{
  "name": "mandrel",
  "version": "2.58.0",
  "description": "Claude Code-first opinionated workflow framework: instructions, skills, rules, and SDLC workflows that govern AI coding assistants.",
  "files": [
    ".agents/",
    "bin/",
    "docs/CHANGELOG.md",
    "lib/",
    "!lib/**/__tests__",
    "!.agents/**/__tests__"
  ],
  "publishConfig": {
    "access": "public",
    "provenance": true
  },
  "scripts": {
    "//test-preflight": "There are deliberately NO pretest* scripts (Story #4936). .npmrc sets ignore-scripts=true as supply-chain defence (CWE-1357), and that suppresses every pre*/post* lifecycle script for `npm run` too — so a pretest entry here would look like a gate and never execute. Each tier's preflight is declared once in .agents/scripts/lib/test-runner-contract.js and invoked by the runners themselves, which is why it fires for `npm test`, `npm run test:coverage` and a bare `node .agents/scripts/run-tests.js` alike.",
    "test": "node .agents/scripts/run-tests.js",
    "test:quick": "node .agents/scripts/run-tests.js --tier quick",
    "test:integration": "node .agents/scripts/run-tests.js --tier integration",
    "test:e2e": "node .agents/scripts/run-tests.js --tier e2e",
    "test:profile": "node .agents/scripts/run-test-profile.js",
    "test:census": "SPAWN_CENSUS_OUT=\"${SPAWN_CENSUS_OUT:-temp/census.json}\" NODE_OPTIONS=\"--require $PWD/tests/fixtures/spawn-census.cjs\" node .agents/scripts/run-tests.js",
    "test:isolate": "node .agents/scripts/test-isolate.js",
    "verify": "node .agents/scripts/run-verify.js",
    "typecheck": "node -e \"process.exit(0)\"",
    "test:coverage": "node .agents/scripts/run-coverage.js",
    "coverage:check": "node .agents/scripts/check-baselines.js --gate coverage",
    "coverage:update": "node .agents/scripts/update-coverage-baseline.js",
    "coverage:reanchor": "node .agents/scripts/update-coverage-baseline.js --full-scope",
    "baseline:agents-loc": "node baselines/agents-loc-baseline.mjs",
    "baselines:scope": "node .agents/scripts/check-baseline-scope.js",
    "baselines:prune": "node .agents/scripts/prune-baseline-orphans.js",
    "baselines:merge-driver": "node .agents/scripts/merge-baseline.js --install",
    "lint:md": "markdownlint-cli2 \".agents/**/*.md\" \"*.md\" \"!node_modules/**\" \"!.worktrees/**\"",
    "lint": "node .agents/scripts/run-lint.js && node .agents/scripts/check-generated-validator.js --check && node .agents/scripts/check-pinned-override-notes.js && npm run docs:check",
    "docs:gen": "node .agents/scripts/generate-config-docs.js && node .agents/scripts/generate-workflows-doc.js && node .agents/scripts/generate-lens-checklists.js",
    "docs:check": "node .agents/scripts/generate-config-docs.js --check && node .agents/scripts/generate-workflows-doc.js --check && node .agents/scripts/generate-lens-checklists.js --check && node .agents/scripts/check-doc-links.js && npm run skills:check",
    "skills:index": "node .agents/scripts/generate-skills-index.js",
    "skills:check": "node .agents/scripts/generate-skills-index.js --check",
    "format": "biome format --write .",
    "format:check": "biome ci .",
    "maintainability:check": "node .agents/scripts/check-baselines.js --gate maintainability",
    "maintainability:update": "node .agents/scripts/update-maintainability-baseline.js",
    "maintainability:reanchor": "node .agents/scripts/update-maintainability-baseline.js --full-scope",
    "check:arch": "node .agents/scripts/check-arch-cycles.js",
    "check:context-budget": "node .agents/scripts/check-context-budget.js",
    "check:cyclomatic": "node .agents/scripts/check-cyclomatic.js",
    "cyclomatic:update": "node .agents/scripts/check-cyclomatic.js --update",
    "dead-exports:update": "node .agents/scripts/update-dead-exports-baseline.js && node .agents/scripts/update-dead-exports-baseline.js --production",
    "check:knip-entries": "node .agents/scripts/check-knip-entries.js",
    "validator:gen": "node .agents/scripts/check-generated-validator.js",
    "validator:check": "node .agents/scripts/check-generated-validator.js --check",
    "check:schema-refs": "node .agents/scripts/check-schema-references.js",
    "check:workflow-citations": "node .agents/scripts/check-workflow-citations.js",
    "crap:check": "node .agents/scripts/check-baselines.js --gate crap",
    "crap:update": "node .agents/scripts/update-crap-baseline.js",
    "crap:reanchor": "node .agents/scripts/update-crap-baseline.js --full-scope",
    "duplication:check": "node .agents/scripts/check-baselines.js --gate duplication",
    "duplication:update": "node .agents/scripts/update-duplication-baseline.js",
    "duplication:reanchor": "node .agents/scripts/update-duplication-baseline.js --full-scope",
    "quality:preview": "node .agents/scripts/check-dead-exports.js && node .agents/scripts/quality-preview.js",
    "quality:watch": "node .agents/scripts/quality-watch.js",
    "sync:commands": "node bin/mandrel.js sync-commands",
    "sync:agents": "node .agents/scripts/sync-claude-agents.js",
    "prepare": "husky && npm run sync:commands && npm run sync:agents && npm run baselines:merge-driver",
    "postinstall": "node bin/postinstall.js mandrel sync"
  },
  "repository": {
    "type": "git",
    "url": "git+https://github.com/dsj1984/mandrel.git"
  },
  "keywords": [
    "claude-code",
    "ai-agents",
    "sdlc",
    "workflow",
    "orchestration",
    "agentic"
  ],
  "author": "",
  "license": "MIT",
  "bin": {
    "mandrel": "./bin/mandrel.js"
  },
  "type": "module",
  "bugs": {
    "url": "https://github.com/dsj1984/mandrel/issues"
  },
  "homepage": "https://github.com/dsj1984/mandrel#readme",
  "engines": {
    "node": ">=22.22.1 <25"
  },
  "devDependencies": {
    "@biomejs/biome": "^2.5.0",
    "@commitlint/cli": "^21.0.2",
    "@commitlint/config-conventional": "^21.0.2",
    "@cucumber/gherkin": "^42.0.1",
    "c8": "^11.0.0",
    "chokidar": "^5.0.0",
    "husky": "^9.1.7",
    "jscpd": "^4.2.5",
    "knip": "^6.17.1",
    "lint-staged": "^17.0.7",
    "markdownlint-cli2": "^0.22.1",
    "memfs": "^4.57.7",
    "node-pty": "^1.0.0",
    "typescript": "^6.0.3"
  },
  "dependencies": {
    "ajv": "^8.20.0",
    "ajv-formats": "^3.0.1",
    "js-yaml": "^4.3.2",
    "minimatch": "^10.0.0",
    "picomatch": "^4.0.4",
    "typhonjs-escomplex": "^0.1.0"
  },
  "peerDependencies": {
    "@cucumber/gherkin": ">=32.0.0",
    "typescript": ">=5.0.0"
  },
  "peerDependenciesMeta": {
    "@cucumber/gherkin": {
      "optional": true
    },
    "typescript": {
      "optional": true
    }
  },
  "//": {
    "peerDependencies.@cucumber/gherkin": "OPTIONAL peer, mirroring the `typescript` precedent, and deliberately NOT a runtime dependency. `check-gherkin-corpus.js` is the only consumer and it is opt-in behind `qa.gherkinLint`, so a consumer with no BDD tier must gain nothing from an upgrade. The devDependency alongside it is what lets this repository's own suite drive the real parser. The gate resolves it through a require path anchored at the consumer project — `.agents/` reaches a consumer by plain file copy, so a bare specifier would resolve against the consumer's module chain, which under a non-hoisting linker need not hold it.",
    "overrides.js-yaml": "COUPLED to devDependencies.markdownlint-cli2 — do not bump either alone, and do NOT drop this override. It is load-bearing: markdownlint-cli2 0.22.x pulls js-yaml 4.1.1, which carries GHSA-52cp-r559-cp3m (high) and GHSA-h67p-54hq-rp68 (moderate); removing the override was measured to reintroduce both (1 high + 1 moderate), while with it in place `npm audit` is clean. An npm override also wins over a transitive package's own pin, so this tree-wide ^4.3.2 is imposed on every js-yaml consumer regardless of what they declare — and markdownlint-cli2 0.23.x declares an exact js-yaml 5.2.1. A dry-run bump confirmed the trap: markdownlint-cli2 0.23.1 resolves against js-yaml 4.3.0, two majors off what it declares, silently. The only safe move is to raise this override and bump markdownlint-cli2 in ONE reviewed commit (first confirming cosmiconfig, under @commitlint/cli, tolerates the same major). renovate.json excludes markdownlint-cli2 from devDependency auto-merge so that pair cannot drift apart unattended. The floor has since been raised twice for advisories against the pinned range itself (most recently to ^4.3.2 for GHSA-2883-xcg3-v3hh, whose fix is 4.3.2) — raising it is safe and does NOT touch the coupling above; check-pinned-override-notes.js now fails the build if this sentence and the pin disagree.",
    "dependencies.js-yaml": "States the SAME range as overrides.js-yaml above. The two are deliberate duplicates — npm has no way to reference the direct range from the overrides block — so they MUST move in lockstep; changing one without the other silently splits the direct and transitive resolutions.",
    "overrides.smol-toml": "Load-bearing: markdownlint-cli2 0.22.1 declares an EXACT smol-toml 1.6.1, which carries GHSA-7w5x-hrqm-74c2 (high — denial of service via malformed TOML). The advisory’s vulnerable range is everything <= 1.7.0, so no lockfile-only resolution reaches a patched version and this tree-wide ^1.7.1 pin is what clears it. npm’s own `audit fix --force` instead proposes markdownlint-cli2 0.21.0 — a DOWNGRADE presented as a breaking change; do not take it. An npm override wins over a transitive package’s own exact pin, so markdownlint-cli2 runs against a minor it never declared: `npm run lint` was confirmed green under the forced version and is what must be re-run if this pin moves. knip declares ^1.6.1 and is satisfied natively. smol-toml is NOT a direct dependency, so unlike overrides.js-yaml there is no lockstep duplicate range to keep in sync."
  },
  "overrides": {
    "js-yaml": "^4.3.2",
    "markdown-it": "^14.2.0",
    "smol-toml": "^1.7.1"
  }
}
