-autopilot.js":"./bin/claude-autopilot.js","./run-state/sameness-detector":{"types":"./dist/src/core/run-state/sameness-detector.d.ts","default":"./dist/src/core/run-state/sameness-detector.js"}},"gitHead":"34e0bd8df3e539f387a7088e3830656b7a475df5","scripts":{"test":"node scripts/test-runner.mjs","build":"tsc -p tsconfig.build.json && node scripts/post-build-rewrite-imports.mjs","db:stop":"bash scripts/db/stop-supabase.sh","db:reset":"bash scripts/db/reset-supabase.sh","db:start":"bash scripts/db/start-supabase.sh","test:rls":"node --test --import=tsx tests/rls/*.test.ts","typecheck":"tsc --noEmit","audit:supabase":"tsx scripts/audit-supabase-imports.ts","prepublishOnly":"npm run audit:supabase && npm run build && npm test","test:adapters:live":"node --test --import=tsx tests/adapters/live/vercel.cert.ts tests/adapters/live/fly.cert.ts tests/adapters/live/render.cert.ts"},"_npmUser":{"name":"axledbetter01","email":"axledbetter01@gmail.com"},"repository":{"url":"git+https://github.com/axledbetter/cadence.git","type":"git"},"workspaces":["apps/*","packages/*"],"_npmVersion":"11.10.0","description":"Cadence — autonomous development pipeline for Claude Code: brainstorm → spec → plan → implement → migrate → validate → PR → review → merge. Multi-model, local-first, every phase a skill you can intervene in. (Formerly @delegance/claude-autopilot.)","directories":{},"_nodeVersion":"22.14.0","dependencies":{"ajv":"^8","tsx":">=4","ulid":"^3.0.2","dotenv":">=16","js-yaml":"^4","minimatch":">=9","ajv-formats":"^3.0.1","shell-quote":"^1.8.3","canonicalize":"^3.0.0","proper-lockfile":"^4.1.2"},"publishConfig":{"tag":"latest"},"_hasShrinkwrap":false,"devDependencies":{"supabase":"^2.20.0","typescript":"^6","@types/node":"^25","@types/js-yaml":"^4","@types/shell-quote":"^1.7.5","@types/proper-lockfile":"^4.1.4"},"peerDependencies":{"superpowers":"*"},"optionalDependencies":{"openai":">=4","cohere-ai":"^7.15.0","@anthropic-ai/sdk":"^0.98.0","@google/generative-ai":"^0.24.1","@supabase/supabase-js":"^2.97.0","@modelcontextprotocol/sdk":"^1.29.0","@aws-sdk/client-bedrock-runtime":"^3.700.0"},"peerDependenciesMeta":{"superpowers":{"optional":true}},"_npmOperationalInternal":{"tmp":"tmp/cadence_8.3.0_1779773515087_0.46219229747132506","host":"s3://npm-registry-packages-npm-production"}},"8.4.0":{"name":"@delegance/cadence","version":"8.4.0","type":"module","publishConfig":{"tag":"latest"},"description":"Cadence — autonomous development pipeline for Claude Code: brainstorm → spec → plan → implement → migrate → validate → PR → review → merge. Multi-model, local-first, every phase a skill you can intervene in. (Formerly @delegance/claude-autopilot.)","keywords":["cadence","claude-autopilot","autopilot","claude-code","ai-agent","code-review","llm","sarif","cli","pipeline","coding-agent","devin-alternative","cursor-alternative","autonomous-coding","multi-model","codex","mit-license","local-first","developer-tools","ci-cd"],"license":"MIT","workspaces":["apps/*","packages/*"],"repository":{"type":"git","url":"git+https://github.com/axledbetter/cadence.git"},"bugs":{"url":"https://github.com/axledbetter/cadence/issues"},"homepage":"https://github.com/axledbetter/cadence#readme","engines":{"node":">=22.0.0"},"bin":{"cadence":"bin/cadence.js","claude-autopilot":"bin/claude-autopilot.js","guardrail":"bin/guardrail.js"},"types":"./dist/src/index.d.ts","exports":{".":{"types":"./dist/src/index.d.ts","default":"./dist/src/index.js"},"./run-state/sameness-detector":{"types":"./dist/src/core/run-state/sameness-detector.d.ts","default":"./dist/src/core/run-state/sameness-detector.js"},"./concurrent-dispatch":{"types":"./dist/src/core/concurrent-dispatch/index.d.ts","default":"./dist/src/core/concurrent-dispatch/index.js"},"./bin/cadence.js":"./bin/cadence.js","./bin/claude-autopilot.js":"./bin/claude-autopilot.js","./bin/guardrail.js":"./bin/guardrail.js","./package.json":"./package.json"},"scripts":{"test":"node scripts/test-runner.mjs","test:adapters:live":"node --test --import=tsx tests/adapters/live/vercel.cert.ts tests/adapters/live/fly.cert.ts tests/adapters/live/render.cert.ts","test:rls":"node --test --import=tsx tests/rls/*.test.ts","typecheck":"tsc --noEmit","build":"tsc -p tsconfig.build.json && node scripts/post-build-rewrite-imports.mjs","prepublishOnly":"npm run audit:supabase && npm run build && npm test","audit:supabase":"tsx scripts/audit-supabase-imports.ts","audit:frontend":"tsx scripts/audit-frontend.ts","db:start":"bash scripts/db/start-supabase.sh","db:stop":"bash scripts/db/stop-supabase.sh","db:reset":"bash scripts/db/reset-supabase.sh"},"dependencies":{"ajv":"^8","ajv-formats":"^3.0.1","canonicalize":"^3.0.0","dotenv":">=16","js-yaml":"^4","minimatch":">=9","proper-lockfile":"^4.1.2","shell-quote":"^1.8.3","tsx":">=4","ulid":"^3.0.2"},"optionalDependencies":{"@anthropic-ai/sdk":"^0.98.0","@aws-sdk/client-bedrock-runtime":"^3.700.0","@google/generative-ai":"^0.24.1","@modelcontextprotocol/sdk":"^1.29.0","@supabase/supabase-js":"^2.97.0","cohere-ai":"^7.15.0","openai":">=4"},"devDependencies":{"@types/js-yaml":"^4","@types/node":"^25","@types/proper-lockfile":"^4.1.4","@types/shell-quote":"^1.7.5","supabase":"^2.20.0","typescript":"^6"},"peerDependencies":{"superpowers":"*"},"peerDependenciesMeta":{"superpowers":{"optional":true}},"gitHead":"299daa1b33cd87e751618d89483d62817eb8c310","_id":"@delegance/cadence@8.4.0","_nodeVersion":"22.14.0","_npmVersion":"11.10.0","dist":{"integrity":"sha512-ch7VDI9AgehfTyfREG+kcC+p2p7nzeksF9MBUG2Sr1ESPSYKqc4dRKkMjWVgLkMoyJN4w3AbiVtn5rdhQ68FZg==","shasum":"4a4118bd32cf701a7238a8c6d61eba6cd880df49","tarball":"https://registry.npmjs.org/@delegance/cadence/-/cadence-8.4.0.tgz","fileCount":544,"unpackedSize":2418076,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIGBNuwDjkXJUksTkTSHW4rreDtARW3V5Lt2R9KNjaW/AAiEAjYRTKOeqwUzEAqH1exVrCUthMgGTwX7w7rrTWFXt3hw="}]},"_npmUser":{"name":"axledbetter01","email":"axledbetter01@gmail.com"},"directories":{},"maintainers":[{"name":"axledbetter01","email":"axledbetter01@gmail.com"},{"name":"scottmccaskill","email":"scott.mccaskill@hotmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/cadence_8.4.0_1779823985661_0.8185759674758248"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-25T21:31:42.109Z","modified":"2026-05-26T19:33:06.027Z","8.0.0":"2026-05-25T21:31:42.572Z","8.1.0":"2026-05-25T21:49:59.524Z","8.1.1":"2026-05-26T03:13:42.685Z","8.2.0":"2026-05-26T03:14:45.462Z","8.3.0":"2026-05-26T05:31:55.297Z","8.4.0":"2026-05-26T19:33:05.890Z"},"bugs":{"url":"https://github.com/axledbetter/cadence/issues"},"license":"MIT","homepage":"https://github.com/axledbetter/cadence#readme","keywords":["cadence","claude-autopilot","autopilot","claude-code","ai-agent","code-review","llm","sarif","cli","pipeline","coding-agent","devin-alternative","cursor-alternative","autonomous-coding","multi-model","codex","mit-license","local-first","developer-tools","ci-cd"],"repository":{"type":"git","url":"git+https://github.com/axledbetter/cadence.git"},"description":"Cadence — autonomous development pipeline for Claude Code: brainstorm → spec → plan → implement → migrate → validate → PR → review → merge. Multi-model, local-first, every phase a skill you can intervene in. (Formerly @delegance/claude-autopilot.)","maintainers":[{"name":"axledbetter01","email":"axledbetter01@gmail.com"},{"name":"scottmccaskill","email":"scott.mccaskill@hotmail.com"}],"readme":"# Cadence (`@delegance/cadence`)\n\n[![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE) [![GitHub](https://img.shields.io/badge/GitHub-axledbetter%2Fcadence-181717?logo=github)](https://github.com/axledbetter/cadence) [![npm](https://img.shields.io/npm/v/@delegance/cadence.svg)](https://www.npmjs.com/package/@delegance/cadence)\n\n> **Formerly known as `@delegance/claude-autopilot`.** As of v8.0.0 the package has been renamed to `@delegance/cadence` and the CLI binary is `cadence`. The old `claude-autopilot` (and `guardrail`) bins remain as aliases through the v8.x line.\n>\n> **CLI / global-install migration:**\n>\n> ```bash\n> # Uninstall BOTH legacy packages first to avoid global-bin collisions\n> npm uninstall -g @delegance/claude-autopilot @delegance/guardrail\n> npm install -g @delegance/cadence\n> cadence --version  # 8.0.0\n> ```\n>\n> **Library / in-process import migration is NOT alias-backed.** The bin aliases (`claude-autopilot`, `guardrail`) keep working through v8.x, but **do not rely on legacy package imports for v8 code — update all `@delegance/claude-autopilot/...` imports to `@delegance/cadence/...` immediately.** `@delegance/claude-autopilot` is deprecated and its subpath exports (`.../run-state/sameness-detector`, `.../concurrent-dispatch`) are reachable only under the new `@delegance/cadence` name:\n>\n> ```ts\n> // before\n> import { computeFingerprint } from '@delegance/claude-autopilot/run-state/sameness-detector';\n> // after (v8.0.0)\n> import { computeFingerprint } from '@delegance/cadence/run-state/sameness-detector';\n> ```\n>\n> The old npm package is deprecated but still installable; the GitHub repo at `axledbetter/claude-autopilot` redirects to `axledbetter/cadence`.\n\n**Autonomous development pipeline for Claude Code. Brainstorm → spec → plan → implement → migrate → validate → PR → review → merge — all from your terminal, on your codebase, with your test suite.**\n\n**Open source, MIT-licensed, runs on your machine with your API keys.** No hosted agent, no per-seat subscription — `npm install -g @delegance/cadence@latest` and you're done.\n\n## Hosted dashboard (early access)\n\nA hosted dashboard for team-wide run history, cost roll-up, and member management is in design-partner phase — not yet open for self-serve signup. The CLI is and stays fully usable without it.\n\nIf you're interested in early access, open an issue or email alex@delegance.com. Otherwise the rest of this README covers everything you need to run the CLI locally with your own API keys.\n\n```bash\ncadence brainstorm \"add SSO with SAML for enterprise tenants\"\n# → writes spec (reviewed by Codex) → writes plan (reviewed by Codex) →\n# → creates branch → implements with subagents → runs migrations →\n# → runs full test + lint + type + security gate → opens PR →\n# → runs risk-tiered Codex PR review (1/2/3 passes by spec risk) →\n# → triages bugbot findings, auto-fixes real bugs, re-runs validate →\n# → merges with your configured permissions (default is admin-squash;\n#   configure branch protection + required checks if you need to enforce\n#   reviews/CI gates that the autopilot agent should not bypass)\n```\n\n*No hosted agent. No per-seat subscription. Runs locally on your machine, against your real repo, using your API keys. Every phase is a Claude Code skill you can intervene in, rewire, or run by itself.*\n\n**See it work end-to-end:** [DEMO.md](DEMO.md) — one real autonomous run on a Python codebase. 12 minutes wall clock, $2.20 spend, 5 new tests, multi-file integration, zero manual intervention. Honest about what's bounded today.\n\n---\n\n## Benchmark\n\nOn a Next.js fixture seeded with 13 production-realistic bugs covering the categories the README advertises — SQL injection, hardcoded secret, missing auth, IDOR, CORS wildcard, SSRF, open redirect, TOCTOU race, silent error swallow, off-by-one, missing rate limit, console.log in prod, and missing input validation:\n\n| Configuration | Bugs caught | Cost | Time |\n|---|---|---|---|\n| **`cadence scan --all` with Claude Opus** | **13 / 13** | $0.21 | 38 s |\n\nEvery finding came with a concrete remediation (often a code patch or named library — `Zod` for validation, atomic Postgres updates for TOCTOU, allowlist + DNS resolution for SSRF). [Reproduce the benchmark.](#reproducing-the-benchmark)\n\n---\n\n## Why this vs the alternatives\n\n| Tool | Where code lives | Pricing model | Models | Pipeline | Intervenable? |\n|---|---|---|---|---|---|\n| **Devin** (Cognition) | Hosted sandbox | Per-ACU (cloud markup) | Cognition's stack | Opaque | No — dashboard only |\n| **Factory Droids** | Hosted | Per-task + seat | Factory's stack | Fixed | Limited |\n| **GitHub Copilot Workspace** | GitHub-hosted | Per-seat ($) | Copilot only | Fixed, non-extensible | Edit the plan |\n| **Cursor / Copilot agent mode** | Local IDE | Per-seat ($) | Vendor's model | None — single-shot | Continuous |\n| **Cursor BugBot / CodeRabbit** | Hosted | Per-PR or seat | Vendor's model | Review only | Post-hoc |\n| **Aider / Cline** | Local CLI | Free + your API key | User's choice | None | Continuous |\n| **OpenHands / SWE-agent** | Local research | Free | User's choice | Agent decides | Rare |\n| **Cadence** (formerly claude-autopilot) | **Local CLI, your repo** | **Open source CLI + your model/API costs (Claude / Codex / Gemini / Groq / Ollama-local)** | **Multi-model per role (Claude + Codex + Gemini)** | **Skill-per-phase, rewireable** | **Every phase, all state on disk** |\n\nFour things only this product gives you:\n\n1. **No hosted workspace or remote sandbox.** Your repo stays on your machine. No third-party agent runtime, no SaaS-side orchestration, no per-seat markup. Model prompts (diffs, file context, design questions) are sent to whichever LLM providers you've configured (Anthropic / OpenAI / Google / Groq / Ollama-local). For a truly local-only setup, you must point _every_ model used by the entire execution path at a local endpoint: that includes the Claude Code agent runtime itself (configure a local Claude Code provider) AND the autopilot review adapter (`openai-compatible` pointed at Ollama). Pointing only the review adapter at Ollama still ships prompts/diffs to Anthropic via Claude Code. For most teams, local-only isn't the goal; \"no hosted orchestration + your existing provider keys\" is.\n2. **Risk-tiered review depth (policy-driven).** Specs declare `risk: low | medium | high` in frontmatter. The autopilot skill runs 1 / 2 / 3 sequential Codex passes accordingly, each with a remediation cycle in between. Enforcement is encoded in the skill (an LLM-driven instruction set, not a hard CLI gate) so it's auditable and editable: read `.claude/skills/autopilot/SKILL.md`, swap the tier rules for your codebase, expand the auto-escalation keyword list. Designed for teams that want review depth to scale with change risk instead of running forensic-grade review on every typo.\n3. **Ships as a Claude Code skill, not a competing IDE.** `/brainstorm`, `/autopilot`, `/migrate`, `/validate` are first-class Claude Code commands. As Claude Code grows, autopilot rides that adoption. You don't switch tools to use it; it's already there.\n4. **Multi-model council, available as a verb.** `cadence council` dispatches the same diff or design question to Claude + Codex + Gemini in parallel and synthesizes the consensus. Wire it into the autopilot pipeline by editing `.claude/skills/autopilot/SKILL.md` Step 7, or invoke standalone for one-off design decisions. The default pipeline uses sequential Codex review (cheaper, faster, often sufficient for routine changes); council is the higher-rigor option when you want broader model diversity.\n\nPlus the four practical differences:\n\n- **Multi-model by role.** Claude writes code, Codex reviews the plan, bugbot triages PR findings. Swap any of them.\n- **Your stack, not a sandbox.** Runs your `npm test`, your `prisma migrate`, your `gh pr create`. If it works in your terminal, it works in the pipeline.\n- **Phase artifacts on disk, editable.** Every phase writes to a file you can open — `docs/specs/*.md`, `docs/plans/*.md`, a branch, a PR. Stop, edit by hand, resume, or re-run any phase in isolation.\n- **Test-gated auto-revert.** `cadence fix --verify` patches a file, runs your tests, reverts on failure. Built into the CLI, not a wrapper.\n\n**Real numbers from a real run:** [DEMO.md](DEMO.md) — autonomous multi-file change on a Python codebase, **12 minutes, $2.20, zero manual intervention.**\n\n## 30-second quickstart\n\n```bash\n# Install\nnpm install -g @delegance/cadence\n\n# One-shot setup — detects stack, writes config, installs skills, sets hooks\ncadence init\n\n# Ship a feature end-to-end\ncadence brainstorm \"add rate limiting to the public API\"\n# Answer ~5 questions. Spec written. Codex reviews it. You approve.\n# Claude walks the plan → implementation → migration → tests → PR → review.\n# ~15-40 min for a typical feature.\n\n# Or run just the review layer on an existing PR\ncadence run --pr 123\n```\n\n## Run State Engine (v6)\n\nPersistent state for autopilot runs. Resume after crashes, enforce hard budget caps, and surface typed JSON events for CI consumers — all opt-in, all on disk.\n\n```yaml\n# guardrail.config.yaml\nengine:\n  enabled: true              # default in v6.1+; explicit `false` is deprecated and removed in v7\nbudgets:\n  perRunUSD: 10              # hard stop; mandatory runtime guard\n  perPhaseUSD: 5\n```\n\n```bash\ncadence scan --all                  # any command — engine writes a per-run dir\ncadence runs list                   # newest-first, with status / cost / lastPhase\ncadence runs show 01HZK7P3D8Q9V…    # state snapshot + optional event tail\ncadence run resume 01HZK7P3D8Q9V…   # lookup-only today; live execution in a later v8.x\ncadence runs gc --older-than-days 7 # retire completed runs\n```\n\nEvery state transition appends a typed event to `.guardrail-cache/runs/<ulid>/events.ndjson`; every CLI verb supports `--json` with strict stdout-envelope / stderr-NDJSON channel discipline. Side-effect phase replay consults persisted `externalRefs` plus a live provider read-back so resume is safe by construction.\n\n**v6.1+ ships with the engine ON by default** (flipped from v6.0's off-by-default after the stabilization criteria in [`docs/specs/v6.1-default-flip.md`](docs/specs/v6.1-default-flip.md) were met). Users who want the legacy v5.x output shape can opt out for one minor version via `--no-engine`, `CLAUDE_AUTOPILOT_ENGINE=off`, or `engine.enabled: false` — each prints a deprecation warning and is removed in v7.\n\n→ [`docs/v6/quickstart.md`](docs/v6/quickstart.md) — five-minute setup\n→ [`docs/v6/migration-guide.md`](docs/v6/migration-guide.md) — full v5.x → v6 walkthrough with precedence matrix, per-phase idempotency rules, and troubleshooting\n\n## The pipeline, phase by phase\n\nEach phase is a Claude Code skill (`.claude/skills/<name>/SKILL.md`). You can invoke any phase directly (`/brainstorm`, `/plan`, `/migrate`, `/validate`) without running the full pipeline. You can also rewire the pipeline by editing the `autopilot` skill.\n\n| Phase | Skill | What it does | Model role |\n|---|---|---|---|\n| **Brainstorm** | `brainstorming` | Turns a rough idea into an approved spec through guided questions | Claude (implementation model) |\n| **Spec review** | `codex-review` | Second model critiques the spec before you commit to it | Codex / GPT-5 |\n| **Plan** | `writing-plans` | Breaks spec into phased, checklist-shaped implementation plan | Claude |\n| **Plan review** | `codex-review` | Second model critiques the plan before you execute it | Codex / GPT-5 |\n| **Implement** | `subagent-driven-development` | Executes plan in a git worktree, one phase at a time, with per-phase tests | Claude |\n| **Migrate** | `migrate` | Dispatches to the configured migration skill (see [Migrate phase](#migrate-phase)) — runs your migration tool dev → QA → prod with per-env validation | Deterministic |\n| **Validate** | `validate` | Static rules + tests + type check + security scan + LLM review | Any |\n| **PR** | `commit-push-pr` | Opens the PR with auto-generated title, summary, and test plan | Claude |\n| **Review** | `codex-pr-review` (default) or `council` (opt-in) | Sequential Codex pass on the diff with risk-tiered iteration count (1/2/3 passes for low/medium/high). Swap in `council` for parallel multi-model dispatch if you want higher rigor. | Codex (default) or multi-model |\n| **Triage** | `bugbot` | Fetches automated reviewer findings, auto-fixes real bugs, dismisses false positives | Claude |\n| **Deploy** (opt-in) | `deploy` | Deploys via configured adapter (`vercel` \\| `fly` \\| `render` \\| `generic`) with optional log streaming, health check, and bounded auto-rollback (see [Deploy phase](#deploy-phase)). Not on the default `/autopilot` critical path: the autopilot loop ends at merge, and your CI/CD handles prod. Invoke `cadence deploy` directly, or wire it into the autopilot skill as Step 10. | Deterministic |\n\n### Migrate phase\n\nConfigure your migration tool in `.autopilot/stack.md`. The pipeline reads stack.md, dispatches to the configured skill (`migrate@1` for generic; `migrate.supabase@1` for rich Supabase ledger; `none@1` to skip), and runs your tool with full safety: structured argv (no shell injection), 4-flag CI prod gate, hash-chained audit log. Run `cadence init` to auto-detect your stack — the detector recognizes Rails, Alembic, Django, Prisma, Drizzle, golang-migrate, dbmate, flyway, supabase-cli, ecto, typeorm, and falls back to a \"configure manually\" path. See [docs/skills/rich-migrate-contract.md](docs/skills/rich-migrate-contract.md) for the skill contract and [docs/skills/version-compatibility.md](docs/skills/version-compatibility.md) for the version model.\n\nGeneric example (Rails):\n\n```yaml\nmigrate:\n  skill: \"migrate@1\"\n  envs:\n    dev:\n      command: { exec: \"rails\", args: [\"db:migrate\"] }\n      env_file: \".env.development\"\n    prod:\n      command: { exec: \"rails\", args: [\"db:migrate\", \"RAILS_ENV=production\"] }\n```\n\nSee `skills/migrate/SKILL.md` for examples covering Alembic, Django, Prisma, Drizzle, golang-migrate, dbmate, flyway, and custom scripts.\n\n### Deploy phase\n\nConfigure your deploy target in `guardrail.config.yaml` under a `deploy:` block. Four adapters ship in 5.6:\n\n- **`vercel`** — Vercel v13 deployments API. SSE+NDJSON log streaming, native rollback via `/promote`. Auth: `VERCEL_TOKEN`.\n- **`fly`** — Fly.io Machines API. WebSocket log streaming, native rollback with simulated fallback. Auth: `FLY_API_TOKEN`. Requires the image to be pre-pushed (`fly deploy --build-only --push`).\n- **`render`** — Render REST API. Polling-based log stream with `(timestamp, logId)` cursor dedup, simulated rollback (re-deploys prior commit). Auth: `RENDER_API_KEY`.\n- **`generic`** — runs any shell `deployCommand` (`vercel --prod`, `kubectl apply`, `make deploy`, etc). No platform integration; `--watch` and `rollback` aren't supported.\n\nEach adapter speaks the same `DeployAdapter` contract: `deploy()`, optional `status()` / `rollback()` / `streamLogs()`, plus a `capabilities` block (`streamMode: 'websocket' | 'polling' | 'none'`, `nativeRollback: boolean`) so the CLI can degrade UX honestly (polling adapters print a one-line stderr notice under `--watch`). Auto-rollback is bounded: max one rollback per deploy attempt, with `runHealthCheck` capped at 5×6s. Log lines emitted into PR comments run through a redaction pass (`AKIA…`, `sk-…`, `eyJ…`, `ghp_`, `xoxb-`, plus configurable patterns) so build output can't leak secrets.\n\nExample (Fly):\n\n```yaml\ndeploy:\n  adapter: fly\n  app: my-app\n  image: registry.fly.io/my-app:latest\n  region: ord\n  watchBuildLogs: true\n  healthCheckUrl: https://my-app.fly.dev/health\n  rollbackOn: [healthCheckFailure]\n```\n\n`cadence doctor` checks for the relevant auth env var when an adapter is configured. See `docs/specs/v5.6-fly-render-adapters.md` for the full adapter contract.\n\n## What's distinctive\n\nFeatures that are hard or impossible to find in the competitive set:\n\n- **Risk-tiered review depth (policy-driven).** Specs are tagged `risk: low | medium | high` in their frontmatter, with auto-escalation by keyword detection for sensitive categories (auth, multi-tenancy, sandboxing, billing, secrets, migrations, RLS, deploy/IAM, vector-DB tenancy — extend the list in the skill for your codebase). The pipeline runs 1 / 2 / 3 sequential Codex passes accordingly, each with a remediation cycle in between. Enforcement is encoded in `.claude/skills/autopilot/SKILL.md` (LLM-driven instructions, not a hard CLI gate), so it's auditable and editable. For teams that need hard enforcement, gate the merge step on the configured pass count by extending the skill or wrapping the CLI.\n- **Retry-loop sameness detector.** Validate / Codex / bugbot retry loops compute a failure fingerprint before consuming each retry. If the same fingerprint fires twice in a row, the pipeline halts and surfaces it to you — instead of burning the remaining retry budget on attempts that are making no progress. Available as a public subpath import (`@delegance/cadence/run-state/sameness-detector`) for embedding into your own retry loops.\n- **Multi-model council, available as a verb.** `cadence council` dispatches the same prompt to 3+ models in parallel and synthesizes the consensus. Opt-in for the autopilot pipeline (wire it into Step 7 of the autopilot skill), or invoke standalone for design decisions and architecture questions.\n- **Fix with test verification.** `cadence fix --verify` runs your full test suite after every patch and reverts on failure. Safer than any tool that proposes fixes without running your tests.\n- **Bug-bot auto-triage.** Watches Cursor BugBot / Copilot comments on your PR, triages each (real bug vs false positive), auto-fixes confirmed bugs, dismisses noise with explanations.\n- **Schema alignment rule.** Ensures DB migrations, backend types, and frontend types stay in sync. Custom static rule, not something any competitor ships.\n- **SARIF output + GitHub Code Scanning integration.** Findings appear as annotations in the PR and in the Security tab.\n\n## Just the review layer\n\nIf you don't want the full pipeline, the review subcommands are a strict superset of what `guardrail run` used to do: LLM code review over git-changed files, SARIF output, inline PR comments, auto-fix, baselines, per-finding triage, cost budgets. The legacy `guardrail` CLI remains aliased to the review subcommands through v5.x.\n\n```bash\ncadence run                             # review changes since main\ncadence run --inline-comments           # post per-line PR annotations\ncadence run --format sarif --output out.sarif\ncadence fix --verify                    # LLM patch + test gate + revert on fail\n```\n\n> **CLI note:** subcommands are flat (`run`, `scan`, `ci`, `fix`, `baseline`, `explain`, …). The grouped `cadence review <verb>` form is also accepted as an alias — flat and grouped both work. The legacy `claude-autopilot` and `guardrail` bins still answer to all of the above.\n\n## Install & requirements\n\n```bash\nnpm install -g @delegance/cadence\n```\n\nMigrating from the old name? `npm uninstall -g @delegance/claude-autopilot && npm install -g @delegance/cadence`. The legacy `claude-autopilot` CLI continues to work as an alias through v8.x.\n\n- Node 22+\n- `gh` CLI (for PR phases)\n- One of: `ANTHROPIC_API_KEY` (recommended), `OPENAI_API_KEY`, `GEMINI_API_KEY`, or `GROQ_API_KEY`\n- Claude Code CLI (for skill-based phases — pipeline falls back to direct CLI invocations without it, but loses interactive checkpoints)\n- `superpowers` Claude Code plugin (required for pipeline phases — `cadence doctor` will remediation-hint if missing)\n\n---\n\n---\n\n## Config (`guardrail.config.yaml`)\n\n```yaml\nconfigVersion: 1\nreviewEngine:\n  adapter: auto        # auto-selects best available key at runtime\ntestCommand: npm test  # null to disable; used by `fix` verified mode\n\nprotectedPaths:\n  - data/deltas/**\n  - .github/workflows/**\n\nstaticRules:\n  - hardcoded-secrets   # Anthropic, OpenAI, Stripe, GitHub, Supabase, Twilio, SendGrid\n  - npm-audit\n  - sql-injection       # template literals / concatenation in SQL context\n  - missing-auth        # Next.js/pages API routes with POST/PUT/DELETE, no auth pattern\n  - ssrf                # HTTP calls with user-controlled URL\n  - insecure-redirect   # redirect() with user-controlled target\n  - console-log\n  - todo-fixme\n  - large-file\n  - missing-tests\n  - package-lock-sync\n  - brand-tokens        # opt-in: requires brand: block below\n\n# Brand token enforcement (opt-in — omit to disable)\nbrand:\n  colorsFrom: tailwind.config.ts   # auto-extract theme.colors as canonical palette\n  colors:                          # explicit palette entries (merged with colorsFrom)\n    - '#f97316'\n    - '#1a1f3a'\n  fonts:\n    - 'Inter'\n    - 'Geist'\n\npolicy:\n  failOn: critical      # critical (default) | warning | note | none\n  newOnly: false        # true = suppress findings present in .guardrail-baseline.json\n\ncost:\n  maxPerRun: 0.50       # abort review phase if spend exceeds $0.50\n  estimateBeforeRun: false  # print token estimate before LLM calls\n\nignore:\n  - src/legacy/**                              # suppress all findings in path\n  - { rule: console-log, path: scripts/** }    # suppress specific rule in path\n\nchunking:\n  rateLimitBackoff: exp    # exp (default) | linear | none\n  parallelism: 3\n```\n\n### Setup Profiles\n\n`guardrail setup --profile <name>` overlays a pre-baked rule + policy configuration on top of the detected stack preset:\n\n| Profile | Rules | `failOn` | Best for |\n|---|---|---|---|\n| `security-strict` | All security rules + hygiene | `warning` | Security audits, regulated environments |\n| `team` | Core security + hygiene | `critical` | Standard CI/CD on shared branches |\n| `solo` | Hygiene only | `critical` | Solo projects, low-noise baseline |\n\n### Review Engine Adapters\n\n| Adapter | Key required | Notes |\n|---|---|---|\n| `auto` | any | Auto-selects best available (recommended) |\n| `claude` | `ANTHROPIC_API_KEY` | Claude Opus 4.7 |\n| `gemini` | `GEMINI_API_KEY` or `GOOGLE_API_KEY` | Gemini 2.5 Pro, 1M context |\n| `codex` | `OPENAI_API_KEY` | GPT-5 Codex |\n| `bedrock` | AWS SDK default credential chain | AWS Bedrock — Claude Sonnet 4.5 default, streaming supported. Resolves credentials via the standard chain (ECS task role, EC2 instance metadata, EKS web identity, SSO, shared config, env vars). Optional `AWS_REGION` (default `us-east-1`). Install `@aws-sdk/client-bedrock-runtime`. |\n| `azure` | `AZURE_OPENAI_API_KEY` + `AZURE_OPENAI_ENDPOINT` + `AZURE_OPENAI_DEPLOYMENT_NAME` | Azure OpenAI — deployment-routed (`/openai/deployments/{deployment}`). Default api-version `2024-10-21`. |\n| `cohere` | `COHERE_API_KEY` | Cohere `command-r-plus-08-2024` default, streaming supported. Install `cohere-ai`. |\n| `mistral` | `MISTRAL_API_KEY` | Mistral La Plateforme — `mistral-large-latest` default, streaming supported. Reuses OpenAI SDK. |\n| `openai-compatible` | configurable | Any OpenAI-API-shape provider — see [OpenAI-compatible providers](#openai-compatible-providers) below. |\n\n`auto` priority: Anthropic → Gemini → OpenAI → Groq.\n\n#### OpenAI-compatible providers\n\nThe `openai-compatible` adapter speaks the standard OpenAI Chat Completions wire shape. Each of the providers below is configured via the OpenAI-compatible adapter — pick one, paste the snippet into `guardrail.config.yaml`, and set the named env var.\n\n> **Security note.** `openai-compatible` accepts an arbitrary `baseUrl` and `apiKeyEnv` from your `guardrail.config.yaml`. The named env var's value is sent as the API key to that URL. **Only use `openai-compatible` with `guardrail.config.yaml` files you trust** — if an attacker can edit your config (e.g. via an unreviewed PR or untrusted repo), they can point `baseUrl` at an attacker-controlled endpoint and set `apiKeyEnv` to a sensitive variable name to exfiltrate it. Treat `guardrail.config.yaml` like any other secret-adjacent config file in code review. The direct provider adapters (`bedrock`, `azure`, `cohere`, `mistral`, `claude`, `gemini`, `codex`) use fixed credential env var names; `claude`, `gemini`, `codex`, `bedrock`, `cohere`, `mistral` also use fixed endpoints. `azure`'s `AZURE_OPENAI_ENDPOINT` is operator-provided but is validated to be `https://` origin-only before any credential is sent — it cannot be coerced into pointing at an arbitrary attacker host via a config file alone (the operator must set the env var on the host).\n\n| Provider | `baseUrl` | `apiKeyEnv` |\n|---|---|---|\n| Together AI | `https://api.together.xyz/v1` | `TOGETHER_API_KEY` |\n| Anyscale | `https://api.endpoints.anyscale.com/v1` | `ANYSCALE_API_KEY` |\n| Fireworks | `https://api.fireworks.ai/inference/v1` | `FIREWORKS_API_KEY` |\n| OpenRouter | `https://openrouter.ai/api/v1` | `OPENROUTER_API_KEY` |\n| Perplexity | `https://api.perplexity.ai` | `PPLX_API_KEY` |\n| DeepInfra | `https://api.deepinfra.com/v1/openai` | `DEEPINFRA_API_TOKEN` |\n| Hyperbolic | `https://api.hyperbolic.xyz/v1` | `HYPERBOLIC_API_KEY` |\n| Groq | `https://api.groq.com/openai/v1` | `GROQ_API_KEY` |\n| Ollama (local) | `http://localhost:11434/v1` | n/a (no key required) |\n\n**Groq (fast/free tier):**\n```yaml\nreviewEngine:\n  adapter: openai-compatible\n  options:\n    model: llama-3.3-70b-versatile\n    baseUrl: https://api.groq.com/openai/v1\n    apiKeyEnv: GROQ_API_KEY\n```\n\n**Together AI:**\n```yaml\nreviewEngine:\n  adapter: openai-compatible\n  options:\n    model: meta-llama/Llama-3.3-70B-Instruct-Turbo\n    baseUrl: https://api.together.xyz/v1\n    apiKeyEnv: TOGETHER_API_KEY\n```\n\n**Anyscale:**\n```yaml\nreviewEngine:\n  adapter: openai-compatible\n  options:\n    model: meta-llama/Meta-Llama-3-70B-Instruct\n    baseUrl: https://api.endpoints.anyscale.com/v1\n    apiKeyEnv: ANYSCALE_API_KEY\n```\n\n**Fireworks:**\n```yaml\nreviewEngine:\n  adapter: openai-compatible\n  options:\n    model: accounts/fireworks/models/llama-v3p3-70b-instruct\n    baseUrl: https://api.fireworks.ai/inference/v1\n    apiKeyEnv: FIREWORKS_API_KEY\n```\n\n**OpenRouter (routes to 100+ models):**\n```yaml\nreviewEngine:\n  adapter: openai-compatible\n  options:\n    model: anthropic/claude-3.5-sonnet\n    baseUrl: https://openrouter.ai/api/v1\n    apiKeyEnv: OPENROUTER_API_KEY\n```\n\n**Perplexity:**\n```yaml\nreviewEngine:\n  adapter: openai-compatible\n  options:\n    model: llama-3.1-sonar-large-128k-online\n    baseUrl: https://api.perplexity.ai\n    apiKeyEnv: PPLX_API_KEY\n```\n\n**DeepInfra:**\n```yaml\nreviewEngine:\n  adapter: openai-compatible\n  options:\n    model: meta-llama/Meta-Llama-3.1-70B-Instruct\n    baseUrl: https://api.deepinfra.com/v1/openai\n    apiKeyEnv: DEEPINFRA_API_TOKEN\n```\n\n**Hyperbolic:**\n```yaml\nreviewEngine:\n  adapter: openai-compatible\n  options:\n    model: meta-llama/Meta-Llama-3.1-70B-Instruct\n    baseUrl: https://api.hyperbolic.xyz/v1\n    apiKeyEnv: HYPERBOLIC_API_KEY\n```\n\n**Ollama (local, no key):**\n```yaml\nreviewEngine:\n  adapter: openai-compatible\n  options:\n    model: llama3.2\n    baseUrl: http://localhost:11434/v1\n```\n\n#### Direct provider adapters\n\n**AWS Bedrock:**\n```yaml\nreviewEngine:\n  adapter: bedrock\n  # Optional overrides — defaults shown:\n  # options:\n  #   model: anthropic.claude-sonnet-4-5-20250929-v1:0\n  #   region: us-east-1\n# Credentials: resolved via the AWS SDK default credential provider chain —\n#   ECS task role / EC2 instance metadata / EKS web identity / SSO / shared\n#   config / env vars (AWS_ACCESS_KEY_ID + AWS_SECRET_ACCESS_KEY, optionally\n#   AWS_SESSION_TOKEN for STS). The secure pattern in ECS/EKS is to use a\n#   task role and NOT set static keys in env.\n# Region: resolved from options.region → AWS_REGION env → us-east-1 default.\n#   The AWS SDK's own profile/SSO-config region resolution is NOT consulted\n#   — set AWS_REGION explicitly for non-us-east-1 Bedrock deployments where\n#   the model is enabled in another region (e.g. us-west-2, eu-west-3).\n# Install: npm install @aws-sdk/client-bedrock-runtime\n```\n\n**Azure OpenAI:**\n```yaml\nreviewEngine:\n  adapter: azure\n# Env: AZURE_OPENAI_API_KEY, AZURE_OPENAI_ENDPOINT\n#      (e.g. https://my-resource.openai.azure.com),\n#      AZURE_OPENAI_DEPLOYMENT_NAME (deployment name, not model name).\n# Optional: AZURE_OPENAI_API_VERSION (default 2024-10-21).\n```\n\n**Cohere:**\n```yaml\nreviewEngine:\n  adapter: cohere\n  # Optional:\n  # options:\n  #   model: command-r-plus-08-2024\n# Env: COHERE_API_KEY\n# Install: npm install cohere-ai\n```\n\n**Mistral:**\n```yaml\nreviewEngine:\n  adapter: mistral\n  # Optional:\n  # options:\n  #   model: mistral-large-latest\n# Env: MISTRAL_API_KEY\n# (Reuses the OpenAI SDK — no separate install required.)\n```\n\n---\n\n## GitHub Actions\n\n```yaml\n- uses: axledbetter/cadence/.github/actions/ci@main\n  with:\n    anthropic-api-key: ${{ secrets.ANTHROPIC_API_KEY }}\n    # Optional:\n    # post-comments: 'true'\n    # inline-comments: 'false'\n    # base-ref: 'main'\n    # sarif-output: 'guardrail.sarif'\n    # version: 'latest'\n```\n\nRuns the pipeline, uploads SARIF to GitHub Code Scanning, annotates the PR diff inline.\n\n---\n\n## Typical Team Workflow\n\n```bash\n# 1. First run — establish a baseline so CI only fails on new issues\nnpx guardrail run --base main\nnpx guardrail baseline create --note \"post-v2 audit\"\ngit add .guardrail-baseline.json && git commit -m \"chore: guardrail baseline\"\n\n# 2. CI — only new findings block the build\nnpx guardrail ci --new-only --fail-on critical\n\n# 3. Triage false positives once, never see them again\nnpx guardrail triage sql-injection:src/db/raw.ts:47 false-positive --reason \"internal admin only\"\ngit add .guardrail-triage.json && git commit -m \"chore: triage false positive\"\n\n# 4. Auto-fix and verify\nnpx guardrail fix --yes   # applies patches + runs tests, reverts on failure\n```\n\n---\n\n## Interpreting Results\n\n**Exit 0** — pass or warnings only (at current `policy.failOn` threshold). Safe to merge.  \n**Exit 1** — findings at or above threshold. Fix before merging.\n\nFindings: `critical` blocks merge · `warning` should fix · `note` informational.\n\nPR comments show: status badge, phase table, critical/warning findings with inline links, cost footer. Re-runs update the existing comment in place.\n\n---\n\n## Architecture\n\nFour pluggable adapter points:\n\n| Point | Built-in | Purpose |\n|---|---|---|\n| `review-engine` | `auto`, `claude`, `gemini`, `codex`, `bedrock`, `azure`, `cohere`, `mistral`, `openai-compatible` | LLM review (16+ providers — see [Review Engine Adapters](#review-engine-adapters)) |\n| `vcs-host` | `github` | PR comments + SARIF |\n| `migration-runner` | `supabase` | DB migrations |\n| `review-bot-parser` | `cursor` | Parse review bot comments |\n\n**Monorepo:** Auto-detects npm/yarn/pnpm workspaces, Turborepo, and Nx.\n\n## Reproducing the benchmark\n\nThe 13/13 benchmark cited in the [Benchmark](#benchmark) section is reproducible end-to-end. The fixture is a minimal Next.js app that seeds each of the README-advertised bug categories at a specific file:line, then `cadence scan --all` is run with the `claude` adapter and the result is compared to the seed list.\n\n```bash\n# 1. Install the CLI\nnpm install -g @delegance/cadence\n\n# 2. Seed the fixture (one file per bug category)\nSEED=$(mktemp -d) && cd $SEED && npm init -y >/dev/null\nmkdir -p app/api/{users,coupons,profile,redirect,proxy} lib\n\n# (Add the 13 seeded files — the canonical fixture lives at\n#  https://github.com/axledbetter/cadence/tree/master/tests/v4-compat/fixtures/13-bugs)\n\n# 3. Init + scan\ncadence init --preset nextjs-supabase\nANTHROPIC_API_KEY=sk-ant-... cadence scan --all\n```\n\n**What \"13 of 13\" means:** the scan output flags each category as a distinct critical or warning finding with file path, line, and concrete remediation. We count one hit per seed regardless of severity bucket. The categories are: SQL injection, hardcoded secret, missing auth, IDOR, CORS wildcard, SSRF, open redirect, TOCTOU race, silent error swallow, off-by-one, missing rate limit, console.log in prod, missing input validation.\n\n**What this doesn't measure:**\n- False positive rate on a clean repo (separate test, expected ~3 findings on real production code per the cold-start eval)\n- Detection rate with cheaper models — this is Claude Opus. Sonnet typically catches 11/13. Llama 3.3 70B (via Groq) caught 8/13 in independent testing\n- Bugs the scan missed: there are none in the 13-category set we measure, but real production bugs are not always in this set\n\nWe do not claim 13/13 reflects every real-world repo — it's a reproducible upper bound on a fixture that exercises the categories we explicitly target.\n\n## What's Next\n\nThe v7.x decoupling work (initially scoped for v8.0.0) is being re-staged\nnow that v8.0.0 is reserved for the Cadence brand reset:\n\n- **`tsx` will eventually be removed from `dependencies`.** Today it ships\n  bundled and the launcher prefers a project-local install if you have one,\n  falling back to the bundled copy with a once-per-day deprecation warning.\n  When the bundled fallback goes away in a future major, you'll install\n  `tsx` locally (`npm install -D tsx`) or set `CLAUDE_AUTOPILOT_TSX=path` to\n  use a global install. (The env-var name keeps the `CLAUDE_AUTOPILOT_`\n  prefix for backward compatibility — renaming it would force another\n  breaking change on operators for zero payoff.)\n- **The hosted-dashboard upload may move to a separate optional package\n  (`@delegance/cadence-cloud`)** so you can skip Supabase entirely with\n  `npm install --omit=optional` today, and skip the dep entirely later. The\n  smoke workflow `.github/workflows/omit-optional-smoke.yml` verifies the\n  install-with-omit path on every PR.\n\nTrack future plans and open issues at https://github.com/axledbetter/cadence/issues\n\n## Contributing\n\nIssues and PRs welcome — https://github.com/axledbetter/cadence/issues. The pipeline literally builds itself; many features in this repo were implemented by autopilot running against autopilot ([DEMO.md](DEMO.md) walks through six self-eat PRs with cost trajectory $10 → ~$2.50). Read [CONTRIBUTING.md](CONTRIBUTING.md) if it exists, otherwise: clone, `npm install`, `npm test`, open a PR.\n\n## License\n\nMIT — see [LICENSE](LICENSE).\n","readmeFilename":"README.md"}