{"_id":"@konstantdotcloud/boombox","_rev":"33-364bf9396e45dd55c699a72cfd2e9cb1","name":"@konstantdotcloud/boombox","dist-tags":{"latest":"0.14.11"},"versions":{"0.1.0":{"name":"@konstantdotcloud/boombox","version":"0.1.0","license":"UNLICENSED","_id":"@konstantdotcloud/boombox@0.1.0","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"ab6c5c49bcb606d4d090954b6a74ea2f461d13ac","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.1.0.tgz","fileCount":10,"integrity":"sha512-RlA9zppFs6PrZgQY4EVWWyUqNVL7oe4kV0JByA+8HSwJ/PSZtstYS4VJk0I8m9apEkcQBqtdv22NKeGXuh83PA==","signatures":[{"sig":"MEYCIQCn6J3dgWCIYDWygOvr3ijwoi6hpCdV7aqM2zpbawl/igIhAOlYQkBmtKabcnJIvjKb3u/ZZ25PtJv2TIY43G387tFa","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":4914316},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"scripts":{"dev":"tsx bin/boombox.ts","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","test:watch":"vitest","release:major":"npm version major --no-git-tag-version && npm publish --access public","release:minor":"npm version minor --no-git-tag-version && npm publish --access public","release:patch":"npm version patch --no-git-tag-version && npm publish --access public","prepublishOnly":"npm run build"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"_npmVersion":"11.10.1","description":"Local Boombox runtime for Konstant cassettes — CLI, stdio MCP server, and local Hono proxy.","directories":{},"_nodeVersion":"25.7.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^1.19.9","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.1.0_1780512735290_0.8647313860980668","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@konstantdotcloud/boombox","version":"0.1.1","license":"UNLICENSED","_id":"@konstantdotcloud/boombox@0.1.1","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"ab4c5e1699e85c069f90c66b4e9259a92abce3df","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.1.1.tgz","fileCount":10,"integrity":"sha512-+WQB/hol9EJrsHCLtcTyoMWLqwPf3bSPHSj9W8mbSmWTzRrq2gzaCaf3VOmbrJ24O5ePKzQCSbocYC2ZfV90gg==","signatures":[{"sig":"MEYCIQCx6J4vHOgdTetnJNXx1YOHheqkgqmwbO1QouUertVQ8gIhAL8aQlpzfZ+XalVuzCCnxlldoWBXsr4b/HwRGL0slUp3","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":4916520},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"scripts":{"dev":"tsx bin/boombox.ts","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","test:watch":"vitest","release:major":"npm version major --no-git-tag-version && npm publish --access public","release:minor":"npm version minor --no-git-tag-version && npm publish --access public","release:patch":"npm version patch --no-git-tag-version && npm publish --access public","prepublishOnly":"npm run build"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"_npmVersion":"11.10.1","description":"Local Boombox runtime for Konstant cassettes — CLI, stdio MCP server, and local Hono proxy.","directories":{},"_nodeVersion":"25.7.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^1.19.9","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.1.1_1780517515176_0.45046305284910226","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@konstantdotcloud/boombox","version":"0.1.2","license":"UNLICENSED","_id":"@konstantdotcloud/boombox@0.1.2","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"5bd4d25f074e0742d87974d516641e2debd1b4c7","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.1.2.tgz","fileCount":10,"integrity":"sha512-CS05isxIzVhOavooUmbnFzRfRwPQpTG3N13vYa4amNW6KuuSL961GJB05iKNR0r2Ec6/fO8QFChBc0a5UabHYA==","signatures":[{"sig":"MEQCIAW6AUmEt8USPqbk+l1JxQ8n0X/hrBGidXeHvpPsdd+aAiAw7rrVSVOp8yDTBIWkt4+cnr9P5+9vyxvNq5AU3McN+g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":4917789},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"gitHead":"12212518ed5233e7609b210c58d354e1372d292d","scripts":{"dev":"tsx bin/boombox.ts","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","test:watch":"vitest","release:major":"npm version major --no-git-tag-version && npm publish --access public","release:minor":"npm version minor --no-git-tag-version && npm publish --access public","release:patch":"npm version patch --no-git-tag-version && npm publish --access public","prepublishOnly":"npm run build"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"_npmVersion":"10.9.4","description":"Local Boombox runtime for Konstant cassettes — CLI, stdio MCP server, and local Hono proxy.","directories":{},"_nodeVersion":"22.22.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^1.19.9","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.1.2_1781261451887_0.9351174499402832","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@konstantdotcloud/boombox","version":"0.2.0","license":"UNLICENSED","_id":"@konstantdotcloud/boombox@0.2.0","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"b5f5938faadb49e010047e92d461fde8f68f709f","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.2.0.tgz","fileCount":10,"integrity":"sha512-KXnHfqm7qPtlDCActp++rUpexRNUVd94n2QH2kR/vzgWXNt6VJvH84roSQxnW5sYXgKuROShasbdrJF9n4Y0XA==","signatures":[{"sig":"MEYCIQCTobQk/O8ZsWcjktTjq/3A6Ixn2tFHjiNpdsKVitXjqQIhAOC0Ls1bD14whN/NYGyeWa9RkUapwrnuntEr3iS1KpJV","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":4923020},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"gitHead":"ce4f5fdf1362f523ec203040a6dec121da5729a0","scripts":{"dev":"tsx bin/boombox.ts","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","test:watch":"vitest","release:major":"npm version major --no-git-tag-version && npm publish --access public","release:minor":"npm version minor --no-git-tag-version && npm publish --access public","release:patch":"npm version patch --no-git-tag-version && npm publish --access public","prepublishOnly":"npm run build"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"_npmVersion":"10.9.4","description":"Local Boombox runtime for Konstant cassettes — CLI, stdio MCP server, and local Hono proxy.","directories":{},"_nodeVersion":"22.22.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^1.19.9","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.2.0_1781295772053_0.6867202781807735","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@konstantdotcloud/boombox","version":"0.3.0","license":"UNLICENSED","_id":"@konstantdotcloud/boombox@0.3.0","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"b7a647288f8b1403be6e7fe200747db7f3fef95d","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.3.0.tgz","fileCount":10,"integrity":"sha512-SGch3e2uXKRMSZhoQoocyW05HzoS1cO3OmuEkZ6FYX9YGvN3+yow1X7fPjP/amIynkFTtwrbDUF/H6m6o8i0oA==","signatures":[{"sig":"MEUCIFQ//cr87U7A4uLbHPzMA6FWGrzprmKUNxu0hhG04o3/AiEAnL+8xENs1wiIwIqHXuMcexFgJ8Qj/oEJlr4mgdFT6NE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":4965373},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"gitHead":"f0066e0d4f52d22477fa7247d647b5cbe17e6f41","scripts":{"dev":"tsx bin/boombox.ts","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","test:watch":"vitest","release:major":"npm version major --no-git-tag-version && npm publish --access public","release:minor":"npm version minor --no-git-tag-version && npm publish --access public","release:patch":"npm version patch --no-git-tag-version && npm publish --access public","prepublishOnly":"npm run build"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"_npmVersion":"10.9.4","description":"Local Boombox runtime for Konstant cassettes — CLI, stdio MCP server, and local Hono proxy.","directories":{},"_nodeVersion":"22.22.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^1.19.9","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.3.0_1781736540739_0.1304740878645685","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@konstantdotcloud/boombox","version":"0.3.1","license":"UNLICENSED","_id":"@konstantdotcloud/boombox@0.3.1","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"e93c6e1d060033c1bbfda257af7473ed45a91e9f","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.3.1.tgz","fileCount":10,"integrity":"sha512-e5GC59pwketuK6KNKcNXDb2PsWPsDmkBnMu3r/BfsqmjWWCP+1+9lyXSTMY8fBIcaukZrbsE4JzJA6jS2c9H0Q==","signatures":[{"sig":"MEQCIHtZGDHJmDg56egE1KBjXThgoYvkiJmFIqO9IrjMih8OAiAQn+1brPzGcckh2B2beCTpQq9ryD8LoMNkrptrly31Zw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":4962157},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"gitHead":"3b508d1531da877f658652eae3f82438a6713684","scripts":{"dev":"tsx bin/boombox.ts","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","test:watch":"vitest","release:major":"npm version major --no-git-tag-version && npm publish --access public","release:minor":"npm version minor --no-git-tag-version && npm publish --access public","release:patch":"npm version patch --no-git-tag-version && npm publish --access public","prepublishOnly":"npm run build"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"_npmVersion":"10.9.4","description":"Local Boombox runtime for Konstant cassettes — CLI, stdio MCP server, and local Hono proxy.","directories":{},"_nodeVersion":"22.22.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^1.19.9","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.3.1_1781738089655_0.11631736203029241","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@konstantdotcloud/boombox","version":"0.4.0","license":"UNLICENSED","_id":"@konstantdotcloud/boombox@0.4.0","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"7550ea9466e707219f4b0d7675fb76cdbb064e57","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.4.0.tgz","fileCount":13,"integrity":"sha512-sBy8ZcUiy2LkYMN4htw7/VavnmIfiBKo0vJDkPIlTnHh4YVeYEFQVJ3mmLd9hLH6eNhMUuk4wyfulH8BBdUKsA==","signatures":[{"sig":"MEUCIQDxXCGc/5MP5ekEVYIph5MxODsqn/IX1iSUaqWSaSQnRAIgGyEBiCnkaW0sZa4MHXmmWB2J0oc44Jz5VNdrQ+fR+Iw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":15800638},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"}},"scripts":{"dev":"tsx bin/boombox.ts","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","test:watch":"vitest","release:major":"npm version major --no-git-tag-version && npm publish --access public","release:minor":"npm version minor --no-git-tag-version && npm publish --access public","release:patch":"npm version patch --no-git-tag-version && npm publish --access public","prepublishOnly":"npm run build"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"_npmVersion":"11.16.0","description":"Local Boombox runtime for Konstant cassettes — CLI, stdio MCP server, and local Hono proxy.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^1.19.9","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.4.0_1783458559270_0.04464417615909988","host":"s3://npm-registry-packages-npm-production"}},"0.4.1":{"name":"@konstantdotcloud/boombox","version":"0.4.1","license":"UNLICENSED","_id":"@konstantdotcloud/boombox@0.4.1","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"3b3b4a1329774010aae727a08a8451fde34c540c","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.4.1.tgz","fileCount":13,"integrity":"sha512-o6rGukW9feUqHM2ve0YOPqPQs6b39iKv5Ngqpbv0qcVYNPYfSPbQSqvhgUbTCpCElAC42pLZkXmmnCmM8wcaOw==","signatures":[{"sig":"MEYCIQCfixpCuSHuPDOsKtmCgdb44n1qRlDKX/I4xrCYstPZtgIhAJ0lwM9JwU+ZhQdvhhChhUWSa3GHViBKzl+PXZCMD2Mp","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":15848675},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"}},"scripts":{"dev":"tsx bin/boombox.ts","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","test:watch":"vitest","release:major":"npm version major --no-git-tag-version && npm publish --access public","release:minor":"npm version minor --no-git-tag-version && npm publish --access public","release:patch":"npm version patch --no-git-tag-version && npm publish --access public","prepublishOnly":"npm run build"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1"},"_npmVersion":"11.10.1","description":"Local Boombox runtime for Konstant cassettes — CLI, stdio MCP server, and local Hono proxy.","directories":{},"_nodeVersion":"25.7.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^1.19.9","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.4.1_1783994339767_0.9641246343138699","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@konstantdotcloud/boombox","version":"0.5.0","license":"UNLICENSED","_id":"@konstantdotcloud/boombox@0.5.0","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"071f3e0d708e614e47b6586d9e18a2f8fa25a665","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.5.0.tgz","fileCount":18,"integrity":"sha512-5T4QJ5XUDEy9GAtGes2TRC8kFk5y6lPKv3m4lpKEaxX+7ybQpedPpfW4SX7MStdgQKe9FA2bxphP9kvnac6meQ==","signatures":[{"sig":"MEQCIHsptWvZa1NXaZ0eMb5NnShmTa9wtUa5SEJUp91vA2o4AiAYLrofs9rpusARz8P3D6N33pT9H8v6I0cGGkqLxAM5cQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":16523067},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"}},"scripts":{"dev":"tsx bin/boombox.ts","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","test:watch":"vitest","release:major":"npm version major --no-git-tag-version && npm publish --access public","release:minor":"npm version minor --no-git-tag-version && npm publish --access public","release:patch":"npm version patch --no-git-tag-version && npm publish --access public","prepublishOnly":"npm run build"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1"},"_npmVersion":"11.17.0","description":"Local Boombox runtime for Konstant cassettes — CLI, stdio MCP server, and local Hono proxy.","directories":{},"_nodeVersion":"26.5.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^1.19.9","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.5.0_1784170252225_0.9592407022451446","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@konstantdotcloud/boombox","version":"0.6.0","license":"UNLICENSED","_id":"@konstantdotcloud/boombox@0.6.0","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"b98b27cc30e82a5edcfb1cedf8450ff91ffae34d","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.6.0.tgz","fileCount":20,"integrity":"sha512-+f8I/eul1Xah08FTvsnE/aR06HEx9wvWJ/EHHay6TfXsARH0nStjNNXqOitynfb9yzO57zdCkitj6o8hejRtyg==","signatures":[{"sig":"MEYCIQC2NdIMcdSXID3p2UTSELNG3V8A7QFpDa1OXdAMIrnW7wIhAIQF8a4w709+pN6dORCgj30+YCzZpgOBxNuM7WjcdPqT","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":16748787},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"}},"scripts":{"dev":"tsx bin/boombox.ts","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","test:watch":"vitest","release:major":"npm version major --no-git-tag-version && npm publish --access public","release:minor":"npm version minor --no-git-tag-version && npm publish --access public","release:patch":"npm version patch --no-git-tag-version && npm publish --access public","prepublishOnly":"npm run build"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1"},"_npmVersion":"11.17.0","description":"Local Boombox runtime for Konstant cassettes — CLI, stdio MCP server, and local Hono proxy.","directories":{},"_nodeVersion":"26.5.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^1.19.9","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.6.0_1784179049235_0.0952692591301898","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@konstantdotcloud/boombox","version":"0.7.0","license":"UNLICENSED","_id":"@konstantdotcloud/boombox@0.7.0","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"e6d331e74712fcd92a80e3d25a28ad0e229cf8a0","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.7.0.tgz","fileCount":20,"integrity":"sha512-Qrm2gBOLQ3GDB5IfjKPbBeVNNY9oKvkDPS/Q2N0VXuqt47bric+4jR/KYL2Mlf3vBbXdd8xQVMpzj2XpUvVbKQ==","signatures":[{"sig":"MEYCIQCixLy49GB9arGalKmTEzNKd6kKIz/J/Iq2QkFviQMDVQIhAK8tJMCPFw7UnQAAX4D36gWVyvggKj+2dwdbq6F5MURg","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":16961162},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"}},"scripts":{"dev":"tsx bin/boombox.ts","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","test:watch":"vitest","release:major":"npm version major --no-git-tag-version && npm publish --access public","release:minor":"npm version minor --no-git-tag-version && npm publish --access public","release:patch":"npm version patch --no-git-tag-version && npm publish --access public","prepublishOnly":"npm run build"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1"},"_npmVersion":"11.17.0","description":"Local Boombox runtime for Konstant cassettes — CLI, stdio MCP server, and local Hono proxy.","directories":{},"_nodeVersion":"26.5.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^1.19.9","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.7.0_1784266914057_0.03386782797609955","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@konstantdotcloud/boombox","version":"0.8.0","license":"UNLICENSED","_id":"@konstantdotcloud/boombox@0.8.0","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"0f444e6c65de639b8644b251a575ffec2ee2d84f","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.8.0.tgz","fileCount":20,"integrity":"sha512-oQa2Jln5KPCmbsizp42EGiCSOd3NQKISkjIYDG8OKwhLxsNe8HPe4V2VHMje7qlScUKwAVrXFkih25Oy0RSCCw==","signatures":[{"sig":"MEQCIFujXyP6EE5F2TTjFM4B6SHCaYKdjRpnRW3DoOk2c1Z8AiARnbNA9j3Segqy4/GbexD0gdMJrCmwniuwGXZasudTdw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":17409972},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"}},"scripts":{"dev":"tsx bin/boombox.ts","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","test:watch":"vitest","release:major":"npm version major --no-git-tag-version && npm publish --access public","release:minor":"npm version minor --no-git-tag-version && npm publish --access public","release:patch":"npm version patch --no-git-tag-version && npm publish --access public","prepublishOnly":"npm run build"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1"},"_npmVersion":"11.17.0","description":"Local Boombox runtime for Konstant cassettes — CLI, stdio MCP server, and local Hono proxy.","directories":{},"_nodeVersion":"26.5.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^1.19.9","@modelcontextprotocol/sdk":"^1.25.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.8.0_1784298799260_0.08569389954761064","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"@konstantdotcloud/boombox","version":"0.9.0","license":"UNLICENSED","_id":"@konstantdotcloud/boombox@0.9.0","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"f1b293e83cb86cb9a479d76286b9468e78ef9fee","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.9.0.tgz","fileCount":22,"integrity":"sha512-wVX3zaTjCyKjLZzJdTAAFza7YeqakR8LPFqjPIj2ux0y3Lh7R3gMuwq3AkqJO89XgaZmjd6xU+lfso9/6fGZzg==","signatures":[{"sig":"MEUCIGLwDfyQ0FJZ819klfiOQmd0AtuTnBwdbmT4IAiceD+OAiEA69g9b4aMaajduTY2RvjGxdK2nd2c+HLeree0VEFM9F4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":17731723},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"}},"scripts":{"dev":"tsx bin/boombox.ts","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","test:watch":"vitest","release:major":"npm version major --no-git-tag-version && npm run release:publish","release:minor":"npm version minor --no-git-tag-version && npm run release:publish","release:patch":"npm version patch --no-git-tag-version && npm run release:publish","prepublishOnly":"npm run verify:release && npm run build","verify:release":"node scripts/verify-release.mjs","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"_npmVersion":"11.17.0","description":"Local Boombox runtime for Konstant cassettes — CLI, stdio MCP server, and local Hono proxy.","directories":{},"_nodeVersion":"26.5.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","fast-uri":"^3.1.4","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"boombox_release":{"source_status":"published","public_registry_version":"0.9.0"},"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.9.0_1785773103745_0.8114844299646566","host":"s3://npm-registry-packages-npm-production"}},"0.10.0":{"name":"@konstantdotcloud/boombox","version":"0.10.0","license":"UNLICENSED","_id":"@konstantdotcloud/boombox@0.10.0","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"aae3b24f685be302dcb5b0a140099de42769282a","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.10.0.tgz","fileCount":22,"integrity":"sha512-OeOcktvmamjjZXkm2vZhQGDrNFTEDBTHxV/iP91ccIdQQ6VKWDw3ekDX6f25P06zwLMeoBEQ88at4DXuiJZ4wA==","signatures":[{"sig":"MEQCIA+QWGArTWdflJxvPFC4udMqLDurqpUSMxNP1XM3ZB5VAiAvgccP4X87eUok65g8l/r0ATVZagcq7+ePHxnwNRtHkg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":17794541},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"}},"scripts":{"dev":"tsx bin/boombox.ts","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","test:watch":"vitest","release:major":"npm version major --no-git-tag-version && npm run release:publish","release:minor":"npm version minor --no-git-tag-version && npm run release:publish","release:patch":"npm version patch --no-git-tag-version && npm run release:publish","prepublishOnly":"npm run verify:release && npm run build","verify:release":"node scripts/verify-release.mjs","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"_npmVersion":"11.17.0","description":"Local Boombox runtime for Konstant cassettes — CLI, stdio MCP server, and local Hono proxy.","directories":{},"_nodeVersion":"26.5.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","fast-uri":"^3.1.4","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"boombox_release":{"source_status":"published","public_registry_version":"0.10.0"},"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.10.0_1785863081547_0.438699854401708","host":"s3://npm-registry-packages-npm-production"}},"0.10.1":{"name":"@konstantdotcloud/boombox","version":"0.10.1","license":"UNLICENSED","_id":"@konstantdotcloud/boombox@0.10.1","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"3fd2a6afa23e588aa7639c88362cf45a5e072a7d","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.10.1.tgz","fileCount":22,"integrity":"sha512-czasH/pujCFPS1rReIJBY6lSYQaTaigGhx+9xXqWjttDAskPwtua9Socia1bc1FX5KfhnUfcHdbcl1t/hpqIrA==","signatures":[{"sig":"MEQCIBQ+q7NQ20U0kjV513ul2QzC8wAFxfULeueR6it9bHxPAiBtrqWHiPXbonmAHKDCunge83jivrGyX8ZLvWADJiI33g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":17795521},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"}},"scripts":{"dev":"tsx bin/boombox.ts","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","test:watch":"vitest","release:major":"npm version major --no-git-tag-version && npm run release:publish","release:minor":"npm version minor --no-git-tag-version && npm run release:publish","release:patch":"npm version patch --no-git-tag-version && npm run release:publish","prepublishOnly":"npm run verify:release && npm run build","verify:release":"node scripts/verify-release.mjs","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"_npmVersion":"11.17.0","description":"Local Boombox runtime for Konstant cassettes — CLI, stdio MCP server, and local Hono proxy.","directories":{},"_nodeVersion":"26.5.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","fast-uri":"^3.1.4","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"boombox_release":{"source_status":"published","public_registry_version":"0.10.1"},"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.10.1_1785863917362_0.8426201115437453","host":"s3://npm-registry-packages-npm-production"}},"0.11.0":{"name":"@konstantdotcloud/boombox","version":"0.11.0","license":"UNLICENSED","_id":"@konstantdotcloud/boombox@0.11.0","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"50cbdd43bed2492a743a71534741c6c9670b7f9a","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.11.0.tgz","fileCount":33,"integrity":"sha512-bzxPerbKLY+IRdC14mFSU4S4BqOePIdiBLf0zVp47IjdaO8ZZNOwj0gyO3dvG1OBJzHo/jwfS8uZ+iPuMJqISw==","signatures":[{"sig":"MEUCIQC2fuRhCNHh9zQTA5nbhlAuaYXSrNfAQk+BpdBpBm+0hAIgH8skRxQ7lyuAq2HQiIBo9m8QzKu4UfjU4f9apIIQspU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":22394054},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./handoff":{"types":"./dist/handoff.d.ts","import":"./dist/handoff.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"},"./evaluations":{"types":"./dist/evaluations.d.ts","import":"./dist/evaluations.js"},"./project-profile":{"types":"./dist/project-profile.d.ts","import":"./dist/project-profile.js"},"./project-attachment":{"types":"./dist/project-attachment.d.ts","import":"./dist/project-attachment.js"}},"scripts":{"dev":"tsx bin/boombox.ts","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","typecheck":"tsc -p tsconfig.json","test:watch":"vitest","release:major":"npm version major --no-git-tag-version && npm run release:publish","release:minor":"npm version minor --no-git-tag-version && npm run release:publish","release:patch":"npm version patch --no-git-tag-version && npm run release:publish","prepublishOnly":"npm run typecheck && npm test && npm run build && npm run verify:release && npm run verify:packed-consumer","verify:release":"node scripts/verify-release.mjs","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"_npmVersion":"11.17.0","description":"Boombox developer kit for governed products, local MCP workflows, portable applications, durable workloads, and tenant operations.","directories":{},"_nodeVersion":"26.5.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","fast-uri":"^3.1.4","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.11.0_1785980362720_0.7568964118623334","host":"s3://npm-registry-packages-npm-production"}},"0.12.0":{"name":"@konstantdotcloud/boombox","version":"0.12.0","license":"UNLICENSED","_id":"@konstantdotcloud/boombox@0.12.0","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"0af1826f9054c24bb98fa5c674b659fdaa6eadaf","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.12.0.tgz","fileCount":33,"integrity":"sha512-NzCVZaMkjY2p+FqOnFtw7T4yTyhFb9Wvpp2iQvpXXEX/5NmEsl6hIlVYaumL98B9dv4WuOrEnWW3u37t92krfQ==","signatures":[{"sig":"MEUCIA+RXm690y409M1erHqlwkCnsTUXRKYopyR0ewZnN5xnAiEAki0DmdmLhC8cpYgXjvRk0YpS16ShJZphji1lwYvn6II=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":22590622},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./handoff":{"types":"./dist/handoff.d.ts","import":"./dist/handoff.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"},"./evaluations":{"types":"./dist/evaluations.d.ts","import":"./dist/evaluations.js"},"./project-profile":{"types":"./dist/project-profile.d.ts","import":"./dist/project-profile.js"},"./project-attachment":{"types":"./dist/project-attachment.d.ts","import":"./dist/project-attachment.js"}},"scripts":{"dev":"tsx bin/boombox.ts","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","typecheck":"tsc -p tsconfig.json","test:watch":"vitest","release:major":"npm version major --no-git-tag-version && npm run release:publish","release:minor":"npm version minor --no-git-tag-version && npm run release:publish","release:patch":"npm version patch --no-git-tag-version && npm run release:publish","prepublishOnly":"npm run typecheck && npm test && npm run build && npm run verify:release && npm run verify:packed-consumer","verify:release":"node scripts/verify-release.mjs","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"_npmVersion":"11.17.0","description":"Boombox developer kit for governed products, local MCP workflows, portable applications, durable workloads, and tenant operations.","directories":{},"_nodeVersion":"26.5.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","fast-uri":"^3.1.4","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.12.0_1786141411887_0.14249305035552529","host":"s3://npm-registry-packages-npm-production"}},"0.13.0":{"name":"@konstantdotcloud/boombox","version":"0.13.0","license":"UNLICENSED","_id":"@konstantdotcloud/boombox@0.13.0","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"bb9eb117433528493ad814b4fa4a4767f765e97d","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.13.0.tgz","fileCount":33,"integrity":"sha512-nC4dJ8O6w/fHb7/uWktC80UrX6Qta6S4m9HGn7sYqzIoOWYmBd+VZt6jK+EnxDM0FtpwbNgZgDzK1aqsBOJ7cw==","signatures":[{"sig":"MEYCIQDLqc9xV6T3eJiyIkDXYdqCuJ3jtVRzBL1QzupBeeAPkwIhAJodK6DLMuUph0VC57U3HCGfgl+RjkAZaC9VVgYJZRaP","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":22459046},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./handoff":{"types":"./dist/handoff.d.ts","import":"./dist/handoff.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"},"./evaluations":{"types":"./dist/evaluations.d.ts","import":"./dist/evaluations.js"},"./project-profile":{"types":"./dist/project-profile.d.ts","import":"./dist/project-profile.js"},"./project-attachment":{"types":"./dist/project-attachment.d.ts","import":"./dist/project-attachment.js"}},"scripts":{"dev":"tsx bin/boombox.ts","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","typecheck":"tsc -p tsconfig.json","test:watch":"vitest","release:major":"npm version major --no-git-tag-version && npm run release:publish","release:minor":"npm version minor --no-git-tag-version && npm run release:publish","release:patch":"npm version patch --no-git-tag-version && npm run release:publish","prepublishOnly":"npm run typecheck && npm test && npm run build && npm run verify:release && npm run verify:packed-consumer","verify:release":"node scripts/verify-release.mjs","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"_npmVersion":"11.16.0","description":"Boombox developer kit for governed products, local MCP workflows, portable applications, durable workloads, and tenant operations.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","fast-uri":"^3.1.4","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.13.0_1786347275947_0.44965594392657926","host":"s3://npm-registry-packages-npm-production"}},"0.13.1":{"name":"@konstantdotcloud/boombox","version":"0.13.1","license":"Apache-2.0","_id":"@konstantdotcloud/boombox@0.13.1","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"98c09685c4ae9f7d1ef3bd85ffb5a318ebc74b10","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.13.1.tgz","fileCount":36,"integrity":"sha512-t8IPsRwBhukBmbAOFW3gV3/hu/LHg0f0wMg0QUekYqwGnOl2FW5NzF1oCy8SjMpn3QrkVziE3CJjCXzkO5RHvQ==","signatures":[{"sig":"MEQCIBFi23RsrcPgWukcIh2f5vkOgohy1+dz/5O/PSmZTEDNAiBC+p9KvFW4uHs3/XJV21kQJMHv17o2FL9rETb1nEd3Bw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":22638544},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./handoff":{"types":"./dist/handoff.d.ts","import":"./dist/handoff.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./receipts":{"types":"./dist/receipts.d.ts","import":"./dist/receipts.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"},"./evaluations":{"types":"./dist/evaluations.d.ts","import":"./dist/evaluations.js"},"./project-profile":{"types":"./dist/project-profile.d.ts","import":"./dist/project-profile.js"},"./project-attachment":{"types":"./dist/project-attachment.d.ts","import":"./dist/project-attachment.js"}},"scripts":{"dev":"tsx bin/boombox.ts","bump":"node scripts/bump-boombox.mjs","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","typecheck":"tsc -p tsconfig.json","test:watch":"vitest","release:major":"node scripts/bump-boombox.mjs major && npm run release:publish","release:minor":"node scripts/bump-boombox.mjs minor && npm run release:publish","release:patch":"node scripts/bump-boombox.mjs patch && npm run release:publish","prepublishOnly":"npm run typecheck && npm test && npm run build && npm run verify:release && npm run verify:packed-consumer","verify:release":"node scripts/verify-release.mjs","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"_npmVersion":"11.16.0","description":"Boombox developer kit for governed products, local MCP workflows, portable applications, durable workloads, and tenant operations.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","fast-uri":"^3.1.4","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.13.1_1787281654289_0.8556226290461766","host":"s3://npm-registry-packages-npm-production"}},"0.13.2":{"name":"@konstantdotcloud/boombox","version":"0.13.2","license":"Apache-2.0","_id":"@konstantdotcloud/boombox@0.13.2","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"5b847b43a989f79fefba68473b805e81da1b02b5","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.13.2.tgz","fileCount":36,"integrity":"sha512-ev8Mt2HWQihvLgUi2O8i9K/B8Pulb+rsOKYxFrM4ubcnxIxEhFZlFC7EcPyStqCeK5A8G+9FDk11Ax9HowDnZw==","signatures":[{"sig":"MEUCIQCLUhk4xaivrPn7cZxprOg+qolqI33JYJ22d91lseSSvwIgfRfsWbv4cWloWUE9SzK5cikP9eTbM5ZSnjKRksp6DLQ=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":23031128},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./handoff":{"types":"./dist/handoff.d.ts","import":"./dist/handoff.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./receipts":{"types":"./dist/receipts.d.ts","import":"./dist/receipts.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"},"./evaluations":{"types":"./dist/evaluations.d.ts","import":"./dist/evaluations.js"},"./project-profile":{"types":"./dist/project-profile.d.ts","import":"./dist/project-profile.js"},"./project-attachment":{"types":"./dist/project-attachment.d.ts","import":"./dist/project-attachment.js"}},"scripts":{"dev":"tsx bin/boombox.ts","bump":"node scripts/bump-boombox.mjs","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","typecheck":"tsc -p tsconfig.json","test:watch":"vitest","release:major":"node scripts/bump-boombox.mjs major && npm run release:publish","release:minor":"node scripts/bump-boombox.mjs minor && npm run release:publish","release:patch":"node scripts/bump-boombox.mjs patch && npm run release:publish","prepublishOnly":"npm run typecheck && npm test && npm run build && npm run verify:release && npm run verify:packed-consumer","verify:release":"node scripts/verify-release.mjs","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"_npmVersion":"11.16.0","description":"Boombox developer kit for governed products, local MCP workflows, portable applications, durable workloads, and tenant operations.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","fast-uri":"^3.1.4","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.13.2_1787328046044_0.8774143202877205","host":"s3://npm-registry-packages-npm-production"}},"0.13.3":{"name":"@konstantdotcloud/boombox","version":"0.13.3","license":"Apache-2.0","_id":"@konstantdotcloud/boombox@0.13.3","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"f4de6acbd0cc3d12654d62e531ce1023261904d9","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.13.3.tgz","fileCount":36,"integrity":"sha512-9hgtuB3nTfL29RcQp1HP+fzkPdfpaSe21JqOYdIuNLWXRHQNvCFiMZj2YKJkeiwcW8wuBL8Kx+fYdf6LvpfYlA==","signatures":[{"sig":"MEQCIANJ4m4ywlATbrHgPxhEw7ob2PZPyFb0JwRlNQX94/IOAiAHEadwsxXT5eAe/0s7dnw3uUcJjAfGumxj/4pwqMrIlg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":23032265},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./handoff":{"types":"./dist/handoff.d.ts","import":"./dist/handoff.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./receipts":{"types":"./dist/receipts.d.ts","import":"./dist/receipts.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"},"./evaluations":{"types":"./dist/evaluations.d.ts","import":"./dist/evaluations.js"},"./project-profile":{"types":"./dist/project-profile.d.ts","import":"./dist/project-profile.js"},"./project-attachment":{"types":"./dist/project-attachment.d.ts","import":"./dist/project-attachment.js"}},"scripts":{"dev":"tsx bin/boombox.ts","bump":"node scripts/bump-boombox.mjs","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"cd ui && npm install --silent && npm run build","typecheck":"tsc -p tsconfig.json","test:watch":"vitest","release:major":"node scripts/bump-boombox.mjs major && npm run release:publish","release:minor":"node scripts/bump-boombox.mjs minor && npm run release:publish","release:patch":"node scripts/bump-boombox.mjs patch && npm run release:publish","prepublishOnly":"npm run typecheck && npm test && npm run build && npm run verify:release && npm run verify:packed-consumer","verify:release":"node scripts/verify-release.mjs","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"_npmVersion":"11.16.0","description":"Boombox developer kit for governed products, local MCP workflows, portable applications, durable workloads, and tenant operations.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","fast-uri":"^3.1.4","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.13.3_1787341511558_0.8477466784428054","host":"s3://npm-registry-packages-npm-production"}},"0.14.0":{"name":"@konstantdotcloud/boombox","version":"0.14.0","license":"Apache-2.0","_id":"@konstantdotcloud/boombox@0.14.0","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"83b80f7e57312bfc24273666feec20b5cdaf1e2b","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.14.0.tgz","fileCount":53,"integrity":"sha512-lyz1o4pLxdwe8h58ydZ6kbGI2J4q6312hd+drQ+EQYXejduTK8hsJ3UJmwEDWH7jzrhlF1i5s9nevD2SpvczMQ==","signatures":[{"sig":"MEUCIQCgovX3TUuQjAOsvMAUPJR+lTpfHn5Wi5wEah/bH+7MYwIgZifuFic+9xiG1KH0ARtfq8XchEG4yDhI9DEoKgT+uhY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":24432683},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./job-io":{"types":"./dist/job-io.d.ts","import":"./dist/job-io.js"},"./custody":{"types":"./dist/custody.d.ts","import":"./dist/custody.js"},"./handoff":{"types":"./dist/handoff.d.ts","import":"./dist/handoff.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./receipts":{"types":"./dist/receipts.d.ts","import":"./dist/receipts.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"},"./evaluations":{"types":"./dist/evaluations.d.ts","import":"./dist/evaluations.js"},"./package.json":"./package.json","./project-profile":{"types":"./dist/project-profile.d.ts","import":"./dist/project-profile.js"},"./project-attachment":{"types":"./dist/project-attachment.d.ts","import":"./dist/project-attachment.js"}},"scripts":{"dev":"tsx bin/boombox.ts","bump":"node scripts/bump-boombox.mjs","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"node scripts/build-boombox-ui.mjs","typecheck":"tsc -p tsconfig.json","test:watch":"vitest","release:major":"node scripts/bump-boombox.mjs major && npm run release:publish","release:minor":"node scripts/bump-boombox.mjs minor && npm run release:publish","release:patch":"node scripts/bump-boombox.mjs patch && npm run release:publish","prepublishOnly":"npm run typecheck && npm test && npm run build && npm run verify:release && npm run verify:packed-consumer","verify:release":"node scripts/verify-release.mjs","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"_npmVersion":"11.16.0","description":"Boombox developer kit for governed products, local MCP workflows, portable applications, durable workloads, and tenant operations.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","fast-uri":"^3.1.4","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.17.1","tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.14.0_1787455401465_0.6512024271944312","host":"s3://npm-registry-packages-npm-production"}},"0.14.1":{"name":"@konstantdotcloud/boombox","version":"0.14.1","license":"Apache-2.0","_id":"@konstantdotcloud/boombox@0.14.1","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"65e2e3f7762545fd31d1aedaa0c1f4ac76948eef","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.14.1.tgz","fileCount":53,"integrity":"sha512-FQ5uxGf0OX/9EGwj/SFQ3fvT1tRpWj910iUXpQ45gqG4X066NQsuKsf2h6mv7RaM3abMbFY09SC/jlnXHmLnxw==","signatures":[{"sig":"MEUCIBI9BXrbuD0lbjtbofgkykEeSIAgx2sp/sIEfxbr/Rm3AiEA02eSYStvnO+lKOv+no+isEGCrbsQ+uGsR/uWL3dtkwY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":24533136},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./job-io":{"types":"./dist/job-io.d.ts","import":"./dist/job-io.js"},"./custody":{"types":"./dist/custody.d.ts","import":"./dist/custody.js"},"./handoff":{"types":"./dist/handoff.d.ts","import":"./dist/handoff.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./receipts":{"types":"./dist/receipts.d.ts","import":"./dist/receipts.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"},"./evaluations":{"types":"./dist/evaluations.d.ts","import":"./dist/evaluations.js"},"./package.json":"./package.json","./project-profile":{"types":"./dist/project-profile.d.ts","import":"./dist/project-profile.js"},"./project-attachment":{"types":"./dist/project-attachment.d.ts","import":"./dist/project-attachment.js"}},"scripts":{"dev":"tsx bin/boombox.ts","bump":"node scripts/bump-boombox.mjs","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"node scripts/build-boombox-ui.mjs","typecheck":"tsc -p tsconfig.json","test:watch":"vitest","release:major":"node scripts/bump-boombox.mjs major && npm run release:publish","release:minor":"node scripts/bump-boombox.mjs minor && npm run release:publish","release:patch":"node scripts/bump-boombox.mjs patch && npm run release:publish","prepublishOnly":"npm run typecheck && npm test && npm run build && npm run verify:release && npm run verify:packed-consumer","verify:release":"node scripts/verify-release.mjs","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"_npmVersion":"11.16.0","description":"Boombox developer kit for governed products, local MCP workflows, portable applications, durable workloads, and tenant operations.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","fast-uri":"^3.1.4","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.17.1","tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.14.1_1787470167740_0.9430270716444513","host":"s3://npm-registry-packages-npm-production"}},"0.14.2":{"name":"@konstantdotcloud/boombox","version":"0.14.2","license":"Apache-2.0","_id":"@konstantdotcloud/boombox@0.14.2","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"a33020674516df8a4a8eb7e86e42bf6ac997a6e2","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.14.2.tgz","fileCount":53,"integrity":"sha512-pA+MvW9E5kxlZgo5n10eD2sXSW/TkIC32I6J8nVcfD0Jd7Ie3Q6Fvoj8RNbgzjmW9AlfWLwcvgEhG2TAWrsM8A==","signatures":[{"sig":"MEYCIQDFJEXjPFps8W6VjnvCWxLpq/5Cjue42ydBLBWzs3o3oAIhALZf+Q7NxuNfRIHRftpWw8SHofjEUa5bBXukTLQGGwCL","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":24500537},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./job-io":{"types":"./dist/job-io.d.ts","import":"./dist/job-io.js"},"./custody":{"types":"./dist/custody.d.ts","import":"./dist/custody.js"},"./handoff":{"types":"./dist/handoff.d.ts","import":"./dist/handoff.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./receipts":{"types":"./dist/receipts.d.ts","import":"./dist/receipts.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"},"./evaluations":{"types":"./dist/evaluations.d.ts","import":"./dist/evaluations.js"},"./package.json":"./package.json","./project-profile":{"types":"./dist/project-profile.d.ts","import":"./dist/project-profile.js"},"./project-attachment":{"types":"./dist/project-attachment.d.ts","import":"./dist/project-attachment.js"}},"scripts":{"dev":"tsx bin/boombox.ts","bump":"node scripts/bump-boombox.mjs","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"node scripts/build-boombox-ui.mjs","typecheck":"tsc -p tsconfig.json","test:watch":"vitest","release:major":"node scripts/bump-boombox.mjs major && npm run release:publish","release:minor":"node scripts/bump-boombox.mjs minor && npm run release:publish","release:patch":"node scripts/bump-boombox.mjs patch && npm run release:publish","prepublishOnly":"npm run typecheck && npm test && npm run build && npm run verify:release && npm run verify:packed-consumer","verify:release":"node scripts/verify-release.mjs","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"_npmVersion":"11.16.0","description":"Boombox developer kit for governed products, local MCP workflows, portable applications, durable workloads, and tenant operations.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","fast-uri":"^3.1.4","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.17.1","tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.14.2_1787480665891_0.0961409457074347","host":"s3://npm-registry-packages-npm-production"}},"0.14.3":{"name":"@konstantdotcloud/boombox","version":"0.14.3","license":"Apache-2.0","_id":"@konstantdotcloud/boombox@0.14.3","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"1a0280c68d09b57ce0358393b559605950548d98","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.14.3.tgz","fileCount":53,"integrity":"sha512-7OYJEMEOgf/JoNpJoS4kc+/J+Q7DnNeTYjbRyxVUsZNCyFsifB0BVCIoKQi7q0eYX3qqeRfnNFL3BPSstpPGKQ==","signatures":[{"sig":"MEUCIE4cgBK/N4ojvxun4j8+oLLDr/KfPBFzZ+EM7y5mtxcIAiEAujW9xEaq/EbbuK6qKVliX83hP4+NZ8omPAmxkVF56RE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":24689939},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./job-io":{"types":"./dist/job-io.d.ts","import":"./dist/job-io.js"},"./custody":{"types":"./dist/custody.d.ts","import":"./dist/custody.js"},"./handoff":{"types":"./dist/handoff.d.ts","import":"./dist/handoff.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./receipts":{"types":"./dist/receipts.d.ts","import":"./dist/receipts.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"},"./evaluations":{"types":"./dist/evaluations.d.ts","import":"./dist/evaluations.js"},"./package.json":"./package.json","./project-profile":{"types":"./dist/project-profile.d.ts","import":"./dist/project-profile.js"},"./project-attachment":{"types":"./dist/project-attachment.d.ts","import":"./dist/project-attachment.js"}},"scripts":{"dev":"tsx bin/boombox.ts","bump":"node scripts/bump-boombox.mjs","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"node scripts/build-boombox-ui.mjs","typecheck":"tsc -p tsconfig.json","test:watch":"vitest","release:major":"node scripts/bump-boombox.mjs major && npm run release:publish","release:minor":"node scripts/bump-boombox.mjs minor && npm run release:publish","release:patch":"node scripts/bump-boombox.mjs patch && npm run release:publish","prepublishOnly":"npm run typecheck && npm test && npm run build && npm run verify:release && npm run verify:packed-consumer","verify:release":"node scripts/verify-release.mjs","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"_npmVersion":"11.16.0","description":"Boombox developer kit for governed products, local MCP workflows, portable applications, durable workloads, and tenant operations.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","fast-uri":"^3.1.4","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.17.1","tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.14.3_1787533701966_0.11365316036331619","host":"s3://npm-registry-packages-npm-production"}},"0.14.4":{"name":"@konstantdotcloud/boombox","version":"0.14.4","license":"Apache-2.0","_id":"@konstantdotcloud/boombox@0.14.4","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"9feefe4f39ad25d9b0c8efd50ea7859d367435e6","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.14.4.tgz","fileCount":53,"integrity":"sha512-pJrfEf06ufLRkHq3UBs20ScK0s2sL1L7vaTFPT7I3NE420gr7yMIRX515QBKdnDwaxHJV5/+Kl2BewsAu5KgmQ==","signatures":[{"sig":"MEUCIQDlVVMwK0XEmwVo3kY34LKJHPI1xfO2UzVC3dwVyAAUIQIgA4lBk4mtN+RKiYRh6cysRvqxvfPGVBaSz83+KzU961A=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":24670686},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./job-io":{"types":"./dist/job-io.d.ts","import":"./dist/job-io.js"},"./custody":{"types":"./dist/custody.d.ts","import":"./dist/custody.js"},"./handoff":{"types":"./dist/handoff.d.ts","import":"./dist/handoff.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./receipts":{"types":"./dist/receipts.d.ts","import":"./dist/receipts.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"},"./evaluations":{"types":"./dist/evaluations.d.ts","import":"./dist/evaluations.js"},"./package.json":"./package.json","./project-profile":{"types":"./dist/project-profile.d.ts","import":"./dist/project-profile.js"},"./project-attachment":{"types":"./dist/project-attachment.d.ts","import":"./dist/project-attachment.js"}},"scripts":{"dev":"tsx bin/boombox.ts","bump":"node scripts/bump-boombox.mjs","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"node scripts/build-boombox-ui.mjs","typecheck":"tsc -p tsconfig.json","test:watch":"vitest","release:major":"node scripts/bump-boombox.mjs major && npm run release:publish","release:minor":"node scripts/bump-boombox.mjs minor && npm run release:publish","release:patch":"node scripts/bump-boombox.mjs patch && npm run release:publish","prepublishOnly":"npm run typecheck && npm test && npm run build && npm run verify:release && npm run verify:packed-consumer","verify:release":"node scripts/verify-release.mjs","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"_npmVersion":"10.8.2","description":"Boombox developer kit for governed products, local MCP workflows, portable applications, durable workloads, and tenant operations.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","fast-uri":"^3.1.4","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.17.1","tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.14.4_1787601900134_0.7786439844950725","host":"s3://npm-registry-packages-npm-production"}},"0.14.5":{"name":"@konstantdotcloud/boombox","version":"0.14.5","license":"Apache-2.0","_id":"@konstantdotcloud/boombox@0.14.5","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"3323bd941ab564ab9841d9df6a69fca76f345848","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.14.5.tgz","fileCount":53,"integrity":"sha512-K8sVBXwrZeKljYI++F/UVYVukzuJe/19CGcHMt8NyrWVdSDNmJ3yFbl//0o1u+OmCNQklUz7tqL+yYTv2n1mjg==","signatures":[{"sig":"MEUCIAwwubYNtMmsNPdJ6hEJqdGW2AJmKos7rDzJ854975mFAiEA5Ee2Q/KJHerOl00bodjX96ggX9N+aYteY8+6CrxHl2w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":24851593},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./job-io":{"types":"./dist/job-io.d.ts","import":"./dist/job-io.js"},"./custody":{"types":"./dist/custody.d.ts","import":"./dist/custody.js"},"./handoff":{"types":"./dist/handoff.d.ts","import":"./dist/handoff.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./receipts":{"types":"./dist/receipts.d.ts","import":"./dist/receipts.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"},"./evaluations":{"types":"./dist/evaluations.d.ts","import":"./dist/evaluations.js"},"./package.json":"./package.json","./project-profile":{"types":"./dist/project-profile.d.ts","import":"./dist/project-profile.js"},"./project-attachment":{"types":"./dist/project-attachment.d.ts","import":"./dist/project-attachment.js"}},"scripts":{"dev":"tsx bin/boombox.ts","bump":"node scripts/bump-boombox.mjs","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"node scripts/build-boombox-ui.mjs","typecheck":"tsc -p tsconfig.json","test:watch":"vitest","release:major":"node scripts/bump-boombox.mjs major && npm run release:publish","release:minor":"node scripts/bump-boombox.mjs minor && npm run release:publish","release:patch":"node scripts/bump-boombox.mjs patch && npm run release:publish","prepublishOnly":"npm run typecheck && npm test && npm run build && npm run verify:release && npm run verify:packed-consumer","verify:release":"node scripts/verify-release.mjs","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"_npmVersion":"11.16.0","description":"Boombox developer kit for governed products, local MCP workflows, portable applications, durable workloads, and tenant operations.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","fast-uri":"^3.1.4","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.17.1","tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.14.5_1787611970551_0.7269526955657288","host":"s3://npm-registry-packages-npm-production"}},"0.14.6":{"name":"@konstantdotcloud/boombox","version":"0.14.6","license":"Apache-2.0","_id":"@konstantdotcloud/boombox@0.14.6","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"b12b38da1318120e5a4e454790a3f5c976a64556","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.14.6.tgz","fileCount":53,"integrity":"sha512-+YP/PsKnpvYvJFP3Z/OFcKvicqE0Z+fnmJ9MHOV9i993dg6B/TyHJ/NDwuKymP5jEOpoC4HeXVTZYTJ6qJn2GA==","signatures":[{"sig":"MEQCIFbhZCbgKEWlRoOfpUNi5+qaCUI8JPaOK7MlzNTURB8XAiBHyh6O4VXOHeFT5KuBBsv05/gE4wQVvefbjk3at47ptQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25121004},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./job-io":{"types":"./dist/job-io.d.ts","import":"./dist/job-io.js"},"./custody":{"types":"./dist/custody.d.ts","import":"./dist/custody.js"},"./handoff":{"types":"./dist/handoff.d.ts","import":"./dist/handoff.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./receipts":{"types":"./dist/receipts.d.ts","import":"./dist/receipts.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"},"./evaluations":{"types":"./dist/evaluations.d.ts","import":"./dist/evaluations.js"},"./package.json":"./package.json","./project-profile":{"types":"./dist/project-profile.d.ts","import":"./dist/project-profile.js"},"./project-attachment":{"types":"./dist/project-attachment.d.ts","import":"./dist/project-attachment.js"}},"scripts":{"dev":"tsx bin/boombox.ts","bump":"node scripts/bump-boombox.mjs","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"node scripts/build-boombox-ui.mjs","typecheck":"tsc -p tsconfig.json","test:watch":"vitest","release:major":"node scripts/bump-boombox.mjs major && npm run release:publish","release:minor":"node scripts/bump-boombox.mjs minor && npm run release:publish","release:patch":"node scripts/bump-boombox.mjs patch && npm run release:publish","prepublishOnly":"npm run typecheck && npm test && npm run build && npm run verify:release && npm run verify:packed-consumer","verify:release":"node scripts/verify-release.mjs","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"_npmVersion":"11.16.0","description":"Boombox developer kit for governed products, local MCP workflows, portable applications, durable workloads, and tenant operations.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","jose":"^6.1.3","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","fast-uri":"^3.1.4","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.17.1","tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.14.6_1787639837541_0.31656704881993214","host":"s3://npm-registry-packages-npm-production"}},"0.14.7":{"name":"@konstantdotcloud/boombox","version":"0.14.7","license":"Apache-2.0","_id":"@konstantdotcloud/boombox@0.14.7","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"d1ad5f676fd688e343b0201bde708cadfd661306","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.14.7.tgz","fileCount":53,"integrity":"sha512-iqrvZ+/PRDUEtYXi3IWn3T8CNWWC1TaPy4VtgfwrlS/4MMazoOZJkGToXKiDx7lB8I5bQJSRx0QGRkr3BV+TuA==","signatures":[{"sig":"MEUCIQC6YP2yO83ngz4WNwnOHAAiWD4Og+7c7LUywgI5aVUQUgIgH93Pa6ybXjfYoEbr6ticaM5YFJqt92u45JlE0zV7xiU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25173030},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./job-io":{"types":"./dist/job-io.d.ts","import":"./dist/job-io.js"},"./custody":{"types":"./dist/custody.d.ts","import":"./dist/custody.js"},"./handoff":{"types":"./dist/handoff.d.ts","import":"./dist/handoff.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./receipts":{"types":"./dist/receipts.d.ts","import":"./dist/receipts.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"},"./evaluations":{"types":"./dist/evaluations.d.ts","import":"./dist/evaluations.js"},"./package.json":"./package.json","./project-profile":{"types":"./dist/project-profile.d.ts","import":"./dist/project-profile.js"},"./project-attachment":{"types":"./dist/project-attachment.d.ts","import":"./dist/project-attachment.js"}},"scripts":{"dev":"tsx bin/boombox.ts","bump":"node scripts/bump-boombox.mjs","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"node scripts/build-boombox-ui.mjs","typecheck":"tsc -p tsconfig.json","test:watch":"vitest","release:major":"node scripts/bump-boombox.mjs major && npm run release:publish","release:minor":"node scripts/bump-boombox.mjs minor && npm run release:publish","release:patch":"node scripts/bump-boombox.mjs patch && npm run release:publish","prepublishOnly":"npm run typecheck && npm test && npm run build && npm run verify:release && npm run verify:packed-consumer","verify:release":"node scripts/verify-release.mjs","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"_npmVersion":"11.16.0","description":"Boombox developer kit for governed products, local MCP workflows, portable applications, durable workloads, and tenant operations.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","jose":"^6.1.3","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","fast-uri":"^3.1.4","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.17.1","tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.14.7_1788036054844_0.576991493593394","host":"s3://npm-registry-packages-npm-production"}},"0.14.8":{"name":"@konstantdotcloud/boombox","version":"0.14.8","license":"Apache-2.0","_id":"@konstantdotcloud/boombox@0.14.8","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"a7f27294be64965facdf00137c78bc1c88b8a1d8","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.14.8.tgz","fileCount":53,"integrity":"sha512-jW95qZT1/kqcoSXpqWRRoyIKOKB5GhS1YmUnUMY5dEnmiHQlQYTv45HBi3dfxVMWKl8R/GmaiFI6Y7HtGcAZTQ==","signatures":[{"sig":"MEUCIE/WJmLBOuf0cbDwr6OBxd62NBJDrhPQlMz4EUZIRNSgAiEAtgu29x7ZYsw/+ZGBp9uNATzxGdILXrAiN+QlKMOT0Jo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25173478},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./job-io":{"types":"./dist/job-io.d.ts","import":"./dist/job-io.js"},"./custody":{"types":"./dist/custody.d.ts","import":"./dist/custody.js"},"./handoff":{"types":"./dist/handoff.d.ts","import":"./dist/handoff.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./receipts":{"types":"./dist/receipts.d.ts","import":"./dist/receipts.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"},"./evaluations":{"types":"./dist/evaluations.d.ts","import":"./dist/evaluations.js"},"./package.json":"./package.json","./project-profile":{"types":"./dist/project-profile.d.ts","import":"./dist/project-profile.js"},"./project-attachment":{"types":"./dist/project-attachment.d.ts","import":"./dist/project-attachment.js"}},"scripts":{"dev":"tsx bin/boombox.ts","bump":"node scripts/bump-boombox.mjs","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"node scripts/build-boombox-ui.mjs","typecheck":"tsc -p tsconfig.json","test:watch":"vitest","release:major":"node scripts/bump-boombox.mjs major && npm run release:publish","release:minor":"node scripts/bump-boombox.mjs minor && npm run release:publish","release:patch":"node scripts/bump-boombox.mjs patch && npm run release:publish","prepublishOnly":"npm run typecheck && npm test && npm run build && npm run verify:release && npm run verify:packed-consumer","verify:release":"node scripts/verify-release.mjs","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"_npmVersion":"11.16.0","description":"Boombox developer kit for governed products, local MCP workflows, portable applications, durable workloads, and tenant operations.","directories":{},"_nodeVersion":"24.18.0","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","jose":"^6.1.3","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","fast-uri":"^3.1.4","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.17.1","tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.14.8_1788062690898_0.11370380128681434","host":"s3://npm-registry-packages-npm-production"}},"0.14.9":{"name":"@konstantdotcloud/boombox","version":"0.14.9","license":"Apache-2.0","_id":"@konstantdotcloud/boombox@0.14.9","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"b97fabc3d89a838fc85cf284e0bc5f8f5e0e8268","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.14.9.tgz","fileCount":55,"integrity":"sha512-rgh6oPgj5aKHSFJrfVZC/vTO/5maw1a7+fLhHKJDo2ocO6hH6UAbBY/KsNC6rXz1xJ4/VGT8UocgseNgIuUh2w==","signatures":[{"sig":"MEUCIA6oR6SBEBuJr8WHQC//VZHDpMr7vJipLkMboF/uO6iqAiEAt8u7iIKkaKZvvXMEMdCRsUlkc8wAB8nDmfUSseu/XrE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25148636},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./job-io":{"types":"./dist/job-io.d.ts","import":"./dist/job-io.js"},"./custody":{"types":"./dist/custody.d.ts","import":"./dist/custody.js"},"./handoff":{"types":"./dist/handoff.d.ts","import":"./dist/handoff.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./testing":{"types":"./dist/testing.d.ts","import":"./dist/testing.js"},"./receipts":{"types":"./dist/receipts.d.ts","import":"./dist/receipts.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"},"./evaluations":{"types":"./dist/evaluations.d.ts","import":"./dist/evaluations.js"},"./package.json":"./package.json","./project-profile":{"types":"./dist/project-profile.d.ts","import":"./dist/project-profile.js"},"./project-attachment":{"types":"./dist/project-attachment.d.ts","import":"./dist/project-attachment.js"}},"scripts":{"dev":"tsx bin/boombox.ts","bump":"node scripts/bump-boombox.mjs","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"node scripts/build-boombox-ui.mjs","typecheck":"tsc -p tsconfig.json","test:watch":"vitest","release:major":"node scripts/bump-boombox.mjs major && npm run release:publish","release:minor":"node scripts/bump-boombox.mjs minor && npm run release:publish","release:patch":"node scripts/bump-boombox.mjs patch && npm run release:publish","prepublishOnly":"npm run typecheck && npm test && npm run build && npm run verify:release && npm run verify:packed-consumer","verify:release":"node scripts/verify-release.mjs","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"_npmVersion":"10.8.2","description":"Boombox developer kit for governed products, local MCP workflows, portable applications, durable workloads, and tenant operations.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","jose":"^6.1.3","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","fast-uri":"^3.1.4","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.17.1","tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.14.9_1788227637898_0.12323093466346435","host":"s3://npm-registry-packages-npm-production"}},"0.14.10":{"name":"@konstantdotcloud/boombox","version":"0.14.10","license":"Apache-2.0","_id":"@konstantdotcloud/boombox@0.14.10","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"bin":{"boombox":"dist/boombox.js"},"dist":{"shasum":"80f03afe511973c97d6309f08d173fad2a9d977a","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.14.10.tgz","fileCount":55,"integrity":"sha512-DjKGuPK8bepsLImewLE1MayOxTG9YOtlLH5vv2y6XsKKCxgI8BsFIRCIcwHllgm69b3qt8IS3qBxDAK/db44kQ==","signatures":[{"sig":"MEUCIENCkRtO5lwBaOGpSwnNsvO9V7CSKfHUsLTJj9Ynbm7NAiEA/5OANIsL1hHXbCNoQnvBHYbPGabMOoMCd7jTexKaSUI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25423708},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./job-io":{"types":"./dist/job-io.d.ts","import":"./dist/job-io.js"},"./custody":{"types":"./dist/custody.d.ts","import":"./dist/custody.js"},"./handoff":{"types":"./dist/handoff.d.ts","import":"./dist/handoff.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./testing":{"types":"./dist/testing.d.ts","import":"./dist/testing.js"},"./receipts":{"types":"./dist/receipts.d.ts","import":"./dist/receipts.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"},"./evaluations":{"types":"./dist/evaluations.d.ts","import":"./dist/evaluations.js"},"./package.json":"./package.json","./project-profile":{"types":"./dist/project-profile.d.ts","import":"./dist/project-profile.js"},"./project-attachment":{"types":"./dist/project-attachment.d.ts","import":"./dist/project-attachment.js"}},"scripts":{"dev":"tsx bin/boombox.ts","bump":"node scripts/bump-boombox.mjs","test":"vitest run","build":"tsup && npm run build:ui","build:ui":"node scripts/build-boombox-ui.mjs","typecheck":"tsc -p tsconfig.json","test:watch":"vitest","release:major":"node scripts/bump-boombox.mjs major && npm run release:publish","release:minor":"node scripts/bump-boombox.mjs minor && npm run release:publish","release:patch":"node scripts/bump-boombox.mjs patch && npm run release:publish","prepublishOnly":"npm run typecheck && npm test && npm run build && npm run verify:release && npm run verify:packed-consumer","verify:release":"node scripts/verify-release.mjs","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs"},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"_npmVersion":"10.8.2","description":"Boombox developer kit for governed products, local MCP workflows, portable applications, durable workloads, and tenant operations.","directories":{},"_nodeVersion":"20.20.2","dependencies":{"zod":"^3.25.76","hono":"^4.11.9","jose":"^6.1.3","open":"^10.1.0","chalk":"^5.6.2","prompts":"^2.4.2","fast-uri":"^3.1.4","commander":"^12.1.0","smol-toml":"^1.3.1","@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"ajv":"^8.17.1","tsx":"^4.7.0","tsup":"^8.3.5","vitest":"^3.2.4","typescript":"^5.0.0","@types/node":"^20.0.0","@types/prompts":"^2.4.9"},"_npmOperationalInternal":{"tmp":"tmp/boombox_0.14.10_1788285419482_0.7001718261373882","host":"s3://npm-registry-packages-npm-production"}},"0.14.11":{"name":"@konstantdotcloud/boombox","version":"0.14.11","description":"Boombox developer kit for governed products, local MCP workflows, portable applications, durable workloads, and tenant operations.","license":"Apache-2.0","type":"module","bin":{"boombox":"dist/boombox.js"},"main":"./dist/index.js","types":"./dist/index.d.ts","scripts":{"build":"tsup && npm run build:ui","build:ui":"node scripts/build-boombox-ui.mjs","dev":"tsx bin/boombox.ts","test":"vitest run","test:watch":"vitest","typecheck":"tsc -p tsconfig.json","prepublishOnly":"npm run typecheck && npm test && npm run build && npm run verify:release && npm run verify:packed-consumer","release:publish":"node scripts/publish-release.mjs","verify:packed-consumer":"node scripts/verify-packed-consumer.mjs","verify:release":"node scripts/verify-release.mjs","bump":"node scripts/bump-boombox.mjs","release:patch":"node scripts/bump-boombox.mjs patch && npm run release:publish","release:minor":"node scripts/bump-boombox.mjs minor && npm run release:publish","release:major":"node scripts/bump-boombox.mjs major && npm run release:publish"},"engines":{"node":">=20"},"publishConfig":{"access":"public"},"dependencies":{"@hono/node-server":"^2.0.8","@modelcontextprotocol/sdk":"^1.30.0","chalk":"^5.6.2","commander":"^12.1.0","fast-uri":"^3.1.4","hono":"^4.11.9","jose":"^6.1.3","open":"^10.1.0","prompts":"^2.4.2","smol-toml":"^1.3.1","zod":"^3.25.76"},"devDependencies":{"@types/node":"^20.0.0","@types/prompts":"^2.4.9","ajv":"^8.17.1","tsup":"^8.3.5","tsx":"^4.7.0","typescript":"^5.0.0","vitest":"^3.2.4"},"overrides":{"esbuild":"0.28.1","fast-uri":"^3.1.4"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./schemas":{"types":"./dist/schemas.d.ts","import":"./dist/schemas.js"},"./apps":{"types":"./dist/apps.d.ts","import":"./dist/apps.js"},"./testing":{"types":"./dist/testing.d.ts","import":"./dist/testing.js"},"./workloads":{"types":"./dist/workloads.d.ts","import":"./dist/workloads.js"},"./onboarding":{"types":"./dist/onboarding.d.ts","import":"./dist/onboarding.js"},"./handoff":{"types":"./dist/handoff.d.ts","import":"./dist/handoff.js"},"./project-profile":{"types":"./dist/project-profile.d.ts","import":"./dist/project-profile.js"},"./project-attachment":{"types":"./dist/project-attachment.d.ts","import":"./dist/project-attachment.js"},"./evaluations":{"types":"./dist/evaluations.d.ts","import":"./dist/evaluations.js"},"./receipts":{"types":"./dist/receipts.d.ts","import":"./dist/receipts.js"},"./custody":{"types":"./dist/custody.d.ts","import":"./dist/custody.js"},"./job-io":{"types":"./dist/job-io.d.ts","import":"./dist/job-io.js"},"./package.json":"./package.json"},"_id":"@konstantdotcloud/boombox@0.14.11","_nodeVersion":"24.18.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-uHSEhtLntTrNT+axEeFjc6pDRvNRqrvKIut4cA7+OPtJzZWBRVmTvhYNPPDT5HiefAebRLeeG9XqCZEPGCp4mw==","shasum":"0c383c7f591c99c31de0dc11bea1b7457687b265","tarball":"https://registry.npmjs.org/@konstantdotcloud/boombox/-/boombox-0.14.11.tgz","fileCount":55,"unpackedSize":25474068,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDTULhA4+1NAbI7sBthCNWfTVurOQL1W7/WeZ/hEVlIbwIhAIgSnznBHdvX5MvxNiN03gO0MfYxrh5xm9QwYYlae2m7"}]},"_npmUser":{"name":"konstantdotcloud","email":"adam@konstant.cloud"},"directories":{},"maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/boombox_0.14.11_1788321299894_0.14563352700148413"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-03T18:52:15.139Z","modified":"2026-09-02T03:55:00.297Z","0.1.0":"2026-06-03T18:52:15.469Z","0.1.1":"2026-06-03T20:11:55.363Z","0.1.2":"2026-06-12T10:50:52.100Z","0.2.0":"2026-06-12T20:22:52.277Z","0.3.0":"2026-06-17T22:49:00.936Z","0.3.1":"2026-06-17T23:14:49.825Z","0.4.0":"2026-07-07T21:09:19.534Z","0.4.1":"2026-07-14T01:58:59.991Z","0.5.0":"2026-07-16T02:50:52.433Z","0.6.0":"2026-07-16T05:17:29.482Z","0.7.0":"2026-07-17T05:41:54.302Z","0.8.0":"2026-07-17T14:33:19.462Z","0.9.0":"2026-08-03T16:05:04.082Z","0.10.0":"2026-08-04T17:04:41.773Z","0.10.1":"2026-08-04T17:18:37.626Z","0.11.0":"2026-08-06T01:39:23.016Z","0.12.0":"2026-08-07T22:23:32.134Z","0.13.0":"2026-08-10T07:34:36.170Z","0.13.1":"2026-08-21T03:07:34.541Z","0.13.2":"2026-08-21T16:00:46.264Z","0.13.3":"2026-08-21T19:45:11.900Z","0.14.0":"2026-08-23T03:23:21.745Z","0.14.1":"2026-08-23T07:29:27.974Z","0.14.2":"2026-08-23T10:24:26.138Z","0.14.3":"2026-08-24T01:08:22.187Z","0.14.4":"2026-08-24T20:05:00.391Z","0.14.5":"2026-08-24T22:52:50.819Z","0.14.6":"2026-08-25T06:37:17.806Z","0.14.7":"2026-08-29T20:40:55.092Z","0.14.8":"2026-08-30T04:04:51.183Z","0.14.9":"2026-09-01T01:53:58.130Z","0.14.10":"2026-09-01T17:56:59.697Z","0.14.11":"2026-09-02T03:55:00.146Z"},"license":"Apache-2.0","description":"Boombox developer kit for governed products, local MCP workflows, portable applications, durable workloads, and tenant operations.","maintainers":[{"name":"konstantdotcloud","email":"adam@konstant.cloud"}],"readme":"# @konstantdotcloud/boombox\n\nThe developer kit for **Boombox** — turn existing software, data, models, workflows, and research into governed AI\nProducts and Capabilities. Run them in the estate you choose, expose them through apps, APIs, MCP, agents, or\nworkflows, operate them with identity, lifecycle, receipts, recovery, and observability, and selectively compose\nthem into a consented capability network.\n\nA **cassette** is one product shape: a repeatable governed workflow with typed inputs, executable steps, an output\ngate, and receipts. The CLI initializes the project, connects existing capabilities, asks Gary, ingests files,\nmanages runs, and serves the developer surface over MCP. The SDK and local MCP tools validate and plan portable\nfrontend+harness applications and durable workloads.\n\nConnected Boombox use always starts with an authenticated developer or automation identity. Its credential is sent only to\nthe explicitly enrolled gateway for authentication and never becomes repository content, Need content, telemetry,\nor a generated artifact.\n\nThe hosted surfaces are deliberately split. `https://boombox.konstant.cloud` is the public `boombox-cloud`\nfront door for browser login and the closed builder-workspace routes (`developer_workspace` on the wire) for contract discovery, project attachment,\nNeeds, and evaluation service facts. Its route adapter accepts only the declared method/path shapes; it is not a\nproxy to arbitrary Konstant APIs. Konstant support reads and Need responses use separately authenticated operator\nroutes on `https://konstant-v2.fly.dev`, with an explicit exact-origin allowlist. Company-account control gateways and\nruntimes are additional, separately enrolled targets. None of these hosts turns authentication into company or\noperator authority.\n\nPackage installation/help plus repository scan, compile, and Product-local proof run without a credential because\nthey create no remote Boombox state. SDK validation/planning may also run offline when authorized host code already\nsupplies an exact canonical target; first-time consumer target composition waits for generated `product_mcp` rather\nthan asking for internal identity. That local utility is not an anonymous platform session:\nevery networked SDK, CLI, or MCP read or write requires authentication.\n\nThis kit is for consumer-side Product builders. It helps you use Boombox from your own repository; it does not make\nyou a Boombox-core developer or ask you to design platform tenancy. Start with the Product outcome. The authenticated\nProduct account supplies Boombox's internal isolation binding automatically; placement separately describes whether the Product runs in\nthe owner's cloud, a customer's cloud, or a Konstant-managed target. If no authorized connection exists, the agent\nreturns the truthful account-administrator continuation while safe local work continues.\n\nCompany context, evaluations, research, telemetry, and the Platform Need return channel are optional enhancements;\ntheir absence or failure does not block the safe local Product path. Refuse only the unsafe operation at a real\ncompany/customer-data, secret, provider-mutation, external-effect, billing, publication, or promotion boundary, and always\nreturn the smallest concrete way to continue.\n\nA builder workspace can attach its reviewed Build Intent and opaque project continuity, submit/list/hydrate its\nown Platform Needs with agent-authored working context, return payload-free evaluation service facts, and report\nbounded SDK-usage signals. It has no company catalog or data, secrets, compute, billing, deployment, or invocation\nauthority. When a Product needs live company/runtime access, use its separately authorized Product account\nconnection. The CLI does not transfer workspace Needs or authority into that account.\n\nBoombox Product owners and Capability providers are domain authorities. You keep the product, research, methods,\nevidence meaning, workflow, customer relationship, graders, and promotion decisions. Boombox supplies reusable\ndeployment, operating, composition, observability, and distribution rails. When a reusable platform seam is\nmissing, the developer kit can return an actionable Need with the working context required to build it while a\nclearly labeled local adapter keeps the Product moving.\n\n## Quickstart — connect a source code project\n\nStart with the outcome:\n\n> Put this workflow on Boombox and get it running. Reuse the frontend and harness already here if they fit. If a\n> small UI is missing, help me build it. Ask me only for decisions you cannot determine safely from the repository.\n\nYou do not need to choose a Boombox Product shape or enumerate platform services. The installed skill infers the\nshape and carries the same request through local proof and every authorized connected action.\n\n### 1. Install and initialize the exact local package\n\nInstall without running dependency lifecycle scripts. Project initialization installs the package-pinned skill and\nprints separate scan and builder MCP connections; it writes no credential and changes no application code:\n\n```bash\nnpm install --save-dev --save-exact --ignore-scripts @konstantdotcloud/boombox@0.14.11\nnode ./node_modules/@konstantdotcloud/boombox/dist/boombox.js project init . \\\n  --client codex --client claude --json\n```\n\nInstall an exact reviewed version with lifecycle scripts disabled and keep it in the consumer lockfile. Invoke its\nexplicit `node_modules/@konstantdotcloud/boombox/dist/boombox.js` entrypoint: do not use `npx` or a bare/global\n`boombox` at this boundary. Project initialization refuses unless the consumer-local package version equals the\npackage instance executing initialization, its real CLI entrypoint remains inside the project, and the lock is exact.\nThe skill is also available as `boombox://developer/skill`. The existing-codebase guide is served as\n`boombox://developer/onboarding`, and the evaluation guide is served as `boombox://developer/evaluations`, so the\ncoding agent can inspect a legacy repository and map an existing runner without asking the developer to hand-author\nthe ontology.\n\nProject initialization returns `scan_mcp`, `builder_mcp`, `product_mcp`, `scan_verify`, `builder_verify`, and\n`product_verify`. Use the MCP commands unchanged; they bind one canonical `--project-root` and must never point at\ndifferent checkouts. `builder_mcp` uses the builder workspace for continuity and Needs; `product_mcp` uses the\nseparate Product-account config for authorized company/customer work. Treat each verify\nobject as a required fragment of the discovery response, not as another tool call. Start only `scan_mcp`. Before reading repository content,\ncall `boombox_platform_describe({})` and compare the response with `scan_verify`: require the exact installed\n`package_version`, `mcp.active_profile:scan`, `mcp.live_product_account_calls:false`, and `mcp.remote_mutation_tools:false`.\n\n### 2. Preview and configure this project's local profile\n\nThe agent proposes a closed `boombox.project-profile.v1` input from the ordinary outcome and local evidence. It\ncontains only the primary Product, repository-relative docs/entrypoints/harnesses/evals, reviewed commands, and\ndeclared deployment targets. A minimal input looks like this:\n\nThe `primary_product.outcome` sentence is also the Build Intent. It answers “what are you trying to make, and for\nwhom is it useful?” in ordinary language. Local profile preview/configuration applies the same bounded text policy\nas attachment, so connecting later introduces no new sentence constraint. It stays local during scan/configuration;\nproject attachment later shows and seals that exact sentence into the authenticated support and requirement-return\nchannel.\n\n```json\n{\n  \"primary_product\": {\n    \"name\": \"workflow-console\",\n    \"outcome\": \"A user runs the existing workflow and inspects its durable result\",\n    \"shape\": \"portable_application\"\n  },\n  \"assets\": {\n    \"docs\": [\"README.md\"],\n    \"entrypoints\": [\"src/server.ts\"],\n    \"harnesses\": [\"tests/harness.test.ts\"],\n    \"evals\": []\n  },\n  \"commands\": [\n    { \"kind\": \"local_test\", \"command\": \"npm test\" },\n    { \"kind\": \"local_build\", \"command\": \"npm run build\" }\n  ],\n  \"deployment_targets\": []\n}\n```\n\nInvoke `boombox_project_profile_preview` with the proposed `profile` and\n`instruction_targets:[\"AGENTS.md\",\"CLAUDE.md\"]`. The result reports profile and instruction dispositions with\n`writes_performed:0` and `network_calls:0`. After explicit confirmation, save the reviewed input to a bounded JSON\nfile and configure it:\n\n```bash\nnode ./node_modules/@konstantdotcloud/boombox/dist/boombox.js project configure . \\\n  --input ./boombox-project-profile.json \\\n  --instructions AGENTS.md --instructions CLAUDE.md\n```\n\nOmit `--instructions` to select both files. Configuration writes `.boombox/project.json` and atomically creates or\nreplaces only the marker-bounded managed block in each instruction file. Repository-owned prose stays byte-for-byte\noutside that block; malformed markers, linked files, and path escape refuse before mutation. Never fork or customize\nthe canonical `build-on-boombox` skill. Put project-specific facts in the profile and managed overlay.\n\nCommit the reviewed `.boombox/project.json` and managed instruction changes so every context shares the same Project\nidentity and Build Intent. Keep `.boombox/handoff.json`, `.boombox/evaluations/`, local attachment/retirement\nreceipts, service-fact outboxes, locks, temporary files, and authentication state out of Git; package-owned local\nhandoff, evaluation, and attachment writers add their durable state paths to `.boombox/.gitignore`. A lock,\nrecovery fence, or temporary file retained after a crash is diagnostic evidence: do not stage it, and do not delete it\nuntil the interrupted operation has been inspected.\n\n### 3. Scan, build, and prove the Product locally\n\nKeep the credential-free scan context open while the agent chooses the smallest Product shape, implements the\nbounded slice, runs repository tests, and proves accepted, refusal, idempotency, recovery, and retirement behavior.\nUse application/workload validate and plan here only when the repository already contains an exact canonical target\nsupplied by authorized host code. For a first-time target, prepare the Product descriptor and placement inputs, then\nuse generated `product_mcp`; never ask the Product builder to author internal identity. For a cassette, finish the\nlocal spec, schema, and repository tests before a connected dry-run or publication. A green local plan is useful\nproof, not deployment authority.\n\nThe stopping point follows the requested outcome. For repository understanding or validation, local proof plus one\nexact continuation may be complete. For “get it running,” continue through the authorized application or workload\nlifecycle, inspect from a fresh session, retain the receipt, and prove recovery or retirement. Optional evaluation,\nprogram, corpus, and network-learning features degrade independently; the selected deploy or Run does not become\noptional merely because those enhancements are unavailable.\n\nWhen returning a reusable gap is useful, `scan` may call `boombox_need_draft`. It writes at most 32 strict,\nstably ordered Needs to `.boombox/handoff.json`. Each draft uses `seam_identity`, `observed_availability`,\n`delivery_continuity`, `requested_delivery` action/priority, and one multiline `working_context` written by the\nagent from the work already done. The developer does not fill out a form.\n\nThe working context accepts up to 64 KiB of UTF-8 text and keeps the original ask, current task, company/Project/Product, repository root and revision,\nrelevant paths and systems, attempts, commands/tests and material results, observed versus expected behavior,\ndecisions and tradeoffs, constraints, and exact unblock. Natural Markdown may include paths, URLs, code fences,\nrevision identifiers, and concise test output. Do not include secret or credential values, bearer tokens, private\nkeys, signer material, or raw customer payloads, and do not dump a repository, transcript, or dataset. Need drafting\ndoes not require a Chronicle, session ontology, transcript-ingest path, or new permission system. Drafting failure\nleaves the local Product result unchanged.\n\n### 4. Authenticate a builder workspace and attach the project\n\nStop only the scan MCP process before a connected action; preserve the developer's coding conversation and working\ncontext:\n\n```bash\nnode ./node_modules/@konstantdotcloud/boombox/dist/boombox.js login\nnode ./node_modules/@konstantdotcloud/boombox/dist/boombox.js doctor\nnode ./node_modules/@konstantdotcloud/boombox/dist/boombox.js project attach . --client-class codex\n```\n\nBuilder-workspace admission is authenticated but does not require a Product-account invitation: any principal\naccepted by the configured WorkOS/AuthKit sign-in can create or resume one narrow personal workspace. There is no\nanonymous hosted session, source access, company-data access, or runtime authority. When a live action needs an\nauthorized Product account, follow the exact connection continuation returned by project configuration or doctor;\nthe browser presents any authorized choices by human company label. Account connection and deployment placement\nare separate decisions. Ask where the Product should run only when owner cloud, customer cloud, or\nKonstant-managed placement cannot be inferred, and never ask the developer to invent an internal identifier or\nchoose a Boombox tenant. Stop and restart the bridge with the returned config while preserving the coding\nconversation; a running process does not hot-switch authority.\n\nDefault login creates or resumes a builder workspace. Attachment is the standard supported connection. It shows\nand sends the one-line Build Intent already declared as `primary_product.outcome`, together with the opaque project\nreference, profile digest, exact package version, and client class. It never sends source, filenames, paths,\ncommands, prompts, provider/region details, customer payloads, or arbitrary reasoning. The request digest and\nverified receipt make that declaration inspectable and revisioned while granting no Product-account or execution authority.\nAn explicitly authorized Konstant support operator may see that verified Build Intent, opaque project/workspace\nanchors, lifecycle, package/client cohort, and bounded activity/Need counts. Compact project, inbox, and list\nprojections contain no email, source, paths, prompts, customer/provider data, credentials, raw requests/evals, or\nNeed prose. An audited operator `show` for one exact Need returns its sealed request, server-derived\nsubmitter/scope, project attachment, submission identity, and full `working_context`.\nThe initial correlation key is the server-derived actor and workspace/tenant scope plus project attachment,\nimmutable submission ID/time, and signed narrative. It recovers who asked, from which connected project, and in\nwhat work context without requiring a separate session-tracking service.\nRecover the receipt with `project get .`. Attachment, context, evaluation, telemetry, or return-channel failure\nnever blocks safe local Product delivery.\nWhen the project no longer needs this continuity binding, inspect it with `project get .`, then retire that exact\nattachment with `project retire . --confirm-receipt-digest <receipt_digest>`. The verified tombstone is retained\nlocally; retirement does not delete the repository or grant tenant/runtime authority.\nWith `project get --json`, the response is `{attachment, drift, remedy}`. Scripts passing\n`project retire --confirm-receipt-digest` read the digest from `.attachment.receipt_digest`.\n\nBuilder-workspace credentials are independently revocable. A bearer can inspect and revoke only its own metadata:\n\n```bash\nnode ./node_modules/@konstantdotcloud/boombox/dist/boombox.js credentials list\nnode ./node_modules/@konstantdotcloud/boombox/dist/boombox.js credentials revoke <credential_id>\n```\n\nUse the exact ID returned by `credentials list`; a bearer cannot enumerate or revoke peer devices. Revoking the\ncredential used by the current machine removes its local login only after the server confirms revocation. To recover\nafter losing a device or every local credential, run `login` again. The authenticated browser flow offers\nsame-principal, exact-one recovery when the workspace has reached its credential limit, so a lost machine cannot\npermanently lock the developer out.\n\n### 5. Reconnect the builder MCP in the same coding conversation\n\nFor project continuity and Needs, start the returned `builder_mcp` at the same project root. Run\n`boombox doctor --require developer_contract,need_return,project_attachment`, adding `evaluation_fact` only when\nthis Product is returning evaluation service facts. Then call\n`boombox_platform_describe({})`, and compare the response with `builder_verify`. Restart the MCP process after every\ncredential, identity-scope, account, or gateway change while preserving the coding conversation; a running process never hot-switches authority.\nIf the config directory watcher fails asynchronously, `serve --mcp` continues with its file watcher; if both\nwatchers fail, the bridge stays up, logs one bounded line per failed watcher, and requires explicit reload for later config changes.\n\nFor authorized company/customer data or runtime work, run `login --account`, start the returned `product_mcp`\nunchanged, and compare `boombox_platform_describe({})` with `product_verify`. The Product-account config is separate\nfrom the builder-workspace config; neither connection inherits the other's authority.\n\nBoth generated connected verification objects require `gateway_contract.status:verified` from the MCP process's\nstartup negotiation; restart that process to refresh the observation. `product_verify` also requires\n`connection.kind:product_account`, `product_account.label_status:configured`, a display-only human label, and hidden internal identity. If verification\nreports unavailable or incompatible, do not claim the connected action; follow its exact continuation while local\nProduct work continues.\n\nBefore any connected action, read `product_account.label` from discovery and confirm that its human name matches\nthe Product account intended by the current work. A mismatch means reconnect by human label; never repair it by\nentering an internal identifier.\n\nFor a drafted Need:\n\n1. `boombox_need_preview` returns the complete request plus a local `boombox.need-approval.v1` envelope. The\n   approval binds the exact `need_key`, `request_digest`, handoff generation, and project attachment without a\n   network call.\n2. `boombox_need_submit` requires `need_key`, `approved_request_digest`, and `approved_approval_digest`, recomputes\n   the approval, refuses local drift before transport, performs an authenticated idempotent round-trip under\n   `capability.request`, and binds only the matching receipt.\n3. On every relevant fresh builder, `boombox_need_list` rediscovers open/answered work for the authenticated scope.\n   Follow the opaque cursor while `truncated` is true.\n4. `boombox_need_get` hydrates only relevant IDs returned by list, including the full `working_context`. Never\n   bootstrap from a pasted ID.\n\nFor a builder workspace, a first Need submission and every new or changed Need context require the current verified\nproject attachment. Login by itself is not enough. An exact already-committed request may replay under its complete\nsuperseded attachment binding after response loss, and historical list/get remain available under that same binding;\nneither path may create or revise a Need. A retired or missing attachment leaves local drafting and Product work\navailable but makes connected preview/submit/list/get return the exact attachment continuation instead of silently\nbroadening scope.\n\nA typed `platform_resolution` binds the exact Need and Need digest, package version/digest, gateway\ncontract/protocol/release digests, feature and contract references, conformance entrypoint, migration-instruction\ndigest, and optional local-adapter retirement condition. It carries `execution_authorized:false`. Verify the exact\ninstalled package, live gateway contract, and local compatibility tests before retiring the adapter. Submission or\nresolution alone does not create a branch, PR, merge, release, deployment, or effect.\n\nWhen the Need is owned by `boombox_platform`, a caller may separately request\n`requested_delivery.action:'draft_github_pr'`. The bounded responder outcome is a `draft_pr_ready` message plus a\nstable `draft_github_pr` artifact reference for review. It remains non-authoritative: the original receipt keeps\n`github_pr_created:false` and `execution_authorized:false`, and neither request nor response performs Git, creates\nor merges a PR, publishes a package, deploys, or retires an adapter.\n\nThe Need service derives scope and actor, uses durable idempotency/rate/capacity admission, and fails closed on\nstorage failure. Its content-addressed receipt is an integrity acknowledgement inside the Need chain, not a\nsignature, Product evidence, provider attestation, or execution authorization. The responder uses `need.respond`\nfor typed compare-and-swap reply, question, answer, resolve, and decline transitions. Terminal closure and capacity\nrelease commit together.\n\nEvery builder-workspace request, receipt, thread, and list filter binds the exact attachment revision under which\nit was accepted. A first/new Need or changed request must use the current revision; a superseded revision supports\nonly exact committed replay and historical read continuity. A Need's stable identity binds the workspace, stable\nproject attachment ID, and Need key, so its thread survives a profile revision without colliding with another\nproject. Each accepted revised request remains a distinct immutable submission.\n\nExternal local orchestrators can import the same strict handoff contract and read/write/bind helpers from\n`@konstantdotcloud/boombox/handoff`; those helpers never authenticate, call a provider, or run Git.\nSigned Needs already stored by an earlier cohort remain readable and verifiable byte-for-byte. Ignored local draft\nhandoffs are package-local working state, not platform evidence; regenerate them with the current scan before a new\nsubmission. Exact response-loss replay applies to a request already committed by its compatible gateway cohort.\n\nUse the generated Product-account connection only when the next operation requires company or runtime\nauthority. Every deployment, invocation, secret, data, billing, cassette, Gary, and admin action still requires its\nexact advertised permission. When HomeBase is enabled, the\nMCP prompt `boombox_company_operating_brief` may instruct the local agent to combine authorized Gary context with\nrecent Runs, open Needs, and available lifecycle/health/receipt reads. It is a read-only guidance prompt, not a tool\nthat performs those reads itself. The agent labels plans as intent, current records as operating evidence, and\nmissing sources as unavailable. Missing company context never blocks repository-only work.\n\n```bash\nnode ./node_modules/@konstantdotcloud/boombox/dist/boombox.js login --account\n```\n\nThe browser presents authorized Product accounts by human label; the connection stores the internal identity.\nRuntime owner, cloud project, region, residency, and billing remain separate explicit Product placement inputs.\n\nThe canonical path is `outcome` → `install/init` → `profile preview/configure` → `scan/build/prove locally` →\nbuilder-workspace `login/attach` → reconnect `builder_mcp` in the same coding conversation → optional Need `preview/submit/list/get` and\npayload-free evaluation return → optional Product account connection for company/runtime authority. Platform\noperations are a separate Konstant surface whose individual operations still enforce their exact credentials and\ngrants:\n\n| Tool | What it proves |\n|-|-|\n| `boombox_platform_describe` | Reports the current `scan`/`builder` contract, package version, active profile, and network/mutation posture. |\n| `boombox_project_profile_preview` | Validates the bounded local profile and previews managed instruction dispositions with zero writes and zero network calls. |\n| `boombox_project_configure` | **Builder/internal ops, local only.** After `write_confirmed:true`, CAS-updates the profile and replaces only managed instruction blocks. The project-local CLI provides the same configuration path before login. |\n| `boombox_project_attach` | **Authenticated builder workspace.** Attaches the reviewed one-line Build Intent plus opaque project/profile/package/client metadata and returns a receipt with no Product-account or execution authority. |\n| `boombox_project_get` | **Authenticated builder workspace.** Recovers the verified attachment for the exact local profile without returning a bearer or Product-account grant. |\n| `boombox_project_retire` | **Authenticated builder workspace.** Retires only the exact attachment receipt digest the caller confirms and returns a verified tombstone with no Product-account or execution authority. |\n| `boombox_need_draft` | **Scan only.** Atomically writes the complete strict multi-Need local handoff. This is a repo-local generated-file mutation, not a network, provider, Git, issue, PR, or deployment action. |\n| `boombox_need_preview` | **Builder/internal ops, local only.** Returns the exact selected request, including its rich `working_context`, and the local approval envelope binding request digest, handoff generation, and project attachment. `approval_required:true` requests an MCP-client decision; it does not attest human or out-of-band review. |\n| `boombox_need_submit` | **Authenticated builder/internal ops.** Requires the exact caller-confirmed Need key, approved request digest, and approved approval digest; submits the authenticated request, verifies its receipt identities/digests, and records that exact binding locally. Client policy may require a person or permit authorized automation. |\n| `boombox_need_get` | **Authenticated builder/internal ops.** Reads one sealed scope-bound Need with its complete current request and `working_context`, messages, artifacts, and lifecycle state without granting mutation or execution authority. |\n| `boombox_need_list` | **Authenticated builder/internal ops.** Lists at most 50 newest-first open/answered summaries plus a nonnegative corrupt count and opaque continuation cursor, without returning message prose, request context, source, evidence, prompts, or artifact references. |\n| `boombox_application_validate` | Validates a portable frontend+harness descriptor against the connected Product account plus declared runtime placement, and reports whether an opaque product qualification pair is declared. It does not fetch or semantically accept that record. |\n| `boombox_application_plan` | Produces the public SDK's side-effect-free application plan; production without qualification refuses. It cannot apply, promote, rollback, or retire, and records a fixed non-authoritative local planner identity rather than a caller-authored audit actor. |\n| `boombox_workload_validate` | Validates an immutable Product worker descriptor against the connected Product account plus declared provider placement, residency, custody/billing, runtime store, cost cap, and retention. Internal isolation paths are compiled behind the Product MCP. |\n| `boombox_workload_plan` | Produces a deterministic, provider-free workload authoring plan; it cannot apply, trigger, attach, retry, reconcile, or observe a provider. |\n\nDurable job authors import `defineWorkload`, `defineWorkloadTarget`, and\n`planBoomboxWorkload` from `@konstantdotcloud/boombox/workloads`. Those\nfunctions deliberately stop before runtime authority. A green plan proves the\ndeclared seam and refusal checks, not that tenant admission, provider execution,\nrecovery, or operator reattachment is live.\n\nAn admitted service composition may additionally use\n`createBoomboxWorkloadControlClient()` from the same entrypoint. The client\nderives exact apply/invoke intent digests, calls the authenticated workload host,\nvalidates response identity plus exact admission/lifecycle receipt context,\nbinds the returned run id to the requested logical run key, keeps its deadline\nactive until the complete bounded response body is read, performs no automatic\nmutation retries, and keeps observer credentials separate. Product-terminal\nreads bind receipt digests to the projected immutable result and product-receipt\ncustody. It does not mint authority: callers must inject purpose-token and\nobserver-credential providers backed by the tenant control plane. Without those\nproviders, return the local plan and the missing authority seam rather than\ntreating a static API key as workload admission.\n\nApplication authors import `defineApplication`, `defineApplicationTarget`, and\n`planBoomboxApplicationDeployment` from `@konstantdotcloud/boombox/apps`.\nProduction descriptors carry only the product-owned opaque\n`{ qualification_ref, qualification_digest }` pair. The product keeps the\nqualification schema, evals, floors, claims, expiry, and evidence meaning;\nBoombox never copies those semantics into runtime state. A composition root\ninjects one tenant-authorized `BoomboxApplicationQualificationVerifier` whose\npinned authority names the exact trust policy and verifier release. Apply and\nevery promote or rollback operation call it before provider work and require a\npayload-free verification receipt bound to the tenant, exact full deployment\ntarget, artifact, manifest, and attestation. Inspect, lifecycle receipts, and\nthe signed fleet projection preserve that binding. An unqualified preview is\npermitted only as explicitly unqualified and cannot inherit qualification evidence from another Release.\n\nBefore wiring a product verifier, run\n`runBoomboxApplicationQualificationVerifierConformance()` with one exact\naccepted case plus explicit expired, product-release-mismatched, placement-\nmismatched, and other product-owned refusal cases. The black-box report retains\nonly immutable digests and refusal facts; product records and customer payloads\nstay inside the product boundary. This conformance helper proves the verifier\ncontract, not that a particular artifact is qualified or deployed.\n\nBoombox exposes application descriptor/target authoring, local validation/planning, verifier conformance, and\n`createBoomboxApplicationLifecycleClient` from `@konstantdotcloud/boombox/apps`, whose apply/inspect/retire\nuse the host's `/api/v2/applications/*` routes. The export exists; it does not grant builder authority. Those routes\nrequire the Product account's lifecycle authority, and a developer-held credential never satisfies them. Compose the\nclient under account-authorized operator composition, never developer-held auth; internal or manual lifecycle evidence\ndoes not widen the developer contract.\n\n### Admit a cross-account application caller\n\nThe callee owner first deploys a standing Cloud Run target with\n`peer_ingress.mode: 'iam_invoker_federation'`. A tenant-admin Product-account credential can then grant one\naccount-bound admission. The principal may be a service account in another GCP project; the callee service itself\nmust remain in a project admitted by the host manifest.\n\n```bash\nboombox admissions grant \\\n  --callee <deployment_id> \\\n  --account tenant:<account> \\\n  --principal serviceAccount:<name>@<project>.iam.gserviceaccount.com \\\n  --transitions capability,status,ask\n\nboombox admissions list --callee <deployment_id>\nboombox admissions revoke --callee <deployment_id> --admission <admission_id>\n```\n\nGrant and revoke synchronously refresh the existing callee deployment. A grant becomes `active` only after the\nexact Cloud Run invoker set is verified and its `invoker_binding` is `applied`; a failed reconcile stays `pending`\nand returns a typed code plus its smallest continuation. Repeating an already-applied grant is an idempotent no-op.\nRevocation removes the admission principal on the same exact-set reconcile.\n\nInside the callee, `createInjectedLifecycleClient(runtime).listAdmissions(deployment_id)` reads active admissions\nwith that deployment's injected operation credential. The method never accepts a Product-account credential for\nthe injected read lane, and a credential bound to another deployment returns a typed 403 client error.\n\n### Give your application end-user login\n\nDeclare end-user login beside the application's secrets and events, and bound the standing Cloud Run target:\n\n```ts\nconst descriptor = defineApplication({\n  // ...existing application fields...\n  end_user_ingress: { mode: 'host_front_door', session_ttl_seconds: 28_800 },\n  end_user_access: {\n    allowed_orgs: ['workos:org_01EXAMPLE'],\n    allowed_email_domains: ['example.com'],\n    open_to_tenant: false,\n  },\n});\n\nconst target = defineApplicationTarget({\n  // ...existing standing cloud_run_service target...\n  scaling: { min_instances: 0, max_instances: 10, concurrency: 80 },\n});\n```\n\n`host_front_door` requires a standing `cloud_run_service` and an explicit `scaling.max_instances` from 1 through\n1000. The platform owns the login front door, hub, application serving origin or fallback path, DNS, IAM hop,\nsession, and public-key injection; the application only declares access and verifies each request.\n\n```ts\nimport {\n  BOOMBOX_END_USER_ASSERTION_HEADER,\n  verifyBoomboxEndUserAssertionFromEnvironment,\n} from '@konstantdotcloud/boombox/apps';\n\nconst assertion = request.headers.get(BOOMBOX_END_USER_ASSERTION_HEADER) ?? '';\nconst principal = await verifyBoomboxEndUserAssertionFromEnvironment(assertion);\n```\n\nThe verifier composes both the injected public keys and the exact deployment-generation audience. Authorize the\nend user and `acting_for` mandate against Product-owned records; `organization` means an IdP org-admin/role claim\nor explicit organization consent, never membership alone. Map the namespaced `org_ref` to a retained Product\nauthorization record. `tenant_id` identifies the deploying estate and is never the authorization subject. Read\nroutes may ignore `jti`; write routes atomically deduplicate it before the effect or require a fresh assertion.\n\nFor a tier-1 local loop, explicitly compose the throwaway signer with the parameterized verifier:\n\n```ts\nconst signer = await createLocalDevelopmentEndUserSigner();\nconst assertion = await signer.mint(localClaims);\nconst principal = await verifyBoomboxEndUserAssertion(assertion, {\n  verificationKeys: signer.verificationKeys,\n  expectedAudience: localClaims.aud,\n});\n```\n\nThe signer generates its own P-256 keypair and forces `assurance: 'local-development-only'`. Its assertions fail\nagainst real injected keys and cannot represent platform verification.\n\n### Application event subscriptions\n\nA standing `cloud_run_service` descriptor may subscribe under its own harness API prefix:\n\n```ts\nevent_subscriptions: [{\n  kinds: ['workload_run.terminal', 'subject_head.advanced'],\n  path: '/harness/events',\n}]\n```\n\nEvery delivery carries the same canonical, payload-free `boombox.application-event.v1` envelope,\nbounded to 4 KiB. Read `x-boombox-event-signature`, `x-boombox-event-kid`,\n`x-boombox-event-delivery`, `x-boombox-event-attempt`, and\n`x-boombox-event-first-delivered-at`, then call\n`verifyBoomboxApplicationEvent(envelope, signature, kid, { verification_keys:\n[runtime.peer_authority_verification] })`. The head source names `subject_kind`, `head_seq`,\n`head_digest`, and nullable `previous_head_digest`; the terminal source names the run, job,\nsubject, `job_revision_digest`, and closed `terminal_state` (`succeeded`, `failed`, or\n`cancelled`). Either source may carry a strict cause made only of bounded ids/refs.\n\nDelivery is at-least-once: durably deduplicate on stable `event_id`; `delivery_id` identifies one\nattempt. Any 2xx acknowledges and its response body is ignored. `tenant_id` is the platform scope;\nProduct namespaces live in fetched data, not the envelope. The envelope is only a pointer, so fetch\ndetails through existing authorized application reads. Observers inspect recent attempts and\nterminal `undeliverable` receipts at\n`GET /api/v2/applications/:deployment_id/events`.\n\n### Test application capability calls offline\n\nImport `createMockBoomboxAppRuntime` from `@konstantdotcloud/boombox/testing`, declare each peer verb and its\n`input_schema`, register the application event handler before calling the verb, and use the returned `fetch` as the\nconsumer transport. A successful verb response registers its terminal delivery immediately; a settled delivery\nfailure is claimed by the next mock transport interaction. Always `await runtime.flushEvents()` after the verb call:\n`flushEvents()` is the synchronization point that proves every scheduled delivery settled or throws its typed\nfailure.\n\nAn unclaimed or pending delivery failure is written to stderr at process exit and changes an otherwise-successful\n`process.exitCode` to `1`; a consumer `unhandledRejection` handler cannot swallow that failure. Use\n`terminal_event_delay_ms` only to simulate asynchronous timing. Correctness must depend on durable ordering and\n`flushEvents()`, never on a chosen delay. The complete offline path is at\n`examples/consumer-app-full-loop` from the Konstant repository root; npm consumers use the\n`@konstantdotcloud/boombox` entrypoints shown there.\n\n### Develop locally against a live application\n\nThe callee owner explicitly declares up to eight exact Google principals in `peer_ingress.developer_invokers` and applies the `iam_invoker_federation` target. An authenticated Product-account developer for the application's own tenant—using an operator-seat or tenant-admin credential—then runs `boombox app dev-token <application_id>` and sends two headers to the callee: `X-Serverless-Authorization` with the standard `Bearer` scheme applied to the output of `gcloud auth print-identity-token --audiences=<app url>` for the declared Cloud Run principal, and `x-boombox-peer-assertion` with the `dev-token` output for application authority. The short-lived host-signed assertion records `sub: developer:<key_id>` and `subject_kind: developer`; the route refuses when the callee has not elected developer access.\n\n### Application secrets and service availability\n\nDeclare each secret reference with the environment name that should receive its file path; the value never enters\nthe descriptor, code, image, environment, or logs:\n\n```json\n{\n  \"secret_refs\": [\n    {\n      \"ref\": \"<SECRET_REF>\",\n      \"residency_class\": \"<RESIDENCY_CLASS>\",\n      \"region\": \"<REGION>\",\n      \"env_file\": \"SECRET_VALUE_FILE\"\n    }\n  ]\n}\n```\n\nThe operator creates the secret and value version in the application's cloud project, then places the matching\nbinding in `application_runtime` in the host manifest:\n\n```bash\ngcloud secrets create <SECRET_ID> --project=<PROJECT_ID> \\\n  --replication-policy=user-managed --locations=<REGION>\ngcloud secrets versions add <SECRET_ID> --project=<PROJECT_ID> --data-file=-\n```\n\n```json\n{\n  \"secret_bindings\": [\n    {\n      \"ref\": \"<SECRET_REF>\",\n      \"kind\": \"gcp_secret_manager\",\n      \"project\": \"<PROJECT_ID>\",\n      \"secret_id\": \"<SECRET_ID>\",\n      \"residency_class\": \"<RESIDENCY_CLASS>\",\n      \"region\": \"<REGION>\"\n    }\n  ]\n}\n```\n\nApply pins the latest enabled numeric version and injects only its mounted file path under `SECRET_VALUE_FILE`.\nRotation is version-add followed by `boombox app refresh <deployment_id>`: refresh re-evaluates the active admitted\ndescriptor and target, rolls provider state only when convergence requires it, records a refresh receipt, and leaves\nan unchanged deployment on the same revision. Running revisions are never silently re-keyed. `APPLICATION_SECRET_BINDING_NOT_FOUND` means the operator creates the missing store object\nand adds the manifest binding; `SECRET_MANAGER_VERSION_UNAVAILABLE` means no enabled value has been placed; and\n`APPLICATION_SECRET_RESOLUTION_UNSUPPORTED` continues on a standing staging `cloud_run_service` in\n`standing_targets[]`, not preview or `boombox_vm`.\n\n**FALLBACK — until `secret_refs`, or for local development.** An application in its own cloud project may read its\nstore directly at boot with ambient identity:\n\n```ts\nimport { SecretManagerServiceClient } from '@google-cloud/secret-manager';\nconst store = new SecretManagerServiceClient();\nconst name = process.env.SECRET_VERSION_REF!;\nconst [version] = await store.accessSecretVersion({ name });\nconst value = version.payload?.data?.toString('utf8');\n```\n\nThis fallback is not portable and is not per-app-isolated. Prefer `secret_refs` whenever the host supports it, and\nnever place a secret value in a descriptor, image `ENV`, or code.\n\nChoose by traffic and latency promise: `preview` is disposable and TTL-bound; standing\n`availability: 'on_demand'` is durable, scale-to-zero, and may cold-start; standing\n`availability: 'always_on'` keeps a warm floor. `on_demand` requires `scaling.min_instances: 0`; `always_on` or an\nomitted `availability` requires at least `1`.\n\nReleased runtime lane facts: `boombox_vm` and standing `cloud_run_service` receive their operation credential as\n`token_file`; bounded Cloud Run preview uses `not_provided_v1`; `staging` forbids a preview block; `production`\nrequires a declared qualification. Standing Cloud Run targets have no preview TTL or cost cap, keep their artifact\nunder `allowed_repository_roots`, and require `standing_artifact_hosts` only when a standing `boombox_vm` target is\npresent. Admission refuses target, artifact, and availability-floor drift before provider apply with\n`APPLICATION_TARGET_NOT_APPROVED`, `APPLICATION_ARTIFACT_NOT_APPROVED`,\n`APPLICATION_STANDING_SCALING_NOT_ALWAYS_ON`, or `APPLICATION_ON_DEMAND_SCALING_NOT_SCALE_TO_ZERO`.\n\nA descriptor may optionally pin a product-owned semantic-admission context\nschema and verifier release. Invoke then supplies only an opaque placed context\nreference and claims digest. The host verifies placement, calls the product\nverifier with frozen input and narrow authenticated identity, independently\nreads and byte-verifies one exact accepted/refused receipt generation in\ncustomer custody, and creates no logical run or provider call on refusal. The\naccepted proof enters the host admission receipt and worker boundary.\nThe public client returns that product outcome as\n`BoomboxWorkloadProductAdmissionRefusalError`, exposing only its bounded\nproduct-owned reason code and host-verified immutable receipt reference. It\ndoes not expose a raw host/provider body, payload, or credential, and only the\nexact domain-refusal HTTP status can produce that typed result; a platform\nfailure with a lookalike body remains generic and redacted.\n\n`runBoomboxWorkloadProductAdmissionVerifierConformance()` proves exact repeated\nacceptance plus explicit stable product-owned refusals without importing product\nsemantics into Boombox.\n`verifyBoomboxWorkloadRunAdmissionReceiptForContext()` supports the separate\nworker-side check of the already-issued host receipt before product code begins.\nProducts implement those adapters and remain authoritative for their claims and receipt meaning;\nBoombox supplies authenticated admission, placement/custody verification, execution,\nrecovery, and host receipts for the current operating arrangement. The generic worker verifier proves host-receipt\nintegrity and exact context; the product adapter must additionally reject a\nstill-valid product proof that is semantically stale or mismatched.\n\nThe MCP transport is the local stdio bridge. Its stdout is reserved for JSON-RPC; diagnostics use stderr. `scan` is\noffline, with `builder` authenticating in a separate working context at the same canonical root. Platform\nadministration is a separate operator-configured surface and does not grant authority by profile selection. The authenticated build route is the single instrumentation point\nfor MCP, CLI, and other admitted clients; the MCP is not a privileged telemetry side door.\n\n`cassettes build` stages the actual Product spec in the tenant's private draft store. Its best-effort activity event is\ndeliberately smaller: server-derived cassette/schema/spec digest and draft/revision, a bounded caller-declared\ntoolchain/version, `content_included:false`, and `storage_semantics:best_effort_activity_log`. The declaration is\nuseful funnel context, not client attestation. Caller-supplied source filenames, prompts, keys, and arbitrary\ntelemetry fields are discarded. The tenant draft remains authoritative Product state; richer connected capture\nrequires the tenant's explicit learning policy and grant.\n\n## Evaluation is local first\n\nImport the common evaluation contract from `@konstantdotcloud/boombox/evaluations` when an existing local harness\nneeds portable lineage. Keep the existing runner and map only facts it really knows to Subject, Claim, Case and Case\nset, Context binding, Configuration, Execution, Observation, Judgment, Outcome, Comparison, and owner Decision.\nBind exact Project, Product, Capability, Surface, Release, Deployment, and Run references.\n\nUse `granularity:'case'`, a present Case slot, and the real Case Set for the declared claim. A genuinely standalone\nepisode uses a singleton set with denominator one; a case within a predeclared suite may bind that exact wider\npopulation, while its Observations retain their own honest denominators. The case record alone does not establish a\nroute, selector, causal, cohort, or population claim. Such a claim uses a separate `granularity:'aggregate'` record,\nmarks Case absent with `reason:'not_applicable'`, and binds the complete decision population. Preserve an explicit\nunknown denominator or return a typed incomplete mapping when that population is not recorded; never substitute a\nconvenient singleton, mix populations, invent a synthetic suite case, or report only selected successes. Create present JSON references from the real\nverified values with `createBoomboxEvaluationJsonReference()`; a missing mandatory source produces a typed,\nnonblocking `mapping_incomplete` continuation rather than a fabricated URI or digest.\n\nCapture progresses in three explicit levels:\n\n1. `local_only` keeps the sealed record under repository or owner-cloud custody and is the default. Seal and verify\n   it, then use `tryRecordBoomboxEvaluation()` for a private ignored `.boombox/evaluations/` recovery journal whose\n   failure cannot replace the Product result.\n2. `service_fact` uses `tryCompileEvaluationServiceFactFromLocalEvaluation()` to derive a transient attached variant\n   internally and return only a payload-free operational discovery fact from the canonical sealed local record,\n   exact local profile, and verified project-attachment receipt. It cannot carry the rich\n   evaluation envelope, buckets source occurrence to a UTC hour, and is not Product evidence, a grader result,\n   outcome, or promotion.\n   Optional `job_id`, `subject_id`, `run_id`, and `head_digest` fields correlate the fact with a registered runtime\n   subject while keeping the projection payload-free. When the developer credential grants `evaluation.fact` and\n   `boombox_platform_describe({})` reports\n   `improvement.evaluation_atlas.service_fact_transport:'available_with_evaluation.fact_grant'`, use\n   `createBoomboxDeveloperWorkspaceEvaluationServiceFactClient()` after ordinary `boombox login`; it loads the\n   developer credential inside the composition root, pins the first receipt to that workspace, and never returns the\n   bearer to Product code. Trusted service/CI hosts may use the lower-level\n   `createBoomboxEvaluationServiceFactClient({base_url, authorize})` authority port. Wrap append with\n   `tryDeliverBoomboxEvaluationServiceFact()` to persist the exact fact before network access; a response-lost\n   delivery resumes with `tryResumeBoomboxEvaluationServiceFactDelivery()`, which first reads by deterministic\n   `bbevf_*` identity and the stored historical attachment binding. Pending entries are discoverable through\n   `listPendingBoomboxEvaluationServiceFactOutboxEntries()`. If the attachment advances before a pending fact is\n   accepted, compile the semantically identical fact against the new receipt and call\n   `tryRebindBoomboxEvaluationServiceFactDelivery()`: it reads the historical identity first, permits a successor\n   only after exact typed `NOT_FOUND`, requires the same stable project and a strictly newer attachment, and retains\n   predecessor/successor lineage so acceptance of either resolves recovery. The delivery result unions make one\n   bounded attempt at a time and report `product_work_blocked:false`; adapter code must still catch journal, compile,\n   and pending-list errors and preserve the Product result itself.\n3. `learning_grant_ref` requests rich connected capture. A local grant reference is never authority; the connected\n   service must verify the effective grant before accepting any rich record. The capture grant remains distinct from\n   `product_learning_authority_ref`. Its required `service_fact` boolean independently keeps or declines the\n   payload-free lane while rich authorization is evaluated; it does not authorize rich capture.\n\nBuilder-workspace usage events have a server-enforced 90-day TTL. Evaluation service facts are currently retained\nwithout a TTL. That is current storage behavior, not indefinite learning permission: richer capture or broader use\nrequires explicit retention, deletion, legal-hold, and derived-use policy before it ships.\n\nThe Product owner controls domain schemas, cases, graders, floors, outcomes, evidence meaning, extensions, and every\nqualification or promotion decision. Context binds by authorized class, immutable reference/digest, freshness,\nscope, and custody; it carries no raw source, prompt, transcript, payload, or evidence bytes and grants no read\nauthority. Evaluation, context, Chronicle, research, telemetry, or learning-service failure never blocks a safe\nProduct validate, plan, deploy, run, inspect, or retire path.\n\nRead the package-shipped `references/evaluation-ontology.md` guide or invoke the MCP prompt\n`boombox_map_existing_evaluations` for repository-specific guidance. Evaluation mapping is SDK authoring plus an\nMCP guidance prompt: the MCP exposes no rich-evaluation append, mutate, qualify, or promote tool. The only connected\nevaluation transport in this cohort is the optional payload-free service-fact SDK lane described above. Jest,\nVitest, Pytest, Promptfoo, a custom harness, human review, or a business-outcome system remains the runner and\nsemantic authority.\n\nFor a long-running ablation or research program, keep the Product's existing `program_id` and append-only scientific\nDAG. The Product store remains authoritative for hypotheses, membership, branches, joins, evidence meaning,\noutcomes, and decisions. The planned connected program projection will index immutable refs to Evaluations, Runs,\nReleases, configurations, receipts, and freshness so a fresh MCP session can reopen the work; reading that index\nwill not grant evidence-handle access. Until that service is advertised, reopen locally and return one typed Need\nwithout blocking the program.\n\nA current lightweight ablation record that may carry raw inputs/outputs and lacks stable evidentiary identity remains Product\ndevelopment evidence. Project only its immutable artifact reference as an Observation using\n`BOOMBOX_EVALUATION_COMPONENT_CONFORMANCE_OBSERVATION_KEY`; do not treat it as preregistered, causal,\nqualification-eligible, or training-eligible evidence. Material work freezes and contextually verifies the Product's\nreal experiment spec and immutable experiment record. Record kind alone grants no Atlas, qualification, promotion, or\ntraining eligibility; durable Run composition remains a separate advertised lifecycle integration.\n\nTraining is a separate optional chain: Product Program Event -> Product-labeled Learning Example -> purpose- and\ngrant-bound Learning Corpus View -> immutable selected-plus-excluded Corpus Manifest -> durable Training Run ->\nProduct eval/floor and promotion decision. A Run, trace, receipt, service fact, or corpus exclusion is not a label.\nRaw material and full manifests stay in declared custody; common refs/digests make authorized records joinable, and\nowner-published compatibility artifacts decide whether labels from different Products or customers may share a\ncorpus. No connected corpus or training API is claimed by this package yet.\n\n## Loading a harness — pick a shape\n\nYou have a capability in another codebase — a harness: pure core, typed\ncommands, self-describe, evals. Boombox maps it to one of four Product shapes. A Product may also use the optional\nsubject-runtime primitive when durable per-subject snapshot reduction fits. Pick the smallest road that fits and prove one harmless vertical slice first; the\ncomplete agent-executable doctrine is the packaged skill\n(`skills/build-on-boombox/SKILL.md`, installed into a consumer repo by\n`boombox project init`, served live as `boombox://developer/skill`).\n\n|Shape|What it is|Author with|Prove locally, no mutation|\n|-|-|-|-|\n|**Cassette**|One capability as a governed, repeatable action: dry-run gated, typed outputs, every run receipted|`CassetteSpecV2` YAML or `defineCassette()` (same grammar)|`cassette_dry_run` until the exact `spec_hash` is green|\n|**Portable application**|Your frontend + your live harness API in one immutable image, one origin, deployed and governed by Boombox|`defineApplication` / `defineApplicationTarget` / `planBoomboxApplicationDeployment` from `@konstantdotcloud/boombox/apps`|`boombox_application_validate` + `boombox_application_plan`|\n|**Durable workload**|A product-owned worker under Boombox admission, leases, fencing, checkpoints, and receipts|`defineWorkload` / `defineWorkloadTarget` / `planBoomboxWorkload` from `@konstantdotcloud/boombox/workloads`|`boombox_workload_validate` + `boombox_workload_plan`|\n|**Optional subject-runtime primitive**|A generic reducer that extends any selected Product shape with durable snapshots for independently addressed subjects|Packaged job/handle declarations plus `@konstantdotcloud/boombox`, `/custody`, and `/job-io`|Declaration dry-runs, the packaged local fixture, and custody conformance|\n|**Existing capability**|A library, CLI, legacy application, HTTP service, or MCP server exposed through its narrow qualified operation set|Existing capability/MCP registration plus explicit allowlist and immutable binding|Local adapter and refusal tests; arbitrary-endpoint qualification and automatic HTTP-to-MCP activation remain staged work|\n\nAll four Product shapes—and the optional primitive when selected—share one law: **a green plan is not a deployment.** Local\nvalidate/plan tools are deliberately non-authoritative; apply, publish,\npromote, trigger, and their receipts require the selected Product account's production\nauthority. Where that authority is unavailable, the honest terminal result\nis the validated plan plus the exact missing adapter — never a fabricated\ndeployment, run, or receipt. The deeper contracts for each shape are in the\nsections above and in the packaged skill.\n\n## Optional subject-runtime job loop\n\nChoose this loop when the Product needs a generic reducer to maintain durable snapshots for independently addressed\nsubjects. It extends the cassette, portable-application, durable-workload, and existing-capability roads; it does\nnot replace them. Stateless and local applications remain first-class and skip this loop. The packaged fixture is\na cloneable starting point, never a required Product, workflow, UI, model, or deployment shape.\n\n### Authority model\n\nBoombox keeps three authorities separate:\n\n- Observer authority reads job status, subject status, subject heads, head content, and run evidence.\n- Product-account authority registers and changes jobs, subjects, handles, plans, credentials, and runs.\n- An injected application operation credential provides a bounded read surface inside a deployed application.\n\nEvery connected `job`, `subject`, and `handle` verb sends its credential only to the enrolled Product runtime host. If no runtime host is enrolled, the CLI refuses before issuing a request and never falls back to the control gateway.\n\nNever put credential values in command arguments, declarations, logs, prompts, fixtures, or reports. The CLI resolves observer and Product-account bindings from its selected configuration. Direct SDK composition supplies the two authorities separately and refuses when the same value is used for both.\n\nThe injected application client refuses every mutation before issuing a request with code `APPLICATION_READ_ONLY` and this remedy:\n\n> Use the product-account setup composition or a product-bound mutation path.\n\n### Supported job journey\n\nThe installed subject-runtime fixtures are under:\n\n```text\nnode_modules/@konstantdotcloud/boombox/fixtures/subject-runtime/\n```\n\nCopy `job-declaration.json` and `handle.json` into your repository, then edit their domain fields. Keep `job.json`, `input.json`, `heads.json`, and `fixture-reducer.mjs` together when running the packaged local example.\n\n#### 1. Validate declarations locally\n\n```bash\n./node_modules/.bin/boombox job register ./job-declaration.json --dry-run\n./node_modules/.bin/boombox handle create ./handle.json --dry-run\n```\n\nA valid dry run exits `0` without loading a connection or issuing a request. An invalid declaration exits `1` and prints the first failing field plus a remedy.\n\nThe accepted job declaration has this shape:\n\n```json\n{\n  \"tenant_id\": \"tenant_fixture\",\n  \"subject_kind\": \"fixture_snapshot\",\n  \"environment\": \"staging\",\n  \"versions\": [\n    {\n      \"job_version\": 1,\n      \"reducer\": {\n        \"image_ref\": \"oci://registry.example/fixture/reducer@sha256:1111111111111111111111111111111111111111111111111111111111111111\",\n        \"image_digest\": \"sha256:1111111111111111111111111111111111111111111111111111111111111111\",\n        \"command\": [\"node\", \"./fixture-reducer.mjs\"],\n        \"env_allowlist\": []\n      },\n      \"snapshot_schema_ref\": \"bb://schemas/fixture-snapshot/v1\",\n      \"handles\": []\n    }\n  ],\n  \"active_version\": 1,\n  \"due\": {\n    \"compose\": \"any\",\n    \"rules\": [{ \"kind\": \"every\", \"seconds\": 3600 }],\n    \"scheduler\": \"external_scheduler\"\n  },\n  \"dependencies\": [],\n  \"requeue_max_depth\": 3,\n  \"timeout_ms\": 5000,\n  \"placement\": {\n    \"lane\": \"bl_ffffffffffffffffffffffffffffffff\",\n    \"project\": \"fixture-project\",\n    \"region\": \"local\",\n    \"residency_class\": \"local\"\n  }\n}\n```\n\nHosted operations have three additional requirements: `reducer.image_ref` must itself include the exact `@sha256:…` suffix even when `image_digest` is present; `job promote` requires the selected version's `qualification { qualification_ref, qualification_digest }` (staging accepts the reducer image digest); and `job trigger --now` applies to watched source events, so a handle-less job refuses with `JOB_TRIGGER_NO_EVENT`, an `external_scheduler` job refuses with `JOB_TRIGGER_EXTERNAL_SCHEDULER`, and a `host_tick` `every` rule admits due runs automatically after a subject is bound.\n\nThe accepted handle declaration has transport, location, format, schema digests, ontology mapping, identity and time policies, freshness, budget, event identity, rights references, resource owner, region, and residency class. Use the complete installed `handle.json` fixture as the starting document.\n\n#### 2. Prove the registered job locally\n\nRun the complete installed `job.json` unchanged:\n\n```bash\nPKG_ROOT=node_modules/@konstantdotcloud/boombox\n./node_modules/.bin/boombox job run-local \\\n  \"$PKG_ROOT/fixtures/subject-runtime/job.json\" \\\n  --input \"$PKG_ROOT/fixtures/subject-runtime/input.json\" \\\n  --heads \"$PKG_ROOT/fixtures/subject-runtime/heads.json\" \\\n  --mode files \\\n  --store memory\n```\n\n`--mode open-commit` proves the same reducer through the service-run open/commit boundary. `--store dir <path>` persists content, pointers, and durable head metadata under the supplied directory; the positional `<path>` follows `job.json`:\n\n```bash\n./node_modules/.bin/boombox job run-local \\\n  \"$PKG_ROOT/fixtures/subject-runtime/job.json\" ./job-store \\\n  --input \"$PKG_ROOT/fixtures/subject-runtime/input.json\" \\\n  --mode open-commit \\\n  --store dir\n```\n\nThe local host validates the shared job input/output schemas, mounts the generated handle grant file read-only for Docker reducers, commits snapshots through the custody port, and records a durable head-to-metadata link. It does not rewrite the registered `job.json`.\n\nThe hosted reducer contract is the same file contract proven by `job run-local`: the host materializes one immutable\n`boombox.job-input/v1` document at launch, supplies its path and the reducer output path through\n`BOOMBOX_JOB_INPUT` and `BOOMBOX_JOB_OUTPUT`, validates the canonical job-output schema, and publishes\n`boombox.job-output/v1` plus snapshots with derived `content_type`. A hosted run requires a host granted\n`workload_runtime` and an approved active workload revision; admission remains typed, including\n`WORKLOAD_TARGET_NOT_APPROVED`, `WORKLOAD_RUNNER_UNSUPPORTED`, `WORKLOAD_IMAGE_NOT_APPROVED`, and\n`WORKLOAD_REVISION_NOT_ACTIVE`. Treat the local run as reducer-contract proof, not proof of a live hosted run.\n\n#### 3. Register and connect\n\nUse an authorized Product-account binding for connected mutations:\n\n```bash\n./node_modules/.bin/boombox job register ./job-declaration.json\n./node_modules/.bin/boombox handle create ./handle.json\n./node_modules/.bin/boombox handle connect <handle> <job>\n./node_modules/.bin/boombox subject register ./subject.json\n```\n\nEvery connected refusal carries both its message and remedy. A registration or connection may return `created` or `reused`; both are successful, idempotent outcomes.\n\n#### 4. Inspect status, heads, content, and evidence\n\nObserver commands read current state:\n\n```bash\n./node_modules/.bin/boombox job status <job>\n./node_modules/.bin/boombox subject status <subject>\n./node_modules/.bin/boombox subject heads <subject> --environment staging\n```\n\nThe SDK adds validated head content and run evidence reads:\n\n```ts\nimport { createBoomboxSubjectRuntimeClient } from '@konstantdotcloud/boombox';\n\nconst client = createBoomboxSubjectRuntimeClient({\n  base_url: gateway_origin,\n  observer_credential: observer_authority,\n  product_account_credential: product_account_authority,\n});\n\nconst registration = await client.ensureSubject({\n  kind: 'fixture_snapshot',\n  external_key: 'fixture-subject',\n  entity_refs: [],\n  job_ids: [],\n});\n\nconst { heads } = await client.listSubjectHeads(registration.subject_id, 'staging');\nif (heads[0]) {\n  const content = await client.readHeadContent(heads[0]);\n  const evidence = await client.getRunEvidence(heads[0].run_id);\n  console.log(content.digest, content.content_type, content.size_bytes, evidence.ref);\n}\n```\n\n`ensureSubject()` and its alias `registerSubject()` return `{ status: 'created' | 'reused', subject_id, subject }`. `listSubjectHeads()` returns validated heads plus a nullable cursor. Each head includes `content_type` and nullable `run_receipt`.\n\n`readHeadContent()` sends `x-boombox-expected-digest`, requires the response `ETag` and `x-boombox-content-digest` to match the head, verifies the SHA-256 bytes, and limits the response to 25 MiB by default. Supply `{ max_bytes }` for a smaller bound. Transport, refusal, and integrity failures use `BoomboxContentTransportError`, `BoomboxContentRefusal`, and `BoomboxContentIntegrityError`.\n\n`getRunEvidence()` returns `{ run_id, ref, digest, media_type }`. Non-terminal, missing-receipt, and mismatch refusals preserve the gateway code, message, and remedy in `BoomboxRunEvidenceRefusal`.\n\n### Injected application reads\n\n`resolveBoomboxAppRuntime()` synchronously validates the required runtime environment. The operation credential is loaded lazily from the file named by `BOOMBOX_APP_OPERATION_TOKEN_FILE`; tests and embedders may provide the `read_file` dependency.\n\nEach `data_handles[]` entry may declare `env: { bucket?, prefix?, uri? }` with application-owned uppercase environment names; Boombox delivers the admitted values under those names and reports the wiring through `data_handles()`, while runtime identity—not any delivered value—remains the credential.\n\n```ts\nimport {\n  createInjectedSubjectRuntimeClient,\n  resolveBoomboxAppRuntime,\n} from '@konstantdotcloud/boombox/apps';\n\nconst runtime = resolveBoomboxAppRuntime();\nif (runtime.status === 'injected') {\n  const client = createInjectedSubjectRuntimeClient(runtime);\n  const status = await client.getSubjectStatus(subject_id);\n  const { heads } = await client.listSubjectHeads(subject_id);\n  const content = heads[0] ? await client.readHeadContent(heads[0]) : null;\n  const evidence = heads[0] ? await client.getRunEvidence(heads[0].run_id) : null;\n  console.log(status, content?.digest, evidence?.ref);\n}\n```\n\nThe injected client supports `getSubjectStatus`, `listSubjectHeads`, `getJobStatus`, `readHeadContent`, and `getRunEvidence`. It does not derive authority from any other environment value or read any other file.\n\n### Custody conformance\n\nThe default in-memory custody store is fail-closed for destructive authority. Its documented conformance one-liner returns a report:\n\n```ts\nimport {\n  createMemoryBoomboxContentCustody,\n  runBoomboxContentCustodyConformance,\n} from '@konstantdotcloud/boombox/custody';\n\nconst report = await runBoomboxContentCustod","readmeFilename":"README.md"}