diff --git a/.git-hooks/_shared/push/commit-messages.mts b/.git-hooks/_shared/push/commit-messages.mts new file mode 100644 index 0000000..d34efb5 --- /dev/null +++ b/.git-hooks/_shared/push/commit-messages.mts @@ -0,0 +1,66 @@ +// Pre-push commit-message gate. Scans every commit in the range for AI +// attribution in commit messages — the push-time backstop for commits created +// with `--no-verify` that bypassed the commit-msg hook. +// +// The scanned range is narrowed by the release-tag exemption: the only remedy +// this gate can offer is a reworded commit, which changes the commit's SHA, so +// it has nothing to say about a commit a published tag has already frozen. + +import { getDefaultLogger } from '@socketsecurity/lib-stable/logger/default' +import { debugCheck } from '../check-output.mts' + +import { containsAiAttribution } from '../../../.claude/hooks/fleet/_shared/ai-attribution.mts' +import { git } from '../git.mts' +import { + reportReleaseTagExemption, + resolveRewritableCommits, +} from './release-tags.mts' + +import type { ReleaseTagOptions } from './release-tags.mts' + +const logger = getDefaultLogger() + +// Scans every rewritable commit in the range for AI attribution in commit +// messages. `options.cwd` runs the gate against a repo other than the process +// cwd; the hook leaves it unset. +export function scanCommitMessages( + range: string, + remote: string, + options?: ReleaseTagOptions | undefined, +): number { + const { cwd } = { __proto__: null, ...options } as ReleaseTagOptions + const repo = cwd ? ['-C', cwd] : [] + debugCheck('Checking commit messages for AI attribution…') + const exemption = resolveRewritableCommits(range, remote, { cwd }) + reportReleaseTagExemption(exemption, 'AI-attribution') + let errors = 0 + for (const sha of exemption.scanned) { + if (!sha) { + continue + } + const msg = git(...repo, 'log', '-1', '--format=%B', sha) + if (containsAiAttribution(msg)) { + if (errors === 0) { + logger.fail('AI attribution found in commit messages!') + logger.info('Commits with AI attribution:') + } + const oneline = git(...repo, 'log', '-1', '--oneline', sha) + logger.info(` - ${oneline}`) + errors++ + } + } + if (errors > 0) { + logger.info('') + logger.info( + 'These commits were likely created with --no-verify, bypassing the', + ) + logger.info('commit-msg hook that strips AI attribution.') + logger.info('') + const rangeBase = range.split('..')[0] + logger.info('To fix:') + logger.info(` git rebase -i ${rangeBase}`) + logger.info(" Mark commits as 'reword', remove AI attribution, save") + logger.info(' git push') + } + return errors +} diff --git a/.git-hooks/_shared/push/durable-ref.mts b/.git-hooks/_shared/push/durable-ref.mts new file mode 100644 index 0000000..b5fcd84 --- /dev/null +++ b/.git-hooks/_shared/push/durable-ref.mts @@ -0,0 +1,85 @@ +// A durable-backup ref: pushed to get work OFF THE MACHINE, never to be +// consumed. Nothing builds from it, nothing installs it, no CI runs it. +// +// Why the namespace exists: on a shared checkout local main carries every +// session's commits, so one session's lint debt gates another session's push. +// The work then lives on one disk. That is how an afternoon of commits was lost +// when a checkout was deleted - the commits were real, reviewed, and nowhere +// else. +// +// So the QUALITY bar is scoped to the branches people consume. A backup push +// still runs every SAFETY scan: a leaked secret or an unsigned commit is a fact +// about the bytes, and a backup ref is as public as any other. What it skips is +// lint, format, types, and dispatch drift - because a backup that has to be +// green is a backup you cannot take at the moment you need it most. + +/** + * The namespaces reserved for durable backups. A branch here is understood to + * be UNTESTED: rebase or cherry-pick from it, never merge it as-is. + */ +export const DURABLE_REF_PREFIXES: readonly string[] = [ + 'refs/heads/wip/', + 'refs/heads/worktree/', +] + +/** + * Whether `remoteRef` names a durable backup rather than a consumed branch. + * + * Matched on the FULL remote ref, so a local branch merely named `wip/x` cannot + * opt a push to `main` out of the gates. The trailing slash is required, so a + * branch called `wip-something` does not qualify by prefix accident, and a bare + * `refs/heads/wip` with nothing after it does not either. + */ +export function isDurableBackupRef(remoteRef: string): boolean { + for (let i = 0, { length } = DURABLE_REF_PREFIXES; i < length; i += 1) { + const prefix = DURABLE_REF_PREFIXES[i]! + if (remoteRef.startsWith(prefix) && remoteRef.length > prefix.length) { + return true + } + } + return false +} + +/** + * Whether this push carries ONLY durable-backup refs. + * + * Every ref must qualify. A push that updates a backup ref AND a real branch in + * one invocation is a real push, because the real branch is what people + * consume. + * + * - Reading it as a backup would let any ref smuggle a main update past the + * quality gates. + * + * An empty list is NOT durable. No refs means nothing was proven, and + * defaulting to "skip the gates" on an unreadable stdin is the wrong direction + * to fail. + */ +export function isDurableBackupPush(remoteRefs: readonly string[]): boolean { + if (remoteRefs.length === 0) { + return false + } + for (let i = 0, { length } = remoteRefs; i < length; i += 1) { + if (!isDurableBackupRef(remoteRefs[i]!)) { + return false + } + } + return true +} + +/** + * The branch name to back the current work up to, given a session label. + * + * Slashes and whitespace in the label would create nested refs or an invalid + * name, so everything outside the safe set collapses to a dash. The `wip/` + * prefix is not optional: it is what the gate keys on. + */ +export function durableBackupBranch(label: string): string { + const safe = label + .toLowerCase() + // Anything outside the safe set becomes one dash, so a slash cannot nest a + // ref and whitespace cannot invalidate the name. + .replace(/[^a-z0-9._-]+/g, '-') + // `^-+` and `-+$` - the dashes the collapse above leaves at either edge. + .replace(/^-+|-+$/g, '') + return `wip/${safe || 'session'}` +} diff --git a/.git-hooks/_shared/push/file-scan.mts b/.git-hooks/_shared/push/file-scan.mts new file mode 100644 index 0000000..83a5280 --- /dev/null +++ b/.git-hooks/_shared/push/file-scan.mts @@ -0,0 +1,374 @@ +// Pre-push per-file content gate. Scans every file changed in the range for +// secrets, credentials, personal paths, logger leaks, cross-repo references, +// programmatic-Claude lockdown violations, and AI-config poison fingerprints. + +import { existsSync, statSync } from 'node:fs' + +import path from 'node:path' + +import { spawnSync } from '@socketsecurity/lib-stable/process/spawn/child' + +import { normalizePath } from '@socketsecurity/lib-stable/paths/normalize' + +import { getDefaultLogger } from '@socketsecurity/lib-stable/logger/default' +import { debugCheck } from '../check-output.mts' + +import { readFileForScan, shouldSkipFile } from '../file-scan.mts' +import { gitLines } from '../git.mts' +import { stripTemplateLayer, suppressionFor } from '../scan-core.mts' + +import type { LineHit } from '../scan-core.mts' +import { scanCrossRepoPaths, scanLoggerLeaks } from '../scan-code-refs.mts' +import { + scanAwsKeys, + scanGitHubTokens, + scanPersonalPaths, + scanPrivateKeys, + scanSocketApiKeys, +} from '../scan-secrets.mts' +import { + scanAiConfigPoison, + scanProgrammaticClaudeLockdown, +} from '../scan-supply-chain.mts' + +const logger = getDefaultLogger() + +// A path under a vendored / third-party tree. The three content scans that +// only apply to first-party code share this exemption. +function isVendoredPath(file: string): boolean { + const normalized = normalizePath(file) + return ( + normalized.includes('/external/') || + normalized.includes('/vendor/') || + normalized.includes('/upstream/') + ) +} + +// Filename-shape gates, independent of content: .env files at any depth +// (matching commit-msg.mts and pre-commit.mts), .DS_Store, and stray logs. +// Allow .env.example, .env.test, .env.precommit (templates / tracked +// placeholders); block bare .env / .env.local / .env.production / anything +// else regardless of directory depth. +function scanForbiddenFilenames(changed: string[]): number { + let errors = 0 + const envHits = changed.filter(f => { + const base = path.basename(f) + return ( + /^\.env(?:\.[^/]+)?$/.test(base) && + !/^\.env\.(?:example|precommit|test)$/.test(base) + ) + }) + if (envHits.length > 0) { + logger.fail('Attempting to push .env file!') + logger.info(`Files: ${envHits.join(', ')}`) + errors += envHits.length + } + const dsHits = changed.filter(f => f.includes('.DS_Store')) + if (dsHits.length > 0) { + logger.fail('.DS_Store file in push!') + logger.info(`Files: ${dsHits.join(', ')}`) + errors += dsHits.length + } + const logHits = changed.filter( + f => f.endsWith('.log') && !/test.*\.log$/.test(f), + ) + if (logHits.length > 0) { + logger.fail('Log file in push!') + logger.info(`Files: ${logHits.join(', ')}`) + errors += logHits.length + } + return errors +} + +// Whether a changed path is a real, tracked, scannable file. Skips paths +// removed from git that still exist on disk, directories, and the shared +// skip list. +function isScannableFile(file: string): boolean { + if (!file || !existsSync(file)) { + return false + } + try { + if (statSync(file).isDirectory()) { + return false + } + } catch { + return false + } + if (shouldSkipFile(file)) { + return false + } + // Tracked-only — skip files removed from git that still exist on disk. + const tracked = spawnSync('git', ['ls-files', '--error-unmatch', file]) + return tracked.status === 0 +} + +// The shared report shape for the three credential scans: a headline, then +// up to three offending lines. +function reportSecretLines(headline: string, hits: LineHit[]): number { + if (hits.length === 0) { + return 0 + } + logger.fail(headline) + const top = hits.slice(0, 3) + for (let i = 0, { length } = top; i < length; i += 1) { + const h = top[i]! + logger.info(`${h.lineNumber}:${h.line.trim()}`) + } + return 1 +} + +function reportPersonalPaths(file: string, text: string): number { + const pathHits = scanPersonalPaths(text) + if (pathHits.length === 0) { + return 0 + } + logger.fail(`Hardcoded personal path found in: ${file}`) + const top = pathHits.slice(0, 3) + for (let i = 0, { length } = top; i < length; i += 1) { + const h = top[i]! + logger.info(`${h.lineNumber}: ${h.line.trim()}`) + if (h.suggested && h.suggested !== h.line) { + logger.info(` fix: ${h.suggested.trim()}`) + } + } + logger.info( + 'Replace with the canonical placeholder for the path platform: ' + + '`/Users//...` (macOS), `/home//...` (Linux), or ' + + '`C:\\Users\\\\...` (Windows). Env vars also work ' + + '(`$HOME`, `${USER}`). For documentation lines that need the ' + + 'literal form, put the marker ' + + `\`${suppressionFor(file, 'personal-path')}\` on its own line above it.`, + ) + return 1 +} + +// Conformance test vectors (`conformance/{vectors,cases,fixtures}/…`) hold +// deterministic golden crypto data — a `-----BEGIN … PRIVATE KEY-----` block +// there is a checked-in test vector for a crypto lib's decrypt conformance +// (e.g. envrypt), never a live secret. Exempt only these test-data dirs. +function reportPrivateKeys(file: string, text: string): number { + const isConformanceVector = + /(?:^|\/)conformance\/(?:cases|fixtures|vectors)\//.test( + normalizePath(file), + ) + const pkHits = isConformanceVector ? [] : scanPrivateKeys(text) + if (pkHits.length === 0) { + return 0 + } + logger.fail(`Private key found in: ${file}`) + return 1 +} + +// The logger-leak scan covers first-party TypeScript only. The guard infra +// (.claude/hooks/, .git-hooks/, scripts/) and the dep-0 bootstrap run before +// any dependency exists, so they call console.* directly. template/ holds the +// canonical sources that cascade to those same trees in downstream fleet +// repos, so the destination exemption has to apply at the source too; +// `layerless` collapses the archetype layer segment so template/base/universal/... stays +// exempt. src/logger/ IS the logger. +function isLoggerScanTarget(file: string, layerless: string): boolean { + return ( + !file.startsWith('.claude/hooks/') && + !file.startsWith('.git-hooks/') && + !file.startsWith('scripts/') && + !file.startsWith('bootstrap/') && + !layerless.startsWith('template/.claude/hooks/') && + !layerless.startsWith('template/.git-hooks/') && + !layerless.startsWith('template/scripts/') && + !isVendoredPath(file) && + !file.startsWith('src/logger/') && + // Matches TypeScript source extensions: .mts, .ts, .tsx, .cts — the only file types that can log. + /\.(?:cts|m?ts|tsx)$/.test(file) + ) +} + +function reportLoggerLeaks(file: string, text: string): number { + const loggerHits = scanLoggerLeaks(text) + if (loggerHits.length === 0) { + return 0 + } + logger.fail(`direct stream write found in: ${file}`) + const top = loggerHits.slice(0, 3) + for (let j = 0, { length: jlen } = top; j < jlen; j += 1) { + const h = top[j]! + logger.info(`${h.lineNumber}: ${h.line.trim()}`) + if (h.suggested && h.suggested !== h.line) { + logger.info(` fix: ${h.suggested.trim()}`) + } + } + logger.info( + 'Use `getDefaultLogger()` from `@socketsecurity/lib-stable/logger/default`. ' + + 'For a deliberate raw write, put the marker on its own line above ' + + 'the call: `// oxlint-disable-next-line socket/no-console-prefer-logger` for `console.*`, or ' + + '`// oxlint-disable-next-line socket/no-direct-stream-write` for `process.std{out,err}.write` ' + + '(the id must match the call kind — that is what `scanLoggerLeaks` keys on). ' + + 'no-malformed-bypass-marker rejects the trailing form.', + ) + return 1 +} + +// Markdown is exempt from the cross-repo rule: docs legitimately show +// cross-repo command examples (e.g. `node scripts/foo.mts --target +// ../socket-lib`) and re-emitting them with `@socketsecurity/lib-stable/…` +// would break the example's runnability. The codepath rule still applies to +// actual source files. +function isCrossRepoScanTarget(file: string): boolean { + return ( + !file.startsWith('.git-hooks/') && + !file.startsWith('.claude/hooks/') && + !file.endsWith('.md') && + !isVendoredPath(file) && + file !== 'pnpm-lock.yaml' && + file !== 'pnpm-workspace.yaml' + ) +} + +// Cross-repo path references — both relative (`..//…`) and +// absolute (`…/projects//…`) forms. +function reportCrossRepoPaths(file: string, text: string): number { + const crossRepoHits = scanCrossRepoPaths(text, path.resolve(file)) + if (crossRepoHits.length === 0) { + return 0 + } + logger.fail(`cross-repo path reference in: ${file}`) + const top = crossRepoHits.slice(0, 3) + for (let i = 0, { length } = top; i < length; i += 1) { + const h = top[i]! + logger.info(`${h.lineNumber}: ${h.line.trim()}`) + } + logger.info( + 'Cross-repo paths are forbidden — import via the published npm ' + + 'package (`@socketsecurity/lib-stable/`) instead. For doc ' + + `lines, append \`${suppressionFor(file, 'cross-repo')}\`.`, + ) + return 1 +} + +// Only application / script .mts that DRIVE Claude via the SDK. The guard +// infra itself (.claude/hooks/, .git-hooks/, and their template/ sources) +// legitimately names query()/permissionMode/bypassPermissions as patterns it +// detects, so it is exempt (same exemption family as the logger / cross-repo +// scans). +function isClaudeLockdownScanTarget(file: string, layerless: string): boolean { + return ( + /\.(?:cts|m?ts)$/.test(file) && + !file.startsWith('.claude/hooks/') && + !file.startsWith('.git-hooks/') && + !layerless.startsWith('template/.claude/hooks/') && + !layerless.startsWith('template/.git-hooks/') && + !isVendoredPath(file) + ) +} + +// Programmatic-Claude lockdown (HARD block). +function reportClaudeLockdown(file: string, text: string): number { + const lockdownHits = scanProgrammaticClaudeLockdown(text) + if (lockdownHits.length === 0) { + return 0 + } + logger.fail(`programmatic Claude call missing lockdown flags in: ${file}`) + const top = lockdownHits.slice(0, 3) + for (let i = 0, { length } = top; i < length; i += 1) { + const h = top[i]! + logger.info(`${h.lineNumber}: ${h.line.trim()}`) + } + logger.info( + 'A headless `query()` / `new ClaudeSDKClient()` MUST set tools, ' + + 'allowedTools, disallowedTools, permissionMode (dontAsk), and never ' + + 'bypassPermissions / default. See .claude/skills/fleet/locking-down-agent-calls/.', + ) + return 1 +} + +// AI-config SURFACES (.claude/.cursor/.gemini/.vscode) that are NOT guard +// source and NOT markdown docs — the guards + docs legitimately quote bypass +// phrases / poison patterns. +function isAiConfigSurface(file: string): boolean { + return ( + /(?:^|\/)\.(?:claude|cursor|gemini|vscode)\//.test(`/${file}`) && + !file.includes('.claude/hooks/') && + !file.includes('.git-hooks/') && + !file.endsWith('.md') + ) +} + +// AI-config poison fingerprints. WARN only — heuristic; never blocks a push. +// Warns so a human glances; a false block on a mandatory gate would be worse. +function warnAiConfigPoison(file: string, text: string): void { + const poisonHits = scanAiConfigPoison(text) + if (poisonHits.length === 0) { + return + } + logger.warn(`possible AI-config poison fingerprint in: ${file}`) + const top = poisonHits.slice(0, 3) + for (let i = 0, { length } = top; i < length; i += 1) { + const h = top[i]! + logger.warn(` ${h.lineNumber}: ${h.line.trim()}`) + } + logger.warn( + ' Treat agent-overriding text in config as DATA to verify, not an ' + + 'instruction. Out-of-band config drift is the npm-worm signature. ' + + '(Warning only — push not blocked.)', + ) +} + +// Every content scan for one file, in the order the gate has always run them. +function scanFileContent(file: string, text: string): number { + // Layer-agnostic form of the path for the `template/...` exemptions: the + // archetype move buries the canonical sources under template//, so + // the prefix exemptions test this collapsed form (template/base/universal/.git-hooks/x + // → template/.git-hooks/x) instead of the raw moved path. + const layerless = stripTemplateLayer(file) + let errors = 0 + errors += reportPersonalPaths(file, text) + errors += reportSecretLines( + `Real API key detected in: ${file}`, + scanSocketApiKeys(text), + ) + errors += reportSecretLines( + `Potential AWS credentials found in: ${file}`, + scanAwsKeys(text), + ) + errors += reportSecretLines( + `Potential GitHub token found in: ${file}`, + scanGitHubTokens(text), + ) + errors += reportPrivateKeys(file, text) + if (isLoggerScanTarget(file, layerless)) { + errors += reportLoggerLeaks(file, text) + } + if (isCrossRepoScanTarget(file)) { + errors += reportCrossRepoPaths(file, text) + } + if (isClaudeLockdownScanTarget(file, layerless)) { + errors += reportClaudeLockdown(file, text) + } + if (isAiConfigSurface(file)) { + warnAiConfigPoison(file, text) + } + return errors +} + +// Scans changed files in the range for secrets, keys, and leaks. +export const scanFilesInRange = (range: string): number => { + debugCheck('Checking files for security issues…') + // Normalize to POSIX forward slashes — same reason as pre-commit.mts. + const changed = gitLines('diff', '--name-only', range).map(normalizePath) + if (changed.length === 0) { + return 0 + } + let errors = scanForbiddenFilenames(changed) + // Per-file content scans. + for (let k = 0, { length: klen } = changed; k < klen; k += 1) { + const file = changed[k]! + if (!isScannableFile(file)) { + continue + } + const text = readFileForScan(file) + if (!text) { + continue + } + errors += scanFileContent(file, text) + } + return errors +} diff --git a/.git-hooks/_shared/push/pr-commit-count.mts b/.git-hooks/_shared/push/pr-commit-count.mts new file mode 100644 index 0000000..f01d06a --- /dev/null +++ b/.git-hooks/_shared/push/pr-commit-count.mts @@ -0,0 +1,65 @@ +import { spawnSync } from '@socketsecurity/lib-stable/process/spawn/child' + +interface OpenPr { + baseRefName?: string | undefined + headRefName?: string | undefined +} + +export function checkPrCommitCount( + remote: string, + localSha: string, + remoteRef: string, +): string | undefined { + if (!remoteRef.startsWith('refs/heads/') || /^0+$/u.test(localSha)) { + return undefined + } + const branch = remoteRef.slice('refs/heads/'.length) + const listed = spawnSync( + 'gh', + [ + 'pr', + 'list', + '--state', + 'open', + '--head', + branch, + '--json', + 'baseRefName,headRefName', + '--limit', + '2', + ], + { encoding: 'utf8', timeout: 5000 }, + ) + if (listed.status !== 0) { + return undefined + } + let prs: OpenPr[] + try { + const parsed: unknown = JSON.parse(String(listed.stdout)) + if (!Array.isArray(parsed)) { + return undefined + } + prs = parsed as OpenPr[] + } catch { + return undefined + } + for (let i = 0, { length } = prs; i < length; i += 1) { + const pr = prs[i]! + if (pr.headRefName !== branch || !pr.baseRefName) { + continue + } + const counted = spawnSync( + 'git', + ['rev-list', '--count', `${remote}/${pr.baseRefName}..${localSha}`], + { encoding: 'utf8', timeout: 5000 }, + ) + const commits = Number(String(counted.stdout ?? '').trim()) + if (counted.status !== 0 || !Number.isSafeInteger(commits)) { + return `PR branch ${branch}: cannot count commits above ${pr.baseRefName}; fetch ${remote} and retry.` + } + if (commits !== 1) { + return `PR branch ${branch}: expected one commit above ${pr.baseRefName}, found ${commits}; squash onto the PR base before pushing.` + } + } + return undefined +} diff --git a/.git-hooks/_shared/push/range.mts b/.git-hooks/_shared/push/range.mts new file mode 100644 index 0000000..9a4aab2 --- /dev/null +++ b/.git-hooks/_shared/push/range.mts @@ -0,0 +1,97 @@ +// Pre-push commit-range computation. Resolves the `..` range the +// security gates scan for a given push line, handling new branches, force-pushes, +// and default-branch fallback. Returns undefined for skip cases (tags, +// deletions, no baseline). + +import { spawnSync } from '@socketsecurity/lib-stable/process/spawn/child' + +import { getDefaultLogger } from '@socketsecurity/lib-stable/logger/default' +import { debugCheck } from '../check-output.mts' + +import { git } from '../git.mts' + +const logger = getDefaultLogger() + +export const ZERO_SHA = '0000000000000000000000000000000000000000' + +// Computes the commit range to scan. Returns null if no scan needed +// (skip case — tag, delete, or no baseline). +export const computeRange = ( + remote: string, + localRef: string, + localSha: string, + remoteSha: string, +): string | undefined => { + if (localRef.startsWith('refs/tags/')) { + debugCheck(`Skipping tag push: ${localRef}`) + return undefined + } + if (localSha === ZERO_SHA) { + return undefined + } + + const refExists = (ref: string): boolean => { + const r = spawnSync('git', ['rev-parse', ref]) + return r.status === 0 + } + + const defaultBranchOf = (remoteName: string): string => { + const sym = git('symbolic-ref', `refs/remotes/${remoteName}/HEAD`).trim() + if (sym) { + return sym.replace(`refs/remotes/${remoteName}/`, '') + } + // symbolic-ref unset (rare — happens with shallow clones, partial + // fetches, freshly-init'd remotes). Try main → master → 'main' + // per CLAUDE.md default-branch resolution. Reversing the order + // would mispick during rename migrations. + if (refExists(`${remoteName}/main`)) { + return 'main' + } + if (refExists(`${remoteName}/master`)) { + return 'master' + } + return 'main' + } + + // git cat-file -e exits 0 silently on success; spawnSync directly + // so we can inspect status without printing. + const remoteShaExists = (sha: string): boolean => { + const result = spawnSync('git', ['cat-file', '-e', sha]) + return result.status === 0 + } + + if (remoteSha === ZERO_SHA) { + // New branch — compare against remote default branch. + const def = defaultBranchOf(remote) + const baseRef = `${remote}/${def}` + if (!refExists(baseRef)) { + logger.warn('Skipping validation (no baseline to compare against)') + return undefined + } + return `${baseRef}..${localSha}` + } + + const isAncestor = (ancestor: string, descendant: string): boolean => + spawnSync('git', ['merge-base', '--is-ancestor', ancestor, descendant]) + .status === 0 + + // Existing branch. + if (!remoteShaExists(remoteSha) || !isAncestor(remoteSha, localSha)) { + // Force-push, history rewrite, or dangling object that is not an + // ancestor of the local tip — fall back to remote default branch. + // + // This base is wider than "new work": a history repair that reattaches an + // orphaned release tag puts already-published commits back in front of it. + // Gates whose only remedy is a rewrite subtract those via + // `resolveRewritableCommits` in ./release-tags.mts rather than + // demanding a rewrite that would re-orphan the tag. + const def = defaultBranchOf(remote) + const baseRef = `${remote}/${def}` + if (!refExists(baseRef)) { + logger.warn('Skipping validation (no baseline for force-push)') + return undefined + } + return `${baseRef}..${localSha}` + } + return `${remoteSha}..${localSha}` +} diff --git a/.git-hooks/_shared/push/release-tags.mts b/.git-hooks/_shared/push/release-tags.mts new file mode 100644 index 0000000..076b078 --- /dev/null +++ b/.git-hooks/_shared/push/release-tags.mts @@ -0,0 +1,253 @@ +// Release-tag exemption for the pre-push range scans. +// +// A commit reachable from a published release tag is immutable. The only way to +// change its message is to rewrite it, which changes its SHA, which changes +// every descendant SHA — orphaning the tag that points at it. A gate whose sole +// remedy is a rewrite cannot be satisfied for such a commit, so this module +// narrows a pushed range down to the commits that are still rewritable. +// +// The exemption is deliberately narrow: +// - ONLY commits reachable from a release tag qualify. "Already on a remote +// branch" is not a reason to skip — a branch can still be force-updated, so +// its commits stay rewritable and stay scanned. +// - Only a tag whose own commit is inside the pushed range counts. A tag +// behind the range base already has its ancestors excluded by the base. +// - The tag must be present on the push remote AND resolve to the same commit +// there. A local-only tag, or a local tag re-pointed at a different commit, +// exempts nothing. +// - When the remote cannot be read, nothing is exempt (fail closed) and the +// unverified tags are named in the notice. + +import { joinAnd } from '@socketsecurity/lib-stable/arrays/join' + +import { debugCheck } from '../check-output.mts' + +import { git, gitLines } from '../git.mts' + +// How many exempt commits the notice names before it summarizes the rest. +const EXEMPT_SAMPLE_LIMIT = 5 + +// Fleet release tags are semver with an OPTIONAL `v` prefix: socket-mcp carries +// both `0.0.10` and `v0.0.9`, socket-lib and socket-sdk-js are `v`-prefixed, +// socket-cli has both. Reading the repo's own `git tag --list` and keeping the +// semver-shaped names covers every convention without hard-coding one repo's +// prefix. Names that are not semver-shaped (`backup/…`, +// `socket-lib-prebump-backup`, `base-assets-node-smol-20260418-50af4c8`) are +// working tags, not published releases, and grant no exemption. +export const RELEASE_TAG_RE = + /^v?(?:0|[1-9]\d*)\.(?:0|[1-9]\d*)\.(?:0|[1-9]\d*)(?:[-+][0-9A-Za-z.+-]+)?$/ + +// One exempt commit. `oneline` is populated for the sampled head of the list +// and is an empty string for the remainder, so the notice stays cheap on a +// range that republishes a long tagged history. +export interface ExemptCommit { + oneline: string + sha: string +} + +// The split of a pushed range into what a rewrite-remedy gate may act on +// (`scanned`) and what a published tag has frozen (`exempt`). `tags` names the +// published release tags responsible for the skip; `unverifiedTags` names +// release tags inside the range whose publication could NOT be confirmed on the +// remote — those grant no exemption and their commits stay in `scanned`. +export interface ReleaseTagExemption { + exempt: ExemptCommit[] + scanned: string[] + tags: string[] + unverifiedTags: string[] +} + +export interface ReleaseTagOptions { + cwd?: string | undefined +} + +// `git -C ` prefix so the resolver can run against a repo other than the +// process cwd (the hook uses the cwd; tests point at a fixture). +function repoArgs(cwd: string | undefined): string[] { + return cwd ? ['-C', cwd] : [] +} + +export function isReleaseTagName(name: string): boolean { + return RELEASE_TAG_RE.test(name) +} + +// Every local release tag mapped to the COMMIT it names. Annotated tags resolve +// through the peeled `*objectname`; lightweight tags use `objectname`. +export function listLocalReleaseTagCommits( + options?: ReleaseTagOptions | undefined, +): Map { + const { cwd } = { __proto__: null, ...options } as ReleaseTagOptions + const lines = gitLines( + ...repoArgs(cwd), + 'for-each-ref', + '--format=%(refname:short) %(objectname) %(*objectname)', + 'refs/tags', + ) + const found = new Map() + for (const line of lines) { + const { 0: name, 1: objectName, 2: peeled } = line.trim().split(/\s+/) + if (!name || !isReleaseTagName(name)) { + continue + } + const commit = peeled || objectName + if (commit) { + found.set(name, commit) + } + } + return found +} + +// Every release tag the push remote already carries, mapped to the commit it +// names there. Best effort: `git` yields an empty string when the remote is +// unreachable, which leaves the map empty so nothing is exempted. +export function listPublishedReleaseTagCommits( + remote: string, + options?: ReleaseTagOptions | undefined, +): Map { + const { cwd } = { __proto__: null, ...options } as ReleaseTagOptions + const found = new Map() + const raw = git(...repoArgs(cwd), 'ls-remote', '--tags', remote) + if (!raw) { + return found + } + const rawLines = raw.split(/\r?\n/) + for (let i = 0, { length } = rawLines; i < length; i += 1) { + const { 0: sha, 1: ref } = rawLines[i]!.trim().split(/\s+/) + if (!sha || !ref) { + continue + } + // An annotated tag emits two lines. `refs/tags/` names the tag + // object, and `refs/tags/^{}` names the commit that tag peels to. + // Note: the peeled line wins whenever both are present. + const isPeeled = ref.endsWith('^{}') + const name = ref.replace(/^refs\/tags\//, '').replace(/\^\{\}$/, '') + if (!isReleaseTagName(name)) { + continue + } + if (isPeeled || !found.has(name)) { + found.set(name, sha) + } + } + return found +} + +// Splits `range` into the commits a rewrite-remedy gate may still act on and +// the commits a published release tag has frozen. A repo with no release tags +// in the range returns every commit in `scanned`, which is the unnarrowed +// behavior. +export function resolveRewritableCommits( + range: string, + remote: string, + options?: ReleaseTagOptions | undefined, +): ReleaseTagExemption { + const { cwd } = { __proto__: null, ...options } as ReleaseTagOptions + const repo = repoArgs(cwd) + const inRange = gitLines(...repo, 'rev-list', range).filter(Boolean) + const unnarrowed: ReleaseTagExemption = { + exempt: [], + scanned: inRange, + tags: [], + unverifiedTags: [], + } + if (inRange.length === 0) { + return unnarrowed + } + const localTags = listLocalReleaseTagCommits({ cwd }) + if (localTags.size === 0) { + return unnarrowed + } + const inRangeShas = new Set(inRange) + const candidates = [...localTags].filter(([, sha]) => inRangeShas.has(sha)) + if (candidates.length === 0) { + return unnarrowed + } + const publishedTags = listPublishedReleaseTagCommits(remote, { cwd }) + const published: string[] = [] + const unverifiedTags: string[] = [] + for (const [name, sha] of candidates) { + if (publishedTags.get(name) === sha) { + published.push(name) + } else { + unverifiedTags.push(name) + } + } + if (published.length === 0) { + return { ...unnarrowed, unverifiedTags } + } + // Spell the exclusions as full refs so a tag named like a branch cannot + // resolve to the wrong object. + const kept = new Set( + gitLines( + ...repo, + 'rev-list', + range, + '--not', + ...published.map(name => `refs/tags/${name}`), + ), + ) + const scanned: string[] = [] + const exempt: ExemptCommit[] = [] + for (let i = 0, { length } = inRange; i < length; i += 1) { + const sha = inRange[i]! + if (kept.has(sha)) { + scanned.push(sha) + } else { + exempt.push({ + oneline: + exempt.length < EXEMPT_SAMPLE_LIMIT + ? git(...repo, 'log', '-1', '--oneline', sha) + : '', + sha, + }) + } + } + return { exempt, scanned, tags: published, unverifiedTags } +} + +// Notice lines for an exemption. Pure — the caller logs them. Returns an empty +// array when there is nothing to disclose, so a repo with no release tags emits +// no extra output at all. +export function formatReleaseTagExemption( + exemption: ReleaseTagExemption, + scanLabel: string, +): string[] { + const { exempt, tags, unverifiedTags } = exemption + const lines: string[] = [] + if (exempt.length > 0) { + lines.push( + `Skipping ${exempt.length} commit(s) in this range for the ${scanLabel} check:`, + ) + const oneTag = tags.length === 1 + lines.push( + ` release ${oneTag ? 'tag' : 'tags'} ${joinAnd(tags)} already ${oneTag ? 'publishes' : 'publish'} them.`, + ) + lines.push( + ' A published tag pins these SHAs — rewriting one orphans the tag, so', + ) + lines.push(' this check has no remedy to offer for them.') + const sample = exempt.slice(0, EXEMPT_SAMPLE_LIMIT) + for (let i = 0, { length } = sample; i < length; i += 1) { + const commit = sample[i]! + lines.push(` - ${commit.oneline || commit.sha}`) + } + if (exempt.length > EXEMPT_SAMPLE_LIMIT) { + lines.push(` ... and ${exempt.length - EXEMPT_SAMPLE_LIMIT} more`) + } + } + if (unverifiedTags.length > 0) { + lines.push( + `Release ${unverifiedTags.length === 1 ? 'tag' : 'tags'} ${joinAnd(unverifiedTags)} could not be confirmed on the push remote — scanning those commits.`, + ) + } + return lines +} + +export function reportReleaseTagExemption( + exemption: ReleaseTagExemption, + scanLabel: string, +): void { + const lines = formatReleaseTagExemption(exemption, scanLabel) + for (let i = 0, { length } = lines; i < length; i += 1) { + debugCheck(lines[i]!) + } +} diff --git a/.git-hooks/_shared/push/repo-gates.mts b/.git-hooks/_shared/push/repo-gates.mts new file mode 100644 index 0000000..54dce73 --- /dev/null +++ b/.git-hooks/_shared/push/repo-gates.mts @@ -0,0 +1,548 @@ +import { + sharedFleetTsconfigCheckJsonPath, + sharedTypescriptBinTscPath, +} from '../../../scripts/fleet/paths/util.mts' +// Pre-push repo-level gates that run against the working-tree state (not a +// commit range): submodule pristine-ness, soak-bypass date annotations, the +// fast lint/format gate, and the wheelhouse-only hook-dispatch-table drift check. + +import { existsSync, readFileSync, statSync } from 'node:fs' + +import path from 'node:path' + +import process from 'node:process' + +import { spawnSync } from '@socketsecurity/lib-stable/process/spawn/child' + +import { normalizePath } from '@socketsecurity/lib-stable/paths/normalize' + +import { getDefaultLogger } from '@socketsecurity/lib-stable/logger/default' + +import { gitLines } from '../git.mts' +import { + debugCheck, + showCheckOutput, + showCheckResult, +} from '../check-output.mts' +import { + dirtyEntry, + readTypecheckVerdict, + typecheckCacheKey, + waitForTypecheckTurn, + writeTypecheckVerdict, +} from '../typecheck-cache.mts' + +// The repo-wide fixer lock, the same one lint.mts and fix.mts take. Sharing +// it is deliberate: a push's typecheck should also serialize against a +// running `pnpm run fix`, since both read the whole working tree. +import { + acquireFixerLock, + fixerLockPath, +} from '../../../scripts/fleet/process/fixer-lock.mts' +// One owner for the path, per `paths-are-constructed-once`: a cascaded file is +// tracked twice (source + live mirror), so a literal spelled here counts as +// two construction sites on its own. +import { HEAVY_JOB_BUSY_EXIT_CODE } from '../../../scripts/fleet/process/heavy-job/admission.mts' +import { + FLEET_TYPE_SCRIPT, + TYPECHECK_CACHE_DIR, +} from '../../../scripts/fleet/paths.mts' + +import type { TypecheckVerdict } from '../typecheck-cache.mts' +import { scanSoakExcludeDateAnnotations } from '../scan-supply-chain.mts' + +const logger = getDefaultLogger() + +// Submodule pristine check — refuses push if any submodule has a +// drifted commit pointer or unresolved merge conflict. +export const checkSubmodules = (): number => { + if (!existsSync('.gitmodules')) { + return 0 + } + debugCheck('Checking submodules are pristine…') + let errors = 0 + const status = gitLines('submodule', 'status') + for (const line of status) { + if (!line) { + continue + } + const prefix = line[0] + const rest = line.slice(1).trim().split(/\s+/) + const smPath = rest[1] || '' + if (prefix === '+') { + logger.fail(`Submodule has wrong commit: ${smPath}`) + logger.info(` Run: git submodule update --init ${smPath}`) + errors++ + } else if (prefix === 'U') { + logger.fail(`Submodule has merge conflict: ${smPath}`) + errors++ + } + // '-' (uninitialized) is OK — CI shallow clones skip submodules. + } + if (errors > 0) { + logger.error('') + logger.fail(`Push blocked: ${errors} submodule(s) not pristine!`) + logger.error('Fix submodules before pushing.') + return errors + } + debugCheck('All submodules pristine') + return 0 +} + +// Soak-exclude date annotations (HARD block). pnpm-workspace.yaml exact-pin +// soak-bypass entries must carry the `# published: … | removable: …` line. The +// edit-time guard + the soak-excludes-have-dates check cover Claude edits + CI; +// this is the push-time tier for entries that arrived via non-Claude paths. +// File-targeted, not per-commit — the working-tree state is what ships. +export const scanSoakAnnotations = (): number => { + const file = 'pnpm-workspace.yaml' + if (!existsSync(file)) { + return 0 + } + let text: string + try { + text = readFileSync(file, 'utf8') + } catch { + return 0 + } + const hits = scanSoakExcludeDateAnnotations(text) + if (hits.length === 0) { + return 0 + } + logger.fail( + `${hits.length} soak-bypass entr${hits.length === 1 ? 'y' : 'ies'} in pnpm-workspace.yaml missing the date annotation:`, + ) + const hs = hits.slice(0, 5) + for (let i = 0, { length } = hs; i < length; i += 1) { + const h = hs[i]! + logger.info(` ${h.lineNumber}: ${h.line.trim()}`) + } + logger.info( + ' Add the line above each exact-pin: ' + + '`# published: YYYY-MM-DD | removable: YYYY-MM-DD` ' + + '(removable = published + 7d). The 7-day soak is malware protection.', + ) + return hits.length +} + +// Fast lint/format gate: catches lint/format drift before push, not just in +// CI ("green locally, red in CI" traces to nothing running lint at the push +// boundary). The FAST, build-INDEPENDENT slice: oxfmt --check + oxlint, never +// the full `check --all` (needs a built dist/, too slow for every push). +// +// MUST invoke the lint script DIRECTLY (`node …`), NOT via +// `pnpm run lint`: the `pnpm run` path triggers pnpm's deps-status check, +// which in a non-TTY context (CI, a linked worktree) tries to purge/reinstall +// node_modules and aborts (`ERR_PNPM_ABORTED_REMOVE_MODULES_DIR_NO_TTY`), a +// false push-block unrelated to lint. +// +// SCOPE: the pushed COMMITS via `--range=`, NEVER the working tree, which on a +// shared checkout also holds a parallel session's files. Empty `ranges` falls +// back to `--all`. See docs/fleet/agents.md/push-policy.md. +// +// Degrades to a skip (not a block) when there's no lint script, the script +// isn't a `node ` invocation, or there's no oxlint config. Bypass: +// `git push --no-verify`, `HUSKY=0`, or a redirected `core.hooksPath`, all +// phrase-gated for Claude by no-revert-guard. Returns 1 on lint failure, 0 on +// pass/skip. +export const scanFastChecks = (ranges: readonly string[] = []): number => { + if (!existsSync('package.json')) { + return 0 + } + // Skip when the checkout lives under a path segment the formatter ignores + // (e.g. a linked git worktree under `.claude/worktrees/...`): the lint + // runner's `oxfmt .` resolves `.` to the abs worktree path, whose `.claude/` + // ancestor matches the `**/.claude/**` ignore in .prettierignore, so EVERY + // file is excluded → "Expected at least one target file" → a false block. + // Such a worktree is a staging area for a push to main; CI re-lints from a + // clean checkout, so skipping here loses nothing. + let toplevel = '' + try { + toplevel = normalizePath(gitLines('rev-parse', '--show-toplevel')[0] ?? '') + } catch { + // bare repo / detached context — proceed, no skip. + } + // Matches `.claude` as a complete path segment anywhere in `toplevel`, start, middle, or end. + if (/(?:^|\/)\.claude(?:\/|$)/.test(toplevel)) { + logger.warn( + 'Fast lint/format check skipped — checkout is under an ignored path (.claude/); CI re-lints from a clean tree.', + ) + return 0 + } + let pkg: { scripts?: Record | undefined } + try { + pkg = JSON.parse(readFileSync('package.json', 'utf8')) as typeof pkg + } catch { + return 0 + } + const lintScript = pkg.scripts?.['lint'] + // No `lint` script → this repo doesn't lint; nothing to gate. + if (!lintScript) { + return 0 + } + // Extract the local node-script path from a `node [args]` lint script + // (the fleet shape is `node scripts/fleet/lint.mts`). A non-node lint script + // can't be run directly here — skip rather than risk a pnpm reinstall. + const m = /^node\s+(\S+\.[cm]?[jt]s)\b/.exec(lintScript.trim()) + if (!m || !existsSync(m[1]!)) { + return 0 + } + const scopeArgs = + ranges.length > 0 ? ranges.map(range => `--range=${range}`) : ['--all'] + debugCheck( + ranges.length > 0 + ? `Running fast lint/format check on the pushed range (${ranges.join(', ')})…` + : 'Running fast lint/format check on the whole tree (no pushed range to scope by)…', + ) + // `CI=true`: lint.mts shells out to `pnpm exec oxfmt/oxlint`, and pnpm's + // deps-status check aborts in a non-TTY context (a linked git worktree, a + // headless run) trying to purge node_modules + // (ERR_PNPM_ABORTED_REMOVE_MODULES_DIR_NO_TTY). Setting CI makes pnpm + // non-interactive — it skips the purge prompt and proceeds — so the gate + // runs the same everywhere (local TTY, worktree, CI) instead of false- + // blocking a worktree push. + const r = spawnSync(process.execPath, [m[1]!, ...scopeArgs], { + env: { ...process.env, CI: 'true' }, + maxBuffer: Infinity, + stdioString: true, + }) + showCheckResult(r) + if (r.status !== 0) { + logger.fail( + 'Fast lint/format check failed — fix lint/format before pushing.', + ) + logger.info( + ' Run `pnpm run fix` to autofix, then re-push. Bypass once with ' + + '`git push --no-verify` (records the skip).', + ) + return 1 + } + return 0 +} + +// The canonical fleet type gate — the same whole-project check the `type` npm +// script and CI run. +const TYPE_CHECK_TSCONFIG = sharedFleetTsconfigCheckJsonPath('.config') +const TSC_BIN = sharedTypescriptBinTscPath('node_modules') + +// Regenerate the hook dispatch table so the whole-project type gate can resolve +// the generated `_shared` modules (`dispatch-table.generated.mts` + variants), which are +// gitignored and absent in a fresh checkout. The write lands on gitignored +// paths, so it never dirties the tracked tree, and this runs AFTER +// scanDispatchDrift in the push sequence so a fresh regen here cannot mask a +// stale on-disk table. Best-effort: on a checkout without the generator (a +// non-wheelhouse member) it is a no-op, and if the regen fails tsc reds loudly +// on the missing module — the type gate is never silently a no-op. +const ensureDispatchTables = (): void => { + const gen = path.join('scripts', 'fleet', 'gen', 'hook-dispatch.mts') + if (!existsSync(gen)) { + return + } + spawnSync(process.execPath, [gen], { stdio: 'ignore' }) +} + +// Fast TYPE gate — the type-check sibling of scanFastChecks. A type error is the +// OTHER class of breakage that reaches origin/main behind CI alone: oxlint and +// oxfmt run per-edit, but a type error only surfaces against the whole project, +// so a push carrying a bad type slipped straight to origin. Runs the canonical +// `tsc --noEmit -p .config/fleet/tsconfig.check.json` at the push boundary. A +// BACKSTOP: this hook is bypassed routinely, so CI's check job runs it too. +// +// Unlike scanFastChecks it does NOT skip under a `.claude/` worktree path. That +// skip exists only because the lint runner's `oxfmt .` resolves `.` to a path +// whose `.claude/` ancestor is ignored, excluding every file; tsc runs against +// an explicit project (`-p `), so the `.`-resolution problem does not +// apply and a worktree push must NOT escape the type gate. +// +// Fails CLOSED: a checkout carrying the fleet tsconfig but no compiler cannot +// verify the push, so it is blocked, not skipped. A repo without the fleet +// tsconfig, a non-fleet member, has nothing to check here → skip. Returns 1 on a +// type error, or an unverifiable checkout, 0 on pass/skip. +// A tsc diagnostic line: `path/to/file.mts(12,7): error TS1234: message`. +const TS_ERROR_LINE_RE = /^(.+?)\((\d+),(\d+)\): error TS\d+:/mu + +/** + * The distinct files tsc reported errors in, repo-relative and `/`-normalized. + * Pure — exported for tests. + */ +export function parseTypeErrorFiles(output: string): string[] { + const seen = new Set() + const lines = output.split(/\r?\n/) + for (let i = 0, { length } = lines; i < length; i += 1) { + const match = TS_ERROR_LINE_RE.exec(lines[i]!) + if (match?.[1]) { + seen.add(normalizePath(match[1].trim())) + } + } + return [...seen].toSorted() +} + +/** + * Split reported error files into the ones this push is answerable for and the + * ones it is not. + * + * A DIRTY file's bytes are not in the push. An error located only in such a + * file cannot exist at origin once the push lands, so blocking on it is wrong — + * and in a shared checkout it is worse than wrong: a co-session's half-finished + * edit blocks every unrelated push in the repo until they happen to finish. + * Measured here, twice in one session: an untracked module's importer, then an + * unused type in a file another session was mid-edit on. + * + * Everything else blocks. An error in a CLEAN file is committed state that CI + * will see, and an error in a dirty file this push also touches is the author's + * own. The conservative direction is deliberate: a diagnostic located in a + * clean file but caused by a dirty one still blocks, because the location is + * all tsc reports and a false block costs a re-push while a false pass reaches + * origin. + * + * Pure over the three sets, so the rule is testable without a git tree. + */ +export function splitTypeErrorBlame( + errorFiles: readonly string[], + dirtyFiles: ReadonlySet, + pushedFiles: ReadonlySet, +): { blocking: string[]; foreign: string[] } { + // An EMPTY pushed set means the gate could not read what this push carries (a + // new branch, a detached range, a git that would not answer) — not that the + // push carries nothing. Attributing against it would call every dirty file + // foreign and wave the whole push through, which is backwards: unknown has to + // block, or the permissive path is exactly the one that fires when the gate + // is least sure. + if (pushedFiles.size === 0) { + return { blocking: [...errorFiles], foreign: [] } + } + const blocking: string[] = [] + const foreign: string[] = [] + for (let i = 0, { length } = errorFiles; i < length; i += 1) { + const file = errorFiles[i]! + if (dirtyFiles.has(file) && !pushedFiles.has(file)) { + foreign.push(file) + } else { + blocking.push(file) + } + } + return { blocking, foreign } +} + +/** + * Working-tree paths with uncommitted changes, staged or not, including + * untracked. `/`-normalized to match {@link parseTypeErrorFiles}. + */ +export function readDirtyFiles(): Set { + const out = new Set() + for (const line of gitLines('status', '--porcelain')) { + // Porcelain is `XY `, and a rename is `R old -> new`. + const body = line.slice(3).trim() + if (!body) { + continue + } + const arrow = body.lastIndexOf(' -> ') + out.add(normalizePath(arrow === -1 ? body : body.slice(arrow + 4))) + } + return out +} + +/** + * `statSync` narrowed to what the cache key needs, with a missing path + * reported as undefined rather than thrown. + */ +function statOrUndefined( + p: string, +): { mtimeMs: number; size: number } | undefined { + try { + const s = statSync(p) + return { mtimeMs: s.mtimeMs, size: s.size } + } catch { + return undefined + } +} + +/** + * Run the whole-project typecheck, serialized against peer pushes, and record + * the verdict for the tree it describes. + * + * The lock WAITS rather than failing: 27 concurrent pushes of one tree each + * spawned their own tsc and put the machine at load 225. Waiting turns the + * other 26 into cache reads. Past the deadline a waiter proceeds anyway, so a + * holder that never releases costs concurrency, never a blocked push. + */ +function runTypeCheckOnce(cacheKey: string): TypecheckVerdict { + const lock = acquireFixerLock( + fixerLockPath(process.cwd()), + 'pre-push type check', + ) + // Hold the ACQUIRED handle, not the first attempt. The retry below returns a + // different handle, and keeping only the original dropped its release: a + // successful retry then left the lock held forever, so every later push + // waited on a holder that had already finished. + let held = lock.acquired ? lock : undefined + if (held === undefined) { + const outcome = waitForTypecheckTurn({ + cacheHit: () => + readTypecheckVerdict(TYPECHECK_CACHE_DIR, cacheKey) !== undefined, + now: () => Date.now(), + sleep: ms => { + Atomics.wait(new Int32Array(new SharedArrayBuffer(4)), 0, 0, ms) + }, + tryAcquire: () => { + const retry = acquireFixerLock( + fixerLockPath(process.cwd()), + 'pre-push type check', + ) + if (retry.acquired) { + held = retry + } + return retry.acquired + }, + }) + if (outcome === 'peer-finished') { + const peer = readTypecheckVerdict(TYPECHECK_CACHE_DIR, cacheKey) + if (peer) { + return peer + } + } + } + try { + debugCheck('Running type check…') + // Captured rather than inherited so the diagnostics can be ATTRIBUTED. tsc + // reads the working tree, which in a shared checkout holds a co-session's + // half-finished edits — errors this push neither caused nor can fix. + const r = spawnSync(process.execPath, [FLEET_TYPE_SCRIPT], { + stdioString: true, + }) + const verdict: TypecheckVerdict = { + output: `${String(r.stdout ?? '')}${String(r.stderr ?? '')}`, + status: r.status ?? 1, + } + if (verdict.status !== HEAVY_JOB_BUSY_EXIT_CODE) { + writeTypecheckVerdict(TYPECHECK_CACHE_DIR, cacheKey, verdict) + } + return verdict + } finally { + held?.release() + } +} + +export const scanTypeCheck = (ranges: readonly string[] = []): number => { + if (!existsSync('package.json') || !existsSync(TYPE_CHECK_TSCONFIG)) { + return 0 + } + if (!existsSync(TSC_BIN)) { + logger.fail('Type check cannot run — the TypeScript compiler is missing.') + logger.info( + ' What: node_modules/typescript is absent but the fleet type gate ' + + `(${TYPE_CHECK_TSCONFIG}) is present.\n` + + ' Where: the checkout you are pushing from.\n' + + ' Saw: no compiler; wanted: an installed toolchain to verify types.\n' + + ' Fix: run `pnpm install`, then re-push.', + ) + return 1 + } + ensureDispatchTables() + const dirty = readDirtyFiles() + const cacheKey = typecheckCacheKey( + gitLines('rev-parse', 'HEAD')[0] ?? '', + [...dirty].map(p => dirtyEntry(process.cwd(), p, statOrUndefined)), + ) + const cached = readTypecheckVerdict(TYPECHECK_CACHE_DIR, cacheKey) + const verdict = cached ?? runTypeCheckOnce(cacheKey) + if (cached) { + debugCheck('Type check: reusing the verdict for this exact tree.') + } + if (verdict.status === 0) { + showCheckOutput(verdict.status, verdict.output) + return 0 + } + const { output } = verdict + process.stderr.write(output.endsWith('\n') ? output : `${output}\n`) + const errorFiles = parseTypeErrorFiles(output) + // No parseable diagnostic means tsc failed some other way (a bad tsconfig, a + // crash). Attribution cannot apply, so it blocks as before. + const { blocking, foreign } = + errorFiles.length === 0 + ? { blocking: errorFiles, foreign: [] } + : splitTypeErrorBlame( + errorFiles, + readDirtyFiles(), + new Set(pushedRangeFiles(ranges)), + ) + if (blocking.length === 0 && foreign.length > 0) { + logger.warn( + `Type check reported ${foreign.length} file(s) with errors, all in uncommitted work this push does not carry — not blocking.`, + ) + logger.info( + ` Where: ${foreign.join(', ')}\n` + + ' Why not blocking: those bytes are not in the push, so they cannot ' + + 'reach origin. In a shared checkout this is usually a parallel ' + + 'session mid-edit, and blocking would hold every unrelated push \n' + + ' hostage until they finish.\n' + + ' Note: CI still type-checks the merged result, and a push that ' + + 'lands them will be gated then.', + ) + return 0 + } + logger.fail('Type check failed — fix the type error(s) above before pushing.') + logger.info( + ' What: the tree does not type-check.\n' + + ' Where: the file(line,col) reported above.\n' + + ' Saw: a type error; wanted: `pnpm run type` clean (what CI verifies).\n' + + ' Fix: resolve the error(s), commit, then re-push. Bypass once with ' + + '`git push --no-verify` (records the skip).', + ) + if (foreign.length > 0) { + logger.info( + ` Note: ${foreign.length} further file(s) with errors are uncommitted ` + + 'and not carried by this push, so they are not what is blocking you: ' + + `${foreign.join(', ')}.`, + ) + } + return 1 +} + +/** + * The files the pushed commits touch, `/`-normalized. Empty when there is no + * range to read, which makes every error blocking — the conservative direction + * when the gate cannot tell what is being pushed. + */ +export function pushedRangeFiles(ranges: readonly string[]): string[] { + const out = new Set() + for (let i = 0, { length } = ranges; i < length; i += 1) { + for (const line of gitLines('diff', '--name-only', ranges[i]!)) { + const file = line.trim() + if (file) { + out.add(normalizePath(file)) + } + } + } + return [...out] +} + +// Dispatch-table drift — WHEELHOUSE-ONLY (gated on the canonical `template/base/universal` +// seed, which only the wheelhouse has). The rolldown bundle's static dispatch +// table must match a fresh regen of the hooks present; a mismatch means a hook +// was added/removed without rebuilding, or a byte-cascaded table references an +// absent hook dir, the concurrent-cargo dangle. Caught at the push boundary so +// it can't reach origin/main and cascade fleet-wide. Members are NOT gated here: +// a member's byte-cascaded dispatch can legitimately differ from a fresh regen +// until the cascade regenerates per-tree, so blocking their push would +// false-fire — they rely on CI's `check --all` for the same check. +export const scanDispatchDrift = (): number => { + if (!existsSync('template/base/universal')) { + return 0 + } + const r = spawnSync( + process.execPath, + ['scripts/fleet/check/dispatch-table-is-current.mts', '--quiet'], + { maxBuffer: Infinity, stdioString: true }, + ) + showCheckResult(r) + if (r.status !== 0) { + logger.fail('Hook dispatch table is stale — rebuild before pushing.') + logger.info( + ' Run `node scripts/fleet/build-hook-bundle.mts`, commit the ' + + 'regenerated table + bundle, then re-push.', + ) + return 1 + } + return 0 +} diff --git a/.git-hooks/_shared/push/signatures.mts b/.git-hooks/_shared/push/signatures.mts new file mode 100644 index 0000000..a3289b7 --- /dev/null +++ b/.git-hooks/_shared/push/signatures.mts @@ -0,0 +1,184 @@ +// Pre-push commit-signature gate. Requires a verified signature on every commit +// pushed to a protected ref, default branch, and — when SSH signing is +// configured with an allowed_signers file — cross-checks each signing key +// against that allowlist. + +import { existsSync, readFileSync } from 'node:fs' + +import process from 'node:process' + +import { getDefaultLogger } from '@socketsecurity/lib-stable/logger/default' +import { debugCheck } from '../check-output.mts' + +import { git, gitLines } from '../git.mts' + +const logger = getDefaultLogger() + +// Scans every commit in the range to require a verified signature +// when pushing to a protected ref, default branch. Block on `N` +// no signature, and `B` (bad/unverifiable) — but allow other +// markers like `G` (good GPG sig), `U` (good GPG sig, unknown trust), +// `E`, missing-key but otherwise valid, `X` (good signature on +// expired key), `Y`/`R` (revoked/expired key with good signature). +// +// Why pre-push and not just rely on GitHub branch protection? The +// fleet enforces branch protection too (lint-github-settings.mts +// audits `required_signatures: true`), but a local pre-push fail +// gives faster feedback (no round-trip to GitHub) and catches the +// case where branch protection is being set up but not yet active +// on a freshly-created fleet repo. + +// Parse the SSH allowed_signers file referenced by +// `git config --get gpg.ssh.allowedSignersFile`. Returns the set of +// public-key BLOBS (the same format `git log --format=%GK` emits for +// SSH-signed commits — ` `). +// +// Returns an empty set if: +// - gpg.format isn't 'ssh', allowed-signers only applies to SSH-format +// - gpg.ssh.allowedSignersFile is unset +// - the file doesn't exist or can't be read +// An empty set means "don't enforce" — the %G? marker check alone +// remains active. This degrades gracefully on first install before +// the user has set up allowed_signers. +export const readAllowedSignerKeys = (): Set => { + const out = new Set() + try { + const fmt = git('config', '--get', 'gpg.format').trim() + if (fmt !== 'ssh') { + return out + } + const file = git('config', '--get', 'gpg.ssh.allowedSignersFile').trim() + if (!file) { + return out + } + const expanded = file.startsWith('~') + ? file.replace(/^~/, () => process.env['HOME'] ?? '') + : file + if (!existsSync(expanded)) { + return out + } + // allowed_signers file format: ` [] ` + // %GK emits ` `, no principal. We extract + // the last two whitespace-separated tokens of each line. + const text = readFileSync(expanded, 'utf8') + const rawLines = text.split(/\r?\n/) + for (let i = 0, { length } = rawLines; i < length; i += 1) { + const rawLine = rawLines[i]! + const line = rawLine.trim() + if (!line || line.startsWith('#')) { + continue + } + const tokens = line.split(/\s+/) + if (tokens.length < 3) { + continue + } + const keyType = tokens[tokens.length - 2]! + const keyBlob = tokens[tokens.length - 1]! + out.add(`${keyType} ${keyBlob}`) + } + } catch { + // best-effort; absence of allowed-signers shouldn't crash the hook + } + return out +} + +interface SignatureVerdict { + unsigned: string[] + unauthorized: string[] +} + +// Sorts one `%H %G? %GK` line per commit into the two blocking buckets. +function classifyCommitSignatures( + lines: string[], + allowedSigners: Set, +): SignatureVerdict { + const unsigned: string[] = [] + const unauthorized: string[] = [] + for (let i = 0, { length } = lines; i < length; i += 1) { + const line = lines[i]! + const parts = line.split(' ') + const sha = parts[0] + const marker = parts[1] + const signerKey = parts.slice(2).join(' ').trim() + if (!sha || !marker) { + continue + } + // `N` = no signature. `B` = bad signature. Both block. + if (marker === 'B' || marker === 'N') { + unsigned.push(sha) + continue + } + // Allowed-signers cross-check, SSH-signed commits only. `G` + // means git verified the signature against SOME key it trusts — + // but "any trusted key" includes attacker-controlled keys on a + // compromised dev machine. The authorized-signer file pins down + // which keys we accept for the protected branch. + if ( + allowedSigners.size > 0 && + signerKey && + !allowedSigners.has(signerKey) + ) { + unauthorized.push(`${sha} (signed by ${signerKey.slice(0, 16)}…)`) + } + } + return { unauthorized, unsigned } +} + +// Prints the operator-facing failure report for both buckets. +function reportSignatureFailures( + verdict: SignatureVerdict, + refBase: string, +): void { + const { unauthorized, unsigned } = verdict + if (unauthorized.length > 0) { + logger.error( + `${unauthorized.length} commit(s) signed by a key NOT in gpg.ssh.allowedSignersFile:`, + ) + for (let i = 0, { length } = unauthorized; i < length; i += 1) { + const u = unauthorized[i]! + logger.error(` ${u}`) + } + } + const errors = unsigned.length + unauthorized.length + logger.fail(`${errors} unsigned commit(s) being pushed to ${refBase}.`) + const shaList = unsigned.slice(0, 5) + for (let j = 0, { length: jlen } = shaList; j < jlen; j += 1) { + const sha = shaList[j]! + const oneline = git('log', '-1', '--oneline', sha) + logger.info(` - ${oneline}`) + } + if (unsigned.length > 5) { + logger.info(` ... and ${unsigned.length - 5} more`) + } + logger.info('') + logger.info('Fix: rebase + re-sign the commits.') + logger.info(` git rebase --exec 'git commit --amend --no-edit -S' `) +} + +export const scanSignedCommits = (range: string, remoteRef: string): number => { + // Only enforce on default-branch refs (main / master). Feature + // branches and topic branches can stay unsigned during development; + // signing is required at the point of landing on the protected ref. + const refBase = remoteRef.replace(/^refs\/heads\//, '') + if (refBase !== 'main' && refBase !== 'master') { + return 0 + } + debugCheck('Checking commit signatures…') + // %G? — signature verification marker (G/U/E/X/Y/R/N/B). + // %GK — signing key fingerprint, empty if unsigned. + // %GS — signer name, from key user-id. + // Cross-check %GK against gpg.ssh.allowedSignersFile when configured + // and `gpg.format = ssh`. For gpg-format signatures, %G? alone + // reflects the local keyring's trust, which is sufficient for our + // threat model (the attacker would need to control the dev's + // ~/.gnupg, at which point the local box is fully owned). + const lines = gitLines('log', '--format=%H %G? %GK', range) + const allowedSigners = readAllowedSignerKeys() + const verdict = classifyCommitSignatures(lines, allowedSigners) + const errors = verdict.unsigned.length + verdict.unauthorized.length + if (errors === 0) { + return 0 + } + reportSignatureFailures(verdict, refBase) + return errors +} diff --git a/.git-hooks/_shared/push/squash-history.mts b/.git-hooks/_shared/push/squash-history.mts new file mode 100644 index 0000000..bc3eedf --- /dev/null +++ b/.git-hooks/_shared/push/squash-history.mts @@ -0,0 +1,63 @@ +// Squash-history roster detection for the pre-push blocked-message teaching. +// Gate-free; reads the fleet-repos roster off disk to tell whether THIS repo +// opts into the squash-history convention. Kept separate from the push gates so +// the roster-read logic has one home. + +import { existsSync, readFileSync } from 'node:fs' + +import path from 'node:path' + +import { spawnSync } from '@socketsecurity/lib-stable/process/spawn/child' + +// Git remotes end in `/name` or `:name`; capture the name and drop optional `.git`. +export const REMOTE_REPO_RE = /[/:](?[^/:]+?)(?:\.git)?$/ + +// True when THIS repo opts into the squash-history convention (roster +// `optIns: ['squash-history']`). Drives the land-freely teaching in the blocked +// message: in a squash-history repo, a gate blocked on in-flight WIP or +// moving-target cascade/format drift, from a parallel session, is NOT a wall — +// local main is canonical + flattens, so committing the dirty tree + a +// `--no-verify` push is the sanctioned way through. +export function isSquashHistoryRepo(): boolean { + const readGit = (args: string[]): string => { + const r = spawnSync('git', args, { + encoding: 'utf8', + stdio: ['ignore', 'pipe', 'ignore'], + }) + return r.status === 0 && typeof r.stdout === 'string' ? r.stdout.trim() : '' + } + const root = readGit(['rev-parse', '--show-toplevel']) + if (!root) { + return false + } + const remote = readGit(['config', '--get', 'remote.origin.url']) + const repo = + REMOTE_REPO_RE.exec(remote)?.groups?.['repo'] ?? path.basename(root) + const rosterRels = [ + 'template/base/universal/.claude/skills/fleet/cascading-commits/lib/fleet-repos.json', + '.claude/skills/fleet/cascading-commits/lib/fleet-repos.json', + ] + for (let i = 0, { length } = rosterRels; i < length; i += 1) { + const p = path.join(root, rosterRels[i]!) + if (!existsSync(p)) { + continue + } + try { + const roster = JSON.parse(readFileSync(p, 'utf8')) as { + repos?: + | ReadonlyArray<{ + name?: string | undefined + optIns?: readonly string[] | undefined + }> + | undefined + } + const entry = (roster.repos ?? []).find(r => r.name === repo) + if (entry) { + return (entry.optIns ?? []).includes('squash-history') + } + } catch { + // Unreadable/malformed roster — treat as non-squash, no teaching. + } + } + return false +} diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index a3a649a..39323e6 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -168,11 +168,11 @@ catalogs: specifier: 1.0.2 version: 1.0.2 '@mdn/browser-compat-data': - specifier: 8.1.2 - version: 8.1.2 + specifier: 8.1.3 + version: 8.1.3 '@modelcontextprotocol/client': - specifier: 2.0.0 - version: 2.0.0 + specifier: 2.2.0 + version: 2.2.0 '@playwright/mcp': specifier: 0.0.81 version: 0.0.81 @@ -192,8 +192,8 @@ catalogs: specifier: 4.0.4 version: 4.0.4 '@types/node': - specifier: 26.6.1 - version: 26.6.1 + specifier: 26.6.3 + version: 26.6.3 '@types/semver': specifier: 7.8.0 version: 7.8.0 @@ -204,38 +204,38 @@ catalogs: specifier: 0.1.1 version: 0.1.1 '@vitest/coverage-v8': - specifier: 5.0.1 - version: 5.0.1 + specifier: 5.0.2 + version: 5.0.2 '@vitest/ui': - specifier: 5.0.1 - version: 5.0.1 + specifier: 5.0.2 + version: 5.0.2 '@vitiate/core': specifier: 0.3.1 version: 0.3.1 ast-v8-to-istanbul: - specifier: 1.0.6 - version: 1.0.6 + specifier: 1.0.7 + version: 1.0.7 ata-validator: - specifier: 1.27.1 - version: 1.27.1 + specifier: 1.39.1 + version: 1.39.1 c8: specifier: 12.0.0 version: 12.0.0 chrome-devtools-mcp: - specifier: 1.9.0 - version: 1.9.0 + specifier: 1.10.1 + version: 1.10.1 compromise: specifier: 14.17.0 version: 14.17.0 fallow: - specifier: 3.27.0 - version: 3.27.0 + specifier: 3.30.0 + version: 3.30.0 fast-check: - specifier: 4.10.1 - version: 4.10.1 + specifier: 4.10.2 + version: 4.10.2 markdownlint-cli2: - specifier: 0.23.2 - version: 0.23.2 + specifier: 0.23.3 + version: 0.23.3 mcp-tada: specifier: 0.4.0 version: 0.4.0 @@ -246,11 +246,11 @@ catalogs: specifier: 3.1.0 version: 3.1.0 mdast-util-to-markdown: - specifier: 2.1.2 - version: 2.1.2 + specifier: 2.1.3 + version: 2.1.3 micromark: - specifier: 4.0.2 - version: 4.0.2 + specifier: 4.0.3 + version: 4.0.3 micromark-extension-gfm: specifier: 3.0.0 version: 3.0.0 @@ -282,8 +282,8 @@ catalogs: specifier: 0.15.6 version: 0.15.6 regjsparser: - specifier: 0.13.2 - version: 0.13.2 + specifier: 0.13.3 + version: 0.13.3 run-local-ci: specifier: 0.18.1 version: 0.18.1 @@ -291,20 +291,20 @@ catalogs: specifier: 7.8.5 version: 7.8.5 shell-quote: - specifier: 1.10.0 - version: 1.10.0 + specifier: 1.11.0 + version: 1.11.0 svgo: specifier: 4.1.0 version: 4.1.0 taze: - specifier: 21.1.0 - version: 21.1.0 + specifier: 21.3.0 + version: 21.3.0 typescript: - specifier: 7.1.0-dev.20260917.1 - version: 7.1.0-dev.20260917.1 + specifier: 7.1.0-dev.20260929.1 + version: 7.1.0-dev.20260929.1 vitest: - specifier: 5.0.1 - version: 5.0.1 + specifier: 5.0.2 + version: 5.0.2 yaml: specifier: 2.9.1 version: 2.9.1 @@ -330,8 +330,8 @@ overrides: iconv-lite: 0.7.3 isexe@>=3: 4.0.0 js-yaml@>=5.0.0 <5.2.2: 5.4.2 - lru-cache@>=10: 11.5.2 - magic-string: 1.4.1 + lru-cache@>=10: 11.5.3 + magic-string: 1.4.2 mime-db: 1.54.0 mime-types@>=3: 3.0.2 minimatch@>=3: 10.2.6 @@ -342,9 +342,9 @@ overrides: semver@>=5.0.0 <7.6.0: 7.8.5 side-channel: npm:@socketregistry/side-channel@1.0.10 ssri@>=12: 13.0.1 - string-width@>=5: 8.2.2 + string-width@>=5: 8.3.0 tinyexec: 1.3.1 - typebox: 1.3.33 + typebox: 1.3.34 undici@<6: 6.28.0 update-notifier@>=4.0.0: 7.3.1 uuid: 11.1.1 @@ -353,7 +353,7 @@ overrides: yaml@2: 2.9.1 '@grpc/proto-loader': 0.8.1 '@types/unist@2': 3.0.3 - ansi-regex: 6.3.0 + ansi-regex: 6.4.0 color-convert: 2.0.1 commander: 11.1.0 content-type: 2.1.0 @@ -365,10 +365,10 @@ overrides: picomatch: 4.0.7 protobufjs: 7.6.6 rolldown: 1.2.10 - sharp: 0.35.4 - string-width: 8.2.2 + sharp: 0.35.5 + string-width: 8.3.0 strip-ansi: 7.2.0 - vite: 8.3.0 + vite: 8.3.1 which@>=4: 7.0.0 patchedDependencies: @@ -376,7 +376,6 @@ patchedDependencies: brace-expansion@5.0.12: c15cb4e3c78bc74448f2dd848dacc1d86afc3c91cc8e70d78ef52150b1d47b04 minimatch@10.2.6: 83f1ea5b333d1b6fe1b36f93ccb222aa02e5dd468b2c646e285d7d53d234e174 run-local-ci@0.18.1: a335253820e963c2659ec1b08ee143e865eb39ec80ca7d313fff50c33e157d99 - vitest@5.0.1: 065993cceebda16dedb4662626ed60c0aeb40f02240c8d0e540b4dc6d9674df2 importers: @@ -387,10 +386,10 @@ importers: version: 1.0.2 '@mdn/browser-compat-data': specifier: 'catalog:' - version: 8.1.2 + version: 8.1.3 '@modelcontextprotocol/client': specifier: 'catalog:' - version: 2.0.0 + version: 2.2.0 '@playwright/mcp': specifier: 'catalog:' version: 0.0.81 @@ -408,10 +407,10 @@ importers: version: '@socketregistry/packageurl-js@1.5.3' '@socketsecurity/lib': specifier: 7.0.3 - version: 7.0.3(typescript@7.1.0-dev.20260917.1) + version: 7.0.3(typescript@7.1.0-dev.20260929.1) '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@socketsecurity/sdk': specifier: 4.1.5 version: 4.1.5 @@ -423,7 +422,7 @@ importers: version: 4.0.4 '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 '@types/semver': specifier: 'catalog:' version: 7.8.0 @@ -435,40 +434,40 @@ importers: version: 0.1.1 '@vitest/coverage-v8': specifier: 'catalog:' - version: 5.0.1(vitest@5.0.1) + version: 5.0.2(vitest@5.0.2) '@vitest/ui': specifier: 'catalog:' - version: 5.0.1(vitest@5.0.1) + version: 5.0.2(vitest@5.0.2) '@vitiate/core': specifier: 'catalog:' - version: 0.3.1(typescript@7.1.0-dev.20260917.1)(vite@8.3.0(@types/node@26.6.1)(jiti@2.7.0)(yaml@2.9.1))(vitest@5.0.1) + version: 0.3.1(typescript@7.1.0-dev.20260929.1)(vite@8.3.1(@types/node@26.6.3)(jiti@2.7.0)(yaml@2.9.1))(vitest@5.0.2) ast-v8-to-istanbul: specifier: 'catalog:' - version: 1.0.6 + version: 1.0.7 ata-validator: specifier: 'catalog:' - version: 1.27.1(yaml@2.9.1) + version: 1.39.1(yaml@2.9.1) c8: specifier: 'catalog:' version: 12.0.0 chrome-devtools-mcp: specifier: 'catalog:' - version: 1.9.0 + version: 1.10.1 fallow: specifier: 'catalog:' - version: 3.27.0 + version: 3.30.0 fast-check: specifier: 'catalog:' - version: 4.10.1 + version: 4.10.2 magic-string: - specifier: 1.4.1 - version: 1.4.1 + specifier: 1.4.2 + version: 1.4.2 markdownlint-cli2: specifier: 'catalog:' - version: 0.23.2(supports-color@7.2.0) + version: 0.23.3(supports-color@7.2.0) mcp-tada: specifier: 'catalog:' - version: 0.4.0(@modelcontextprotocol/client@2.0.0)(typescript@7.1.0-dev.20260917.1) + version: 0.4.0(@modelcontextprotocol/client@2.2.0)(typescript@7.1.0-dev.20260929.1) mdast-util-from-markdown: specifier: 'catalog:' version: 2.0.3(supports-color@7.2.0) @@ -477,10 +476,10 @@ importers: version: 3.1.0(supports-color@7.2.0) mdast-util-to-markdown: specifier: 'catalog:' - version: 2.1.2 + version: 2.1.3 micromark: specifier: 'catalog:' - version: 4.0.2(supports-color@7.2.0) + version: 4.0.3(supports-color@7.2.0) micromark-extension-gfm: specifier: 'catalog:' version: 3.0.0 @@ -513,7 +512,7 @@ importers: version: 0.15.6 regjsparser: specifier: 'catalog:' - version: 0.13.2 + version: 0.13.3 rolldown: specifier: 1.2.10 version: 1.2.10 @@ -525,22 +524,22 @@ importers: version: 7.8.5 shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 svgo: specifier: 'catalog:' version: 4.1.0 taze: specifier: 'catalog:' - version: 21.1.0 + version: 21.3.0 typebox: - specifier: 1.3.33 - version: 1.3.33 + specifier: 1.3.34 + version: 1.3.34 typescript: specifier: 'catalog:' - version: 7.1.0-dev.20260917.1 + version: 7.1.0-dev.20260929.1 vitest: specifier: 'catalog:' - version: 5.0.1(patch_hash=065993cceebda16dedb4662626ed60c0aeb40f02240c8d0e540b4dc6d9674df2)(@types/node@26.6.1)(@vitest/coverage-v8@5.0.1)(@vitest/ui@5.0.1)(vite@8.3.0(@types/node@26.6.1)(jiti@2.7.0)(yaml@2.9.1)) + version: 5.0.2(@types/node@26.6.3)(@vitest/coverage-v8@5.0.2)(@vitest/ui@5.0.2)(vite@8.3.1(@types/node@26.6.3)(jiti@2.7.0)(yaml@2.9.1)) yaml: specifier: 'catalog:' version: 2.9.1 @@ -549,359 +548,359 @@ importers: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/actionlint-on-workflow-edit: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/active-edits-bash-recorder: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/active-edits-ledger: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/adversarial-review-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/agent-orphan-sweep-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' .claude/hooks/fleet/agent-prompt-budget-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/agent-session-budget-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/ai-adapter-source-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' .claude/hooks/fleet/ai-balancer-proxy-start: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/ai-balancer-watchdog: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/ai-config-drift-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/ai-config-poisoning-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/ai-shim-start: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/alpha-sort-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/answer-questions-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/answer-status-requests-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/anti-prose-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/artifact-gates-on-stop: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/ask-suppression-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/attribution-rewrite-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/auth-rotation-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/authorization-phrase-emission-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/auto-land-on-edit: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/auto-land-on-stop: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/auto-push-on-stop: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/avoid-cd-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/bash-file-write-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/bash-timeout-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/bot-comment-collapse-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/brew-supply-chain-is-hardened-at-edit: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/broken-hook-detector: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/browser-extension-build-current-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/bump-defers-to-release-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/bundle-flags-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/bundle-stale-reminder: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/c8-ignore-reason-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/cascade-first-triage-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/cascade-graph-defers-to-script-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/catch-message-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/changelog-entry-shape-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/changelog-no-empty-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/check-new-deps: dependencies: @@ -910,384 +909,384 @@ importers: version: '@socketregistry/packageurl-js@1.5.3' '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@socketsecurity/sdk-stable': specifier: 'catalog:' version: '@socketsecurity/sdk@4.1.5' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/ci-poll-throttle-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/claude-code-action-lockdown-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/claude-lockdown-guard: dependencies: shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/claude-md-defer-detail-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/claude-md-rule-add-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/claude-md-section-size-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/claude-md-size-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/claude-segmentation-guard: devDependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/clipboard-snippet-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/clone-reviewed-repo-nudge: devDependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/code-as-law-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/codex-no-write-guard: dependencies: shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/codify-footgun-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/commit-author-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/commit-cadence-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/commit-message-format-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/commit-paths-are-named-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/commit-pr-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/commit-size-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/compound-lessons-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/config-refs-are-segregated-at-edit: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/consumer-grep-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/convo-prose-nudge: devDependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/corepack-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/corrupt-rebase-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/crlf-split-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/cross-repo-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/default-branch-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/defer-to-script-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/deferred-residue-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/denied-domain-reference-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/dep-derived-source-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/detached-head-write-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/dirty-lockfile-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/dirty-worktree-stop-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/disowned-dirt-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/dogfood-cascade-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/dont-blame-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/dont-stop-mid-queue-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/drift-check-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/enqueue-dont-pivot-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/enterprise-push-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/env-kill-switches-are-absent-at-edit: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/error-messages-are-thorough-at-edit: dependencies: @@ -1297,211 +1296,211 @@ importers: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/excuse-detector: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/fetch-allowlist-is-respected-at-edit: devDependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/file-size-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/fixer-peer-edits-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/fixes-need-tests-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/follow-direct-imperative-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/foreign-repo-conventions-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/generic-export-name-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/gh-body-code-format-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/gh-token-hygiene-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/git-config-write-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/git-identity-drift-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/gitignore-is-single-file-at-edit: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/gitmodules-comment-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' .claude/hooks/fleet/golden-fixtures-are-named-golden-at-edit: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/handoff-command-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/handoff-request-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/history-rewrite-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/honeypot-echo-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/hook-snapshot-rewire-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/human-gate-ends-turn-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/immutable-release-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/inline-script-defer-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/instruction-precedence-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' .claude/hooks/fleet/issue-autolink-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/judgment-nudge: dependencies: @@ -1511,68 +1510,68 @@ importers: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/keep-working-while-waiting-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/land-as-you-go-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/land-fast-nudge: devDependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/latest-release-pin-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/link-protocol-dep-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/live-edit-collision-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/lock-step-ref-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/logger-guard: dependencies: @@ -1582,209 +1581,209 @@ importers: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/long-running-task-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/markdown-filenames-are-canonical-at-edit: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/mass-delete-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/memories-are-codified-at-edit: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/memory-codify-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/memory-discovery-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/memory-pressure-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/mermaid-github-safe-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/minimum-release-age-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/mixed-clock-recency-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/model-fallback: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/model-policy-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/model-spawn-policy-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/module-noun-name-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/new-hook-claude-md-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-amend-peer-commit-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-blanket-file-exclusion-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-blind-keychain-read-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-boolean-trap-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-branch-reuse-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-cascade-transient-git-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-chained-pausing-git-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-ci-env-install-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-clipboard-access-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-comment-essays-guard: dependencies: @@ -1794,172 +1793,172 @@ importers: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-commit-ai-attribution-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-copyleft-source-read: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-corepack-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-credential-file-read-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-description-aside-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-designated-ignore-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-direct-linter-guard: devDependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-disable-lint-rule-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-duplicate-pr-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-empty-commit-guard: dependencies: shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-ext-issue-ref-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-file-oxlint-disable-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-fleet-fork-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-fleet-pr-to-main-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-fleet-scope-in-non-member-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-force-push-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-github-ai-attribution-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-hook-cmd-regex-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-ignoring-tracked-file-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-meta-comments-guard: dependencies: @@ -1969,491 +1968,491 @@ importers: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-new-config-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-non-fleet-push-guard: dependencies: shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-npm-otp-flag-guard: dependencies: shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-orphaned-staging: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-other-linters-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-pkgjson-pnpm-overrides-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-placeholder-commit-subject-guard: dependencies: shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-platform-import-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-pm-exec-guard: devDependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-pr-assets-in-branch-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-pr-from-default-branch-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-pr-from-default-checkout-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-pr-in-squash-repo-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-pr-review-verdict-guard: dependencies: shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-premature-commit-kill-guard: devDependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-primary-branch-switch: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-private-ref-in-tests-docs-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-private-repo-leak-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-raw-gh-auth-login-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-registry-mutation-in-repo-script-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-removal-comment-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-repo-scope-in-fleet-config-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-revert-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-screenshot-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-self-referential-symlink-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-shell-injection-bypass-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-shrinking-overwrite-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-stdin-flag-without-input-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-strip-types-guard: dependencies: shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-subagent-commit-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-tail-install-out-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-test-in-scripts-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-token-in-dotenv-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-total-squash-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-tsx-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-unasked-non-fleet-pr-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-underscore-ident-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-unisolated-git-fixture-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-unmocked-ai-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-unmocked-net-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-unsafe-delete-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-upstream-edit-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-verify-format-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-version-bump-pr-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-vitest-double-dash-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-wheelhouse-pr-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/no-wheelhouse-pr-link-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/node-modules-staging-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/non-fleet-pr-issue-ask-guard: dependencies: shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 .claude/hooks/fleet/notion-backup-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/notion-replace-content-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/npm-2fa-needs-pty-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/npm-otp-flow-nudge: dependencies: shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/npmrc-trust-optout-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/observed-test-failure-stop-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/operate-from-repo-root-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/options-param-naming-guard: dependencies: @@ -2465,82 +2464,82 @@ importers: devDependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/overeager-staging-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/oxlint-plugin-load-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/package-manager-auto-update-is-disabled-at-edit: devDependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/parallel-agent-edit-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/parallel-agent-on-stop-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/parallel-agent-removal-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/parallel-agent-spawn-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/parallel-agent-staging-guard: dependencies: shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/parallel-spawn-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/path-guard: dependencies: @@ -2556,194 +2555,194 @@ importers: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/paths-mts-inherit-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/peer-claim-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/peer-resource-lease-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/peer-uncommitted-work-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/peer-workstream-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/personal-path-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/plan-location-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/plan-review-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/pnpm-filter-zero-match-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/pointer-comment-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@ultrathink/acorn.rs.wasm': specifier: 'catalog:' version: 0.1.1 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/post-push-ci-monitor-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/pr-body-style-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/pr-comment-brevity-guard: devDependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/pr-comment-shape-nudge: devDependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/pr-merge-conflict-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/pr-vs-push-default-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/pre-commit-race-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/prefer-async-spawn-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/prefer-evergreen-target-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/prefer-fff-search-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/prefer-fn-decl-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/prefer-inline-small-dependency-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/prefer-join-helpers-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/prefer-json-clone-guard: dependencies: @@ -2755,98 +2754,98 @@ importers: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/prefer-pipx-over-pip-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/prefer-pnpm-over-npm-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/prefer-rebase-over-revert-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/prefer-script-emission-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/prefer-type-import-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/prefer-vitest-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/primary-checkout-branch-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/primary-checkout-on-default-stop-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/private-name-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/private-package-name-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/private-paths-are-absent-at-edit: dependencies: @@ -2856,325 +2855,325 @@ importers: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/proc-environ-exfil-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/prompt-injection-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/prose-code-format-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/provenance-publish-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/public-surface-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/pull-request-target-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/push-protected-branch-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/read-orientation-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/readme-fleet-shape-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/rebase-during-merge-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/release-commit-subject-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/release-defers-to-script-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/release-tag-tied-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/release-workflow-guard: dependencies: shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/repeat-action-needs-a-script-nudge: devDependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/reply-code-format-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/reply-prose-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/reply-ref-link-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/reply-tone-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/repo-map-refresh: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/report-location-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/reserved-script-dir-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/resource-lease-recorder: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/revert-bypass-last-resort-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/rg-replace-flag-guard: devDependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/rule-citations-are-generic-at-edit: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/rust-target-sweep-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/sabotage-target-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/scan-label-in-commit-guard: dependencies: shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/scratch-in-tree-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/secret-content-guard: devDependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/sed-in-place-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/session-handoff-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/setup-basics-tools: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/setup-claude-scanners: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/setup-firewall: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/setup-misc-tools: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/setup-security-tools: dependencies: @@ -3183,202 +3182,202 @@ importers: version: '@socketregistry/packageurl-js@1.5.3' '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' .claude/hooks/fleet/setup-signing: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/shallow-clone-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/shared-index-add-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/shell-substitution-in-message-guard: devDependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/silent-guard-compliance-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/single-lander-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/skill-usage-logger: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/small-pr-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/snapshot-hostile-require-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/soak-exclude-date-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' .claude/hooks/fleet/soak-exclude-scope-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/soak-pin-needs-annotation-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/spend-warning-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/squash-freeze-boundary-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/squash-history-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/stale-log-read-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/stale-node-modules-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/stale-process-sweeper: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' .claude/hooks/fleet/stale-tree-clobber-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/ste-language-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/stop-means-commit-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/sweep-ds-store: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/synthesized-script-edit-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/target-arch-env-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/task-scope-guard: {} @@ -3386,51 +3385,51 @@ importers: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/test-env-scrub-order-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/test-network-pattern-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/test-platform-coverage-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/test-script-defers-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/token-guard: {} @@ -3438,287 +3437,287 @@ importers: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/trust-downgrade-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/tsc-canonical-tsconfig-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/unaddressed-review-feedback-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/unbacked-claim-guard: dependencies: shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/unbacked-claim-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/uncodified-lesson-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/uncommitted-sweep-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/unpushed-main-nudge: devDependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/untrusted-coauthor-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/untrusted-content-directive-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/upstream-gitlinks-are-absent-at-edit: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/upstream-is-read-only-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/upstream-read-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/use-repo-test-script-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/use-the-script-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/uses-sha-verify-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' .claude/hooks/fleet/variant-analysis-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/verify-absence-claims-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/verify-before-publish-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/verify-render-pre-commit-nudge: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/version-bump-order-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/vitest-vs-node-test-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/vscode-folder-open-task-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/waiting-discipline-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/wheelhouse-drift-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/workflow-agent-task-tools-nudge: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/workflow-multiline-body-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/workflow-sha-pins-are-stamped-at-edit: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' .claude/hooks/fleet/worktree-create-defers-to-script-guard: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/worktree-remove-relink-nudge: dependencies: shell-quote: specifier: 'catalog:' - version: 1.10.0 + version: 1.11.0 devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/worktree-sweep: dependencies: '@socketsecurity/lib-stable': specifier: 'catalog:' - version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)' + version: '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)' devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .claude/hooks/fleet/zsh-word-split-guard: devDependencies: '@types/node': specifier: 'catalog:' - version: 26.6.1 + version: 26.6.3 .config/fleet/oxlint-plugin: dependencies: @@ -3727,7 +3726,7 @@ importers: version: 0.1.1 regjsparser: specifier: 'catalog:' - version: 0.13.2 + version: 0.13.3 .config/fleet/oxlint-plugin/fleet/bag-param-optionality-naming: {} @@ -3977,7 +3976,7 @@ importers: dependencies: regjsparser: specifier: 'catalog:' - version: 0.13.2 + version: 0.13.3 .config/fleet/oxlint-plugin/fleet/require-vitest-globals-import: {} @@ -4017,8 +4016,8 @@ packages: resolution: {integrity: sha512-hghYVU7h//IGf+NaQgZrO7SI2Pre88ZKZQ8sM/1CBx1bEIJM9t9MMAeTCnKOknNaxBScbDPmmpwil26DxKgMwA==} engines: {node: '>= 18'} - '@antfu/ni@30.5.0': - resolution: {integrity: sha512-VwQoM9qF1dzDrye55b1qIBeLr4zQ1a5wZQMPCe496HTiquViBZqxtNBaq98WX3ze5kC9Yl7gKSU4W2vtLztxYw==} + '@antfu/ni@30.6.0': + resolution: {integrity: sha512-vRZX+aPd9UzUMjsCeH0CR4ldbCwwGaKjbotF7PBRyZdbZRZJz3Em+HXUNaxGWcdajRpTBL1HQ0KECudftPs7CQ==} engines: {node: '>=20.19.0'} hasBin: true @@ -4026,42 +4025,42 @@ packages: resolution: {integrity: sha512-UQFQ6SgyJ6LX42W8rHCs8KVc0JS0tzVL9ct4XYedJukskYVWTo49tNiMEK9C2HTyarbNiT/RVIRSY82vH+6sTg==} engines: {node: '>=4'} - '@ata-validator/native-darwin-arm64@1.27.1': - resolution: {integrity: sha512-qTEoUGsnlFffPN1zNrX0sDbgxc9fMqx3ErJL/1V+UtPoU7HZNuEjU5ENhyaeLMNOUjAsvufq4sRVgGvYqUykDA==} + '@ata-validator/native-darwin-arm64@1.39.1': + resolution: {integrity: sha512-gE7ulwoWGlmO4GpU82xGiex1/mbzap8HdKPvy2CV44IE8Con2jlQGzaR6rnOrMboOkfVXIX8jNE80i3+RFkJjA==} cpu: [arm64] os: [darwin] - '@ata-validator/native-darwin-x64@1.27.1': - resolution: {integrity: sha512-jqgCkc5Z8XMOyrf/pi7AIl4yMjOlsDxUYbL0TakTsnYDt42F9ej16Ex5+zln774aDY96y9GYCRdjePZ5heeyPg==} + '@ata-validator/native-darwin-x64@1.39.1': + resolution: {integrity: sha512-r2GieJXbgjQugmlBpyD52QPhFzy3JJUH5MxRYMvPnUESOj26k4MeOc3jywGinqbVEeXA/8ytypnbQhhW6z6dyw==} cpu: [x64] os: [darwin] - '@ata-validator/native-linux-arm64-gnu@1.27.1': - resolution: {integrity: sha512-4ZsrKJoL+QjMrIO0xoGX/xOesGQYucSIjNrM2VYSQ3oX8mWKhi6+fpAwSNh73zymCQFwoUw6VUYXFie6nseYgg==} + '@ata-validator/native-linux-arm64-gnu@1.39.1': + resolution: {integrity: sha512-0iUhc97jugwABDbXl1kQCB3Pn7DhoTI6NY4VQf4xyKGpjSFAqna13kZ0UDDe9DHjrLR/oGtc1PIVpwVkPoa+ew==} cpu: [arm64] os: [linux] libc: [glibc] - '@ata-validator/native-linux-arm64-musl@1.27.1': - resolution: {integrity: sha512-PYlp02lfdWiBqkGF+wTqZL2jt6VAhXjl6FqTA74sdz2Ll3Ys1uUSIaKSX1H58WEY6VVPi3WPGE2786z1ZjzhlQ==} + '@ata-validator/native-linux-arm64-musl@1.39.1': + resolution: {integrity: sha512-TSM6/uAQ5eL2X32024BhmKSpYTTB0IqXd9FF2SdW1q7gd5+nYV7BjFXeaBq6IdfSPlzFfEly0GUZEfWSx87GFw==} cpu: [arm64] os: [linux] libc: [musl] - '@ata-validator/native-linux-x64-gnu@1.27.1': - resolution: {integrity: sha512-emGMbUAztGWNIklnkubOfRF/e+E5UOAiB2weHVCpuF9PxDazLh/FjtzTyaL8/NJCAU/KFM/kJe7rUg48KEvIMw==} + '@ata-validator/native-linux-x64-gnu@1.39.1': + resolution: {integrity: sha512-b0uNloVsPW0F+yH2v7kfzXXejR4AmZnRMj2LVOosGhiejAG9HQT2XPN4M/7Q37LeRCfhlznkxYZ+GiN07sZW9g==} cpu: [x64] os: [linux] libc: [glibc] - '@ata-validator/native-linux-x64-musl@1.27.1': - resolution: {integrity: sha512-NPc0LXGEWvo5vonQuG0uLrnUBy9RWQHeznxGmXNMeAquybXsFgBbsow9c0peW5yY5sHjPA82wWh6xCID+tSnFA==} + '@ata-validator/native-linux-x64-musl@1.39.1': + resolution: {integrity: sha512-CO9vi+VgWVvQDJgifpbVXr4M9EGaS6brGX96UQUvup7PXgvLJWZFHr/zu1QxGdZeNgOkQMWmAEBXVf2XjHFCAQ==} cpu: [x64] os: [linux] libc: [musl] - '@ata-validator/native-win32-x64@1.27.1': - resolution: {integrity: sha512-39CIxLp7AQIetSmilOorFgl9vx1mpMT6BVgjN+EZBIVL1OIPd650fSF8YqucsHe140B2NV1T9GOQRhlA+VhAWw==} + '@ata-validator/native-win32-x64@1.39.1': + resolution: {integrity: sha512-9THeOIS/BUt1XH0yRzAPluXRBGygrWKRtc9npFiXUzGysuMUrb7/dftd31taYlg0HpaAL093165sPM9fiINRNw==} cpu: [x64] os: [win32] @@ -4089,43 +4088,43 @@ packages: resolution: {integrity: sha512-6zABk/ECA/QYSCQ1NGiVwwbQerUCZ+TQbp64Q3AgmfNvurHH0j8TtXa1qbShXA6qqkpAj4V5W8pP6mLe1mcMqA==} engines: {node: '>=18'} - '@fallow-cli/darwin-arm64@3.27.0': - resolution: {integrity: sha512-e8Tn+GxeYONnfWecFO8YrW1sHRaS4wTU23Oq8xsp6myFTTguRBOHiLxANHVpibG7evrnZniJTJ1l6DacP/z9RA==} + '@fallow-cli/darwin-arm64@3.30.0': + resolution: {integrity: sha512-u3MkZKaHH/dX3qm5ks44QRSsTIspDbaJhoNG5y0j7nl2LPo1ZcM5Feyt6lxta007KKH8YgS6TgwCFaYZjzdOvQ==} cpu: [arm64] os: [darwin] - '@fallow-cli/darwin-x64@3.27.0': - resolution: {integrity: sha512-X3g6SkKIn9WTWsxUEJlKD4WzPDCADFhTd1f/pgLEDz6rVtW7gZZ3bu/L/GYg4n0B2qZxaG6Aci34vl3QuDvQsg==} + '@fallow-cli/darwin-x64@3.30.0': + resolution: {integrity: sha512-zufVDV7HaAcNBFPEKmERL6b/0lMIswFCSPq2EvzgtPke+1GQC/Vb7CzrSoWc/pHovnOcTL72yc3POFgd3ZOA/A==} cpu: [x64] os: [darwin] - '@fallow-cli/linux-arm64-gnu@3.27.0': - resolution: {integrity: sha512-+gzjMVBHho1PCJp0cU4rwfyroRg8aNCsLHxjqY9FMVAG+Sp42SBnLPi/AyagGtUdf/GY9Vn74F1auhVLCxqvQA==} + '@fallow-cli/linux-arm64-gnu@3.30.0': + resolution: {integrity: sha512-/Gq+zVOc/s1tVAUhLoSA4nBhs4RK59u8pBjNzhJBPdwIAtDQ9jXpCAKPzG5JZuYXKoQ6hSpQDJnrH1v7pCsZxA==} cpu: [arm64] os: [linux] - '@fallow-cli/linux-arm64-musl@3.27.0': - resolution: {integrity: sha512-RsPpC7KTG0bhBJrN0up+C2WmsQHFOGLNjAtIG8hp87xKRDIp4/uTu15jNtAK57H/kFShcn+feWaol/Fojzx3vg==} + '@fallow-cli/linux-arm64-musl@3.30.0': + resolution: {integrity: sha512-T41dkQRNICfi17lJqchxJSsDtshcJdqMOPBKrLwIGs1At23qX6PBjmQGkCyHhyKMBFSOKFmISwzG722X7ZYi7w==} cpu: [arm64] os: [linux] - '@fallow-cli/linux-x64-gnu@3.27.0': - resolution: {integrity: sha512-t+bzC7AGxfi1GPp9sUkGbJbrALesACtOwO0CZ176jKby4BOYnyuIn80XwnX8eEHY32THqNucOng3nVwCnfIEvA==} + '@fallow-cli/linux-x64-gnu@3.30.0': + resolution: {integrity: sha512-+cEZI516t2POYTDeNhijjuHvToNgTobez71maiib6nxivoixl8M6hzj838/8/DTrLy3AxXBH6bfOax78F95FnA==} cpu: [x64] os: [linux] - '@fallow-cli/linux-x64-musl@3.27.0': - resolution: {integrity: sha512-kLv7iholQ05qzlVTp6KMzoTW86o5oPoOtrMlsS4ZNUceMAnflLacEmwJEtp1O2vO2RAcKcd89bREWM+wBz8t4Q==} + '@fallow-cli/linux-x64-musl@3.30.0': + resolution: {integrity: sha512-QX8ZUQSFEMhkGc0fBOcoSjHiv1mconxpWBu0XW+i/K+XlAnjAYsFrQ8lrKJajSzURgon7iTAy7NfFNY1zJVyTw==} cpu: [x64] os: [linux] - '@fallow-cli/win32-arm64-msvc@3.27.0': - resolution: {integrity: sha512-HPzeqLxlz1wxc2fLNt6QUosiLkDFhdzmV03s75JMgEQskgc1K0vlc4E6UIY5M3Q73hNstTfzUTcqcD8YZ5CZOA==} + '@fallow-cli/win32-arm64-msvc@3.30.0': + resolution: {integrity: sha512-LajU38z7LKbmBTGYuJPsxyIZs/tgqRkW6jFDdJJctd/VEexwuAC4tdODCdyXuYYbavjorgJQH2bB+XmicAPkmg==} cpu: [arm64] os: [win32] - '@fallow-cli/win32-x64-msvc@3.27.0': - resolution: {integrity: sha512-F1VHSLgn3X2tA45WamK3+IXLNgFTQiolZbthkawvRPCHAXdksSjhujJ9Ruuln24Y+q/2zsctrEdypLDpuaI/uA==} + '@fallow-cli/win32-x64-msvc@3.30.0': + resolution: {integrity: sha512-YgMSneNsCWUPuyOdseDVGQx9AhuOjzmUaoNILhBfu7MhdI4oOHEtBSftdTenp0E7tXRCzPpMMWuCL17l7IvwSg==} cpu: [x64] os: [win32] @@ -4158,15 +4157,15 @@ packages: '@js-sdsl/ordered-map@4.4.2': resolution: {integrity: sha512-iUKgm52T8HOE/makSxjqoWhe95ZJA1/G1sYsGev2JDKUSS14KAgg1LHb+Ba+IPow0xflbnSkOsZcO08C7w1gYw==} - '@mdn/browser-compat-data@8.1.2': - resolution: {integrity: sha512-pe2qO3VDkRybAvmpr1UfC4zMnvOiVHUp4EMJU8RboulqzEvearRrUWCi/Y0QVRvkfe6Fh5Nahdk9uncU9anrFw==} + '@mdn/browser-compat-data@8.1.3': + resolution: {integrity: sha512-CMVFbWe6y0EEc4qXtcoIc9WnFiLzk8Xd/0CTGUZZI0xC/7fhZOPIFbgCesG2wGhPBMzwEpD9VuKcPqy0r6LNKQ==} - '@modelcontextprotocol/client@2.0.0': - resolution: {integrity: sha512-8f1OghQ2rjzIOfqgUCP+8GiUWqRs89njoWLNqAe8kWmDePv3s1fZXseej+QXemssEuuOvLLmLO/kqM3IQHtISw==} + '@modelcontextprotocol/client@2.2.0': + resolution: {integrity: sha512-LxCou/CSYQ6dwEnjhLZY0KnEuc8V4UJ3IEQCl/uR2yHobSQIEdJKUlKLRYRF5i5FqRGHy1eK7une3aAWDHLtig==} engines: {node: '>=20'} - '@modelcontextprotocol/core@2.0.0': - resolution: {integrity: sha512-pJCEwGG7Lfr/+PQp9ZTwKXNeO5wzbfKL7H3MYpCorM4oFBoQrdjnBgEoqG+RjhsvS1FKrDbKux+M1HhlnGWqcA==} + '@modelcontextprotocol/core@2.2.0': + resolution: {integrity: sha512-iLhmprRmWI8EcosOA3wVvww22z02NkgqhV4fBH6f/odQBsi7xnJc0HGmi21yWO+/iKw2yzqVE127Zhna5/+JXw==} engines: {node: '>=20'} '@mswjs/interceptors@0.41.9': @@ -4779,8 +4778,8 @@ packages: '@types/ms@2.1.0': resolution: {integrity: sha512-GsCCIZDE/p3i96vtEqx+7dBUGXrc7zeSK3wwPHIaRThS+9OhWIXRqzs4d6k1SVU8g91DrNRWxWUGhp5KXQb2VA==} - '@types/node@26.6.1': - resolution: {integrity: sha512-VqGJBMCtdhqkBUCcBLvywI0NJ+KLuVzgNnlBUNFOQjqVxzo2lxLUNg1DSey8+u2u6ktswSAxg+s68QLzWHNOuA==} + '@types/node@26.6.3': + resolution: {integrity: sha512-dsqMQQoeTLqu9wynDD00q573mNzso3IdQOAfHRJqLCcmCFPoGo9A1bDpUcv/9tnKpErQWv9uKeGfl37EIS02Yg==} '@types/semver@7.8.0': resolution: {integrity: sha512-1mAINjtQCXXeLkJ9ehXkwOcBpqtLxiVtKhpUf83DdRNdQKV0iXZpaHYqRr7nj+wvxuJzoAmAwXI+sCNMv1CzLQ==} @@ -4803,8 +4802,8 @@ packages: cpu: [arm64] os: [darwin] - '@typescript/typescript-darwin-arm64@7.1.0-dev.20260917.1': - resolution: {integrity: sha512-Xh+k4mgp9YZKZNsvqF3qJmXuBsdJ6O4wjY+++pliKvFXrSq7QUn2WjKnaKtIkU9XIXhTtHwdeaFVMwC2hOeCSg==} + '@typescript/typescript-darwin-arm64@7.1.0-dev.20260929.1': + resolution: {integrity: sha512-dJhNpxeVxqYqDL6K9cy63eqvzmnKEX39uv5ujbt7n73biiPK/gE3jkq6icwQz0dRZP8HKEhk6pmFb7Ytmt3PsA==} engines: {node: '>=16.20.0'} cpu: [arm64] os: [darwin] @@ -4815,8 +4814,8 @@ packages: cpu: [x64] os: [darwin] - '@typescript/typescript-darwin-x64@7.1.0-dev.20260917.1': - resolution: {integrity: sha512-n0RJzJsXMzm0SJ21awMCTd4DJJd7Qv80RRz5W2bM1qpqppb3eHZxgd6TmM5L0dobwkcHoYanfuJpQ1HzSNFr9Q==} + '@typescript/typescript-darwin-x64@7.1.0-dev.20260929.1': + resolution: {integrity: sha512-bx4Bc8v+WqXZUzRRI2j/jDP7/1aOmzRaakOEUnwH5ad5SA2gJcA5w+Vd+nxpANSIlJ0LE90sakFTUfWdyOKN6A==} engines: {node: '>=16.20.0'} cpu: [x64] os: [darwin] @@ -4839,8 +4838,8 @@ packages: cpu: [arm64] os: [linux] - '@typescript/typescript-linux-arm64@7.1.0-dev.20260917.1': - resolution: {integrity: sha512-E1nilsSSid1OI8rCZbzF+aRS46IkHecK3eRNZLECf5Uj8ASLmoi2UBghGjJM1T8UD/hgRKuSM2LvCkXN9AxPVQ==} + '@typescript/typescript-linux-arm64@7.1.0-dev.20260929.1': + resolution: {integrity: sha512-sJadLogwZGfSg25r+dWa8uSs+gk4x6i1PZ4bYge47PwJ6fGte1qRJyCYEb5bpbEISjvXeyDPhNbW/52d1RJWxQ==} engines: {node: '>=16.20.0'} cpu: [arm64] os: [linux] @@ -4851,8 +4850,8 @@ packages: cpu: [arm] os: [linux] - '@typescript/typescript-linux-arm@7.1.0-dev.20260917.1': - resolution: {integrity: sha512-y69VYKvcFKjojsytSPHdOUjbOeVpLZixBF9XwQeKac9Kz1o3Zjofv5geLekABJei8ShRyqVUy5QadOMbL3dczw==} + '@typescript/typescript-linux-arm@7.1.0-dev.20260929.1': + resolution: {integrity: sha512-z/wnfIGgl1PrlGEcetVhAAK9XBCymewKEA0L7O5zSXFai2bICayx+amWr4KYLJhevkI7h3yxM7CBrTWWj+jDWw==} engines: {node: '>=16.20.0'} cpu: [arm] os: [linux] @@ -4893,8 +4892,8 @@ packages: cpu: [x64] os: [linux] - '@typescript/typescript-linux-x64@7.1.0-dev.20260917.1': - resolution: {integrity: sha512-oAR9Aq3n1LFpUrLkc8cBdODA2NKDnMCPcjdBrdDTYvIUe2TFyzSTTU8z2Njwe2Eaoo8HInqCqQ3MG7tZ7FWsqA==} + '@typescript/typescript-linux-x64@7.1.0-dev.20260929.1': + resolution: {integrity: sha512-y5zegerny0t8PCsluQNzMKO9xoYvqyYD+TA3Io7yj2crikm1Y4TUMpj/2VyHX75g+G5IllGbGnaNI8UFKUQ2Fg==} engines: {node: '>=16.20.0'} cpu: [x64] os: [linux] @@ -4935,8 +4934,8 @@ packages: cpu: [arm64] os: [win32] - '@typescript/typescript-win32-arm64@7.1.0-dev.20260917.1': - resolution: {integrity: sha512-8jAa6rnRPuTrKL2fvd8Ta1lpzqGz4ijiM+klXywzELOwDu85QYF72uFFkDnkSPa1kbIFgaDqqSu5Q+YwQKTpXQ==} + '@typescript/typescript-win32-arm64@7.1.0-dev.20260929.1': + resolution: {integrity: sha512-4PE8d8xizDqmkrmisJdk161f9Tpv3Fx6vEW7E7sjd1YeERA9fijdtsjdefXOfDLMwsEJMHJOsTpJ6D0Uj0fQbg==} engines: {node: '>=16.20.0'} cpu: [arm64] os: [win32] @@ -4947,8 +4946,8 @@ packages: cpu: [x64] os: [win32] - '@typescript/typescript-win32-x64@7.1.0-dev.20260917.1': - resolution: {integrity: sha512-pVNBDlAK3H68thFAESvPuxKqsWK71dU4SZ8DZbaw9vPhS+fyJdSAYxPxZjCh7vA9JaBiO05qxwI8ioC9ZtdIHg==} + '@typescript/typescript-win32-x64@7.1.0-dev.20260929.1': + resolution: {integrity: sha512-2FrwvlLkwL3c3fsI2xsehk1C7bNj/eBrCIq3NnwVWZdURlX/l3MaZhkq4lfnH/cjLlDvzTpJOR6m44E9TGI+oA==} engines: {node: '>=16.20.0'} cpu: [x64] os: [win32] @@ -4957,11 +4956,11 @@ packages: resolution: {integrity: sha512-oL0uqC5cROkhhVqeGQ4h0CeGYPwkc+tu/dPyfUcmdA2tKpa0o9x5L5L+nu/FeWsqMoO/OjAqHQDCUF0bqVNVwQ==} engines: {node: '>=18'} - '@vitest/coverage-v8@5.0.1': - resolution: {integrity: sha512-FRC8ACiudC3dI6MTplzRSYWHDRnIv2IPfbzs4FdoJNsMal/35sWV8hwIfV8ZcqzSPy+uXHeMVONt9CEqtOU17w==} + '@vitest/coverage-v8@5.0.2': + resolution: {integrity: sha512-3ffHBEi8DOOBLwIGBhOBZbRfYFYWjMUuxZicONdhuFEFEG5AVsMOSrVeuROskqnqpbOmEJwxM2eTVZ9N3a1t+A==} peerDependencies: - '@vitest/browser': 5.0.1 - vitest: 5.0.1 + '@vitest/browser': 5.0.2 + vitest: 5.0.2 peerDependenciesMeta: '@vitest/browser': optional: true @@ -4974,36 +4973,36 @@ packages: resolution: {integrity: sha512-1EOLRfsTMnyAr3+kEAsP4o9dhaDlGPpD7H5iLBBeq//YpNB1VIahkPhB+eRp9N2Dkfw8oySROjE3yf9XDeaIkQ==} engines: {node: '>=22'} - '@vitest/mocker@5.0.1': - resolution: {integrity: sha512-6K1DoBNAPGvuOcSsGA4D6x+5zEEff/KmOOP3uetT2TrGpVfI+HRHRnJJfKi5ib/g1vx8IYHQD8s0pbJz8WQI7Q==} + '@vitest/mocker@5.0.2': + resolution: {integrity: sha512-Z5FS00Q1SJHkB35xATsmWGdQ5WA1/0MV3CDjqyv7GavHv1OfOj145MNfHOlHk7QLes21dKFDHr8EO2zvL+9WGA==} peerDependencies: msw: ^2.4.9 - vite: 8.3.0 + vite: 8.3.1 peerDependenciesMeta: msw: optional: true vite: optional: true - '@vitest/pretty-format@5.0.1': - resolution: {integrity: sha512-6guWwj5d9bguuefTOvJoq387tfpkzSv554YdUEGzjJH2PnnmvzTLQ1UQSuAk5wBFVhf2CUmy/S/palOcb6dmpA==} + '@vitest/pretty-format@5.0.2': + resolution: {integrity: sha512-YHM+mQQ7N1ROHMugJ7P/M+fC/q1G4zs/iAMZZCvhHcY8WkwPQcXBHD+z18oz+808Cfa12K7jOr3XPQMcLIovjw==} - '@vitest/spy@5.0.1': - resolution: {integrity: sha512-rbto/mF/SGERxEgYOek7Xm6B9b+y+mVoo+f4b2LymYO8zM1b7uB5nHuhVMTP2hxdzgxvGiZYGxGIaMvL5y180Q==} + '@vitest/spy@5.0.2': + resolution: {integrity: sha512-Ijc7T1nT9efNb5LxvjaBrEqw3f/QwUv5EE0nKqZxgqsaV/FxAAZ8baGylA8X/Z2oS4Lp+K74Jr6dTJsDKxJDeg==} - '@vitest/ui@5.0.1': - resolution: {integrity: sha512-7PvQu/X9/pQoHYfNLAYL22qsD4/+sx2k7zpUA7XvjW0sc40r3/r0lGZ2fsEyOHMuO8Q1KjiO1QQVjJdnWUy/WQ==} + '@vitest/ui@5.0.2': + resolution: {integrity: sha512-FRGWhLK/S+aaAtty/5d+jTtY5l+9pGNcjz6IHbyUiP3VWs6a+zIgU4lc1SzWCR7H+OXgetAI06i/VpCWQmVorQ==} peerDependencies: - vitest: 5.0.1 + vitest: 5.0.2 - '@vitest/utils@5.0.1': - resolution: {integrity: sha512-E9+yEA+jsfaoxZcUHFzEqUrQcoNh2EwrPT5efIqkUPUwD5Ua2Li9BRWaYeRwvzvdLgTSVrre8oKNeyrfg7KkdQ==} + '@vitest/utils@5.0.2': + resolution: {integrity: sha512-mgpUtxFhKeOKVaArBVHNJGdYHAeRh135o59l13uVmPUCS1OUtis5pBqXEgE25iqRgFqEBwXvJlkhknRsYnMeqg==} '@vitiate/core@0.3.1': resolution: {integrity: sha512-VFej4WEPuOsenIfMEROl0CkvPeZNZXYtL+p5XQEukoRCkWhVYZNlEHcNTysyzDpvQz7+gGM6LzJQZ9lkh5yzJw==} engines: {node: '>= 18'} peerDependencies: - vite: 8.3.0 + vite: 8.3.1 vitest: '>=3.1.0' '@vitiate/engine-darwin-arm64@0.3.1': @@ -5061,8 +5060,8 @@ packages: resolution: {integrity: sha512-WMWoiPFD+DdQTWu+Imv6OGME5X3IBxx2W+626x+YqJ+G+tUFB6Ulwppobofz+ydymhx9vvfQMbV29hGd7fZfNQ==} engines: {node: '>= 18'} - ansi-regex@6.3.0: - resolution: {integrity: sha512-WpDfL7NO6j7tH88IDBNVdUJxDh9nmCteAVW9dsep846XdwF4naCBK+/tGLX3KJgcpgMRXCFlTM2hKGoK9FsdrQ==} + ansi-regex@6.4.0: + resolution: {integrity: sha512-KzTVk2tCWAHtYrvvvaP8bJKJq2pVinhLcGEQdtLIYPbmNGNyYe8QwNaTUYQp2J7/vIsUKt5QCqAfUkYyG9DkOw==} engines: {node: '>=12'} ansi-styles@4.3.0: @@ -5083,11 +5082,11 @@ packages: resolution: {integrity: sha512-Izi8RQcffqCeNVgFigKli1ssklIbpHnCYc6AknXGYoB6grJqyeby7jv12JUQgmTAnIDnbck1uxksT4dzN3PWBA==} engines: {node: '>=12'} - ast-v8-to-istanbul@1.0.6: - resolution: {integrity: sha512-fvpl29helSO2w/z7utIbrkNXILdrLwDwAMH2I/zPKlGf5244+gf+B4cyS1sANcrPY2h+hWCGSgC8N61s/+AF9A==} + ast-v8-to-istanbul@1.0.7: + resolution: {integrity: sha512-kFL68AG6ajd8fg248zwM9GQrUWEp79gsmjum34OEXjs4yHuUMZfYKwOLW9GMmB4oNvVrj+EAGxsP7ye2UR9UlA==} - ata-validator@1.27.1: - resolution: {integrity: sha512-FFbzRalSLW0poT+FGzgOMV755z6suwvQoFKFxlwBzxuy9E+HpOSsh+TODhiV70ym8DhQhbmTNFiNdZBdd5dTsQ==} + ata-validator@1.39.1: + resolution: {integrity: sha512-7a1nLMiZ+sIuSD4lfLW7YTbEbOy8V33zayDcoNy46R/4LlrRg1hvdcBWOEt2LTOtwpjnwEAaDokPQF20IbP6xw==} engines: {node: '>=20.0.0'} hasBin: true peerDependencies: @@ -5168,8 +5167,8 @@ packages: chownr@1.1.4: resolution: {integrity: sha512-jJ0bqzaylmJtVnNgzTeSOs8DPavpbYgEr/b0YL8/2GO3xJEhInFmhKMUnEJQjZumK7KXGFhUy89PrsJWlakBVg==} - chrome-devtools-mcp@1.9.0: - resolution: {integrity: sha512-RnzXoJiUQ44hpOihWk90uOhLD/CnwDkDy0ldHMZONJ2nYQ+dWN1fq1luHHqyd+7FuYnyIlCY6uTThbN5ut9kSQ==} + chrome-devtools-mcp@1.10.1: + resolution: {integrity: sha512-Klw6HWDqHC/XS1JwZldd2r49aUhbUJN9m9Mvcx4SEueIPXtzuQX+QelxAViobv8YUkDZ7HWDrmViR6LeYK0wAw==} engines: {node: ^20.19.0 || ^22.12.0 || >=23} hasBin: true peerDependencies: @@ -5340,18 +5339,18 @@ packages: resolution: {integrity: sha512-KfYbmpRm0VbLjEvVa9yGwCi9GI34xvi7A/HXYWQO65CSD2u3MczUJSuwXKFIxlGsgBQizV9q5J9NHj4VG0n+pA==} engines: {node: '>=12.0.0'} - fallow-type-aware@3.27.0: - resolution: {integrity: sha512-8wUV7b3ss/ApbLDy+I67xvkmpcy/eAcZCtbp6Dcwg75AzPHD2Gpte9j95ZLx1i2UDqohKbFfovUiTx3xs4ma3w==} + fallow-type-aware@3.30.0: + resolution: {integrity: sha512-I/PDTJVhQkgFzNiPiEpL6D7zmg8sjow55qIZYWu9bzpfwGt9zxepnGykTqmqLVHh4e7QWpjzjjNcPimQAVeDFw==} engines: {node: '>=20'} hasBin: true - fallow@3.27.0: - resolution: {integrity: sha512-ZTImVVtqPK6ya68XoFP+uoOLGYX6UTWpXOTfIZCs6QyFygEv5v5BZ7jmdUfOGs27BcpzPlfGXKYovR778MO7Ow==} + fallow@3.30.0: + resolution: {integrity: sha512-+TPkF4TjdmYuT3WC6NxLwnaIL6RWPtBIu8ue0RBSQWmLrATMc4lNm8jEhXIy2jbgTk3RTs+0i6NZZZo7AzK0SQ==} engines: {node: '>=22'} hasBin: true - fast-check@4.10.1: - resolution: {integrity: sha512-sB5Vghiu8MyCyToHoBVGsT0baZg3sZWNIY+a6Ct2EDrQJlT4YdH6MC1BSLNe3kX1k5i5g0q1O52XFgcKK/rGHg==} + fast-check@4.10.2: + resolution: {integrity: sha512-iK2f+YrcmoeGqk6fA0ea2bptcu/itMIm4NfEozq6N25+aG6h7s5HZbB/k1aV7b5w5sFLMCbbtRUsTVR+BgC3xw==} engines: {node: '>=12.17.0'} fast-glob@3.3.3: @@ -5415,8 +5414,8 @@ packages: resolution: {integrity: sha512-Wjlyrolmm8uDpm/ogGyXZXb1Z+Ca2B8NbJwqBVg0axK9GbBeoS7yGV6vjXnYdGm6X53iehEuxxbyiKp8QmN4Vw==} engines: {node: 18 || 20 || >=22} - globby@16.2.2: - resolution: {integrity: sha512-NLvV9ubZ6NDsJaOpKPy3cQeJpKi9DcWiyCiFUpJPA0YihRqiE6RWaLUmgNNPr8MgPpLZjnBjSmou7uZBRJv9wA==} + globby@16.2.4: + resolution: {integrity: sha512-c8B/VNLmxRcmqqenRA9t+9IyOjf9+V6lTxPaUJLqOCONdQkWZ0ETYgX0qbtJqPsgCNusT9MZ5Jeidw8Eb9tn2g==} engines: {node: '>=20'} grad-school@0.0.5: @@ -5509,8 +5508,8 @@ packages: js-tokens@10.0.0: resolution: {integrity: sha512-lM/UBzQmfJRo9ABXbPWemivdCW8V2G8FHaHdypQaIy523snUjog0W71ayWXTjiR+ixeMyVHN2XcpnTd/liPg/Q==} - js-yaml@5.2.2: - resolution: {integrity: sha512-dayzUzKkJ1MkuUtZglSebU43utNXH0OWQByK9rKOOuYIO8M5TV1y+n8ALMdG0rdzBnfNkOmZEqrURepb0ejqBw==} + js-yaml@5.4.1: + resolution: {integrity: sha512-28R/k+NAjeuf7+CKlTxWZVExJGwVVLwY06DgEnOMz2gEpfNkDcD7QvyiVPT0xy0XXhU8vHsd4Ot42OOPdJG7dQ==} hasBin: true jsesc@3.1.0: @@ -5622,12 +5621,12 @@ packages: longest-streak@3.1.0: resolution: {integrity: sha512-9Ri+o0JYgehTaVBBDoMqIl8GXtbWg711O3srftcHhZ0dqnETqLaoIK0x17fUw9rFSlK/0NlsKe0Ahhyl5pXE2g==} - lru-cache@11.5.2: - resolution: {integrity: sha512-4pfM1Ff0x50o0tQwb5ucw/RzNyD0/YJME6IVcStalZuMWxdt3sR3huStTtxz4PUmvZfRguvDejasvQ2kifR11g==} + lru-cache@11.5.3: + resolution: {integrity: sha512-U4N8FgzmWxc8k1VH8Kr6lQg18U7Fjvby6wXHVRX/ZZ7IwWbRMgrRbP0Wrb5q5NVinryp4SQampHKdvtecItxUg==} engines: {node: 20 || >=22} - magic-string@1.4.1: - resolution: {integrity: sha512-8lyCu36ErXR0J9uaGKlKQoiLZKmtI63YGLE8G2o9jyRPdr4X47LusSOwgOJOzcVtp81fTAAjxR7BwKz682Jhow==} + magic-string@1.4.2: + resolution: {integrity: sha512-vG+rjFRj1PqdIBozIxAGMjPlOhaVe+GXpbttY/iSK7rGcJRMlwNJO7dcUwmUqkymsFLJiNGI06t4D7Fr7yRC9g==} magicast@0.5.5: resolution: {integrity: sha512-UicdXN8zQ3JHlxVq+28afMXPr1z7WNY6+7EJnzTdQWkTAlMLF5fNCCKxJHBQwGaNGR11581EiQmQzx73+MvszA==} @@ -5648,8 +5647,8 @@ packages: peerDependencies: markdownlint-cli2: '>=0.0.4' - markdownlint-cli2@0.23.2: - resolution: {integrity: sha512-eUhcnkSpzURo/o4htSqc7LPDszgOOTknhU4eY/sPHvMCLxnTCYscv1gw1/js/idmaZPisv9ECVEIORcllqjTUw==} + markdownlint-cli2@0.23.3: + resolution: {integrity: sha512-xAr5o/TGpC3v6lE6cKIW4b5eOFRrRX5u7Vtjae9ix3RALv8nNOd94XMkD/1OXXBtpMcJ4uQGbpSo3hv5UqS4uQ==} engines: {node: '>=22'} hasBin: true @@ -5704,8 +5703,8 @@ packages: mdast-util-phrasing@4.1.0: resolution: {integrity: sha512-TqICwyvJJpBwvGAMZjj4J2n0X8QWp21b9l0o7eXyVJ25YNWYbJDVIyD1bZXE6WtV6RmKJVYmQAKWa0zWOABz2w==} - mdast-util-to-markdown@2.1.2: - resolution: {integrity: sha512-xj68wMTvGXVOKonmog6LwyJKrYXZPvlwabaryTjLh9LuvovB/KAH+kvi8Gjj+7rJjsFi23nkUxRQv1KqSroMqA==} + mdast-util-to-markdown@2.1.3: + resolution: {integrity: sha512-wgyJtgUkUcdU7zci7uuwc/tzoAhm0TswWhaXuvnWolqug+8jY7bgNkBBL0dYBnHgc/tHL7lCzRdPsdUxUKKBqw==} mdast-util-to-string@4.0.0: resolution: {integrity: sha512-0H44vDimn51F0YwvxSJSm0eCDOJTRlmN0R1yBh4HLj9wiV1Dn0QoXGbvFAWj2hSItVTlCmBF1hqKlIyUBVFLPg==} @@ -5787,6 +5786,9 @@ packages: micromark-util-decode-string@2.0.1: resolution: {integrity: sha512-nDV/77Fj6eH1ynwscYTOsbK7rR//Uj0bZXBwJZRfaLEJ1iGBR6kIfNmlNqaqJf649EP0F3NWNdeJi03elllNUQ==} + micromark-util-edit-map@1.0.0: + resolution: {integrity: sha512-Pa2ljlsEL6sVwFaYeyrOLSYbQt73JvGbPOYFq+9AElXiSnfI5Q4465RRZ1sHv7lDjDOnGRDDaqPXqClqWK/q1Q==} + micromark-util-encode@2.0.1: resolution: {integrity: sha512-c3cVx2y4KqUnwopcO9b/SCdo2O67LwJJ/UyqGfbigahfegL9myoEFoDYZgkT7f36T0bLrM9hZTAaAyH+PCAXjw==} @@ -5814,6 +5816,9 @@ packages: micromark@4.0.2: resolution: {integrity: sha512-zpe98Q6kvavpCr1NPVSCMebCKfD7CA2NqZ+rykeNhONIJBpc1tFKt9hucLGwha3jNTNI8lHpctWJWoimVF4PfA==} + micromark@4.0.3: + resolution: {integrity: sha512-oGYfQzHSG5dOMovQcJ3fyTmZlWAWpi0XA0sJwJs+i6OT88o1+Jtw/8z0CmdowSLxGhhFK89rQ/oXph/wN02PNw==} + micromatch@4.0.8: resolution: {integrity: sha512-PXwfBhYu0hBCPw8Dn0E+WDYb7af3dSLVWKi3HGv84IdF4TyFoC0ysxFd0Goxw7nSv4T/PzEJQxsYsEiFCKo2BA==} engines: {node: '>=8.6'} @@ -5884,6 +5889,10 @@ packages: resolution: {integrity: sha512-XrsrhT5sybtKI6wakr2SPOlGZWWYbUXZ7a0jT8/QOeAPau+1X/bSegNe5YR75oJmEZQbKningirmGOEJCIk61Q==} engines: {node: '>=12.20.0'} + obug@3.0.0: + resolution: {integrity: sha512-5vvB5+W7ePv+p3uqxi+RcW1XAzLW0/hxt3/4X4Lc4qHudzOhmBiBwOY6DRob4WnanAEGvNcLjF+KNOufrUoEQw==} + engines: {node: '>=12.20.0'} + ofetch@1.5.1: resolution: {integrity: sha512-2W4oUZlVaqAPAil6FUg/difl6YhqhUR7x2eZY4bQCko22UXg3hptq9KLQdqFClV+Wu85UX7hNtdGTngi/1BxcA==} @@ -6046,8 +6055,8 @@ packages: resolution: {integrity: sha512-9u/sniCrY3D5WdsERHzHE4G2YCXqoG5FTHUiCC4SIbr6XcLZBY05ya9EKjYek9O5xOAwjGq+1JdGBAS7Q9ScoA==} engines: {node: '>= 6'} - regjsparser@0.13.2: - resolution: {integrity: sha512-NgRBy2Nx/bE+9F27nVHnqcN5HjyLmecqsqx2PJHu3/IEtADD4WuxuXIVExD5PoSDFVrl78dOonfcOe5O+5nbzQ==} + regjsparser@0.13.3: + resolution: {integrity: sha512-ycwFAS14Jw4mppvmK4GR/J6u3WpWpjkEApehuHtLc/8VpPNpDMbQ4WjqwplXifGeyKOzHSFLmSPqzksDQE2Sfg==} hasBin: true require-directory@2.1.1: @@ -6095,13 +6104,10 @@ packages: resolution: {integrity: sha512-7++dFhtcx3353uBaq8DDR4NuxBetBzC7ZQOhmTQInHEd6bSrXdiEyzCvG07Z44UYdLShWUyXt5M/yhz8ekcb1A==} engines: {node: '>=8'} - shell-quote@1.10.0: - resolution: {integrity: sha512-w1aiOKwKuRgtwAReIIj89puqg+I7GvX4IbLrvmhXbzQsj1+Zwi4VO3+fa6ZF91TWSjIxoEkKnMeHcLEODK5ZXA==} + shell-quote@1.11.0: + resolution: {integrity: sha512-JdxDPD0DBTyu08pq0kPC0xSNet/qsU07qT6IsX1AS8oO2ICNRY4ldNa8OAI6PuwAH8tG3lxEhbqmyp4Dw4036g==} engines: {node: '>= 0.4'} - siginfo@2.0.0: - resolution: {integrity: sha512-ybx0WO1/8bSBLEWXZvEd7gMW3Sn3JFlW3TvX1nREbDLRNQNaeNN8WK0meBwPdAaOI7TtRRRJn/Es1zhrrCHu7g==} - signal-exit@4.1.0: resolution: {integrity: sha512-bzyZ1e88w9O1iNJbKnOlvYTrWPDl46O1bG0D3XInv+9tkPrxrN8jUUTiFlDkkmKWgn1M6CfIA13SuGqOa9Korw==} engines: {node: '>=14'} @@ -6114,8 +6120,8 @@ packages: resolution: {integrity: sha512-ZA6oR3T/pEyuqwMgAKT0/hAv8oAXckzbkmR0UkUosQ+Mc4RxGoJkRmwHgHufaenlyAgE1Mxgpdcrf75y6XcnDg==} engines: {node: '>=14.16'} - smol-toml@1.7.0: - resolution: {integrity: sha512-aqVvWoyO21L23mb+drl4RmMXbf6N7FdHjAhTRA9ZBL7apWBgfWC16KjrASI+1p9GAroljyMHj6fK67i0UiTNvQ==} + smol-toml@1.8.0: + resolution: {integrity: sha512-kCZr2V3ch9i00x8zXRhjUNVcjG9ijES5dDudkXvUVCT5QlJNQWElSJdZqyPemffHoLNUYwOcou0Fy+ojN0uHSQ==} engines: {node: '>= 18'} source-map-js@1.2.1: @@ -6129,9 +6135,6 @@ packages: resolution: {integrity: sha512-wPldCk3asibAjQ/kziWQQt1Wh3PgDFpC0XpwclzKcdT1vql6KeYxf5LIt4nlFkUeR8WuphYMKqUA56X4rjbfgQ==} engines: {node: '>=10.16.0'} - stackback@0.0.2: - resolution: {integrity: sha512-1XMJE5fQo1jGH6Y/7ebnwPOBEkIEnT4QF32d5R1+VXdXveM0IBMJt8zfaxX1P3QhVwrYe+576+jkANtSS2mBbw==} - statuses@2.0.2: resolution: {integrity: sha512-DvEy55V3DB7uknRo+4iOGT5fP1slR8wQohVdknigZPMpMstaKJQWhwiYBACJE3Ul2pTnATihhBYnRhZQHGBiRw==} engines: {node: '>= 0.8'} @@ -6142,8 +6145,8 @@ packages: strict-event-emitter@0.5.1: resolution: {integrity: sha512-vMgjE/GGEPEFnhFub6pa4FmJBRBVOLpIII2hvCZ8Kzb7K0hlHo7mQv6xYrBvCL2LtAIBwFUK8wvuJgTVSQ5MFQ==} - string-width@8.2.2: - resolution: {integrity: sha512-GaPUh5gfdrYzqeVNZvUfT23vYYxXzKYidUcnMtJg/3rxRV63EFZy3k6xfKlmfeJD0176lnUV/Usr3XcwSvFzpg==} + string-width@8.3.0: + resolution: {integrity: sha512-ZbmZM0JCihQN91dWnxoipT2KOEyHqEyfRXUyjuRhW8b/xnqPDoq4gWEVApTVa9db2wN8mmoikgFBbjh71+cGeQ==} engines: {node: '>=20'} string_decoder@1.3.0: @@ -6172,8 +6175,8 @@ packages: resolution: {integrity: sha512-ujeqbceABgwMZxEJnk2HDY2DlnUZ+9oEcb1KzTVfYHio0UE6dG71n60d8D2I4qNvleWrrXpmjpt7vZeF1LnMZQ==} engines: {node: '>=6'} - taze@21.1.0: - resolution: {integrity: sha512-NkFkadmqqpaVZ9x3bV4cul1xQnUknhs1HzE3Q/VXHKS7np2Kg7ZNL7nNsEsBXKsafmgepa+aZNtzoegDgsymPw==} + taze@21.3.0: + resolution: {integrity: sha512-9l1x5+weSLJvxO0ImL8hIukVbmNSotTS0Fe47J8TRucL+3htVIzh53YRMqQldsqYXHsBH90bca3LoXN1cLV6Ng==} hasBin: true test-exclude@8.0.0: @@ -6227,8 +6230,8 @@ packages: resolution: {integrity: sha512-faYHw0anBbc/kWF3zFTEnxSFOAGUX9GFbOBthvDdLsIlEoWOFOtS0zgCiQYwIskL9iGXZL3kAXD8OoZ4GmMATA==} engines: {node: '>= 18'} - typebox@1.3.33: - resolution: {integrity: sha512-25XRfVMsTPaaS4RvZf+wsM8U34cKWSRHBTbHSlCvEqGkvqXNHyfrynOC1h2ma1m8A5UpCJglVRAPK5ORpfPyFg==} + typebox@1.3.34: + resolution: {integrity: sha512-wbnzrXXDW8xEFHDZZs2jo1MkhaYlKAY4FRhpBc1+2LF1fZVBGCXGdLEhA/Z/NBbgzJMFfeM8m7elKPa/+KxaUQ==} typescript@5.9.3: resolution: {integrity: sha512-jl1vZzPDinLr9eUt3J/t7V6FgNEw9QjvBPdysz9KfQDD41fQrC2Y4vKQdiaUpFT4bXlb1RHhLpp8wtm6M5TgSw==} @@ -6240,8 +6243,8 @@ packages: engines: {node: '>=16.20.0'} hasBin: true - typescript@7.1.0-dev.20260917.1: - resolution: {integrity: sha512-War5cgUqD2+S+n+HwhIRfCurpK/VSKeKnaxeeeQLU9zzA40b/l0saBL1vFlBpIFvUApyuerxxNSqEhqtiFbhmw==} + typescript@7.1.0-dev.20260929.1: + resolution: {integrity: sha512-ZFhJbdPZYLrgNjUL2ZimvvQ1hYKyZVoZpfNcZyfVZBukWU5ui/ovGPbOZOaXsogyXWmGhCv3H/2VIa2NFV44OA==} engines: {node: '>=16.20.0'} hasBin: true @@ -6295,12 +6298,12 @@ packages: typescript: optional: true - verkit@0.3.2: - resolution: {integrity: sha512-zj/ob3UsvJGN0whEAKFp53REA5X66hvffVqoCtVQAakJKnKlH+/PcOfMoFwIG/o4rElqLv/ycAFlx8ZlXUorCg==} + verkit@0.5.0: + resolution: {integrity: sha512-u4J1hr6Y+C/hit34GwL3eIcUf3wngT8TlYUjK7tk0jxydKLAq3sYvifjdTDA6U3KCKRcQCQDGf/srjxfZF3l7g==} engines: {node: '>=18.12.0'} - vite@8.3.0: - resolution: {integrity: sha512-lhZBVvEHefgE+HQZC9O7EBJgCU/nVzFNl7vkS4RE0APtWLP02/8QVIkQtzBxPquh7lq5/78NHipTj7ODQ6XuyQ==} + vite@8.3.1: + resolution: {integrity: sha512-/bvH9E9tmCXRGp2uXY3WbOldqpTwFkbha/8ANaEQ6VkxhH60KyqLwgZq6lG2y+4uT55x9+9eUHMpQ7uGnOCKjA==} engines: {node: ^20.19.0 || >=22.12.0} hasBin: true peerDependencies: @@ -6342,23 +6345,23 @@ packages: yaml: optional: true - vitest@5.0.1: - resolution: {integrity: sha512-iA95lQbKEkvrtTkdAgnWbXfbipWiiWe/hDl2P5tMi6WFwD76G0NxXAGp/M9EOcYupeGJRr6wppMc7CoA41TQjg==} + vitest@5.0.2: + resolution: {integrity: sha512-7MQrx9pDv5aHiUcovIb/70Ys3tgtkUVgCtledvKdCmEO+/1Dicq5ZqoSxOW034m03oqC+oHOKui2dM6qtMLoJg==} engines: {node: ^22.12.0 || ^24.0.0 || >=26.0.0} hasBin: true peerDependencies: '@edge-runtime/vm': '*' '@opentelemetry/api': ^1.9.0 '@types/node': ^22.0.0 || >=24.0.0 - '@vitest/browser-playwright': 5.0.1 - '@vitest/browser-preview': 5.0.1 + '@vitest/browser-playwright': 5.0.2 + '@vitest/browser-preview': 5.0.2 '@vitest/browser-webdriverio': ^5.0.0-beta.5 || >=5.0.0 - '@vitest/coverage-istanbul': 5.0.1 - '@vitest/coverage-v8': 5.0.1 - '@vitest/ui': 5.0.1 + '@vitest/coverage-istanbul': 5.0.2 + '@vitest/coverage-v8': 5.0.2 + '@vitest/ui': 5.0.2 happy-dom: '*' jsdom: '*' - vite: 8.3.0 + vite: 8.3.1 peerDependenciesMeta: '@edge-runtime/vm': optional: true @@ -6388,9 +6391,9 @@ packages: engines: {node: ^22.22.2 || ^24.15.0 || >=26.0.0} hasBin: true - why-is-node-running@2.3.0: - resolution: {integrity: sha512-hUrmaWBdVDcxvYqnyh09zunKzROWjbZTiNy8dBEjkS7ehEDQibXJ7XvlmtbwuTclUiIyN+CyXQD4Vmko8fNm8w==} - engines: {node: '>=8'} + why-is-node-running@3.2.1: + resolution: {integrity: sha512-Tb2FUhB4vUsGQlfSquQLYkApkuPAFQXGFzxWKHHumVz2dK+X1RUm/HnID4+TfIGYJ1kTcwOaCk/buYCEJr6YjQ==} + engines: {node: '>=20.11'} hasBin: true wrap-ansi@7.0.0: @@ -6455,7 +6458,7 @@ snapshots: cronstrue: 2.59.0 yaml: 2.9.1 - '@antfu/ni@30.5.0': + '@antfu/ni@30.6.0': dependencies: fzf: 0.5.2 package-manager-detector: 1.8.0 @@ -6464,25 +6467,25 @@ snapshots: '@arr/every@1.0.1': {} - '@ata-validator/native-darwin-arm64@1.27.1': + '@ata-validator/native-darwin-arm64@1.39.1': optional: true - '@ata-validator/native-darwin-x64@1.27.1': + '@ata-validator/native-darwin-x64@1.39.1': optional: true - '@ata-validator/native-linux-arm64-gnu@1.27.1': + '@ata-validator/native-linux-arm64-gnu@1.39.1': optional: true - '@ata-validator/native-linux-arm64-musl@1.27.1': + '@ata-validator/native-linux-arm64-musl@1.39.1': optional: true - '@ata-validator/native-linux-x64-gnu@1.27.1': + '@ata-validator/native-linux-x64-gnu@1.39.1': optional: true - '@ata-validator/native-linux-x64-musl@1.27.1': + '@ata-validator/native-linux-x64-musl@1.39.1': optional: true - '@ata-validator/native-win32-x64@1.27.1': + '@ata-validator/native-win32-x64@1.39.1': optional: true '@babel/helper-string-parser@7.29.7': {} @@ -6502,28 +6505,28 @@ snapshots: '@bcoe/v8-coverage@1.0.2': {} - '@fallow-cli/darwin-arm64@3.27.0': + '@fallow-cli/darwin-arm64@3.30.0': optional: true - '@fallow-cli/darwin-x64@3.27.0': + '@fallow-cli/darwin-x64@3.30.0': optional: true - '@fallow-cli/linux-arm64-gnu@3.27.0': + '@fallow-cli/linux-arm64-gnu@3.30.0': optional: true - '@fallow-cli/linux-arm64-musl@3.27.0': + '@fallow-cli/linux-arm64-musl@3.30.0': optional: true - '@fallow-cli/linux-x64-gnu@3.27.0': + '@fallow-cli/linux-x64-gnu@3.30.0': optional: true - '@fallow-cli/linux-x64-musl@3.27.0': + '@fallow-cli/linux-x64-musl@3.30.0': optional: true - '@fallow-cli/win32-arm64-msvc@3.27.0': + '@fallow-cli/win32-arm64-msvc@3.30.0': optional: true - '@fallow-cli/win32-x64-msvc@3.27.0': + '@fallow-cli/win32-x64-msvc@3.30.0': optional: true '@grpc/grpc-js@1.14.4': @@ -6553,11 +6556,11 @@ snapshots: '@js-sdsl/ordered-map@4.4.2': {} - '@mdn/browser-compat-data@8.1.2': {} + '@mdn/browser-compat-data@8.1.3': {} - '@modelcontextprotocol/client@2.0.0': + '@modelcontextprotocol/client@2.2.0': dependencies: - '@modelcontextprotocol/core': 2.0.0 + '@modelcontextprotocol/core': 2.2.0 cross-spawn: 7.0.6 eventsource: 3.0.7 eventsource-parser: 3.1.1 @@ -6565,7 +6568,7 @@ snapshots: pkce-challenge: 5.0.1 zod: 4.6.2 - '@modelcontextprotocol/core@2.0.0': + '@modelcontextprotocol/core@2.2.0': dependencies: zod: 4.6.2 @@ -6841,9 +6844,9 @@ snapshots: '@socketregistry/side-channel@1.0.10': {} - '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260917.1)': + '@socketsecurity/lib@7.0.3(typescript@7.1.0-dev.20260929.1)': optionalDependencies: - typescript: 7.1.0-dev.20260917.1 + typescript: 7.1.0-dev.20260929.1 '@socketsecurity/sdk@4.1.5': {} @@ -6930,7 +6933,7 @@ snapshots: '@types/ms@2.1.0': {} - '@types/node@26.6.1': + '@types/node@26.6.3': dependencies: undici-types: 8.9.0 @@ -6946,13 +6949,13 @@ snapshots: '@typescript/typescript-darwin-arm64@7.0.2': optional: true - '@typescript/typescript-darwin-arm64@7.1.0-dev.20260917.1': + '@typescript/typescript-darwin-arm64@7.1.0-dev.20260929.1': optional: true '@typescript/typescript-darwin-x64@7.0.2': optional: true - '@typescript/typescript-darwin-x64@7.1.0-dev.20260917.1': + '@typescript/typescript-darwin-x64@7.1.0-dev.20260929.1': optional: true '@typescript/typescript-freebsd-arm64@7.0.2': @@ -6964,13 +6967,13 @@ snapshots: '@typescript/typescript-linux-arm64@7.0.2': optional: true - '@typescript/typescript-linux-arm64@7.1.0-dev.20260917.1': + '@typescript/typescript-linux-arm64@7.1.0-dev.20260929.1': optional: true '@typescript/typescript-linux-arm@7.0.2': optional: true - '@typescript/typescript-linux-arm@7.1.0-dev.20260917.1': + '@typescript/typescript-linux-arm@7.1.0-dev.20260929.1': optional: true '@typescript/typescript-linux-loong64@7.0.2': @@ -6991,7 +6994,7 @@ snapshots: '@typescript/typescript-linux-x64@7.0.2': optional: true - '@typescript/typescript-linux-x64@7.1.0-dev.20260917.1': + '@typescript/typescript-linux-x64@7.1.0-dev.20260929.1': optional: true '@typescript/typescript-netbsd-arm64@7.0.2': @@ -7012,28 +7015,28 @@ snapshots: '@typescript/typescript-win32-arm64@7.0.2': optional: true - '@typescript/typescript-win32-arm64@7.1.0-dev.20260917.1': + '@typescript/typescript-win32-arm64@7.1.0-dev.20260929.1': optional: true '@typescript/typescript-win32-x64@7.0.2': optional: true - '@typescript/typescript-win32-x64@7.1.0-dev.20260917.1': + '@typescript/typescript-win32-x64@7.1.0-dev.20260929.1': optional: true '@ultrathink/acorn.rs.wasm@0.1.1': {} - '@vitest/coverage-v8@5.0.1(vitest@5.0.1)': + '@vitest/coverage-v8@5.0.2(vitest@5.0.2)': dependencies: '@bcoe/v8-coverage': 1.0.2 '@vitest/istanbul-lib-coverage': 1.0.1 '@vitest/istanbul-lib-report': 1.0.1 - ast-v8-to-istanbul: 1.0.6 + ast-v8-to-istanbul: 1.0.7 magicast: 0.5.5 obug: 2.2.1 std-env: 4.2.0 tinyrainbow: 3.1.1 - vitest: 5.0.1(patch_hash=065993cceebda16dedb4662626ed60c0aeb40f02240c8d0e540b4dc6d9674df2)(@types/node@26.6.1)(@vitest/coverage-v8@5.0.1)(@vitest/ui@5.0.1)(vite@8.3.0(@types/node@26.6.1)(jiti@2.7.0)(yaml@2.9.1)) + vitest: 5.0.2(@types/node@26.6.3)(@vitest/coverage-v8@5.0.2)(@vitest/ui@5.0.2)(vite@8.3.1(@types/node@26.6.3)(jiti@2.7.0)(yaml@2.9.1)) '@vitest/istanbul-lib-coverage@1.0.1': {} @@ -7041,38 +7044,38 @@ snapshots: dependencies: '@vitest/istanbul-lib-coverage': 1.0.1 - '@vitest/mocker@5.0.1(vite@8.3.0(@types/node@26.6.1)(jiti@2.7.0)(yaml@2.9.1))': + '@vitest/mocker@5.0.2(vite@8.3.1(@types/node@26.6.3)(jiti@2.7.0)(yaml@2.9.1))': dependencies: '@jridgewell/trace-mapping': 0.3.31 - '@vitest/spy': 5.0.1 + '@vitest/spy': 5.0.2 estree-walker: 3.0.3 - magic-string: 1.4.1 + magic-string: 1.4.2 optionalDependencies: - vite: 8.3.0(@types/node@26.6.1)(jiti@2.7.0)(yaml@2.9.1) + vite: 8.3.1(@types/node@26.6.3)(jiti@2.7.0)(yaml@2.9.1) - '@vitest/pretty-format@5.0.1': + '@vitest/pretty-format@5.0.2': dependencies: tinyrainbow: 3.1.1 - '@vitest/spy@5.0.1': {} + '@vitest/spy@5.0.2': {} - '@vitest/ui@5.0.1(vitest@5.0.1)': + '@vitest/ui@5.0.2(vitest@5.0.2)': dependencies: - '@vitest/utils': 5.0.1 + '@vitest/utils': 5.0.2 fflate: 0.8.3 flatted: 3.4.4 pathe: 2.0.3 sirv: 3.0.2 tinyrainbow: 3.1.1 - vitest: 5.0.1(patch_hash=065993cceebda16dedb4662626ed60c0aeb40f02240c8d0e540b4dc6d9674df2)(@types/node@26.6.1)(@vitest/coverage-v8@5.0.1)(@vitest/ui@5.0.1)(vite@8.3.0(@types/node@26.6.1)(jiti@2.7.0)(yaml@2.9.1)) + vitest: 5.0.2(@types/node@26.6.3)(@vitest/coverage-v8@5.0.2)(@vitest/ui@5.0.2)(vite@8.3.1(@types/node@26.6.3)(jiti@2.7.0)(yaml@2.9.1)) - '@vitest/utils@5.0.1': + '@vitest/utils@5.0.2': dependencies: - '@vitest/pretty-format': 5.0.1 + '@vitest/pretty-format': 5.0.2 convert-source-map: 2.0.0 tinyrainbow: 3.1.1 - '@vitiate/core@0.3.1(typescript@7.1.0-dev.20260917.1)(vite@8.3.0(@types/node@26.6.1)(jiti@2.7.0)(yaml@2.9.1))(vitest@5.0.1)': + '@vitiate/core@0.3.1(typescript@7.1.0-dev.20260929.1)(vite@8.3.1(@types/node@26.6.3)(jiti@2.7.0)(yaml@2.9.1))(vitest@5.0.2)': dependencies: '@optique/core': 1.1.0 '@optique/run': 1.1.0 @@ -7082,10 +7085,10 @@ snapshots: es-module-lexer: 2.3.2 escape-string-regexp: 5.0.0 ipaddr.js: 2.5.0 - magic-string: 1.4.1 - valibot: 1.5.0(typescript@7.1.0-dev.20260917.1) - vite: 8.3.0(@types/node@26.6.1)(jiti@2.7.0)(yaml@2.9.1) - vitest: 5.0.1(patch_hash=065993cceebda16dedb4662626ed60c0aeb40f02240c8d0e540b4dc6d9674df2)(@types/node@26.6.1)(@vitest/coverage-v8@5.0.1)(@vitest/ui@5.0.1)(vite@8.3.0(@types/node@26.6.1)(jiti@2.7.0)(yaml@2.9.1)) + magic-string: 1.4.2 + valibot: 1.5.0(typescript@7.1.0-dev.20260929.1) + vite: 8.3.1(@types/node@26.6.3)(jiti@2.7.0)(yaml@2.9.1) + vitest: 5.0.2(@types/node@26.6.3)(@vitest/coverage-v8@5.0.2)(@vitest/ui@5.0.2)(vite@8.3.1(@types/node@26.6.3)(jiti@2.7.0)(yaml@2.9.1)) transitivePeerDependencies: - '@swc/helpers' - typescript @@ -7123,7 +7126,7 @@ snapshots: '@vitiate/swc-plugin@0.3.1': {} - ansi-regex@6.3.0: {} + ansi-regex@6.4.0: {} ansi-styles@4.3.0: dependencies: @@ -7139,21 +7142,21 @@ snapshots: assertion-error@2.0.1: {} - ast-v8-to-istanbul@1.0.6: + ast-v8-to-istanbul@1.0.7: dependencies: '@jridgewell/trace-mapping': 0.3.31 estree-walker: 3.0.3 js-tokens: 10.0.0 - ata-validator@1.27.1(yaml@2.9.1): + ata-validator@1.39.1(yaml@2.9.1): optionalDependencies: - '@ata-validator/native-darwin-arm64': 1.27.1 - '@ata-validator/native-darwin-x64': 1.27.1 - '@ata-validator/native-linux-arm64-gnu': 1.27.1 - '@ata-validator/native-linux-arm64-musl': 1.27.1 - '@ata-validator/native-linux-x64-gnu': 1.27.1 - '@ata-validator/native-linux-x64-musl': 1.27.1 - '@ata-validator/native-win32-x64': 1.27.1 + '@ata-validator/native-darwin-arm64': 1.39.1 + '@ata-validator/native-darwin-x64': 1.39.1 + '@ata-validator/native-linux-arm64-gnu': 1.39.1 + '@ata-validator/native-linux-arm64-musl': 1.39.1 + '@ata-validator/native-linux-x64-gnu': 1.39.1 + '@ata-validator/native-linux-x64-musl': 1.39.1 + '@ata-validator/native-win32-x64': 1.39.1 yaml: 2.9.1 balanced-match@4.0.4: {} @@ -7232,17 +7235,17 @@ snapshots: chownr@1.1.4: {} - chrome-devtools-mcp@1.9.0: {} + chrome-devtools-mcp@1.10.1: {} cliui@8.0.1: dependencies: - string-width: 8.2.2 + string-width: 8.3.0 strip-ansi: 7.2.0 wrap-ansi: 7.0.0 cliui@9.0.1: dependencies: - string-width: 8.2.2 + string-width: 8.3.0 strip-ansi: 7.2.0 wrap-ansi: 9.0.2 @@ -7398,26 +7401,26 @@ snapshots: expect-type@1.4.0: {} - fallow-type-aware@3.27.0: + fallow-type-aware@3.30.0: dependencies: typescript: 7.0.2 optional: true - fallow@3.27.0: + fallow@3.30.0: dependencies: detect-libc: 2.1.2 optionalDependencies: - '@fallow-cli/darwin-arm64': 3.27.0 - '@fallow-cli/darwin-x64': 3.27.0 - '@fallow-cli/linux-arm64-gnu': 3.27.0 - '@fallow-cli/linux-arm64-musl': 3.27.0 - '@fallow-cli/linux-x64-gnu': 3.27.0 - '@fallow-cli/linux-x64-musl': 3.27.0 - '@fallow-cli/win32-arm64-msvc': 3.27.0 - '@fallow-cli/win32-x64-msvc': 3.27.0 - fallow-type-aware: 3.27.0 - - fast-check@4.10.1: + '@fallow-cli/darwin-arm64': 3.30.0 + '@fallow-cli/darwin-x64': 3.30.0 + '@fallow-cli/linux-arm64-gnu': 3.30.0 + '@fallow-cli/linux-arm64-musl': 3.30.0 + '@fallow-cli/linux-x64-gnu': 3.30.0 + '@fallow-cli/linux-x64-musl': 3.30.0 + '@fallow-cli/win32-arm64-msvc': 3.30.0 + '@fallow-cli/win32-x64-msvc': 3.30.0 + fallow-type-aware: 3.30.0 + + fast-check@4.10.2: dependencies: pure-rand: 8.4.2 @@ -7476,12 +7479,13 @@ snapshots: minipass: 7.1.3 path-scurry: 2.0.2 - globby@16.2.2: + globby@16.2.4: dependencies: '@sindresorhus/merge-streams': 4.0.0 fast-glob: 3.3.3 ignore: 7.0.9 is-path-inside: 4.0.0 + micromatch: 4.0.8 slash: 5.1.0 unicorn-magic: 0.4.0 @@ -7555,7 +7559,7 @@ snapshots: js-tokens@10.0.0: {} - js-yaml@5.2.2: + js-yaml@5.4.1: dependencies: argparse: 2.0.1 @@ -7634,9 +7638,9 @@ snapshots: longest-streak@3.1.0: {} - lru-cache@11.5.2: {} + lru-cache@11.5.3: {} - magic-string@1.4.1: + magic-string@1.4.2: dependencies: '@jridgewell/sourcemap-codec': 1.6.0 @@ -7661,21 +7665,21 @@ snapshots: markdown-table@3.0.4: {} - markdownlint-cli2-formatter-default@0.0.6(markdownlint-cli2@0.23.2(supports-color@7.2.0)): + markdownlint-cli2-formatter-default@0.0.6(markdownlint-cli2@0.23.3(supports-color@7.2.0)): dependencies: - markdownlint-cli2: 0.23.2(supports-color@7.2.0) + markdownlint-cli2: 0.23.3(supports-color@7.2.0) - markdownlint-cli2@0.23.2(supports-color@7.2.0): + markdownlint-cli2@0.23.3(supports-color@7.2.0): dependencies: - globby: 16.2.2 - js-yaml: 5.2.2 + globby: 16.2.4 + js-yaml: 5.4.1 jsonc-parser: 3.3.1 jsonpointer: 5.0.1 markdown-it: 14.3.2 markdownlint: 0.41.1(supports-color@7.2.0) - markdownlint-cli2-formatter-default: 0.0.6(markdownlint-cli2@0.23.2(supports-color@7.2.0)) + markdownlint-cli2-formatter-default: 0.0.6(markdownlint-cli2@0.23.3(supports-color@7.2.0)) micromatch: 4.0.8 - smol-toml: 1.7.0 + smol-toml: 1.8.0 transitivePeerDependencies: - supports-color @@ -7689,7 +7693,7 @@ snapshots: micromark-extension-gfm-table: 2.1.1 micromark-extension-math: 3.1.0 micromark-util-types: 2.0.2 - string-width: 8.2.2 + string-width: 8.3.0 transitivePeerDependencies: - supports-color @@ -7697,10 +7701,10 @@ snapshots: dependencies: '@arr/every': 1.0.1 - mcp-tada@0.4.0(@modelcontextprotocol/client@2.0.0)(typescript@7.1.0-dev.20260917.1): + mcp-tada@0.4.0(@modelcontextprotocol/client@2.2.0)(typescript@7.1.0-dev.20260929.1): optionalDependencies: - '@modelcontextprotocol/client': 2.0.0 - typescript: 7.1.0-dev.20260917.1 + '@modelcontextprotocol/client': 2.2.0 + typescript: 7.1.0-dev.20260929.1 mdast-util-find-and-replace@3.0.2: dependencies: @@ -7716,7 +7720,7 @@ snapshots: decode-named-character-reference: 1.3.0 devlop: 1.1.0 mdast-util-to-string: 4.0.0 - micromark: 4.0.2(supports-color@7.2.0) + micromark: 4.0.3(supports-color@7.2.0) micromark-util-decode-numeric-character-reference: 2.0.2 micromark-util-decode-string: 2.0.1 micromark-util-normalize-identifier: 2.0.1 @@ -7739,7 +7743,7 @@ snapshots: '@types/mdast': 4.0.4 devlop: 1.1.0 mdast-util-from-markdown: 2.0.3(supports-color@7.2.0) - mdast-util-to-markdown: 2.1.2 + mdast-util-to-markdown: 2.1.3 micromark-util-normalize-identifier: 2.0.1 transitivePeerDependencies: - supports-color @@ -7748,7 +7752,7 @@ snapshots: dependencies: '@types/mdast': 4.0.4 mdast-util-from-markdown: 2.0.3(supports-color@7.2.0) - mdast-util-to-markdown: 2.1.2 + mdast-util-to-markdown: 2.1.3 transitivePeerDependencies: - supports-color @@ -7758,7 +7762,7 @@ snapshots: devlop: 1.1.0 markdown-table: 3.0.4 mdast-util-from-markdown: 2.0.3(supports-color@7.2.0) - mdast-util-to-markdown: 2.1.2 + mdast-util-to-markdown: 2.1.3 transitivePeerDependencies: - supports-color @@ -7767,7 +7771,7 @@ snapshots: '@types/mdast': 4.0.4 devlop: 1.1.0 mdast-util-from-markdown: 2.0.3(supports-color@7.2.0) - mdast-util-to-markdown: 2.1.2 + mdast-util-to-markdown: 2.1.3 transitivePeerDependencies: - supports-color @@ -7779,7 +7783,7 @@ snapshots: mdast-util-gfm-strikethrough: 2.0.0(supports-color@7.2.0) mdast-util-gfm-table: 2.0.0(supports-color@7.2.0) mdast-util-gfm-task-list-item: 2.0.0(supports-color@7.2.0) - mdast-util-to-markdown: 2.1.2 + mdast-util-to-markdown: 2.1.3 transitivePeerDependencies: - supports-color @@ -7788,15 +7792,17 @@ snapshots: '@types/mdast': 4.0.4 unist-util-is: 6.0.1 - mdast-util-to-markdown@2.1.2: + mdast-util-to-markdown@2.1.3: dependencies: '@types/mdast': 4.0.4 '@types/unist': 3.0.3 longest-streak: 3.1.0 mdast-util-phrasing: 4.1.0 mdast-util-to-string: 4.0.0 + micromark-util-character: 2.1.1 micromark-util-classify-character: 2.0.1 micromark-util-decode-string: 2.0.1 + micromark-util-html-tag-name: 2.0.1 unist-util-visit: 5.1.0 zwitch: 2.0.4 @@ -7972,6 +7978,10 @@ snapshots: micromark-util-decode-numeric-character-reference: 2.0.2 micromark-util-symbol: 2.0.1 + micromark-util-edit-map@1.0.0: + dependencies: + micromark-util-types: 2.0.2 + micromark-util-encode@2.0.1: {} micromark-util-html-tag-name@2.0.1: {} @@ -8023,6 +8033,29 @@ snapshots: transitivePeerDependencies: - supports-color + micromark@4.0.3(supports-color@7.2.0): + dependencies: + '@types/debug': 4.1.13 + debug: 4.4.3(supports-color@7.2.0) + decode-named-character-reference: 1.3.0 + devlop: 1.1.0 + micromark-core-commonmark: 2.0.3 + micromark-factory-space: 2.0.1 + micromark-util-character: 2.1.1 + micromark-util-chunked: 2.0.1 + micromark-util-combine-extensions: 2.0.1 + micromark-util-decode-numeric-character-reference: 2.0.2 + micromark-util-edit-map: 1.0.0 + micromark-util-encode: 2.0.1 + micromark-util-normalize-identifier: 2.0.1 + micromark-util-resolve-all: 2.0.1 + micromark-util-sanitize-uri: 2.0.1 + micromark-util-subtokenize: 2.1.0 + micromark-util-symbol: 2.0.1 + micromark-util-types: 2.0.2 + transitivePeerDependencies: + - supports-color + micromatch@4.0.8: dependencies: braces: 3.0.3 @@ -8073,6 +8106,8 @@ snapshots: obug@2.2.1: {} + obug@3.0.0: {} + ofetch@1.5.1: dependencies: destr: 2.0.5 @@ -8179,7 +8214,7 @@ snapshots: path-scurry@2.0.2: dependencies: - lru-cache: 11.5.2 + lru-cache: 11.5.3 minipass: 7.1.3 pathe@2.0.3: {} @@ -8230,7 +8265,7 @@ snapshots: '@protobufjs/path': 1.1.2 '@protobufjs/pool': 1.1.0 '@protobufjs/utf8': 1.1.2 - '@types/node': 26.6.1 + '@types/node': 26.6.3 long: 5.3.2 pump@3.0.4: @@ -8264,7 +8299,7 @@ snapshots: string_decoder: 1.3.0 util-deprecate: 1.0.2 - regjsparser@0.13.2: + regjsparser@0.13.3: dependencies: jsesc: 3.1.0 @@ -8324,9 +8359,7 @@ snapshots: shebang-regex@3.0.0: {} - shell-quote@1.10.0: {} - - siginfo@2.0.0: {} + shell-quote@1.11.0: {} signal-exit@4.1.0: {} @@ -8338,7 +8371,7 @@ snapshots: slash@5.1.0: {} - smol-toml@1.7.0: {} + smol-toml@1.8.0: {} source-map-js@1.2.1: {} @@ -8352,15 +8385,13 @@ snapshots: cpu-features: 0.0.10 nan: 2.28.0 - stackback@0.0.2: {} - statuses@2.0.2: {} std-env@4.2.0: {} strict-event-emitter@0.5.1: {} - string-width@8.2.2: + string-width@8.3.0: dependencies: get-east-asian-width: 1.6.0 strip-ansi: 7.2.0 @@ -8371,7 +8402,7 @@ snapshots: strip-ansi@7.2.0: dependencies: - ansi-regex: 6.3.0 + ansi-regex: 6.4.0 suffix-thumb@5.0.3: {} @@ -8404,12 +8435,12 @@ snapshots: inherits: 2.0.4 readable-stream: 3.6.2 - taze@21.1.0: + taze@21.3.0: dependencies: - '@antfu/ni': 30.5.0 + '@antfu/ni': 30.6.0 '@henrygd/queue': 1.2.0 cac: 7.0.0 - obug: 2.2.1 + obug: 3.0.0 ofetch: 1.5.1 package-manager-detector: 1.8.0 pathe: 2.0.3 @@ -8418,7 +8449,7 @@ snapshots: tinyexec: 1.3.1 tinyglobby: 0.2.17 unconfig: 7.5.0 - verkit: 0.3.2 + verkit: 0.5.0 yaml: 2.9.1 test-exclude@8.0.0: @@ -8465,7 +8496,7 @@ snapshots: media-typer: 1.1.1 mime-types: 3.0.2 - typebox@1.3.33: {} + typebox@1.3.34: {} typescript@5.9.3: {} @@ -8493,15 +8524,15 @@ snapshots: '@typescript/typescript-win32-x64': 7.0.2 optional: true - typescript@7.1.0-dev.20260917.1: + typescript@7.1.0-dev.20260929.1: optionalDependencies: - '@typescript/typescript-darwin-arm64': 7.1.0-dev.20260917.1 - '@typescript/typescript-darwin-x64': 7.1.0-dev.20260917.1 - '@typescript/typescript-linux-arm': 7.1.0-dev.20260917.1 - '@typescript/typescript-linux-arm64': 7.1.0-dev.20260917.1 - '@typescript/typescript-linux-x64': 7.1.0-dev.20260917.1 - '@typescript/typescript-win32-arm64': 7.1.0-dev.20260917.1 - '@typescript/typescript-win32-x64': 7.1.0-dev.20260917.1 + '@typescript/typescript-darwin-arm64': 7.1.0-dev.20260929.1 + '@typescript/typescript-darwin-x64': 7.1.0-dev.20260929.1 + '@typescript/typescript-linux-arm': 7.1.0-dev.20260929.1 + '@typescript/typescript-linux-arm64': 7.1.0-dev.20260929.1 + '@typescript/typescript-linux-x64': 7.1.0-dev.20260929.1 + '@typescript/typescript-win32-arm64': 7.1.0-dev.20260929.1 + '@typescript/typescript-win32-x64': 7.1.0-dev.20260929.1 uc.micro@2.1.0: {} @@ -8553,13 +8584,13 @@ snapshots: '@types/istanbul-lib-coverage': 2.0.6 convert-source-map: 2.0.0 - valibot@1.5.0(typescript@7.1.0-dev.20260917.1): + valibot@1.5.0(typescript@7.1.0-dev.20260929.1): optionalDependencies: - typescript: 7.1.0-dev.20260917.1 + typescript: 7.1.0-dev.20260929.1 - verkit@0.3.2: {} + verkit@0.5.0: {} - vite@8.3.0(@types/node@26.6.1)(jiti@2.7.0)(yaml@2.9.1): + vite@8.3.1(@types/node@26.6.3)(jiti@2.7.0)(yaml@2.9.1): dependencies: lightningcss: 1.33.0 picomatch: 4.0.7 @@ -8567,31 +8598,31 @@ snapshots: rolldown: 1.2.10 tinyglobby: 0.2.17 optionalDependencies: - '@types/node': 26.6.1 + '@types/node': 26.6.3 fsevents: 2.3.3 jiti: 2.7.0 yaml: 2.9.1 - vitest@5.0.1(patch_hash=065993cceebda16dedb4662626ed60c0aeb40f02240c8d0e540b4dc6d9674df2)(@types/node@26.6.1)(@vitest/coverage-v8@5.0.1)(@vitest/ui@5.0.1)(vite@8.3.0(@types/node@26.6.1)(jiti@2.7.0)(yaml@2.9.1)): + vitest@5.0.2(@types/node@26.6.3)(@vitest/coverage-v8@5.0.2)(@vitest/ui@5.0.2)(vite@8.3.1(@types/node@26.6.3)(jiti@2.7.0)(yaml@2.9.1)): dependencies: '@types/chai': 5.2.3 - '@vitest/mocker': 5.0.1(vite@8.3.0(@types/node@26.6.1)(jiti@2.7.0)(yaml@2.9.1)) + '@vitest/mocker': 5.0.2(vite@8.3.1(@types/node@26.6.3)(jiti@2.7.0)(yaml@2.9.1)) chai: 6.2.2 es-module-lexer: 2.3.2 expect-type: 1.4.0 - magic-string: 1.4.1 + magic-string: 1.4.2 obug: 2.2.1 picomatch: 4.0.7 std-env: 4.2.0 tinybench: 6.1.4 tinyexec: 1.3.1 tinyglobby: 0.2.17 - vite: 8.3.0(@types/node@26.6.1)(jiti@2.7.0)(yaml@2.9.1) - why-is-node-running: 2.3.0 + vite: 8.3.1(@types/node@26.6.3)(jiti@2.7.0)(yaml@2.9.1) + why-is-node-running: 3.2.1 optionalDependencies: - '@types/node': 26.6.1 - '@vitest/coverage-v8': 5.0.1(vitest@5.0.1) - '@vitest/ui': 5.0.1(vitest@5.0.1) + '@types/node': 26.6.3 + '@vitest/coverage-v8': 5.0.2(vitest@5.0.2) + '@vitest/ui': 5.0.2(vitest@5.0.2) transitivePeerDependencies: - msw @@ -8599,21 +8630,18 @@ snapshots: dependencies: isexe: 4.0.0 - why-is-node-running@2.3.0: - dependencies: - siginfo: 2.0.0 - stackback: 0.0.2 + why-is-node-running@3.2.1: {} wrap-ansi@7.0.0: dependencies: ansi-styles: 4.3.0 - string-width: 8.2.2 + string-width: 8.3.0 strip-ansi: 7.2.0 wrap-ansi@9.0.2: dependencies: ansi-styles: 6.2.3 - string-width: 8.2.2 + string-width: 8.3.0 strip-ansi: 7.2.0 wrappy@1.0.2: {} @@ -8632,7 +8660,7 @@ snapshots: escalade: 3.2.0 get-caller-file: 2.0.5 require-directory: 2.1.1 - string-width: 8.2.2 + string-width: 8.3.0 y18n: 5.0.8 yargs-parser: 21.1.1 @@ -8641,7 +8669,7 @@ snapshots: cliui: 9.0.1 escalade: 3.2.0 get-caller-file: 2.0.5 - string-width: 8.2.2 + string-width: 8.3.0 y18n: 5.0.8 yargs-parser: 22.0.0 diff --git a/pnpm-workspace.yaml b/pnpm-workspace.yaml index 3c1543a..b543027 100644 --- a/pnpm-workspace.yaml +++ b/pnpm-workspace.yaml @@ -182,15 +182,15 @@ savePrefix: '' saveTypes: true progress: false catalog: - '@mdn/browser-compat-data': 8.1.2 - '@modelcontextprotocol/client': 2.0.0 + '@mdn/browser-compat-data': 8.1.3 + '@modelcontextprotocol/client': 2.2.0 # run-local-ci (bin: local-ci, formerly published as @redwoodjs/agent-ci) # runs a repo's GitHub Actions workflows locally in Docker so a change can # be validated before it's pushed (see the `agent-ci` skill). dtu-github- # actions is its GitHub-Actions parser, pinned explicitly (not left # transitive) so its version is uniform fleet-wide. '@ultrathink/acorn.rs.wasm': 0.1.1 - 'ata-validator': 1.27.1 + 'ata-validator': 1.39.1 'brace-expansion': 5.0.12 'dtu-github-actions': 0.18.1 # shadscan — shadcn UI audit CLI for the design skills (missing UI @@ -199,14 +199,14 @@ catalog: '@shadscan/cli': 0.17.0 '@sinclair/typebox': 0.34.52 'ecc-agentshield': 1.6.0 - 'fallow': 3.27.0 + 'fallow': 3.30.0 'mcp-tada': 0.4.0 'run-local-ci': 0.18.1 # typebox 1.x — the unscoped rewrite of @sinclair/typebox. Both names are # pinned while the fleet migrates; the 0.x entry is deleted once no member # imports the scoped name. 1.3.10 is inside the 7-day soak, so it carries a # dated minimumReleaseAgeExclude entry above. - 'typebox': 1.3.33 + 'typebox': 1.3.34 '@socketregistry/packageurl-js': 1.5.3 # -stable aliases: pnpm `overrides:` can't redirect a package's own # name when used INSIDE that same package — Node ESM treats it as a @@ -226,16 +226,16 @@ catalog: '@socketsecurity/sdk': 4.1.5 '@socketsecurity/sdk-stable': 'npm:@socketsecurity/sdk@4.1.5' '@types/mdast': 4.0.4 - '@types/node': 26.6.1 + '@types/node': 26.6.3 '@types/semver': 7.8.0 '@types/shell-quote': 1.7.5 'compromise': 14.17.0 # fast-check — property-based testing for pure fleet-script logic (pin # derivation, version compare, config validation). Runs standalone in vitest. # published: 2026-07-08 (past 7-day soak). See .claude/skills/fleet/property-testing. - 'fast-check': 4.10.1 - 'magic-string': 1.4.1 - 'markdownlint-cli2': 0.23.2 + 'fast-check': 4.10.2 + 'magic-string': 1.4.2 + 'markdownlint-cli2': 0.23.3 'mdast-util-from-markdown': 2.0.3 # GFM pair for render-faithful markdown parsing (tables, footnotes, # strikethrough, autolinks) — mdast-util-from-markdown must always be @@ -243,8 +243,8 @@ catalog: 'mdast-util-gfm': 3.1.0 # The serializer half, for tools that legitimately EMIT markdown; edits to # existing documents stay position-based (never a whole-doc round-trip). - 'mdast-util-to-markdown': 2.1.2 - 'micromark': 4.0.2 + 'mdast-util-to-markdown': 2.1.3 + 'micromark': 4.0.3 'micromark-extension-gfm': 3.0.0 'minimatch': 10.2.6 'neosanitize': 0.3.0 @@ -283,27 +283,27 @@ catalog: # vite-bundled rolldown (8.0.14 → 1.0.2); the per-platform # @rolldown/binding-* + @oxc-project/types stay as soak-excluded # transitives (consumers depend on `rolldown` only). - 'regjsparser': 0.13.2 + 'regjsparser': 0.13.3 'rolldown': 1.2.10 'semver': 7.8.5 - 'shell-quote': 1.10.0 - 'taze': 21.1.0 + 'shell-quote': 1.11.0 + 'taze': 21.3.0 # vite 8.0.16 swaps esbuild → rolldown natively (bundles rolldown # 1.0.2) and patches the <=8.0.15 advisories (GHSA-fx2h-pf6j-xcff # high, GHSA-v6wh-96g9-6wx3 medium). Tracked here so the pnpm # override below pins every transitive `vite` (vitest, @vitest/*, # plugin authors) to it. - 'typescript': 7.1.0-dev.20260917.1 - 'vitest': 5.0.1 - '@vitest/coverage-v8': 5.0.1 + 'typescript': 7.1.0-dev.20260929.1 + 'vitest': 5.0.2 + '@vitest/coverage-v8': 5.0.2 '@bcoe/v8-coverage': 1.0.2 - ast-v8-to-istanbul: 1.0.6 - 'chrome-devtools-mcp': 1.9.0 + ast-v8-to-istanbul: 1.0.7 + 'chrome-devtools-mcp': 1.10.1 # Playwright MCP server — agent-driven browsing with the fleet agent-banner # init script (see .config/fleet/playwright/). '@playwright/mcp': 0.0.81 - '@vitest/ui': 5.0.1 - 'sharp': 0.35.4 + '@vitest/ui': 5.0.2 + 'sharp': 0.35.5 c8: 12.0.0 # pnpm `overrides` block — two purposes: @@ -328,7 +328,7 @@ catalog: # platform-binary optionalDependencies, despite the monorepo's internal # workspace layout. dtu-github-actions is its GitHub-Actions parser, pinned # explicitly (not left transitive) so its version is uniform fleet-wide. - '@anthropic-ai/claude-code': 2.1.273 + '@anthropic-ai/claude-code': 2.1.285 # comptime 0.1.0 — Zig-inspired build-time evaluation for Rolldown/Vite. # Wraps comptime(() => expr) calls; the Rolldown plugin evaluates them at # build time and replaces the call site with the serialized literal result. @@ -337,7 +337,7 @@ catalog: 'comptime': 0.1.0 'rolldown-plugin-dts': 0.28.6 'svgo': 4.1.0 - 'vite': 8.3.0 + 'vite': 8.3.1 'vitiate': 0.3.1 '@vitiate/core': 0.3.1 @@ -381,8 +381,8 @@ overrides: 'iconv-lite': '0.7.3' 'isexe@>=3': '4.0.0' 'js-yaml@>=5.0.0 <5.2.2': '5.4.2' - 'lru-cache@>=10': '11.5.2' - 'magic-string': '1.4.1' + 'lru-cache@>=10': '11.5.3' + 'magic-string': '1.4.2' 'mime-db': '1.54.0' 'mime-types@>=3': '3.0.2' 'minimatch@>=3': '10.2.6' @@ -393,7 +393,7 @@ overrides: 'semver@>=5.0.0 <7.6.0': '7.8.5' 'side-channel': 'npm:@socketregistry/side-channel@1.0.10' 'ssri@>=12': '13.0.1' - 'string-width@>=5': '8.2.2' + 'string-width@>=5': '8.3.0' 'tinyexec': '1.3.1' 'typebox': 'catalog:' 'undici@<6': '6.28.0' @@ -422,7 +422,7 @@ overrides: '@types/unist@2': '3.0.3' # Dedup compat shim: ansi-regex 5 (CJS yargs@17 cluster) vs 6 (ESM, # markdownlint). See the patchedDependencies comment for the shim. - 'ansi-regex': '6.3.0' + 'ansi-regex': '6.4.0' # Dedup: color-convert 0.5.3 is a declared-but-unused dependency of # css-color-converter@2.0.0 (badge-maker) — its lib/index.js never # `require`s color-convert at all, so the 0.5.3 resolution is dead weight. @@ -467,8 +467,8 @@ overrides: # sharp 0.35.0 dropped its install script (source compile is opt-in); pin the # logo generator's sharp to 0.35.3 so it stays on a no-build-script line — its # prebuilt @img/sharp-* binaries cover the rasterize + animated-GIF encode. - 'sharp': '0.35.4' - 'string-width': '8.2.2' + 'sharp': '0.35.5' + 'string-width': '8.3.0' # Dedup compat shim: strip-ansi 6 (CJS yargs@17 cluster) vs 7 (ESM, # via string-width@8 -> markdownlint). See the patchedDependencies comment # for the shim. @@ -539,7 +539,6 @@ patchedDependencies: # This preserves membership and bounds matcher memory for fleet coverage. # CPU-profiled forks use the configured teardown deadline to flush profiles. # Ordinary forks retain the upstream 500 ms termination grace. - vitest@5.0.1: patches/fleet/vitest@5.0.1.patch # Proceed with a node_modules purge WITHOUT an interactive confirm. The fleet # runs pnpm non-interactively everywhere (skills, scripts, hooks, agents, CI) —