{"_id":"@dolhocodev/sigil","name":"@dolhocodev/sigil","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@dolhocodev/sigil","version":"0.1.0","description":"Your signature, sealed in history. A Git-native cryptographic agreement protocol.","keywords":["git","gpg","contracts","agreements","protocol","cryptography","signing"],"homepage":"https://dolhocodev.github.io/sigil","author":{"name":"dolhocodev","email":"dolhocodev@gmail.com","url":"https://github.com/dolhocodev"},"repository":{"type":"git","url":"git+https://github.com/dolhocodev/sigil.git"},"license":"AGPL-3.0","bin":{"sigil":"cli/sigil.js"},"main":"cli/sigil.js","scripts":{"test":"node cli/sigil.js --help","demo":"node cli/sigil.js demo"},"dependencies":{"chalk":"^5.3.0","commander":"^11.1.0","inquirer":"^9.2.12","uuid":"^9.0.0","ajv":"^8.12.0","marked":"^9.1.6","ora":"^7.0.1","boxen":"^7.1.1"},"engines":{"node":">=18.0.0"},"type":"module","gitHead":"e851080ee5a25aee04c6753732887821e3a91442","_id":"@dolhocodev/sigil@0.1.0","bugs":{"url":"https://github.com/dolhocodev/sigil/issues"},"_nodeVersion":"24.12.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-N29yptB5WO4//b3jnKlzh+/52+4l1cc+flnEMRaBgCHYe85V07+XOqzkCLcC5OCKSK+Z1xZsdt/M5ABL7XhyVw==","shasum":"c7693d9555128ce27b442de99831ddae96146a43","tarball":"https://registry.npmjs.org/@dolhocodev/sigil/-/sigil-0.1.0.tgz","fileCount":17,"unpackedSize":470389,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIG0KYQ1Yi431vOsQe2qOu0LLSoh4wSqvPsjo+Jp2QMDDAiAwUW2FaiQxECtxM2VoLDn3pw/5iQjFheK2bJx3qfnpog=="}]},"_npmUser":{"name":"dolhocodev","email":"dolhocodev@gmail.com"},"directories":{},"maintainers":[{"name":"dolhocodev","email":"dolhocodev@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/sigil_0.1.0_1776796570439_0.18647927314224466"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-21T18:36:10.259Z","0.1.0":"2026-04-21T18:36:10.624Z","modified":"2026-04-21T18:36:10.922Z"},"maintainers":[{"name":"dolhocodev","email":"dolhocodev@gmail.com"}],"description":"Your signature, sealed in history. A Git-native cryptographic agreement protocol.","homepage":"https://dolhocodev.github.io/sigil","keywords":["git","gpg","contracts","agreements","protocol","cryptography","signing"],"repository":{"type":"git","url":"git+https://github.com/dolhocodev/sigil.git"},"author":{"name":"dolhocodev","email":"dolhocodev@gmail.com","url":"https://github.com/dolhocodev"},"bugs":{"url":"https://github.com/dolhocodev/sigil/issues"},"license":"AGPL-3.0","readme":"<div align=\"center\">\n\n<br/>\n\n```\n  ◆ SIGIL\n```\n\n# Your signature, sealed in history.\n\n**A Git-native, GPG-verified agreement protocol.**  \nCryptographically bind freelance contracts, CLAs, SLAs, and milestones  \ndirectly into your Git history — no blockchain, no intermediaries, no trust required.\n\n<br/>\n\n[![Protocol](https://img.shields.io/badge/Protocol-Sigil%20v0.1.0-7C3AED?style=for-the-badge&logo=git)](https://github.com/dolhocodev/sigil)\n[![License](https://img.shields.io/badge/License-AGPL--3.0-A78BFA?style=for-the-badge)](LICENSE)\n[![npm](https://img.shields.io/badge/npm-%40dolhocodev%2Fsigil-6D28D9?style=for-the-badge&logo=npm)](https://npmjs.com/package/@dolhocodev/sigil)\n[![Agreements](https://img.shields.io/badge/Agreements%20in%20Registry-0-4C1D95?style=for-the-badge)](registry/index.json)\n[![Site](https://img.shields.io/badge/Docs-dolhocodev.github.io%2Fsigil-4C1D95?style=for-the-badge&logo=github)](https://dolhocodev.github.io/sigil)\n\n</div>\n\n---\n\n## The Insight\n\n**Git is already a blockchain.** Every commit is a SHA-256 hash that includes the previous state, author, and timestamp — forming a cryptographically immutable, distributed ledger. Nobody had used this as a protocol for human agreements.\n\n**Sigil** makes it one.\n\n```\nH(commit) = SHA256(tree ∥ parent ∥ author ∥ timestamp ∥ message)\n\nValid Agreement ⟺\n  ∀ party ∈ parties: verify_gpg(party.signature, SHA256(text)) = true\n  ∧ contentHash matches current file\n  ∧ commit is in the immutable git history\n```\n\n---\n\n## Why Git Beats Blockchain for Agreements\n\n| | Ethereum Smart Contract | Sigil |\n|---|---|---|\n| **Cost per agreement** | $0.01 – $50 | **$0** |\n| **Setup time** | Hours (wallet, gas, Solidity) | **30 seconds** |\n| **Infrastructure** | Blockchain nodes | **GitHub (free)** |\n| **Developer familiarity** | Low | **High (git + gpg)** |\n| **Offline access** | No | **Yes (local clone)** |\n| **Cryptographic proof** | ✅ | ✅ |\n| **Immutability** | ✅ | ✅ |\n| **Public auditability** | ✅ | ✅ |\n\n---\n\n## Quickstart\n\n### Install\n\n```bash\nnpm install -g @dolhocodev/sigil\n```\n\n### Create an Agreement\n\n```bash\nsigil init\n```\n\n```\n◆ SIGIL\nYour signature, sealed in history.\n\n? Agreement type:  💼  Freelance Contract\n? Agreement title: Frontend Development — Q2 2026\n? Party A:         alice@github.com\n? Party B:         bob@github.com\n? Description:     Full redesign of dashboard UI, 3 pages, Figma to code.\n? Expiry date:     2026-07-01\n\n✓ Agreement created!\n  ID:   a3f9c12e\n  Hash: 8d4b2f1a9c7e3b5d...\n  File: registry/agreements/a3f9c12e.md\n\nNext steps:\n  1. Share the agreement ID with the other party\n  2. Each party runs: sigil sign a3f9c12e\n  3. Verify with:    sigil verify a3f9c12e\n  4. Publish with:   sigil publish a3f9c12e\n```\n\n### Sign (each party, on their own machine)\n\n```bash\nsigil sign a3f9c12e\n# Uses your GPG key — the same one you use for git commits\n```\n\n### Verify\n\n```bash\nsigil verify a3f9c12e\n```\n\n```\n◆ a3f9c12e  Frontend Development — Q2 2026\n  Type:    freelance\n  Parties: alice@github.com ↔ bob@github.com\n  Status:  ██ ACTIVE ██\n  Hash:    ✓ Verified (untampered)\n  Sigs:    ✓ 2 signature(s): alice.asc, bob.asc\n  Expires: 2026-07-01\n```\n\n### Publish to the Public Registry\n\n```bash\nsigil publish a3f9c12e\n# → git commit + git push → PR to sigil registry\n```\n\n---\n\n## Agreement Types\n\n| Template | Use Case | Command |\n|----------|----------|---------| \n| `freelance` | Client ↔ contractor work agreement | `sigil init --template freelance` |\n| `cla` | Contributor License Agreement for OSS | `sigil init --template cla` |\n| `sla` | Service Level Agreement between teams | `sigil init --template sla` |\n| `milestone` | Delivery commitments with success criteria | `sigil init --template milestone` |\n| `split` | Revenue sharing between collaborators | `sigil init --template split` |\n\n---\n\n## How It Works\n\n```\nAlice                          Sigil Registry (GitHub)             Bob\n  │                                     │                           │\n  │── sigil init ──────────────────────►│                           │\n  │   Creates agreement file            │                           │\n  │   Computes SHA-256 content hash     │                           │\n  │                                     │                           │\n  │── sigil sign ───────────────────────┤                           │\n  │   GPG-signs the content hash        │                           │\n  │                                     │◄────── sigil sign ────────│\n  │                                     │   Bob signs independently  │\n  │                                     │                           │\n  │── sigil publish ───────────────────►│                           │\n  │   git commit + PR to registry       │                           │\n  │                                     │                           │\n  │             GitHub Actions          │                           │\n  │             auto-verifies all sigs  │                           │\n  │◄── ✅ Verified ─────────────────────│──── ✅ Verified ──────────►│\n  │                                     │                           │\n  │   BOTH PARTIES HOLD A LOCAL CLONE — zero dependency on GitHub  │\n```\n\n### Security Model\n\n- **Content hash** anchors the agreement text — any modification breaks verification instantly\n- **GPG signatures** prove each party's consent cryptographically\n- **Git history** provides an immutable, timestamped audit trail\n- **Distributed clones** mean the agreement survives even if GitHub goes offline\n\n---\n\n## All Commands\n\n```bash\nsigil init [--template <type>]     # Create a new agreement (interactive)\nsigil sign <id> [--key <keyid>]    # Sign with your GPG key\nsigil verify [id]                   # Verify integrity and signatures\nsigil list                          # List all agreements in registry\nsigil publish <id>                  # Commit & push to registry\nsigil demo                          # Show usage guide\nsigil --help                        # Full help\n```\n\n---\n\n## Use Sigil for Your Open-Source Project\n\nReplace your PDF CLA with a Sigil agreement:\n\n```markdown\n## Contributing\n\nWe use [Sigil](https://github.com/dolhocodev/sigil) for contributor agreements.\n\nBefore your first PR is merged, run:\n\\`\\`\\`bash\nnpx @dolhocodev/sigil init --template cla --party your@email.com --party project@org.com\n\\`\\`\\`\n```\n\n---\n\n## Repository Structure\n\n```\nsigil/\n├── registry/\n│   ├── agreements/          ← All agreement documents (.md)\n│   │   └── {id}.md\n│   ├── signatures/          ← GPG signatures per agreement\n│   │   └── {id}/\n│   │       ├── party-a.asc\n│   │       └── party-b.asc\n│   └── index.json           ← Machine-readable registry index\n├── templates/               ← Agreement templates\n│   ├── freelance.md\n│   ├── cla.md\n│   ├── sla.md\n│   ├── milestone.md\n│   └── split.md\n├── schema/\n│   └── agreement.schema.json ← JSON Schema for validation\n├── cli/\n│   └── sigil.js             ← CLI entry point\n└── .github/\n    └── workflows/\n        └── verify.yml       ← Auto-verification on every PR\n```\n\n---\n\n## Contributing\n\n1. Fork the repository\n2. Create your agreement: `sigil init`\n3. Sign it: `sigil sign <id>`\n4. Open a PR — GitHub Actions will auto-verify\n\nAll protocol changes are governed by a Sigil milestone agreement between maintainers.\n\n---\n\n## Roadmap\n\n- [x] Core CLI (`init`, `sign`, `verify`, `publish`, `list`)\n- [x] 5 agreement templates\n- [x] GitHub Actions auto-verification\n- [x] Hash-only fallback (no GPG required)\n- [ ] `sigil dispute` — on-chain dispute protocol\n- [ ] `sigil status <id> fulfilled` — mark agreements complete\n- [ ] Web UI for the public registry\n- [ ] GitHub App integration\n- [ ] Webhook support (agreement signed → trigger CI)\n- [ ] `sigil score` — reputation score based on fulfilled agreements\n- [ ] Private registry support (Sigil Pro)\n- [ ] Legal PDF export with notarization\n\n---\n\n## License\n\nAGPL-3.0 © [dolhocodev](https://github.com/dolhocodev) and Sigil Protocol Contributors\n\n---\n\n<div align=\"center\">\n\n**Sigil** — *Ancient word. Cryptographic proof.*\n\n[Registry](registry/index.json) · [Templates](templates/) · [Schema](schema/) · [CLI](cli/sigil.js) · [Docs](https://dolhocodev.github.io/sigil)\n\n</div>\n","readmeFilename":"README.md","_rev":"1-dad5cfd726d28fcb432893908737c2a4"}