@decantr/verifier
Advanced tools
+1
-1
@@ -87,3 +87,3 @@ { | ||
| "types": "dist/index.d.ts", | ||
| "version": "3.11.0" | ||
| "version": "3.11.2" | ||
| } |
+6
-3
@@ -10,3 +10,3 @@ # @decantr/verifier | ||
| Decantr 3.11.0 is the current stable line. It adds Changed-UI Assurance to the independent UI authority axes, route and non-route task context, compatible route-backed task capsules, adoption truth, governance deltas, and report schemas. The release is not quantitatively adoption-proven. | ||
| Decantr 3.11.2 is the current stable line. It adds Changed-UI Assurance to the independent UI authority axes, route and non-route task context, compatible route-backed task capsules, adoption truth, governance deltas, and report schemas. The release is not quantitatively adoption-proven. | ||
@@ -27,3 +27,3 @@ The verifier models routes, layouts, components, stories, overlays, flows, packages, and runtime states as independent UI surfaces and reports selected-app, surface-authority, topology, taskability, component-inventory, styling-authority, and runtime-evidence axes separately. These shipped APIs do not establish that Decantr improves model outcomes; only a separate controlled A/B program can support that claim. | ||
| - `auditBuiltDist()` for built-output runtime verification against emitted HTML, assets, and route hints | ||
| - `discoverProject()` for shared read-only Brownfield discovery of workspace/app scope, package manager, framework, language, source-declared routes, taskable routes, component inventory, styling authority, Decantr presence, and inherited assistant-rule files. Formal framework routes outrank generated trees, and Angular discovery begins at the selected production bootstrap/router graph while excluding test and fixture source. | ||
| - `discoverProject()` for shared read-only Brownfield discovery of workspace/app scope, package manager, framework, language, source-declared routes, taskable routes, component inventory, styling authority, Decantr presence, and inherited assistant-rule files. Authored framework routes remain implementation authority; TanStack generated route metadata may corroborate public paths without becoming the edit target. Angular discovery begins at the selected production bootstrap/router graph while excluding test and fixture source. | ||
| - `scanProject()` for read-only Brownfield reconnaissance that emits `scan-report.v2` by default using the shared discovery substrate | ||
@@ -94,2 +94,5 @@ - `auditComponentReuse()` for the first AST-derived component reuse drift slice, focused on AI reimplementing common UI primitives instead of importing project-owned components, plus local import references that the typed graph can turn into source-to-source impact edges | ||
| - Next App/Pages Router discovery evaluates root or `src/` middleware/proxy policy and reachable local helpers separately from file-route declaration. Statically identified 4xx-conditioned routes remain observable but non-taskable; unresolved path-dependent policy degrades authority and fails closed. | ||
| - TanStack file-route discovery maps route groups, pathless layouts, and parameter identifiers to generated public-path metadata when available. Root and pathless layouts remain non-taskable; convention-sensitive paths without generated corroboration cap completeness at `partial`. | ||
| - Astro discovery treats `.astro`, `.md`, `.mdx`, and `.html` files under `pages` as UI pages. TypeScript and JavaScript files in that tree remain observable response endpoints but are not taskable UI surfaces. | ||
| - Angular discovery treats wildcard routes as terminal fallbacks, resolves `ng-packagr` workspace secondary entries to their exported component source, and includes static `templateUrl`, `styleUrl`/`styleUrls`, and adjacent Pug authoring sources in task reads. | ||
| - Candidate styling discovery follows ordered production stylesheet imports through local files and workspace package exports. Task read sets preserve that cascade order, and Next API route handlers are excluded from the UI component inventory. | ||
@@ -168,3 +171,3 @@ | ||
| These contracts define deterministic evidence shapes; they do not prove product value by themselves. Stable 3.11.0 is product-qualified, not human-qualified or adoption-proven. A separate frozen 40-task, two-model, two-arm, repeated A/B protocol gates only a measured model-improvement claim. Development-corpus results may tune implementation but cannot grant that confirmatory claim; qualification failures, unsupported targets, missing evaluators, build failures, and model substitutions remain visible in its denominator. | ||
| These contracts define deterministic evidence shapes; they do not prove product value by themselves. Stable 3.11.2 is product-qualified, not human-qualified or adoption-proven. A separate frozen 40-task, two-model, two-arm, repeated A/B protocol gates only a measured model-improvement claim. Development-corpus results may tune implementation but cannot grant that confirmatory claim; qualification failures, unsupported targets, missing evaluators, build failures, and model substitutions remain visible in its denominator. | ||
@@ -171,0 +174,0 @@ ## Security And Permissions |
Sorry, the diff of this file is too big to display
Sorry, the diff of this file is too big to display
Sorry, the diff of this file is too big to display
URL strings
Supply chain riskPackage contains fragments of external URLs or IP addresses, which the package may be accessing at runtime.
Network access
Supply chain riskThis module accesses the network.
Filesystem access
Supply chain riskAccesses the file system, and could potentially read sensitive data.
Found 2 instances
URL strings
Supply chain riskPackage contains fragments of external URLs or IP addresses, which the package may be accessing at runtime.
3149770
1.42%30810
1.09%187
1.63%1
-94.44%1
-83.33%