{"_id":"@divenire990/local-tarot-draw","name":"@divenire990/local-tarot-draw","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@divenire990/local-tarot-draw","version":"0.1.0","description":"Lightweight CLI installer and launcher for Local Tarot Draw (Windows EXE with SHA-256 verification)","type":"module","bin":{"local-tarot-draw":"bin/local-tarot-draw.mjs"},"engines":{"node":">=20.0.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/divenire990/local-tarot-draw.git","directory":"packages/cli"},"homepage":"https://github.com/divenire990/local-tarot-draw#readme","bugs":{"url":"https://github.com/divenire990/local-tarot-draw/issues"},"author":{"name":"Divenire"},"license":"MIT","scripts":{"test":"node --test test/**/*.test.mjs"},"_id":"@divenire990/local-tarot-draw@0.1.0","gitHead":"c4bdd4be472fc7de6b9afadccbdbe844efab6f61","_nodeVersion":"24.19.0","_npmVersion":"11.5.2","dist":{"integrity":"sha512-OYeCOAdKKtjMxRFc/vAcvdiU4WZty4iIepant52LlosSU1M26u47kNf7kGgAamnIhz8pTD1uC1It8rMW/c3jdA==","shasum":"59dce0dd279643d5c3a142806c8638a159bde661","tarball":"https://registry.npmjs.org/@divenire990/local-tarot-draw/-/local-tarot-draw-0.1.0.tgz","fileCount":11,"unpackedSize":23450,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIFI4nawu7yzGGpDOqjg2AEwPFFC4kREGjFMWt0zJ5sinAiBwl5jjUGoP1S8inAfNOZEIXVGBhl6B/z5g+osU9r8Hxw=="}]},"_npmUser":{"name":"divenire990","email":"zhihaocai2023@163.com"},"directories":{},"maintainers":[{"name":"divenire990","email":"zhihaocai2023@163.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/local-tarot-draw_0.1.0_1788568684518_0.7674241136574946"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-05T00:38:04.331Z","0.1.0":"2026-09-05T00:38:04.653Z","modified":"2026-09-05T00:38:04.860Z"},"maintainers":[{"name":"divenire990","email":"zhihaocai2023@163.com"}],"description":"Lightweight CLI installer and launcher for Local Tarot Draw (Windows EXE with SHA-256 verification)","homepage":"https://github.com/divenire990/local-tarot-draw#readme","repository":{"type":"git","url":"git+https://github.com/divenire990/local-tarot-draw.git","directory":"packages/cli"},"author":{"name":"Divenire"},"bugs":{"url":"https://github.com/divenire990/local-tarot-draw/issues"},"license":"MIT","readme":"# @divenire990/local-tarot-draw\n\nLightweight, secure, and zero-runtime-dependency CLI launcher for **Local Tarot Draw (本地塔罗抽牌器)**.\n\nFetches the latest official GitHub Release for Windows, validates asset integrity against official SHA-256 checksums, and launches the desktop installer safely.\n\n---\n\n## 🚀 Quickstart\n\nRun directly without installation via `npx`:\n\n```bash\nnpx @divenire990/local-tarot-draw\n```\n\nOr install globally:\n\n```bash\nnpm install -g @divenire990/local-tarot-draw\nlocal-tarot-draw\n```\n\n---\n\n## ⚙️ Options & Usage\n\n```text\nUsage: local-tarot-draw [options]\n\nOptions:\n  -y, --yes            Skip launch confirmation after SHA-256 verification\n  -d, --download-only  Download and verify installer without launching\n  -o, --output-dir     Directory to store the verified installer\n  -v, --version        Display CLI version\n  -h, --help           Display this help message\n```\n\n### Examples\n\n- **Standard interactive workflow** (download -> verify SHA-256 -> prompt to launch):\n  ```bash\n  npx @divenire990/local-tarot-draw\n  ```\n- **Non-interactive unattended run**:\n  ```bash\n  npx @divenire990/local-tarot-draw --yes\n  ```\n- **Download and verify only** (e.g. for inspection or manual installation):\n  ```bash\n  npx @divenire990/local-tarot-draw --download-only\n  ```\n- **Specify download target directory**:\n  ```bash\n  npx @divenire990/local-tarot-draw --download-only -o ./downloads\n  ```\n\n---\n\n## 🔒 Security Architecture & Guarantees\n\n1. **Zero Runtime Dependencies**: Written entirely using Node.js built-in modules (`node:crypto`, `node:fs`, `node:https`, `node:child_process`, `node:os`).\n2. **No Postinstall Scripts**: The package never runs postinstall scripts. Network queries and file writes occur exclusively during explicit user execution.\n3. **Strict URL Validation**:\n   - Downloads are strictly restricted to official GitHub Release assets from `divenire990/local-tarot-draw`.\n   - Only `https:` protocol and whitelisted GitHub hosts (`github.com`, `objects.githubusercontent.com`, `github-releases.githubusercontent.com`) are accepted.\n4. **Mandatory SHA-256 Checksum Verification**:\n   - The installer is streamed to a secure isolated temporary directory.\n   - The SHA-256 checksum is computed during download and verified against the official `.sha256` asset published in the GitHub Release.\n   - If verification fails, the installer is immediately deleted and execution is halted. It will **never** be executed upon checksum mismatch.\n5. **Safe Process Spawning**:\n   - Launching the installer is executed without `shell: true`, completely avoiding shell interpolation and command injection risks.\n   - Interactive confirmation is requested before launching unless `--yes` is specified.\n\n---\n\n## 💻 Platform Support\n\n- **Windows**: Full automated download, SHA-256 verification, and installer launch.\n- **macOS / Linux**: The desktop installer (`.exe`) is built for Windows. On non-Windows platforms, the CLI provides helpful instructions and direct links to GitHub Releases and local web setup.\n\n---\n\n## 📦 Direct Release Download Alternative\n\nIf you prefer not to use npm or Node.js, download the installer and verify checksums manually:\n\n- GitHub Releases: [https://github.com/divenire990/local-tarot-draw/releases](https://github.com/divenire990/local-tarot-draw/releases)\n- Repository: [https://github.com/divenire990/local-tarot-draw](https://github.com/divenire990/local-tarot-draw)\n\n---\n\n## 📜 License\n\n[MIT](LICENSE) © 2026 Divenire\n","readmeFilename":"README.md","_rev":"1-01de3e7f06b97638ec883a3e57efe1af"}