{"_id":"@homepages/template-cli","_rev":"77-8c6e3d44650c89c5049a34fc38887004","name":"@homepages/template-cli","dist-tags":{"dev":"2.2.0-dev-20260731213520","latest":"10.0.0"},"versions":{"0.1.0":{"name":"@homepages/template-cli","version":"0.1.0","license":"UNLICENSED","_id":"@homepages/template-cli@0.1.0","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"0ce10783d18b3979cc9a432a1ee248bd7cbf1a32","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-0.1.0.tgz","fileCount":110,"integrity":"sha512-EJhxuNCAtxe3cHozfcbisCT0kRsq12r5AwLyKzmKZrlOW6z+trkzTrRqHhk0SJhTGDqKGzlirMugIyno8qNCmg==","signatures":[{"sig":"MEUCIBGeKGaX2vOEpceabgFGiXfZ5tUx0t5ChilakppPjlcAAiEA7cmFSJJ9y//F2+g9A4mo10x5ngjRC0VfKjCkVNAEboA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":492566},"type":"module","engines":{"node":">=20.0.0"},"exports":{"./package.json":"./package.json"},"gitHead":"cc7a7c88efbb8a86289647625ffadcd30ab13cef","scripts":{"lint":"eslint .","test":"node --import tsx --test 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"travisfalk","email":"falk.travis@gmail.com"},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"10.9.7","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.22.2","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^9.39.4","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","react-dom":"^19.0.0","@eslint/js":"^9.39.4","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","@types/semver":"^7.5.8","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@homepages/template-kit":"*","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"*"},"peerDependencies":{"@homepages/template-kit":">=0.9.0-0 <0.10.0"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer.","_npmOperationalInternal":{"tmp":"tmp/template-cli_0.1.0_1784503892349_0.9499692704386431","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"0.1.1":{"name":"@homepages/template-cli","version":"0.1.1","license":"UNLICENSED","_id":"@homepages/template-cli@0.1.1","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"09eb0fd6873d4d731c7effbe39b06f5428749d1d","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-0.1.1.tgz","fileCount":111,"integrity":"sha512-nUoV0rvHd483o+3Tv3aoZeqfkk3brkJjgVMwmHMblNBnq2iSRW/uVEpqUZdFVYeQY9W6phdnQ4a9YoRI0TARMw==","signatures":[{"sig":"MEYCIQCpXngbhB+O/8heJShhv4olVnyRe+vhea9K63szAhP5PgIhALWeu5vBYhnLCwmhlnySuA3ishuPMELMy+6+n5vztNaH","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":497038},"type":"module","engines":{"node":">=20.0.0"},"exports":{"./package.json":"./package.json"},"gitHead":"4cf2860882897aef0774794e94b2da916906d302","scripts":{"lint":"eslint .","test":"node --import tsx --test 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^9.39.4","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","react-dom":"^19.0.0","@eslint/js":"^9.39.4","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","@types/semver":"^7.5.8","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@homepages/template-kit":"*","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"*"},"peerDependencies":{"@homepages/template-kit":">=0.9.0-0 <0.10.0"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer.","_npmOperationalInternal":{"tmp":"tmp/template-cli_0.1.1_1784510721367_0.9150120347878876","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"0.1.2":{"name":"@homepages/template-cli","version":"0.1.2","license":"UNLICENSED","_id":"@homepages/template-cli@0.1.2","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"81860d7206d70647872047985fb394cfd7b07fba","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-0.1.2.tgz","fileCount":113,"integrity":"sha512-JtXZkvt9Ik+264fus4CamdC9Ius4hmeE6zVIZ0uRsB8vfOagalEGaCo8Scv1sQ5PANIHr95qylnih9/6WhTRMg==","signatures":[{"sig":"MEUCIEeTAOyQlI2haoKkC6bfW50YWSmEwZvoKGRwq388TjUtAiEA9jgE2/NklehpCndj8yRdEktbaclKnGYfnswTHf6f9Kc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":771853},"type":"module","engines":{"node":">=20.0.0"},"exports":{"./package.json":"./package.json"},"gitHead":"ba7a4919a548cbb29f7faf0d694f7e1f2509f9ef","scripts":{"lint":"eslint .","test":"node --import tsx --test 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^9.39.4","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^9.39.4","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"*","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"*"},"peerDependencies":{"@homepages/template-kit":">=0.9.1-0 <0.10.0"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_0.1.2_1784593443151_0.5478018963414168","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"0.2.0":{"name":"@homepages/template-cli","version":"0.2.0","license":"UNLICENSED","_id":"@homepages/template-cli@0.2.0","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"921099763e32be514f5e11af5f32b709ac1558bd","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-0.2.0.tgz","fileCount":115,"integrity":"sha512-Ip0wGMbaPL0SGcka3uebBEl09dvb5eE+ON2QOrhvv8cgf+ZYW6RJU/z6qTIM3p/xGiu9Bfq5wykMKcafRfcL5A==","signatures":[{"sig":"MEUCIQDAN6rL/bxGyebmnuEu0HK1k87jlDqR2+fX0cbzMrf9ngIgUR/TaPECpX0dysHdOQtBdH8q8LafYi1icu0S2Z2FF88=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":798166},"type":"module","engines":{"node":">=20.0.0"},"exports":{"./package.json":"./package.json"},"gitHead":"a7faec4d0615ab1c0ad19bf765df3653338c4c18","scripts":{"lint":"eslint .","test":"node --import tsx --test 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^9.39.4","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^9.39.4","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"*","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"*"},"peerDependencies":{"@homepages/template-kit":">=0.10.0-0 <0.11.0"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_0.2.0_1784721614167_0.6716284101535714","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"0.2.1-dev-20260722152325":{"name":"@homepages/template-cli","version":"0.2.1-dev-20260722152325","license":"UNLICENSED","_id":"@homepages/template-cli@0.2.1-dev-20260722152325","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"baabed064e583952f6121528c542db7fede4d963","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-0.2.1-dev-20260722152325.tgz","fileCount":115,"integrity":"sha512-7UO82mdpaYLyEiMvgh6DDsn7mLZHTghbuFgV8mH09323JRO7GQHbB436H7uJ3P2f9gV6LAmLR9igu7sNlhufVw==","signatures":[{"sig":"MEQCID0TekaWoM9gbYHGBwCcQREMmwJ5L4/i2sZ4GackChXkAiBGUeQNy1gNnKjYdElc0dlfvEjcv8XVlFVSmNo8Eid0qQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":800736},"type":"module","engines":{"node":">=20.0.0"},"exports":{"./package.json":"./package.json"},"scripts":{"lint":"eslint .","test":"node --import tsx --test 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"travisfalk","email":"falk.travis@gmail.com"},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"10.9.7","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.22.2","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^9.39.4","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^9.39.4","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"0.10.1-dev-20260722152325","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"*"},"peerDependencies":{"@homepages/template-kit":"0.10.1-dev-20260722152325"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_0.2.1-dev-20260722152325_1784733954914_0.9760729260115493","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"0.2.1":{"name":"@homepages/template-cli","version":"0.2.1","license":"UNLICENSED","_id":"@homepages/template-cli@0.2.1","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"4853ed6086f26ff44f37a7acd134415ddb09a80a","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-0.2.1.tgz","fileCount":115,"integrity":"sha512-qg6PAO8RvmczSCAqpdBI9cymLZxq9sq6+Tl57VPPt2tjPEe0TotOcL5dsNoTVUEweKVCBT1amgREsOfYiYSgnw==","signatures":[{"sig":"MEUCIAmJ3eqT80ewGkitZo6+DOBrDHupFqmR9q95nx3LiCWQAiEAwEAyiH28TFpvWcYA4VO36FJK5pCPbOu3Fmyb3MAyX9E=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":800495},"type":"module","engines":{"node":">=20.0.0"},"exports":{"./package.json":"./package.json"},"gitHead":"65983d3d0323c0eb1c95344d4d12b40d4a62b033","scripts":{"lint":"eslint .","test":"node --import tsx --test 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^9.39.4","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^9.39.4","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"*","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"*"},"peerDependencies":{"@homepages/template-kit":">=0.10.0-0 <0.11.0"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_0.2.1_1784735370746_0.06713727231453648","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"1.0.0-dev-20260722183710":{"name":"@homepages/template-cli","version":"1.0.0-dev-20260722183710","license":"UNLICENSED","_id":"@homepages/template-cli@1.0.0-dev-20260722183710","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"80d97eebdf5e62082a7d935b870c6fe642c641ca","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-1.0.0-dev-20260722183710.tgz","fileCount":116,"integrity":"sha512-asAelp5cdvqNm0/cpixrCU4cW8NDw+6elPTYtVP0oTo7vjO6oNb4IHOYpBQoVTtTdWaf1HuajhSu59ZUctIxhg==","signatures":[{"sig":"MEUCICBqkH+t2MBX/yS6sn/LPh/+8xppKve+dhW5Asq/yr53AiEAzQOM3LT3zB/H3mbJqPO8MteEqbov5m4Nrm/ZKy6tTUo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":804927},"type":"module","engines":{"node":">=20.0.0"},"exports":{"./package.json":"./package.json"},"gitHead":"458392dcf8b9be72e35bd561b444b1c9250f443a","scripts":{"lint":"eslint .","test":"node --import tsx --test 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^9.39.4","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^9.39.4","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"0.11.0-dev-20260722183710","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"1.0.0-dev-20260722183710"},"peerDependencies":{"@homepages/template-kit":"0.11.0-dev-20260722183710"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_1.0.0-dev-20260722183710_1784745437803_0.8796458291894622","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"1.0.0-dev-20260722191436":{"name":"@homepages/template-cli","version":"1.0.0-dev-20260722191436","license":"UNLICENSED","_id":"@homepages/template-cli@1.0.0-dev-20260722191436","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"a64932b29dac0b9c1a5cbb0300e3b6ef20495510","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-1.0.0-dev-20260722191436.tgz","fileCount":116,"integrity":"sha512-n7IGvwGciLLxXBpmnsdChZRXfbMyF/V42sg6xf2GCvm21gk5ygw94DwS1zThefA/8Q1S5Wb7pYz/89fO/XSb3Q==","signatures":[{"sig":"MEUCIQD3ESbB8Og6me6vYShy5ws6PPWrC+bggVi/YA12+njcGAIgH7LV20hSqy1sMKkBj/pak+RiIaNneuo7htNTcq39I48=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":804960},"type":"module","engines":{"node":">=20.0.0"},"exports":{"./package.json":"./package.json"},"gitHead":"5fddd9960264da5b0e3df7f38b9560ceaffec5e8","scripts":{"lint":"eslint .","test":"node --import tsx --test 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^9.39.4","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^9.39.4","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"0.11.0-dev-20260722191436","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"1.0.0-dev-20260722191436"},"peerDependencies":{"@homepages/template-kit":"0.11.0-dev-20260722191436"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_1.0.0-dev-20260722191436_1784747683617_0.7604790828301771","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"1.0.0-dev-20260722193254":{"name":"@homepages/template-cli","version":"1.0.0-dev-20260722193254","license":"UNLICENSED","_id":"@homepages/template-cli@1.0.0-dev-20260722193254","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"03da880107398e3708c8a59e150e7700d929c2c0","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-1.0.0-dev-20260722193254.tgz","fileCount":116,"integrity":"sha512-x7mGtzAHciKiKRUICfZCDERYj94PVf4Um8rQ0sOywJDOPVvJCc45/0kXZfpLPHL7r7K6TX5m5hYBBbaMpzPt0g==","signatures":[{"sig":"MEQCIA2qXCaVj7hX7C2oEETouqgkVHV1YjYdqre/J8gFazDhAiA44dQh6CAR1GO5MxyxywzJJTdfiBRTZQP/WhzY6rPkEQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":804960},"type":"module","engines":{"node":">=20.0.0"},"exports":{"./package.json":"./package.json"},"gitHead":"f73a1b3a0525bcb09d392833e641197f7072f830","scripts":{"lint":"eslint .","test":"node --import tsx --test 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^9.39.4","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^9.39.4","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"0.11.0-dev-20260722193254","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"1.0.0-dev-20260722193254"},"peerDependencies":{"@homepages/template-kit":"0.11.0-dev-20260722193254"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_1.0.0-dev-20260722193254_1784748783289_0.9821276901301572","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"0.2.2":{"name":"@homepages/template-cli","version":"0.2.2","license":"UNLICENSED","_id":"@homepages/template-cli@0.2.2","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"bdfd0886289919623b81594b8bda85a31017e78d","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-0.2.2.tgz","fileCount":117,"integrity":"sha512-GpZQJb1tF1sd8b8jH1ZfDuD2hhHWM9ASWsOlHE5qO69JUThXlGE/rGvLHJSqyvYUkEtohdE0dRs/eF5ZriIi5w==","signatures":[{"sig":"MEYCIQDSzoaonPr0pQUHQt+HOOkjIqlcZJGto7SKT0R9u8BtewIhAJ1cwk1plRW0tqMILGUn1FlWurRkTGl9BpkzUaJUVmts","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":813573},"type":"module","engines":{"node":">=20.0.0"},"exports":{"./package.json":"./package.json"},"gitHead":"2e2860f60927ff1851bfdb0ba4dbf7191bf4f01c","scripts":{"lint":"eslint .","test":"node --import tsx --test 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^9.39.4","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^9.39.4","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"*","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"*"},"peerDependencies":{"@homepages/template-kit":">=0.10.0-0 <0.13.0"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_0.2.2_1784764496261_0.06306346233530169","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"0.3.0":{"name":"@homepages/template-cli","version":"0.3.0","license":"UNLICENSED","_id":"@homepages/template-cli@0.3.0","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"b52fcb4f887d11758b779bb4e988c9932a1d5a99","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-0.3.0.tgz","fileCount":117,"integrity":"sha512-6LdjRAUwOqVjk9oDglsbLyzV34DliXaKLr7Q4DdgEmNSb0OBhjPhKRfp3dW87slz+SJY3gZufCZpCM2+6HT74w==","signatures":[{"sig":"MEUCIQD88ZSRY+MBffSD4HGfiQTLzt5m6YpGL+YdJaM8kFWNRgIgQgozdVar54IafdcskNbUKUSi7aVyB1MBFXdF+2W0Svw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":822977},"type":"module","engines":{"node":">=20.0.0"},"exports":{"./package.json":"./package.json"},"gitHead":"bdc8c25411814c86ee4c01e11e6f76c7c31e6403","scripts":{"lint":"eslint .","test":"node --import tsx --test 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^9.39.4","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^9.39.4","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"*","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"*"},"peerDependencies":{"@homepages/template-kit":">=0.10.0-0 <0.13.0"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_0.3.0_1784771379651_0.5097314068593639","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"1.0.0":{"name":"@homepages/template-cli","version":"1.0.0","license":"UNLICENSED","_id":"@homepages/template-cli@1.0.0","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"6121e2f3803654fc4fd2ae62c857a9e12bbda3f8","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-1.0.0.tgz","fileCount":117,"integrity":"sha512-KZimat7jU56Dct7o4mHO+ey5ae3zqOfUCovyye2fZWe1ClPzPcY0FS9zzSX3O+ERdor/FxhrPOfRdusyyOH4Cg==","signatures":[{"sig":"MEUCIQCFPR11jEWbGCfBHPvhpMhsqpqgOz8FAAw6jMeIch5I6AIgBswkIVPKkZ7P2gArBaEkTRwIfUQheGboa/vHD4AJ2iQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":823567},"type":"module","engines":{"node":">=20.0.0"},"exports":{"./package.json":"./package.json"},"gitHead":"0f1f129edb490ce6ea7142263b8a791e1edac718","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^9.39.4","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^9.39.4","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"*","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"*"},"peerDependencies":{"@homepages/template-kit":">=0.10.0-0 <2.0.0"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_1.0.0_1784816314003_0.14561078662430726","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260724195104":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260724195104","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260724195104","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"5a0937b40b405b9d8bf13c90dd26fa728a62e635","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260724195104.tgz","fileCount":117,"integrity":"sha512-WU1deV/JwDI0CQDVhCGLCTH6yTOeGixCYTEXOaIYD2FcUVEVn2l1o7ArX6im2Ghsr+3XFsop6Upt1XfmFf0AWQ==","signatures":[{"sig":"MEQCIEJeL59rNHQQQ+In6xVbH8Qnt2MwDioPslQOVI9e4yamAiB/Zjx0jkZrlN6xTpBep+lNl8LVrrQCE6RKhCmEkVTscA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":825274},"type":"module","engines":{"node":">=20.0.0"},"exports":{"./package.json":"./package.json"},"gitHead":"32be9f79e06efad25aff50e3d8f4833cdbe7a1a6","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^9.39.4","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^9.39.4","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260724195104","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260724195104"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260724195104"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260724195104_1784922672518_0.1918310409793711","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260725021840":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260725021840","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260725021840","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"a1150b9ab37c457d5d09da7497db7012aed28d63","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260725021840.tgz","fileCount":119,"integrity":"sha512-6QZYMse6ZjBsf/388ogTqTN4BcSXYXzdpyO84JRn+VY01lQLZds5ZOxvXnhS2vK/cUNpq/JbTqTxObTGOex1ZA==","signatures":[{"sig":"MEYCIQDfYZO7IHPz2ZaBzyybR0RlP01PzJrTeu261y7sea17ZAIhAMXmi42fOQtABFpPpYv3rl6Eejeg9i37E42RARU5ehwq","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":833248},"type":"module","engines":{"node":">=20.0.0"},"exports":{"./package.json":"./package.json"},"gitHead":"6b8bfc7d043ed1b26b6a3f7fc1358af4e5b8171a","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260725021840","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260725021840"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260725021840"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260725021840_1784945929264_0.02361716887471421","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260725222034":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260725222034","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260725222034","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"c95907bc69bbbf067c57394db4d09574079ffa4d","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260725222034.tgz","fileCount":121,"integrity":"sha512-QVRWASSR4I+RIiPKV98roLelcoLQYfvil2mW+7khuCzIwZyHWHkm0FrNKGKoiMhGPT+WyJRWx2r3icLuMDwKTA==","signatures":[{"sig":"MEQCICsVcIf1+Yc/gNaBFaO83Q/TpmxoJ/9YP02spXWOCOT6AiBzMQql1oX3ZkpRDFbYA33RLHjrDTh8NCjLcLgkjtEDAw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":848995},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"72c3f34fd4b911518f845e17d35a7e122be87755","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260725222034","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260725222034"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260725222034"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260725222034_1785018045261_0.83079645776833","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260725233009":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260725233009","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260725233009","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"b7d89f84a2528ba083fd6c4f40ab319572d286e0","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260725233009.tgz","fileCount":121,"integrity":"sha512-GbhcwSKhGsaOqZXlpPpccGnt0c8m4qVoNs0KthgDIB6tbc9WrmH7Ljydp1ZxAH1RJudgKz7HeKQ/vI6MlhANRw==","signatures":[{"sig":"MEUCIQDS9UMXx250E4XKV2r5UhjR/y44PpbpGGzEul6pHh7pTgIgANtTf74V2TcnoQuIxjF2uAl4xQN0fGhQEPOldCL+BTs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":850624},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"e4480dbade80b7d384ed897bd67da76a64901206","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260725233009","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260725233009"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260725233009"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260725233009_1785022219703_0.56058614035074","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260726004823":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260726004823","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260726004823","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"3418690e4c8ef7d90eed2d6d1f4a98a2849e1d62","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260726004823.tgz","fileCount":121,"integrity":"sha512-jMytnH3KS5ejU4pRrnrlijUiQvkIwRAat5psps8sWy/ArysP7dKtrOvD2p2nUHB4eRt5MQWVPxxNhNq9vXBB0Q==","signatures":[{"sig":"MEUCIQDbAwTsAkPGGeI8A3rpZ2M/ijbb9gRdkVLeafBfDxPA0AIgCbYjcIw3vjIfZ019GW/cnYTJegoWiGGCeTiLJ0KOFPM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":848353},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"6583d2da242f04526970a04175550500b993be7d","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260726004823","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260726004823"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260726004823"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260726004823_1785026915215_0.07837872109825295","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260726015619":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260726015619","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260726015619","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"bedd24a2e1fb64f4d6380088b6af70ffddb950ac","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260726015619.tgz","fileCount":125,"integrity":"sha512-K21z6fw4iXvgboguuztBH97x6vliqAp85xbkRST5jXsRvnZTD7OUQ3x4Y2TAj36lTL3TsgktUqF9WvfOWmy9gg==","signatures":[{"sig":"MEUCIQCHJFYBQaUSRoPolkwYxRvgFKdHjevHNQROOFurQ15mtwIgEC06W8HojZmgtd4PAGASK8aO6S+8rEOxKOZ3oG+l8dw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":864729},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"be39d8881312a7febec621fac104391a8b208834","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260726015619","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260726015619"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260726015619"},"optionalDependencies":{"sharp":"0.34.5"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260726015619_1785030991501_0.14288315202921154","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. Pinned to exactly the version intake-pipeline uses so the image ladder derives identically; when sharp is absent the deriver degrades to responsive: null and passes the master through.","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260726022255":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260726022255","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260726022255","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"df4d57e48e3b064fc4f88593eb6ecaa49ba84681","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260726022255.tgz","fileCount":125,"integrity":"sha512-hXnzsepKtLF/8fxwjJZc/rUyynYFC/Y6SCxcCkAj/pvXzwUlaepq1+/rg1jM88rJYW3N/PW4IlP085Q1Y6wcDw==","signatures":[{"sig":"MEUCIQCNr7YbO/avwyzXTFz4WPXlPgSvsdgMjJgXHwx+WBB5JwIgclUXupeKO8g2cZuh1uoPUnRXY0msZZAKOkuWA7o+oCY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":864729},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"be39d8881312a7febec621fac104391a8b208834","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260726022255","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260726022255"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260726022255"},"optionalDependencies":{"sharp":"0.34.5"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260726022255_1785032586355_0.9773606212847732","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. Pinned to exactly the version intake-pipeline uses so the image ladder derives identically; when sharp is absent the deriver degrades to responsive: null and passes the master through.","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260726031323":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260726031323","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260726031323","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"927f1ab98536fb48511285a9ce060dc6f7fb15ca","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260726031323.tgz","fileCount":125,"integrity":"sha512-udXfo3zPWM8ib0/ekbR81m2q7SXHfht7cVDwqIaWOrvW0SqSNzpghx0PptaNgjc2xepfrMpLxrxKPiQTG7K+mw==","signatures":[{"sig":"MEUCICOEyOnAzJjsQbkDB7unnAFBiuRDpArd1fndo+bDjL+4AiEA0WuBj/sFT7Uys7yJlu70jk4mX9P4WRhs+kadwchNJAc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":864762},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"f92dd52c3e39e6f7edbf6d01be79fe9f56119ee4","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260726031323","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260726031323"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260726031323"},"optionalDependencies":{"sharp":"0.34.5"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260726031323_1785035614479_0.42244801548247124","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. Pinned to exactly the version intake-pipeline uses so the image ladder derives identically; when sharp is absent the deriver degrades to responsive: null and passes the master through.","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260726112057":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260726112057","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260726112057","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"601261ad6146f964225267086aa6c8209e83fa83","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260726112057.tgz","fileCount":125,"integrity":"sha512-NA1KmbwTPQ7aICB1unoKvcM5X43RF25t4fgON+XDnmoS5QVF95jBM5d+QVHfxmrGAZHsV9w88WLOuBBbdfkr/g==","signatures":[{"sig":"MEUCIQC1W7S+oFlFgp5TTg0Uz83OuD5LbvrBuRZO3HN5t0yHYgIgHmP/uRHVmDdgcyVW2nwpLQfihjXGP18sTtccS7S9Wbk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":866308},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"aedd86ad77bffa425cdefbe3f648e2fe5b2dbe3e","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260726112057","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260726112057"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260726112057"},"optionalDependencies":{"sharp":"0.34.5"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260726112057_1785064869339_0.9098393013249602","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. Pinned to exactly the version intake-pipeline uses so the image ladder derives identically; when sharp is absent the deriver degrades to responsive: null and passes the master through.","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260726122014":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260726122014","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260726122014","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"34b18092a570a6d3440a1336dcbb652791ec02cd","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260726122014.tgz","fileCount":125,"integrity":"sha512-/WwZdWihDfhq5243ZOh4Gg25QTN9j7mVbJzkI6RLCOGWbJj3bojP+m/6j2aLRpR6FS+G/skxb/ijPezOTHSNZg==","signatures":[{"sig":"MEUCIDlg+jUZXMt3NGHzejTs3NvBVv48zMZVexBWLTTVHZd1AiEA72gIDNArpUUxUa2g/61RvAKM2agSN1EBf8frrZPGMEQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":866341},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"f744e8345b8841c0500bdd52b3683be594ee80f5","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260726122014","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260726122014"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260726122014"},"optionalDependencies":{"sharp":"0.34.5"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260726122014_1785068425496_0.9920746074010014","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. Pinned to exactly the version intake-pipeline uses so the image ladder derives identically; when sharp is absent the deriver degrades to responsive: null and passes the master through.","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260726122601":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260726122601","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260726122601","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"06ab259d71877de6d70fdd7b87130a69c865130d","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260726122601.tgz","fileCount":127,"integrity":"sha512-0oWyntgnCX1wmcblXHheV40rJvmex4XjI3qwolEpRpnYUweojfMu/xowgR07l0B1EZiOfeG/ZWiSJkf07dKPAw==","signatures":[{"sig":"MEUCIHsGIZj4CctrQr2hUM3C4r9oz3ntQLIbLNffIowhDSqQAiEA0hp7hwDt8ahXeZP5mMdyYmTzzu0BP6v/LQkKe7bnZSs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":873697},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"b1ead07b40a843e69a10a289164fba3693864a1a","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260726122601","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260726122601"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260726122601"},"optionalDependencies":{"sharp":"0.34.5"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260726122601_1785068772938_0.9829249099689634","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. Pinned to exactly the version intake-pipeline uses so the image ladder derives identically; when sharp is absent the deriver degrades to responsive: null and passes the master through.","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260726130403":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260726130403","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260726130403","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"cdadbf7a2c74ce7f8589103aca5978b8bebb1a99","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260726130403.tgz","fileCount":128,"integrity":"sha512-VCh8ILANysGs73eMCLbkRGhIY7zGdIAw42avAIhyK+Plosspb+vX3iXPGtduWflniHmed/mL33V4OEayH3SIWw==","signatures":[{"sig":"MEQCIBBRl53WQFzVdQZEIOF1HDI7LcqEVKQ1RHfYY8CqIWn8AiAWr4yIUuX3bkrsvaDiMOHcCVfXtorfb3ZvkoBaaQWjRg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":878618},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"f07273535b3eb1c4341d5e8b014ad33b25d24a0f","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260726130403","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260726130403"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260726130403"},"optionalDependencies":{"sharp":"0.34.5"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260726130403_1785071055634_0.7502426379040525","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. Pinned to exactly the version intake-pipeline uses so the image ladder derives identically; when sharp is absent the deriver degrades to responsive: null and passes the master through.","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260726150557":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260726150557","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260726150557","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"b100b0ddf63935b838aa76a79fd28c94b3afff91","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260726150557.tgz","fileCount":128,"integrity":"sha512-KRb1d9bXJ3TCzC7hDCJBhO8ApeNGA1yOx5FP7aGMfExe6mPl22rKKpN2PVgZBbKNXjnsEsaiKKYsdwWITeSsuQ==","signatures":[{"sig":"MEUCIHI0YtAZtQ9KvHKUC4CZjDv8Ad7HxqZVXV86LWM0gFX6AiEAziP++CJqZ3YHXSOCjl8gJQlfHc6X3AjLjKrznUi2VkI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":878618},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"b8ebf4b5a3741ae794362d7a0be22ecfe731678d","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260726150557","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260726150557"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260726150557"},"optionalDependencies":{"sharp":"0.34.5"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260726150557_1785078368481_0.6565863272153902","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. Pinned to exactly the version intake-pipeline uses so the image ladder derives identically; when sharp is absent the deriver degrades to responsive: null and passes the master through.","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260726151403":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260726151403","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260726151403","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"1b70d373edf8c6a1ebf0577a302c7ec405e170bd","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260726151403.tgz","fileCount":128,"integrity":"sha512-Mno57RQpqErKGogSje1JVgsiUL2o+VXR7d2NYqVW7r8JyIj9n+fEq6RHiMkhbFaIpKFuX7LG3fslcA/KQ55LNw==","signatures":[{"sig":"MEQCIFOjbzctxAHfiEQorEDQW6VpucGBlE6CIEzFOI8Df5jBAiBW8Mcler/5IZdy58dEjpKr8CXh/qMI6x9DESx7CmjKgA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":879326},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"751337ab97ac6aaccee85ed627d8b34592dd9fff","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260726151403","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260726151403"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260726151403"},"optionalDependencies":{"sharp":"0.34.5"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260726151403_1785078853877_0.26632248156903504","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. Pinned to exactly the version intake-pipeline uses so the image ladder derives identically; when sharp is absent the deriver degrades to responsive: null and passes the master through.","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260726163042":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260726163042","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260726163042","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"331861ee1b69cd815b1039dcc9f47262deb1d2ed","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260726163042.tgz","fileCount":128,"integrity":"sha512-TUQPEHgIISG/eFaN7qbCU9tPCsQts+aYZ71pvpHxINAratlieBrJ487YLiQvWHBnc4/8LoTEQKIwQiPk63uc+A==","signatures":[{"sig":"MEUCIQCZt+03zTpMMo8Rpdvb8kym5h7RAKX/+rKAWno4/lTW3AIgTDDOWfLfxRAOVcxEiYhPZeMPGT6FVsybjte9ji/XHr0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":880376},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"1613e859bfebae3f09cd9d15a125981373783b1c","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260726163042","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260726163042"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260726163042"},"optionalDependencies":{"sharp":"0.34.5"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260726163042_1785083454281_0.13420324190667898","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. Pinned to exactly the version intake-pipeline uses so the image ladder derives identically; when sharp is absent the deriver degrades to responsive: null and passes the master through.","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260726171747":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260726171747","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260726171747","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"9817c9627ff64f2ff435dbfb3cb27886d3d9f444","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260726171747.tgz","fileCount":128,"integrity":"sha512-PSlKROG8Gz7BDzQfvEaSBPrUUvICEzudJWQvO8R8kq5DapQPFClzUNZzGfunp7hp5ogdcIOmGA/9zOWYYTJMRw==","signatures":[{"sig":"MEUCID8DrqY2v5rv9z/AxABVS6ySR6Y3pGfvn0D193tOq9rZAiEAr8vroAbXqOwB2THDwbMQRVX7bgjxhaNy5rgH04TfoCs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":880376},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"f83959ac3a4d0a0afaa462f728dcd2bf2dbd02bf","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260726171747","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260726171747"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260726171747"},"optionalDependencies":{"sharp":"0.34.5"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260726171747_1785086278077_0.7690590325196562","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. Pinned to exactly the version intake-pipeline uses so the image ladder derives identically; when sharp is absent the deriver degrades to responsive: null and passes the master through.","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260726175448":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260726175448","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260726175448","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"fc3de66dcfa66ec9ae1d29de11aade71f914781b","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260726175448.tgz","fileCount":129,"integrity":"sha512-xTArZNA49WbYgUmW75Q2cSVHnBGLWUCTHhw49Vhat4HFfTkjuXRYvLEcVocSjNc94/43vZsuguCzKyR/ourQ+A==","signatures":[{"sig":"MEUCIQDDEJEXO+F9JzILP6mWt88EEIyw3XgB8Ivs8X5TbZqmbQIgYkGNHbyJIJEQk5QbjwcjM9wcg46GAJaE3QCGIRf4EsY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":897147},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"d382ff5de78b4dcca862bfd2bec8393b1867a60a","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260726175448","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260726175448"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260726175448"},"optionalDependencies":{"sharp":"0.34.5"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260726175448_1785088498986_0.6856660412465994","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. Pinned to exactly the version intake-pipeline uses so the image ladder derives identically; when sharp is absent the deriver degrades to responsive: null and passes the master through.","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260726193345":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260726193345","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260726193345","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"695225cf252274c1bcabeb9f0f153dad6cf588dc","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260726193345.tgz","fileCount":129,"integrity":"sha512-Nbyyx1kquZb0z9s/k8FhwxtVHfIgIEst9DtMi7pCuaJcjFAGIlE4/1ZO001vKTK5pt6BhmAr/q3QLPHPQYOD2w==","signatures":[{"sig":"MEQCIA3T2bQr68ifYr86iRW6V1njD6WXgox809Uf7DQmZIihAiBDDnmcnFpFluxGXjFwnI5icYCIX/SeK4Fy6TyHNpVChA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":899070},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"03f41015ae09d67019185d9d92b80586867a594a","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260726193345","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260726193345"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260726193345"},"optionalDependencies":{"sharp":"0.34.5"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260726193345_1785094437002_0.65170690308974","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. Pinned to exactly the version intake-pipeline uses so the image ladder derives identically; when sharp is absent the deriver degrades to responsive: null and passes the master through.","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260726215326":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260726215326","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260726215326","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"191262851322ead77d6335fab4643a87e8fa6606","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260726215326.tgz","fileCount":130,"integrity":"sha512-aRw/D/m4sdcw/UvBtT6tWF86USCFuwLOaxlETmS1MXvPMu7IBRsuqhF6FfXY7VEbUoFqP7LGTMoiptIvEqhTuA==","signatures":[{"sig":"MEQCIH5+zkgL5je3+a/DWzy6vPxQJQOMhLH40YOgI+ffJdNaAiAiTT0H13yRW5kjCiX18e4tQiIw4antETw7eMklvwANLA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":902451},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"30280d3bdcd583a860553b5f17333a49b51d4971","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260726215326","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260726215326"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260726215326"},"optionalDependencies":{"sharp":"0.34.5"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260726215326_1785102818568_0.6877457222908367","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. Pinned to exactly the version intake-pipeline uses so the image ladder derives identically; when sharp is absent the deriver degrades to responsive: null and passes the master through.","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260727000223":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260727000223","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260727000223","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"f13b46a4f43be4a02635d374d0f29dc29ba5b6e3","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260727000223.tgz","fileCount":130,"integrity":"sha512-N9MQJWQv7R0g9NbUmJzbpstnz/xQAffU+HT/rUmMbiyCfnLGKcsJ0D7W06ZUh//FZz1UBScZUrj0uUqNo45ziA==","signatures":[{"sig":"MEQCIDsBUPk8Rezg68UlAdqjXqwuRKT9C10pPDpIfwaRKn1vAiB+5qwWdtw/j4qgwxTcRHbCgMz5sSgo4YuqMd6VSCTyrA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":903507},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"592fbafe9ea0be1d736a853af6b8e3bdd86ed662","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260727000223","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260727000223"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260727000223"},"optionalDependencies":{"sharp":"0.34.5"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260727000223_1785110554137_0.5293853501389509","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. Pinned to exactly the version intake-pipeline uses so the image ladder derives identically; when sharp is absent the deriver degrades to responsive: null and passes the master through.","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260727003512":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260727003512","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260727003512","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"f971e9876565617c33fa0838ca23e53786e6a375","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260727003512.tgz","fileCount":130,"integrity":"sha512-lXJQuTb/nWQ7h4beauxrEIeK0ui6BuHEM7hCuMoaNWNKobMy2au0wGdtRPRBIthZJbpwnb9TvPCzIiVMh6HqNA==","signatures":[{"sig":"MEQCICOImXETLiRj9Mpm0F81xta5+rAgG8lSXD3KR4tM6+TIAiAPMOxYR0jGq8ZZX95jxnO5ayLCXy/BKT9zM2MH9WHrMw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":905659},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"2cf4318a2522e1a3821d63050020b693b625ee7e","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260727003512","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260727003512"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260727003512"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260727003512_1785112524310_0.25197216179526816","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin did guarantee was that a libvips CVE below the floor could not be cleared by any consumer: an exact version inside a dependency is unreachable from a consumer's overrides, so a CVE below the floor could not be cleared downstream — it forced a consumer's workspace tree to carry a local overrides patch and forced this package to be republished. A caret keeps the next one a lockfile refresh. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260727015628":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260727015628","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260727015628","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"61435afff368df9cb847f52307223e5ab57a17c8","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260727015628.tgz","fileCount":130,"integrity":"sha512-g+sEIJvDjY41qqmD909lDdZLnlNbzYOWcwgz/n1MfPb1MNf9kHJRxIAZWM/desDWThSth3ku6L4PEPB/iAqpZg==","signatures":[{"sig":"MEUCIQDOTOuQKSeFlSXHqfk/LPrF8dqk+qo/lvkw5PJlD0z7hwIgInM49qUrYIMCBvh1NdpwIicn8tXdzIy9OEX7vdYnHmw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":906497},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"57fd605bfddb8bfde71d870438aecf5522fcb271","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260727015628","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260727015628"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260727015628"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260727015628_1785117400055_0.02162701515699239","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin did guarantee was that a libvips CVE below the floor could not be cleared by any consumer: an exact version inside a dependency is unreachable from a consumer's overrides, so a CVE below the floor could not be cleared downstream — it forced a consumer's workspace tree to carry a local overrides patch and forced this package to be republished. A caret keeps the next one a lockfile refresh. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260727031013":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260727031013","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260727031013","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"9d17df1047f99913687c0f8ec657643c3272fbdf","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260727031013.tgz","fileCount":130,"integrity":"sha512-KQxe4DBuaf91u1dsFx36lYZ3HpAvOqbRVGqagLXZ9piNDelGbmxAISXEuAqsfIdxtXBJhlhhAmAbb+JseMFt4A==","signatures":[{"sig":"MEQCIB6iLONrFjuPVIV7e8wK5CnYtPQBLMxIqbc0z7/i9VUQAiBYlWik3GAhRMl3UODFAjciHVpo3Df1E+GJK/8VcFPpWg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":907520},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"39926f2f3a39cd5a07d6981d6d4866025f47b3e6","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260727031013","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260727031013"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260727031013"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260727031013_1785121824955_0.17855978632274616","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260727035145":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260727035145","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260727035145","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"aba0f6badfe0440b37140ac596521bee25f1776b","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260727035145.tgz","fileCount":130,"integrity":"sha512-gT0Fbn8zYuX1zcHkOyFx+v1pyoR77FpbZQnvQL3PBaeaWrpk6ENNIZeKK6gvVQm/TBLBFXZn/vK1r2q+rWFsbg==","signatures":[{"sig":"MEUCIQCx1i3qPsOSsibqBZaXNWBZOIprLAlEA/cLDYDqC71zdgIgXFPKaRFM79qAh04s+dvQpHbMEllJMlKmiqoIhTdIzkw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":908218},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"e32aedb144bfda46a1c60b2c7281b6056344f34d","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260727035145","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260727035145"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260727035145"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260727035145_1785124317320_0.6734418586869506","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260727115109":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260727115109","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260727115109","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"53ba751faeb7db3c5ca2af80ddc48009d5221625","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260727115109.tgz","fileCount":132,"integrity":"sha512-IpsRzJF9NlIOkQuFMSCrXYtpywLZzNqEWeNCENjIpMS6QfBz2UIkbrCWwZ25ccCZyN9yqNuTifITgAtPaTR1Dg==","signatures":[{"sig":"MEYCIQCpcocEFJTm2uR3ogp/QnLOZKtNx3CdHmCd9em4rdl5pgIhAK22tlpmjmo0jQr2rNQj+B1vfV+olYMjroXMm5VP9/SC","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":921220},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"78196184e840a724e39b6825bc723fa219b18f64","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260727115109","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260727115109"},"peerDependencies":{"@homepages/template-kit":"2.0.0-dev-20260727115109"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260727115109_1785153080777_0.10534066913008644","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260727122838":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260727122838","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260727122838","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"ff2922f5d369c0702088824a93bebbd62cdc7d4d","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260727122838.tgz","fileCount":132,"integrity":"sha512-YU4/IB90ucoVsbmJOCyg2RgY7JXfvtBstzCMR8P7BFYRKKzJhfLA9dS60XoRsetB5zXIhYTLWaxHt5Kjb41yeg==","signatures":[{"sig":"MEUCIQC+P5pvW3TG/Olioh3rUDHA1LFR93ZO0yeYiO/YSYwvfwIgSfXUYrgRhr/JuI2ob49fxNagz+i/ck204IeuQmpz5uw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":920425},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"b27d0e431ab9f901646ac748e4a917f3d965ee40","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260727122838","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260727122838"},"peerDependencies":{"@homepages/template-kit":">=2.0.0-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260727122838_1785155329636_0.37330022656895245","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260727133549":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260727133549","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260727133549","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"16a1168458cdd065d175363de81b81e04bbd3a69","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260727133549.tgz","fileCount":132,"integrity":"sha512-0rsRJo69EfE/3kaa+ktkFtINRlU9h70ex4RkjAiWxlR3R6fjer2ExwWCrYMAJ8/TZ+DDkrqva7TJ8jwYwecePw==","signatures":[{"sig":"MEUCIQDmvJBWT2WrKKD4Oc6Egi9KfDKOVIRpTPBwaJ99Kn0MhwIgff3KpiUhqMx/VMXrgLw1oxbVqAOLgiODkAHF9AbBbRk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":920425},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"7dc4d76c036edb6481d3902ca5d035c01ffecca4","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260727133549","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260727133549"},"peerDependencies":{"@homepages/template-kit":">=2.0.0-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260727133549_1785159362569_0.4165507894652447","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260727142818":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260727142818","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260727142818","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"3a1d1c1003b74728eec02b04345e594dd29f63a6","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260727142818.tgz","fileCount":132,"integrity":"sha512-YExpPp8+28jcOaEScH40AyTL58mE3zRkVG2A0eLD9O8a7DvyIWwfhv6eaXnh3E0goSU1REZYKjnR9DwdnQVHEA==","signatures":[{"sig":"MEQCIFXmvcqvZFp5j9+/NZVOBHNMhOZ6uQZESZqVxt2xvilzAiBr8agZ5tyan/qGx6Vhg8IYXiGinO+oqI71tSekUdh4sQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":921102},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"31026820efb90082c66ac8c0a7f705b257e5d977","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260727142818","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260727142818"},"peerDependencies":{"@homepages/template-kit":">=2.0.0-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260727142818_1785162509039_0.5079689737325919","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260727174231":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260727174231","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260727174231","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"562d308206770370174b152bce668ea1153c502c","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260727174231.tgz","fileCount":132,"integrity":"sha512-bEAm7CAD6dKn/HQqKLKkNFVSsGZxUBJjztMYQTlt70doj11Sfsj8P2TJrMQdxfFPziNw8Hrkj/2Gu0xlnLcySA==","signatures":[{"sig":"MEUCIQDszuvQT9Law3zxrYQ3ROhs8d1pOFGE5MZVWxkDtfdMdAIgL4UyN88tcq3ePEj7W5FSIQEf2mMULRDmCZ1Gak56tWs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":921121},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"f8cc8dc8dabcccb57d0d5cc00a8e3ae53c301de8","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260727174231","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260727174231"},"peerDependencies":{"@homepages/template-kit":">=2.0.0-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260727174231_1785174185287_0.16488927360677152","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260727180158":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260727180158","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260727180158","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"2aebc11be5c39966be59897e5e41e958fc1e5e5d","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260727180158.tgz","fileCount":132,"integrity":"sha512-QJ9uoTGjUZZtuIDPL8iMVwjh9qL0GWPUhm9Wa6I52DMrT7elef0MxXb78j+lKaG3LCo9DNFESBRpeuy0UHcJiw==","signatures":[{"sig":"MEYCIQCsqREFUCMVOErZ9BZrnoHa8DZYIdOr58K8kgu2BIn79gIhAIIFzoaPfK+MMKVPOX7HiB4zT7o/Swn6ZP6OVYZSNxAP","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":921121},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"02ade7bc63ad18b84be283827254334065e16ffa","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260727180158","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260727180158"},"peerDependencies":{"@homepages/template-kit":">=2.0.0-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260727180158_1785175352307_0.0936252938284694","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260727194158":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260727194158","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260727194158","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"e8a6345c11014e4a3462745c89c4a781fc8f8e92","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260727194158.tgz","fileCount":132,"integrity":"sha512-HsA0QGU6Jr0DlzH9Lst7HFjBO+bZUG9bpJ8xJEBHVh46+JwNe9mQpygpiXFY+iGn5v9GhN99J8UX90WkPrrqeA==","signatures":[{"sig":"MEUCID6CoDDeIj1Qtl0urXT7SzIQCsqZ7XxDbPSMN/DgYiImAiEA9UALujebbO9+tA7SlgaaV/WQynswXg2Z4YZSc7lCV1k=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":923111},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"3cbcf2865ca45a402ab96c0e6005c08b42bcfcc2","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260727194158","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260727194158"},"peerDependencies":{"@homepages/template-kit":">=2.0.0-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260727194158_1785181354439_0.03260840860628034","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260727202116":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260727202116","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260727202116","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"205f8877b44cfba73a036606acfa7a21bc614bd0","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260727202116.tgz","fileCount":132,"integrity":"sha512-4fPuz7ufourhGj5D3Os3WoNynK9eTdkTPuRbdz+KAZVXaXtnGxpQv7hwP3ucJW9sjq6uBIbsb/UJptevcYoESg==","signatures":[{"sig":"MEQCH1kdv5QCV1GbOGBDrJMXBYjqcM0fNpjouYzYfFD4bUACIQDH5OFz+rIP7xgbTwN6MNlC4Lu/eiwW3RZpa7SyzQgSnQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":923266},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"971b1323023710a34623b26477fb2cce7a357533","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260727202116","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260727202116"},"peerDependencies":{"@homepages/template-kit":">=2.0.0-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260727202116_1785183711675_0.13707044949904668","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260727205941":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260727205941","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260727205941","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"0031216c0d97bc176e27bb6a0ec8de58e97030f1","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260727205941.tgz","fileCount":132,"integrity":"sha512-Ch2n174b/SwSaVGYZ1zm2U+YDF5wuV/TmsWx1R4TpehnJzbNKBRrjc9Ayz+f6/WRkG86f72Q8YaH24hyGMtNuQ==","signatures":[{"sig":"MEUCIQCvN1K6vgBPJqlc1foAn5ZpkPO4bUlrEm/MexWlcqLOAgIgES2SgKjgQ721/SU3gCDGsisWCxu6euHPKkIxGhNkgoE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":923266},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"971b1323023710a34623b26477fb2cce7a357533","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260727205941","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260727205941"},"peerDependencies":{"@homepages/template-kit":">=2.0.0-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260727205941_1785186018508_0.11963065379690474","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260727225138":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260727225138","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260727225138","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"3d6736574f1e6df01acd6ba22c0f68902df92ef5","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260727225138.tgz","fileCount":132,"integrity":"sha512-Ym3d+C2sU2983xKzKRLT201Hpqin7U3fZdtlcFdiljU9ojU/TXUL1zD12+hyBBYchotDkVdxSPZp/rNYnlobbA==","signatures":[{"sig":"MEUCICo5CgF7xoQbv/9LJb1gOJOCovwzMN+9rKkJ7gC1R3G3AiEAkic89Ad2l9OhBmolVRQ2GdF231GvsNpj7ADmmjH6Nwc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":923266},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"4933d5ad6e56597aff466152ee053e0923eac171","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260727225138","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260727225138"},"peerDependencies":{"@homepages/template-kit":">=2.0.0-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260727225138_1785192734349_0.37789100674078235","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260728011139":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260728011139","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260728011139","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"56c82d8a6b9c2d184135838e3d3c813953362b5a","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260728011139.tgz","fileCount":124,"integrity":"sha512-xcf9sIb2nHB4JRQZicUK6VK4hl2yQIkSouEeawo0tQAf29Nblc8Spmqm1zRNK93BXi0plOq0vNarMoUKn+SdyA==","signatures":[{"sig":"MEUCIQCX5mW0VU6EfxXDZmTk/u3CqvvpNXpsiHqu9/JWKlW2EAIgQ3U3Rhx/VLRB4cSIHscunZa3MAUW9aaJhwtHVv9tRIU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":916391},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"fe1b78d00383ee49a6aeee393117949779d299af","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260728011139","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260728011139"},"peerDependencies":{"@homepages/template-kit":">=2.0.0-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260728011139_1785201134803_0.913016275639402","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260728021150":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260728021150","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260728021150","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"889e7347d0a013a43da0f9f91c6da313d885f840","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260728021150.tgz","fileCount":124,"integrity":"sha512-ih1ryVeOZxLYscA1pCOaXj/XLBde2Mx1gVbqtFjVdcq9ZUUlBIWrTBRmwxlc7hlXDT3ScGT7qqgmSW3zQpIsYQ==","signatures":[{"sig":"MEUCIGfTefi1KGSaU3OGNQEqHm3HnxroDv9jVMob+42nWkcVAiEA664HMArjOjhfjTXMJ4qLtXOT/p8VWiEMGkU/9/amKRU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":918000},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"4585d812d7db617aa89acb5499f4706355897f1b","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260728021150","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260728021150"},"peerDependencies":{"@homepages/template-kit":">=2.0.0-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260728021150_1785204743286_0.8723843821475865","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260728033307":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260728033307","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260728033307","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"e517f7b2912b540a6f20276b322f5ccb45bac7ff","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260728033307.tgz","fileCount":124,"integrity":"sha512-k4gqq2fdOlD0MVwJajItUDxFMPLmK19ch/GYqCXcjSCMS8wBjBgt8djQfd81UJSGtaQcLc1EhwfHaZpCbAA8Iw==","signatures":[{"sig":"MEQCIBt/MzQUl1mhPeFhIHKcxR4P+WYv1GikGRGnTKRThi41AiA/YQvYArjH8neHYRdnVlh0jCD/Rad5BC3VcSAsQVFSSA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":919672},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"1ec7490e8f1ff5d2246bd473c65180ebf5e7e26d","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260728033307","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260728033307"},"peerDependencies":{"@homepages/template-kit":">=2.0.0-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260728033307_1785209616865_0.7559788129597373","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260728113846":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260728113846","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260728113846","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"926ea558710109b29fccaea0efecf5f5f395b93b","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260728113846.tgz","fileCount":124,"integrity":"sha512-3OBFjqFF+8+YKsFRKOu6xiLCNnCqB68EI8acdEjABmHz58WmCtEIAafB2W2MzO8dkih8WSpTkGWcF9sRtKoVQQ==","signatures":[{"sig":"MEUCIQDaR8EW1x0GNt80ryx1cNUlBjmhB7F00f1iqMSpRWt9IwIgBko/gNo5AI/+Zvl9dUwfXzGuHps4+HIyzZAiOo/+5ns=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":919493},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"58a81418673037e8f3c253d7c6ec86b68f73d079","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260728113846","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260728113846"},"peerDependencies":{"@homepages/template-kit":">=2.0.0-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260728113846_1785238761826_0.21681374150046961","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260728131506":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260728131506","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260728131506","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"6b793a3587986d51e94f4ed653b8f642ee477e74","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260728131506.tgz","fileCount":125,"integrity":"sha512-0KoQ+SV/oAxkRRt3XP5aVVg9wVdt5kLvYhbMClISWkywHAsTsGVIke3sARi4UxMm/yjeEyF8Rc09sDaSyn/dIA==","signatures":[{"sig":"MEUCIQDT54TuVw+e2aSNbOxoDEmZFMwcjAhWDN2IzQG3L7LVRAIgJUvkdu0TxTe5p5tqz1zxXsQHNTsfQHwiNUzz8iW52G4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":919919},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"2d27492161034df0058501480deaa3a9b74a2948","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260728131506","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260728131506"},"peerDependencies":{"@homepages/template-kit":">=2.0.0-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260728131506_1785244540610_0.15723108406943576","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260728172654":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260728172654","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260728172654","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"07212cdfdbd7035d75428f16e84a1bbd73cd7e53","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260728172654.tgz","fileCount":125,"integrity":"sha512-wrhPAd7i9Nml12eNoSV8YIOk3NV7B2EAdTG5u5UQxW9Oz2wFSstjvkSp8GT3KmfhY1tvIUrP/IQag/1O+HTIfg==","signatures":[{"sig":"MEQCICAAjA535Pv3pJomlRvqK1+MKzqUvTpOc3qwS8fQsPnUAiArqZxqWySlKTBc8BKbJENAJ6rdgpls/+JOc5vrbg+v6g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":919919},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"31eadaf8d3215e92d3568f470203fca5babb8764","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260728172654","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260728172654"},"peerDependencies":{"@homepages/template-kit":">=2.0.0-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260728172654_1785259650401_0.45355643225004205","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0-dev-20260728180604":{"name":"@homepages/template-cli","version":"2.0.0-dev-20260728180604","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0-dev-20260728180604","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"3110bda8f6ec218a7e9456f5be93a7019d941479","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0-dev-20260728180604.tgz","fileCount":125,"integrity":"sha512-lMGlLnWh+0WV78UUIlFYmfmdcM3xZGEWImXKM3eTbiHWot/9H+XRiYlnbqxEKiwS+miTMdLq96sNNwCwbp2S6A==","signatures":[{"sig":"MEYCIQCJ9k6/x5Q7uTLM41OovE7cGHZaqYxBQirCp1XrEo3NBwIhAIVxPgA5RbiJM7Q0zuB6+FH/YbH7AmyacRGoIacvkXbr","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":924579},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"440fb33b1d64792efde31744a8c8f2fbffcebe90","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.0-dev-20260728180604","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.0-dev-20260728180604"},"peerDependencies":{"@homepages/template-kit":">=2.0.0-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0-dev-20260728180604_1785262000753_0.024003245685273455","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.0":{"name":"@homepages/template-cli","version":"2.0.0","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.0","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"c87d44bc2e75e9e7e594c16d9f53b2c1f62569b3","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.0.tgz","fileCount":125,"integrity":"sha512-6sHLiX5kSWNbYIUavWw3nE2zzZoE1Lc0hFzbRfakvF4ShBtQBuEbDt5xDaoFKXt6u55RyWQmTMeurnx/i1dmeA==","signatures":[{"sig":"MEUCICAjuA6DuJmXphJbPVT0rtlSPyvIRRDj5NcJi5qRTDcjAiEAtNyVI+XLcu9TVmD33YXQJ3Xs1Z65u0+SgW5ORN3vb34=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":924208},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"ec4f440ee1ed631fcb8cefd96365e10a394a7405","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"*","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"*"},"peerDependencies":{"@homepages/template-kit":">=2.0.0-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.0_1785330523647_0.23411925313454662","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.1-dev-20260729174949":{"name":"@homepages/template-cli","version":"2.0.1-dev-20260729174949","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.1-dev-20260729174949","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"1b838ff2e1061e0ee63693e594af183c6900f99a","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.1-dev-20260729174949.tgz","fileCount":125,"integrity":"sha512-xB+gpqh2XJobm/RsYyfgLmO4Jp+IJt6dtYHFV5pydMFs6YYVdKObg6D58RtkafsA2QT0BtDyTxY7f0ELpd7oow==","signatures":[{"sig":"MEUCIQCyi+ITzKd7NhSSQ3mFkEn0N+2fD/hbr8+vigA1bS5CtAIgD9NH6R5bDKVIeLlA4m5XF65Y1TEqncZFA3jz6NEPxBo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":927553},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"84ac10e57b45c95d6b28d7025fda276f13c611fb","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.0.1-dev-20260729174949","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.1-dev-20260729174949"},"peerDependencies":{"@homepages/template-kit":">=2.0.1-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.1-dev-20260729174949_1785347421780_0.21133172211634554","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.0.1":{"name":"@homepages/template-cli","version":"2.0.1","license":"UNLICENSED","_id":"@homepages/template-cli@2.0.1","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"3d9abd53390f5f30b9323186da048678b601ffea","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.0.1.tgz","fileCount":125,"integrity":"sha512-hxTxvuDC83ycoMEx6wz5Z67m68HDTmSdVz6jbErahs4ZRuwOfV62EYgn4AbQhqtFteu8xr2uJtUZeJtvsfH46A==","signatures":[{"sig":"MEQCIB0lEeVo/ohPqhESgN1+rIzJlrSme1yKJOsBWczgAEgmAiB+U3u5FkJ7jnDS0JgHymQBhM7DSJ+sahLC+mrBaKEJaw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":927450},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"21dd9ee33f9a1df50be91414475e09b394b6c0a6","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"*","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"*"},"peerDependencies":{"@homepages/template-kit":">=2.0.1-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.0.1_1785350276087_0.11412258731843994","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.1.0-dev-20260729203301":{"name":"@homepages/template-cli","version":"2.1.0-dev-20260729203301","license":"UNLICENSED","_id":"@homepages/template-cli@2.1.0-dev-20260729203301","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"e9f043e8582ab538105853804c358089bad862b5","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.1.0-dev-20260729203301.tgz","fileCount":127,"integrity":"sha512-OQn5MLsHqBuwvY4ID1Nl12G8w/jCwP51y0jkoQ+lP3lEeuskFqRJGMb9euZdRk0ak3sjvKtS+y4+AICDIgr+xg==","signatures":[{"sig":"MEUCIQCcaXJ9cz8If1QQL8QRqLaAPOBYpZFLrJ5YICsH3JgZKwIgKgSE+7GU1VvMd22hY6mTE9AtGeCJCCgZClhtzUV2oTg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":931843},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"f75076c73bec39ccf9f9346996e1155ce7ebb577","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.1","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.1.0-dev-20260729203301","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.2-dev-20260729203301"},"peerDependencies":{"@homepages/template-kit":">=2.1.0-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.1.0-dev-20260729203301_1785357212612_0.3095193732404111","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.1.0-dev-20260729232501":{"name":"@homepages/template-cli","version":"2.1.0-dev-20260729232501","license":"UNLICENSED","_id":"@homepages/template-cli@2.1.0-dev-20260729232501","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"ce6e2fe864e8ed43736e2b9225292b0c1c778d28","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.1.0-dev-20260729232501.tgz","fileCount":127,"integrity":"sha512-Sunz+fHlcagKpx/zArZGMAQbVWVWzn0sulFZ1zU0dAkCknaRT5aKmAp3Q4WkkGrQjDf4DYJ4DprbF6TBpqoPGg==","signatures":[{"sig":"MEQCIGwBTvjZxyO+KqOEw7ECuWX2G/NGTh6G/E/vzPTjLkuMAiAIklvNu9ZzJAHc2jwv3wQc/bHvrXLuXqjHxijM9Nx4Aw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":934021},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"3e8f16fdb9ad6ca2d45ff92f8af0739823e06beb","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.2","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.1.0-dev-20260729232501","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.0.2-dev-20260729232501"},"peerDependencies":{"@homepages/template-kit":">=2.1.0-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.1.0-dev-20260729232501_1785367534727_0.8983460705934068","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.1.0":{"name":"@homepages/template-cli","version":"2.1.0","license":"UNLICENSED","_id":"@homepages/template-cli@2.1.0","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"46da34ec7b8183ab7580fd9f287f394ae22c8751","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.1.0.tgz","fileCount":127,"integrity":"sha512-QK6GF6e4pPxqsu3jQXmdHpkDcWaPgn+7IYsKciNl/mdLiu49Agy/FKfemcaZe8DAq05kB4NlkAMv2G9rkwVlqg==","signatures":[{"sig":"MEUCIAutztIMU/uksKA6HP3/SzBbhUVOa4hlLZhYsQB3nVp4AiEAmyNL44s/s29wMc8K5Dn/+2QwjJQlHsl4NJWmHV73nmE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":933918},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"f1d8565f00390f354063ea379f491fea842606be","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.2","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"*","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"*"},"peerDependencies":{"@homepages/template-kit":">=2.1.0-0 <3.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.1.0_1785370643985_0.6467030472103752","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.2.0-dev-20260731213520":{"name":"@homepages/template-cli","version":"2.2.0-dev-20260731213520","license":"UNLICENSED","_id":"@homepages/template-cli@2.2.0-dev-20260731213520","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"47afd109f1a2a2594bbbd05f319558178fbb8582","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.2.0-dev-20260731213520.tgz","fileCount":130,"integrity":"sha512-+Y0GhLZQNYHsO+MuKelaNSjjHoCyOklrCBZc2mN15gVD4iradT3jA2JsGw7H4Q1nm5g7kxEUSIlFashRLvrpTg==","signatures":[{"sig":"MEQCIF+ZN1s5QjGeteHlg5IChh72uHQIDb2zRzpcI2MxxmO0AiBtqO8ifxsJMC1mGrnpgnG35on6LAn6rMTNY6/TrIUPqg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":952003},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"e0358ce5524151bee00509dcf950b853a1ad9095","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.2","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.2.0-dev-20260731213520","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"2.2.0-dev-20260731213520"},"peerDependencies":{"@homepages/template-kit":"2.2.0-dev-20260731213520"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.2.0-dev-20260731213520_1785533750420_0.27996213369704437","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.2.0":{"name":"@homepages/template-cli","version":"2.2.0","license":"UNLICENSED","_id":"@homepages/template-cli@2.2.0","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"55d769d797cba8f0374e87247fb1a69fc95a43b4","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.2.0.tgz","fileCount":130,"integrity":"sha512-VK/j737GuC9PQg7Lnz1ixcygNFlCNr5onc98liy5ozykjemOP0G64uNxpHG0RTyZvLNIgyGLn89OtImwwbIL7A==","signatures":[{"sig":"MEQCIHypAHDkWFFBiv/26EM1jr3E1fs3fGDf6UsbDGCf4ZMpAiAjOnTeN98iTC4JLEqjGEmr/RfGIoPTlGXl01uaa+L5hg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":951829},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"14325d95e0810fcfd8c1338ad4ade695ce377ba6","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.2","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"*","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"*"},"peerDependencies":{"@homepages/template-kit":"^2.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.2.0_1785541578107_0.30284041110569615","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.2.1":{"name":"@homepages/template-cli","version":"2.2.1","license":"UNLICENSED","_id":"@homepages/template-cli@2.2.1","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/template-packages#readme","bugs":{"url":"https://github.com/falktravis/template-packages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"0fdee59f095014f7780e3c9c9f60fbbc7f0df5bf","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.2.1.tgz","fileCount":130,"integrity":"sha512-1vqa4OKosplVPKop57FFKnEtYs/QnhUwhoVf+6jJF6/TVIzsNMDZFIqVJAcxLDh+Ri+RCzwKyZrjsQzTMJ+apA==","signatures":[{"sig":"MEYCIQCczKml2GYNtPg9fdVxfgHRkpsxUNSE6JjJccQASBqqAAIhAJV+3t1qIg7Hwh4eGLY2Sd1wXaxir9F/bLDNbK1wSmdd","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":952178},"type":"module","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"gitHead":"e504825460f3c5bb4970a251ab3e8d111c9d3196","scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:736ca8a5-f869-4d0d-8724-bd8fd72c3249"}},"repository":{"url":"git+https://github.com/falktravis/template-packages.git","type":"git","directory":"packages/template-cli"},"_npmVersion":"12.0.2","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.23.1","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"*","@typescript-eslint/parser":"^8.60.1","@homepages/eslint-plugin-template":"*"},"peerDependencies":{"@homepages/template-kit":"^2.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.2.1_1785544570682_0.7817813648815826","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.2.2":{"name":"@homepages/template-cli","version":"2.2.2","license":"UNLICENSED","_id":"@homepages/template-cli@2.2.2","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/homepages#readme","bugs":{"url":"https://github.com/falktravis/homepages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"f2e988c6f5201bc9c4835693d499f2c732e9f4e5","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.2.2.tgz","fileCount":125,"integrity":"sha512-zh6/WWa1ddOpKh7n05wMUhYBraemD8OaDSwkcQSGtGAeHflfZOdvqcYKkLVOVKQ2uQAf74+8WkicLDjAl9V4/Q==","signatures":[{"sig":"MEUCIQCD+hdoVC8w6k7bfc7l9na7cRwCjhG6ik+e6mEeXnZWHAIgbfJdmXDnpvRJLw0FQRsm7Zh7PU9JE601QY2pMXBIisA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":922317},"type":"module","_from":"file:homepages-template-cli-2.2.2.tgz","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"travisfalk","email":"falk.travis@gmail.com"},"_resolved":"/tmp/1e81cb854f5fc38455e3bf821784124f/homepages-template-cli-2.2.2.tgz","_integrity":"sha512-zh6/WWa1ddOpKh7n05wMUhYBraemD8OaDSwkcQSGtGAeHflfZOdvqcYKkLVOVKQ2uQAf74+8WkicLDjAl9V4/Q==","repository":{"url":"git+https://github.com/falktravis/homepages.git","type":"git","directory":"packages/external/template-cli"},"_npmVersion":"10.9.7","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.22.2","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@homepages/dev-media":"2.2.2","@vitejs/plugin-react":"^4.3.4","@tanstack/react-query":"^5.100.14","@homepages/template-kit":"2.2.2","@homepages/internal-refs":"0.0.1","@typescript-eslint/parser":"^8.60.1","@homepages/effective-version":"0.0.1","@homepages/static-assets-binding":"0.0.1","@homepages/eslint-plugin-template":"2.2.2"},"peerDependencies":{"@homepages/template-kit":"^2.0.0"},"optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.2.2_1785703547660_0.8861128502750115","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the vendored ladder POLICY (src/cli/media/image-ladder.ts), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"2.3.0":{"name":"@homepages/template-cli","version":"2.3.0","license":"UNLICENSED","_id":"@homepages/template-cli@2.3.0","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/homepages#readme","bugs":{"url":"https://github.com/falktravis/homepages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"76a67a258be9796d035f8e2d5fbcf38516cb1bcc","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-2.3.0.tgz","fileCount":136,"integrity":"sha512-0yx4FQmZWSHpQ4XF3cYGc4sznvn9om5DxXp6BRqM7r6SOF+AfMfW20WPS2qgYu7Fxcp9Lra39JjkuKJi+CttbA==","signatures":[{"sig":"MEUCIEk3a+MlTUhBdRoDfv4vZ+vyQCWYpofELpwO5+tFtmINAiEAimlnSstKL60Z4g3lS6EFgEeoCbvKXuVIE7EVVNsfPDM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":963935},"type":"module","_from":"file:/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-2.3.0.tgz","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"travisfalk","email":"falk.travis@gmail.com","approver":{"name":"travisfalk","email":"falk.travis@gmail.com"}},"_resolved":"/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-2.3.0.tgz","_integrity":"sha512-0yx4FQmZWSHpQ4XF3cYGc4sznvn9om5DxXp6BRqM7r6SOF+AfMfW20WPS2qgYu7Fxcp9Lra39JjkuKJi+CttbA==","repository":{"url":"git+https://github.com/falktravis/homepages.git","type":"git","directory":"packages/external/template-cli"},"_npmVersion":"12.0.2","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.22.2","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@homepages/icon":"workspace:*","@homepages/modal":"workspace:*","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@homepages/dev-media":"workspace:*","@vitejs/plugin-react":"^4.3.4","@homepages/image-crop":"workspace:*","@tanstack/react-query":"^5.100.14","@homepages/canvas-core":"workspace:*","@homepages/html-escape":"workspace:*","@homepages/image-ladder":"workspace:*","@homepages/slot-editors":"workspace:*","@homepages/template-kit":"workspace:*","@homepages/editor-tokens":"workspace:*","@homepages/internal-refs":"workspace:*","@homepages/media-library":"workspace:*","@typescript-eslint/parser":"^8.60.1","@homepages/fill-vocabulary":"workspace:*","@homepages/effective-version":"workspace:*","@homepages/section-contracts":"workspace:*","@homepages/template-contracts":"workspace:*","@homepages/static-assets-binding":"workspace:*","@homepages/eslint-plugin-template":"workspace:*"},"peerDependencies":{"@homepages/template-kit":"^2.0.0"},"$comment:bin-warning":"A `pnpm install` before this package's first build prints 'WARN Failed to create bin ... template-kit ENOENT' once per internal workspace member that declares this package as a devDependency — pnpm's bin linker reads dist/cli.js to set it up and it does not exist yet. Expected and harmless: a subsequent build populates dist/cli.js and the next install links cleanly. Not fixable without either committing build output (dist/ is gitignored by design) or moving the bin off dist/ (would touch the published entry point every consumer and guide page resolves — too large a change for this warning). Suppressing it would need a pnpm bin-link config pnpm does not expose (verified: preferSymlinkedExecutables still fails, at the chmod step).","optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_2.3.0_1785872338922_0.03154418490300559","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the shared ladder POLICY (@homepages/image-ladder, inlined into dist at build time), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.0.0":{"name":"@homepages/template-cli","version":"3.0.0","license":"UNLICENSED","_id":"@homepages/template-cli@3.0.0","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/homepages#readme","bugs":{"url":"https://github.com/falktravis/homepages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"d8c829baa439ed8b1d030ecdd925f7cd11da7151","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-3.0.0.tgz","fileCount":152,"integrity":"sha512-SGnXmztN8CgFukdh2GNlqTE1vqjJsgF0IRgC8JeKRrGn2yAKn1OQHocWTWPZ9wJDrdN0eRSpXTZOidD/NiquAg==","signatures":[{"sig":"MEUCIQCxwfpD23Rjoq0eCDEzRqgJYGeqg8CBoOy6HtHcz1qiSgIgGQS7++JXKQT8CRnx2kG9a5GH8IK7wNbPdP1pb//ID8g=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1060052},"type":"module","_from":"file:/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-3.0.0.tgz","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"travisfalk","email":"falk.travis@gmail.com","approver":{"name":"travisfalk","email":"falk.travis@gmail.com"}},"_resolved":"/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-3.0.0.tgz","_integrity":"sha512-SGnXmztN8CgFukdh2GNlqTE1vqjJsgF0IRgC8JeKRrGn2yAKn1OQHocWTWPZ9wJDrdN0eRSpXTZOidD/NiquAg==","repository":{"url":"git+https://github.com/falktravis/homepages.git","type":"git","directory":"packages/external/template-cli"},"_npmVersion":"12.0.2","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.22.2","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@homepages/icon":"workspace:*","@homepages/modal":"workspace:*","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@homepages/dev-media":"workspace:*","@vitejs/plugin-react":"^4.3.4","@homepages/image-crop":"workspace:*","@tanstack/react-query":"^5.100.14","@homepages/canvas-core":"workspace:*","@homepages/html-escape":"workspace:*","@homepages/image-ladder":"workspace:*","@homepages/slot-editors":"workspace:*","@homepages/template-kit":"workspace:*","@homepages/editor-tokens":"workspace:*","@homepages/internal-refs":"workspace:*","@homepages/media-library":"workspace:*","@typescript-eslint/parser":"^8.60.1","@homepages/fill-vocabulary":"workspace:*","@homepages/template-tooling":"workspace:*","@homepages/effective-version":"workspace:*","@homepages/section-contracts":"workspace:*","@homepages/template-contracts":"workspace:*","@homepages/static-assets-binding":"workspace:*","@homepages/eslint-plugin-template":"workspace:*","@homepages/template-rule-registry":"workspace:*"},"peerDependencies":{"@homepages/template-kit":"^3.0.0"},"$comment:bin-warning":"A `pnpm install` before this package's first build prints 'WARN Failed to create bin ... template-kit ENOENT' once per internal workspace member that declares this package as a devDependency — pnpm's bin linker reads dist/cli.js to set it up and it does not exist yet. Expected and harmless: a subsequent build populates dist/cli.js and the next install links cleanly. Not fixable without either committing build output (dist/ is gitignored by design) or moving the bin off dist/ (would touch the published entry point every consumer and guide page resolves — too large a change for this warning). Suppressing it would need a pnpm bin-link config pnpm does not expose (verified: preferSymlinkedExecutables still fails, at the chmod step).","optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_3.0.0_1785979254303_0.9125364762457171","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the shared ladder POLICY (@homepages/image-ladder, inlined into dist at build time), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"3.0.1":{"name":"@homepages/template-cli","version":"3.0.1","license":"UNLICENSED","_id":"@homepages/template-cli@3.0.1","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/homepages#readme","bugs":{"url":"https://github.com/falktravis/homepages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"b56e31805727bbe9d28e116d4bfc80a49ae257ab","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-3.0.1.tgz","fileCount":152,"integrity":"sha512-rdg4MwsH+tAyO+oTz2wdIdC+vQpVyLaXkV7h+fuxuV/9rhUecnQsl7NWDayYW9rx22Jvn/S2lF/17UB05HxrUA==","signatures":[{"sig":"MEUCIQCWZFay+ocb8GUjBgGgkfUuNbjG127nsxrSzZZ684N/wgIgOwLHs/pRxF9Hy+K7kDDJ1ce1WS9bis15kPI+rM5n9VA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1060062},"type":"module","_from":"file:/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-3.0.1.tgz","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"travisfalk","email":"falk.travis@gmail.com","approver":{"name":"travisfalk","email":"falk.travis@gmail.com"}},"_resolved":"/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-3.0.1.tgz","_integrity":"sha512-rdg4MwsH+tAyO+oTz2wdIdC+vQpVyLaXkV7h+fuxuV/9rhUecnQsl7NWDayYW9rx22Jvn/S2lF/17UB05HxrUA==","repository":{"url":"git+https://github.com/falktravis/homepages.git","type":"git","directory":"packages/external/template-cli"},"_npmVersion":"12.0.2","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.22.2","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@homepages/icon":"workspace:*","@homepages/modal":"workspace:*","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@homepages/dev-media":"workspace:*","@vitejs/plugin-react":"^4.3.4","@homepages/image-crop":"workspace:*","@tanstack/react-query":"^5.100.14","@homepages/canvas-core":"workspace:*","@homepages/html-escape":"workspace:*","@homepages/image-ladder":"workspace:*","@homepages/slot-editors":"workspace:*","@homepages/template-kit":"workspace:*","@homepages/editor-tokens":"workspace:*","@homepages/internal-refs":"workspace:*","@homepages/media-library":"workspace:*","@typescript-eslint/parser":"^8.60.1","@homepages/fill-vocabulary":"workspace:*","@homepages/template-tooling":"workspace:*","@homepages/effective-version":"workspace:*","@homepages/section-contracts":"workspace:*","@homepages/template-contracts":"workspace:*","@homepages/static-assets-binding":"workspace:*","@homepages/eslint-plugin-template":"workspace:*","@homepages/template-rule-registry":"workspace:*"},"peerDependencies":{"@homepages/template-kit":"^3.0.0"},"$comment:bin-warning":"A `pnpm install` before this package's first build prints 'WARN Failed to create bin ... template-kit ENOENT' once per internal workspace member that declares this package as a devDependency — pnpm's bin linker reads dist/cli.js to set it up and it does not exist yet. Expected and harmless: a subsequent build populates dist/cli.js and the next install links cleanly. Not fixable without either committing build output (dist/ is gitignored by design) or moving the bin off dist/ (would touch the published entry point every consumer and guide page resolves — too large a change for this warning). Suppressing it would need a pnpm bin-link config pnpm does not expose (verified: preferSymlinkedExecutables still fails, at the chmod step).","optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_3.0.1_1786025517828_0.8969497993744193","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the shared ladder POLICY (@homepages/image-ladder, inlined into dist at build time), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"4.0.0":{"name":"@homepages/template-cli","version":"4.0.0","license":"UNLICENSED","_id":"@homepages/template-cli@4.0.0","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/homepages#readme","bugs":{"url":"https://github.com/falktravis/homepages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"ae554b5c4c1ad1209d8ad071e4ed09c5a0e3992b","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-4.0.0.tgz","fileCount":167,"integrity":"sha512-+qmRpytyE+Wot15gOAC/k3GrGwMKVfi16F/u0oOiYscLhsRpMnK+l1HemCXt7QiZHjV3G+h6YxYdDGNSJ3pIiw==","signatures":[{"sig":"MEUCIQDoQ14aR3ru0R6Y2f8B/5oz9w3mhEgRHXIIXzzW6Qx++AIgIBjAPivv1Kkr8hCIODidH02eOiquQOpP8TdHGw8+BcI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1157084},"type":"module","_from":"file:/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-4.0.0.tgz","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"travisfalk","email":"falk.travis@gmail.com","approver":{"name":"travisfalk","email":"falk.travis@gmail.com"}},"_resolved":"/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-4.0.0.tgz","_integrity":"sha512-+qmRpytyE+Wot15gOAC/k3GrGwMKVfi16F/u0oOiYscLhsRpMnK+l1HemCXt7QiZHjV3G+h6YxYdDGNSJ3pIiw==","repository":{"url":"git+https://github.com/falktravis/homepages.git","type":"git","directory":"packages/external/template-cli"},"_npmVersion":"12.0.2","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.22.2","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@homepages/icon":"workspace:*","@homepages/modal":"workspace:*","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@homepages/dev-media":"workspace:*","@vitejs/plugin-react":"^4.3.4","@homepages/image-crop":"workspace:*","@tanstack/react-query":"^5.100.14","@homepages/canvas-core":"workspace:*","@homepages/html-escape":"workspace:*","@homepages/image-ladder":"workspace:*","@homepages/slot-editors":"workspace:*","@homepages/template-kit":"workspace:*","@homepages/editor-tokens":"workspace:*","@homepages/internal-refs":"workspace:*","@homepages/media-library":"workspace:*","@typescript-eslint/parser":"^8.60.1","@homepages/fill-vocabulary":"workspace:*","@homepages/template-tooling":"workspace:*","@homepages/effective-version":"workspace:*","@homepages/section-contracts":"workspace:*","@homepages/template-contracts":"workspace:*","@homepages/static-assets-binding":"workspace:*","@homepages/eslint-plugin-template":"workspace:*","@homepages/template-rule-registry":"workspace:*"},"peerDependencies":{"@homepages/template-kit":"^4.0.0"},"$comment:bin-warning":"A `pnpm install` before this package's first build prints 'WARN Failed to create bin ... template-kit ENOENT' once per internal workspace member that declares this package as a devDependency — pnpm's bin linker reads dist/cli.js to set it up and it does not exist yet. Expected and harmless: a subsequent build populates dist/cli.js and the next install links cleanly. Not fixable without either committing build output (dist/ is gitignored by design) or moving the bin off dist/ (would touch the published entry point every consumer and guide page resolves — too large a change for this warning). Suppressing it would need a pnpm bin-link config pnpm does not expose (verified: preferSymlinkedExecutables still fails, at the chmod step).","optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_4.0.0_1786288820389_0.3931661584165984","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the shared ladder POLICY (@homepages/image-ladder, inlined into dist at build time), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"5.0.0":{"name":"@homepages/template-cli","version":"5.0.0","license":"UNLICENSED","_id":"@homepages/template-cli@5.0.0","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/homepages#readme","bugs":{"url":"https://github.com/falktravis/homepages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"57fc42a114847d91f0239c8244b84d55ce32af06","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-5.0.0.tgz","fileCount":179,"integrity":"sha512-QVwzltF4tpSa9YBdCEx3LLLI+qN9xyrwc96NYsijhs0jBxr2FM18lJqkIbc0ApY+IeTEf79X5kFAqeW74yzpNA==","signatures":[{"sig":"MEUCIBQIGaq2zvTnHK7BMD/DSkg1SMsJ+mMHbNPj7wD7KHIRAiEArbab2TMwmVLNDg6b/3cX2jTQ9hV6ymw/1cKka8c1cT8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1315381},"type":"module","_from":"file:/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-5.0.0.tgz","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"travisfalk","email":"falk.travis@gmail.com","approver":{"name":"travisfalk","email":"falk.travis@gmail.com"}},"_resolved":"/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-5.0.0.tgz","_integrity":"sha512-QVwzltF4tpSa9YBdCEx3LLLI+qN9xyrwc96NYsijhs0jBxr2FM18lJqkIbc0ApY+IeTEf79X5kFAqeW74yzpNA==","repository":{"url":"git+https://github.com/falktravis/homepages.git","type":"git","directory":"packages/external/template-cli"},"_npmVersion":"12.0.2","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.22.2","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@homepages/icon":"workspace:*","@homepages/modal":"workspace:*","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@homepages/dev-media":"workspace:*","@vitejs/plugin-react":"^4.3.4","@homepages/image-crop":"workspace:*","@tanstack/react-query":"^5.100.14","@homepages/canvas-core":"workspace:*","@homepages/html-escape":"workspace:*","@homepages/image-ladder":"workspace:*","@homepages/slot-editors":"workspace:*","@homepages/template-kit":"workspace:*","@homepages/editor-tokens":"workspace:*","@homepages/internal-refs":"workspace:*","@homepages/media-library":"workspace:*","@typescript-eslint/parser":"^8.60.1","@homepages/fill-vocabulary":"workspace:*","@homepages/template-tooling":"workspace:*","@homepages/effective-version":"workspace:*","@homepages/section-contracts":"workspace:*","@homepages/template-contracts":"workspace:*","@homepages/static-assets-binding":"workspace:*","@homepages/eslint-plugin-template":"workspace:*","@homepages/template-rule-registry":"workspace:*"},"peerDependencies":{"@homepages/template-kit":"^5.0.0"},"$comment:bin-warning":"A `pnpm install` before this package's first build prints 'WARN Failed to create bin ... template-kit ENOENT' once per internal workspace member that declares this package as a devDependency — pnpm's bin linker reads dist/cli.js to set it up and it does not exist yet. Expected and harmless: a subsequent build populates dist/cli.js and the next install links cleanly. Not fixable without either committing build output (dist/ is gitignored by design) or moving the bin off dist/ (would touch the published entry point every consumer and guide page resolves — too large a change for this warning). Suppressing it would need a pnpm bin-link config pnpm does not expose (verified: preferSymlinkedExecutables still fails, at the chmod step).","optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_5.0.0_1786495816794_0.14887528778614767","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the shared ladder POLICY (@homepages/image-ladder, inlined into dist at build time), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"6.0.0":{"name":"@homepages/template-cli","version":"6.0.0","license":"UNLICENSED","_id":"@homepages/template-cli@6.0.0","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/homepages#readme","bugs":{"url":"https://github.com/falktravis/homepages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"e760fa155ee11529d06e4cfc535e1d08b0658612","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-6.0.0.tgz","fileCount":178,"integrity":"sha512-C13PbulkZEhj04hQYqvBbyZe1S0Fz1+1fvC7+bQfYr2Qmc/McMCNJ+enUl35+8EUb391eg6cDir1ohkRXl9yNw==","signatures":[{"sig":"MEUCIQDicmahy6ymDwFpuqzrxhHjF6sXMl/mpna+VGFqKReV3gIgfj3VQ4pxvV+POtWKXD2BTgwG2uAXmxlVtSfkubY/CYo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1330554},"type":"module","_from":"file:/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-6.0.0.tgz","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"travisfalk","email":"falk.travis@gmail.com","approver":{"name":"travisfalk","email":"falk.travis@gmail.com"}},"_resolved":"/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-6.0.0.tgz","_integrity":"sha512-C13PbulkZEhj04hQYqvBbyZe1S0Fz1+1fvC7+bQfYr2Qmc/McMCNJ+enUl35+8EUb391eg6cDir1ohkRXl9yNw==","repository":{"url":"git+https://github.com/falktravis/homepages.git","type":"git","directory":"packages/external/template-cli"},"_npmVersion":"12.0.2","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.22.2","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@homepages/icon":"workspace:*","@homepages/modal":"workspace:*","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@homepages/dev-media":"workspace:*","@vitejs/plugin-react":"^4.3.4","@homepages/image-crop":"workspace:*","@tanstack/react-query":"^5.100.14","@homepages/canvas-core":"workspace:*","@homepages/html-escape":"workspace:*","@homepages/image-ladder":"workspace:*","@homepages/slot-editors":"workspace:*","@homepages/template-kit":"workspace:*","@homepages/editor-tokens":"workspace:*","@homepages/internal-refs":"workspace:*","@homepages/media-library":"workspace:*","@typescript-eslint/parser":"^8.60.1","@homepages/fill-vocabulary":"workspace:*","@homepages/template-tooling":"workspace:*","@homepages/effective-version":"workspace:*","@homepages/section-contracts":"workspace:*","@homepages/template-contracts":"workspace:*","@homepages/static-assets-binding":"workspace:*","@homepages/eslint-plugin-template":"workspace:*","@homepages/template-rule-registry":"workspace:*"},"peerDependencies":{"@homepages/template-kit":"^6.0.0"},"$comment:bin-warning":"A `pnpm install` before this package's first build prints 'WARN Failed to create bin ... template-kit ENOENT' once per internal workspace member that declares this package as a devDependency — pnpm's bin linker reads dist/cli.js to set it up and it does not exist yet. Expected and harmless: a subsequent build populates dist/cli.js and the next install links cleanly. Not fixable without either committing build output (dist/ is gitignored by design) or moving the bin off dist/ (would touch the published entry point every consumer and guide page resolves — too large a change for this warning). Suppressing it would need a pnpm bin-link config pnpm does not expose (verified: preferSymlinkedExecutables still fails, at the chmod step).","optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_6.0.0_1786662131751_0.7528846517859715","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the shared ladder POLICY (@homepages/image-ladder, inlined into dist at build time), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"7.0.0":{"name":"@homepages/template-cli","version":"7.0.0","license":"UNLICENSED","_id":"@homepages/template-cli@7.0.0","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/homepages#readme","bugs":{"url":"https://github.com/falktravis/homepages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"5430ca27f346cc9f0f5c69e39e01e0e7811bb660","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-7.0.0.tgz","fileCount":183,"integrity":"sha512-aIB2GMpUoyWHgLwEV15MtYWFjtMaAnGxMj+p3xUkQ3x9xfr7x5gZnFqUUWSQsWddGHBv4LPNsfKdBdCVTBOpkQ==","signatures":[{"sig":"MEQCIFrqaTwFTE7m0SYpo5lKe58kCVDbNTzo79O72qmgtRf0AiBJwlYYIiVrXeRu7regefkq7g7JFW+kiacXcVMjAB/H5w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1366255},"type":"module","_from":"file:/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-7.0.0.tgz","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs && node scripts/build-cli-assets.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"travisfalk","email":"falk.travis@gmail.com","approver":{"name":"travisfalk","email":"falk.travis@gmail.com"}},"_resolved":"/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-7.0.0.tgz","_integrity":"sha512-aIB2GMpUoyWHgLwEV15MtYWFjtMaAnGxMj+p3xUkQ3x9xfr7x5gZnFqUUWSQsWddGHBv4LPNsfKdBdCVTBOpkQ==","repository":{"url":"git+https://github.com/falktravis/homepages.git","type":"git","directory":"packages/external/template-cli"},"_npmVersion":"12.0.2","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.22.2","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@homepages/icon":"workspace:*","@homepages/modal":"workspace:*","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@homepages/dev-media":"workspace:*","@vitejs/plugin-react":"^4.3.4","@homepages/image-crop":"workspace:*","@tanstack/react-query":"^5.100.14","@homepages/canvas-core":"workspace:*","@homepages/html-escape":"workspace:*","@homepages/image-ladder":"workspace:*","@homepages/slot-editors":"workspace:*","@homepages/template-kit":"workspace:*","@homepages/editor-tokens":"workspace:*","@homepages/internal-refs":"workspace:*","@homepages/media-library":"workspace:*","@typescript-eslint/parser":"^8.60.1","@homepages/fill-vocabulary":"workspace:*","@homepages/template-tooling":"workspace:*","@homepages/effective-version":"workspace:*","@homepages/section-contracts":"workspace:*","@homepages/template-contracts":"workspace:*","@homepages/static-assets-binding":"workspace:*","@homepages/eslint-plugin-template":"workspace:*","@homepages/template-rule-registry":"workspace:*"},"peerDependencies":{"@homepages/template-kit":"^7.0.0"},"$comment:bin-warning":"A `pnpm install` before this package's first build prints 'WARN Failed to create bin ... template-kit ENOENT' once per internal workspace member that declares this package as a devDependency — pnpm's bin linker reads dist/cli.js to set it up and it does not exist yet. Expected and harmless: a subsequent build populates dist/cli.js and the next install links cleanly. Not fixable without either committing build output (dist/ is gitignored by design) or moving the bin off dist/ (would touch the published entry point every consumer and guide page resolves — too large a change for this warning). Suppressing it would need a pnpm bin-link config pnpm does not expose (verified: preferSymlinkedExecutables still fails, at the chmod step).","optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids.","_npmOperationalInternal":{"tmp":"tmp/template-cli_7.0.0_1786841111951_0.4923341240807324","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the shared ladder POLICY (@homepages/image-ladder, inlined into dist at build time), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"8.0.0":{"name":"@homepages/template-cli","version":"8.0.0","license":"UNLICENSED","_id":"@homepages/template-cli@8.0.0","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/homepages#readme","bugs":{"url":"https://github.com/falktravis/homepages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"90733813feb6860d3a691eb9bd44c258f3f35f42","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-8.0.0.tgz","fileCount":204,"integrity":"sha512-xIbm03fiHSUvC6KnWwZGwnGbrcT026ttBC2fuceZlfWOycQtRp9OD44/hqjnZnfeUmGApaLUB1bP6kYCSaO5CA==","signatures":[{"sig":"MEUCIQCx2x6HH5k1Y14urNkqpBnhFmapTHixGaU1I6d3Epb4RQIgUbjuKLt5xIrelj9yTnBkeWt4zcqoHM7H6ytKrqdw+mw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1520668},"type":"module","_from":"file:/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-8.0.0.tgz","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"travisfalk","email":"falk.travis@gmail.com","approver":{"name":"travisfalk","email":"falk.travis@gmail.com"}},"_resolved":"/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-8.0.0.tgz","_integrity":"sha512-xIbm03fiHSUvC6KnWwZGwnGbrcT026ttBC2fuceZlfWOycQtRp9OD44/hqjnZnfeUmGApaLUB1bP6kYCSaO5CA==","repository":{"url":"git+https://github.com/falktravis/homepages.git","type":"git","directory":"packages/external/template-cli"},"_npmVersion":"12.0.2","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.22.2","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","fflate":"^0.8.2","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@homepages/icon":"workspace:*","@homepages/modal":"workspace:*","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@homepages/dev-media":"workspace:*","@vitejs/plugin-react":"^4.3.4","@homepages/image-crop":"workspace:*","@homepages/page-shell":"workspace:*","@tanstack/react-query":"^5.100.14","@homepages/canvas-core":"workspace:*","@homepages/html-escape":"workspace:*","@homepages/image-ladder":"workspace:*","@homepages/slot-editors":"workspace:*","@homepages/template-kit":"workspace:*","@homepages/editor-tokens":"workspace:*","@homepages/internal-refs":"workspace:*","@homepages/media-library":"workspace:*","@typescript-eslint/parser":"^8.60.1","@homepages/fill-vocabulary":"workspace:*","@homepages/format-geometry":"workspace:*","@homepages/template-tooling":"workspace:*","@homepages/effective-version":"workspace:*","@homepages/section-contracts":"workspace:*","@homepages/template-contracts":"workspace:*","@homepages/static-assets-binding":"workspace:*","@homepages/eslint-plugin-template":"workspace:*","@homepages/template-rule-registry":"workspace:*"},"peerDependencies":{"@homepages/template-kit":"^8.0.0"},"$comment:bin-warning":"A `pnpm install` before this package's first build prints 'WARN Failed to create bin ... template-kit ENOENT' once per internal workspace member that declares this package as a devDependency — pnpm's bin linker reads dist/cli.js to set it up and it does not exist yet. Expected and harmless: a subsequent build populates dist/cli.js and the next install links cleanly. Not fixable without either committing build output (dist/ is gitignored by design) or moving the bin off dist/ (would touch the published entry point every consumer and guide page resolves — too large a change for this warning). Suppressing it would need a pnpm bin-link config pnpm does not expose (verified: preferSymlinkedExecutables still fails, at the chmod step).","optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids. fflate is a fourth kind again: the dev server zips an image template's page set the way the render worker does, and tsdown compiles it INTO dist (it is neither in `deps.neverBundle` nor auto-externalized), so a consumer installs nothing for it — do not \"fix\" it into `dependencies`.","_npmOperationalInternal":{"tmp":"tmp/template-cli_8.0.0_1787506087641_0.002068151217903269","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the shared ladder POLICY (@homepages/image-ladder, inlined into dist at build time), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"8.0.1":{"name":"@homepages/template-cli","version":"8.0.1","license":"UNLICENSED","_id":"@homepages/template-cli@8.0.1","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/homepages#readme","bugs":{"url":"https://github.com/falktravis/homepages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"0a1ee738337fd0e26f7fc2d7bb0e1829ebe2b846","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-8.0.1.tgz","fileCount":204,"integrity":"sha512-YVdAvQEiD1h+cROi2VonWKq611MV4REXlghl97K/Yr2RuftfMIAigzq5s22iPEXw0geb3JceiPT5b+ZFSx7FLA==","signatures":[{"sig":"MEUCIQCiOAuiDbHeVXrgcDe3sXgCVUxYEwGP2fb6jCWgTzYgEgIgTAWdYsjHejwuHj95aF5loMyqZtmjtj9xSNHpR95YCrY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1520678},"type":"module","_from":"file:/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-8.0.1.tgz","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"travisfalk","email":"falk.travis@gmail.com","approver":{"name":"travisfalk","email":"falk.travis@gmail.com"}},"_resolved":"/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-8.0.1.tgz","_integrity":"sha512-YVdAvQEiD1h+cROi2VonWKq611MV4REXlghl97K/Yr2RuftfMIAigzq5s22iPEXw0geb3JceiPT5b+ZFSx7FLA==","repository":{"url":"git+https://github.com/falktravis/homepages.git","type":"git","directory":"packages/external/template-cli"},"_npmVersion":"12.0.2","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.22.2","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","fflate":"^0.8.2","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@homepages/icon":"workspace:*","@homepages/modal":"workspace:*","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@homepages/dev-media":"workspace:*","@vitejs/plugin-react":"^4.3.4","@homepages/image-crop":"workspace:*","@homepages/page-shell":"workspace:*","@tanstack/react-query":"^5.100.14","@homepages/canvas-core":"workspace:*","@homepages/html-escape":"workspace:*","@homepages/image-ladder":"workspace:*","@homepages/slot-editors":"workspace:*","@homepages/template-kit":"workspace:*","@homepages/editor-tokens":"workspace:*","@homepages/internal-refs":"workspace:*","@homepages/media-library":"workspace:*","@typescript-eslint/parser":"^8.60.1","@homepages/fill-vocabulary":"workspace:*","@homepages/format-geometry":"workspace:*","@homepages/template-tooling":"workspace:*","@homepages/effective-version":"workspace:*","@homepages/section-contracts":"workspace:*","@homepages/template-contracts":"workspace:*","@homepages/static-assets-binding":"workspace:*","@homepages/eslint-plugin-template":"workspace:*","@homepages/template-rule-registry":"workspace:*"},"peerDependencies":{"@homepages/template-kit":"^8.0.0"},"$comment:bin-warning":"A `pnpm install` before this package's first build prints 'WARN Failed to create bin ... template-kit ENOENT' once per internal workspace member that declares this package as a devDependency — pnpm's bin linker reads dist/cli.js to set it up and it does not exist yet. Expected and harmless: a subsequent build populates dist/cli.js and the next install links cleanly. Not fixable without either committing build output (dist/ is gitignored by design) or moving the bin off dist/ (would touch the published entry point every consumer and guide page resolves — too large a change for this warning). Suppressing it would need a pnpm bin-link config pnpm does not expose (verified: preferSymlinkedExecutables still fails, at the chmod step).","optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids. fflate is a fourth kind again: the dev server zips an image template's page set the way the render worker does, and tsdown compiles it INTO dist (it is neither in `deps.neverBundle` nor auto-externalized), so a consumer installs nothing for it — do not \"fix\" it into `dependencies`.","_npmOperationalInternal":{"tmp":"tmp/template-cli_8.0.1_1787508427999_0.7202358144251013","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the shared ladder POLICY (@homepages/image-ladder, inlined into dist at build time), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"9.0.0":{"name":"@homepages/template-cli","version":"9.0.0","license":"UNLICENSED","_id":"@homepages/template-cli@9.0.0","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/homepages#readme","bugs":{"url":"https://github.com/falktravis/homepages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"7ecac49ee5a7ddec335093007fdfc7bad6bbf10b","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-9.0.0.tgz","fileCount":205,"integrity":"sha512-t4JCPenNf9/+IujmAkXqscR2h2ME6ZtUu6Ypmi3cLHkZL/QfPb7OtkSJiAE+rx1VnFfAOWXRQQ9hNR1iNb+PyA==","signatures":[{"sig":"MEYCIQCJNQxeXzVB10mZmBmje76wGrcLpc8fHvY7AckEZDvg2AIhAN81mAWy1LxYItFbTykySksNWJxaEyelwS7puDF79OzS","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1620262},"type":"module","_from":"file:/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-9.0.0.tgz","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"travisfalk","email":"falk.travis@gmail.com","approver":{"name":"travisfalk","email":"falk.travis@gmail.com"}},"_resolved":"/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-9.0.0.tgz","_integrity":"sha512-t4JCPenNf9/+IujmAkXqscR2h2ME6ZtUu6Ypmi3cLHkZL/QfPb7OtkSJiAE+rx1VnFfAOWXRQQ9hNR1iNb+PyA==","repository":{"url":"git+https://github.com/falktravis/homepages.git","type":"git","directory":"packages/external/template-cli"},"_npmVersion":"12.0.2","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.22.2","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","fflate":"^0.8.2","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@homepages/icon":"workspace:*","@homepages/modal":"workspace:*","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@homepages/dev-media":"workspace:*","@vitejs/plugin-react":"^4.3.4","@homepages/image-crop":"workspace:*","@homepages/page-shell":"workspace:*","@tanstack/react-query":"^5.100.14","@homepages/canvas-core":"workspace:*","@homepages/html-escape":"workspace:*","@homepages/image-ladder":"workspace:*","@homepages/slot-editors":"workspace:*","@homepages/template-kit":"workspace:*","@homepages/editor-tokens":"workspace:*","@homepages/internal-refs":"workspace:*","@homepages/media-library":"workspace:*","@typescript-eslint/parser":"^8.60.1","@homepages/fill-vocabulary":"workspace:*","@homepages/format-geometry":"workspace:*","@homepages/template-tooling":"workspace:*","@homepages/effective-version":"workspace:*","@homepages/section-contracts":"workspace:*","@homepages/template-contracts":"workspace:*","@homepages/static-assets-binding":"workspace:*","@homepages/eslint-plugin-template":"workspace:*","@homepages/template-rule-registry":"workspace:*"},"peerDependencies":{"@homepages/template-kit":"^9.0.0"},"$comment:bin-warning":"A `pnpm install` before this package's first build prints 'WARN Failed to create bin ... template-kit ENOENT' once per internal workspace member that declares this package as a devDependency — pnpm's bin linker reads dist/cli.js to set it up and it does not exist yet. Expected and harmless: a subsequent build populates dist/cli.js and the next install links cleanly. Not fixable without either committing build output (dist/ is gitignored by design) or moving the bin off dist/ (would touch the published entry point every consumer and guide page resolves — too large a change for this warning). Suppressing it would need a pnpm bin-link config pnpm does not expose (verified: preferSymlinkedExecutables still fails, at the chmod step).","optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids. fflate is a fourth kind again: the dev server zips an image template's page set the way the render worker does, and tsdown compiles it INTO dist (it is neither in `deps.neverBundle` nor auto-externalized), so a consumer installs nothing for it — do not \"fix\" it into `dependencies`.","_npmOperationalInternal":{"tmp":"tmp/template-cli_9.0.0_1787936036968_0.787922478694097","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the shared ladder POLICY (@homepages/image-ladder, inlined into dist at build time), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."},"10.0.0":{"name":"@homepages/template-cli","version":"10.0.0","license":"UNLICENSED","_id":"@homepages/template-cli@10.0.0","maintainers":[{"name":"travisfalk","email":"falk.travis@gmail.com"}],"homepage":"https://github.com/falktravis/homepages#readme","bugs":{"url":"https://github.com/falktravis/homepages/issues"},"bin":{"template-kit":"dist/cli.js"},"dist":{"shasum":"206f814611f43a39242351e447264ee9617336f3","tarball":"https://registry.npmjs.org/@homepages/template-cli/-/template-cli-10.0.0.tgz","fileCount":209,"integrity":"sha512-zmfC7kTh3R/ptI1E45zaLhNoAVIuMofn017wK+CDEEQqsJaGBTPxmSXALoRxCh7CvAKhOZsVo87XXw05AXVjEA==","signatures":[{"sig":"MEUCIGHkwo5MFLjpbjsW8+VrQy2n78KaZ6MOv3yHgsmcfBxAAiEAuJPeG3Eu54QoTeVLMgz5r63Y+puFHkcdMBiw54SqEmE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1659906},"type":"module","_from":"file:/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-10.0.0.tgz","engines":{"node":"^22.13.0 || >=24"},"exports":{"./package.json":"./package.json"},"scripts":{"lint":"eslint .","test":"node --import tsx --test --test-timeout=300000 'src/**/*.test.ts' 'src/**/*.test.tsx'","build":"tsdown && node --import tsx scripts/build-dev-client.mjs","check":"npm run typecheck && npm run lint && npm run build && npm run test && npm run lint:pkg && npm run verify:consumer","prepack":"npm run build","pretest":"node test/link-fixture-workspace.mjs","lint:pkg":"publint --strict","typecheck":"tsc --noEmit","verify:consumer":"node scripts/verify-consumer.mjs"},"_npmUser":{"name":"travisfalk","email":"falk.travis@gmail.com","approver":{"name":"travisfalk","email":"falk.travis@gmail.com"}},"_resolved":"/home/tfalk/Documents/homepages/packages/external/template-cli/homepages-template-cli-10.0.0.tgz","_integrity":"sha512-zmfC7kTh3R/ptI1E45zaLhNoAVIuMofn017wK+CDEEQqsJaGBTPxmSXALoRxCh7CvAKhOZsVo87XXw05AXVjEA==","repository":{"url":"git+https://github.com/falktravis/homepages.git","type":"git","directory":"packages/external/template-cli"},"_npmVersion":"12.0.2","description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","directories":{},"$comment:bin":"The package is @homepages/template-cli but the command stays `template-kit`. Package/bin mismatch is ordinary (@angular/cli -> ng, typescript -> tsc) and it keeps every guide page, workspace script, and skill runbook that types `template-kit dev` working unchanged.","_nodeVersion":"22.22.2","dependencies":{"zod":"^4.4.3"},"$comment:peer":"The kit is a PEER, never a dependency. As a dependency, a range here that diverged from the consumer workspace's would make npm install TWO copies of the kit — two zod schema identities and two sets of marker constants, silently, and invisible to jsdom. The peer makes 'exactly one kit' structural; scripts/verify-consumer.mjs asserts it.","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.2","clsx":"^2.1.1","vite":"^6.0.5","jsdom":"^26.1.0","react":"^19.0.0","eslint":"^10.8.0","fflate":"^0.8.2","semver":"^7.6.3","tsdown":"0.22.7","esbuild":"^0.28.1","publint":"^0.3.21","zustand":"^5.0.13","react-dom":"^19.0.0","@eslint/js":"^10.0.1","typescript":"^5.7.2","@types/node":"^20.17.10","tailwindcss":"^4.3.0","@types/jsdom":"^21.1.7","@types/react":"^19.0.0","lucide-react":"^1.17.0","@types/semver":"^7.5.8","tailwind-merge":"^3.6.0","@homepages/icon":"workspace:*","@homepages/modal":"workspace:*","@playwright/test":"^1.60.0","@tailwindcss/cli":"^4.3.0","@types/react-dom":"^19.0.0","@tailwindcss/vite":"^4.3.3","typescript-eslint":"^8.60.1","@homepages/dev-media":"workspace:*","@vitejs/plugin-react":"^4.3.4","@homepages/image-crop":"workspace:*","@homepages/page-shell":"workspace:*","@tanstack/react-query":"^5.100.14","@homepages/canvas-core":"workspace:*","@homepages/html-escape":"workspace:*","@homepages/image-ladder":"workspace:*","@homepages/slot-editors":"workspace:*","@homepages/template-kit":"workspace:*","@homepages/editor-tokens":"workspace:*","@homepages/internal-refs":"workspace:*","@homepages/media-library":"workspace:*","@typescript-eslint/parser":"^8.60.1","@homepages/fill-vocabulary":"workspace:*","@homepages/format-geometry":"workspace:*","@homepages/template-tooling":"workspace:*","@homepages/effective-version":"workspace:*","@homepages/section-contracts":"workspace:*","@homepages/template-contracts":"workspace:*","@homepages/static-assets-binding":"workspace:*","@homepages/eslint-plugin-template":"workspace:*","@homepages/template-rule-registry":"workspace:*"},"peerDependencies":{"@homepages/template-kit":"^10.0.0"},"$comment:bin-warning":"A `pnpm install` before this package's first build prints 'WARN Failed to create bin ... template-kit ENOENT' once per internal workspace member that declares this package as a devDependency — pnpm's bin linker reads dist/cli.js to set it up and it does not exist yet. Expected and harmless: a subsequent build populates dist/cli.js and the next install links cleanly. Not fixable without either committing build output (dist/ is gitignored by design) or moving the bin off dist/ (would touch the published entry point every consumer and guide page resolves — too large a change for this warning). Suppressing it would need a pnpm bin-link config pnpm does not expose (verified: preferSymlinkedExecutables still fails, at the chmod step).","optionalDependencies":{"sharp":"^0.35.3"},"$comment:dependencies":"zod is the ONLY real runtime dependency, and the list stays that way on purpose. TypeScript, ESLint, esbuild, vite and @vitejs/plugin-react are all loaded through src/cli/check/resolve-tool.ts from the WORKSPACE being operated on, never from this package's tree — so an author's own version judges their code, and every one of them can be a devDependency here, the only block npm never installs for a consumer. An optional peer would NOT be equivalent: npm resolves the peer edge from an installed package and `--omit=dev` keeps it. @homepages/eslint-plugin-template is likewise the workspace's devDependency (the scaffold declares it, and `check` reaches it through the workspace's own eslint.config.mjs), not ours. react/react-dom are type-only on the node side and pre-bundled into dist/dev-client by vite, so they are neither dependency nor peer. @tanstack/react-query and zustand join them on exactly that footing: the vendored media slot editors import them, and they reach a consumer only inside the pre-bundled dev-client, never as an install-time edge. Their ranges are pinned to match the application the editors are vendored from — two copies of a state library that disagree at runtime is the failure this avoids. fflate is a fourth kind again: the dev server zips an image template's page set the way the render worker does, and tsdown compiles it INTO dist (it is neither in `deps.neverBundle` nor auto-externalized), so a consumer installs nothing for it — do not \"fix\" it into `dependencies`.","_npmOperationalInternal":{"tmp":"tmp/template-cli_10.0.0_1788888414266_0.0989845026288434","host":"s3://npm-registry-packages-npm-production"},"$comment:optionalDependencies":"sharp is optional, not a dependency: this package ships to agencies over public npm, and a hard sharp would put platform-specific native binaries into every install. The range is a CARET, deliberately. It used to be an exact version, on the theory that matching the pipeline that processes uploaded photos byte-for-byte made the image ladder derive identically — but nothing enforced that (that pipeline was itself a caret), and what actually guarantees identical derivation is the shared ladder POLICY (@homepages/image-ladder, inlined into dist at build time), not the encoder build. What the exact pin cost was that clearing a libvips CVE below the floor was no longer a shared fix: a consumer's own overrides block CAN reach through an exact pin and win, but only inside that one consumer's tree, so every consumer needed its own — including agencies installing over public npm who cannot be reached or coordinated — and it forced this package to be republished on top of that. A caret in this range clears the CVE for every consumer at once via a lockfile refresh instead. TWO TRAPS if you revisit this: (1) npm's own fixAvailable for the libvips advisory proposes a MAJOR DOWNGRADE of @homepages/template-cli — it satisfies the advisory count by removing the CLI the templates are authored against, and is not a fix; (2) when sharp is absent the deriver degrades to responsive: null and passes the master through, so a failed install passes npm audit AND `template-kit check` while silently disabling the responsive ladder — verify a real derivation, not the audit count (src/cli/media/derive.test.ts asserts exactly that: sharp resolving means passthrough must be false).","deprecated":"Package no longer supported. Contact Support at https://www.npmjs.com/support for more info."}},"time":{"created":"2026-07-19T23:31:32.097Z","modified":"2026-09-18T13:43:55.711Z","0.1.0":"2026-07-19T23:31:32.518Z","0.1.1":"2026-07-20T01:25:21.537Z","0.1.2":"2026-07-21T00:24:03.325Z","0.2.0":"2026-07-22T12:00:14.361Z","0.2.1-dev-20260722152325":"2026-07-22T15:25:55.069Z","0.2.1":"2026-07-22T15:49:30.972Z","1.0.0-dev-20260722183710":"2026-07-22T18:37:17.979Z","1.0.0-dev-20260722191436":"2026-07-22T19:14:43.842Z","1.0.0-dev-20260722193254":"2026-07-22T19:33:03.477Z","0.2.2":"2026-07-22T23:54:56.404Z","0.3.0":"2026-07-23T01:49:39.868Z","1.0.0":"2026-07-23T14:18:34.200Z","2.0.0-dev-20260724195104":"2026-07-24T19:51:12.685Z","2.0.0-dev-20260725021840":"2026-07-25T02:18:49.431Z","2.0.0-dev-20260725222034":"2026-07-25T22:20:45.429Z","2.0.0-dev-20260725233009":"2026-07-25T23:30:19.879Z","2.0.0-dev-20260726004823":"2026-07-26T00:48:35.368Z","2.0.0-dev-20260726015619":"2026-07-26T01:56:31.637Z","2.0.0-dev-20260726022255":"2026-07-26T02:23:06.576Z","2.0.0-dev-20260726031323":"2026-07-26T03:13:34.645Z","2.0.0-dev-20260726112057":"2026-07-26T11:21:09.512Z","2.0.0-dev-20260726122014":"2026-07-26T12:20:25.714Z","2.0.0-dev-20260726122601":"2026-07-26T12:26:13.078Z","2.0.0-dev-20260726130403":"2026-07-26T13:04:15.815Z","2.0.0-dev-20260726150557":"2026-07-26T15:06:08.639Z","2.0.0-dev-20260726151403":"2026-07-26T15:14:14.064Z","2.0.0-dev-20260726163042":"2026-07-26T16:30:54.471Z","2.0.0-dev-20260726171747":"2026-07-26T17:17:58.240Z","2.0.0-dev-20260726175448":"2026-07-26T17:54:59.150Z","2.0.0-dev-20260726193345":"2026-07-26T19:33:57.196Z","2.0.0-dev-20260726215326":"2026-07-26T21:53:38.724Z","2.0.0-dev-20260727000223":"2026-07-27T00:02:34.316Z","2.0.0-dev-20260727003512":"2026-07-27T00:35:24.525Z","2.0.0-dev-20260727015628":"2026-07-27T01:56:40.223Z","2.0.0-dev-20260727031013":"2026-07-27T03:10:25.107Z","2.0.0-dev-20260727035145":"2026-07-27T03:51:57.501Z","2.0.0-dev-20260727115109":"2026-07-27T11:51:21.047Z","2.0.0-dev-20260727122838":"2026-07-27T12:28:49.815Z","2.0.0-dev-20260727133549":"2026-07-27T13:36:02.716Z","2.0.0-dev-20260727142818":"2026-07-27T14:28:29.208Z","2.0.0-dev-20260727174231":"2026-07-27T17:43:05.465Z","2.0.0-dev-20260727180158":"2026-07-27T18:02:32.516Z","2.0.0-dev-20260727194158":"2026-07-27T19:42:34.675Z","2.0.0-dev-20260727202116":"2026-07-27T20:21:51.827Z","2.0.0-dev-20260727205941":"2026-07-27T21:00:18.697Z","2.0.0-dev-20260727225138":"2026-07-27T22:52:14.505Z","2.0.0-dev-20260728011139":"2026-07-28T01:12:14.982Z","2.0.0-dev-20260728021150":"2026-07-28T02:12:23.433Z","2.0.0-dev-20260728033307":"2026-07-28T03:33:37.014Z","2.0.0-dev-20260728113846":"2026-07-28T11:39:21.969Z","2.0.0-dev-20260728131506":"2026-07-28T13:15:40.843Z","2.0.0-dev-20260728172654":"2026-07-28T17:27:30.570Z","2.0.0-dev-20260728180604":"2026-07-28T18:06:41.036Z","2.0.0":"2026-07-29T13:08:43.787Z","2.0.1-dev-20260729174949":"2026-07-29T17:50:21.958Z","2.0.1":"2026-07-29T18:37:56.247Z","2.1.0-dev-20260729203301":"2026-07-29T20:33:32.752Z","2.1.0-dev-20260729232501":"2026-07-29T23:25:34.879Z","2.1.0":"2026-07-30T00:17:24.205Z","2.2.0-dev-20260731213520":"2026-07-31T21:35:50.601Z","2.2.0":"2026-07-31T23:46:18.308Z","2.2.1":"2026-08-01T00:36:10.835Z","2.2.2":"2026-08-02T20:45:47.828Z","2.3.0":"2026-08-04T19:38:59.038Z","3.0.0":"2026-08-06T01:20:54.425Z","3.0.1":"2026-08-06T14:11:57.942Z","4.0.0":"2026-08-09T15:20:20.557Z","5.0.0":"2026-08-12T00:50:16.959Z","6.0.0":"2026-08-13T23:02:11.969Z","7.0.0":"2026-08-16T00:45:12.057Z","8.0.0":"2026-08-23T17:28:07.740Z","8.0.1":"2026-08-23T18:07:08.109Z","9.0.0":"2026-08-28T16:53:57.128Z","10.0.0":"2026-09-08T17:26:54.379Z"},"bugs":{"url":"https://github.com/falktravis/homepages/issues"},"license":"UNLICENSED","homepage":"https://github.com/falktravis/homepages#readme","repository":{"url":"git+https://github.com/falktravis/homepages.git","type":"git","directory":"packages/external/template-cli"},"description":"The template-kit CLI: check, dev (with the canvas playground), new, pack, theme, and link. Peers @homepages/template-kit.","maintainers":[{"name":"falktravis","email":"travis@homepages.io"}],"readme":"ERROR: No README data found!","readmeFilename":""}