{
  "schemaVersion": 1,
  "contract": "kungfu-buildchain-site-bundle",
  "generatedAt": "2026-08-13T09:05:27.306Z",
  "publishedAt": "2026-08-13T09:05:27.306Z",
  "reproducible": true,
  "timestampPolicy": "ci-injected",
  "deterministicInputs": [
    "README.md",
    "docs/*.md",
    "actions/*/README.md",
    "fixtures/*/README.md",
    "packages/core/README.md",
    "package.json#exports",
    "tests/buildchain-inventory.json",
    "sourceRevision",
    "sourceDateEpoch",
    "package content",
    "declared Buildchain surface manifest contract"
  ],
  "sourceDateEpoch": "0",
  "sourceRevision": "45a49dcaa0fcef59bc66481a85c39514d08972cc",
  "timestampPolicyDetails": {
    "contract": "kungfu-buildchain-surface-timestamp-policy",
    "timestampFields": [
      "generatedAt",
      "publishedAt"
    ],
    "timestampFieldsParticipateInArtifactDigest": true,
    "artifactDigestScope": "npm package dist/site JSON files",
    "note": "Human-readable timestamps are separate from reproducibility inputs; do not infer reproducibility from epoch timestamps."
  },
  "product": {
    "name": "Buildchain",
    "formalName": "Buildchain by Kungfu",
    "category": "Buildchain Release Passport"
  },
  "package": {
    "name": "@kungfu-tech/buildchain",
    "version": "4.0.0",
    "versionSource": "package.json#version"
  },
  "source": {
    "package": "@kungfu-tech/buildchain",
    "homepageTextSource": "README.md",
    "docsMap": "docs/MAP.md",
    "manualRegistry": "manual-registry.json",
    "siteFactsDir": "dist/site"
  },
  "routes": {
    "home": "/",
    "docsPattern": "/docs/{id}",
    "llms": "/llms.txt",
    "manifest": "/manifest.json"
  },
  "sourceOfTruth": "npm package @kungfu-tech/buildchain/dist/site",
  "humanFirst": true,
  "agentFirst": true,
  "entrypoints": [
    "page-registry.json",
    "capability-registry.json",
    "cli-registry.json",
    "manual-registry.json",
    "node-api-registry.json",
    "workflow-registry.json",
    "controller-registry.json",
    "publication-authority-registry.json",
    "public-surface-audit.json",
    "release-model.json",
    "artifact-schemas.json",
    "badge-endpoint-registry.json",
    "publication-registry.json",
    "product-mechanism.json",
    "release-provenance.json",
    "kfd-upstream-aggregate.json",
    "kfd-claims.json",
    "agent-index.json",
    "site-manifest.json"
  ],
  "capabilityRegistry": {
    "path": "capability-registry.json",
    "contract": "kungfu-buildchain-capability-registry",
    "groupCount": 9,
    "defaultOrder": [
      "getting-started",
      "release-passport-trust",
      "reusable-build",
      "kfd-trust",
      "site-and-propagation",
      "distribution-indexes",
      "observability-diagnostics",
      "governance-versioning",
      "api-cli-reference"
    ]
  },
  "pages": [
    {
      "id": "overview:home",
      "title": "Buildchain",
      "route": "/",
      "category": "overview",
      "capabilityGroup": "getting-started",
      "audience": [
        "consumer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "README.md",
      "digest": "sha256:6eaf6142c4cf66bbfba30b941fce230905eb4b1fce5720b135a7275e2fb12cf9",
      "headings": [
        {
          "level": 1,
          "title": "Buildchain",
          "anchor": "buildchain"
        },
        {
          "level": 2,
          "title": "Buildchain beginner bootstrap",
          "anchor": "buildchain-beginner-bootstrap"
        },
        {
          "level": 2,
          "title": "Choose Your Path",
          "anchor": "choose-your-path"
        },
        {
          "level": 2,
          "title": "Where Buildchain sits in the Agent Supply Chain",
          "anchor": "where-buildchain-sits-in-the-agent-supply-chain"
        },
        {
          "level": 2,
          "title": "Install and Verify",
          "anchor": "install-and-verify"
        },
        {
          "level": 2,
          "title": "Project Governance",
          "anchor": "project-governance"
        },
        {
          "level": 2,
          "title": "Use Buildchain",
          "anchor": "use-buildchain"
        },
        {
          "level": 2,
          "title": "Release Model",
          "anchor": "release-model"
        },
        {
          "level": 2,
          "title": "Toolkit Observability",
          "anchor": "toolkit-observability"
        },
        {
          "level": 2,
          "title": "Site Fact Source",
          "anchor": "site-fact-source"
        },
        {
          "level": 2,
          "title": "Homepage Content Contract",
          "anchor": "homepage-content-contract"
        },
        {
          "level": 2,
          "title": "Local Verification",
          "anchor": "local-verification"
        },
        {
          "level": 2,
          "title": "Read Next",
          "anchor": "read-next"
        }
      ],
      "markdown": "# Buildchain\n\n<!-- buildchain-auditable-demo:start -->\n## Buildchain beginner bootstrap\n\n[![Buildchain beginner bootstrap](docs/evidence/auditable-demo/aa5cc40f4a62ed516e163e7e2c9dae0bcf32b3c77143a17105dfc4e5eaf9f01a/beginner-bootstrap/demo.gif)](docs/evidence/auditable-demo/aa5cc40f4a62ed516e163e7e2c9dae0bcf32b3c77143a17105dfc4e5eaf9f01a/beginner-bootstrap/public-evidence.json)\n\nAnimation scenario:\n\n```text\n$ buildchain init --cwd ./starter --type package --package-manager npm\n$ buildchain layout --cwd ./starter --json\n$ buildchain version\n```\n\nNative renditions: [1080p MP4](docs/evidence/auditable-demo/aa5cc40f4a62ed516e163e7e2c9dae0bcf32b3c77143a17105dfc4e5eaf9f01a/beginner-bootstrap/demo.mp4) · [1080p WebM](docs/evidence/auditable-demo/aa5cc40f4a62ed516e163e7e2c9dae0bcf32b3c77143a17105dfc4e5eaf9f01a/beginner-bootstrap/demo.webm) · [720p MP4](docs/evidence/auditable-demo/aa5cc40f4a62ed516e163e7e2c9dae0bcf32b3c77143a17105dfc4e5eaf9f01a/beginner-bootstrap/demo-720p.mp4) · [720p WebM](docs/evidence/auditable-demo/aa5cc40f4a62ed516e163e7e2c9dae0bcf32b3c77143a17105dfc4e5eaf9f01a/beginner-bootstrap/demo-720p.webm)\n\n[Static poster / reduced-motion fallback](docs/evidence/auditable-demo/aa5cc40f4a62ed516e163e7e2c9dae0bcf32b3c77143a17105dfc4e5eaf9f01a/beginner-bootstrap/poster.png)\n\n<details>\n<summary>Evidence and claim boundary</summary>\n\nThis exact standalone-binary scenario proves deterministic local bootstrap behavior only; it does not grant release, repository, network, or production authority.\n\n[Release Passport](docs/evidence/auditable-demo/aa5cc40f4a62ed516e163e7e2c9dae0bcf32b3c77143a17105dfc4e5eaf9f01a/beginner-bootstrap/release-passport.json) · [auditable evidence](docs/evidence/auditable-demo/aa5cc40f4a62ed516e163e7e2c9dae0bcf32b3c77143a17105dfc4e5eaf9f01a/beginner-bootstrap/public-evidence.json)\n\n</details>\n<!-- buildchain-auditable-demo:end -->\n\n<!-- buildchain:badges:start -->\n\n[![KFD-1: passed](https://buildchain.libkungfu.dev/badges/v1/kfd-1/passed.svg)](https://github.com/kungfu-systems/buildchain/releases/latest/download/buildchain.release.json)\n[![KFD-2: passed](https://buildchain.libkungfu.dev/badges/v1/kfd-2/passed.svg)](https://github.com/kungfu-systems/buildchain/releases/latest/download/buildchain.release.json)\n[![KFD-3: passed](https://buildchain.libkungfu.dev/badges/v1/kfd-3/passed.svg)](https://github.com/kungfu-systems/buildchain/releases/latest/download/buildchain.release.json)\n[![KFD-4: declared](https://buildchain.libkungfu.dev/badges/v1/kfd-4/declared.svg)](https://github.com/kungfu-systems/buildchain/releases/latest/download/buildchain.release.json)\n[![Buildchain Release Passport: passed](https://buildchain.libkungfu.dev/badges/v1/buildchain-release-passport/passed.svg)](https://github.com/kungfu-systems/buildchain/releases/latest/download/buildchain.release.json)\n[![License: Apache-2.0](https://img.shields.io/badge/license-Apache--2.0-0969da.svg)](https://github.com/kungfu-systems/buildchain/blob/HEAD/LICENSE)\n[![Platform: macOS | Linux | Windows](https://img.shields.io/badge/platform-macOS%20%7C%20Linux%20%7C%20Windows-6e7781.svg)](https://github.com/kungfu-systems/buildchain/releases/latest/download/buildchain.release.json)\n[![Verify](https://github.com/kungfu-systems/buildchain/actions/workflows/verify.yml/badge.svg)](https://github.com/kungfu-systems/buildchain/actions/workflows/verify.yml)\n[![Buildchain Ref Promotion](https://github.com/kungfu-systems/buildchain/actions/workflows/buildchain-ref-promotion.yml/badge.svg)](https://github.com/kungfu-systems/buildchain/actions/workflows/buildchain-ref-promotion.yml)\n[![Binary Distribution](https://github.com/kungfu-systems/buildchain/actions/workflows/binary-distribution.yml/badge.svg)](https://github.com/kungfu-systems/buildchain/actions/workflows/binary-distribution.yml)\n<!-- buildchain:badges:end -->\n\nBuildchain Release Passport is a mature product release record for artifacts\nthat users or agents depend on.\n\nBuildchain by Kungfu uses GitHub as the execution and trust substrate: protected\nrefs, reviewed promotion PRs, exact tags, GitHub Releases, npm Trusted\nPublishing, and machine-readable evidence. Its job is to turn release intent\ninto an auditable product record, not to ask a repository to migrate away from\nits existing CI.\n\nThe same mechanism releases Buildchain itself.\n\n## Choose Your Path\n\n| You are... | Start here | You will get... |\n| --- | --- | --- |\n| adopting Buildchain for the first time | [Golden Path](docs/getting-started.md) | an exact install, project declaration, validated config, reusable workflow, release dry-run, and Passport inspection |\n| looking up a CLI command | [Generated CLI Reference](docs/cli-reference.md) | governed syntax, options, aliases, and side-effect-free help paths |\n| writing JavaScript automation | [Generated Node API Reference](docs/node-api-reference.md) | every public subpath and symbol with source-derived signatures and behavior boundaries |\n| operating an advanced build or release | [Documentation Map](docs/MAP.md) | capability-, intent-, and maturity-based navigation to normative contracts |\n\nProduction release operators should also read the\n[Buildchain v4 production release runbook](docs/v4-production-release.md).\n\nThe Golden Path is the beginner lane. Advanced workflow, signing, publishing,\nand governance manuals remain separate so a first-time consumer does not need\nto understand the entire release control plane before reaching a valid local\nconfiguration.\n\n## Where Buildchain sits in the Agent Supply Chain\n\nBuildchain binds a product's declarations to the exact source cut, build,\nartifacts, checks, and promotion record that produced a release. In the wider\nAgent Supply Chain it sits between KFD-3 product discovery and KFD-2\npurpose-bound assessment:\n\n```text\nKFD-3 declaration -> Buildchain exact-artifact evidence -> KFD-2 assessment\n```\n\nBuildchain can prove that a declared claim and an exact artifact remain\nconsistent, or fail/downgrade when their evidence drifts. It does not invent\nthe product fact, decide whether a receiver should trust it for a purpose,\ncertify every platform, or prove external adoption. Receivers and downstream\nKFD-2 assessors retain the admission decision and residual risk.\n\nTo evaluate the layer, inspect a release's `buildchain.release.json` and\n`artifact-evidence.json`, verify them with the CLI, and report missing product\nor protocol evidence through the repository issue tracker.\n\n## Install and Verify\n\nNew repository adopters should follow the [15–30 minute Golden Path](docs/getting-started.md).\nThe commands below are the shorter verification-only route for an existing\nconsumer.\n\nFor v4, use the published npm package and verify the release passport before\ntrusting release evidence:\n\n```bash\ncurl -LO https://github.com/kungfu-systems/buildchain/releases/download/v4.0.0/buildchain.release.json\ncurl -LO https://github.com/kungfu-systems/buildchain/releases/download/v4.0.0/artifact-evidence.json\nnpx @kungfu-tech/buildchain@4.0.0 verify release-passport buildchain.release.json\nnpx @kungfu-tech/buildchain@4.0.0 version\n```\n\nThe v4.0.0 release publishes evidence assets and platform archives through the\nsame protected promotion transaction.\nThe names below describe the optional archive contract used by legacy release\nlines:\n\n- `buildchain-x86_64-unknown-linux-gnu.tar.gz`\n- `buildchain-aarch64-apple-darwin.tar.gz`\n- `buildchain-x86_64-pc-windows-msvc.zip`\n- `checksums.txt`\n- `buildchain.release.json`\n- `artifact-evidence.json`\n- `product-mechanism.json`\n- `impact.json`\n- `agent-index.json`\n- `check-report.json`\n- `llms.txt`\n- `buildchain-release-bundle.tar.gz`\n- `buildchain-release-bundle.json`\n\nLoose top-level `buildchain` and `buildchain.exe` assets are intentionally not\npublished. The executable lives inside each platform archive, which prevents\nLinux and macOS artifacts from overwriting each other in a merged release lane.\n\nFor npm consumers:\n\n```bash\nnpm install -D @kungfu-tech/buildchain\nnpx buildchain version\nnpx buildchain doctor --json\n```\n\nThe npm package is also the Buildchain toolkit. Use the command when a workflow\nor shell step needs an executable; use the ESM APIs directly from JavaScript\nbuild scripts. JavaScript callers should import the package instead of spawning\nthe CLI or unpacking the standalone binary:\n\n```js\nimport {\n  createBuildchainLogger,\n  verifyBuildchainLogEvents,\n} from \"@kungfu-tech/buildchain/logging\";\n\nconst logger = createBuildchainLogger({\n  path: \".buildchain/logs/native-build.jsonl\",\n  source: \"user\",\n  component: \"native-build\",\n});\n\nawait logger.span(\"native.compile\", { phase: \"build\" }, async () => {\n  await compileNativeTargets();\n});\n\nconst report = verifyBuildchainLogEvents({\n  path: logger.path,\n  requireEvents: [\"native.compile.start\", \"native.compile.end\"],\n});\n```\n\nThe package also ships `dist/site/` as the Buildchain-owned fact source for\n`buildchain.libkungfu.dev`.\n\nRepositories can also generate README status badges from Buildchain-owned facts\ninstead of hand-maintaining badge Markdown:\n\n```bash\nbuildchain badges bundle --check\nbuildchain badges bundle --write\nbuildchain badges readme --check\nbuildchain badges readme --write\n```\n\n## Project Governance\n\n- [`LICENSE-POLICY.md`](LICENSE-POLICY.md) explains the Apache-2.0 project\n  license, DCO-based contributions, and third-party notice boundary.\n- [`TRADEMARK.md`](TRADEMARK.md) explains official project marks and fork\n  identity boundaries.\n- [`ACCEPTABLE_USE.md`](ACCEPTABLE_USE.md) explains acceptable use of official\n  services and maintainer-operated infrastructure.\n- [`PROVIDER_COMPLIANCE.md`](PROVIDER_COMPLIANCE.md) explains the official\n  posture for GitHub, npm, cloud, credential, release evidence, and other\n  provider integrations.\n- [`SECURITY.md`](SECURITY.md) explains private vulnerability reporting.\n\nNative build consumers can import the diagnostics toolkit instead of copying\nrepository-local probes:\n\n```js\nimport {\n  collectBuildchainDiagnostics,\n  collectRunnerDiagnostics,\n  writeDiagnosticsArtifact,\n} from \"@kungfu-tech/buildchain/diagnostics\";\n\nwriteDiagnosticsArtifact(\".buildchain/artifacts/diagnostics.json\", {\n  contract: \"consumer-build-diagnostics\",\n  buildchain: collectBuildchainDiagnostics({ cwd: process.cwd() }),\n  runner: collectRunnerDiagnostics(),\n});\n```\n\n`buildchain lifecycle run` writes a small `diagnostics.json` next to the\nplatform manifest. It includes lifecycle-wide observability, runner/tool/cache\nsnapshots, Git state, and links to the larger manifest and artifact outputs.\n\nConsumers can report Buildchain-owned workflow failures directly to the\nBuildchain repository with a scoped issue-write token:\n\n```yaml\n- uses: kungfu-systems/buildchain/actions/report-buildchain-issue@v4\n  if: failure()\n  with:\n    token: ${{ steps.buildchain-issue-token.outputs.token }}\n    summary: \"Reusable build failed before artifact finalization\"\n    failure-code: reusable-build-failed\n    buildchain-ref: v4\n    diagnostics-path: .buildchain/artifacts/diagnostics.json\n```\n\nThe action deduplicates by fingerprint, comments on existing open reports, and\nis fail-soft by default so issue reporting does not hide the original failure.\nUse `report-kind: workflow-friction` when Buildchain workflows should report\ntheir own repeated release friction back to the Buildchain issue tracker.\n\n## Use Buildchain\n\nBootstrap a repository:\n\n```bash\nnpx @kungfu-tech/buildchain init --type package --package-manager pnpm\nnpx @kungfu-tech/buildchain validate --require-version-state\nnpx @kungfu-tech/buildchain release --dry-run --target-ref alpha/v4/v4.0\n```\n\nBootstrap and inspect a governed paper repository through one interface:\n\n```bash\nnpx @kungfu-tech/buildchain paper scaffold \\\n  --package @kungfu-tech/paper-example \\\n  --repository kungfu-systems/paper-example\npnpm add -D @kungfu-tech/buildchain@<exact-v4-version>\npnpm exec buildchain paper work start <topic>\npnpm exec buildchain paper work submit\npnpm exec buildchain paper preflight --offline\npnpm exec buildchain paper status\n```\n\nThe paper surface is dry-run first. Add `--write` only to create missing\nscaffold files. `work start` and `work submit` validate the canonical remote,\nexact development SHA, clean source, safe branch, and fast-forward boundary\nbefore changing local or GitHub state. External mutations such as npm\nbootstrap, Alpha PR creation, and release resumption require `--execute`. See\n[`docs/publication-artifacts.md`](docs/publication-artifacts.md) for the\nevidence-state model and operator flow.\n\nBuildchain supports package and non-package projects through\n`.buildchain/buildchain.toml`. Legacy root `buildchain.toml` files remain\nreadable, but new consumers should keep Buildchain-owned files under\n`.buildchain/`:\n\n```text\n.buildchain/buildchain.toml\n.buildchain/contract-lock.json\n.buildchain/kfd/kfd-3/surfaces.json\n.buildchain/release-passport/buildchain.release.json\n```\n\nLifecycle commands can call pnpm, npm, yarn, pip, Conan, CMake, Make, custom\nscripts, or any other command that can run in the repository checkout.\n\nThe KFD entrypoint is `buildchain kfd`. Buildchain provides concrete KFD-1\ncontract-world, KFD-2 trust-claim, and KFD-3 collaboration-surface workflows,\nplus fail-closed product-evidence gates for KFD-4, KFD-5, and KFD-7. These\ngates preserve product-owned qualification and support decisions; they do not\nturn a schema-valid record into certification or shipped support.\n\nBuildchain's action registry currently contains seven active entries. Five are\ndirect consumer integration actions:\n\n- `actions/validate-config`\n- `actions/run-lifecycle`\n- `actions/promote-buildchain-ref`\n- `actions/report-buildchain-issue`\n- `actions/release-tail`\n\nTwo additional release-authority components are also registered and versioned:\n\n- `actions/github-artifact-attestation`\n- `actions/macos-credential-island`\n\n`dist/site/workflow-registry.json#actions` is the machine-readable inventory;\nthis split keeps the older four-action consumer snapshot from being mistaken for\nthe complete current registry.\n\nThe active reusable workflow surfaces are:\n\n- `.github/workflows/.gate-profile.yml` for project-neutral Shifu Gate profile\n  planning, capability-aware runner dispatch, receipt validation, and one\n  stable aggregate check;\n- `.github/workflows/.auditable-demo.yml` for exact-artifact demo\n  qualification, transcript-bound renderer smoke, optional media rendering\n  from the exact passing Gate bundle, and opt-in content-addressed web-delivery\n  profiles with independently verified rendition roles;\n- `.github/workflows/.declarative-auditable-demo.yml` for standalone binary\n  consumers that provide only a versioned multi-demo argv scenario and exact\n  same-run binary artifact coordinates; Buildchain owns isolated native\n  capture, Gate, Release Passport, materialization, and protected README PRs;\n- `.github/workflows/.build.yml` for deterministic multi-platform build and\n  artifact contracts;\n- `.github/workflows/build.yml` for the single-config channel router that uses\n  `vN-alpha` during development/prerelease work and `vN` for stable releases;\n- `.github/workflows/release-candidate-promote.yml` for post-merge\n  promote-only publication from a PR-stage release candidate, without a second\n  heavy build;\n- `.github/workflows/.web-surface.yml` for preview, staging, production, and\n  cleanup plans for site/app repositories;\n- `.github/workflows/buildchain-ref-promotion.yml` for protected release\n  promotion and version-state transactions;\n- `.github/workflows/binary-distribution.yml` for Buildchain's own release\n  passport proof case.\n\nStable consumers should reference actions and workflows through floating major\nrefs after reviewing the exact release passport:\n\n```yaml\nuses: kungfu-systems/buildchain/actions/validate-config@v4\n```\n\n```yaml\nuses: kungfu-systems/buildchain/.github/workflows/build.yml@v4\n```\n\n```yaml\nuses: kungfu-systems/buildchain/.github/workflows/release-candidate-promote.yml@v4\n```\n\n## Release Model\n\nBuildchain treats a reviewed branch merge as release intent:\n\n| Merge path                              | Meaning                                                | Exact tag        | Floating refs                                        |\n| --------------------------------------- | ------------------------------------------------------ | ---------------- | ---------------------------------------------------- |\n| `dev/vX/vX.Y -> alpha/vX/vX.Y`          | publish the next testable alpha for a minor line       | `vX.Y.Z-alpha.N` | `vX.Y-alpha`, `alpha/vX/vX.Y`, `dev/vX/vX.Y`         |\n| `alpha/vX/vX.Y -> release/vX/vX.Y`      | publish production for that minor line                 | `vX.Y.Z`         | `vX.Y`, usually `vX`, `release/vX/vX.Y`              |\n| `release/vX/vX.Y -> publish-gate/major` | publish the next major from a reviewed production line | `v(X+1).0.0`     | `v(X+1)`, `v(X+1).0`, new dev/alpha/release branches |\n\nExact tags are immutable. Floating channel tags and branches are machine-updated\nby Buildchain and must remain writable by the release authority.\n\nAfter a production release, Buildchain prepares the next alpha source commit for\nthe same minor line. That keeps production consumers pinned to the production\npassport while development can continue on the next testable patch.\n\n`publish-gate/major` is not an active development trunk. It is a reviewed\npromotion gate used when maintainers decide that the next production release\nshould open a new major line.\n\n## Toolkit Observability\n\nBuildchain includes a logging toolkit for release and build steps. Inside\nJavaScript build code, prefer the package API:\n\n```js\nimport { createBuildchainLogger } from \"@kungfu-tech/buildchain/logging\";\n\nconst logger = createBuildchainLogger({ source: \"user\", component: \"conan\" });\nlogger.mark(\"conan.profile.ready\", { phase: \"configure\" });\nawait logger.span(\"conan.install\", { phase: \"dependencies\" }, runConanInstall);\n```\n\nIn workflows or shell scripts, use the equivalent CLI:\n\n```bash\nbuildchain mark --event native.configure --phase configure --component cmake\nbuildchain span --event native.build --phase build -- cmake --build build\nbuildchain log summary --json\nbuildchain verify observability-log .buildchain/logs/events.jsonl --min-events 4\n```\n\nEvery event records a timestamp. `span` records duration. The API form can be\nimported from repository scripts so heavy builds can mark phases from inside\ntheir own code.\n\n## Site Fact Source\n\n`@kungfu-tech/buildchain` publishes `dist/site/`:\n\n- `buildchain-site.json`\n- `site-manifest.json`\n- `page-registry.json`\n- `cli-registry.json`\n- `workflow-registry.json`\n- `release-model.json`\n- `artifact-schemas.json`\n- `product-mechanism.json`\n- `release-provenance.json`\n- `agent-index.json`\n\n`buildchain.libkungfu.dev` should render from these package-owned facts, then\nlayer presentation around them. The site should not hand-write Buildchain's\ncurrent release mechanics. `page-registry.json` is the complete markdown page\nsource for the public site: README homepage content, all packaged `docs/*.md`\nmanuals, action READMEs, the Node API package overview, and fixture guides.\n\n## Homepage Content Contract\n\nThis README is also the homepage text source for `buildchain.libkungfu.dev`.\nWhen a site repository consumes the `@kungfu-tech/buildchain` npm package, it\nshould use the generated `dist/site/buildchain-site.json` homepage fields\ninstead of parsing this README or maintaining separate homepage copy.\n\nThe first screen should be derived from:\n\n- Page identity: the top-level heading.\n- Lead: the opening paragraph that defines Buildchain Release Passport.\n- Trust signal: the start of `Install and Verify`, especially passport-first\n  binary verification.\n- Use signal: the start of `Use Buildchain`, especially the reusable workflow\n  and action surfaces.\n\nThe package-owned site bundle exposes ordered `homepage.sections`,\n`homepage.displayPlan`, `homepage.rendererContract`, and a complete\n`pages` collection mirrored from `page-registry.json`. A site renderer may adapt\nlayout, navigation, typography, examples, and visual assets, but it should not\nmaintain separate wording for Buildchain's release mechanics, workflow surface,\noperation manuals, Node API overview, fixture guides, or release-passport trust\nmodel. Renderer-contract text is machine/implementation metadata, not ordinary\nhomepage content.\n\n## Local Verification\n\n```bash\ncorepack enable pnpm\npnpm install --frozen-lockfile\npnpm run generate:site\npnpm run check\nnpm pack --dry-run --json --registry=https://registry.npmjs.org/\n```\n\n## Read Next\n\n- [Install and verify](docs/install.md)\n- [Documentation map](docs/MAP.md)\n- [Product mechanism](docs/product-mechanism.md)\n- [Release Passport and binary distribution](docs/release-passport.md)\n- [GitHub governance authority](docs/github-governance-authority.md)\n- [GitHub-native Linux artifact attestation](docs/github-artifact-attestation.md)\n- [Binary distribution details](docs/binary-distribution.md)\n- [Toolkit observability](docs/toolkit-observability.md)\n- [Site bundle contract](docs/site-bundle-contract.md)\n- [Lifecycle protocol](docs/lifecycle-protocol.md)\n- [Reusable build surface](docs/reusable-build-surface.md)\n- [Shifu Gate profile orchestration](docs/shifu-gate-profiles.md)\n- [Release candidate passport](docs/release-candidate.md)\n- [Consumer issue reporting](docs/consumer-issue-reporting.md)\n- [Publish transaction](docs/publish-transaction.md)\n- [Declarative release-tail contract](docs/release-tail-contract.md)\n- [Release governance](docs/release-governance.md)",
      "slug": "home"
    },
    {
      "id": "action:github-artifact-attestation",
      "title": "GitHub Artifact Attestation Evidence",
      "route": "/actions/github-artifact-attestation",
      "category": "action",
      "capabilityGroup": "api-cli-reference",
      "audience": [
        "developer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "actions/github-artifact-attestation/README.md",
      "digest": "sha256:5d18b6cb88a311e660d5895b3264b1a3e3813d00c43a1655a0a9f5ddd5b51895",
      "headings": [
        {
          "level": 1,
          "title": "GitHub Artifact Attestation Evidence",
          "anchor": "github-artifact-attestation-evidence"
        }
      ],
      "markdown": "# GitHub Artifact Attestation Evidence\n\nThis internal Buildchain action validates one downloaded Linux release artifact\nagainst its platform manifest and Release Passport, writes the custom predicate\nconsumed by `actions/attest`, and finalizes the retained v1 evidence document.\n\nConsumers should call\n`.github/workflows/github-artifact-attestation.yml`; they should not call this\naction directly. The action parses data files only. It never checks out or\nexecutes consumer source or the downloaded subject."
    },
    {
      "id": "action:macos-credential-island",
      "title": "macOS Credential Island",
      "route": "/actions/macos-credential-island",
      "category": "action",
      "capabilityGroup": "api-cli-reference",
      "audience": [
        "developer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "actions/macos-credential-island/README.md",
      "digest": "sha256:174ffb3e3424effc02164ad3577268fc060bfeefb223d0a2bc8d4cc43e66b110",
      "headings": [
        {
          "level": 1,
          "title": "macOS Credential Island",
          "anchor": "macos-credential-island"
        }
      ],
      "markdown": "# macOS Credential Island\n\nThis action signs one sealed macOS application on an isolated macOS runner. It\ndoes not check out consumer source and does not execute files from the input\nartifact. Buildchain validates the source-bound input manifest, imports one\nexact Developer ID Application identity into a temporary keychain, signs the\napplication, submits Apple notarization, staples the application and DMG,\nverifies Gatekeeper, and writes bounded JSON evidence.\n\nDMG assembly uses a unique execution- and attempt-bound image path and volume\nname. Only the exact `hdiutil: create failed - Resource busy` failure is retried,\nwith three attempts and a total retry delay of seven seconds. Certificate,\nentitlement, signature, notarization, provenance, and policy failures remain\nterminal. Attempt artifacts stay below the owned temporary root, and successful\nevidence binds the request, unsigned archive, runtime, runner attempt, toolchain,\nretry history, cleanup result, and signed output digests.\n\nThe reusable Buildchain workflow invokes this action from a job bound to the\ncaller's protected GitHub Environment. The job downloads the exact sealed\nBuildchain input and immutable action runtime, then uploads the signed payload\nand its Buildchain platform manifest. It has no consumer checkout. Do not add a\npackage manager, lifecycle, hook, or consumer-script execution to that job.\n\nThe supported `electron-desktop-v1` entitlements profile is owned by\nBuildchain. Consumer-provided entitlement files are intentionally unsupported;\notherwise pull-request bytes could expand the signing authority."
    },
    {
      "id": "action:promote-buildchain-ref",
      "title": "promote-buildchain-ref",
      "route": "/actions/promote-buildchain-ref",
      "category": "action",
      "capabilityGroup": "api-cli-reference",
      "audience": [
        "developer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "actions/promote-buildchain-ref/README.md",
      "digest": "sha256:d5e6c15dde52a15034118d2fdcc3b1bda7488a069b93a6aa201b874e6b884ed4",
      "headings": [
        {
          "level": 1,
          "title": "promote-buildchain-ref",
          "anchor": "promote-buildchain-ref"
        },
        {
          "level": 2,
          "title": "Dry Run",
          "anchor": "dry-run"
        },
        {
          "level": 2,
          "title": "Publish Transactions",
          "anchor": "publish-transactions"
        }
      ],
      "markdown": "---\nstatus: active\nperiod: ongoing\ntheme: buildchain-ref-promotion-action\ndoc_type: technical-reference\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-07-31\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-31\n  invisible_context: not asserted\n---\n\n# promote-buildchain-ref\n\nInternal buildchain action for promoting verified buildchain release-line and\ncompatibility refs from buildchain release channels:\n\n- `alpha/v3/v3.0` creates or reuses the next exact prerelease tag such as\n  `v3.0.3-alpha.0`, writes that version into package version state, points the\n  alpha and dev channel branches at the version commit, then promotes\n  `v3.0-alpha` and, when this is the highest published alpha minor, `v3-alpha`;\n- `release/v3/v3.0` creates or reuses the next exact release tag such as\n  `v3.0.2`, writes that version into package version state, points the release\n  channel branch and release tags at the release commit, then prepares a second\n  source commit for the next exact prerelease tag such as `v3.0.3-alpha.0` and\n  points the alpha/dev channel branches plus `v3.0-alpha` at that prerelease\n  commit, and moves `v3-alpha` only if no higher v3 minor has published an alpha;\n- `publish-gate/major` accepts a reviewed PR from a production release line such\n  as `release/v3/v3.0`, writes the next major production version such as\n  `v4.0.0`, points `publish-gate/major`, `release/v4/v4.0`, `v4.0`, and `v4`\n  at that release commit, then prepares `v4.0.1-alpha.0` for\n  `alpha/v4/v4.0`, `dev/v4/v4.0`, `v4.0-alpha`, and `v4-alpha`. The older `major-gate`\n  branch name is a compatibility alias only.\n\nThe release branch name defines the minor line. For example,\n`release/v3/v3.1` creates `v3.1.N`, promotes `v3.1`, and promotes `v3` only\nwhen the next minor tag such as `v3.2` does not already exist.\n\nThe action updates version state in `lerna.json`, root `package.json`, and\nworkspace package manifests discovered from package manager metadata\n(`package.json` workspaces, `lerna.json` packages, or `pnpm-workspace.yaml`).\nPackage manager detection is adaptive (`pnpm`, `npm`, or `yarn`) and is recorded\nin logs.\n\nRepositories can also provide `buildchain.toml` to declare version-state files\nand `lifecycle.verify`. TOML-configured version files take precedence over\npackage-manager discovery and can target JSON, TOML, or regex-based files. The\nversion commit itself is written through the GitHub Git Data API so the ref\ngraph is the durable source of truth. Repositories without any supported version\nstate degrade to ref-only promotion only when strict version state is disabled.\n\nJSON and TOML version entries whose declared key already matches the requested\nversion are treated as semantic no-ops. TOML changes use a parser-verified\nlossless key edit, so repository formatting is preserved and formatter-only\nrelease-preparation commits are not created. If a unique lossless edit cannot\nbe proven, promotion fails closed instead of rewriting the full TOML document.\n\n## Dry Run\n\nUse `dry-run: \"true\"` or the CLI `buildchain release --dry-run` before merging a\nchannel PR when you need to understand what Buildchain would do. This dry-run is\nat the Buildchain release-line level. It explains:\n\n- the legal source branch for the target channel;\n- exact release or alpha tags that would be created or reused;\n- floating tags and channel branches that would move;\n- version-state files and verification lifecycle that would apply;\n- branch protection, PR lineage, and release-from-alpha checks;\n- publish transaction behavior when `lifecycle.publish` or\n  `publish-transaction` is enabled.\n\nIt does not move refs, move tags, write package files, run publish commands, or\npublish npm packages. The GitHub action dry-run still calls GitHub APIs to\nresolve the current target SHA and concrete pending ref updates, but every\nwrite is reported as a dry-run update.\n\nWhen the requested version already matches every declared version-state file,\ndry-run planning still runs `lifecycle.version-state` and any explicit\n`verification-command` so it can discover declared derived material. It does\nnot fall back to the repository-wide `lifecycle.verify` in that no-op case;\nfull product verification can require candidate artifacts that are deliberately\nnot present until the later admission phase. Non-dry-run version-state writes\ncontinue to require the configured verification lifecycle before any ref moves.\n\nRepositories whose package version is anchored to an explicitly selected\nupstream release can opt into manual next-anchor behavior:\n\n```toml\n[version]\nrequired = true\nstrategy = \"anchored\"\nnext = \"manual\"\nmanifest = \"libnode.release.json\"\n```\n\nIn this mode, the action validates the configured version files and anchor\nmanifest through the repository's verify lifecycle, but it does not rewrite the\npackage version to match the Buildchain release tag. After a production\nrelease, it sets `next-anchor-required=true` and does not auto-create the next\nalpha branch or tag. The repository must create the next upstream anchor line\nexplicitly, then run the normal channel promotion flow for that line.\n\nWhen branch protection requires pull requests, generated version-state commits\nstill run through promotion automation first. The action updates\nBuildchain-managed channel protection before generated bookkeeping, admits only\nthe exact `github-actions` App to the target-bound bypass allowlist, creates\nevery configured required check on the exact generated version-state commit, then\ntries to apply that commit directly. If GitHub still rejects release\nfinalization bookkeeping, Buildchain creates or reuses a same-repository\n`buildchain/version-state/*` PR based on the current target channel head and\nreturns `finalization-needed=true`; a later idempotent promotion run can resume\nfrom the durable transaction state. Strict alpha uses the same protected\nversion-state PR recovery for its target and dev bookkeeping, and does not move\ntags until those provider-enforced transactions land. Reusable wrapper callers\nshould allow `checks: write` so the generated checks are owned by GitHub Actions\nand match the managed branch protection rule.\n\nStable promotion also protects concurrent development work. The reusable\nwrapper checks out the exact current `dev/vN/vN.M` head as a reconciliation\nworkspace. If next-alpha bookkeeping cannot fast-forward that branch, the\naction reruns the declared version-state generation and verification from that\ndev tree, creates a two-parent reconciliation commit from the regenerated\nfiles, and fails closed if the checkout moved before the mutation boundary.\nThis prevents generated projections from an older release tree from replacing\ncapabilities that reached dev while the release was in progress.\n\nFor Buildchain-owned automation, callers may pass\n`branch-protection-bypass-apps: github-actions`. The action rejects every other\nApp slug and all user or team bypass actors. It configures managed\n`dev/vN/vN.M`, `alpha/vN/vN.M`, and `release/vN/vN.M` branches with one\nrequired approving review, Code Owner review, stale-review dismissal,\nlatest-push approval, exact App-bound GitHub Actions checks, admin enforcement,\nconversation resolution, no force pushes, and no deletions; the bypass\nallowance only lets the named automation identity apply generated version-state\nor channel bookkeeping without a second human review after the reviewed channel\nPR has already merged.\n\nGitHub may return either `403` or a deliberately opaque `404` when a\nnon-administrator token reads the full branch-protection endpoint. In that\ncase, promotion reads the provider's branch summary and accepts only an\nalready-protected branch that enforces the exact required check for everyone.\nIt does not interpret the opaque response as missing protection or try to\nrewrite policy with a developer token. The independent publication-authority\naudit remains responsible for the complete read-only governance proof.\n\n## Publish Transactions\n\nPromotion can also own external publish side effects. Enable this only from a\ntrusted channel workflow:\n\n```yaml\n- uses: kungfu-systems/buildchain/actions/promote-buildchain-ref@v3\n  with:\n    token: ${{ secrets.BUILDCHAIN_PROMOTION_TOKEN }}\n    generated-ref-update-token: ${{ github.token }}\n    sha: ${{ github.sha }}\n    target-ref: release/v3/v3.0\n    publish-transaction: \"true\"\n    publish-mode: publish-final-version\n    publish-auth: trusted-publishing\n    publish-required-artifacts-json: >-\n      [\n        {\"kind\":\"npm\",\"name\":\"@kungfu-tech/buildchain\",\"ref\":\"3.0.0\",\"digest\":\"sha256:...\"}\n      ]\n```\n\nFor anchored/manual package repositories that build through the reusable\nworkflow, keep the publish entrypoint on the `publish-gate/*` source-lock\ncontract:\n\n```yaml\n- uses: kungfu-systems/buildchain/actions/promote-buildchain-ref@v3\n  with:\n    token: ${{ secrets.BUILDCHAIN_PROMOTION_TOKEN }}\n    sha: ${{ needs.build.outputs.publish-source-sha }}\n    target-ref: release/v22/v22.22\n    require-publish-source-lock: \"true\"\n    publish-source-ref: ${{ needs.build.outputs.publish-source-ref }}\n    publish-source-sha: ${{ needs.build.outputs.publish-source-sha }}\n    publish-source-locked: ${{ needs.build.outputs.publish-source-locked }}\n    publish-transaction: \"true\"\n    publish-mode: publish-final-version\n    publish-auth: trusted-publishing\n```\n\n`target-ref` remains the channel promotion target that must point at `sha`.\n`publish-source-ref` is the reviewed source-lock branch that authorized this\nspecific package publication. Direct `alpha/*` or `release/*` channel refs are\nnot valid publish source locks when `require-publish-source-lock` is enabled,\nand a mismatched `publish-source-sha` fails before any promotion or publish side effects begin.\n\nConsumers that opt in to a product-owned final predicate set\n`require-publication-qualification: \"true\"` and pass the exact sealed\n`publication-capability-json`, complete `publication-gate-aggregate-json`, and\n`publication-qualification-receipt-json`. The action validates their canonical\ndigests, predicate identity, freshness, nonce, source, version, channel, target,\nand evidence bindings both before provider access and immediately before the\npublish transaction. Missing or drifted receipts fail before mutation. The\nreusable `release-candidate-promote.yml` workflow creates these values in a\nseparate credentialless consumer job; direct callers must preserve the same\ncontract and may pass previously consumed nonces through\n`publication-used-qualification-nonces-json`.\n\nThe reusable promote workflow serializes non-dry-run promotion intents per\nrepository and re-reads `target-ref` before checkout, dependency installation,\nrelease-candidate resolution, or publish-gate writes. If a queued intent asks\nfor an older SHA after the protected channel has advanced, the workflow records\nthe requested/current SHA pair, verifies that the current target is ahead of\nthe requested commit, and exits successfully as a superseded no-op. Diverged,\nbehind, or unreadable comparisons still fail closed.\nAfter queued-intent revalidation, the reusable workflow runs the canonical\nrelease-candidate resolver in metadata-only mode before installing candidate\ndependencies or starting the full promotion job. The full job resolves and\ndownloads the evidence again before any publish-gate or publication mutation.\nThis preserves the final exact-evidence trust check while making missing or\nstale PR-stage evidence fail early.\nThe action repeats that check at its mutation boundary for governed promotion\ncalls, closing the race between workflow preflight and action start. Direct\nnon-governed calls and dry-runs keep the strict target mismatch error so local\ndiagnostics cannot silently reinterpret a stale request.\nExpected manual dry-run failures remain visible in the workflow result and do\nnot create automated workflow-friction issues; issue reporting is reserved for\nnon-dry-run promotion failures.\nThe reusable build workflow performs the cheaper channel-ref preflight earlier:\nafter source-lock resolution and before the build matrix, it requires the target\nchannel ref such as `alpha/v22/v22.22` or `release/v22/v22.22` to already point\nat the locked `publish-source-sha`. If not, maintainers should merge the source\ncommit through the channel PR first.\n\nFor promote-only release candidates, attach the PR-stage reusable build evidence\nand fail before publish-gate side effects if it no longer matches:\n\n```yaml\n- uses: kungfu-systems/buildchain/actions/promote-buildchain-ref@v3\n  with:\n    token: ${{ secrets.BUILDCHAIN_PROMOTION_TOKEN }}\n    sha: ${{ needs.build.outputs.publish-source-sha }}\n    target-ref: alpha/v22/v22.22\n    promote-only-release-candidate: \"true\"\n    release-candidate-passport-path: .buildchain/artifacts/release-candidate-passport.json\n    release-candidate-build-summary-path: .buildchain/artifacts/build-summary.json\n    release-candidate-family-evidence-required: \"true\"\n    release-candidate-family-evidence-root: sha256:<initiative-family-root>\n    release-candidate-family-initiative-id: 2026-07-30-example-initiative\n    release-candidate-family-assignment-id: 2026-07-30-example-release\n```\n\nThe action validates repository, channel, source identity, platform matrix, and\nthe aggregate build-summary hash before it writes version state, opens\nrelease-state, runs publish transaction logic, or moves tags/branches. Source\nidentity accepts the exact source SHA, the PR merge ref SHA, or the promoted\nchannel HEAD's Git tree SHA matching the passport tree hash. If validation\nfails, run or attach the verified channel PR build first instead of promoting a\nstale or unproven artifact set.\n\nThe four family-evidence inputs are optional. When enabled, the action requires\nthe candidate passport to carry the exact\n`kungfu-buildchain-initiative-family-release-evidence/v1` envelope and checks\nits family root, Initiative id, and Assignment id before any promotion\nmutation. Buildchain only transports and validates this adapter-edge release\nevidence; Kungfu Work Control remains authoritative for native Family State v1\nand its additive v2 typed envelope.\n\nWhen enabled, the action creates or resumes a release transaction keyed by\nrepository, version, source SHA, and target ref. It persists that transaction to\na machine-managed branch under `buildchain/release-state/<version>`, with\n`state.json` and, once available, `evidence.json`. Fresh GitHub runners read\nthat durable ref before running publish, so reruns do not depend on a previous\nrunner's local `.buildchain` directory.\n\nConsumers whose publish lifecycle only assembles local release assets or\nPassport inputs may set `publish-rematerialize-on-resume: true`. After\nBuildchain restores and validates durable publish evidence, it replays that\nconsumer-owned lifecycle with the original transaction environment before\nPassport collection. This is explicit opt-in because registry publication and\nother provider mutations must not be replayed blindly; the option rejects\n`promote-existing-version`.\n\nBuild-once callers additionally pass `publish-sealed-bundle-root` and\n`publish-sealed-bundle-manifest`. The action verifies the typed manifest and\npersists every declared file below\n`sealed-bundle/<candidate-root>/files/` on the same durable ref before it starts\nthe publish command. A fresh runner can omit both inputs: the action restores\nthe exact binary bundle into `.buildchain/recovered-publication/<version>/`,\nre-verifies it, and exports the recovered npm tarball through\n`BUILDCHAIN_SEALED_NPM_TARBALL` with its exact integrity and SHA-256. This path\nnever repacks the npm tarball.\n\nThe action runs `lifecycle.publish` from `buildchain.toml` or the explicit\n`publish-command` input, then validates publish evidence before exact tags and\nfloating refs move. If durable state persistence fails, the action fails closed\nbefore publish or public ref finalization.\n\n`publish-mode` defaults to `publish-final-version`, the token-free path for\nnormal npm Trusted Publishing. Same-version alpha-to-latest recovery must be\ndeclared as `publish-mode: promote-existing-version` and\n`publish-auth: npm-token`; Buildchain runs `npm whoami` before it creates\nrelease-state or moves any `npm dist-tag`. The Trusted Publishing mode is not\nallowed to perform `npm dist-tag add`.\n\nBuildchain itself uses this path for npm. Its `lifecycle.publish` runs\n`node scripts/npm-publish-transaction.mjs`, which publishes\n`@kungfu-tech/buildchain` through npm Trusted Publishing and writes npm\nartifact evidence into the transaction before release refs move. The separate\n`.github/workflows/npm-publish.yml` workflow is dry-run only.\n\nPublish lifecycle environment:\n\n```text\nBUILDCHAIN_VERSION\nBUILDCHAIN_CHANNEL\nBUILDCHAIN_SOURCE_SHA\nBUILDCHAIN_TARGET_REF\nBUILDCHAIN_RELEASE_STATE\nBUILDCHAIN_EVIDENCE_DIR\nBUILDCHAIN_RELEASE_SHA\nBUILDCHAIN_RELEASE_MATERIAL_SHA\nBUILDCHAIN_PUBLISH_TOOLING_SHA\nBUILDCHAIN_PUBLISH_EVIDENCE\nBUILDCHAIN_SEALED_BUNDLE_ROOT\nBUILDCHAIN_SEALED_NPM_TARBALL\nBUILDCHAIN_SEALED_NPM_INTEGRITY\nBUILDCHAIN_SEALED_NPM_SHA256\nBUILDCHAIN_REQUIRED_ARTIFACTS\n```\n\n`BUILDCHAIN_REQUIRED_ARTIFACTS` is the normalized requirement array after the\naction resolves a missing artifact `ref` to `BUILDCHAIN_VERSION`, or expands an\noptional `ref_template` containing exactly one `{version}`, and binds any\ndeclared provenance to the current release coordinate. Template expansion\nhappens after exact version selection; ambiguous or unsupported templates fail\nbefore `lifecycle.publish`. Requirement descriptors may omit `digest`; final\npublish evidence may not.\n\nThe action outputs `transaction-id`, `transaction-state`,\n`transaction-publication-state`, `transaction-sealed-bundle-root`,\n`transaction-resume-command`,\n`transaction-exact-tag`, `public-release-tag`, `transaction-release-sha`,\n`transaction-state-ref`, `transaction-state-sha`, `transaction-state-path`,\n`publish-evidence-path`, and `release-passport-path`, `release-passport-output-dir`,\n`release-passport-state-sha`, and `finalization-needed`.\n`transaction-state-ref` is the durable recovery location.\n`transaction-publication-state` provides the stable\n`prepared`, `sealed`, `package-published`, `alpha-complete`, or\n`release-complete` operator view. `transaction-resume-command` is the exact\nconsumer-facing resume entrypoint bound into the sealed manifest.\n`release-passport-state-sha` is the durable ref commit after the generated\n`release-passport/*` files have been uploaded into that recovery ref.\n`finalization-needed=true` means publish evidence is valid, but protected branch\nor ref finalization needs a later idempotent promotion run. For release\nfinalization, Buildchain may create a same-repository generated version-state\nPR when GitHub rejects the direct protected ref update; that PR is Buildchain\nbookkeeping, not a consumer-authored release change.\nSet `github-release: \"true\"` when the semver promotion should also publish the\npublic GitHub Release. After the release transaction reaches `complete` and\n`finalization-needed` is false, the action creates or updates the GitHub Release\nfor `public-release-tag`, applies deterministic metadata from the authoritative\npublication channel (`alpha` is a prerelease and never latest; `release`,\n`stable`, and `major` are stable and latest), and uploads the publish evidence\nfile plus generated release passport assets. Tag syntax remains the fallback for\nordinary callers that do not supply publication intent. For anchored/manual\npackage releases, `public-release-tag` is derived\nfrom the published package version, while `transaction-exact-tag` remains the\ninternal Buildchain transaction ref for recovery and audit. If the transaction is\nnot complete yet, the action defers GitHub Release publication to the next\nidempotent promotion run. When sealed release assets are present, those restored\nfiles replace caller-supplied artifact paths. After upload succeeds, the action\nwrites the `github_release` milestone back to the durable transaction; an\ninterruption before that write is safe to retry because release creation and\nasset replacement are idempotent.\n\nAfter a publish transaction reaches `complete`, the action generates the unified\n`buildchain-release-passport` in `.buildchain/release-passport` by default and\npersists those files under `release-passport/` in the durable release-state ref.\nSet `release-passport-product-name` to record the consumer product name, for\nexample `Libnode`, instead of the default `Buildchain`.\nSet `release-passport-kfd-1-witness-jsons` to newline-separated KFD-1\ncontract-world witness JSON paths when released artifacts must prove\nbyte-for-byte KFD contract surfaces. Buildchain imports the KFD metadata from\n`@kungfu-tech/kfd`, freezes the witness, verifies artifact bytes, and writes the\nresult under the KFD-provided `kfd-1` passport section.\nSet `release-passport-kfd-2-claim-jsons` to newline-separated KFD-2 public\nrelease trust claim JSON paths when a release makes additional human/agent\nvisible claims. Buildchain requires each public claim to bind declared sources,\nmachine-readable evidence, hashes, artifact coordinates, verification results,\naudit boundary, responsibility state, and residual risk. Unbound claims fail\npassport verification; prose-only claims downgrade the KFD-2 audit.\nSet `release-passport-kfd-3-prebuild-witness-jsons` to newline-separated KFD-3\ncollaboration-interface pre-build witness paths, then provide artifact-side\nevidence with `release-passport-kfd-3-artifact-witness-jsons` or a\nproduct-owned `release-passport-kfd-3-artifact-verify-command` such as\n`kungfu agent verify --json`. Buildchain compares declared shipped public\nsurfaces with artifact-exposed public surfaces and writes the result under the\nKFD-provided `kfd-3` passport section.\nSet `release-passport-kfd-adopter-manifest-json` to the standard full-cut\nadopter manifest and `release-passport-kfd-product-gate-jsons` to the\nnewline-separated KFD-4, KFD-5, and KFD-7 gate results. Buildchain binds the\nexact published KFD package, registry, verifier set, source, decision witness,\nand product-gate roots into both Passport and artifact evidence. The optional\n`release-passport-kfd-support-matrix-json` is comparison-only; it must exactly\nmatch the derived `kfd-support.json` compatibility projection and cannot widen\ncandidate, unsupported, draft, or non-shipped states.\nSet `release-passport-invariant-passport-jsons` to one or more product-owned\ninvariant Passport paths, or set `release-passport-invariant-passport-command`\nto a command that emits one canonical Passport JSON document. Buildchain does\nnot reinterpret product invariants: it verifies the declared semantic root,\nrequires a `verified` verdict, complete platform coverage, a clean exact source\nrevision, and then binds the result into `buildchain.release.json`. Missing,\nstale, falsified, incomplete, dirty, or tampered Passport evidence fails the\nrelease transaction closed.\nSet `release-passport-evidence-jsons` to newline-separated product-owned release\nevidence attachment indexes. Each JSON document must declare `schemaVersion`, a\nstable `id`, a product contract, and the exact release source SHA, tag, and\nchannel. Buildchain copies and hashes the documents, verifies their coordinates\nagainst the final Passport, and retains them in the release evidence bundle\nwithout interpreting product-specific or legal claims.\n\nWhen release coordinates are not known until promotion, set\n`release-passport-attachment-command`. Buildchain supplies\n`BUILDCHAIN_RELEASE_SOURCE_SHA`, `BUILDCHAIN_RELEASE_TAG`,\n`BUILDCHAIN_RELEASE_CHANNEL`, `BUILDCHAIN_RELEASE_VERSION`,\n`BUILDCHAIN_RELEASE_DEPLOYMENT_COORDINATE`, `BUILDCHAIN_RELEASE_TARGET_REF`, and\n`BUILDCHAIN_RELEASE_PASSPORT_OUTPUT_DIR`; the command must emit a JSON array or\nan object with a non-empty `files` array. Direct Action callers may still use\nthe v2 alias `release-passport-evidence-command`. Reusable v3 workflows reserve\nthat older name for the distinct post-activation released-evidence command.\n\nBuildchain's own release workflow sets `release-passport-buildchain-self-kfd:\n\"true\"`. In that mode the action generates Buildchain-owned KFD-1/2/3 witnesses\ninside the final version-state workspace, after the release transaction has\nmaterialized generated files such as `package.json` and `dist/site/*`. This\nkeeps self-hosted KFD witness hashes bound to the exact published package\ninstead of to a pre-promotion checkout.\nSet `release-passport-github-artifact-attestation-policy-jsons` to one or more\nnewline-separated `buildchain.github-artifact-attestation-policy/v1` paths when\nthe Release Passport must require GitHub keyless provenance for Linux release\nartifacts. The higher-level v3 promotion workflow exposes the single-artifact\n`github-artifact-attestation-policy-json` input and owns staging, signing,\nprovider verification, immutable GitHub Release evidence upload, and read-back;\ndirect action callers own those post-Passport steps themselves.\nWhen present, the passport includes the aggregate build summary, platform\nartifact manifests, npm publish evidence, dist-tag promotion evidence, the\nrelease-state ref, trusted publishing metadata, and the Buildchain transaction\nresult. After the first passport upload, Buildchain backfills the durable\nrelease-state SHA into `buildchain.release.json` and persists the passport\nagain, so the consumer-side passport is a complete audit entrypoint. Set\n`release-passport: \"false\"` only for a controlled recovery run that must skip\npassport generation.\n\nFinalization recovery is anchored to the durable transaction, not to a single\nworkflow run SHA. After generated version-state bookkeeping is applied, the\ncurrent channel head can be the generated version-state commit or a historical\nmerge commit that contains or corresponds to the recorded `release_material_sha`;\nit does not have to equal the original `source_sha` or the transaction\n`release_sha`. Reruns accept exact tags that already point at the transaction\nrelease/material SHA or the finalized channel head, and continue moving any\nmissing floating tags or dev/alpha refs before marking the transaction\n`complete`. An explicit recovery of an already `complete` transaction is also\naccepted when the requested source SHA, version, exact tag, channel, and target\nall match the durable record exactly. It returns the completed transaction\nwithout republishing package bytes; a source accepted only through later branch\nhistory is not sufficient for this terminal-state reuse.\n\nNormal reruns accept already-published artifacts only when evidence matches.\nMissing required artifacts can be published on the next run. Conflicting\nrefs, digests, or declared provenance put the transaction into\n`repair_required`; `abandoned` and\n`failed_permanently` also fail closed unless `publish-transaction-override` is\nset for a controlled repair. The same override may replace a stale transaction\nonly when its version, exact tag, target ref, and channel are unchanged, the\ntransaction is not complete, and it contains no published artifacts or\nevidence. This lets a newly admitted source retry a previously failed paper\npublication without weakening already-published facts.\n\nIn strict buildchain promotion, ref movement is also gated by the old ABV\ngovernance semantics:\n\n- when detailed target branch protection is readable, it must enforce\n  protection for administrators and require approving PR review plus the strict\n  `check` job from the `Verify` workflow; when GitHub withholds that\n  administration endpoint from the workflow token, the exact transaction must\n  instead prove a protected current head, same-repository merged PR,\n  independent approval, and the required successful `check` from its configured\n  GitHub App;\n- post-publish channel reconciliation reuses an already qualifying\n  provider-enforced policy when the workflow token cannot read or rewrite the\n  administrative protection document, and fails closed if the public branch\n  summary no longer carries the required check for everyone;\n- alpha promotion must come from a merged same-repository PR\n  `dev/vN/vN.M -> alpha/vN/vN.M`, or from a strict same-line\n  `publish-gate/alpha/vN/vN.M/<version> -> alpha/vN/vN.M` source-lock PR;\n- release promotion must come from a merged same-repository PR\n  `alpha/vN/vN.M -> release/vN/vN.M`, or from a strict same-line\n  `publish-gate/release/vN/vN.M/<version> -> release/vN/vN.M` source-lock PR;\n- major promotion must come from a merged same-repository PR\n  `release/vN/vN.M -> publish-gate/major`;\n- release promotion must have an exact alpha tag for the same patch line, and\n  the release source tree must match that alpha tag tree, so release does not\n  introduce new code after alpha;\n- anchored/manual release promotion may differ from that alpha tree only in\n  declared `version.files` and the configured anchor manifest, and only when the\n  checked-out release material has passed `lifecycle.verify` or the explicit\n  `verification-command`;\n- generated release and next-alpha version-state trees can be verified locally\n  with either the `verification-command` input or `buildchain.toml`\n  `lifecycle.verify` before any tags or channel refs move.\n\nThe reusable promotion workflow keeps governance reads, generated status checks,\nand generated ref updates on the run-scoped `github.token`. When branch\nprotection rejects generated bookkeeping, it supplies `BUILDCHAIN_PROMOTION_TOKEN`\nonly through `generated-pull-request-token` so the same-repository recovery PR can\nbe listed or created without broadening the governance client. Protected branch\nreview and check rules guard human channel merges, while the reusable build trust\ngate checks the source-lock channel HEAD and merged same-repository PR lineage\nbefore heavy build runners start. This action still independently rechecks PR\nlineage, alpha/release tree equivalence, and generated version-state verification\nbefore moving channel refs and tags.\nThe reusable `release-candidate-promote.yml` wrapper defaults\n`branch-protection-bypass-apps` to `github-actions`, so flow-internal promotion\ncan complete generated `dev`/`alpha`/`release` bookkeeping while ordinary human\npushes and PR merges remain governed by the one-review branch protection rule.\nThe promotion action rejects alternate App slugs and every user or team bypass,\nso the mutation path cannot widen the authority descriptor.\n\nThe tag names intentionally follow the old ABV release semantics:\nexact release tags are `vX.Y.Z`, exact alpha tags are `vX.Y.Z-alpha.N`, floating\nrelease tags are minor/major tags such as `v3.0` and `v3`, and floating alpha\ntags are minor-line tags such as `v3.0-alpha` plus cross-minor major tags such\nas `v3-alpha`. A major alpha tag only moves for the highest minor in that major\nwith a published alpha, so older-line maintenance cannot roll consumers back.\nBare tags such as `1.0.0` are not\nmaintained as buildchain release entrypoints.\n\nRepository rulesets should protect exact tags, not every `v*` tag. A ruleset\nsuch as `refs/tags/v*` also protects floating channel tags like `v3.0-alpha` and `v3-alpha`,\nwhich Buildchain must update after exact tags and publish evidence are durable.\nUse an exact-tag rule such as `refs/tags/v*.*.*` for immutable evidence tags and\nleave floating channel tags mutable for the promotion token."
    },
    {
      "id": "action:release-tail",
      "title": "Declarative Release Tail",
      "route": "/actions/release-tail",
      "category": "action",
      "capabilityGroup": "api-cli-reference",
      "audience": [
        "developer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "actions/release-tail/README.md",
      "digest": "sha256:f2a4344525a8422b0b063e213cdfddeadcc0cdb3c098e9bdbc112c4984e43861",
      "headings": [
        {
          "level": 1,
          "title": "Declarative Release Tail",
          "anchor": "declarative-release-tail"
        }
      ],
      "markdown": "# Declarative Release Tail\n\nThis Action executes the versioned `buildchain.release-tail/v1` declaration\nthrough one durable Buildchain transaction. It accepts only data bindings for\nsealed artifacts, rooted JSON documents, HTTP provider endpoints and released\nevidence inputs. It does not accept a command, script, executable path, plugin\nor repository callback.\n\nEvery mutation is preceded and followed by provider readback. Buildchain core,\nnot the adapter, compares the observed subject and target roots, owns retry and\nterminal classification, checkpoints state and emits the standardized receipt.\nTokens remain Action inputs and are never written to the transaction or\nreceipt."
    },
    {
      "id": "action:report-buildchain-issue",
      "title": "report-buildchain-issue",
      "route": "/actions/report-buildchain-issue",
      "category": "action",
      "capabilityGroup": "api-cli-reference",
      "audience": [
        "developer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "actions/report-buildchain-issue/README.md",
      "digest": "sha256:6c03ae2b3570ef2f3f8aa3dc42bfa05df3bb7639f85344ebe25f792d21b4276a",
      "headings": [
        {
          "level": 1,
          "title": "report-buildchain-issue",
          "anchor": "report-buildchain-issue"
        }
      ],
      "markdown": "---\nstatus: active\nperiod: ongoing\ntheme: buildchain-consumer-issue-action\ndoc_type: technical-reference\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-07-31\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-31\n  invisible_context: not asserted\n---\n\n# report-buildchain-issue\n\nCreate or update a Buildchain repository issue from a consumer workflow or from\nBuildchain's own workflow-friction feedback loop.\n\nThis action is intended for consumer repositories that need to report\nBuildchain-owned failures with enough evidence for maintainers to act. It\nrequires a token that can write issues on the target Buildchain repository.\nFor cross-repository consumers, generate that token with a GitHub App\ninstallation token or another scoped credential owned by the consumer\norganization.\n\n```yaml\n- uses: actions/create-github-app-token@v2\n  id: buildchain-issue-token\n  with:\n    app-id: ${{ secrets.BUILDCHAIN_ISSUE_APP_ID }}\n    private-key: ${{ secrets.BUILDCHAIN_ISSUE_APP_PRIVATE_KEY }}\n    owner: kungfu-systems\n    repositories: buildchain\n\n- uses: kungfu-systems/buildchain/actions/report-buildchain-issue@v3\n  if: failure()\n  with:\n    token: ${{ steps.buildchain-issue-token.outputs.token }}\n    summary: \"Reusable build failed before artifact finalization\"\n    failure-code: reusable-build-failed\n    buildchain-ref: ${{ inputs.buildchain-ref || 'v3' }}\n    diagnostics-path: .buildchain/artifacts/diagnostics.json\n```\n\nThe action computes a stable fingerprint from the consumer repository,\nworkflow, job, failure code, and Buildchain ref. When an open issue already\nexists for that fingerprint, it comments with the new run instead of opening a\nduplicate issue.\n\nBy default issue reporting is fail-soft:\n\n- `fail-on-error: \"false\"` prevents a reporting outage from hiding the original\n  build failure.\n- transient GitHub API 429/5xx errors and connection failures are retried.\n- if a configured label is missing, issue creation is retried without labels.\n- if issue creation/commenting is still unavailable, the action writes the full\n  copyable issue title, fingerprint, and body into the workflow summary.\n- common token, private-key, password, and authorization values are redacted\n  before submission.\n\nUse `dry-run: \"true\"` to verify the computed fingerprint and body shape without\ncalling GitHub.\n\nFor Buildchain-owned workflow friction, use `report-kind: workflow-friction`.\nThis uses a separate marker and default labels so duplicate PRs, duplicate\nbuilds, transient API failures, stale release-state, or missing RC evidence can\nbe grouped without mixing with consumer failure reports:\n\n```yaml\npermissions:\n  issues: write\n\nsteps:\n  - uses: actions/create-github-app-token@v2\n    id: buildchain-issue-token\n    with:\n      app-id: ${{ secrets.BUILDCHAIN_ISSUE_APP_ID }}\n      private-key: ${{ secrets.BUILDCHAIN_ISSUE_APP_PRIVATE_KEY }}\n      owner: kungfu-systems\n      repositories: buildchain\n\n  - uses: kungfu-systems/buildchain/actions/report-buildchain-issue@v3\n    if: failure()\n    with:\n      token: ${{ steps.buildchain-issue-token.outputs.token || secrets.BUILDCHAIN_ISSUE_TOKEN || secrets.BUILDCHAIN_PROMOTION_TOKEN || github.token }}\n      report-kind: workflow-friction\n      target-repository: kungfu-systems/buildchain\n      repository: ${{ github.repository }}\n      workflow: ${{ github.workflow }}\n      run-id: ${{ github.run_id }}\n      run-attempt: ${{ github.run_attempt }}\n      channel: alpha/v3/v3.0\n      source-sha: ${{ github.sha }}\n      friction-class: duplicate-build\n      related-runs-json: ${{ steps.classify.outputs.related-runs-json }}\n      heavy-builds-json: ${{ steps.classify.outputs.heavy-builds-json }}\n      comment-cooldown-hours: \"24\"\n```\n\n`comment-cooldown-hours` is optional. When it is greater than zero, Buildchain\nstill deduplicates by fingerprint but skips adding another comment if the\nexisting issue already received a recent update."
    },
    {
      "id": "action:run-lifecycle",
      "title": "run-lifecycle",
      "route": "/actions/run-lifecycle",
      "category": "action",
      "capabilityGroup": "api-cli-reference",
      "audience": [
        "developer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "actions/run-lifecycle/README.md",
      "digest": "sha256:6f0fa7439801d0557e59c6112235b2db0bd4439fcd1660a5cac14994be7c4314",
      "headings": [
        {
          "level": 1,
          "title": "run-lifecycle",
          "anchor": "run-lifecycle"
        }
      ],
      "markdown": "# run-lifecycle\n\nRun a Buildchain lifecycle stage or an explicit command and write a deterministic\nartifact manifest.\n\n```yaml\n- uses: kungfu-systems/buildchain/actions/run-lifecycle@v3\n  with:\n    stage: build\n    required: \"true\"\n    artifact-name: my-product-linux-x64-${{ github.sha }}\n    artifact-paths: |\n      dist\n      build/stage\n```\n\nWhen `command` is provided, it overrides `buildchain.toml` for that invocation.\nWhen `command` is empty, the action loads `buildchain.toml` and runs the named\nstage.\n\n`timeout-minutes` defaults to 120 and bounds either command source. A\nstage-specific `timeout_minutes` in `buildchain.toml` takes precedence. Timeout\nerrors identify the lifecycle stage and platform so a hung self-hosted build can\nbe diagnosed after the runner is released.\n\nThe action writes both a full manifest and a compact summary. It also exposes\nthe summary as outputs for reusable workflow callers:\n\nFor a `build` stage, paths selected by `[[signing.artifacts]]` for the current\n`platform-id` are automatically included in the lifecycle manifest even when\nthey sit outside `artifact-paths`. This binds every byte sent to the signing\nauthority without changing which ordinary product paths the caller uploads.\n\n| Output | Meaning |\n| --- | --- |\n| `manifest-path` | Full manifest path |\n| `summary-path` | Compact summary path |\n| `artifact-name` | Resolved artifact name |\n| `artifact-file-count` | Number of manifest files |\n| `artifact-total-bytes` | Total manifest bytes |\n| `artifact-summary-json` | One-line JSON summary |\n| `expected-artifacts-ok` | `true` when expectations passed |\n\n`expected-artifacts-json` can require exact paths, file count bounds, and a\nminimum byte total:\n\n```yaml\nwith:\n  expected-artifacts-json: >-\n    {\"minFiles\":2,\"requiredPaths\":[\"dist/app.tar.gz\",\"dist/checksums.txt\"]}\n```\n\nFor long native builds, set `sample-process-tree: \"true\"` and pass\n`process-summary-path`. The action wraps either the explicit `command` or the\nconfigured lifecycle stage with `buildchain sample process-tree`, then embeds\nthe produced summary in the lifecycle diagnostics artifact:\n\n```yaml\nwith:\n  stage: build\n  sample-process-tree: \"true\"\n  process-summary-path: .buildchain/diagnostics/process-summary.json\n```\n\nCustom wrappers can still pass an existing sampler report or summary with\n`process-summary-path`; the action reads it after the lifecycle command\nfinishes, so commands may generate the file during the same invocation.\nSet `process-summary-required: \"false\"` when the summary is an optional sidecar,\nfor example when a reusable workflow may skip an optional build stage.\nThe diagnostics directory also includes `diagnostics-manifest.json`, a compact\ninventory of the diagnostics sidecars with byte counts and sha256 hashes."
    },
    {
      "id": "action:validate-config",
      "title": "validate-config",
      "route": "/actions/validate-config",
      "category": "action",
      "capabilityGroup": "api-cli-reference",
      "audience": [
        "developer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "actions/validate-config/README.md",
      "digest": "sha256:ef48cd786973d9b6a1970c73ed780444415369075392f23404cdba5e1f988410",
      "headings": [
        {
          "level": 1,
          "title": "validate-config",
          "anchor": "validate-config"
        },
        {
          "level": 2,
          "title": "Usage",
          "anchor": "usage"
        }
      ],
      "markdown": "---\nstatus: active\nperiod: ongoing\ntheme: buildchain-config-validation-action\ndoc_type: technical-reference\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-07-31\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-31\n  invisible_context: not asserted\n---\n\n# validate-config\n\nBuildchain v3 action for validating `.buildchain/buildchain.toml` without running lifecycle\ncommands.\n\nUse this action during repository migration when a heavyweight project needs to\nprove that its Buildchain version state and lifecycle declaration are ready, but\nthe actual build should not run yet.\n\n## Usage\n\n```yaml\n- uses: kungfu-systems/buildchain/actions/validate-config@v3\n  with:\n    require-version-state: \"true\"\n    require-lifecycle-stages: \"install,build,verify\"\n```\n\nThe action checks:\n\n- `buildchain.toml` exists and uses schema `1`;\n- configured version-state files exist and expose a string version;\n- anchored/manual version strategy declarations and JSON/TOML anchor manifests\n  are structurally valid when configured;\n- web-surface project, channel, deploy adapter, retention, and staging security\n  declarations are structurally valid when configured;\n- required lifecycle stages are declared and structurally valid.\n\nIt does not execute `lifecycle.install`, `lifecycle.build`, `lifecycle.verify`,\nor any other lifecycle command.\n\nOutputs include `project-type`, `project-name`, `project-site`, `channels`, and\n`deploy-adapters-json`, so callers can route site workflows without reparsing\nTOML in every repository."
    },
    {
      "id": "api:node-package",
      "title": "Buildchain Core Package",
      "route": "/api/node-package",
      "category": "api",
      "capabilityGroup": "api-cli-reference",
      "audience": [
        "developer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "packages/core/README.md",
      "digest": "sha256:a73db80985e32c2ebb4ae94e30bc0e9bdc06f04eae189e8af25f89e901c14573",
      "headings": [
        {
          "level": 1,
          "title": "Buildchain Core Package",
          "anchor": "buildchain-core-package"
        },
        {
          "level": 2,
          "title": "Toolkit Imports",
          "anchor": "toolkit-imports"
        }
      ],
      "markdown": "# Buildchain Core Package\n\nShared code lives here when workflow and action migration shows repeated logic\nthat is worth centralizing.\n\nCurrent shared surfaces:\n\n- `buildchain.toml` loading and normalization;\n- version-state file discovery and update helpers;\n- lifecycle stage normalization and execution;\n- config validation for release-package and `web-surface` projects.\n- toolkit observability logging through `@kungfu-tech/buildchain/logging`;\n- toolkit diagnostics and native profile collection through\n  `@kungfu-tech/buildchain/diagnostics`;\n- source/version/module/product build facts through\n  `@kungfu-tech/buildchain/build-facts`;\n- release passport creation and verification through\n  `@kungfu-tech/buildchain/release-passport`.\n- anchored/manual derived witness preflight and exact-tree evidence through\n  `@kungfu-tech/buildchain/anchored-version-material`.\n- sealed exact-root and KFD assessment inputs for KFX admission through\n  `@kungfu-tech/buildchain/artifact-verification-envelope`.\n- managed KFD / Release Passport badge bundle facts and README marker blocks\n  through `@kungfu-tech/buildchain/badges`.\n- publication artifact manifests, source bundles, and publication artifact\n  passports through `@kungfu-tech/buildchain/publication-artifact`.\n- two-clean-build byte reproducibility receipts through\n  `@kungfu-tech/buildchain/publication-reproducibility`.\n- build-once publication bundle manifests and exact-byte verification through\n  `@kungfu-tech/buildchain/publication-sealed-bundle`.\n- governed Paper work-branch start/submit, fleet audit/update, scaffold,\n  preflight, status, npm bootstrap, build, Alpha, and resume plans through\n  `@kungfu-tech/buildchain/paper`.\n\n## Toolkit Imports\n\nThe npm package exports ESM APIs. JavaScript build scripts should import these\nAPIs directly instead of spawning the `buildchain` CLI:\n\n```js\nimport { createBuildchainLogger } from \"@kungfu-tech/buildchain/logging\";\n\nconst logger = createBuildchainLogger({ source: \"user\", component: \"native\" });\nawait logger.span(\"native.package\", { phase: \"package\" }, packageArtifacts);\n```\n\nThe CLI remains the right surface for GitHub Actions steps, shell scripts, and\nnon-JavaScript build tools.\n\nDiagnostics consumers should import the published subpath and compare stable\ncontracts through the exported constants instead of hardcoding JSON contract\nnames:\n\n```js\nimport {\n  BUILDCHAIN_DIAGNOSTICS_CONTRACT,\n  BUILDCHAIN_DIAGNOSTICS_SUMMARY_CONTRACT,\n  collectRunnerDiagnostics,\n  summarizeDiagnosticsArtifacts,\n} from \"@kungfu-tech/buildchain/diagnostics\";\n```\n\nCommonJS scripts can use dynamic imports for the same package surfaces:\n\n```js\nconst { createBuildchainLogger } =\n  await import(\"@kungfu-tech/buildchain/logging\");\nconst { collectRunnerDiagnostics } =\n  await import(\"@kungfu-tech/buildchain/diagnostics\");\n```\n\nBuild facts consumers can collect source-bound module/product facts before\npublishing and pass those facts into the release passport:\n\n```js\nimport {\n  collectModuleBuildFacts,\n  writeBuildFacts,\n} from \"@kungfu-tech/buildchain/build-facts\";\n\nconst fact = collectModuleBuildFacts({ moduleId: \"native-core\" });\nwriteBuildFacts({ fact, output: \".buildchain/facts/native-core.json\" });\n```\n\nKFX producers can seal one passing artifact verification with exact roots,\nidentity, lifecycle, revocation, and an existing ADR-0052 assessment. Consumers\nverify or project the same envelope instead of reconstructing bindings:\n\n```js\nimport {\n  projectArtifactVerificationEnvelopeToKfx,\n  verifyArtifactVerificationEnvelope,\n} from \"@kungfu-tech/buildchain/artifact-verification-envelope\";\n```\n\nPublication repositories can produce site-consumable paper/report facts without\nbecoming web-surface repositories. When `[publication.archive]` is configured,\nthe same API also maintains the append-only publication registry used by site\nrepositories for latest and historical version pages. The preferred\n`latex-docker` toolchain records the pinned build-images LaTeX builder digest in\nthe publication artifact passport:\n\n```js\nimport { writePublicationArtifact } from \"@kungfu-tech/buildchain/publication-artifact\";\n\nwritePublicationArtifact({ sourceSha: process.env.GITHUB_SHA });\n```\n\nBefore publication admission, prove the exact PDF, source bundle, manifests,\nand npm tarball twice from the same Git commit:\n\n```js\nimport { verifyPublicationReproducibility } from \"@kungfu-tech/buildchain/publication-reproducibility\";\n\nconst receipt = verifyPublicationReproducibility({\n  sourceSha: process.env.GITHUB_SHA,\n  promote: true,\n});\nif (!receipt.qualifying) throw new Error(\"publication is not reproducible\");\n```\n\nBind the promoted bytes into the durable build-once publication envelope:\n\n```js\nimport {\n  createPublicationSealedBundle,\n  verifyPublicationSealedBundle,\n} from \"@kungfu-tech/buildchain/publication-sealed-bundle\";\n```\n\nThe sealed manifest names the exact npm tarball and release assets. Promotion\npersists those binary files before registry publication and verifies them again\nwhen a fresh runner resumes.\n\nPaper automation can use the same typed contracts as the CLI:\n\n```js\nimport {\n  collectPaperPreflight,\n  collectPaperStatus,\n  planPaperMigration,\n  planPaperScaffold,\n  writePaperMigration,\n} from \"@kungfu-tech/buildchain/paper\";\n```\n\nPlanning and observation are side-effect free. `writePaperScaffold()` and\n`writePaperMigration()` perform the bounded local writes, while external\nmutations remain explicit CLI operations guarded by `--execute`.\n\nWeb-surface validation stays in core because both local scripts and GitHub\nActions need the same fail-closed interpretation of project, channel, deploy,\nretention, and staging security declarations.\n\nREADME badge consumers should import the public badge subpath and treat\nMarkdown as a projection of the returned facts:\n\n```js\nimport {\n  collectBadgeBundleFacts,\n  renderBadgeBundleBlock,\n} from \"@kungfu-tech/buildchain/badges\";\n\nconst facts = await collectBadgeBundleFacts({ cwd: process.cwd() });\nconst markdown = renderBadgeBundleBlock(facts);\n```\n\nThe older `@kungfu-tech/buildchain/readme-badges` subpath remains available for\ncallers that need the full README badge surface instead of the default\nKFD-1 / KFD-2 / KFD-3 / Release Passport bundle.",
      "slug": "node-package"
    },
    {
      "id": "manual:artifact-verification-envelope",
      "title": "Artifact Verification Envelope",
      "route": "/docs/artifact-verification-envelope",
      "category": "manual",
      "capabilityGroup": "getting-started",
      "audience": [
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "docs/artifact-verification-envelope.md",
      "digest": "sha256:514911d2a5ee8ea65e070ffb0fc81a87f0ae35d7d87ff61999e47f784a7e9769",
      "headings": [
        {
          "level": 1,
          "title": "Artifact Verification Envelope",
          "anchor": "artifact-verification-envelope"
        },
        {
          "level": 2,
          "title": "Public API",
          "anchor": "public-api"
        },
        {
          "level": 2,
          "title": "Canonicalization and roots",
          "anchor": "canonicalization-and-roots"
        },
        {
          "level": 2,
          "title": "Fail-closed behavior",
          "anchor": "fail-closed-behavior"
        }
      ],
      "markdown": "# Artifact Verification Envelope\n\nBuildchain can turn a passing exact-artifact passport verification into one\nsealed, versioned input for Kungfu KFX admission. The envelope carries the\npublic verification result together with exact package, source, dependency,\nbuild-plan, toolchain, artifact, qualification, and verifier roots; issuer and\npublisher identity; lifecycle and revocation facts; and an existing ADR-0052\nKFD assessment.\n\nThe envelope does not create a second KFD evaluator. It validates and binds an\nassessment produced by the Kungfu KFD lifecycle. It also does not claim that an\nartifact is malware-free, universally safe, fit for every workspace, or\nauthorized as a Product System component.\n\n## Public API\n\nImport the dedicated package subpath:\n\n```js\nimport {\n  projectArtifactVerificationEnvelopeToKfx,\n  sealArtifactVerificationReport,\n  verifyArtifactVerificationEnvelope,\n} from \"@kungfu-tech/buildchain/artifact-verification-envelope\";\n```\n\n`verifyArtifactPassport` also accepts an optional `verificationEnvelope`\nobject. Existing callers that omit it receive the unchanged\n`kungfu-buildchain-artifact-verification` v1 result.\n\n```js\nconst attestation = await verifyArtifactPassport({\n  subject: \"dist/example.kfx\",\n  passportLocation: \"dist/buildchain.release.json\",\n  verificationEnvelope: {\n    bindings,\n    kfdAssessment,\n    issuedAt,\n    expiresAt,\n    revocation,\n  },\n});\n```\n\nThe result keeps the artifact-verification v1 fields that existing consumers\nunderstand and adds:\n\n- `bindings`: the schema-closed `kungfu.kfx-trust-inputs/v1` exact roots and\n  identities;\n- `issuedAt`, `expiresAt`, `revoked`, and a root-bound `revocation` fact;\n- `kfdAssessment`: the pinned fresh `kungfu.trust.assessment/v1` lifecycle\n  result;\n- `envelope`: the envelope contract, canonicalization version, and exact\n  content root.\n\n`projectArtifactVerificationEnvelopeToKfx` returns the same sealed report as\n`attestation`, its exact `bindings` as `trustInputs`, and its existing\n`kfdAssessment`. A consumer does not reconstruct fields, recompute the KFD\ndecision, or inspect private Buildchain structures.\n\nThe read-only CLI uses those same functions for portable verification and\nprojection:\n\n```bash\nbuildchain verify artifact-envelope envelope.json \\\n  --assessment-time 150 \\\n  --expected-root sha256:... \\\n  --expected-issuer buildchain.libkungfu.dev \\\n  --expected-publisher kungfu-systems \\\n  --expected-contract buildchain.release/v1 \\\n  --json\n\nbuildchain project kfx-admission envelope.json \\\n  --assessment-time 150 \\\n  --json\n```\n\nThe projection's `envelopeRoot` is the same root returned by the Node verifier.\nThe CLI never adds consumer-side bindings or KFD conclusions.\n\n## Canonicalization and roots\n\nThe v1 envelope uses `buildchain-stable-json/v1`: object keys are sorted\nrecursively, array order is retained, and the root is lowercase SHA-256 with a\n`sha256:` prefix. `envelope.root` is excluded from its own root basis.\n\nThe KFD report hash is independently recomputed over the report with\n`report_hash` removed. The envelope is accepted only when:\n\n- the base artifact passport verification passes;\n- `bindings.artifactRoot` equals both the exact subject digest and the matched\n  passport artifact digest;\n- every binding root is canonical lowercase SHA-256;\n- `bindings.qualificationRoot` equals the recomputed KFD `report_hash`;\n- the assessment key matches the report and its lifecycle state is `fresh`;\n- the report binds purpose, query proof, contract world, policy, and at least\n  one fact-surface root;\n- lifecycle bounds are active and revocation facts are internally consistent;\n- any caller-pinned envelope root, issuer, publisher, or contract version\n  matches exactly.\n\n## Fail-closed behavior\n\n`verifyArtifactVerificationEnvelope` returns a machine-readable check report.\nIt rejects sibling artifacts, root tampering, identity drift, invalid contract\nversions, expired or revoked envelopes, stale assessments, altered KFD report\ncontent, and missing fact-surface bindings. Callers may pin expected authority\nfields without changing the envelope.\n\nThe canonical root detects changed serialized content; authenticity still\ndepends on the pinned Buildchain verifier and release passport authority. The\nenvelope is supply-chain and evidence input. Kungfu Product and Workspace\npolicy retain operation, capability, and System-role authority."
    },
    {
      "id": "manual:auditable-demo",
      "title": "Auditable Demo Pipeline",
      "route": "/docs/auditable-demo",
      "category": "manual",
      "capabilityGroup": "reusable-build",
      "audience": [
        "consumer",
        "agent"
      ],
      "maturity": "preview",
      "sourcePath": "docs/auditable-demo.md",
      "digest": "sha256:c49e734fdfe3b74d317e23a523e198f1194b2c7cd16cca87e8e3a3ffc7bf589f",
      "headings": [
        {
          "level": 1,
          "title": "Auditable Demo Pipeline",
          "anchor": "auditable-demo-pipeline"
        },
        {
          "level": 2,
          "title": "Declarative Standalone Binary Scenarios",
          "anchor": "declarative-standalone-binary-scenarios"
        },
        {
          "level": 2,
          "title": "Authority Boundary",
          "anchor": "authority-boundary"
        },
        {
          "level": 2,
          "title": "Required Gate",
          "anchor": "required-gate"
        },
        {
          "level": 2,
          "title": "Selective Render",
          "anchor": "selective-render"
        },
        {
          "level": 2,
          "title": "Media Qualification Profiles",
          "anchor": "media-qualification-profiles"
        },
        {
          "level": 2,
          "title": "Consumer Example",
          "anchor": "consumer-example"
        },
        {
          "level": 2,
          "title": "Failure Evidence",
          "anchor": "failure-evidence"
        }
      ],
      "markdown": "---\nstatus: draft\nperiod: 2026-07\ntheme: auditable-demo-pipeline\ndoc_type: technical-contract\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: self-reviewed\nlast_reviewed: 2026-08-05\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-08-02\n  invisible_context_boundary: No hidden model build, parameter count, or private corpus is asserted.\n---\n\n# Auditable Demo Pipeline\n\nBuildchain's auditable demo workflow turns an exact GitHub build artifact into\ntwo distinct evidence products:\n\n1. a required qualified Gate bundle; and\n2. an optional rendered media bundle that can exist only after that exact Gate\n   bundle passes.\n\nThe public reusable workflow is\n`.github/workflows/.auditable-demo.yml`. It is consumer-neutral: Buildchain\ndoes not know how a Kungfu, library, service, or application artifact should be\ninterpreted. The consumer owns a small checked-in executable adapter.\n\nFor standalone binary CLIs, the higher-level first-class surface is\n`.github/workflows/.declarative-auditable-demo.yml`. A consumer checks in only\n`.buildchain/auditable-demo.json`, builds and uploads its exact same-run binary\nplus metadata, and passes the producer-owned artifact name and digest to that\nworkflow. Buildchain then owns capture, Gate adaptation, independent native\n1080p and 720p rendering, Release Passport construction, content-addressed\nmaterialization, and the protected README update pull request. No\nproduct-specific capture, adapter, passport, or materializer is required.\n\n## Declarative Standalone Binary Scenarios\n\nThe schema is `contracts/auditable-demo-scenario-v1.schema.json`. One scenario\ncan declare up to eight demos, and each demo can contain up to twelve ordered\nliteral argv steps. Steps in one demo share a disposable workspace; separate\ndemos and the two rendition captures do not. Commands are never accepted as a\nshell string. An omitted or explicit `standard` duration class remains bounded\nto 60 seconds. A reviewed `execution.durationClass: long-form` declaration may\nraise the scenario and literal step ceilings to 180 seconds; it does not change\nthe default. Both classes retain 4 MiB per step, a clean Home/XDG environment,\nno inherited credentials, and a network-disabled read-only container with\nbounded tmpfs.\n\nConsumers may optionally add a\n`buildchain.declarative-demo-presentation/v1` presentation. This contract\nbinds one consumer-owned proof label, question, summary, and optional\ntransition to every demo in declared order. Buildchain verifies that each\nquestion is the same title used by capture and media; it does not invent or\nreinterpret the product argument.\n\nThe presentation also chooses one of two README materialization modes. The\ndefault, when no presentation is declared, remains the original full generated\nblock with commands, renditions, evidence, and claim boundary. `media-only`\nupdates only the image inside each existing README marker so consumer-authored\nnarrative and transitions survive regeneration. The generated technical\ndetails move to a separately declared Markdown specification, where stable\nper-demo markers preserve proof order and idempotent updates. The publication\npull request stages that specification together with the README and\ncontent-addressed evidence. No presentation field grants publication or Work\nauthority.\n\nThe optional top-level `compositionMode` is an explicit visual contract.\nOmitting it preserves `presentation-framed`; declaring `terminal-fill` makes\nthe bounded PTY replay the complete pixel surface without renderer-owned\nwindow chrome. Buildchain carries that choice into both native scenes. It does\nnot infer full-frame intent from output resolution.\n\nThe optional `buildchain.declarative-demo-playback/v1` contract separates\nobserved command latency from presentation timing. Its\n`deterministic-readable` mode preserves the captured terminal event payloads\nand their order, records the observed final-event time as non-authoritative\nevidence, and maps event ordinals onto the declared `activeDurationMs` before a\nbounded `finalHoldMs`. Both native renditions therefore replay at the same\nreadable pace even when an identical command runs faster or slower. Omitting\nthe contract preserves the original PTY timestamp behavior.\n\nThe uploaded metadata must bind the executable SHA-256, declare an empty\nruntime dependency set, and provide a bounded `executableFiles` array of exact\nartifact-relative paths and SHA-256 digests. GitHub Artifact transport does not\nretain Unix executable modes, so Buildchain restores mode `0755` only for this\ndigest-verified executable closure and verifies the same closure again inside\nthe network-disabled capture boundary. It never recursively changes artifact\nmodes. This metadata controls assembly only and grants no execution,\npublication, or identity authority. Capture rejects an artifact name or upload\ndigest that does not resolve to exactly one live artifact from the current workflow run.\n\nConsumers may also declare one bounded, non-interactive `transportSmoke` argv\nin the same scenario and opt the reusable build into\n`pre-upload-transport-smoke-scenario-path`. Before any GitHub Artifact or S3\nrelay upload, Buildchain copies the exact distribution directory, removes Unix\nexecute bits to simulate transport, restores only the digest-bound executable\nclosure, and runs that real binary with a clean Home/XDG environment. A missing\nlauncher, runtime, or embedded interpreter therefore fails before the expensive\nupload begins. This is a transport diagnostic with no authority grants; the\nlater network-disabled capture and Gate remain the qualification authority.\nIt retains ANSI terminal bytes with the real PTY read timestamps, verifies\ndeclared stdout and JSON file facts, enforces the total deadline while a step is\nrunning, and removes the disposable workspace before emitting evidence.\n\nBoth manual validation and alpha or release refreshes call the same reusable\nworkflow. Manual callers select Gate-only or full rendering and can explicitly\nrequest a materialization PR. Release callers select full rendering and the\nsame materializer automatically; there is no separate release-only recording\nimplementation. Publication requires a dedicated update token and target\nbranch. The token is an explicit bounded capability, while actor identity,\nfirst-party/System classification, KFD compliance, Product System metadata,\npackage metadata, registry history, scans, and generated evidence grant no\nauthority.\n\n```yaml\njobs:\n  demo:\n    needs: exact-binary\n    uses: kungfu-systems/buildchain/.github/workflows/.declarative-auditable-demo.yml@BUILDCHAIN_EXACT_SHA\n    with:\n      source-ref: ${{ github.sha }}\n      binary-artifact-name: ${{ needs.exact-binary.outputs.artifact-name }}\n      binary-artifact-digest: ${{ needs.exact-binary.outputs.artifact-digest }}\n      scenario-path: .buildchain/auditable-demo.json\n      renderer-image: ghcr.io/kungfu-systems/build-images/demo-renderer@sha256:RENDERER_DIGEST\n      render-media: true\n      render-failure-advisory: false\n      media-profile: responsive-web-delivery-v1\n      materialize: true\n      materialize-base-ref: dev/v1/v1.0\n    secrets:\n      DEMO_UPDATE_TOKEN: ${{ secrets.DEMO_UPDATE_TOKEN }}\n```\n\nBuildchain recursively consumes this surface in\n`.github/workflows/auditable-demo.yml` using its own exact standalone binary\nand the beginner bootstrap scenario in `.buildchain/auditable-demo.json`.\n\n## Authority Boundary\n\nThe retained build output is authoritative. The adapter reads that exact\nartifact and projects three files:\n\n```text\ncomplete-transcript.txt\npublic-projection.json\nscene.json\n```\n\nIt may additionally emit one declared `terminal-capture.json` using\n`kungfu.terminal-capture/v1`. The optional capture is bounded to 60 seconds by\ndefault or 180 seconds only when its scene explicitly declares `long-form`,\nfixed 80-200 by 24-80 terminal cells, 10,000 events, and 4 MiB of canonical\nbase64 bytes. It must contain a qualified completion sentinel and an explicitly\nempty authority-grant list. Existing three-file adapters remain valid.\n\nThe completion sentinel names a consumer-owned versioned schema, the exact\n`qualified` status, a content root, and an event count. Buildchain validates\nthat envelope generically; it does not reinterpret a command-specific result\nas Agent Work Lab evidence or grant authority from the schema name. The\nconsumer projection and its retained source artifact remain responsible for\nthe exact claim boundary.\n\nTerminal bytes are volatile observations, not Work, Warrant, capability, or\npublication authority. First-party or System identity, KFD compliance, Product\nSystem metadata, package metadata, scan output, registry history, and\nstandalone generation remain non-authoritative unless an exact higher-level\ncontract independently admits them.\n\nThe adapter must not rebuild or rerun the product. It receives:\n\n```text\n--artifact-root PATH\n--output PATH\n--source-coordinate PATH\n```\n\nConsumers with one shared adapter for several deterministic demos may also set\n`adapter-arguments-json` to a bounded JSON array. Buildchain parses the array,\nrejects malformed values, newlines, NUL bytes, more than 32 arguments, values\nlonger than 256 bytes, and attempts to override the three coordinate flags\nabove, then appends the accepted strings directly to the adapter argv. It never\nevaluates a shell command. The exact argument vector and its content root are\nretained in `adapter.json`; the Gate receipt binds that root. Adapter arguments\nselect consumer-owned capture behavior only and grant no authority.\n\n`--source-coordinate` identifies the caller repository, run, artifact id,\nartifact name, upload digest, expiry, and exact source SHA. The workflow finds\nexactly one live artifact with the requested name in the current caller run and\nrejects a digest mismatch before invoking the adapter. Callers must pass the\ndigest emitted by their own `upload-artifact` step; a name resolved later from\nthe Actions API is discovery evidence, not a substitute for that producer\noutput.\n\nBuildchain's reusable build workflow exposes `artifact-coordinates-json` after\nall resolved platform uploads complete. That producer-owned output binds every\nplatform id to its same-run artifact id, name, upload digest, URL, and expiry,\nso a consumer that delegates its build to Buildchain can pass an exact\ncoordinate without rediscovering authority in a downstream job. The build\naggregate fails closed if any declared platform lacks one live, digest-bearing\nartifact coordinate. The compact coordinate set is sorted by platform id so\ndownstream machine consumers do not depend on matrix completion order.\n\nThe adapter runs with a disposable Home/XDG/npm prefix, a minimal environment,\nand no GitHub, npm, or cloud credential injection. It must be a regular,\nnon-symlink, executable file inside the exact checked-out consumer source.\n\n## Required Gate\n\nThe Gate:\n\n- checks out the exact consumer source and exact called-workflow SHA;\n- resolves and downloads one exact same-run GitHub Artifact;\n- invokes the checked-in adapter by argv, never as an evaluated shell string;\n- rejects undeclared adapter outputs, symlinks, invalid UTF-8, invalid scene or\n  projection or terminal-capture schemas, implicit capture grants,\n  out-of-range transcript references, and oversized input;\n- derives a one-second compatibility scene from the consumer projection;\n- anonymously pulls an immutable `image@sha256:digest` renderer;\n- runs it as non-root with `--network none`, a read-only root filesystem, and a\n  bounded tmpfs;\n- verifies the renderer manifest, media probe, exact input roots, exact output\n  member set, and complete checksums;\n- independently verifies the requested composition mode, browser-observed\n  content viewport, PTY rows and columns, and deterministic cell geometry for\n  every frame set; `terminal-fill` is rejected unless the viewport and cell\n  grid resolve to the complete declared frame;\n- uploads a content-addressed qualified bundle plus an independent GitHub\n  Artifact id, URL, archive digest, and expiry-bearing source coordinate.\n\nThe Gate bundle contains the complete consumer transcript/projection/scene,\nsource artifact coordinate, adapter identity, bounded renderer evidence, a\npassed gate receipt, and checksums covering every member exactly once.\n\n## Selective Render\n\n`render-media: true` enables the full-media step only after every declared demo\nhas passed the required Gate. It recomputes each Gate member root, verifies the\nexact source SHA and renderer digest, and only then renders the complete\nqualified scene.\n\nThe media bundle contains MP4, WebM, GIF, poster, probe, renderer manifest,\nrenderer checksums, passed Gate receipt, a versioned media receipt, and\ndistribution checksums. A web-delivery profile also retains\n`media-inspection.json`, whose content root is bound into the receipt.\n`render-media: false` does not weaken or skip the Gate.\n\n`render-failure-advisory: true` makes only the full-media step advisory. A\nrender failure remains visible as a failed step and workflow warning, while the\nrequired Gate keeps its normal failure semantics. Failed or partial media can\nnever open a materialization PR. Use this for an Alpha lane whose binary\npublication must not depend on animation capacity; keep the default `false`\nfor explicit media refreshes and other workflows that require complete media.\n\nWhen the Gate bundle contains a qualified terminal capture, the render job\npasses it read-only to the immutable renderer. The renderer manifest binds the\ncapture root and terminal-state-machine version, but raw capture bytes remain\nin the Gate bundle rather than being copied into the public media bundle.\nMissing, malformed, out-of-bounds, non-full-frame, rendition-mismatched, or\ninternally drifted composition evidence fails before media finalization.\n\n## Media Qualification Profiles\n\nThe single machine-readable source is\n`contracts/auditable-demo-media-profiles-v1.json`. Callers select one reviewed\nprofile through `media-profile`; they cannot pass ffmpeg commands, codec flags,\nshell fragments, arbitrary profile paths, or transcoding instructions.\n\n| Profile                                | Meaning                                                                                                                                                                                                                                                                                        |\n| -------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| `archive-v1`                           | Default compatibility contract. Retains the exact renderer outputs and classifies GIF as README compatibility evidence without making a browser-delivery claim.                                                                                                                                |\n| `web-delivery-v1`                      | Independently qualifies H.264 MP4 and VP9 WebM playback sources, forbids audio, requires exact scene dimensions and bounded duration/frame-rate drift, checks per-rendition byte ceilings, and proves MP4 `moov` precedes `mdat`. PNG remains the lossless evidence poster.                    |\n| `responsive-web-delivery-v1`           | Extends `web-delivery-v1` with exact 1280x720 H.264 MP4 and VP9 WebM responsive sources plus a 1280x720 README GIF while keeping the primary MP4/WebM and evidence poster at the source scene dimensions. Every declared downscale must preserve the scene aspect ratio and may never upscale. |\n| `responsive-long-form-web-delivery-v1` | Extends the responsive profile for explicitly admitted long-form scenes. Its measured-baseline multipliers raise only the GIF ceiling to 8 MiB and the four video ceilings to 4 MiB; all codec, native-resolution, no-audio, duration, and authority checks remain unchanged.                  |\n| `site-hero-v1`                         | Extends `web-delivery-v1` and additionally requires a qualified WebP browser poster. The current Build Images v1 renderer does not emit that member, so selecting this profile fails closed until the producer adds it.                                                                        |\n\nFor web-delivery profiles, Buildchain runs its own fixed `ffprobe` invocation\ninside the same immutable, network-disabled renderer image. That command is\nBuildchain-controlled; the producer cannot inject flags. The resulting witness\nrecords exact roots and byte counts plus container, codec, pixel format,\ndimensions, duration, frame rate, audio stream count, and progressive-download\nevidence. Finalization re-hashes the retained bytes, rechecks the witness root,\nand parses MP4 top-level boxes itself. The producer's `media-probe.json.passed`\nfield remains supporting evidence, never sufficient authority.\n\nThe default `archive-v1` path preserves the existing v1 media receipt exactly.\nAn explicitly selected web-delivery profile emits a v2 media receipt with a\ncontent-addressed rendition list and explicit roles, MIME types, dimensions,\nand dimension policy. Agents and site builds select `primary-video`,\n`alternate-video`, `responsive-primary-video`,\n`responsive-alternate-video`, `browser-poster`, or evidence-only roles from\nthat receipt; they do not infer semantics from extensions or filenames.\nProfile-declared responsive renditions must match their exact dimensions,\nremain within the source scene, and preserve its aspect ratio. Additional\nproducer-declared renditions remain bounded by the selected profile and cannot\nraise their own byte ceiling. Unbound outputs, implicit upscales, aspect-ratio\ndrift, duplicate singleton roles, unknown profiles, or unsupported required\nversions fail closed.\n\nThe required Gate binds the exact selected media profile and the smoke media\nqualification root before optional full rendering starts. Gate-only validation\nand full rendering therefore exercise the same profile contract; a later media\njob cannot silently switch rendition authority.\n\nInitial byte ceilings are derived from the checked-in\n`auditable-demo-web-delivery-v1` fixture rendered by Build Images\n`v1.3.0-alpha.16` at its exact source SHA and image digest. GIF, MP4, WebM, and\nPNG ceilings are the next power of two above sixteen times the measured member\nbytes. The explicit responsive long-form profile derives its 4 MiB video and\n8 MiB GIF ceilings from the same observed bytes at a bounded 128-times\nmultiplier; it does not change another profile. The not-yet-produced WebP poster\nuses eight times the measured lossless PNG as its conservative proxy. The path-scoped qualification workflow\nregenerates the content-addressed evidence and fails on any byte or fact drift.\nIts matrix retains the original 1280x720 web-delivery baseline on the renderer\nthat produced it and separately measures the responsive profile against a\n1920x1080 fixture and the first exact renderer release that emits both\nsource-resolution and 720p renditions. This keeps historical budget evidence\nreproducible while giving the responsive contract its own immutable\nqualification root.\n\n## Consumer Example\n\nThe build job must expose both the exact artifact name and the digest returned\nby `upload-artifact`:\n\n```yaml\njobs:\n  build:\n    runs-on: ubuntu-24.04\n    outputs:\n      artifact-name: product-linux-${{ github.sha }}\n      artifact-digest: ${{ steps.upload.outputs.artifact-digest }}\n    steps:\n      - uses: actions/checkout@fbc6f3992d24b796d5a048ff273f7fcc4a7b6c09\n      - run: ./scripts/build-product\n      - id: upload\n        uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a\n        with:\n          name: product-linux-${{ github.sha }}\n          path: dist\n          if-no-files-found: error\n          retention-days: 14\n          compression-level: 0\n\n  auditable-demo:\n    needs: build\n    permissions:\n      actions: read\n      contents: read\n    uses: kungfu-systems/buildchain/.github/workflows/.auditable-demo.yml@BUILDCHAIN_EXACT_SHA\n    with:\n      source-ref: ${{ github.sha }}\n      source-artifact-name: ${{ needs.build.outputs.artifact-name }}\n      source-artifact-digest: ${{ needs.build.outputs.artifact-digest }}\n      adapter-path: scripts/auditable-demo-adapter\n      adapter-arguments-json: '[\"--demo-id\",\"agent-work-lab\"]'\n      renderer-image: ghcr.io/kungfu-systems/build-images/demo-renderer@sha256:RENDERER_DIGEST\n      render-media: false\n      media-profile: archive-v1\n```\n\nReplace both placeholders with reviewed immutable SHAs or digests. An eligible\nbuild should always call the reusable workflow. Selection policy changes only\n`render-media`; it must never condition away the Gate job.\n\nUse `web-delivery-v1` only when the rendered bundle is intended to become a\nqualified web-delivery source. Use `site-hero-v1` when an optimized browser\nposter is also required. Select `responsive-long-form-web-delivery-v1` only\nwith an explicit long-form scenario. Profile qualification does not prove browser playback,\nresponsive layout, reduced-motion behavior, accessibility, or production\ndeployment; those remain site responsibilities.\n\n## Failure Evidence\n\nGate and render jobs use bounded timeouts and non-cancelling concurrency.\nDiagnostics artifacts are attempted with `always()` so adapter stdout/stderr\nand the resolved source coordinate remain available when qualification fails.\nNo production deployment, publication authority, token, or provider mutation\nis part of this workflow."
    },
    {
      "id": "manual:aws-us-elastic-runner-burst-plane",
      "title": "AWS US elastic runner burst plane",
      "route": "/docs/aws-us-elastic-runner-burst-plane",
      "category": "manual",
      "capabilityGroup": "getting-started",
      "audience": [
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "docs/aws-us-elastic-runner-burst-plane.md",
      "digest": "sha256:7baa2a7221b5b521a592275227cf497e4a91912bf968cc0e6c12cbfdcd88632f",
      "headings": [
        {
          "level": 1,
          "title": "AWS US elastic runner burst plane",
          "anchor": "aws-us-elastic-runner-burst-plane"
        },
        {
          "level": 2,
          "title": "Phase 1 contract",
          "anchor": "phase-1-contract"
        },
        {
          "level": 2,
          "title": "Cost and kill-switch envelope",
          "anchor": "cost-and-kill-switch-envelope"
        },
        {
          "level": 2,
          "title": "Qualification evidence",
          "anchor": "qualification-evidence"
        },
        {
          "level": 3,
          "title": "Phase 1 recorded outcome",
          "anchor": "phase-1-recorded-outcome"
        },
        {
          "level": 2,
          "title": "Phase 2 contract",
          "anchor": "phase-2-contract"
        },
        {
          "level": 3,
          "title": "Phase 2 operator workflow",
          "anchor": "phase-2-operator-workflow"
        },
        {
          "level": 3,
          "title": "Lower-level campaign and launch controllers",
          "anchor": "lower-level-campaign-and-launch-controllers"
        },
        {
          "level": 2,
          "title": "Phase 3 contract",
          "anchor": "phase-3-contract"
        },
        {
          "level": 3,
          "title": "Phase 3 lifecycle controller",
          "anchor": "phase-3-lifecycle-controller"
        },
        {
          "level": 2,
          "title": "Provider lifecycle",
          "anchor": "provider-lifecycle"
        },
        {
          "level": 2,
          "title": "Source boundaries",
          "anchor": "source-boundaries"
        }
      ],
      "markdown": "---\nstatus: draft\nperiod: 2026-07-28\ntheme: aws-us-elastic-runner-burst-plane\ndoc_type: design\nsource_level: local-files-and-provider-docs\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-08-03\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-08-03\n  invisible_information: No hidden model checkpoint, parameters, or private training data were available.\n---\n\n# AWS US elastic runner burst plane\n\nThe local runner fleet remains the normal Kungfu build plane. This AWS US plane\nis an explicit, temporary overflow mechanism with sequential qualification:\n\n1. Linux CodeBuild proof of concept under USD 50.\n2. Windows EC2 one-job JIT runners.\n3. One bounded 24-hour EC2 Mac campaign.\n\nNo later phase can start from design intent alone. The preceding phase must\nproduce a qualifying source-bound receipt, actual cost, and zero-resource\ncleanup proof.\n\n## Phase 1 contract\n\n`aws-us-codebuild-linux` is a Linux-only runner preset. It requires the exact\nCodeBuild project name and resolves the runner label at workflow evaluation\ntime:\n\n```text\ncodebuild-<project>-<github.run_id>-<github.run_attempt>\n```\n\nThe GitHub-hosted `trust-gate` remains ahead of the matrix job. A fork pull\nrequest therefore fails or skips before the CodeBuild `runs-on` label exists as\na queued job. The dedicated consumer workflow is manual-only and does not add\nthe preset to dev, alpha, release, signing, notarization, deployment, or\npublication workflows.\n\nThe CodeBuild project is:\n\n- repository-scoped through an AWS CodeConnections GitHub App;\n- one ephemeral runner and one GitHub job per CodeBuild build;\n- outside a VPC, with no idle VM, NAT gateway, public ingress, SSH, or persistent\n  workspace;\n- limited to two concurrent builds, 15 queued minutes, and 40 execution\n  minutes;\n- allowed to write only its dedicated CloudWatch log group and request a token\n  from its dedicated GitHub App connection;\n- forbidden from receiving signing, notarization, package publication, release,\n  deploy, static AWS, long-lived GitHub, or SSH credentials.\n\nThe AWS-managed Ubuntu 24.04 standard image is the immutable base. Before a\nnative lifecycle starts, Buildchain installs the distribution's `gcc-14` and\n`g++-14` packages, exposes only per-job `gcc`/`g++` aliases, and downloads the\npinned Kitware CMake 3.31.6 archive after verifying its reviewed SHA256. The\nresolved package manager, versions, and CMake source digest are retained as\n`aws-native-toolchain.json`; no toolchain state survives the ephemeral\nCodeBuild execution. The toolchain adapter also retains the reviewed Amazon\nLinux 2023 `gcc14` path for compatible projects.\n\n## Cost and kill-switch envelope\n\nThe 2026-07-28 AWS Price List entry for\n`BUILD_GENERAL1_XLARGE` Linux in `us-east-1` is USD 0.0798 per build minute.\nThe contract rounds that rate up to USD 0.08. Twelve fully timed-out accepted\nbuilds reserve at most USD 38.40. At project concurrency two, the fail-closed\ncontroller can see at most two over-cap builds. The envelope conservatively\ncharges both race builds for their complete 40-minute timeout rather than\nassuming fast EventBridge delivery. The bounded CodeBuild maximum is therefore\nUSD 44.80, below the dedicated USD 49 budget and leaving USD 4.20 for the small\ncontroller, state, notification, and log charges.\n\nThe controller stores an idempotent build-id ledger, an atomic accepted-build\ncounter, and worst-case reservation in DynamoDB. Duplicate EventBridge delivery\ndoes not consume the bounded build allowance. It deletes the CodeBuild webhook\nand stops the triggering build when:\n\n- the accepted-build or reserved-cost cap is reached;\n- actual-cost telemetry is missing or more than six hours old;\n- actual CodeBuild spend reaches the budget;\n- AWS Budgets sends the 80% or 95% actual-spend notification;\n- the kill switch was already set.\n\nThe stack starts fail closed: it has no cost telemetry item and CloudFormation\ndoes not create the webhook. Before arming the webhook, the operator must write\na current Cost Explorer observation to the `COST` item, clear only the dedicated\ncontroller's killed state, and create the exact workflow-filtered webhook.\nRe-arming after any kill is a separate provider mutation and requires a new\nexplicit approval.\n\n## Qualification evidence\n\nEach successful job uploads `aws-runner-burst.json`, binding:\n\n- consumer repository, exact source SHA and ref;\n- GitHub run id, attempt and job;\n- CodeBuild project, build id, build ARN and initiator;\n- observation timestamp and canonical digest.\n\nLinux qualification requires:\n\n- at least 10 trusted exact-source successful jobs;\n- observed concurrency of at least two;\n- p95 queue-to-start of at most five minutes;\n- actual incremental AWS spend below USD 49;\n- no idle build and no active cloud residue.\n\n`node scripts/aws-runner-burst.mjs verify-linux --input <snapshot.json>` fails\nclosed when cost telemetry is missing/stale or any acceptance predicate is\nfalse.\n\n### Phase 1 recorded outcome\n\nThe Linux phase passed on 2026-07-29. Ten trusted exact-source Kungfu jobs\ncompleted successfully, including four overlapping two-job waves. The observed\nCodeBuild queue-to-start p95 was 0.696 seconds. All 16 paid executions,\nincluding six diagnostic runs, produced a conservative incremental compute\nupper bound of USD 25.798 by rounding every execution up to a whole minute at\nthe live AWS Price List rate.\n\nThe global webhook kill switch was exercised after the tenth qualifying job.\nThe project then reported no webhook or in-progress build, and the card-owned\nEC2 inventory was empty. AWS Billing and Cost Explorer still reported an\nestimated zero during their provider ingestion delay; the retained\nexecution-derived upper bound is therefore the immediate cost proof and must be\nreconciled with the eventual AWS line item in the final campaign report.\n\nThe source-bound evidence and deterministic phase receipt are:\n\n- `evidence/aws-us-elastic-runner-burst-plane/linux-codebuild-qualification-input.json`\n- `evidence/aws-us-elastic-runner-burst-plane/linux-codebuild-qualification-receipt.json`\n\n## Phase 2 contract\n\nThe Windows phase uses the explicit `aws-us-ec2-windows-jit` runner preset.\nIts caller supplies one bounded label under\n`aws-us-ec2-windows-jit-<campaign-id>-<qualification-id>`, and Buildchain\nresolves exactly one Windows x64 native lane. The reusable trust gate still\nruns on a GitHub-hosted runner before the JIT label can select EC2.\n\nThe provider creates repository-level GitHub JIT configuration for\n`kungfu-systems/kungfu`. Its `labels` request must contain all four scheduling\nlabels: `self-hosted`, `Windows`, `X64`, and the card-scoped\n`aws-us-ec2-windows-jit-<campaign-id>-<qualification-id>` label. The workflow\ndisplay title also carries both identities, allowing the launch controller to\nverify the queued run against its campaign plan. GitHub's JIT endpoint does\nnot infer the default OS and architecture labels when they are omitted. The\nencoded configuration is never placed in EC2 user data, a tag, a command log,\nor an artifact. The operator writes it to a card-scoped SSM SecureString under\n`/kungfu/burst/windows/`; the instance role can read and delete only that\nprefix. Bootstrap reads the value once, deletes the parameter immediately, and\npasses it only to the pinned runner process.\n\nEach runner uses:\n\n- Amazon's current Windows Server 2025 Full Base AMI, resolved through the\n  public SSM AMI parameter and retained by exact AMI id and name;\n- `c7i.4xlarge`, one instance and one JIT runner per job;\n- GitHub Actions Runner 2.336.0 with the official Windows x64 SHA256;\n- PowerShell 7.6.4 with the official Windows x64 MSI SHA256 and Microsoft\n  Authenticode verification;\n- pinned PortableGit 2.55.0.3 with its GitHub release SHA256, exposing only its\n  `cmd` directory so POSIX compatibility tools cannot shadow Windows tools;\n- a Microsoft Authenticode-verified Visual Studio 2022 Build Tools bootstrap;\n- IMDSv2, an encrypted root volume with delete-on-termination, no inbound\n  security-group rule, no key pair, and no warm Auto Scaling capacity.\n\nRunner diagnostics and a redacted lifecycle record are uploaded to the\nprovider's encrypted, private evidence bucket under the exact campaign, run,\nattempt, and instance identity. The runner process exits after one job, Windows\nshuts down, and EC2's instance-initiated shutdown behavior is set to\n`terminate`. A five-minute reaper terminates card-owned stopped or\nthree-hour-old instances and deletes only their dedicated JIT parameter.\n\nAt the 2026-07-29 AWS Price List rate of USD 1.45 per Windows\n`c7i.4xlarge` hour, each accepted instance reserves its complete three-hour\nUSD 4.35 fail-closed lifetime before `RunInstances`. A DynamoDB transaction\nbinds the exact campaign and source, creates an idempotent run ledger entry,\nand atomically refuses a sixth accepted instance. Five accepted instances\ntherefore reserve at most USD 21.75. The campaign also persists the\noperator-observed spend from earlier Windows work, and refuses to arm unless\nthat baseline, all five reservations, and one USD 4.35 fail-closed race\nallowance remain below the USD 110 phase cap.\n\nThe campaign starts unarmed and expires within 24 hours. Its `CONTROL` record\ncan be created only once: a killed or expired campaign cannot be re-armed by\nthe campaign tool. A budget notification or any instance lifetime violation\npersists `KILLED` before cleanup, so later workflow dispatches fail before a\npaid launch. Reservations are never refunded: a controller crash, ambiguous\nlaunch, or successful launch all remain charged to the campaign, favoring a\nfalse stop over an accidental budget overrun.\n\nThe 2026-08-03 timeout-only campaign decision narrows the campaign to two\naccepted instances with one active instance at a time. The second reservation\nis an operator-gated repair retry: it may be used only after the first attempt\nis classified as non-counting and runner, EC2, EBS, SSM, and workflow residue\nhave returned to zero. The two-slot ledger is a maximum spend boundary, not an\nauthorization to consume both reservations.\n\nEach stack owns a stack-scoped reaper log group, so an independent retained\none-shot campaign stack can be created without colliding with another\ncampaign's audit log resource.\n\nThe account-native AWS Budget is defense in depth, not the authoritative launch\ngate. It is owned by the singleton\n`kungfu-buildchain-windows-jit-budget-guard` stack rather than any retained\ncampaign stack. This prevents Budget-name collisions and prevents a stale\ncampaign reaper from becoming the provider-wide cost authority. The Budget\nfilters exactly `USAGE_TYPE=BoxUsage:c7i.4xlarge`,\n`OPERATION=RunInstances:0002` (Windows), and `REGION=us-east-1`; its 80% and\n95% actual notifications persist the provider kill sentinel, terminate every\ntagged Windows JIT instance, and delete scoped JIT parameters. Every launch\ncontroller refuses to proceed when the sentinel exists or when the Budget\nidentity or dimension filter does not match.\n\nBudget installation is intentionally deployable by the workload account without\nAWS Organizations management-account access. It fails closed unless Cost\nExplorer exposes all three AWS-owned billing dimensions in the requested phase\nwindow. The `kungfu:provider=windows-ec2-jit` resource tag remains mandatory for\nownership, cleanup, and IAM scoping, but it is not a billing filter. Do not\ncreate an unfiltered fallback Budget or treat an incomplete dimension readback\nas evidence.\nThe DynamoDB campaign reservation remains the atomic launch authority because\nCost Explorer and AWS Budgets can lag provider activity.\n\nQualification requires one runner-profile smoke and three trusted exact-source\nfull Windows jobs all bound to the same campaign, independent cancellation and\ntimeout cleanup exercises, and zero repository runner, EC2 instance,\ndisposable volume, min capacity, and desired capacity within 15 minutes of the\nfinal job.\n\n### Phase 2 operator workflow\n\n`pnpm operator:windows-jit` is the reusable lifecycle entrypoint. Its default\nmode is `plan`, which performs no AWS or GitHub call. A plan binds the account,\nregion, unique campaign and stack names, source SHA/ref, Cost Explorer window,\nworkflow id, network, OIDC provider, expiry, slot ceiling, singleton Budget\nidentity, and exact confirmation digest.\n\nThe modes are deliberately separated:\n\n- `plan` emits the deterministic mutation boundary and digest.\n- `audit` reads AWS and GitHub only. It verifies the account, disabled workflow,\n  singleton guard stack, exact Budget filter, SNS thresholds/subscribers,\n  provider kill sentinel, campaign stack, and zero EC2/EBS/SSM/JIT/runner\n  residue.\n- `install-budget --execute` deploys or updates only the singleton Budget guard.\n  It refuses to mutate unless all exact Windows billing dimensions are visible,\n  the Windows workflow is disabled, and the account, campaign, source, Budget,\n  and plan digest confirmations match.\n- `prepare --execute` requires the installed Budget guard, absent kill\n  sentinel, fresh Cost Explorer readback filtered by `BoxUsage:c7i.4xlarge`,\n  `RunInstances:0002`, and `us-east-1`, zero residue, a\n  never-used campaign stack name, and the disabled workflow. The receipt binds\n  the query timestamp and exact filter identity. Preparation deploys the\n  campaign stack and atomically arms the ledger with that provider-spend\n  baseline. It never enables or dispatches the workflow and never creates EC2\n  capacity.\n- `close --execute` disables the workflow first, persists `KILLED`, publishes\n  the campaign kill switch, and reports terminal success only after EC2, EBS,\n  SSM, JIT parameter, and GitHub runner residue is zero. It is safe to rerun\n  while the reaper settles.\n\nAll mutating modes require `--execute`, `--confirm-plan-digest`,\n`--confirm-account-id`, `--confirm-campaign-id`, and\n`--confirm-source-sha`. Budget installation and preparation additionally\nrequire `--confirm-budget-name`. A future paid workload still requires a\nseparate exact workflow/run authorization and uses\n`scripts/aws-windows-jit-controller.mjs`; preparation is not paid-launch\nauthority.\n\nStart by recording one reproducible plan:\n\n```bash\npnpm operator:windows-jit plan \\\n  --aws-profile us \\\n  --account-id 727884401362 \\\n  --campaign-id win-REPLACE \\\n  --source-sha REPLACE_WITH_EXACT_40_CHARACTER_SHA \\\n  --source-ref refs/heads/dev/v4/v4.0 \\\n  --observed-at REPLACE_WITH_ISO_TIMESTAMP \\\n  --expires-at REPLACE_WITH_ISO_TIMESTAMP_WITHIN_24_HOURS \\\n  --cost-start REPLACE_WITH_PHASE_START_DATE \\\n  --cost-end REPLACE_WITH_EXCLUSIVE_END_DATE \\\n  --max-accepted-instances 1 \\\n  --workflow-id 322620360 \\\n  --vpc-id REPLACE_WITH_VPC_ID \\\n  --subnet-id REPLACE_WITH_SUBNET_ID \\\n  --oidc-provider-arn REPLACE_WITH_GITHUB_OIDC_PROVIDER_ARN\n```\n\nReuse those exact arguments for `audit`, `install-budget`, `prepare`, or\n`close`; never regenerate `--observed-at` between the plan and its confirmed\nmutation. Capture stdout as the operator receipt. Do not put credentials,\ntokens, JIT configuration, or signed URLs in arguments or receipts.\n\n### Lower-level campaign and launch controllers\n\n`scripts/aws-windows-jit-campaign-core.mjs` owns the pure one-shot ledger\ncontract used by the operator and launch controller. Arming creates `CONTROL`\nand `CAMPAIGN#<id>` with `attribute_not_exists` conditions, so DynamoDB refuses\na second campaign in the same retained state table. There is deliberately no\nclear or re-arm operation.\n\nEvery `scripts/aws-windows-jit-controller.mjs --execute` call must provide the\nsame `--account-id`, `--campaign-id`, `--confirm-campaign-id`, `--state-table`,\nand `--confirm-state-table`. Before GitHub JIT material is created, the\ncontroller verifies the exact provider Budget/dimension filter and proves the\nglobal Budget kill sentinel absent. After the GitHub, AMI, active-instance,\nSSM, and EC2 DryRun checks pass, the controller\natomically reserves one run. Duplicate run-attempt-qualification identities,\nsource mismatch, expiry, `KILLED`, the sixth accepted instance, or a\nreservation that would exceed the USD 110 ceiling after combining the persisted\nfresh Cost Explorer baseline with all in-flight campaign reservations all fail\nclosed in one DynamoDB transaction before `RunInstances`. AWS Budget alarms are\ndefense in depth for delayed billing telemetry; the atomic ledger is the\nauthoritative launch-time guard. The operator is the only supported mutation\nsurface for campaign preparation and closeout; direct imports of the core are\nnot operator authority.\n\n## Phase 3 contract\n\nThe macOS phase uses the explicit `aws-us-ec2-macos-jit` runner preset. Its\ncaller supplies one unique label under\n`aws-us-ec2-macos-jit-<qualification-id>`, and Buildchain resolves exactly one\nnative macOS ARM64 lane with `self-hosted`, `macOS`, `ARM64`, and the unique\ncampaign label. The reusable trust gate remains ahead of the JIT runner.\n\nUnlike Windows, the Mac campaign deliberately reuses one instance on one\n`mac2.metal` Dedicated Host. The operator allocates exactly one tagged host,\nlaunches exactly one tagged instance, and sends three sequential SSM bootstrap\ncommands. Each command consumes and immediately deletes a distinct repository\nJIT SecureString under `/kungfu/burst/macos/`, then runs GitHub Actions Runner\n2.336.0 for exactly one job. The runner archive is pinned to the official\nmacOS ARM64 SHA256. No GitHub, signing, notarization, publication, SSH, or\nstatic AWS credential is admitted to the instance.\n\nThe instance uses the exact retained Amazon EC2 macOS AMI, IMDSv2, an encrypted\ndelete-on-termination root volume, no inbound security-group rule, and the\nAMI's preinstalled SSM Agent and AWS CLI v2. The three accepted jobs must bind\nto the same host id, instance id, AMI id, source SHA, and campaign. At least one\njob must exercise the full native lifecycle.\n\nAWS imposes a 24-hour minimum Dedicated Host allocation. The contract therefore\nkeeps the one host for at least 24 hours even if all three jobs finish earlier.\nAt the recorded USD 0.6498 hourly rate, the minimum commitment rounds to USD\n15.60. A 30-hour fail-closed ceiling rounds to USD 19.49, below the dedicated\nUSD 25 budget. A ten-minute reaper terminates an expired campaign instance and\nretries host release after the minimum allocation and Apple scrub constraints\nallow it. Budget notifications at 80% and 95% invoke the same card-scoped kill\nswitch.\n\nQualification requires three trusted exact-source one-job JIT runs on the one\nhost, including at least one full run, plus proof that:\n\n- the instance terminated and the encrypted disposable volume disappeared;\n- Apple host scrub completed;\n- the Dedicated Host was released between 24 and 30 hours after allocation;\n- the repository has no registered campaign runner;\n- AWS has no active campaign instance or allocated campaign host;\n- actual incremental spend remained below USD 25.\n\n### Phase 3 lifecycle controller\n\n`scripts/aws-macos-jit-controller.mjs` is the operator boundary for the paid\ncampaign. It has three explicit mutation modes:\n\n- `launch-campaign` binds the exact repository source, AMI, availability zone,\n  tagged Dedicated Host, and reusable instance. It rejects pre-existing Mac\n  capacity and requires successful `AllocateHosts` and `RunInstances` DryRuns\n  before either real call.\n- `run-job` binds one queued exact-source GitHub job to the existing campaign\n  host and instance. It writes the repository JIT configuration through a\n  mode-0600 temporary file into a distinct SSM SecureString, sends only the\n  credential-free bootstrap through SSM, and removes the parameter plus runner\n  registration if command delivery fails.\n- `close-campaign` refuses execution before the provider's 24-hour minimum,\n  verifies the encrypted delete-on-termination root volume, removes scoped JIT\n  residue, terminates the exact instance, and requires a `ReleaseHosts` DryRun\n  before release. If Apple host scrubbing is still in progress, it reports\n  `release-pending`; the ten-minute card-scoped reaper remains the bounded\n  retry path.\n\nEvery execute mode requires the exact source SHA and campaign id to be repeated\nthrough `--confirm-source-sha` and `--confirm-campaign-id`. `run-job` also\nrequires `--confirm-run-id`. Omitting `--execute` emits a deterministic plan\nwithout changing AWS or GitHub state.\n\n## Provider lifecycle\n\nThe three infrastructure templates live under\n`infra/aws-us-elastic-runner-burst-plane/`. Creating a change set is the review\nboundary. Executing it, completing the GitHub App connection, creating or\nre-arming a webhook, allocating or releasing a Dedicated Host, writing cost\ntelemetry, dispatching paid jobs, operating a kill switch, and deleting a stack\nare all explicit provider mutations.\n\nThe reviewed Phase 1 provider sequence is below. It deliberately separates\nconnection creation, change-set inspection, stack execution, cost observation,\nand webhook arming:\n\n```bash\nburst_profile=us\nburst_region=us-east-1\nburst_stack=kungfu-buildchain-linux-burst-poc\nburst_project=kungfu-buildchain-linux-burst-poc\nburst_connection_name=kungfu-linux-burst-poc\nburst_change_set=phase1-linux-codebuild-poc\n\naws --profile \"$burst_profile\" --region \"$burst_region\" \\\n  codeconnections create-connection \\\n  --provider-type GitHub \\\n  --connection-name \"$burst_connection_name\" \\\n  --tags Key=kungfu:owner,Value=buildchain \\\n    Key=kungfu:plane,Value=aws-us-elastic-runner-burst\n```\n\nThe returned connection is `PENDING` until an operator completes the GitHub App\nhandshake in AWS. Read back `ConnectionStatus=AVAILABLE` before creating the\nchange set. Do not put an OAuth token or GitHub token in the shell:\n\nAWS CodeConnections connection names are limited to 32 characters, so keep the\nshorter connection name even when the stack and project use the longer\nBuildchain-specific name.\n\n```bash\nburst_connection_arn=REPLACE_WITH_AVAILABLE_CONNECTION_ARN\n\naws --profile \"$burst_profile\" --region \"$burst_region\" \\\n  codeconnections get-connection \\\n  --connection-arn \"$burst_connection_arn\"\n\naws --profile \"$burst_profile\" --region \"$burst_region\" \\\n  cloudformation create-change-set \\\n  --stack-name \"$burst_stack\" \\\n  --change-set-name \"$burst_change_set\" \\\n  --change-set-type CREATE \\\n  --template-body \\\n    file://infra/aws-us-elastic-runner-burst-plane/codebuild-poc.template.yml \\\n  --capabilities CAPABILITY_IAM \\\n  --parameters \\\n    ParameterKey=GitHubConnectionArn,ParameterValue=\"$burst_connection_arn\" \\\n    ParameterKey=ProjectName,ParameterValue=\"$burst_project\"\n\naws --profile \"$burst_profile\" --region \"$burst_region\" \\\n  cloudformation wait change-set-create-complete \\\n  --stack-name \"$burst_stack\" \\\n  --change-set-name \"$burst_change_set\"\n\naws --profile \"$burst_profile\" --region \"$burst_region\" \\\n  cloudformation describe-change-set \\\n  --stack-name \"$burst_stack\" \\\n  --change-set-name \"$burst_change_set\"\n```\n\nOnly after the change-set resource list and IAM diff are accepted:\n\n```bash\naws --profile \"$burst_profile\" --region \"$burst_region\" \\\n  cloudformation execute-change-set \\\n  --stack-name \"$burst_stack\" \\\n  --change-set-name \"$burst_change_set\"\n\naws --profile \"$burst_profile\" --region \"$burst_region\" \\\n  cloudformation wait stack-create-complete \\\n  --stack-name \"$burst_stack\"\n```\n\nArming requires a fresh, operator-observed CodeBuild cost value. `COST` is the\nonly mutable telemetry item and `CONTROL` is the only state cleared:\n\n```bash\nburst_table=$(\n  aws --profile \"$burst_profile\" --region \"$burst_region\" \\\n    cloudformation describe-stacks \\\n    --stack-name \"$burst_stack\" \\\n    --query \"Stacks[0].Outputs[?OutputKey=='StateTable'].OutputValue\" \\\n    --output text\n)\nburst_observed_at=$(date -u +%s)\nburst_actual_usd=REPLACE_WITH_CURRENT_CODEBUILD_ACTUAL_USD\n\naws --profile \"$burst_profile\" --region \"$burst_region\" \\\n  dynamodb put-item \\\n  --table-name \"$burst_table\" \\\n  --item \"{\\\"pk\\\":{\\\"S\\\":\\\"COST\\\"},\\\"actual_usd\\\":{\\\"N\\\":\\\"$burst_actual_usd\\\"},\\\"observed_at\\\":{\\\"N\\\":\\\"$burst_observed_at\\\"}}\"\n\naws --profile \"$burst_profile\" --region \"$burst_region\" \\\n  dynamodb delete-item \\\n  --table-name \"$burst_table\" \\\n  --key '{\"pk\":{\"S\":\"CONTROL\"}}'\n\naws --profile \"$burst_profile\" --region \"$burst_region\" \\\n  codebuild create-webhook \\\n  --project-name \"$burst_project\" \\\n  --filter-groups \\\n    '[[{\"type\":\"EVENT\",\"pattern\":\"WORKFLOW_JOB_QUEUED\"},{\"type\":\"WORKFLOW_NAME\",\"pattern\":\"^AWS US Linux Burst Qualification$\"}]]'\n```\n\nThe immediate global kill is idempotent and targets only the dedicated project:\n\n```bash\naws --profile \"$burst_profile\" --region \"$burst_region\" \\\n  codebuild delete-webhook \\\n  --project-name \"$burst_project\"\n```\n\nAfter preserving the qualification evidence and proving no build is in\nprogress, rollback removes only the card-owned stack and connection:\n\n```bash\naws --profile \"$burst_profile\" --region \"$burst_region\" \\\n  cloudformation delete-stack \\\n  --stack-name \"$burst_stack\"\n\naws --profile \"$burst_profile\" --region \"$burst_region\" \\\n  cloudformation wait stack-delete-complete \\\n  --stack-name \"$burst_stack\"\n\naws --profile \"$burst_profile\" --region \"$burst_region\" \\\n  codeconnections delete-connection \\\n  --connection-arn \"$burst_connection_arn\"\n```\n\nPhase cleanup evidence must include:\n\n- CodeBuild batch/list results showing no in-progress build;\n- controller state and accepted-build ledger;\n- CodeBuild actual cost observation and its timestamp;\n- no EC2 instance, volume, launch template, Auto Scaling group, or dedicated\n  host created by this phase;\n- the CodeBuild webhook deleted or the whole stack deleted.\n\n## Source boundaries\n\nThe design follows the current AWS CodeBuild GitHub Actions runner contract:\n`WORKFLOW_JOB_QUEUED` starts an ephemeral runner, the run id maps cancellation,\nand the build terminates after one job. It uses the current GitHub guidance to\nprefer ephemeral autoscaled self-hosted runners and to retain runner logs\nexternally. Provider documentation and the live AWS Price List query are the\nauthoritative external sources; this document is an auditable cache."
    },
    {
      "id": "manual:binary-distribution",
      "title": "Binary Distribution",
      "route": "/docs/binary-distribution",
      "category": "manual",
      "capabilityGroup": "release-passport-trust",
      "audience": [
        "release-operator",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "docs/binary-distribution.md",
      "digest": "sha256:b1611dcf0e6825e53921e4c9d31d1afe16fca81e6868360bfad1902587cd52ef",
      "headings": [
        {
          "level": 1,
          "title": "Binary Distribution",
          "anchor": "binary-distribution"
        },
        {
          "level": 2,
          "title": "Asset Rules",
          "anchor": "asset-rules"
        },
        {
          "level": 2,
          "title": "KFD-3 Distribution Declaration",
          "anchor": "kfd-3-distribution-declaration"
        },
        {
          "level": 2,
          "title": "Runner Policy",
          "anchor": "runner-policy"
        },
        {
          "level": 2,
          "title": "Evidence Bundle",
          "anchor": "evidence-bundle"
        },
        {
          "level": 2,
          "title": "Local Smoke",
          "anchor": "local-smoke"
        }
      ],
      "markdown": "# Binary Distribution\n\nBuildchain's binary distribution is the first high-pressure proof case for the\nRelease Passport protocol. It is not the boundary of the product.\n\n## Asset Rules\n\nGitHub Release assets use platform-specific archives:\n\n- `buildchain-x86_64-unknown-linux-gnu.tar.gz`\n- `buildchain-aarch64-apple-darwin.tar.gz`\n- `buildchain-x86_64-pc-windows-msvc.zip`\n\nThe release lane does not upload loose top-level `buildchain` or\n`buildchain.exe` assets. Linux and macOS both name the executable `buildchain`\ninside their archives, so top-level loose assets would collide when matrix\nartifacts are merged.\n\n`Binary Distribution` is evidence-only. It never receives `contents: write`\nand never calls `gh release upload`; `upload-release=true` is rejected before\nthe matrix starts. A completed promotion explicitly dispatches the workflow at\nthe exact public tag because tags created by `GITHUB_TOKEN` do not recursively\nstart ordinary `push` workflows.\n\nAfter all three runners qualify, the workflow seals a\n`binary-distribution` controller receipt over the exact source/runtime SHA,\nrelease bundle, and Release Passport. `Binary Release Assets` observes the\nsuccessful evidence run, rechecks that its source SHA still equals the exact\ntag, derives the governed alpha/release branch, and asks the credential-free\npublication authority to assemble a short-lived capability. Only the nested\npublisher owns `contents: write`, and it runs behind the protected\n`buildchain-release-assets` Environment.\n\nGitHub Release metadata remains deterministic and tag-derived. Exact alpha tags such\nas `v2.6.2-alpha.0` are created or updated with `prerelease=true` and\n`make_latest=false`; exact stable tags such as `v2.6.1` are created or updated\nwith `prerelease=false` and `make_latest=true`. The sealed publisher uses\n`scripts/ensure-github-release.mjs` before asset upload instead of relying on\nGitHub's default latest-release heuristic.\n\nEach archive is accompanied by:\n\n- a platform manifest from the standalone binary builder;\n- platform observability event logs and summaries;\n- `checksums.txt`;\n- Release Passport evidence files;\n- `buildchain-release-bundle.tar.gz`;\n- `buildchain-release-bundle.json`.\n\nLinux archives may also be accompanied by a GitHub/Sigstore bundle and\n`buildchain.github-artifact-attestation-evidence/v1`. These prove the exact\nGitHub signer workflow and source digest while preserving the original compiler\nrunner in the platform manifest. The GitHub-hosted signer does not rebuild or\nexecute consumer source. See\n[`github-artifact-attestation.md`](github-artifact-attestation.md).\n\n## KFD-3 Distribution Declaration\n\nBuildchain self-describes this release lane in `dist/site/kfd-claims.json` as\nthe KFD-3 surface `distribution:buildchain-standalone`. Its declaration assigns\nregistration to Shifu, names `binary:build` as the reproducible task, and lists\nthe artifact kind, platform, and path glob for all three archives. Shifu should\ndiscover the registry through `buildchain layout --json`, not by copying the\nregistry path.\n\nThe repository-owned task is:\n\n```bash\npnpm binary:build\n```\n\nThe release workflow still builds each target on its declared runner. The local\ntask is the stable task identity used by the KFD declaration and local smoke\nchecks; it does not replace the three-platform release matrix.\n\n## Runner Policy\n\nProduction binary builds use GitHub-hosted runners:\n\n- `ubuntu-24.04`\n- `macos-latest`\n- `windows-2022`\n\nSelf-hosted runners are compatibility fixtures. They can prove that consumers\nwith private runner fleets can still use the protocol, but Buildchain's public\nbinary distribution should stay reproducible on GitHub-hosted runners.\n\n## Evidence Bundle\n\n`buildchain-release-bundle.tar.gz` groups release assets and passport evidence\nunder one archive:\n\n```text\nbuildchain-release-bundle/\n  release-assets/\n  release-passport/\n  buildchain-release-bundle.index.json\n```\n\n`buildchain-release-bundle.json` records the bundle digest and every included\nfile digest. Consumers can download the bundle when they want one artifact for\noffline review, mirroring, or site ingestion.\n\nPublication fails closed unless the bundle contains all three archives,\n`checksums.txt`, and `buildchain.release.json`; its archive digest, controller\nreceipt, live control-plane audit, runner provenance, source/runtime SHA, and\nexact target tag must all match the sealed admission.\n\n## Local Smoke\n\n```bash\npnpm binary:build -- --version v0.0.0-local\nnode bin/buildchain.mjs collect github-release \\\n  --tag v0.0.0-local \\\n  --assets-dir dist/binary \\\n  --output-dir .buildchain/release-passport\nnode scripts/create-release-bundle.mjs \\\n  --assets-dir dist/binary \\\n  --passport-dir .buildchain/release-passport \\\n  --output-dir .buildchain/release-passport \\\n  --tag v0.0.0-local\n```"
    },
    {
      "id": "manual:build-facts",
      "title": "Build Facts",
      "route": "/docs/build-facts",
      "category": "manual",
      "capabilityGroup": "observability-diagnostics",
      "audience": [
        "maintainer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "docs/build-facts.md",
      "digest": "sha256:75dcf7a6628dac9e982a455de9966044ae771611d4efc04e7264a2d4adb0bd3e",
      "headings": [
        {
          "level": 1,
          "title": "Build Facts",
          "anchor": "build-facts"
        },
        {
          "level": 2,
          "title": "Config",
          "anchor": "config"
        },
        {
          "level": 2,
          "title": "CLI",
          "anchor": "cli"
        },
        {
          "level": 2,
          "title": "Node API",
          "anchor": "node-api"
        },
        {
          "level": 2,
          "title": "Release Passport Integration",
          "anchor": "release-passport-integration"
        },
        {
          "level": 2,
          "title": "Kungfu Legacy Projection",
          "anchor": "kungfu-legacy-projection"
        }
      ],
      "markdown": "# Build Facts\n\nBuild Facts are Buildchain's machine-readable record of what a repository\nbuilt. They sit between lifecycle logs and release passports:\n\n- lifecycle logs explain what ran and how long it took;\n- module build facts bind one module to its Git source digest, version source,\n  platform, lifecycle invocation, and output digests;\n- product build facts aggregate module facts and product artifacts;\n- release passports can carry build facts as first-class evidence.\n\nThe goal is to remove handwritten build metadata from consumer repositories.\nConsumers declare where their version and outputs live; Buildchain collects and\nverifies the facts.\n\n## Config\n\nDeclare build facts in `buildchain.toml`:\n\n```toml\nschema = 1\n\n[[facts.version_sources]]\nid = \"package\"\ntype = \"json\"\npath = \"package.json\"\nkey = \"version\"\n\n[[facts.modules]]\nid = \"native-core\"\nroot = \"src/core\"\nscope = \"core\"\nversion_source = \"package\"\nlifecycle = \"build\"\noutputs = [\"dist/core.node\"]\n\n[[facts.products]]\nid = \"kungfu\"\nmodule_facts = [\".buildchain/facts/native-core.json\"]\nartifacts = [\"dist/kungfu.zip\"]\n\n[[facts.legacy_projections]]\ntype = \"kungfu-buildinfo\"\nmodule = \"native-core\"\npath = \"framework/core/src/kungfu/yijinjing/kungfubuildinfo.json\"\n```\n\nSupported version sources:\n\n- `static`: an explicit `value`;\n- `json`: a JSON file plus dotted `key`;\n- `toml`: a TOML file plus dotted `key`;\n- `regex`: a text file plus regex `pattern`, using a named `version` group or\n  the first capture group;\n- `command`: an explicit command whose output is the version.\n\nPrefer file-based sources. Command sources are allowed for legacy projects but\nare marked as less reproducible because the command output is not a static\nsource file.\n\n## CLI\n\nCollect a module fact:\n\n```bash\nbuildchain facts module \\\n  --module native-core \\\n  --output .buildchain/facts/native-core.json\n```\n\nOverride declarative config from a workflow step when needed:\n\n```bash\nbuildchain facts module \\\n  --cwd \"$GITHUB_WORKSPACE\" \\\n  --module native-core \\\n  --module-root src/core \\\n  --version-source package \\\n  --output-path dist/core.node \\\n  --output .buildchain/facts/native-core.json \\\n  --json\n```\n\nWrite the Kungfu legacy `kungfubuildinfo.json` projection from the same module\nfact:\n\n```bash\nbuildchain facts module \\\n  --module native-core \\\n  --output .buildchain/facts/native-core.json \\\n  --legacy-kungfu-buildinfo framework/core/src/kungfu/yijinjing/kungfubuildinfo.json\n```\n\nAggregate product facts:\n\n```bash\nbuildchain facts aggregate \\\n  --product kungfu \\\n  --module-fact .buildchain/facts/native-core.json \\\n  --artifact dist/kungfu.zip \\\n  --output .buildchain/facts/kungfu.json\n```\n\nVerify a fact before publishing:\n\n```bash\nbuildchain facts verify --fact .buildchain/facts/kungfu.json\n```\n\nVerification fails closed when a declared output is missing, an output digest is\nstale, a module fact was collected from a different Git `HEAD`, or a source\ndigest no longer matches the tracked source files.\n\n## Node API\n\n```js\nimport {\n  aggregateBuildFacts,\n  collectModuleBuildFacts,\n  verifyBuildFacts,\n  writeBuildFacts,\n  writeKungfuBuildInfoProjection,\n} from \"@kungfu-tech/buildchain/build-facts\";\n\nconst moduleFact = collectModuleBuildFacts({ moduleId: \"native-core\" });\nwriteBuildFacts({ fact: moduleFact, output: \".buildchain/facts/native-core.json\" });\n\nconst productFact = aggregateBuildFacts({ productId: \"kungfu\" });\nconst verification = verifyBuildFacts({ fact: productFact });\n```\n\nThe root package export also re-exports these APIs from\n`@kungfu-tech/buildchain`.\n\n## Release Passport Integration\n\nPass build facts into a release passport:\n\n```bash\nbuildchain collect github-release \\\n  --tag \"$TAG\" \\\n  --assets-dir dist \\\n  --build-facts-json .buildchain/facts/native-core.json \\\n  --build-facts-json .buildchain/facts/kungfu.json \\\n  --output-dir .buildchain/release-passport\n```\n\nThe passport records the full build facts in `buildFacts[]` and a compact\nevidence index in `evidence.buildFacts[]`. Agents can start from\n`buildchain.release.json`, discover the module/product facts, and verify that\nthe released artifacts still match the declared source, version, and output\nfacts.\n\n## Kungfu Legacy Projection\n\nKungfu historically consumes `kungfubuildinfo.json`. Buildchain now treats that\nfile as a projection of module build facts, not as an independent source of\ntruth. The projection preserves legacy fields such as `version`,\n`python_version`, `git_branch`, `git_revision`, and `git_pristine`, while adding\na `buildchain` section that points back to the module fact digest, version\nsource digest, and source digest.\n\nRepositories that no longer need the legacy file should consume the module and\nproduct facts directly."
    },
    {
      "id": "manual:cli",
      "title": "Buildchain CLI, npm Package, and Toolkit API",
      "route": "/docs/cli",
      "category": "manual",
      "capabilityGroup": "api-cli-reference",
      "audience": [
        "agent",
        "developer"
      ],
      "maturity": "stable",
      "sourcePath": "docs/cli.md",
      "digest": "sha256:fad47682ed909f7b16f58bb8c24c51a943eb704a0a50ab6e033d745ee16a809a",
      "headings": [
        {
          "level": 1,
          "title": "Buildchain CLI, npm Package, and Toolkit API",
          "anchor": "buildchain-cli-npm-package-and-toolkit-api"
        },
        {
          "level": 2,
          "title": "Install and Run",
          "anchor": "install-and-run"
        },
        {
          "level": 2,
          "title": "Node API and Package Exports",
          "anchor": "node-api-and-package-exports"
        },
        {
          "level": 2,
          "title": "Commands",
          "anchor": "commands"
        },
        {
          "level": 3,
          "title": "Governed paper lifecycle",
          "anchor": "governed-paper-lifecycle"
        },
        {
          "level": 2,
          "title": "npm Publish Gate",
          "anchor": "npm-publish-gate"
        }
      ],
      "markdown": "---\nstatus: active\nperiod: ongoing\ntheme: buildchain-cli\ndoc_type: technical-reference\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-07-31\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-31\n  invisible_context: not asserted\n---\n\n# Buildchain CLI, npm Package, and Toolkit API\n\nBuildchain is published as the public npm package\n`@kungfu-tech/buildchain`. The package contains the `buildchain` command,\nthe importable ESM toolkit APIs, and the local scripts needed to initialize and\nvalidate repositories before they use the reusable GitHub workflow surface.\n\nThe npm package is not the release authority. Release authority still comes\nfrom the protected Buildchain branch and tag state machine. npm publishing is a\nside effect of an exact release tag that has already been produced by that\nstate machine.\n\n## Install and Run\n\nUse the published package directly:\n\n```bash\nnpx @kungfu-tech/buildchain --help\nnpx @kungfu-tech/buildchain init --type package\nnpx @kungfu-tech/buildchain validate --require-version-state\n```\n\nOr install it in a repository:\n\n```bash\npnpm add -D @kungfu-tech/buildchain\npnpm exec buildchain validate\n```\n\nConsumers should pin the exact Buildchain version that was validated in their\nrepository. When dogfooding a fresh Buildchain release immediately after it is\npublished, pnpm may block the install through a minimum release-age policy. In\nthat case, add a temporary package/version-specific `minimumReleaseAgeExclude`\nentry, such as `@kungfu-tech/buildchain@4.0.0`, and remove it once the package\nhas aged past the normal policy window. Do not replace that with a broad\nregistry or scope-wide exclude. Paper scaffold and migration maintain the\nexact current entry in `pnpm-workspace.yaml` before refreshing the lockfile.\n\nUse the package API directly inside JavaScript build scripts:\n\n```js\nimport { createBuildchainLogger } from \"@kungfu-tech/buildchain/logging\";\n\nconst logger = createBuildchainLogger({ source: \"user\", component: \"build\" });\nawait logger.span(\"build.native\", { phase: \"build\" }, async () => {\n  await buildNativeArtifacts();\n});\n```\n\nThe standalone binary and CLI are for workflow steps, shell scripts, and\nnon-JavaScript environments. JavaScript code that already depends on\n`@kungfu-tech/buildchain` should import the toolkit API instead of spawning\n`npx buildchain` or a downloaded binary.\n\n## Node API and Package Exports\n\nBuildchain's public Node API is the package `exports` surface, not arbitrary\ninternal file paths. The npm package also ships\n`dist/site/node-api-registry.json` and exports it as\n`@kungfu-tech/buildchain/site/node-api-registry.json` so agents can enumerate\nthe supported imports from the installed package.\nFor navigation, start with `dist/site/capability-registry.json`: it groups\nmanuals, CLI commands, workflow/action inputs, Node exports, site pages, and KFD\nclaim facts by product capability before an agent chooses a concrete command or\nmanual.\n\nCurrent public import families include:\n\n```js\nimport * as buildchain from \"@kungfu-tech/buildchain\";\nimport { createBuildchainLogger } from \"@kungfu-tech/buildchain/logging\";\nimport { collectModuleBuildFacts } from \"@kungfu-tech/buildchain/build-facts\";\nimport { checkHomebrewTap } from \"@kungfu-tech/buildchain/homebrew\";\nimport { verifyKfd1ReleaseGate } from \"@kungfu-tech/buildchain/kfd-gate\";\nimport { collectBadgeBundleFacts } from \"@kungfu-tech/buildchain/badges\";\nimport { collectReadmeBadgeFacts } from \"@kungfu-tech/buildchain/readme-badges\";\nimport { verifyReleasePassport } from \"@kungfu-tech/buildchain/release-passport\";\nimport { verifyGitHubArtifactAttestationEvidence } from \"@kungfu-tech/buildchain/github-artifact-attestation\";\nimport { createReleasePropagationPlan } from \"@kungfu-tech/buildchain/release-propagation\";\nimport { verifyPublicationReproducibility } from \"@kungfu-tech/buildchain/publication-reproducibility\";\nimport { collectPaperStatus } from \"@kungfu-tech/buildchain/paper\";\nimport { planReleaseLineBootstrap } from \"@kungfu-tech/buildchain/release-line-bootstrap\";\nimport { collectPublicSurfaceReverseAudit } from \"@kungfu-tech/buildchain/public-surface-audit\";\nimport { createBuildchainLayoutDiscovery } from \"@kungfu-tech/buildchain/buildchain-layout\";\nimport { createPortableDevCachePlan } from \"@kungfu-tech/buildchain/portable-dev-cache\";\nimport contractWorld from \"@kungfu-tech/buildchain/site/buildchain-contract.json\" with { type: \"json\" };\nimport capabilityRegistry from \"@kungfu-tech/buildchain/site/capability-registry.json\" with { type: \"json\" };\nimport manualRegistry from \"@kungfu-tech/buildchain/site/manual-registry.json\" with { type: \"json\" };\nimport nodeApiRegistry from \"@kungfu-tech/buildchain/site/node-api-registry.json\" with { type: \"json\" };\nimport publicSurfaceAudit from \"@kungfu-tech/buildchain/site/public-surface-audit.json\" with { type: \"json\" };\n```\n\nUse `dist/site/manual-registry.json` to find the packaged operating manuals and\ntheir SHA-256 digests. Use `dist/site/buildchain-contract.json` to verify the\nfloating-ref contract world for a runtime such as `@v4`.\n\nFor exhaustive lookup, use the generated references rather than scanning this\nconceptual guide:\n\n- [`cli-reference.md`](cli-reference.md) is projected from the governed usage\n  model and runtime command registry. `buildchain <path> --help` is intercepted\n  before dispatch at every listed path, exits zero, and has no command side\n  effects.\n- [`node-api-reference.md`](node-api-reference.md) is projected from\n  `package.json#exports` and exact ESM export declarations. The packaged\n  `dist/site/node-api-registry.json` carries the same per-symbol signatures,\n  parameters, conservative return/error boundaries, side-effect classification,\n  maturity, example import, and source location.\n\n## Commands\n\n`buildchain create github-artifact-attestation-policy` seals the expected\nartifact, caller source, original Linux build, immutable Buildchain signer, and\nGitHub permission set before the Release Passport is collected.\n`buildchain verify github-artifact-attestation` invokes `gh attestation verify`\nwith the exact signer/source policy and then verifies the retained bundle,\npredicate, platform manifest, Passport, and Buildchain evidence locally. See\n[`github-artifact-attestation.md`](github-artifact-attestation.md).\n\n### Governed paper lifecycle\n\n`buildchain paper` is the unified operator surface for one paper repository or\na discovered fleet. Every subcommand returns a versioned JSON contract with\n`--json`:\n\n```bash\nbuildchain paper scaffold --package @kungfu-tech/paper-example \\\n  --repository kungfu-systems/paper-example\nbuildchain paper migrate --json\nbuildchain paper agent verify --json\nbuildchain paper work start golden-path --json\nbuildchain paper work submit --json\nbuildchain paper fleet audit --root ../papers --json\nbuildchain paper fleet update --root ../paper-worktrees --json\nbuildchain paper preflight --offline --json\nbuildchain paper bootstrap npm --json\nbuildchain paper build --json\nbuildchain paper alpha --json\nbuildchain paper status --json\nbuildchain paper resume --json\n```\n\nThe safety and authority boundary is explicit:\n\n- `scaffold` plans a 17-file, no-overwrite repository shape by default; add\n  `--write` to create only missing files.\n- `migrate` plans the Buildchain-owned authority, workflow, contract lock,\n  version pin, package, agent-entry policy, managed `AGENTS.md` section, and\n  required-check changes needed by an existing paper repository. It pins an\n  exact v3 dependency and adds pnpm-backed paper scripts.\n  Add `--write` only after reviewing exact old and new digests; paper content\n  and publication configuration are never rewritten. Refresh\n  `pnpm-lock.yaml` with `pnpm install --lockfile-only` after a write.\n- `agent verify` is the mandatory resume check on an existing work branch. It\n  verifies the digest-bound `.buildchain/paper/agent-entry.json`, the single\n  managed `AGENTS.md` section, exact package scripts and v3 dependency, runtime\n  source SHA, development target, and current branch lineage. `--ci` derives\n  the pull-request source and target from GitHub context and fails closed on a\n  non-work source branch or a target other than the configured development\n  line.\n- `work start` derives the protected development branch from the configured\n  publication semver line and creates a safe local work branch only when the\n  worktree is clean, the sole `origin` is the canonical `kungfu-systems`\n  repository, and local HEAD equals the exact remotely observed development\n  SHA. It never fetches or merges silently.\n- `work submit` accepts only an allowed non-protected work branch that contains\n  the exact remote development commit. It rejects divergent remote work,\n  wrong-base pull requests, dirty trees, forks, and ambiguous remotes; execution\n  uses a normal non-force push and opens or reuses a PR to the derived\n  development branch.\n- `fleet audit` discovers `paper-*` repositories from a root and emits one\n  deterministic audit root over exact runtime, dependency, lockfile, workflow,\n  authority, and repository observations. `fleet update` reuses the migration\n  contract for every discovered repository, remains dry-run by default, and\n  refuses protected or non-work branches.\n- The scaffolded `.buildchain/paper/provisioning-authority.json` binds both\n  build/release caller workflow byte digests, the required verify caller, the\n  agent-entry policy and instructions, their exact reusable-workflow SHA, the\n  runtime SHA, contract-lock bytes, npm registry and trusted-publisher\n  coordinates, and the repository Actions/generated-write policy under one\n  digest. A floating Buildchain ref cannot change release policy after that\n  authority is accepted.\n- The reusable `check.yml` detects publication-artifact repositories and runs\n  `paper preflight --offline --ci` inside the existing required check context.\n  Skipping the local CLI therefore cannot admit a missing entry contract,\n  drifted Buildchain-owned surface, unsafe source branch, or wrong PR target.\n- `preflight` separates local readiness from readiness for external mutation.\n  `--offline` skips live GitHub and npm observations without treating them as\n  local failures. Live readiness requires default workflow permissions `read`,\n  Actions pull-request approval disabled, and GitHub App or equivalent narrow\n  generated-write credential metadata.\n- `bootstrap npm` always performs npm pack and publish dry-runs first. A real\n  public bootstrap requires both `--execute` and\n  `--confirm-public-package <exact-name>`, uses only the official npm registry,\n  fixes the bootstrap version at `0.0.0-bootstrap.0`, and returns only npm URLs\n  observed from command output. Success requires public package readback and\n  the exact repository/workflow/environment trusted-publisher binding. For\n  GitHub, the npm coordinate is the workflow filename (`paper-release.yml`),\n  not its `.github/workflows/` repository path.\n- `build` plans the two-clean-build reproducibility proof. Add `--execute` to\n  create and verify the sealed publication bundle.\n- `alpha` plans or opens the protected Alpha pull request; it never merges,\n  publishes, or advances a floating ref.\n- `status` reports only evidence found in the repository or external\n  observations. It never infers a later lifecycle state from an earlier one.\n- `resume` plans or dispatches the repository's thin release workflow; the\n  protected workflow remains the release authority.\n\nThe ordered evidence states are `scaffolded`, `governed`, `admitted`,\n`bootstrapped`, `trust-bound`, `content-ready`, `artifact-sealed`,\n`package-published`, `alpha-complete`, `staging-visible`, and\n`production-visible`. A state can be `satisfied`, `not-reached`, `blocked`, or\n`unknown`; consumers must not collapse those distinctions.\n\nThe corresponding Node surface is\n`@kungfu-tech/buildchain/paper`. Planning and status functions are read-only;\n`writePaperScaffold()`, `writePaperMigration()`, and\n`writePaperFleetUpdate()` are the bounded local writers. Work plans expose\nseparate rechecking executors for local branch creation and normal push, and\n`executePaperNpmBootstrap()` preserves the same confirmation boundary used by\nthe CLI.\n\n`buildchain layout` is the stable machine question for repository layout. Tools\nsuch as Shifu should call it instead of copying `.buildchain/` path constants:\n\n```bash\nbuildchain layout --cwd /path/to/repository --json\n```\n\nThe result identifies the Buildchain version pin, repository root and config,\nthe canonical and currently resolved KFD-3 registry paths, and the KFD field\nused to declare Shifu jurisdiction. A repository is in Shifu's distribution\njurisdiction only when a KFD-3 surface explicitly declares\n`distribution.registrar=\"shifu\"`; the presence of Buildchain configuration is\nnot sufficient. The same contract is available through\n`createBuildchainLayoutDiscovery()` from\n`@kungfu-tech/buildchain/buildchain-layout`.\n\n`buildchain init` writes a starter `.buildchain/buildchain.toml` and a reusable workflow\ncaller at `.github/workflows/build.yml`.\n\n`buildchain portable-cache plan` turns a consumer-owned, secret-free manifest\ninto GitHub Actions cache inputs without letting each consumer invent key or\nrestore-prefix semantics. The exact key binds source SHA and the consumer plan\ndigest; the compatible restore prefix still requires the same provider schema,\nlayer, roots, runner image, platform/architecture, toolchain, dependency lock,\nand build profile.\n\n```bash\nbuildchain portable-cache plan \\\n  --manifest .buildchain/portable-cache.json \\\n  --output .buildchain/portable-cache-plan.json \\\n  --github-output \"$GITHUB_OUTPUT\"\n```\n\nThe emitted `cache-key`, `restore-keys`, and `cache-paths` values are intended\nfor pinned `actions/cache/restore` and `actions/cache/save` actions. After\nrestore and a consumer validation probe, seal the provider result:\n\n```bash\nbuildchain portable-cache receipt \\\n  --plan .buildchain/portable-cache-plan.json \\\n  --matched-key \"$CACHE_MATCHED_KEY\" \\\n  --cache-hit \"$CACHE_HIT\" \\\n  --validation-status pass \\\n  --cold-fallback-status passed \\\n  --output .buildchain/portable-cache-receipt.json\n```\n\nThe receipt distinguishes `exact`, `compatible`, `miss`, and `corrupt`.\nUnknown or contradictory provider evidence fails closed. A miss or corruption\nrequires the consumer's audited cold path; a cache never substitutes for the\nconsumer's current build or tests. Roots must be workspace-relative or under\n`~/`, and manifests cannot carry credentials, absolute host paths, or escape\nsegments. `cold-fallback-status=passed` qualifies a miss only after the current\nsource has completed its normal build and test path.\n\nSupported presets:\n\n- `--type package` for Node package repositories with pnpm, npm, or yarn.\n- `--type native` for CMake-style native projects.\n- `--type web-surface` for preview/staging/production site or app deployments.\n- `--type infra-contract` for provider-agnostic infrastructure contract\n  validation, observation, contract publication, and downstream propagation\n  planning without default mutation. Provider adapters expose built-in command\n  plans by default, and only configured `[infra.commands]` hooks can execute.\n- `--type publication-artifact` for papers, reports, specifications, and other\n  publication repositories that produce PDFs, metadata, source bundles, and\n  site-consumable manifests without becoming web-surface repositories. The\n  scaffold uses Buildchain's pinned\n  `ghcr.io/kungfu-systems/build-images/latex-pdf-builder:v1.2.0` toolchain for\n  LaTeX PDF builds.\n- `--type distribution-index` for Homebrew taps and other index repositories\n  whose files are projections of upstream release passport evidence.\n- `--type anchored-package` for packages whose version is anchored to an\n  explicit upstream release manifest.\n\nThe native preset includes an opt-in `[diagnostics.native]` profile with common\ntool/cache/artifact probes. Consumers can keep it enabled, adjust the tool and\ndirectory lists, or disable it if a repository does not need native diagnostics.\n\n`buildchain validate` parses `.buildchain/buildchain.toml`, checks configured version-state\nfiles, and can require named lifecycle stages:\n\n```bash\nbuildchain validate \\\n  --require-version-state \\\n  --require-lifecycle-stages install,build,verify\n```\n\n`buildchain lifecycle run <stage>` executes a lifecycle stage and writes the\nsame deterministic artifact manifest contract used by the reusable workflow:\n\n```bash\nbuildchain lifecycle run build \\\n  --artifact-path dist \\\n  --artifact-name \"{repo}-{version}-{platform}\"\n```\n\n`buildchain dev merge-queue` plans a GitHub merge-queue policy for a protected\nBuildchain dev channel. Declare every workflow that emits a required check; the\ncommand fails closed unless each file handles both `pull_request` and\n`merge_group` without reading `github.event.pull_request` directly:\n\n```bash\nbuildchain dev merge-queue \\\n  --repository kungfu-systems/example \\\n  --branch dev/v4/v4.0 \\\n  --workflow .github/workflows/source-acceptance.yml \\\n  --workflow .github/workflows/affected-native-pr.yml\n```\n\nThe default output is a read-only plan. Add `--apply` only after reviewing it.\nApply creates the exact-branch merge-queue ruleset before changing classic\nrequired status checks from strict to loose, preserves the required check\nidentities, and is safe to repeat. `gh` must be authenticated with repository\nAdministration write permission for apply mode.\n\nRepositories can make that policy declarative in `buildchain.toml`:\n\n```toml\n[governance.dev.merge_queue]\nmode = \"enabled\" # enabled, inherit, or disabled\nrequired_workflows = [\".github/workflows/verify.yml\"]\ncheck_response_timeout_minutes = 120\nmax_entries_to_build = 1\nbypass_users = [\"release-owner\"]\n```\n\nUse `buildchain dev merge-queue --from-config` to resolve and reconcile the\ndeclaration. `enabled` requires an exact queue on the target dev branch;\n`disabled` suppresses automatic queue creation; `inherit` copies the active\ndefault dev branch's queue parameters and bypass actors. When the table is\nabsent, release-line bootstrap uses the backward-compatible `inherit` mode.\nEvery inherited or explicitly enabled queue still validates each declared\nrequired workflow before any mutation. For a legacy repository with no table,\nan already-active exact queue on the current default dev branch is accepted as\nthe inheritance evidence; new declarations should list the workflows so future\nchanges are revalidated from source.\nThe `Dev Merge Queue Governance` workflow runs this reconciliation after\ngovernance-relevant changes land on a dev branch; its manual dispatch remains\ndry-run by default.\n\n`buildchain release line open` plans or writes the first version-state commit\nfor a new semver minor line. It does not publish anything. The dry-run mode is\nthe default and returns the dev/alpha/release refs, protection contract, default\nbranch action, and initial version before any GitHub mutation happens:\n\n```bash\nbuildchain release line open \\\n  --major 4 \\\n  --minor 1 \\\n  --source-ref release/v4/v4.0 \\\n  --json\n```\n\nThe write mode only updates local version-state files. The repository workflow\n`Release Line Bootstrap` wraps this command and, when `apply=true`, commits the\ninitial version state, creates `dev/vX/vX.Y`, `alpha/vX/vX.Y`, and\n`release/vX/vX.Y`, applies one-review branch protection, reconciles declared or\ninherited merge-queue governance, switches the default branch only after that\nreconciliation succeeds, and opens the first dev-to-alpha channel PR:\n\n```bash\nbuildchain release line open \\\n  --major 4 \\\n  --minor 1 \\\n  --source-ref release/v4/v4.0 \\\n  --write \\\n  --json\n```\n\n`buildchain` also publishes a public surface reverse audit as\n`dist/site/public-surface-audit.json`. The audit enumerates CLI commands from\n`bin/buildchain.mjs`, workflow inputs, action inputs, site pages, and docs\ncommand references, then compares them with the generated registries. Buildchain\nself-checks fail closed when an enumerable public surface is missing from the\nregistry:\n\n```js\nimport {\n  collectPublicSurfaceReverseAudit,\n  assertPublicSurfaceReverseAudit,\n} from \"@kungfu-tech/buildchain/public-surface-audit\";\n\nassertPublicSurfaceReverseAudit(\n  collectPublicSurfaceReverseAudit({ root: process.cwd() }),\n);\n```\n\n`buildchain kfd` is the product-facing KFD namespace. Schema commands expose the\nmachine-readable KFD standards shipped by `@kungfu-tech/kfd`, while versioned\nsubcommands host concrete product workflows. KFD-1, KFD-2, and KFD-3 are\nfirst-class Buildchain surfaces. KFD-4, KFD-5, and KFD-7 expose fail-closed\nproduct-evidence gate and verification protocols; passing those protocols does\nnot itself qualify, certify, activate, or ship support.\n\n`status` reports implemented support and the active repo-owned file layout.\n`migrate-layout` moves legacy root files into `.buildchain/`:\n\n```bash\nbuildchain kfd status --json\nbuildchain kfd migrate-layout --write\nbuildchain kfd 4 gate --input-json kfd-4-gate-input.json --output kfd-4-gate.json\nbuildchain kfd 5 gate --input-json kfd-5-gate-input.json --output kfd-5-gate.json\nbuildchain kfd 7 gate --input-json kfd-7-gate-input.json --output kfd-7-gate.json\nbuildchain kfd support project --manifest-json adopter-manifest.json \\\n  --manifest-gate-json adopter-manifest-gate.json --output kfd-support.json\n```\n\nKFD-1 commands generate and validate contract-world release evidence:\n\n```bash\nbuildchain kfd 1 schema --json\nbuildchain kfd 1 witness --json\nbuildchain kfd 1 gate --witness-json kfd-1-witness.json --json\nbuildchain kfd 1 verify --gate-json kfd-1-gate.json --json\n```\n\nKFD-2 commands validate trust taxonomy entries and generate Buildchain's public\nclaim evidence. Product repositories use the `product-claims` subcommand to\nvalidate and render their own declared KFD-2 release claims under the canonical\nBuildchain KFD layout:\n\n```bash\nbuildchain kfd 2 schema --json\nbuildchain kfd 2 taxonomy --entry-json residual-risk.json --kind residualRisk --json\nbuildchain kfd 2 claims --json\nbuildchain kfd 2 product-claims check --json\nbuildchain kfd 2 product-claims write --json\nbuildchain kfd 2 product-claims render --json\n```\n\nThe default source is `.buildchain/kfd/kfd-2/registry.json`; outputs are\n`.buildchain/kfd/kfd-2/release-claims.json`, per-claim release-passport inputs\nunder `claims/`, and `buildchain-claim-args.txt`. Use `--registry` or\n`--output-dir` only for an explicit product packaging projection. `check` never\nwrites and exits non-zero when outputs drift.\n\nKFD-3 commands are separate from Buildchain's self reverse audit: products can\ndetect standard public surfaces, register the accepted boundary, audit the\ncurrent source or artifact tree, generate a release-passport-compatible witness,\nand expose a capability map for agents:\n\n```bash\nbuildchain kfd schema list --json\nbuildchain kfd schema show kfd-3 --json\nbuildchain kfd 3 detect --kind node-api --kind cli --json\nbuildchain kfd 3 register node-api --product Buildchain\nbuildchain kfd 3 audit --json\nbuildchain kfd 3 witness --kind prebuild --output .buildchain/kfd/kfd-3/collaboration-interface.prebuild.json\nbuildchain kfd 3 query buildchain --json\nbuildchain kfd 4 schema --json\n```\n\nThe public Node API is exported from `@kungfu-tech/buildchain/kfd`. See\n[`kfd-support.md`](kfd-support.md) for the detected / declared / enforced model\nand the agent query flow.\n\nLifecycle runs also write a Buildchain observability JSONL log at\n`.buildchain/logs/events.jsonl` by default. Framework events use\n`source=buildchain`; consumer lifecycle commands use `source=user`. This lets a\nmaintainer tell apart time spent inside Buildchain's artifact/manifest\nframework from time spent in the repository's own build, test, packaging, or\npublish commands. The artifact manifest and summary embed the observability\nsummary for that lifecycle run id, so uploaded artifacts preserve the timing\nfacts without mixing in older JSONL events.\n\n`buildchain log`, `buildchain mark`, and `buildchain span` expose the same event\nprotocol to repository scripts:\n\n```bash\nbuildchain mark --event configure.ready --phase configure --attribute target=release\nbuildchain span --event native.build --phase build -- cmake --build build\nbuildchain log warn --event cache.miss --component conan --attribute token=hidden\nbuildchain log summary --json\nbuildchain verify observability-log .buildchain/logs/events.jsonl --min-events 4 --require-phase build\nbuildchain diagnostics summary .buildchain/artifacts/*/diagnostics.json --json\nbuildchain sample process-tree --label native-build --interval-ms 15000 -- make -j20\n```\n\nDuring `buildchain lifecycle run`, child processes receive\n`BUILDCHAIN_LOG_PATH` and `BUILDCHAIN_LOG_RUN_ID`. A shell, Python, CMake, Conan,\nor JavaScript helper can call `buildchain mark` or `buildchain span` mid-build\nand have those events grouped into the same lifecycle summary.\n`buildchain verify observability-log` is a release gate: it fails when the log\nis missing, has too few events, contains error events, or does not include\nrequired phases, components, or event names.\n\nThe JSON summary also includes an additive `controlPlane` block. It counts\nworkflow-friction incident outcomes and production release-intent outcomes,\nincluding incident reuse rate, release-intent suppression rate, and suppression\nreasons. Buildchain writes those outcome events locally; it does not send\ntelemetry outside the runner.\n\nThe event protocol is JSONL and is also available from the SDK:\n\n```js\nimport { createBuildchainLogger } from \"@kungfu-tech/buildchain/logging\";\n\nconst logger = createBuildchainLogger({\n  source: \"user\",\n  component: \"native-build\",\n});\nlogger.mark(\"configure.ready\", { phase: \"configure\" });\n```\n\nSecret-looking attribute keys such as `token`, `password`, `secret`,\n`authorization`, `cookie`, and `private-key` are redacted before they are written.\nFull command strings are not recorded by `span`; scripts should provide stable\nevent names and safe attributes instead.\n\n`buildchain diagnostics summary` reads one or more small diagnostics artifacts\nand emits the same cross-platform summary as the diagnostics SDK:\n\n```bash\nbuildchain diagnostics summary \\\n  .buildchain/artifacts/linux-x64/diagnostics.json \\\n  .buildchain/artifacts/macos-arm64/diagnostics.json \\\n  --output .buildchain/artifacts/diagnostics-summary.json \\\n  --json\n```\n\nThe JSON summary keeps per-platform lifecycle stage tables, adds lifecycle\ntotal durations, carries top slow spans, aggregates warning/error counts, and\nsorts the slowest platforms. Each platform row carries compact runner facts,\nchecked tool versions/missing tools, package manager/cache directory details,\ncompiler-cache availability, and a compact process sampler summary: requested\nparallelism, observed max active processes, the ratio between them, sample\ncount, process categories, and the top sampled command basenames. This lets\nmaintainers inspect matrix timing, runner, tool, cache, and concurrency context\nwithout downloading large platform binaries or process sidecars first.\nWhen a sibling `diagnostics-manifest.json` is available, the summary also records\nits file list and verifies the listed `diagnostics.json` byte count and sha256.\nMissing, unreadable, or mismatched sidecar manifests are reported through\n`diagnosticsManifestWarningCount` and the per-platform `diagnosticsManifest`\nfield without failing the timing rollup.\nThe summary also compares each `diagnostics.json` contract to\n`BUILDCHAIN_DIAGNOSTICS_CONTRACT`; mismatches are reported through\n`diagnosticsContractWarningCount` and the per-platform `diagnosticsContract`\nfield so reviewers can separate diagnostics schema drift from lifecycle\nwarnings or build failures.\n\nWithout `--json`, the command prints a compact lifecycle timing table with\ninstall/build/verify/publish, artifact scan/upload, total, warning, and error\ncolumns for each platform, plus `jobs` and `active` columns for requested and\nobserved process concurrency when sampler data is present.\n\n`buildchain facts` collects and verifies source/version/output facts for\nmodules and products:\n\n```bash\nbuildchain facts module \\\n  --module native-core \\\n  --output .buildchain/facts/native-core.json \\\n  --legacy-kungfu-buildinfo framework/core/src/kungfu/yijinjing/kungfubuildinfo.json\n\nbuildchain facts aggregate \\\n  --product kungfu \\\n  --module-fact .buildchain/facts/native-core.json \\\n  --artifact dist/kungfu.zip \\\n  --output .buildchain/facts/kungfu.json\n\nbuildchain facts verify --fact .buildchain/facts/kungfu.json\n```\n\nThe same implementation is available from\n`@kungfu-tech/buildchain/build-facts`. Release passports can include these\nfacts with repeated `--build-facts-json` arguments to\n`buildchain collect github-release`. See\n[`build-facts.md`](build-facts.md) for the config schema and Node API.\n\n`buildchain sample process-tree` wraps a long-running command and periodically\nwrites process-tree snapshots:\n\n```bash\nbuildchain sample process-tree \\\n  --label native-build \\\n  --interval-ms 15000 \\\n  --output .buildchain/diagnostics/process-samples.jsonl \\\n  --summary-output .buildchain/diagnostics/process-summary.json \\\n  -- \\\n  make -j20\n```\n\nThe command returns the wrapped command's exit status. The JSONL file contains\nsmall timestamped samples; the summary JSON records requested parallelism,\nobserved concurrency, sampled CPU, command categories, and top command\nbasenames. Use it when a native build requests high parallelism but appears to\nspend long stretches in low-concurrency compile, archive, link, or cache steps.\n\n`buildchain doctor` checks repository readiness before remote side effects:\n\n```bash\nbuildchain doctor --json\n```\n\nIt validates `.buildchain/buildchain.toml`, package-manager detection, Git repository state,\nand the reusable workflow caller. For `version.strategy = \"anchored\"` with\n`version.next = \"manual\"`, it also embeds the anchored package release contract\ncheck: anchor manifest readability, configured version files, trusted\npublishing, package publish order, and required lifecycle stages. Add\n`--require-publish-source-lock` inside a publish job when the doctor report\nshould also fail unless the job is running from a resolved `publish-gate/*`\nsource lock.\n\nAnchored/manual package publish jobs can run the narrower source-lock gate\ndirectly:\n\n```bash\nbuildchain publish-source validate-anchored-release --json\n```\n\nThe command requires `BUILDCHAIN_PUBLISH_SOURCE_REF`,\n`BUILDCHAIN_PUBLISH_SOURCE_SHA`, and `BUILDCHAIN_PUBLISH_SOURCE_LOCKED` from the\nreusable build workflow outputs. It fails closed for direct `alpha/*` or\n`release/*` channel-branch publication, and checks the publish-gate consumer\nversion against configured version files and the anchor manifest. The JSON\nresult is shaped for future `buildchain.libkungfu.dev` fact ingestion.\n\n`buildchain release`, `buildchain web-surface`, `buildchain infra-contract`,\n`buildchain publication-artifact`, `buildchain publish-source`,\n`buildchain badges`, `buildchain homebrew`, and `buildchain build-contract`\nroute to the same implementation used by\nBuildchain's package APIs or GitHub Actions workflows. This keeps local\ninspection and CI behavior on the same implementation path.\n\nGenerate publication artifact metadata after building a paper or report:\n\n```bash\nbuildchain publication-artifact manifest \\\n  --source-sha \"$(git rev-parse HEAD)\" \\\n  --json\n```\n\nRun the fail-closed clean-room gate before Alpha or release admission:\n\n```bash\nbuildchain publication-artifact reproducibility \\\n  --source-sha \"$(git rev-parse HEAD)\" \\\n  --promote \\\n  --json\n```\n\nThe command checks two independent clones of the exact commit, isolates caches,\nderives `SOURCE_DATE_EPOCH` from Git, and compares every declared artifact,\nsource bundle, publication evidence file, npm package file, and actual npm\ntarball. It writes\n`.buildchain/publication/reproducibility-receipt.json`. Only a byte-identical\nbuild using the digest-pinned `latex-docker` toolchain is qualifying.\n`--allow-unpinned-toolchain` exists for local diagnostics and never changes the\nreceipt's `qualifying` field.\n\nGenerate the Buildchain-owned npm paper package contents from declared\npublication facts:\n\n```bash\nbuildchain publication-artifact npm-package --json\n```\n\nThis command reads `project.type = \"publication-artifact\"`,\n`publication.version`, and `[publish] kind = \"npm-paper-package\"` plus\n`publish.package`; it writes `.buildchain/publication/npm-package` by default.\nThe `paper-release.yml@v3` reusable workflow uses the same command before\nrunning the standard npm publish transaction.\n\nThe command writes `.buildchain/publication/publication-artifact.json`,\n`.buildchain/publication/publication-artifact-passport.json`, a source bundle,\nand, when `[publication.archive]` is configured,\n`.buildchain/publication/publication-registry.json` by default. See\n[`publication-artifacts.md`](publication-artifacts.md) for the repository\ncontract, pinned LaTeX builder, and reusable workflow.\n\nGenerate, check, or update the managed README badge block:\n\n```bash\nbuildchain badges readme --json\nbuildchain badges readme --check\nbuildchain badges readme --write\nbuildchain badges bundle --json\nbuildchain badges bundle --check\nbuildchain badges bundle --write\nbuildchain badges bundle --claims kfd-1,release-passport --write\n```\n\nThe `--json` form emits the `kungfu-buildchain-readme-badge-facts` object.\n`--check` fails closed when the README marker block is missing or stale.\n`--write` inserts or replaces only the marked block. KFD passed badges come\nfrom the repository's own verified release passport; unreleased repositories\ndowngrade to explicit local declarations such as `declared`, `aligned`, or\n`planned`. `buildchain badges bundle` is the focused trust-badge entrypoint: it\nemits `kungfu-buildchain-badge-bundle-facts` and defaults to KFD-1, KFD-2,\nKFD-3, and Release Passport. See [`readme-badges.md`](readme-badges.md) for the\nmarker contract and `[badges]` / `[badges.bundle]` configuration.\n\nGenerate or check Homebrew tap projections from upstream release passports:\n\n```bash\nbuildchain homebrew update-formula \\\n  --package buildchain \\\n  --release-passport https://github.com/kungfu-systems/buildchain/releases/download/v3.0.0/buildchain.release.json \\\n  --write\n\nbuildchain homebrew check --json\n```\n\n`update-formula` writes `Formula/buildchain.rb` and `tap-manifest.json` from\nupstream release passport evidence. `check` fails closed when the Formula,\nmanifest, artifact digests, or KFD status drift from the upstream passport. See\n[`homebrew.md`](homebrew.md) for the distribution-index project contract.\n\n`buildchain collect github-release` creates a release passport bundle from\nGitHub Release assets or a local asset directory:\n\n```bash\nbuildchain collect github-release \\\n  --tag v3.0.0 \\\n  --repository kungfu-systems/buildchain \\\n  --assets-dir dist \\\n  --output-dir .buildchain/release-passport\n```\n\nThe bundle includes `buildchain.release.json`, `artifact-evidence.json`,\n`impact.json`, `agent-index.json`, `product-mechanism.json`, `check-report.json`,\nand `llms.txt`. Production binary distribution defaults to GitHub-hosted\nrunners so other projects can reproduce the release lane; self-hosted runners\nremain compatibility fixtures and are recorded as runner facts when used.\n\nFor publish-transaction releases, pass the additional evidence inputs so\n`buildchain.release.json` becomes the unified passport instead of a binary-only\nasset summary:\n\n```bash\nbuildchain collect github-release \\\n  --tag v3.0.0 \\\n  --repository kungfu-systems/buildchain \\\n  --assets-dir dist \\\n  --publish-evidence-json .buildchain/release-evidence/v3.0.0/evidence.json \\\n  --transaction-json .buildchain/release-state/v3.0.0/state.json \\\n  --package-set-json package-set.json \\\n  --impact-json impact.json \\\n  --trusted-publishing-json trusted-publishing.json \\\n  --anchor-manifest-json libnode.release.json \\\n  --build-summary-json .buildchain/artifacts/build-summary.json \\\n  --platform-manifest-json .buildchain/artifacts/linux-x64/manifest.json \\\n  --platform-manifest-json .buildchain/artifacts/darwin-arm64/manifest.json \\\n  --platform-manifest-json .buildchain/artifacts/win32-x64/manifest.json \\\n  --dist-tag-evidence-json .buildchain/release-evidence/v3.0.0/dist-tag-evidence.json \\\n  --kfd-1-witness-json .buildchain/kfd/kfd-1/contract-world.witness.json \\\n  --kfd-2-claim-json .buildchain/kfd/kfd-2/release-claims.json \\\n  --kfd-3-prebuild-witness-json .buildchain/kfd/kfd-3/collaboration-interface.prebuild.json \\\n  --kfd-3-artifact-verify-cmd \"kungfu agent verify --json\" \\\n  --release-extra-json '{\"channel\":\"release\",\"targetRef\":\"release/v3/v3.0\"}' \\\n  --output-dir .buildchain/release-passport\n```\n\nThe generated passport records the main and platform packages, npm dist-tags,\npublished versions, release source/ref state, anchor manifest digest, registry\nartifact digests, trusted publishing evidence, and Buildchain transaction\nresult. It also records `buildSummary`, `platformArtifactManifests`, and\n`distTagPromotion` when those JSON inputs are supplied. `packageSet` keeps the\nordered package set; `publish.packages[]` is the agent-readable npm publication\nsummary for each main/platform package. For Buildchain releases, verification\nexpects the supplied package set to include the main package plus the three\nplatform packages with version, dist-tag, and digest evidence. Verification\nfails closed if supplied sections are internally incomplete or point to\nartifacts without matching evidence.\n\n`--kfd-1-witness-json` attaches a KFD-1 contract-world release gate. The witness\nis structured JSON: consumers declare the contract world, canonical JSON policy,\nartifact paths, and expected SHA-256 digests. Buildchain imports KFD-owned\nmetadata from `@kungfu-tech/kfd`, freezes the witness before build publication,\nthen verifies the resulting artifact bytes itself and writes the evidence under\nthe KFD-provided top-level key currently named `kfd-1`. Consumers should not\nduplicate this by running repository-specific scripts or invoking the Kungfu\nSDK from their release workflow.\n\nFor the KFD repository, KFD-1 witnesses may be self-hosted standard-contract\nwitnesses: docs, schemas, standards metadata, package exports, and\nsite-consumption entrypoints are checked from source hashes to packaged artifact\nhashes, and the passport records schema IDs, self-hosting boundary, result, and\nresponsibility state.\n\n`--kfd-2-claim-json` attaches explicit public release claims to the KFD-2\nrelease trust passport audit. Buildchain also derives KFD-2 claims from KFD-1\nand KFD-3 gate evidence. Public claims must bind declared sources,\nmachine-readable evidence, hashes, artifact coordinates, verification results,\naudit boundary, responsibility state, and residual risk. Unbound claims fail\npassport verification; prose-only claims downgrade the KFD-2 audit and emit a\nwarning.\n\n`--kfd-3-prebuild-witness-json` attaches a KFD-3 collaboration-interface\nrelease gate. The product remains the source of truth: it emits a pre-build\nwitness that contains or points to its KFD-3 collaboration interface, declared\nparticipant-facing public surfaces, and registry digest. Buildchain freezes\nthat declaration before publication. The artifact side is supplied either by\n`--kfd-3-artifact-witness-json` or by a product-owned command such as\n`--kfd-3-artifact-verify-cmd \"kungfu agent verify --json\"`. Buildchain then\nchecks closure: every declared shipped public surface must be present in the\nartifact witness, and every artifact-exposed participant-facing public surface\nmust have been declared. The generated passport writes this evidence under the\nKFD-provided top-level key currently named `kfd-3`.\n\nThis gate is useful for agent-facing products because it turns KFD-3 from prose\ninto release evidence. A package cannot claim KFD-3 collaboration-interface\nsupport merely because the docs mention it; the release passport must show the\nfrozen declaration, the artifact-side witness digest, and a passing closure\ncomparison.\n\n`--invariant-passport-json` attaches a product-owned invariant Passport to the\nrelease gate and may be repeated. `--invariant-passport-cmd` runs a product\ncommand that emits one Passport JSON document. Buildchain verifies the\nPassport root, exact clean source identity, `verified` verdict, complete\nplatform coverage, and residual-risk shape; it does not redefine the product's\ninvariant semantics. Declared invariant Passport input is fail-closed.\nFor the KFD repository itself, the witness can declare docs, schemas, standards\nmetadata, package exports, and site-consumption contracts as grouped public\nsurfaces; the artifact witness must expose the same enumerable package/site\nsurfaces or verification fails closed.\n\n`--impact-json` supplies the surface-aware impact ledger. Production release\npassports (`release/*`) and major publish-gate passports require\n`surfaceImpacts[]`; alpha, local, and legacy passport contexts keep it\noptional. When `surfaceImpacts[]` is required or supplied, the verifier requires\neach entry to include an id, impact, and rationale, and requires\n`versionImpact.final` to match the highest declared surface impact. The\ncollector copies `versionImpact` plus `surfaceImpacts` into\n`buildchain.release.json`. This lets\n`buildchain explain release --for agent --json` state why a release is patch,\nminor, or major instead of relying on file-path memory.\n\nFor a promote-only stable transaction, Buildchain can derive a patch-level\nrelease-governance ledger when the PR-stage release-candidate passport proves\nthe stable source tree is exactly the previously qualified candidate tree.\nThis fallback is unavailable when candidate evidence is absent, stale, or not\ntree-equivalent.\n\nBuildchain dogfoods its observability toolkit in this lane. The standalone\nbuilder writes API-generated events, while the workflow uses `buildchain mark`,\n`buildchain span`, `buildchain verify observability-log`, and `buildchain log\nsummary`; the event logs and summaries are published as release passport assets.\n\nVerify and explain release passports:\n\n```bash\nbuildchain verify release-passport .buildchain/release-passport/buildchain.release.json\nbuildchain explain release --passport .buildchain/release-passport/buildchain.release.json --for agent --json\nbuildchain inspect release --passport .buildchain/release-passport/buildchain.release.json\n```\n\nThe verifier fails closed when required protocol files are absent, artifacts are\nnot covered by evidence, or digests disagree. The explanation output is shaped\nfor agents: trust, completeness, impact, recovery route, and next action.\n\nVerify a published artifact by subject:\n\n```bash\nbuildchain verify artifact ./Kungfu-2.8.0-windows-x64.exe\nbuildchain inspect artifact ./Kungfu-2.8.0-windows-x64.exe --json\nbuildchain explain artifact ./Kungfu-2.8.0-windows-x64.exe --for agent --json\nbuildchain verify artifact npm:@kungfu-tech/libnode@22.22.3-kf.3-alpha.18 \\\n  --repository kungfu-systems/libnode \\\n  --tag v22.22.3-kf.3-alpha.18 \\\n  --json\n```\n\n`verify artifact` computes or obtains the subject digest, discovers the\ndetached release passport, verifies the passport, then requires that the\nsubject digest appears in the passport's release assets, package set, publish\nevidence, or artifact evidence. Outcomes are explicit: `pass`, `fail`, or\n`unverifiable`. A filename is only a hint; trust comes from digest equality.\nFor `npm:<name>@<version>` subjects, Buildchain resolves `dist.integrity` from\nthe npm registry before matching passport evidence. Use `--npm-registry <url>`\nto verify packages from a custom registry; otherwise Buildchain uses\n`npm_config_registry` or `https://registry.npmjs.org/`.\n\nDiscovery is fail-closed and ordered:\n\n1. `--passport <file-or-url>`.\n2. Sidecar pointer, such as `<artifact>.buildchain-passport.json`.\n3. Embedded/package pointer, such as `package.json` `buildchain.releasePassport`.\n4. Local config or org index, such as `.buildchain/artifact-passport-locators.json`.\n5. GitHub Release default discovery from `github-release:` subjects, GitHub\n   Release asset URLs, or `--repository <owner/repo> --tag <tag>`.\n6. Custom `--locator-config <json-or-url>`.\n7. `unverifiable` with retry guidance.\n\nLocator files are policy, not protocol. They map subject fields such as\n`name`, `kind`, `version`, `digest`, `repository`, or `tag` to a detached\npassport location:\n\n```json\n{\n  \"schemaVersion\": 1,\n  \"contract\": \"kungfu-buildchain-artifact-passport-locator\",\n  \"locators\": [\n    {\n      \"match\": {\n        \"name\": \"Kungfu-2.8.0-windows-x64.exe\",\n        \"digest\": \"sha256:...\"\n      },\n      \"passport\": \"../release-passport/buildchain.release.json\"\n    }\n  ]\n}\n```\n\nSupported subject shapes include local files and directories, URLs,\n`npm:<name>@<version>`, `oci:...`, `s3:...`,\n`github-release:<owner/repo>@<tag>/<asset>`, and deployment endpoints. Local\nfiles, directories, and URLs are digestable directly; remote package, OCI,\nobject storage, and deployment subjects should provide a digest or resolve to a\nlocator that records one.\n\nSeal an exact artifact verification with the Node API, then verify or project\nthe resulting KFX admission envelope without reconstructing its roots:\n\n```bash\nbuildchain verify artifact-envelope envelope.json \\\n  --assessment-time 150 \\\n  --expected-root sha256:... \\\n  --expected-issuer buildchain.libkungfu.dev \\\n  --expected-publisher kungfu-systems \\\n  --expected-contract buildchain.release/v1 \\\n  --json\n\nbuildchain project kfx-admission envelope.json \\\n  --assessment-time 150 \\\n  --json\n```\n\nBoth commands call the public artifact-verification-envelope verifier. The\nprojected `attestation`, `trustInputs`, and `kfdAssessment` are direct copies of\nthe sealed envelope, and `envelopeRoot` stays identical across Node and CLI.\nSee [`artifact-verification-envelope.md`](artifact-verification-envelope.md).\n\nVerify infra-contract lifecycle evidence bundles:\n\n```bash\nbuildchain infra-contract --mode ci --source-sha \"$GITHUB_SHA\"\nbuildchain verify infra-contract-evidence-bundle .buildchain/infra-contract-evidence-bundle.json\n```\n\nThe infra-contract `ci` mode is mutation-free. It writes validate, plan,\ncontract, propagation dry-run, evidence bundle, and verification JSON artifacts\nunder `.buildchain/`, giving reusable workflows one standard responsibility\nchain instead of hand-written command sequences.\n\nThe infra-contract verifier is read-only. It recomputes the bundle hash and\nchecks that desired, plan, approval, apply, observe, contract, and propagate\nevidence remain bound to the same contract artifact. It also recomputes the\nbundle validation summary, so stale or misleading summary booleans fail closed\neven when the bundle hash has been refreshed.\n\n`buildchain release --dry-run` explains the release-line state machine before a\nmaintainer opens or merges a channel PR:\n\n```bash\nbuildchain release --dry-run --target-ref alpha/v4/v4.0\nbuildchain release --dry-run --target-ref release/v4/v4.0 --sha <verified-sha>\nbuildchain release dry-run --target-ref publish-gate/major --source-ref release/v4/v4.0\nbuildchain release explain --target-ref alpha/v4/v4.0 --json\n```\n\nThis is a Buildchain-level dry-run, not an npm dry-run. It explains the legal\nsource branch, exact release or alpha tags, floating tags, channel branches,\nversion-state files, governance checks, and publish transaction behavior that\nwould apply if the corresponding PR merge were promoted. It does not move\nbranches, move tags, edit files, publish npm packages, or run lifecycle publish\ncommands. `release explain` is the same explanation surface with a clearer name.\nPass `--json` for a machine-readable plan.\n\n`buildchain transaction inspect` is the top-level recovery inspection command\nfor the publish transaction state:\n\n```bash\nbuildchain transaction inspect --version v4.0.1-alpha.2\n```\n\nIt reads or locally initializes the durable transaction record and validates\navailable publish evidence. Remote durable refs and public Git ref finalization\nremain owned by `actions/promote-buildchain-ref`; the CLI inspection surface is\nfor preflight and recovery reasoning before a maintainer reruns or resumes a\npromotion.\n\n`buildchain npm dry-run` verifies the package shape before a release tag exists:\n\n```bash\nbuildchain npm dry-run --json\n```\n\nThe command validates `package.json`, infers the exact release tag\n`v${package.json.version}`, chooses npm dist-tag `alpha` for prereleases and\n`latest` for stable releases, runs `npm pack --dry-run --json`, and then runs\n`npm publish --dry-run --access public --tag <alpha|latest>` unless\n`--skip-npm-publish-dry-run` is passed. It never performs a real publish.\n\n## npm Publish Gate\n\nBuildchain's own npm package is published from\n`.github/workflows/buildchain-ref-promotion.yml`, inside the same publish\ntransaction that promotes release refs:\n\n- `v4.0.3-alpha.0` publishes to npm with dist-tag `alpha`.\n- `v4.0.2` publishes to npm with dist-tag `latest`.\n- moving refs such as `v4`, `v4.0`, and `v4.0-alpha` do not match the publish\n  workflow and do not publish.\n\nThe promotion workflow uses npm Trusted Publishing through GitHub Actions OIDC.\nIt runs on a GitHub-hosted runner with `id-token: write`, but it does not\nmanually run the release-candidate resolver or promote action. Buildchain's own\ndogfood path calls the declarative `release-candidate-promote.yml` wrapper with\nchannel, target ref/SHA, PR-stage workflow, artifact, status-check, and passport\ninputs. The wrapper generates the version-state commit, runs\n`lifecycle.verify`, runs `lifecycle.publish`, writes Buildchain publish\nevidence, validates that evidence, and only then moves exact tags and floating\nrefs.\n\n```bash\nnode scripts/npm-publish-transaction.mjs\n```\n\nBefore the first real release, configure npm Trusted Publishing for:\n\n- package: `@kungfu-tech/buildchain`\n- repository: `kungfu-systems/buildchain`\n- workflow: `.github/workflows/buildchain-ref-promotion.yml`\n\nNo npm package is published by manual dispatch or ordinary branch builds.\nManual dispatch on `.github/workflows/npm-publish.yml` remains dry-run only, so\nmaintainers can verify package contents and npm publish shape before opening or\nmerging the release PR."
    },
    {
      "id": "manual:cli-reference",
      "title": "Buildchain CLI Reference",
      "route": "/docs/cli-reference",
      "category": "manual",
      "capabilityGroup": "api-cli-reference",
      "audience": [
        "agent",
        "developer",
        "operator"
      ],
      "maturity": "stable",
      "sourcePath": "docs/cli-reference.md",
      "digest": "sha256:0aa0c937ca4f3f239f67c10a3e656ca0934cd3618bf84639525ea1fbd685c055",
      "headings": [
        {
          "level": 1,
          "title": "Buildchain CLI Reference",
          "anchor": "buildchain-cli-reference"
        },
        {
          "level": 2,
          "title": "`architecture`",
          "anchor": "architecture"
        },
        {
          "level": 3,
          "title": "`buildchain architecture`",
          "anchor": "buildchain-architecture"
        },
        {
          "level": 3,
          "title": "`buildchain architecture list`",
          "anchor": "buildchain-architecture-list"
        },
        {
          "level": 3,
          "title": "`buildchain architecture qualify`",
          "anchor": "buildchain-architecture-qualify"
        },
        {
          "level": 3,
          "title": "`buildchain architecture show`",
          "anchor": "buildchain-architecture-show"
        },
        {
          "level": 3,
          "title": "`buildchain architecture validate`",
          "anchor": "buildchain-architecture-validate"
        },
        {
          "level": 2,
          "title": "`audit`",
          "anchor": "audit"
        },
        {
          "level": 3,
          "title": "`buildchain audit`",
          "anchor": "buildchain-audit"
        },
        {
          "level": 3,
          "title": "`buildchain audit github-governance`",
          "anchor": "buildchain-audit-github-governance"
        },
        {
          "level": 3,
          "title": "`buildchain audit publication-control-plane`",
          "anchor": "buildchain-audit-publication-control-plane"
        },
        {
          "level": 2,
          "title": "`badges`",
          "anchor": "badges"
        },
        {
          "level": 3,
          "title": "`buildchain badges`",
          "anchor": "buildchain-badges"
        },
        {
          "level": 3,
          "title": "`buildchain badges bundle`",
          "anchor": "buildchain-badges-bundle"
        },
        {
          "level": 3,
          "title": "`buildchain badges readme`",
          "anchor": "buildchain-badges-readme"
        },
        {
          "level": 2,
          "title": "`build-contract`",
          "anchor": "build-contract"
        },
        {
          "level": 3,
          "title": "`buildchain build-contract`",
          "anchor": "buildchain-build-contract"
        },
        {
          "level": 2,
          "title": "`candidate`",
          "anchor": "candidate"
        },
        {
          "level": 3,
          "title": "`buildchain candidate`",
          "anchor": "buildchain-candidate"
        },
        {
          "level": 3,
          "title": "`buildchain candidate timeline`",
          "anchor": "buildchain-candidate-timeline"
        },
        {
          "level": 2,
          "title": "`collect`",
          "anchor": "collect"
        },
        {
          "level": 3,
          "title": "`buildchain collect`",
          "anchor": "buildchain-collect"
        },
        {
          "level": 3,
          "title": "`buildchain collect github-release`",
          "anchor": "buildchain-collect-github-release"
        },
        {
          "level": 2,
          "title": "`create`",
          "anchor": "create"
        },
        {
          "level": 3,
          "title": "`buildchain create`",
          "anchor": "buildchain-create"
        },
        {
          "level": 3,
          "title": "`buildchain create github-artifact-attestation-policy`",
          "anchor": "buildchain-create-github-artifact-attestation-policy"
        },
        {
          "level": 3,
          "title": "`buildchain create publication-admission`",
          "anchor": "buildchain-create-publication-admission"
        },
        {
          "level": 3,
          "title": "`buildchain create runner-provenance`",
          "anchor": "buildchain-create-runner-provenance"
        },
        {
          "level": 2,
          "title": "`dev`",
          "anchor": "dev"
        },
        {
          "level": 3,
          "title": "`buildchain dev`",
          "anchor": "buildchain-dev"
        },
        {
          "level": 3,
          "title": "`buildchain dev merge-queue`",
          "anchor": "buildchain-dev-merge-queue"
        },
        {
          "level": 3,
          "title": "`buildchain dev pr-admit`",
          "anchor": "buildchain-dev-pr-admit"
        },
        {
          "level": 3,
          "title": "`buildchain dev proof classify`",
          "anchor": "buildchain-dev-proof-classify"
        },
        {
          "level": 3,
          "title": "`buildchain dev proof integration`",
          "anchor": "buildchain-dev-proof-integration"
        },
        {
          "level": 3,
          "title": "`buildchain dev proof replay`",
          "anchor": "buildchain-dev-proof-replay"
        },
        {
          "level": 3,
          "title": "`buildchain dev proof source`",
          "anchor": "buildchain-dev-proof-source"
        },
        {
          "level": 3,
          "title": "`buildchain dev proof verify-integration`",
          "anchor": "buildchain-dev-proof-verify-integration"
        },
        {
          "level": 3,
          "title": "`buildchain dev proof verify-source`",
          "anchor": "buildchain-dev-proof-verify-source"
        },
        {
          "level": 3,
          "title": "`buildchain dev warrant cancel-queued`",
          "anchor": "buildchain-dev-warrant-cancel-queued"
        },
        {
          "level": 3,
          "title": "`buildchain dev warrant close`",
          "anchor": "buildchain-dev-warrant-close"
        },
        {
          "level": 3,
          "title": "`buildchain dev warrant heartbeat`",
          "anchor": "buildchain-dev-warrant-heartbeat"
        },
        {
          "level": 3,
          "title": "`buildchain dev warrant observe`",
          "anchor": "buildchain-dev-warrant-observe"
        },
        {
          "level": 3,
          "title": "`buildchain dev warrant recover`",
          "anchor": "buildchain-dev-warrant-recover"
        },
        {
          "level": 3,
          "title": "`buildchain dev warrant select`",
          "anchor": "buildchain-dev-warrant-select"
        },
        {
          "level": 3,
          "title": "`buildchain dev warrant submit`",
          "anchor": "buildchain-dev-warrant-submit"
        },
        {
          "level": 2,
          "title": "`diagnostics`",
          "anchor": "diagnostics"
        },
        {
          "level": 3,
          "title": "`buildchain diagnostics`",
          "anchor": "buildchain-diagnostics"
        },
        {
          "level": 3,
          "title": "`buildchain diagnostics summary`",
          "anchor": "buildchain-diagnostics-summary"
        },
        {
          "level": 2,
          "title": "`doctor`",
          "anchor": "doctor"
        },
        {
          "level": 3,
          "title": "`buildchain doctor`",
          "anchor": "buildchain-doctor"
        },
        {
          "level": 2,
          "title": "`explain`",
          "anchor": "explain"
        },
        {
          "level": 3,
          "title": "`buildchain explain`",
          "anchor": "buildchain-explain"
        },
        {
          "level": 3,
          "title": "`buildchain explain artifact`",
          "anchor": "buildchain-explain-artifact"
        },
        {
          "level": 3,
          "title": "`buildchain explain release`",
          "anchor": "buildchain-explain-release"
        },
        {
          "level": 2,
          "title": "`facts`",
          "anchor": "facts"
        },
        {
          "level": 3,
          "title": "`buildchain facts`",
          "anchor": "buildchain-facts"
        },
        {
          "level": 3,
          "title": "`buildchain facts aggregate`",
          "anchor": "buildchain-facts-aggregate"
        },
        {
          "level": 3,
          "title": "`buildchain facts module`",
          "anchor": "buildchain-facts-module"
        },
        {
          "level": 3,
          "title": "`buildchain facts verify`",
          "anchor": "buildchain-facts-verify"
        },
        {
          "level": 2,
          "title": "`github-governance`",
          "anchor": "github-governance"
        },
        {
          "level": 3,
          "title": "`buildchain github-governance`",
          "anchor": "buildchain-github-governance"
        },
        {
          "level": 3,
          "title": "`buildchain github-governance apply`",
          "anchor": "buildchain-github-governance-apply"
        },
        {
          "level": 3,
          "title": "`buildchain github-governance plan`",
          "anchor": "buildchain-github-governance-plan"
        },
        {
          "level": 3,
          "title": "`buildchain github-governance protection-policy-plan`",
          "anchor": "buildchain-github-governance-protection-policy-plan"
        },
        {
          "level": 3,
          "title": "`buildchain github-governance rollback`",
          "anchor": "buildchain-github-governance-rollback"
        },
        {
          "level": 3,
          "title": "`buildchain github-governance ruleset-policy-plan`",
          "anchor": "buildchain-github-governance-ruleset-policy-plan"
        },
        {
          "level": 2,
          "title": "`help`",
          "anchor": "help"
        },
        {
          "level": 3,
          "title": "`buildchain help`",
          "anchor": "buildchain-help"
        },
        {
          "level": 2,
          "title": "`homebrew`",
          "anchor": "homebrew"
        },
        {
          "level": 3,
          "title": "`buildchain homebrew`",
          "anchor": "buildchain-homebrew"
        },
        {
          "level": 3,
          "title": "`buildchain homebrew check`",
          "anchor": "buildchain-homebrew-check"
        },
        {
          "level": 3,
          "title": "`buildchain homebrew update-formula`",
          "anchor": "buildchain-homebrew-update-formula"
        },
        {
          "level": 2,
          "title": "`infra-contract`",
          "anchor": "infra-contract"
        },
        {
          "level": 3,
          "title": "`buildchain infra-contract`",
          "anchor": "buildchain-infra-contract"
        },
        {
          "level": 2,
          "title": "`init`",
          "anchor": "init"
        },
        {
          "level": 3,
          "title": "`buildchain init`",
          "anchor": "buildchain-init"
        },
        {
          "level": 2,
          "title": "`inspect`",
          "anchor": "inspect"
        },
        {
          "level": 3,
          "title": "`buildchain inspect`",
          "anchor": "buildchain-inspect"
        },
        {
          "level": 3,
          "title": "`buildchain inspect artifact`",
          "anchor": "buildchain-inspect-artifact"
        },
        {
          "level": 3,
          "title": "`buildchain inspect release`",
          "anchor": "buildchain-inspect-release"
        },
        {
          "level": 2,
          "title": "`kfd`",
          "anchor": "kfd"
        },
        {
          "level": 3,
          "title": "`buildchain kfd`",
          "anchor": "buildchain-kfd"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 1 gate`",
          "anchor": "buildchain-kfd-1-gate"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 1 schema`",
          "anchor": "buildchain-kfd-1-schema"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 1 verify`",
          "anchor": "buildchain-kfd-1-verify"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 1 witness`",
          "anchor": "buildchain-kfd-1-witness"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 2 claims`",
          "anchor": "buildchain-kfd-2-claims"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 2 product-claims check`",
          "anchor": "buildchain-kfd-2-product-claims-check"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 2 product-claims render`",
          "anchor": "buildchain-kfd-2-product-claims-render"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 2 product-claims write`",
          "anchor": "buildchain-kfd-2-product-claims-write"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 2 schema`",
          "anchor": "buildchain-kfd-2-schema"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 2 taxonomy`",
          "anchor": "buildchain-kfd-2-taxonomy"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 2 trust-assessment`",
          "anchor": "buildchain-kfd-2-trust-assessment"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 2 trust-claims`",
          "anchor": "buildchain-kfd-2-trust-claims"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 3`",
          "anchor": "buildchain-kfd-3"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 3 audit`",
          "anchor": "buildchain-kfd-3-audit"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 3 detect`",
          "anchor": "buildchain-kfd-3-detect"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 3 query`",
          "anchor": "buildchain-kfd-3-query"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 3 register binary`",
          "anchor": "buildchain-kfd-3-register-binary"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 3 register cli`",
          "anchor": "buildchain-kfd-3-register-cli"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 3 register documentation`",
          "anchor": "buildchain-kfd-3-register-documentation"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 3 register node-api`",
          "anchor": "buildchain-kfd-3-register-node-api"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 3 register python-api`",
          "anchor": "buildchain-kfd-3-register-python-api"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 3 register site-bundle`",
          "anchor": "buildchain-kfd-3-register-site-bundle"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 3 witness`",
          "anchor": "buildchain-kfd-3-witness"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 4 gate`",
          "anchor": "buildchain-kfd-4-gate"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 4 schema`",
          "anchor": "buildchain-kfd-4-schema"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 4 verify`",
          "anchor": "buildchain-kfd-4-verify"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 5 gate`",
          "anchor": "buildchain-kfd-5-gate"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 5 schema`",
          "anchor": "buildchain-kfd-5-schema"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 5 verify`",
          "anchor": "buildchain-kfd-5-verify"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 7 gate`",
          "anchor": "buildchain-kfd-7-gate"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 7 schema`",
          "anchor": "buildchain-kfd-7-schema"
        },
        {
          "level": 3,
          "title": "`buildchain kfd 7 verify`",
          "anchor": "buildchain-kfd-7-verify"
        },
        {
          "level": 3,
          "title": "`buildchain kfd aggregate`",
          "anchor": "buildchain-kfd-aggregate"
        },
        {
          "level": 3,
          "title": "`buildchain kfd hub explain`",
          "anchor": "buildchain-kfd-hub-explain"
        },
        {
          "level": 3,
          "title": "`buildchain kfd hub init`",
          "anchor": "buildchain-kfd-hub-init"
        },
        {
          "level": 3,
          "title": "`buildchain kfd hub inspect`",
          "anchor": "buildchain-kfd-hub-inspect"
        },
        {
          "level": 3,
          "title": "`buildchain kfd hub test`",
          "anchor": "buildchain-kfd-hub-test"
        },
        {
          "level": 3,
          "title": "`buildchain kfd migrate-layout`",
          "anchor": "buildchain-kfd-migrate-layout"
        },
        {
          "level": 3,
          "title": "`buildchain kfd schema list`",
          "anchor": "buildchain-kfd-schema-list"
        },
        {
          "level": 3,
          "title": "`buildchain kfd schema show kfd-1`",
          "anchor": "buildchain-kfd-schema-show-kfd-1"
        },
        {
          "level": 3,
          "title": "`buildchain kfd schema show kfd-2`",
          "anchor": "buildchain-kfd-schema-show-kfd-2"
        },
        {
          "level": 3,
          "title": "`buildchain kfd schema show kfd-3`",
          "anchor": "buildchain-kfd-schema-show-kfd-3"
        },
        {
          "level": 3,
          "title": "`buildchain kfd schema show kfd-4`",
          "anchor": "buildchain-kfd-schema-show-kfd-4"
        },
        {
          "level": 3,
          "title": "`buildchain kfd status`",
          "anchor": "buildchain-kfd-status"
        },
        {
          "level": 3,
          "title": "`buildchain kfd support project`",
          "anchor": "buildchain-kfd-support-project"
        },
        {
          "level": 3,
          "title": "`buildchain kfd support verify`",
          "anchor": "buildchain-kfd-support-verify"
        },
        {
          "level": 3,
          "title": "`buildchain kfd upstream check`",
          "anchor": "buildchain-kfd-upstream-check"
        },
        {
          "level": 3,
          "title": "`buildchain kfd upstream collect`",
          "anchor": "buildchain-kfd-upstream-collect"
        },
        {
          "level": 3,
          "title": "`buildchain kfd upstream roles`",
          "anchor": "buildchain-kfd-upstream-roles"
        },
        {
          "level": 2,
          "title": "`layout`",
          "anchor": "layout"
        },
        {
          "level": 3,
          "title": "`buildchain layout`",
          "anchor": "buildchain-layout"
        },
        {
          "level": 2,
          "title": "`lifecycle`",
          "anchor": "lifecycle"
        },
        {
          "level": 3,
          "title": "`buildchain lifecycle`",
          "anchor": "buildchain-lifecycle"
        },
        {
          "level": 3,
          "title": "`buildchain lifecycle run`",
          "anchor": "buildchain-lifecycle-run"
        },
        {
          "level": 2,
          "title": "`log`",
          "anchor": "log"
        },
        {
          "level": 3,
          "title": "`buildchain log`",
          "anchor": "buildchain-log"
        },
        {
          "level": 3,
          "title": "`buildchain log error`",
          "anchor": "buildchain-log-error"
        },
        {
          "level": 3,
          "title": "`buildchain log info`",
          "anchor": "buildchain-log-info"
        },
        {
          "level": 3,
          "title": "`buildchain log summary`",
          "anchor": "buildchain-log-summary"
        },
        {
          "level": 3,
          "title": "`buildchain log warn`",
          "anchor": "buildchain-log-warn"
        },
        {
          "level": 2,
          "title": "`mark`",
          "anchor": "mark"
        },
        {
          "level": 3,
          "title": "`buildchain mark`",
          "anchor": "buildchain-mark"
        },
        {
          "level": 2,
          "title": "`npm`",
          "anchor": "npm"
        },
        {
          "level": 3,
          "title": "`buildchain npm`",
          "anchor": "buildchain-npm"
        },
        {
          "level": 3,
          "title": "`buildchain npm dry-run`",
          "anchor": "buildchain-npm-dry-run"
        },
        {
          "level": 2,
          "title": "`paper`",
          "anchor": "paper"
        },
        {
          "level": 3,
          "title": "`buildchain paper`",
          "anchor": "buildchain-paper"
        },
        {
          "level": 3,
          "title": "`buildchain paper agent verify`",
          "anchor": "buildchain-paper-agent-verify"
        },
        {
          "level": 3,
          "title": "`buildchain paper alpha`",
          "anchor": "buildchain-paper-alpha"
        },
        {
          "level": 3,
          "title": "`buildchain paper bootstrap npm`",
          "anchor": "buildchain-paper-bootstrap-npm"
        },
        {
          "level": 3,
          "title": "`buildchain paper build`",
          "anchor": "buildchain-paper-build"
        },
        {
          "level": 3,
          "title": "`buildchain paper fleet audit`",
          "anchor": "buildchain-paper-fleet-audit"
        },
        {
          "level": 3,
          "title": "`buildchain paper fleet update`",
          "anchor": "buildchain-paper-fleet-update"
        },
        {
          "level": 3,
          "title": "`buildchain paper migrate`",
          "anchor": "buildchain-paper-migrate"
        },
        {
          "level": 3,
          "title": "`buildchain paper preflight`",
          "anchor": "buildchain-paper-preflight"
        },
        {
          "level": 3,
          "title": "`buildchain paper resume`",
          "anchor": "buildchain-paper-resume"
        },
        {
          "level": 3,
          "title": "`buildchain paper scaffold`",
          "anchor": "buildchain-paper-scaffold"
        },
        {
          "level": 3,
          "title": "`buildchain paper status`",
          "anchor": "buildchain-paper-status"
        },
        {
          "level": 3,
          "title": "`buildchain paper work start`",
          "anchor": "buildchain-paper-work-start"
        },
        {
          "level": 3,
          "title": "`buildchain paper work submit`",
          "anchor": "buildchain-paper-work-submit"
        },
        {
          "level": 2,
          "title": "`portable-cache`",
          "anchor": "portable-cache"
        },
        {
          "level": 3,
          "title": "`buildchain portable-cache`",
          "anchor": "buildchain-portable-cache"
        },
        {
          "level": 3,
          "title": "`buildchain portable-cache plan`",
          "anchor": "buildchain-portable-cache-plan"
        },
        {
          "level": 3,
          "title": "`buildchain portable-cache receipt`",
          "anchor": "buildchain-portable-cache-receipt"
        },
        {
          "level": 2,
          "title": "`project`",
          "anchor": "project"
        },
        {
          "level": 3,
          "title": "`buildchain project`",
          "anchor": "buildchain-project"
        },
        {
          "level": 3,
          "title": "`buildchain project kfx-admission`",
          "anchor": "buildchain-project-kfx-admission"
        },
        {
          "level": 2,
          "title": "`publication-artifact`",
          "anchor": "publication-artifact"
        },
        {
          "level": 3,
          "title": "`buildchain publication-artifact`",
          "anchor": "buildchain-publication-artifact"
        },
        {
          "level": 3,
          "title": "`buildchain publication-artifact manifest`",
          "anchor": "buildchain-publication-artifact-manifest"
        },
        {
          "level": 3,
          "title": "`buildchain publication-artifact npm-package`",
          "anchor": "buildchain-publication-artifact-npm-package"
        },
        {
          "level": 3,
          "title": "`buildchain publication-artifact reproducibility`",
          "anchor": "buildchain-publication-artifact-reproducibility"
        },
        {
          "level": 2,
          "title": "`publish-source`",
          "anchor": "publish-source"
        },
        {
          "level": 3,
          "title": "`buildchain publish-source`",
          "anchor": "buildchain-publish-source"
        },
        {
          "level": 3,
          "title": "`buildchain publish-source lock`",
          "anchor": "buildchain-publish-source-lock"
        },
        {
          "level": 3,
          "title": "`buildchain publish-source manifest`",
          "anchor": "buildchain-publish-source-manifest"
        },
        {
          "level": 3,
          "title": "`buildchain publish-source validate-anchored-release`",
          "anchor": "buildchain-publish-source-validate-anchored-release"
        },
        {
          "level": 3,
          "title": "`buildchain publish-source verify-channel-ref`",
          "anchor": "buildchain-publish-source-verify-channel-ref"
        },
        {
          "level": 3,
          "title": "`buildchain publish-source verify-lock`",
          "anchor": "buildchain-publish-source-verify-lock"
        },
        {
          "level": 2,
          "title": "`release`",
          "anchor": "release"
        },
        {
          "level": 3,
          "title": "`buildchain release`",
          "anchor": "buildchain-release"
        },
        {
          "level": 3,
          "title": "`buildchain release --dry-run`",
          "anchor": "buildchain-release-dry-run"
        },
        {
          "level": 3,
          "title": "`buildchain release abort`",
          "anchor": "buildchain-release-abort"
        },
        {
          "level": 3,
          "title": "`buildchain release dry-run`",
          "anchor": "buildchain-release-dry-run"
        },
        {
          "level": 3,
          "title": "`buildchain release explain`",
          "anchor": "buildchain-release-explain"
        },
        {
          "level": 3,
          "title": "`buildchain release finalize`",
          "anchor": "buildchain-release-finalize"
        },
        {
          "level": 3,
          "title": "`buildchain release inspect`",
          "anchor": "buildchain-release-inspect"
        },
        {
          "level": 3,
          "title": "`buildchain release line open`",
          "anchor": "buildchain-release-line-open"
        },
        {
          "level": 3,
          "title": "`buildchain release recover`",
          "anchor": "buildchain-release-recover"
        },
        {
          "level": 2,
          "title": "`release-governance`",
          "anchor": "release-governance"
        },
        {
          "level": 3,
          "title": "`buildchain release-governance`",
          "anchor": "buildchain-release-governance"
        },
        {
          "level": 3,
          "title": "`buildchain release-governance reconcile`",
          "anchor": "buildchain-release-governance-reconcile"
        },
        {
          "level": 2,
          "title": "`release-propagation`",
          "anchor": "release-propagation"
        },
        {
          "level": 3,
          "title": "`buildchain release-propagation`",
          "anchor": "buildchain-release-propagation"
        },
        {
          "level": 3,
          "title": "`buildchain release-propagation entry`",
          "anchor": "buildchain-release-propagation-entry"
        },
        {
          "level": 3,
          "title": "`buildchain release-propagation pickup`",
          "anchor": "buildchain-release-propagation-pickup"
        },
        {
          "level": 3,
          "title": "`buildchain release-propagation plan`",
          "anchor": "buildchain-release-propagation-plan"
        },
        {
          "level": 3,
          "title": "`buildchain release-propagation work`",
          "anchor": "buildchain-release-propagation-work"
        },
        {
          "level": 3,
          "title": "`buildchain release-propagation write-lock`",
          "anchor": "buildchain-release-propagation-write-lock"
        },
        {
          "level": 2,
          "title": "`release-tail`",
          "anchor": "release-tail"
        },
        {
          "level": 3,
          "title": "`buildchain release-tail`",
          "anchor": "buildchain-release-tail"
        },
        {
          "level": 3,
          "title": "`buildchain release-tail compat`",
          "anchor": "buildchain-release-tail-compat"
        },
        {
          "level": 3,
          "title": "`buildchain release-tail init`",
          "anchor": "buildchain-release-tail-init"
        },
        {
          "level": 3,
          "title": "`buildchain release-tail plan`",
          "anchor": "buildchain-release-tail-plan"
        },
        {
          "level": 3,
          "title": "`buildchain release-tail status`",
          "anchor": "buildchain-release-tail-status"
        },
        {
          "level": 3,
          "title": "`buildchain release-tail verify`",
          "anchor": "buildchain-release-tail-verify"
        },
        {
          "level": 2,
          "title": "`sample`",
          "anchor": "sample"
        },
        {
          "level": 3,
          "title": "`buildchain sample`",
          "anchor": "buildchain-sample"
        },
        {
          "level": 3,
          "title": "`buildchain sample process-tree`",
          "anchor": "buildchain-sample-process-tree"
        },
        {
          "level": 2,
          "title": "`span`",
          "anchor": "span"
        },
        {
          "level": 3,
          "title": "`buildchain span`",
          "anchor": "buildchain-span"
        },
        {
          "level": 2,
          "title": "`transaction`",
          "anchor": "transaction"
        },
        {
          "level": 3,
          "title": "`buildchain transaction`",
          "anchor": "buildchain-transaction"
        },
        {
          "level": 3,
          "title": "`buildchain transaction inspect`",
          "anchor": "buildchain-transaction-inspect"
        },
        {
          "level": 2,
          "title": "`validate`",
          "anchor": "validate"
        },
        {
          "level": 3,
          "title": "`buildchain validate`",
          "anchor": "buildchain-validate"
        },
        {
          "level": 2,
          "title": "`verify`",
          "anchor": "verify"
        },
        {
          "level": 3,
          "title": "`buildchain verify`",
          "anchor": "buildchain-verify"
        },
        {
          "level": 3,
          "title": "`buildchain verify artifact dir`",
          "anchor": "buildchain-verify-artifact-dir"
        },
        {
          "level": 3,
          "title": "`buildchain verify artifact file`",
          "anchor": "buildchain-verify-artifact-file"
        },
        {
          "level": 3,
          "title": "`buildchain verify artifact github-release:...`",
          "anchor": "buildchain-verify-artifact-github-release"
        },
        {
          "level": 3,
          "title": "`buildchain verify artifact npm:...`",
          "anchor": "buildchain-verify-artifact-npm"
        },
        {
          "level": 3,
          "title": "`buildchain verify artifact oci:...`",
          "anchor": "buildchain-verify-artifact-oci"
        },
        {
          "level": 3,
          "title": "`buildchain verify artifact url`",
          "anchor": "buildchain-verify-artifact-url"
        },
        {
          "level": 3,
          "title": "`buildchain verify artifact-envelope`",
          "anchor": "buildchain-verify-artifact-envelope"
        },
        {
          "level": 3,
          "title": "`buildchain verify github-artifact-attestation`",
          "anchor": "buildchain-verify-github-artifact-attestation"
        },
        {
          "level": 3,
          "title": "`buildchain verify infra-contract-evidence-bundle`",
          "anchor": "buildchain-verify-infra-contract-evidence-bundle"
        },
        {
          "level": 3,
          "title": "`buildchain verify observability-log`",
          "anchor": "buildchain-verify-observability-log"
        },
        {
          "level": 3,
          "title": "`buildchain verify publication-admission`",
          "anchor": "buildchain-verify-publication-admission"
        },
        {
          "level": 3,
          "title": "`buildchain verify release-passport`",
          "anchor": "buildchain-verify-release-passport"
        },
        {
          "level": 2,
          "title": "`version`",
          "anchor": "version"
        },
        {
          "level": 3,
          "title": "`buildchain version`",
          "anchor": "buildchain-version"
        },
        {
          "level": 2,
          "title": "`web-surface`",
          "anchor": "web-surface"
        },
        {
          "level": 3,
          "title": "`buildchain web-surface`",
          "anchor": "buildchain-web-surface"
        }
      ],
      "markdown": "---\nstatus: active\nperiod: ongoing\ntheme: buildchain-generated-reference\ndoc_type: technical-reference\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: generated\nlast_reviewed: 2026-08-01\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-08-01\n  invisible_context: not asserted\n---\n\n# Buildchain CLI Reference\n\n> Generated from `BUILDCHAIN_USAGE` and the runtime command registry. Do not edit this file by hand.\n\nEvery listed help command is intercepted before dispatch, exits zero, and performs no command side effects.\n\n## `architecture`\n\n### `buildchain architecture`\n\n- Help: `buildchain architecture --help`\n- Canonical id: `architecture`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain architecture\n```\n\n### `buildchain architecture list`\n\n- Help: `buildchain architecture list --help`\n- Canonical id: `architecture`\n- Options: `--cwd`, `--json`\n- Syntax:\n\n```text\nbuildchain architecture list [--cwd <dir>] [--json]\n```\n\n### `buildchain architecture qualify`\n\n- Help: `buildchain architecture qualify --help`\n- Canonical id: `architecture`\n- Options: `--authority-revision`, `--candidate-revision`, `--cwd`, `--json`\n- Syntax:\n\n```text\nbuildchain architecture qualify --authority-revision <git-revision> [--candidate-revision <git-revision>] [--cwd <dir>] [--json]\n```\n\n### `buildchain architecture show`\n\n- Help: `buildchain architecture show --help`\n- Canonical id: `architecture`\n- Options: `--cwd`, `--json`\n- Syntax:\n\n```text\nbuildchain architecture show <capability-id> [--cwd <dir>] [--json]\n```\n\n### `buildchain architecture validate`\n\n- Help: `buildchain architecture validate --help`\n- Canonical id: `architecture`\n- Options: `--cwd`, `--json`\n- Syntax:\n\n```text\nbuildchain architecture validate [--cwd <dir>] [--json]\n```\n\n## `audit`\n\n### `buildchain audit`\n\n- Help: `buildchain audit --help`\n- Canonical id: `audit`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain audit\n```\n\n### `buildchain audit github-governance`\n\n- Help: `buildchain audit github-governance --help`\n- Canonical id: `audit`\n- Options: `--allow-nonqualifying`, `--environment`, `--job`, `--json`, `--npm-trust-json`, `--organization`, `--output`, `--package`, `--provider-audit-json`, `--publisher-mode`, `--repository`, `--require-qualifying`, `--source-sha`, `--workflow`, `--workflow-ref`, `--workflow-repository`\n- Syntax:\n\n```text\nbuildchain audit github-governance [--organization <owner>] [--repository <owner/repo>] [--output <file>] [--require-qualifying] [--json] [--source-sha <merged-branch-sha>] [--workflow-repository <owner/repo>] [--workflow <path>] [--workflow-ref <sha-or-ref>] [--job <id>] [--environment <name>] [--package <name>] [--publisher-mode npm-trusted-publisher|github-token|oidc-role] [--npm-trust-json <file-or-json>] [--provider-audit-json <file>] [--output <file>] [--allow-nonqualifying]\n```\n\n### `buildchain audit publication-control-plane`\n\n- Help: `buildchain audit publication-control-plane --help`\n- Canonical id: `audit`\n- Options: `--branch`, `--repository`\n- Syntax:\n\n```text\nbuildchain audit publication-control-plane --repository <owner/repo> --branch <protected-branch>\n```\n\n## `badges`\n\n### `buildchain badges`\n\n- Help: `buildchain badges --help`\n- Canonical id: `badges`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain badges\n```\n\n### `buildchain badges bundle`\n\n- Help: `buildchain badges bundle --help`\n- Canonical id: `badges-bundle`\n- Options: `--check`, `--claims`, `--cwd`, `--json`, `--readme`, `--write`\n- Syntax:\n\n```text\nbuildchain badges bundle [--cwd <dir>] [--readme <path>] [--claims <csv>] [--check] [--write] [--json]\n```\n\n### `buildchain badges readme`\n\n- Help: `buildchain badges readme --help`\n- Canonical id: `badges-readme`\n- Options: `--check`, `--cwd`, `--json`, `--readme`, `--write`\n- Syntax:\n\n```text\nbuildchain badges readme [--cwd <dir>] [--readme <path>] [--check] [--write] [--json]\n```\n\n## `build-contract`\n\n### `buildchain build-contract`\n\n- Help: `buildchain build-contract --help`\n- Canonical id: `build-contract`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain build-contract ...\n```\n\n## `candidate`\n\n### `buildchain candidate`\n\n- Help: `buildchain candidate --help`\n- Canonical id: `candidate`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain candidate\n```\n\n### `buildchain candidate timeline`\n\n- Help: `buildchain candidate timeline --help`\n- Canonical id: `candidate`\n- Options: `--input`, `--json`, `--output`\n- Syntax:\n\n```text\nbuildchain candidate timeline --input <file-or-json> [--output <file>] [--json]\n```\n\n## `collect`\n\n### `buildchain collect`\n\n- Help: `buildchain collect --help`\n- Canonical id: `collect`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain collect\n```\n\n### `buildchain collect github-release`\n\n- Help: `buildchain collect github-release --help`\n- Canonical id: `collect-github-release`\n- Options: `--anchor-manifest-json`, `--assets-dir`, `--assets-json`, `--base-passport-json`, `--build-facts-json`, `--build-summary-json`, `--dist-tag-evidence-json`, `--github-artifact-attestation-policy-json`, `--impact-json`, `--invariant-passport-cmd`, `--invariant-passport-json`, `--json`, `--kfd-1-witness-json`, `--kfd-2-claim-json`, `--kfd-3-artifact-verify-cmd`, `--kfd-3-artifact-witness-json`, `--kfd-3-prebuild-witness-json`, `--kfd-adopter-manifest-json`, `--kfd-agent-hub-evidence-json`, `--kfd-product-gate-json`, `--kfd-support-matrix-json`, `--output-dir`, `--package-set-json`, `--platform-manifest-json`, `--product-name`, `--publish-evidence-json`, `--publish-json`, `--release-evidence-json`, `--release-extra-json`, `--release-json`, `--repository`, `--require-base-kfd`, `--tag`, `--transaction-json`, `--trusted-publishing-json`\n- Syntax:\n\n```text\nbuildchain collect github-release --tag <tag> [--repository <owner/repo>] [--assets-dir <dir>] [--assets-json <json-or-path>] [--release-json <json-or-path>] [--package-set-json <json-or-path>] [--product-name <name>] [--publish-evidence-json <json-or-path>] [--trusted-publishing-json <json-or-path>] [--transaction-json <json-or-path>] [--anchor-manifest-json <json-or-path>] [--impact-json <json-or-path>] [--build-summary-json <json-or-path>] [--build-facts-json <json-or-path>]... [--platform-manifest-json <json-or-path>]... [--dist-tag-evidence-json <json-or-path>] [--kfd-1-witness-json <json-or-path>]... [--kfd-2-claim-json <json-or-path>]... [--kfd-3-prebuild-witness-json <json-or-path>]... [--kfd-3-artifact-witness-json <json-or-path>]... [--kfd-3-artifact-verify-cmd <command>] [--kfd-adopter-manifest-json <json-or-path>] [--kfd-support-matrix-json <json-or-path>] [--kfd-product-gate-json <json-or-path>]... [--invariant-passport-json <json-or-path>]... [--invariant-passport-cmd <command>] [--release-evidence-json <json-or-path>]... [--github-artifact-attestation-policy-json <json-or-path>]... [--kfd-agent-hub-evidence-json <json-or-path>] [--base-passport-json <json-or-path>] [--require-base-kfd] [--release-extra-json <json-or-path>] [--publish-json <json-or-path>] [--output-dir <dir>] [--json]\n```\n\n## `create`\n\n### `buildchain create`\n\n- Help: `buildchain create --help`\n- Canonical id: `create`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain create\n```\n\n### `buildchain create github-artifact-attestation-policy`\n\n- Help: `buildchain create github-artifact-attestation-policy --help`\n- Canonical id: `create`\n- Options: `--input-json`, `--json`, `--output`\n- Syntax:\n\n```text\nbuildchain create github-artifact-attestation-policy --input-json <file-or-json> [--output <file>] [--json]\n```\n\n### `buildchain create publication-admission`\n\n- Help: `buildchain create publication-admission --help`\n- Canonical id: `create`\n- Options: `--input-json`, `--json`, `--output`\n- Syntax:\n\n```text\nbuildchain create publication-admission --input-json <file-or-json> [--output <file>] [--json]\n```\n\n### `buildchain create runner-provenance`\n\n- Help: `buildchain create runner-provenance --help`\n- Canonical id: `create`\n- Options: `--input-json`, `--json`, `--output`\n- Syntax:\n\n```text\nbuildchain create runner-provenance --input-json <file-or-json> [--output <file>] [--json]\n```\n\n## `dev`\n\n### `buildchain dev`\n\n- Help: `buildchain dev --help`\n- Canonical id: `dev`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain dev\n```\n\n### `buildchain dev merge-queue`\n\n- Help: `buildchain dev merge-queue --help`\n- Canonical id: `dev`\n- Options: `--apply`, `--branch`, `--check-response-timeout-minutes`, `--cwd`, `--from-config`, `--max-entries-to-build`, `--repository`, `--workflow`\n- Syntax:\n\n```text\nbuildchain dev merge-queue --repository <owner/repo> --branch <dev/vN/vN.M> [--from-config | --workflow <required-workflow.yml>...] [--cwd <dir>] [--check-response-timeout-minutes <n>] [--max-entries-to-build <n>] [--apply]\n```\n\n### `buildchain dev pr-admit`\n\n- Help: `buildchain dev pr-admit --help`\n- Canonical id: `dev`\n- Options: `--branch`, `--execute`, `--expected-head`, `--json`, `--output`, `--pull-request`, `--repository`\n- Syntax:\n\n```text\nbuildchain dev pr-admit --repository <owner/repo> --branch <dev/vN/vN.M> --pull-request <n> --expected-head <sha> [--execute] [--output <file>] [--json]\n```\n\n### `buildchain dev proof classify`\n\n- Help: `buildchain dev proof classify --help`\n- Canonical id: `dev`\n- Options: `--json`, `--output`\n- Syntax:\n\n```text\nbuildchain dev proof <source|verify-source|classify|replay|integration|verify-integration> [--output <file>] [--json]\n```\n\n### `buildchain dev proof integration`\n\n- Help: `buildchain dev proof integration --help`\n- Canonical id: `dev`\n- Options: `--json`, `--output`\n- Syntax:\n\n```text\nbuildchain dev proof <source|verify-source|classify|replay|integration|verify-integration> [--output <file>] [--json]\n```\n\n### `buildchain dev proof replay`\n\n- Help: `buildchain dev proof replay --help`\n- Canonical id: `dev`\n- Options: `--json`, `--output`\n- Syntax:\n\n```text\nbuildchain dev proof <source|verify-source|classify|replay|integration|verify-integration> [--output <file>] [--json]\n```\n\n### `buildchain dev proof source`\n\n- Help: `buildchain dev proof source --help`\n- Canonical id: `dev`\n- Options: `--json`, `--output`\n- Syntax:\n\n```text\nbuildchain dev proof <source|verify-source|classify|replay|integration|verify-integration> [--output <file>] [--json]\n```\n\n### `buildchain dev proof verify-integration`\n\n- Help: `buildchain dev proof verify-integration --help`\n- Canonical id: `dev`\n- Options: `--json`, `--output`\n- Syntax:\n\n```text\nbuildchain dev proof <source|verify-source|classify|replay|integration|verify-integration> [--output <file>] [--json]\n```\n\n### `buildchain dev proof verify-source`\n\n- Help: `buildchain dev proof verify-source --help`\n- Canonical id: `dev`\n- Options: `--json`, `--output`\n- Syntax:\n\n```text\nbuildchain dev proof <source|verify-source|classify|replay|integration|verify-integration> [--output <file>] [--json]\n```\n\n### `buildchain dev warrant cancel-queued`\n\n- Help: `buildchain dev warrant cancel-queued --help`\n- Canonical id: `dev`\n- Options: `--branch`, `--execute`, `--json`, `--output`, `--repository`\n- Syntax:\n\n```text\nbuildchain dev warrant <submit|select|heartbeat|recover|close|cancel-queued|observe> --repository <owner/repo> --branch <dev/vN/vN.M> [--execute] [--output <file>] [--json]\n```\n\n### `buildchain dev warrant close`\n\n- Help: `buildchain dev warrant close --help`\n- Canonical id: `dev`\n- Options: `--branch`, `--execute`, `--json`, `--output`, `--repository`\n- Syntax:\n\n```text\nbuildchain dev warrant <submit|select|heartbeat|recover|close|cancel-queued|observe> --repository <owner/repo> --branch <dev/vN/vN.M> [--execute] [--output <file>] [--json]\n```\n\n### `buildchain dev warrant heartbeat`\n\n- Help: `buildchain dev warrant heartbeat --help`\n- Canonical id: `dev`\n- Options: `--branch`, `--execute`, `--json`, `--output`, `--repository`\n- Syntax:\n\n```text\nbuildchain dev warrant <submit|select|heartbeat|recover|close|cancel-queued|observe> --repository <owner/repo> --branch <dev/vN/vN.M> [--execute] [--output <file>] [--json]\n```\n\n### `buildchain dev warrant observe`\n\n- Help: `buildchain dev warrant observe --help`\n- Canonical id: `dev`\n- Options: `--branch`, `--execute`, `--json`, `--output`, `--repository`\n- Syntax:\n\n```text\nbuildchain dev warrant <submit|select|heartbeat|recover|close|cancel-queued|observe> --repository <owner/repo> --branch <dev/vN/vN.M> [--execute] [--output <file>] [--json]\n```\n\n### `buildchain dev warrant recover`\n\n- Help: `buildchain dev warrant recover --help`\n- Canonical id: `dev`\n- Options: `--branch`, `--execute`, `--json`, `--output`, `--repository`\n- Syntax:\n\n```text\nbuildchain dev warrant <submit|select|heartbeat|recover|close|cancel-queued|observe> --repository <owner/repo> --branch <dev/vN/vN.M> [--execute] [--output <file>] [--json]\n```\n\n### `buildchain dev warrant select`\n\n- Help: `buildchain dev warrant select --help`\n- Canonical id: `dev`\n- Options: `--branch`, `--execute`, `--json`, `--output`, `--repository`\n- Syntax:\n\n```text\nbuildchain dev warrant <submit|select|heartbeat|recover|close|cancel-queued|observe> --repository <owner/repo> --branch <dev/vN/vN.M> [--execute] [--output <file>] [--json]\n```\n\n### `buildchain dev warrant submit`\n\n- Help: `buildchain dev warrant submit --help`\n- Canonical id: `dev`\n- Options: `--branch`, `--execute`, `--json`, `--output`, `--repository`\n- Syntax:\n\n```text\nbuildchain dev warrant <submit|select|heartbeat|recover|close|cancel-queued|observe> --repository <owner/repo> --branch <dev/vN/vN.M> [--execute] [--output <file>] [--json]\n```\n\n## `diagnostics`\n\n### `buildchain diagnostics`\n\n- Help: `buildchain diagnostics --help`\n- Canonical id: `diagnostics`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain diagnostics\n```\n\n### `buildchain diagnostics summary`\n\n- Help: `buildchain diagnostics summary --help`\n- Canonical id: `diagnostics-summary`\n- Options: `--artifact`, `--json`, `--output`\n- Syntax:\n\n```text\nbuildchain diagnostics summary <diagnostics.json>... [--artifact <file>]... [--output <file>] [--json]\n```\n\n## `doctor`\n\n### `buildchain doctor`\n\n- Help: `buildchain doctor --help`\n- Canonical id: `doctor`\n- Options: `--cwd`, `--json`, `--require-publish-source-lock`\n- Syntax:\n\n```text\nbuildchain doctor [--cwd <dir>] [--require-publish-source-lock] [--json]\n```\n\n## `explain`\n\n### `buildchain explain`\n\n- Help: `buildchain explain --help`\n- Canonical id: `explain`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain explain\n```\n\n### `buildchain explain artifact`\n\n- Help: `buildchain explain artifact --help`\n- Canonical id: `explain-artifact`\n- Options: `--for`, `--json`, `--npm-registry`, `--passport`\n- Syntax:\n\n```text\nbuildchain explain artifact <subject> [--passport <file-or-url>] [--npm-registry <url>] [--for human|agent] [--json]\n```\n\n### `buildchain explain release`\n\n- Help: `buildchain explain release --help`\n- Canonical id: `explain-release`\n- Options: `--for`, `--json`, `--passport`\n- Syntax:\n\n```text\nbuildchain explain release --passport <file-or-url> [--for human|agent] [--json]\n```\n\n## `facts`\n\n### `buildchain facts`\n\n- Help: `buildchain facts --help`\n- Canonical id: `facts`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain facts\n```\n\n### `buildchain facts aggregate`\n\n- Help: `buildchain facts aggregate --help`\n- Canonical id: `build-facts`\n- Options: `--artifact`, `--cwd`, `--json`, `--module-fact`, `--output`, `--product`\n- Syntax:\n\n```text\nbuildchain facts aggregate [--cwd <dir>] [--product <id>] [--module-fact <file>]... [--artifact <path>]... [--output <file>] [--json]\n```\n\n### `buildchain facts module`\n\n- Help: `buildchain facts module --help`\n- Canonical id: `build-facts`\n- Options: `--cwd`, `--json`, `--legacy-kungfu-buildinfo`, `--module`, `--module-root`, `--output`, `--output-path`, `--version-source`\n- Syntax:\n\n```text\nbuildchain facts module [--cwd <dir>] [--module <id>] [--module-root <path>] [--version-source <id>] [--output <file>] [--output-path <path>]... [--legacy-kungfu-buildinfo <file>] [--json]\n```\n\n### `buildchain facts verify`\n\n- Help: `buildchain facts verify --help`\n- Canonical id: `build-facts`\n- Options: `--cwd`, `--fact`, `--json`\n- Syntax:\n\n```text\nbuildchain facts verify [--cwd <dir>] --fact <file> [--json]\n```\n\n## `github-governance`\n\n### `buildchain github-governance`\n\n- Help: `buildchain github-governance --help`\n- Canonical id: `github-governance`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain github-governance\n```\n\n### `buildchain github-governance apply`\n\n- Help: `buildchain github-governance apply --help`\n- Canonical id: `github-governance`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain github-governance <plan|apply|rollback|protection-policy-plan|ruleset-policy-plan> ...\n```\n\n### `buildchain github-governance plan`\n\n- Help: `buildchain github-governance plan --help`\n- Canonical id: `github-governance`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain github-governance <plan|apply|rollback|protection-policy-plan|ruleset-policy-plan> ...\n```\n\n### `buildchain github-governance protection-policy-plan`\n\n- Help: `buildchain github-governance protection-policy-plan --help`\n- Canonical id: `github-governance`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain github-governance <plan|apply|rollback|protection-policy-plan|ruleset-policy-plan> ...\n```\n\n### `buildchain github-governance rollback`\n\n- Help: `buildchain github-governance rollback --help`\n- Canonical id: `github-governance`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain github-governance <plan|apply|rollback|protection-policy-plan|ruleset-policy-plan> ...\n```\n\n### `buildchain github-governance ruleset-policy-plan`\n\n- Help: `buildchain github-governance ruleset-policy-plan --help`\n- Canonical id: `github-governance`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain github-governance <plan|apply|rollback|protection-policy-plan|ruleset-policy-plan> ...\n```\n\n## `help`\n\n### `buildchain help`\n\n- Help: `buildchain help --help`\n- Canonical id: `help`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain help\n```\n\n## `homebrew`\n\n### `buildchain homebrew`\n\n- Help: `buildchain homebrew --help`\n- Canonical id: `homebrew`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain homebrew\n```\n\n### `buildchain homebrew check`\n\n- Help: `buildchain homebrew check --help`\n- Canonical id: `homebrew-check`\n- Options: `--cwd`, `--json`, `--package`, `--release-passport`\n- Syntax:\n\n```text\nbuildchain homebrew check [--cwd <dir>] [--package <name>] [--release-passport <file-or-url>] [--json]\n```\n\n### `buildchain homebrew update-formula`\n\n- Help: `buildchain homebrew update-formula --help`\n- Canonical id: `homebrew-update-formula`\n- Options: `--json`, `--package`, `--release-passport`, `--write`\n- Syntax:\n\n```text\nbuildchain homebrew update-formula --package <name> --release-passport <file-or-url> [--write] [--json]\n```\n\n## `infra-contract`\n\n### `buildchain infra-contract`\n\n- Help: `buildchain infra-contract --help`\n- Canonical id: `infra-contract`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain infra-contract ...\n```\n\n## `init`\n\n### `buildchain init`\n\n- Help: `buildchain init --help`\n- Canonical id: `init`\n- Options: `--artifact-name`, `--cwd`, `--force`, `--package-manager`, `--runner-preset`, `--type`\n- Syntax:\n\n```text\nbuildchain init [--cwd <dir>] [--type package|native|web-surface|infra-contract|publication-artifact|anchored-package] [--force] [--package-manager pnpm|npm|yarn] [--runner-preset <preset>] [--artifact-name <template>]\n```\n\n## `inspect`\n\n### `buildchain inspect`\n\n- Help: `buildchain inspect --help`\n- Canonical id: `inspect`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain inspect\n```\n\n### `buildchain inspect artifact`\n\n- Help: `buildchain inspect artifact --help`\n- Canonical id: `inspect-artifact`\n- Options: `--json`, `--npm-registry`, `--passport`\n- Syntax:\n\n```text\nbuildchain inspect artifact <subject> [--passport <file-or-url>] [--npm-registry <url>] [--json]\n```\n\n### `buildchain inspect release`\n\n- Help: `buildchain inspect release --help`\n- Canonical id: `inspect-release`\n- Options: `--json`, `--passport`\n- Syntax:\n\n```text\nbuildchain inspect release --passport <file-or-url> [--json]\n```\n\n## `kfd`\n\n### `buildchain kfd`\n\n- Help: `buildchain kfd --help`\n- Canonical id: `kfd`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain kfd ...\n```\n\n### `buildchain kfd 1 gate`\n\n- Help: `buildchain kfd 1 gate --help`\n- Canonical id: `kfd-1-gate`\n- Options: `--artifact-root`, `--cwd`, `--json`, `--output`, `--witness-json`\n- Syntax:\n\n```text\nbuildchain kfd 1 gate --witness-json <file-or-json>... [--cwd <dir>] [--artifact-root <dir>] [--output <file>] [--json]\n```\n\n### `buildchain kfd 1 schema`\n\n- Help: `buildchain kfd 1 schema --help`\n- Canonical id: `kfd-1-schema`\n- Options: `--json`, `--schema`\n- Syntax:\n\n```text\nbuildchain kfd 1 schema [--schema <name>] [--json]\n```\n\n### `buildchain kfd 1 verify`\n\n- Help: `buildchain kfd 1 verify --help`\n- Canonical id: `kfd-1-verify`\n- Options: `--gate-json`, `--json`\n- Syntax:\n\n```text\nbuildchain kfd 1 verify --gate-json <file-or-json> [--json]\n```\n\n### `buildchain kfd 1 witness`\n\n- Help: `buildchain kfd 1 witness --help`\n- Canonical id: `kfd-1-witness`\n- Options: `--cwd`, `--json`, `--output`, `--source-sha`\n- Syntax:\n\n```text\nbuildchain kfd 1 witness [--cwd <dir>] [--source-sha <sha>] [--output <file>] [--json]\n```\n\n### `buildchain kfd 2 claims`\n\n- Help: `buildchain kfd 2 claims --help`\n- Canonical id: `kfd-2-claims`\n- Options: `--cwd`, `--json`, `--output-dir`\n- Syntax:\n\n```text\nbuildchain kfd 2 claims [--cwd <dir>] [--output-dir <dir>] [--json]\n```\n\n### `buildchain kfd 2 product-claims check`\n\n- Help: `buildchain kfd 2 product-claims check --help`\n- Canonical id: `kfd-2-product-claims`\n- Options: `--channel`, `--cwd`, `--json`, `--output-dir`, `--registry`, `--source-sha`, `--tag`, `--version`\n- Syntax:\n\n```text\nbuildchain kfd 2 product-claims <check|write|render> [--cwd <dir>] [--registry <path>] [--output-dir <dir>] [--version <version>] [--channel <channel>] [--tag <tag>] [--source-sha <sha>] [--json]\n```\n\n### `buildchain kfd 2 product-claims render`\n\n- Help: `buildchain kfd 2 product-claims render --help`\n- Canonical id: `kfd-2-product-claims`\n- Options: `--channel`, `--cwd`, `--json`, `--output-dir`, `--registry`, `--source-sha`, `--tag`, `--version`\n- Syntax:\n\n```text\nbuildchain kfd 2 product-claims <check|write|render> [--cwd <dir>] [--registry <path>] [--output-dir <dir>] [--version <version>] [--channel <channel>] [--tag <tag>] [--source-sha <sha>] [--json]\n```\n\n### `buildchain kfd 2 product-claims write`\n\n- Help: `buildchain kfd 2 product-claims write --help`\n- Canonical id: `kfd-2-product-claims`\n- Options: `--channel`, `--cwd`, `--json`, `--output-dir`, `--registry`, `--source-sha`, `--tag`, `--version`\n- Syntax:\n\n```text\nbuildchain kfd 2 product-claims <check|write|render> [--cwd <dir>] [--registry <path>] [--output-dir <dir>] [--version <version>] [--channel <channel>] [--tag <tag>] [--source-sha <sha>] [--json]\n```\n\n### `buildchain kfd 2 schema`\n\n- Help: `buildchain kfd 2 schema --help`\n- Canonical id: `kfd-2-schema`\n- Options: `--json`, `--schema`\n- Syntax:\n\n```text\nbuildchain kfd 2 schema [--schema <name>] [--json]\n```\n\n### `buildchain kfd 2 taxonomy`\n\n- Help: `buildchain kfd 2 taxonomy --help`\n- Canonical id: `kfd-2-taxonomy`\n- Options: `--entry-json`, `--json`, `--kind`\n- Syntax:\n\n```text\nbuildchain kfd 2 taxonomy --entry-json <file-or-json>... [--kind residualRisk|downgradeReason] [--json]\n```\n\n### `buildchain kfd 2 trust-assessment`\n\n- Help: `buildchain kfd 2 trust-assessment --help`\n- Canonical id: `kfd-2-trust-assessment`\n- Options: `--assessment-json`, `--json`\n- Syntax:\n\n```text\nbuildchain kfd 2 trust-assessment [--assessment-json <file-or-json>] [--json]\n```\n\n### `buildchain kfd 2 trust-claims`\n\n- Help: `buildchain kfd 2 trust-claims --help`\n- Canonical id: `kfd-2-trust-claims`\n- Options: `--claims-json`, `--json`\n- Syntax:\n\n```text\nbuildchain kfd 2 trust-claims [--claims-json <file-or-json>] [--json]\n```\n\n### `buildchain kfd 3`\n\n- Help: `buildchain kfd 3 --help`\n- Canonical id: `kfd-3`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain kfd 3 ...\n```\n\n### `buildchain kfd 3 audit`\n\n- Help: `buildchain kfd 3 audit --help`\n- Canonical id: `kfd-3-audit`\n- Options: `--artifact`, `--cwd`, `--json`, `--registry`\n- Syntax:\n\n```text\nbuildchain kfd 3 audit [--cwd <dir>] [--registry <path>] [--artifact <path>] [--json]\n```\n\n### `buildchain kfd 3 detect`\n\n- Help: `buildchain kfd 3 detect --help`\n- Canonical id: `kfd-3-detect`\n- Options: `--artifact`, `--cwd`, `--json`, `--kind`\n- Syntax:\n\n```text\nbuildchain kfd 3 detect [--cwd <dir>] [--kind <kind>]... [--artifact <path>] [--json]\n```\n\n### `buildchain kfd 3 query`\n\n- Help: `buildchain kfd 3 query --help`\n- Canonical id: `kfd-3-query`\n- Options: `--artifact`, `--cwd`, `--json`, `--passport`, `--registry`\n- Syntax:\n\n```text\nbuildchain kfd 3 query [<product>] [--cwd <dir>] [--registry <path>] [--passport <file-or-url>] [--artifact <path>] [--json]\n```\n\n### `buildchain kfd 3 register binary`\n\n- Help: `buildchain kfd 3 register binary --help`\n- Canonical id: `kfd-3-register`\n- Options: `--artifact`, `--cwd`, `--json`, `--product`, `--registry`\n- Syntax:\n\n```text\nbuildchain kfd 3 register <node-api|python-api|cli|binary|documentation|site-bundle> [--cwd <dir>] [--registry <path>] [--artifact <path>] [--product <name>] [--json]\n```\n\n### `buildchain kfd 3 register cli`\n\n- Help: `buildchain kfd 3 register cli --help`\n- Canonical id: `kfd-3-register`\n- Options: `--artifact`, `--cwd`, `--json`, `--product`, `--registry`\n- Syntax:\n\n```text\nbuildchain kfd 3 register <node-api|python-api|cli|binary|documentation|site-bundle> [--cwd <dir>] [--registry <path>] [--artifact <path>] [--product <name>] [--json]\n```\n\n### `buildchain kfd 3 register documentation`\n\n- Help: `buildchain kfd 3 register documentation --help`\n- Canonical id: `kfd-3-register`\n- Options: `--artifact`, `--cwd`, `--json`, `--product`, `--registry`\n- Syntax:\n\n```text\nbuildchain kfd 3 register <node-api|python-api|cli|binary|documentation|site-bundle> [--cwd <dir>] [--registry <path>] [--artifact <path>] [--product <name>] [--json]\n```\n\n### `buildchain kfd 3 register node-api`\n\n- Help: `buildchain kfd 3 register node-api --help`\n- Canonical id: `kfd-3-register`\n- Options: `--artifact`, `--cwd`, `--json`, `--product`, `--registry`\n- Syntax:\n\n```text\nbuildchain kfd 3 register <node-api|python-api|cli|binary|documentation|site-bundle> [--cwd <dir>] [--registry <path>] [--artifact <path>] [--product <name>] [--json]\n```\n\n### `buildchain kfd 3 register python-api`\n\n- Help: `buildchain kfd 3 register python-api --help`\n- Canonical id: `kfd-3-register`\n- Options: `--artifact`, `--cwd`, `--json`, `--product`, `--registry`\n- Syntax:\n\n```text\nbuildchain kfd 3 register <node-api|python-api|cli|binary|documentation|site-bundle> [--cwd <dir>] [--registry <path>] [--artifact <path>] [--product <name>] [--json]\n```\n\n### `buildchain kfd 3 register site-bundle`\n\n- Help: `buildchain kfd 3 register site-bundle --help`\n- Canonical id: `kfd-3-register`\n- Options: `--artifact`, `--cwd`, `--json`, `--product`, `--registry`\n- Syntax:\n\n```text\nbuildchain kfd 3 register <node-api|python-api|cli|binary|documentation|site-bundle> [--cwd <dir>] [--registry <path>] [--artifact <path>] [--product <name>] [--json]\n```\n\n### `buildchain kfd 3 witness`\n\n- Help: `buildchain kfd 3 witness --help`\n- Canonical id: `kfd-3-witness`\n- Options: `--artifact`, `--cwd`, `--json`, `--kind`, `--output`, `--registry`, `--source-sha`\n- Syntax:\n\n```text\nbuildchain kfd 3 witness [--cwd <dir>] [--registry <path>] [--kind prebuild|artifact] [--source-sha <sha>] [--artifact <path>] [--output <file>] [--json]\n```\n\n### `buildchain kfd 4 gate`\n\n- Help: `buildchain kfd 4 gate --help`\n- Canonical id: `kfd-4-gate`\n- Options: `--cwd`, `--input-json`, `--json`, `--output`\n- Syntax:\n\n```text\nbuildchain kfd 4 gate --input-json <file-or-json> [--cwd <dir>] [--output <file>] [--json]\n```\n\n### `buildchain kfd 4 schema`\n\n- Help: `buildchain kfd 4 schema --help`\n- Canonical id: `kfd-4-schema`\n- Options: `--json`, `--schema`\n- Syntax:\n\n```text\nbuildchain kfd 4 schema [--schema <name>] [--json]\n```\n\n### `buildchain kfd 4 verify`\n\n- Help: `buildchain kfd 4 verify --help`\n- Canonical id: `kfd-4-verify`\n- Options: `--expected-source-sha`, `--gate-json`, `--json`\n- Syntax:\n\n```text\nbuildchain kfd 4 verify --gate-json <file-or-json> [--expected-source-sha <sha>] [--json]\n```\n\n### `buildchain kfd 5 gate`\n\n- Help: `buildchain kfd 5 gate --help`\n- Canonical id: `kfd-5-gate`\n- Options: `--cwd`, `--input-json`, `--json`, `--output`\n- Syntax:\n\n```text\nbuildchain kfd 5 gate --input-json <file-or-json> [--cwd <dir>] [--output <file>] [--json]\n```\n\n### `buildchain kfd 5 schema`\n\n- Help: `buildchain kfd 5 schema --help`\n- Canonical id: `kfd-5-schema`\n- Options: `--json`, `--schema`\n- Syntax:\n\n```text\nbuildchain kfd 5 schema [--schema <name>] [--json]\n```\n\n### `buildchain kfd 5 verify`\n\n- Help: `buildchain kfd 5 verify --help`\n- Canonical id: `kfd-5-verify`\n- Options: `--expected-source-sha`, `--gate-json`, `--json`\n- Syntax:\n\n```text\nbuildchain kfd 5 verify --gate-json <file-or-json> [--expected-source-sha <sha>] [--json]\n```\n\n### `buildchain kfd 7 gate`\n\n- Help: `buildchain kfd 7 gate --help`\n- Canonical id: `kfd-7-gate`\n- Options: `--cwd`, `--input-json`, `--json`, `--output`\n- Syntax:\n\n```text\nbuildchain kfd 7 gate --input-json <file-or-json> [--cwd <dir>] [--output <file>] [--json]\n```\n\n### `buildchain kfd 7 schema`\n\n- Help: `buildchain kfd 7 schema --help`\n- Canonical id: `kfd-7-schema`\n- Options: `--json`, `--schema`\n- Syntax:\n\n```text\nbuildchain kfd 7 schema [--schema <name>] [--json]\n```\n\n### `buildchain kfd 7 verify`\n\n- Help: `buildchain kfd 7 verify --help`\n- Canonical id: `kfd-7-verify`\n- Options: `--expected-source-sha`, `--gate-json`, `--json`\n- Syntax:\n\n```text\nbuildchain kfd 7 verify --gate-json <file-or-json> [--expected-source-sha <sha>] [--json]\n```\n\n### `buildchain kfd aggregate`\n\n- Help: `buildchain kfd aggregate --help`\n- Canonical id: `kfd-aggregate`\n- Options: `--cwd`, `--json`\n- Syntax:\n\n```text\nbuildchain kfd aggregate [--cwd <dir>] [--json]\n```\n\n### `buildchain kfd hub explain`\n\n- Help: `buildchain kfd hub explain --help`\n- Canonical id: `kfd-hub`\n- Options: `--cwd`, `--declaration`, `--for`, `--force`, `--json`, `--output-dir`, `--write`\n- Syntax:\n\n```text\nbuildchain kfd hub <init|inspect|test|explain> [--cwd <dir>] [--declaration <path>] [--output-dir <path>] [--write] [--force] [--for agent] [--json]\n```\n\n### `buildchain kfd hub init`\n\n- Help: `buildchain kfd hub init --help`\n- Canonical id: `kfd-hub`\n- Options: `--cwd`, `--declaration`, `--for`, `--force`, `--json`, `--output-dir`, `--write`\n- Syntax:\n\n```text\nbuildchain kfd hub <init|inspect|test|explain> [--cwd <dir>] [--declaration <path>] [--output-dir <path>] [--write] [--force] [--for agent] [--json]\n```\n\n### `buildchain kfd hub inspect`\n\n- Help: `buildchain kfd hub inspect --help`\n- Canonical id: `kfd-hub`\n- Options: `--cwd`, `--declaration`, `--for`, `--force`, `--json`, `--output-dir`, `--write`\n- Syntax:\n\n```text\nbuildchain kfd hub <init|inspect|test|explain> [--cwd <dir>] [--declaration <path>] [--output-dir <path>] [--write] [--force] [--for agent] [--json]\n```\n\n### `buildchain kfd hub test`\n\n- Help: `buildchain kfd hub test --help`\n- Canonical id: `kfd-hub`\n- Options: `--cwd`, `--declaration`, `--for`, `--force`, `--json`, `--output-dir`, `--write`\n- Syntax:\n\n```text\nbuildchain kfd hub <init|inspect|test|explain> [--cwd <dir>] [--declaration <path>] [--output-dir <path>] [--write] [--force] [--for agent] [--json]\n```\n\n### `buildchain kfd migrate-layout`\n\n- Help: `buildchain kfd migrate-layout --help`\n- Canonical id: `kfd-migrate-layout`\n- Options: `--cwd`, `--force`, `--json`, `--write`\n- Syntax:\n\n```text\nbuildchain kfd migrate-layout [--cwd <dir>] [--write] [--force] [--json]\n```\n\n### `buildchain kfd schema list`\n\n- Help: `buildchain kfd schema list --help`\n- Canonical id: `kfd-schema-list`\n- Options: `--json`, `--standard`\n- Syntax:\n\n```text\nbuildchain kfd schema list [--standard kfd-1|kfd-2|kfd-3|kfd-4] [--json]\n```\n\n### `buildchain kfd schema show kfd-1`\n\n- Help: `buildchain kfd schema show kfd-1 --help`\n- Canonical id: `kfd-schema-show`\n- Options: `--json`, `--schema`\n- Syntax:\n\n```text\nbuildchain kfd schema show <kfd-1|kfd-2|kfd-3|kfd-4> [--schema <name>] [--json]\n```\n\n### `buildchain kfd schema show kfd-2`\n\n- Help: `buildchain kfd schema show kfd-2 --help`\n- Canonical id: `kfd-schema-show`\n- Options: `--json`, `--schema`\n- Syntax:\n\n```text\nbuildchain kfd schema show <kfd-1|kfd-2|kfd-3|kfd-4> [--schema <name>] [--json]\n```\n\n### `buildchain kfd schema show kfd-3`\n\n- Help: `buildchain kfd schema show kfd-3 --help`\n- Canonical id: `kfd-schema-show`\n- Options: `--json`, `--schema`\n- Syntax:\n\n```text\nbuildchain kfd schema show <kfd-1|kfd-2|kfd-3|kfd-4> [--schema <name>] [--json]\n```\n\n### `buildchain kfd schema show kfd-4`\n\n- Help: `buildchain kfd schema show kfd-4 --help`\n- Canonical id: `kfd-schema-show`\n- Options: `--json`, `--schema`\n- Syntax:\n\n```text\nbuildchain kfd schema show <kfd-1|kfd-2|kfd-3|kfd-4> [--schema <name>] [--json]\n```\n\n### `buildchain kfd status`\n\n- Help: `buildchain kfd status --help`\n- Canonical id: `kfd-status`\n- Options: `--cwd`, `--json`\n- Syntax:\n\n```text\nbuildchain kfd status [--cwd <dir>] [--json]\n```\n\n### `buildchain kfd support project`\n\n- Help: `buildchain kfd support project --help`\n- Canonical id: `kfd-support`\n- Options: `--checked-at`, `--expected-source-sha`, `--json`, `--manifest-gate-json`, `--manifest-json`, `--output`\n- Syntax:\n\n```text\nbuildchain kfd support project --manifest-json <file-or-json> --manifest-gate-json <file-or-json> [--expected-source-sha <sha>] [--checked-at <date-time>] [--output <file>] [--json]\n```\n\n### `buildchain kfd support verify`\n\n- Help: `buildchain kfd support verify --help`\n- Canonical id: `kfd-support`\n- Options: `--checked-at`, `--expected-source-sha`, `--json`, `--manifest-gate-json`, `--manifest-json`, `--projection-json`\n- Syntax:\n\n```text\nbuildchain kfd support verify --projection-json <file-or-json> --manifest-json <file-or-json> --manifest-gate-json <file-or-json> [--expected-source-sha <sha>] [--checked-at <date-time>] [--json]\n```\n\n### `buildchain kfd upstream check`\n\n- Help: `buildchain kfd upstream check --help`\n- Canonical id: `kfd-upstream-check`\n- Options: `--aggregate-json`, `--cwd`, `--json`\n- Syntax:\n\n```text\nbuildchain kfd upstream check [--cwd <dir>] [--aggregate-json <file-or-json>] [--json]\n```\n\n### `buildchain kfd upstream collect`\n\n- Help: `buildchain kfd upstream collect --help`\n- Canonical id: `kfd-upstream-collect`\n- Options: `--cwd`, `--json`, `--output`\n- Syntax:\n\n```text\nbuildchain kfd upstream collect [--cwd <dir>] [--output <file>] [--json]\n```\n\n### `buildchain kfd upstream roles`\n\n- Help: `buildchain kfd upstream roles --help`\n- Canonical id: `kfd-upstream-roles`\n- Options: `--json`\n- Syntax:\n\n```text\nbuildchain kfd upstream roles [--json]\n```\n\n## `layout`\n\n### `buildchain layout`\n\n- Help: `buildchain layout --help`\n- Canonical id: `layout`\n- Options: `--cwd`, `--json`\n- Syntax:\n\n```text\nbuildchain layout [--cwd <dir>] [--json]\n```\n\n## `lifecycle`\n\n### `buildchain lifecycle`\n\n- Help: `buildchain lifecycle --help`\n- Canonical id: `lifecycle`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain lifecycle\n```\n\n### `buildchain lifecycle run`\n\n- Help: `buildchain lifecycle run --help`\n- Canonical id: `lifecycle`\n- Options: `--artifact-name`, `--artifact-path`, `--cwd`, `--manifest-path`, `--platform-id`, `--platform-name`, `--process-summary`, `--required`, `--summary-path`\n- Syntax:\n\n```text\nbuildchain lifecycle run <stage> [--cwd <dir>] [--required] [--artifact-name <name>] [--artifact-path <path>]... [--platform-id <id>] [--platform-name <name>] [--manifest-path <path>] [--summary-path <path>] [--process-summary <json>]\n```\n\n## `log`\n\n### `buildchain log`\n\n- Help: `buildchain log --help`\n- Canonical id: `log`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain log\n```\n\n### `buildchain log error`\n\n- Help: `buildchain log error --help`\n- Canonical id: `logging`\n- Options: `--attribute`, `--component`, `--event`, `--json`, `--path`, `--phase`, `--source`\n- Syntax:\n\n```text\nbuildchain log <info|warn|error> --event <name> [--phase <phase>] [--component <name>] [--source <name>] [--attribute key=value]... [--path <jsonl>] [--json]\n```\n\n### `buildchain log info`\n\n- Help: `buildchain log info --help`\n- Canonical id: `logging`\n- Options: `--attribute`, `--component`, `--event`, `--json`, `--path`, `--phase`, `--source`\n- Syntax:\n\n```text\nbuildchain log <info|warn|error> --event <name> [--phase <phase>] [--component <name>] [--source <name>] [--attribute key=value]... [--path <jsonl>] [--json]\n```\n\n### `buildchain log summary`\n\n- Help: `buildchain log summary --help`\n- Canonical id: `logging`\n- Options: `--json`, `--path`\n- Syntax:\n\n```text\nbuildchain log summary [--path <jsonl>] [--json]\n```\n\n### `buildchain log warn`\n\n- Help: `buildchain log warn --help`\n- Canonical id: `logging`\n- Options: `--attribute`, `--component`, `--event`, `--json`, `--path`, `--phase`, `--source`\n- Syntax:\n\n```text\nbuildchain log <info|warn|error> --event <name> [--phase <phase>] [--component <name>] [--source <name>] [--attribute key=value]... [--path <jsonl>] [--json]\n```\n\n## `mark`\n\n### `buildchain mark`\n\n- Help: `buildchain mark --help`\n- Canonical id: `mark`\n- Options: `--attribute`, `--component`, `--event`, `--json`, `--path`, `--phase`\n- Syntax:\n\n```text\nbuildchain mark --event <name> [--phase <phase>] [--component <name>] [--attribute key=value]... [--path <jsonl>] [--json]\n```\n\n## `npm`\n\n### `buildchain npm`\n\n- Help: `buildchain npm --help`\n- Canonical id: `npm`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain npm\n```\n\n### `buildchain npm dry-run`\n\n- Help: `buildchain npm dry-run --help`\n- Canonical id: `npm-dry-run`\n- Options: `--cwd`, `--dist-tag`, `--expected-tag`, `--json`, `--registry`, `--skip-npm-publish-dry-run`\n- Syntax:\n\n```text\nbuildchain npm dry-run [--cwd <dir>] [--expected-tag <tag>] [--registry <url>] [--dist-tag <tag>] [--skip-npm-publish-dry-run] [--json]\n```\n\n## `paper`\n\n### `buildchain paper`\n\n- Help: `buildchain paper --help`\n- Canonical id: `paper`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain paper\n```\n\n### `buildchain paper agent verify`\n\n- Help: `buildchain paper agent verify --help`\n- Canonical id: `paper-agent`\n- Options: `--cwd`, `--json`, `--offline`\n- Syntax:\n\n```text\nbuildchain paper agent verify [--cwd <dir>] [--offline] [--json]\n```\n\n### `buildchain paper alpha`\n\n- Help: `buildchain paper alpha --help`\n- Canonical id: `paper-alpha`\n- Options: `--cwd`, `--execute`, `--json`, `--source-ref`, `--target-ref`\n- Syntax:\n\n```text\nbuildchain paper alpha [--cwd <dir>] [--source-ref <ref>] [--target-ref <ref>] [--execute] [--json]\n```\n\n### `buildchain paper bootstrap npm`\n\n- Help: `buildchain paper bootstrap npm --help`\n- Canonical id: `paper-bootstrap-npm`\n- Options: `--confirm-public-package`, `--cwd`, `--execute`, `--json`\n- Syntax:\n\n```text\nbuildchain paper bootstrap npm [--cwd <dir>] [--execute] [--confirm-public-package <name>] [--json]\n```\n\n### `buildchain paper build`\n\n- Help: `buildchain paper build --help`\n- Canonical id: `paper-build`\n- Options: `--cwd`, `--execute`, `--json`\n- Syntax:\n\n```text\nbuildchain paper build [--cwd <dir>] [--execute] [--json]\n```\n\n### `buildchain paper fleet audit`\n\n- Help: `buildchain paper fleet audit --help`\n- Canonical id: `paper-fleet-audit`\n- Options: `--json`, `--offline`, `--root`\n- Syntax:\n\n```text\nbuildchain paper fleet audit [--root <dir>] [--offline] [--json]\n```\n\n### `buildchain paper fleet update`\n\n- Help: `buildchain paper fleet update --help`\n- Canonical id: `paper-fleet-update`\n- Options: `--json`, `--root`, `--write`\n- Syntax:\n\n```text\nbuildchain paper fleet update [--root <dir>] [--write] [--json]\n```\n\n### `buildchain paper migrate`\n\n- Help: `buildchain paper migrate --help`\n- Canonical id: `paper-migrate`\n- Options: `--cwd`, `--json`, `--write`\n- Syntax:\n\n```text\nbuildchain paper migrate [--cwd <dir>] [--write] [--json]\n```\n\n### `buildchain paper preflight`\n\n- Help: `buildchain paper preflight --help`\n- Canonical id: `paper-preflight`\n- Options: `--cwd`, `--json`, `--offline`\n- Syntax:\n\n```text\nbuildchain paper preflight [--cwd <dir>] [--offline] [--json]\n```\n\n### `buildchain paper resume`\n\n- Help: `buildchain paper resume --help`\n- Canonical id: `paper-resume`\n- Options: `--buildchain-ref`, `--cwd`, `--execute`, `--json`\n- Syntax:\n\n```text\nbuildchain paper resume [--cwd <dir>] [--buildchain-ref <ref>] [--execute] [--json]\n```\n\n### `buildchain paper scaffold`\n\n- Help: `buildchain paper scaffold --help`\n- Canonical id: `paper-scaffold`\n- Options: `--json`, `--package`, `--repository`, `--write`\n- Syntax:\n\n```text\nbuildchain paper scaffold --package <name> --repository <owner/repo> [--write] [--json]\n```\n\n### `buildchain paper status`\n\n- Help: `buildchain paper status --help`\n- Canonical id: `paper-status`\n- Options: `--cwd`, `--json`\n- Syntax:\n\n```text\nbuildchain paper status [--cwd <dir>] [--json]\n```\n\n### `buildchain paper work start`\n\n- Help: `buildchain paper work start --help`\n- Canonical id: `paper-work-start`\n- Options: `--branch`, `--cwd`, `--execute`, `--json`\n- Syntax:\n\n```text\nbuildchain paper work start <topic> [--cwd <dir>] [--branch <branch>] [--execute] [--json]\n```\n\n### `buildchain paper work submit`\n\n- Help: `buildchain paper work submit --help`\n- Canonical id: `paper-work-submit`\n- Options: `--body`, `--cwd`, `--execute`, `--json`, `--title`\n- Syntax:\n\n```text\nbuildchain paper work submit [--cwd <dir>] [--title <title>] [--body <body>] [--execute] [--json]\n```\n\n## `portable-cache`\n\n### `buildchain portable-cache`\n\n- Help: `buildchain portable-cache --help`\n- Canonical id: `portable-cache`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain portable-cache\n```\n\n### `buildchain portable-cache plan`\n\n- Help: `buildchain portable-cache plan --help`\n- Canonical id: `portable-cache`\n- Options: `--github-output`, `--json`, `--manifest`, `--output`\n- Syntax:\n\n```text\nbuildchain portable-cache plan --manifest <file-or-json> [--output <file>] [--github-output <file>] [--json]\n```\n\n### `buildchain portable-cache receipt`\n\n- Help: `buildchain portable-cache receipt --help`\n- Canonical id: `portable-cache`\n- Options: `--cache-hit`, `--cold-fallback-status`, `--json`, `--matched-key`, `--output`, `--plan`, `--validation-reason`, `--validation-status`\n- Syntax:\n\n```text\nbuildchain portable-cache receipt --plan <file-or-json> [--matched-key <key>] [--cache-hit true|false] [--validation-status pass|fail] [--validation-reason <text>] [--cold-fallback-status not-run|passed|failed] [--output <file>] [--json]\n```\n\n## `project`\n\n### `buildchain project`\n\n- Help: `buildchain project --help`\n- Canonical id: `project`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain project\n```\n\n### `buildchain project kfx-admission`\n\n- Help: `buildchain project kfx-admission --help`\n- Canonical id: `project`\n- Options: `--assessment-time`, `--expected-contract`, `--expected-issuer`, `--expected-publisher`, `--expected-root`, `--json`\n- Syntax:\n\n```text\nbuildchain project kfx-admission <file-or-json> [--assessment-time <epoch>] [--expected-root <sha256:...>] [--expected-issuer <issuer>] [--expected-publisher <publisher>] [--expected-contract <version>] [--json]\n```\n\n## `publication-artifact`\n\n### `buildchain publication-artifact`\n\n- Help: `buildchain publication-artifact --help`\n- Canonical id: `publication-artifact`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain publication-artifact\n```\n\n### `buildchain publication-artifact manifest`\n\n- Help: `buildchain publication-artifact manifest --help`\n- Canonical id: `publication-artifact-manifest`\n- Options: `--cwd`, `--json`, `--no-source-bundle`, `--output`, `--passport-output`, `--registry-output`, `--source-bundle`, `--source-sha`\n- Syntax:\n\n```text\nbuildchain publication-artifact manifest [--cwd <dir>] [--source-sha <sha>] [--output <file>] [--passport-output <file>] [--registry-output <file>] [--source-bundle <file>] [--no-source-bundle] [--json]\n```\n\n### `buildchain publication-artifact npm-package`\n\n- Help: `buildchain publication-artifact npm-package --help`\n- Canonical id: `publication-artifact-npm-package`\n- Options: `--cwd`, `--json`, `--output-dir`, `--package-name`\n- Syntax:\n\n```text\nbuildchain publication-artifact npm-package [--cwd <dir>] [--output-dir <dir>] [--package-name <name>] [--json]\n```\n\n### `buildchain publication-artifact reproducibility`\n\n- Help: `buildchain publication-artifact reproducibility --help`\n- Canonical id: `publication-artifact-reproducibility`\n- Options: `--allow-unpinned-toolchain`, `--cwd`, `--json`, `--no-toolchain-pull`, `--output`, `--promote`, `--source-sha`\n- Syntax:\n\n```text\nbuildchain publication-artifact reproducibility [--cwd <dir>] [--source-sha <sha>] [--output <file>] [--promote] [--no-toolchain-pull] [--allow-unpinned-toolchain] [--json]\n```\n\n## `publish-source`\n\n### `buildchain publish-source`\n\n- Help: `buildchain publish-source --help`\n- Canonical id: `publish-source`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain publish-source\n```\n\n### `buildchain publish-source lock`\n\n- Help: `buildchain publish-source lock --help`\n- Canonical id: `publish-source`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain publish-source <lock|manifest|verify-lock|verify-channel-ref|validate-anchored-release> ...\n```\n\n### `buildchain publish-source manifest`\n\n- Help: `buildchain publish-source manifest --help`\n- Canonical id: `publish-source`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain publish-source <lock|manifest|verify-lock|verify-channel-ref|validate-anchored-release> ...\n```\n\n### `buildchain publish-source validate-anchored-release`\n\n- Help: `buildchain publish-source validate-anchored-release --help`\n- Canonical id: `publish-source`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain publish-source <lock|manifest|verify-lock|verify-channel-ref|validate-anchored-release> ...\n```\n\n### `buildchain publish-source verify-channel-ref`\n\n- Help: `buildchain publish-source verify-channel-ref --help`\n- Canonical id: `publish-source`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain publish-source <lock|manifest|verify-lock|verify-channel-ref|validate-anchored-release> ...\n```\n\n### `buildchain publish-source verify-lock`\n\n- Help: `buildchain publish-source verify-lock --help`\n- Canonical id: `publish-source`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain publish-source <lock|manifest|verify-lock|verify-channel-ref|validate-anchored-release> ...\n```\n\n## `release`\n\n### `buildchain release`\n\n- Help: `buildchain release --help`\n- Canonical id: `release-transaction`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain release\n```\n\n### `buildchain release --dry-run`\n\n- Help: `buildchain release --dry-run --help`\n- Canonical id: `release-dry-run`\n- Options: `--dry-run`, `--json`, `--sha`, `--source-ref`, `--tags`, `--target-ref`\n- Syntax:\n\n```text\nbuildchain release --dry-run --target-ref <ref> [--sha <sha>] [--source-ref <ref>] [--tags <comma-list>] [--json]\n```\n\n### `buildchain release abort`\n\n- Help: `buildchain release abort --help`\n- Canonical id: `release-transaction`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain release <inspect|recover|finalize|abort> ...\n```\n\n### `buildchain release dry-run`\n\n- Help: `buildchain release dry-run --help`\n- Canonical id: `release-dry-run`\n- Options: `--json`, `--sha`, `--source-ref`, `--tags`, `--target-ref`\n- Syntax:\n\n```text\nbuildchain release dry-run --target-ref <ref> [--sha <sha>] [--source-ref <ref>] [--tags <comma-list>] [--json]\n```\n\n### `buildchain release explain`\n\n- Help: `buildchain release explain --help`\n- Canonical id: `release-dry-run`\n- Options: `--json`, `--sha`, `--source-ref`, `--tags`, `--target-ref`\n- Syntax:\n\n```text\nbuildchain release explain --target-ref <ref> [--sha <sha>] [--source-ref <ref>] [--tags <comma-list>] [--json]\n```\n\n### `buildchain release finalize`\n\n- Help: `buildchain release finalize --help`\n- Canonical id: `release-transaction`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain release <inspect|recover|finalize|abort> ...\n```\n\n### `buildchain release inspect`\n\n- Help: `buildchain release inspect --help`\n- Canonical id: `release-transaction`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain release <inspect|recover|finalize|abort> ...\n```\n\n### `buildchain release line open`\n\n- Help: `buildchain release line open --help`\n- Canonical id: `release-line-open`\n- Options: `--initial-version`, `--json`, `--major`, `--minor`, `--source-ref`, `--write`\n- Syntax:\n\n```text\nbuildchain release line open --major <n> --minor <n> [--source-ref <ref>] [--initial-version <version>] [--write] [--json]\n```\n\n### `buildchain release recover`\n\n- Help: `buildchain release recover --help`\n- Canonical id: `release-transaction`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain release <inspect|recover|finalize|abort> ...\n```\n\n## `release-governance`\n\n### `buildchain release-governance`\n\n- Help: `buildchain release-governance --help`\n- Canonical id: `release-governance`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain release-governance\n```\n\n### `buildchain release-governance reconcile`\n\n- Help: `buildchain release-governance reconcile --help`\n- Canonical id: `release-governance`\n- Options: `--apply`, `--branch`, `--candidate-sha`, `--json`, `--repository`\n- Syntax:\n\n```text\nbuildchain release-governance reconcile --repository <owner/repo> --branch <dev|alpha|release/vN/vN.N> --candidate-sha <sha> [--apply] [--json]\n```\n\n## `release-propagation`\n\n### `buildchain release-propagation`\n\n- Help: `buildchain release-propagation --help`\n- Canonical id: `release-propagation`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain release-propagation\n```\n\n### `buildchain release-propagation entry`\n\n- Help: `buildchain release-propagation entry --help`\n- Canonical id: `release-propagation`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain release-propagation <plan|write-lock|work|entry|pickup> ...\n```\n\n### `buildchain release-propagation pickup`\n\n- Help: `buildchain release-propagation pickup --help`\n- Canonical id: `release-propagation`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain release-propagation <plan|write-lock|work|entry|pickup> ...\n```\n\n### `buildchain release-propagation plan`\n\n- Help: `buildchain release-propagation plan --help`\n- Canonical id: `release-propagation`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain release-propagation <plan|write-lock|work|entry|pickup> ...\n```\n\n### `buildchain release-propagation work`\n\n- Help: `buildchain release-propagation work --help`\n- Canonical id: `release-propagation`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain release-propagation <plan|write-lock|work|entry|pickup> ...\n```\n\n### `buildchain release-propagation write-lock`\n\n- Help: `buildchain release-propagation write-lock --help`\n- Canonical id: `release-propagation`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain release-propagation <plan|write-lock|work|entry|pickup> ...\n```\n\n## `release-tail`\n\n### `buildchain release-tail`\n\n- Help: `buildchain release-tail --help`\n- Canonical id: `release-tail`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain release-tail\n```\n\n### `buildchain release-tail compat`\n\n- Help: `buildchain release-tail compat --help`\n- Canonical id: `release-tail`\n- Options: `--hooks-json`, `--output`\n- Syntax:\n\n```text\nbuildchain release-tail compat --hooks-json <json-or-path> [--output <path>]\n```\n\n### `buildchain release-tail init`\n\n- Help: `buildchain release-tail init --help`\n- Canonical id: `release-tail`\n- Options: `--declaration`, `--state`\n- Syntax:\n\n```text\nbuildchain release-tail init --declaration <json-or-path> [--state <path>]\n```\n\n### `buildchain release-tail plan`\n\n- Help: `buildchain release-tail plan --help`\n- Canonical id: `release-tail`\n- Options: `--declaration`, `--output`\n- Syntax:\n\n```text\nbuildchain release-tail plan --declaration <json-or-path> [--output <path>]\n```\n\n### `buildchain release-tail status`\n\n- Help: `buildchain release-tail status --help`\n- Canonical id: `release-tail`\n- Options: `--output`, `--state`\n- Syntax:\n\n```text\nbuildchain release-tail <status|verify> [--state <path>] [--output <path>]\n```\n\n### `buildchain release-tail verify`\n\n- Help: `buildchain release-tail verify --help`\n- Canonical id: `release-tail`\n- Options: `--output`, `--state`\n- Syntax:\n\n```text\nbuildchain release-tail <status|verify> [--state <path>] [--output <path>]\n```\n\n## `sample`\n\n### `buildchain sample`\n\n- Help: `buildchain sample --help`\n- Canonical id: `sample`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain sample\n```\n\n### `buildchain sample process-tree`\n\n- Help: `buildchain sample process-tree --help`\n- Canonical id: `sample-process-tree`\n- Options: `--interval-ms`, `--json`, `--label`, `--output`, `--requested-parallelism`, `--summary-output`\n- Syntax:\n\n```text\nbuildchain sample process-tree [--interval-ms <n>] [--label <name>] [--output <jsonl>] [--summary-output <json>] [--requested-parallelism <n>] [--json] -- <command> [args...]\n```\n\n## `span`\n\n### `buildchain span`\n\n- Help: `buildchain span --help`\n- Canonical id: `span`\n- Options: `--component`, `--event`, `--path`, `--phase`\n- Syntax:\n\n```text\nbuildchain span --event <name> [--phase <phase>] [--component <name>] [--path <jsonl>] -- <command> [args...]\n```\n\n## `transaction`\n\n### `buildchain transaction`\n\n- Help: `buildchain transaction --help`\n- Canonical id: `transaction-inspect`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain transaction\n```\n\n### `buildchain transaction inspect`\n\n- Help: `buildchain transaction inspect --help`\n- Canonical id: `transaction-inspect`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain transaction inspect ...\n```\n\n## `validate`\n\n### `buildchain validate`\n\n- Help: `buildchain validate --help`\n- Canonical id: `validate`\n- Options: `--cwd`, `--require-lifecycle-stages`, `--require-version-state`\n- Syntax:\n\n```text\nbuildchain validate [--cwd <dir>] [--require-version-state] [--require-lifecycle-stages <comma-list>]\n```\n\n## `verify`\n\n### `buildchain verify`\n\n- Help: `buildchain verify --help`\n- Canonical id: `verify`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain verify\n```\n\n### `buildchain verify artifact dir`\n\n- Help: `buildchain verify artifact dir --help`\n- Canonical id: `verify-artifact`\n- Options: `--json`, `--locator-config`, `--npm-registry`, `--passport`, `--repository`, `--tag`\n- Syntax:\n\n```text\nbuildchain verify artifact <file|dir|url|npm:...|oci:...|github-release:...> [--passport <file-or-url>] [--locator-config <json>] [--repository <owner/repo>] [--tag <tag>] [--npm-registry <url>] [--json]\n```\n\n### `buildchain verify artifact file`\n\n- Help: `buildchain verify artifact file --help`\n- Canonical id: `verify-artifact`\n- Options: `--json`, `--locator-config`, `--npm-registry`, `--passport`, `--repository`, `--tag`\n- Syntax:\n\n```text\nbuildchain verify artifact <file|dir|url|npm:...|oci:...|github-release:...> [--passport <file-or-url>] [--locator-config <json>] [--repository <owner/repo>] [--tag <tag>] [--npm-registry <url>] [--json]\n```\n\n### `buildchain verify artifact github-release:...`\n\n- Help: `buildchain verify artifact github-release:... --help`\n- Canonical id: `verify-artifact`\n- Options: `--json`, `--locator-config`, `--npm-registry`, `--passport`, `--repository`, `--tag`\n- Syntax:\n\n```text\nbuildchain verify artifact <file|dir|url|npm:...|oci:...|github-release:...> [--passport <file-or-url>] [--locator-config <json>] [--repository <owner/repo>] [--tag <tag>] [--npm-registry <url>] [--json]\n```\n\n### `buildchain verify artifact npm:...`\n\n- Help: `buildchain verify artifact npm:... --help`\n- Canonical id: `verify-artifact`\n- Options: `--json`, `--locator-config`, `--npm-registry`, `--passport`, `--repository`, `--tag`\n- Syntax:\n\n```text\nbuildchain verify artifact <file|dir|url|npm:...|oci:...|github-release:...> [--passport <file-or-url>] [--locator-config <json>] [--repository <owner/repo>] [--tag <tag>] [--npm-registry <url>] [--json]\n```\n\n### `buildchain verify artifact oci:...`\n\n- Help: `buildchain verify artifact oci:... --help`\n- Canonical id: `verify-artifact`\n- Options: `--json`, `--locator-config`, `--npm-registry`, `--passport`, `--repository`, `--tag`\n- Syntax:\n\n```text\nbuildchain verify artifact <file|dir|url|npm:...|oci:...|github-release:...> [--passport <file-or-url>] [--locator-config <json>] [--repository <owner/repo>] [--tag <tag>] [--npm-registry <url>] [--json]\n```\n\n### `buildchain verify artifact url`\n\n- Help: `buildchain verify artifact url --help`\n- Canonical id: `verify-artifact`\n- Options: `--json`, `--locator-config`, `--npm-registry`, `--passport`, `--repository`, `--tag`\n- Syntax:\n\n```text\nbuildchain verify artifact <file|dir|url|npm:...|oci:...|github-release:...> [--passport <file-or-url>] [--locator-config <json>] [--repository <owner/repo>] [--tag <tag>] [--npm-registry <url>] [--json]\n```\n\n### `buildchain verify artifact-envelope`\n\n- Help: `buildchain verify artifact-envelope --help`\n- Canonical id: `verify-artifact-envelope`\n- Options: `--assessment-time`, `--expected-contract`, `--expected-issuer`, `--expected-publisher`, `--expected-root`, `--json`\n- Syntax:\n\n```text\nbuildchain verify artifact-envelope <file-or-json> [--assessment-time <epoch>] [--expected-root <sha256:...>] [--expected-issuer <issuer>] [--expected-publisher <publisher>] [--expected-contract <version>] [--json]\n```\n\n### `buildchain verify github-artifact-attestation`\n\n- Help: `buildchain verify github-artifact-attestation --help`\n- Canonical id: `verify-github-artifact-attestation`\n- Options: `--bundle`, `--evidence`, `--json`, `--platform-manifest`, `--release-passport`\n- Syntax:\n\n```text\nbuildchain verify github-artifact-attestation <artifact> --evidence <file> --bundle <file> --platform-manifest <file> --release-passport <file> [--json]\n```\n\n### `buildchain verify infra-contract-evidence-bundle`\n\n- Help: `buildchain verify infra-contract-evidence-bundle --help`\n- Canonical id: `verify-infra-contract-evidence-bundle`\n- Options: `--json`\n- Syntax:\n\n```text\nbuildchain verify infra-contract-evidence-bundle <file> [--json]\n```\n\n### `buildchain verify observability-log`\n\n- Help: `buildchain verify observability-log --help`\n- Canonical id: `verify-observability-log`\n- Options: `--allow-errors`, `--json`, `--min-events`, `--require-component`, `--require-event`, `--require-phase`\n- Syntax:\n\n```text\nbuildchain verify observability-log <jsonl> [--min-events <n>] [--require-phase <csv>] [--require-component <csv>] [--require-event <csv>] [--allow-errors] [--json]\n```\n\n### `buildchain verify publication-admission`\n\n- Help: `buildchain verify publication-admission --help`\n- Canonical id: `verify-publication-admission`\n- Options: `--control-plane-audit-json`, `--expected-json`, `--json`, `--publication-evidence-json`, `--registry-json`, `--runner-json`, `--used-nonce`\n- Syntax:\n\n```text\nbuildchain verify publication-admission <file-or-json> --registry-json <file-or-json> --runner-json <file-or-json> --control-plane-audit-json <file-or-json> --publication-evidence-json <file-or-json> [--expected-json <file-or-json>] [--used-nonce <nonce>]... [--json]\n```\n\n### `buildchain verify release-passport`\n\n- Help: `buildchain verify release-passport --help`\n- Canonical id: `verify-release-passport`\n- Options: `--json`\n- Syntax:\n\n```text\nbuildchain verify release-passport <file-or-url> [--json]\n```\n\n## `version`\n\n### `buildchain version`\n\n- Help: `buildchain version --help`\n- Canonical id: `version`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain version\n```\n\n## `web-surface`\n\n### `buildchain web-surface`\n\n- Help: `buildchain web-surface --help`\n- Canonical id: `web-surface`\n- Options: none declared\n- Syntax:\n\n```text\nbuildchain web-surface ...\n```"
    },
    {
      "id": "manual:consumer-issue-reporting",
      "title": "Consumer Issue Reporting",
      "route": "/docs/consumer-issue-reporting",
      "category": "manual",
      "capabilityGroup": "observability-diagnostics",
      "audience": [
        "consumer",
        "maintainer"
      ],
      "maturity": "stable",
      "sourcePath": "docs/consumer-issue-reporting.md",
      "digest": "sha256:324342b10e69ca5ce6d04a267fb5fc2a6b52e674f6252eec2121557c5542f729",
      "headings": [
        {
          "level": 1,
          "title": "Consumer Issue Reporting",
          "anchor": "consumer-issue-reporting"
        },
        {
          "level": 2,
          "title": "Trust model",
          "anchor": "trust-model"
        },
        {
          "level": 2,
          "title": "Behavior",
          "anchor": "behavior"
        },
        {
          "level": 2,
          "title": "JavaScript API",
          "anchor": "javascript-api"
        }
      ],
      "markdown": "---\nstatus: active\nperiod: ongoing\ntheme: buildchain-consumer-issue-reporting\ndoc_type: technical-reference\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-07-31\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-31\n  invisible_context: not asserted\n---\n\n# Consumer Issue Reporting\n\nBuildchain ships a first-class issue reporting surface for consumer workflows.\nIt lets a repository open or update a Buildchain-owned GitHub issue when a\nBuildchain reusable workflow, action, or toolkit API produces a failure that\nneeds Buildchain maintainers.\n\n## Trust model\n\nThe consumer workflow must provide a token with issue-write access to the\ntarget repository. A repository's default `GITHUB_TOKEN` only writes to its own\nrepository, so cross-repository reports should use a GitHub App installation\ntoken scoped to:\n\n- the `kungfu-systems/buildchain` repository;\n- Issues: read and write;\n- no content write permission unless another workflow step needs it.\n\nThe recommended pattern is:\n\n```yaml\n- uses: actions/create-github-app-token@v2\n  id: buildchain-issue-token\n  with:\n    app-id: ${{ secrets.BUILDCHAIN_ISSUE_APP_ID }}\n    private-key: ${{ secrets.BUILDCHAIN_ISSUE_APP_PRIVATE_KEY }}\n    owner: kungfu-systems\n    repositories: buildchain\n\n- uses: kungfu-systems/buildchain/actions/report-buildchain-issue@v3\n  if: failure()\n  with:\n    token: ${{ steps.buildchain-issue-token.outputs.token }}\n    summary: \"Buildchain reusable build failed before artifact finalization\"\n    failure-code: reusable-build-failed\n    diagnostics-path: .buildchain/artifacts/diagnostics.json\n    buildchain-ref: ${{ inputs.buildchain-ref || 'v3' }}\n```\n\n## Behavior\n\n`report-buildchain-issue` builds an issue body with consumer repository,\nworkflow, ref, SHA, Buildchain ref/version, diagnostics links, and optional\ndetails. It computes a stable fingerprint and embeds a hidden marker:\n\n```text\nbuildchain-consumer-issue:fingerprint=<sha256-prefix>\n```\n\nWhen an open issue with the same marker exists, the action comments on it with\nthe new run evidence. Otherwise it creates a new issue. Consumers may pass an\nexplicit `fingerprint` when they need a different dedupe boundary.\n\nThe action is fail-soft by default. It retries GitHub API 429/5xx responses and\nconnection failures, redacts common secret/token/private-key patterns, truncates\nlarge bodies, and retries issue creation without labels if the target\nrepository does not have the configured labels yet.\n\nSet `fail-on-error: \"true\"` only when the reporting step is part of a release\ngate and missing Buildchain feedback should stop the workflow.\n\n## JavaScript API\n\nConsumer scripts can import the same implementation:\n\n```js\nimport {\n  buildConsumerIssueReport,\n  reportBuildchainIssue,\n} from \"@kungfu-tech/buildchain/issue-reporting\";\n\nconst result = await reportBuildchainIssue({\n  token: process.env.BUILDCHAIN_ISSUE_TOKEN,\n  summary: \"Native artifact manifest is incomplete\",\n  failureCode: \"native-manifest-incomplete\",\n  buildchainRef: \"v3\",\n  diagnosticsPath: \".buildchain/artifacts/diagnostics.json\",\n});\n```\n\nUse `buildConsumerIssueReport` for dry-run validation, previewing redaction, or\nunit tests without calling GitHub."
    },
    {
      "id": "manual:controller-evidence",
      "title": "Controller Evidence",
      "route": "/docs/controller-evidence",
      "category": "manual",
      "capabilityGroup": "reusable-build",
      "audience": [
        "consumer",
        "release-operator",
        "agent"
      ],
      "maturity": "draft",
      "sourcePath": "docs/controller-evidence.md",
      "digest": "sha256:442e1b72e3977af56a8ae5e081ffd89c2f3ebcd9cfd50f07af730344bdf9fb0e",
      "headings": [
        {
          "level": 1,
          "title": "Controller Evidence",
          "anchor": "controller-evidence"
        },
        {
          "level": 2,
          "title": "Public controller inventory",
          "anchor": "public-controller-inventory"
        },
        {
          "level": 2,
          "title": "Plan contract",
          "anchor": "plan-contract"
        },
        {
          "level": 2,
          "title": "Receipt and aggregation",
          "anchor": "receipt-and-aggregation"
        },
        {
          "level": 2,
          "title": "Shifu boundary",
          "anchor": "shifu-boundary"
        },
        {
          "level": 2,
          "title": "Release Passport references",
          "anchor": "release-passport-references"
        },
        {
          "level": 2,
          "title": "Train validation",
          "anchor": "train-validation"
        }
      ],
      "markdown": "---\nstatus: draft\nperiod: ongoing\ntheme: buildchain-controller-evidence\ndoc_type: analysis\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: B\nreview_state: unreviewed\nlast_reviewed: 2026-07-14\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-14\n  boundary: Based on repository source and tests; no claim about unobserved downstream runs.\n---\n\n# Controller Evidence\n\nBuildchain controller evidence records what a reusable workflow intended to do\nand what it actually completed. It is a project-independent envelope around\nBuildchain orchestration; it does not replace a consumer project's own policy,\nGate registry, or domain receipts.\n\nThe machine-readable entrypoint is\n`dist/site/controller-registry.json`. The Node API is exported as\n`@kungfu-tech/buildchain/controller-evidence`.\n\n## Public controller inventory\n\nThe first versioned inventory contains:\n\n- source check;\n- lifecycle build and channel routing;\n- the Shifu Gate profile envelope;\n- web-surface build/deploy orchestration;\n- publication artifact and paper release;\n- release-candidate promotion;\n- release propagation.\n\nPatrol and repository-maintenance workflows are not controllers. A controller\ndescriptor declares its workflow, version, input classifications, expected\nstages, capabilities, evidence kinds, and a deterministic descriptor digest.\n\n## Plan contract\n\nA `buildchain.controller-evidence/v1` plan binds:\n\n- the controller id, version, workflow path, and descriptor digest;\n- the exact consumer repository and 40-character source SHA;\n- the requested Buildchain ref, exact runtime SHA, and runtime contract digest;\n- normalized inputs;\n- expected stages, capabilities, and evidence kinds.\n\nInputs use one of four policies:\n\n- `included` for safe scalar values;\n- `digest-only` for commands, structured values, runner selection, paths, role\n  identifiers, registries, mirrors, and other environment-shaped values;\n- `redacted` for workflow secrets and token/private-key shaped fields;\n- `unsupported` for a declared input that must fail closed when provided.\n\nRedacted inputs carry no value, digest, or presence bit. Included path-like\ninputs reject absolute runner paths. Undeclared inputs fail plan creation.\n\n## Receipt and aggregation\n\nA receipt binds back to the plan digest and repeats the source and runtime\nidentities. Every declared stage is recorded as `passed`, `failed`, `skipped`,\n`cancelled`, or `missing`; the receipt status is `passed`, `failed`, `skipped`,\nor `partial`. Evidence is represented by kind and SHA-256 digest, with an\noptional artifact name.\n\nReusable workflows expose these outputs:\n\n- `controller-plan-artifact`, `controller-plan-json`, and\n  `controller-plan-digest`;\n- `controller-receipt-artifact`, `controller-receipt-json`,\n  `controller-receipt-digest`, and `controller-receipt-status`.\n\nFinal aggregation uses `always()`. A required missing stage, required missing\nevidence, invalid digest, source/runtime mismatch, or missing receipt cannot be\nreported as qualifying green. `aggregateControllerReceipts()` reports an\nexplicit `receipt-missing` status when a plan has no receipt.\n\n## Shifu boundary\n\nThe Shifu profile controller is an envelope only. Its controller receipt\nreferences the digest and status of `buildchain.shifu-gate-aggregate/v1`; it\ndoes not copy project Gate identifiers, Gate semantics, registry contents, or\nper-Gate results into Buildchain's generic controller contract.\n\n## Release Passport references\n\nRelease-candidate and final Release Passport documents may carry compact\n`controllerReceipts[]` references. Each reference contains the controller id,\nplan and receipt digests, source and runtime SHAs, status, and artifact name.\nThe passport validates those identities; it never invents a controller receipt\nfrom a successful job conclusion.\n\nThe PR-stage lifecycle build creates its qualifying receipt before the\nrelease-candidate passport. Promotion validates that passport and preserves the\nsame references in the final Release Passport, closing the build-to-publish\nevidence chain.\n\n## Train validation\n\nAn unreleased contract should be tested through a temporary Buildchain train\nref and an exact downstream consumer source SHA. The downstream run should\nretain the plan artifact, receipt artifact, workflow outputs, and Release\nPassport or release-candidate reference. Promote to an official alpha or stable\nchannel only after those identities and digests agree."
    },
    {
      "id": "manual:dev-alpha-candidate-patrol",
      "title": "Dev to Alpha Candidate Patrol",
      "route": "/docs/dev-alpha-candidate-patrol",
      "category": "manual",
      "capabilityGroup": "governance-versioning",
      "audience": [
        "release-operator",
        "consumer",
        "agent"
      ],
      "maturity": "preview",
      "sourcePath": "docs/dev-alpha-candidate-patrol.md",
      "digest": "sha256:53a76ece171b7750a3f9952a64f50fe9b1e43ed69212522fed70b394619b4d8d",
      "headings": [
        {
          "level": 1,
          "title": "Dev to Alpha Candidate Patrol",
          "anchor": "dev-to-alpha-candidate-patrol"
        },
        {
          "level": 2,
          "title": "Reusable workflow",
          "anchor": "reusable-workflow"
        }
      ],
      "markdown": "---\nstatus: preview\nperiod: ongoing\ntheme: dev-alpha-candidate-patrol\ndoc_type: architecture-and-usage\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: self-reviewed\nlast_reviewed: 2026-08-11\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-08-11\n  visible_context: Buildchain v4 parity of the proven v3 Release Train and Release Cut contracts, existing source locks, exact-source Alpha preflight, Dev Patrol, cancelled duplicate runs, protected auto-merge policy, repository release governance, and the consumer-owned settlement renderer threat model.\n  invisible_context_boundary: No credentials, private logs, or private configuration were used.\n---\n\n# Dev to Alpha Candidate Patrol\n\nBuildchain provides a reusable observation and single-flight PR controller for\nrepositories that promote a development branch into a protected Alpha branch.\nIt does not publish Alpha. The read-only observer reads the exact heads of both\nbranches, walks the\nbounded development history from newest to oldest (stopping early at the Alpha\nhead), and selects the newest commit that satisfies all of these conditions:\n\n- the source is strictly ahead of the recorded target head;\n- the latest completed, non-cancelled Dev Patrol for that exact commit SHA\n  succeeded;\n- the latest completed, non-cancelled Alpha preflight for the same commit SHA\n  succeeded; and\n- both runs are within the caller's evidence age limit.\n\nWhen no managed candidate is active, the selected commit can be behind the observed development head when newer\ncommits have not completed both workflows yet. The decision binds the observed\nhead, selected SHA, and count of skipped newer commits. This makes a slow native\nverification lane live under continuous development without silently treating\nan unqualified head as releasable.\n\nBefore any new selection, the v4 controller now resolves the open managed PR and\nvalidates its embedded authoritative Release Train. If one exists, the frozen\nRelease Cut wins: Candidate Patrol does not scan for or retain a newer qualified\ncandidate. It returns the cut's exact candidate commit, candidate tree,\ngeneration, Alpha base, Buildchain runtime and authority roots. A newer dev head\nis appended once as a rooted, non-invalidating observation. Repeated webhooks or\na restarted controller observing the same dev head reuse the existing\nobservation and do not change the candidate identity.\n\nA cancelled workflow run carries no qualification verdict, so a newer\ncancelled duplicate does not erase the prior completed verdict for the same\nworkflow and source SHA. Other non-success conclusions remain authoritative:\na newer failed, timed-out, skipped, or otherwise non-successful completed run\nstill excludes that SHA and forces the controller to fall back or fail closed.\n\nHistory discovery is bounded to the newest 1000 development commits. The\ncontroller then compares the selected SHA to the exact Alpha head before it can\nbe eligible, so a bounded scan cannot turn a commit outside the promotion\nancestry into a candidate.\n\nThe decision is `kungfu-buildchain-channel-candidate-decision/v1`. It records the\nsource and target branches and SHAs, comparison distance, workflow paths, run\nidentities and attempts, completion times, URLs, policy, and a canonical decision\nroot. Missing, stale, failed, duplicate, or source-mismatched evidence fails\nclosed as an auditable `blocked` or `stale` observation and cannot enter\nsettlement.\n\nThe companion state is\n`kungfu-buildchain-dev-alpha-candidate-state/v1`. Its current state is one of:\n\n- `observed`: no exact candidate is currently settleable;\n- `eligible-for-settlement`: a qualified candidate exists and no managed Alpha\n  candidate PR is active;\n- `active`: exactly one managed candidate PR is open;\n- `held`: the active Release Cut failed exact candidate, tree, Alpha-base,\n  runtime or route readback and cannot resume;\n- `superseded`: the embedded train contains a valid explicit supersession\n  transition;\n- `stale`: the available exact-SHA evidence pair is outside policy age; or\n- `blocked`: qualification or reconciliation failed closed.\n\nNew v4 states embed the complete `kungfu-buildchain-release-train/v1` record.\n`held` states include a rooted `kungfu-buildchain-release-train-hold/v1`\nreceipt with the expected cut and observed coordinates. Dev movement alone is\nnot an allowed supersession cause. Legacy markers remain readable by the core\ncontract, but the active-train workflow refuses to manufacture missing Release\nCut authority for an already-open legacy PR.\n\n## Reusable workflow\n\nCall `.github/workflows/dev-alpha-candidate-patrol.yml` from a thin repository\nworkflow. Start with `dry-run: true`. The reusable workflow always runs an\n`observe` job with only Actions/content/pull-request read permissions. Once the\nrepository has proven that its two workflow names and branch topology produce\nexact same-SHA evidence, it may set `settlement-authorized: true` and\n`dry-run: false`. The older `create-pull-request` input remains a compatibility\nalias for settlement authorization.\n\nRepositories whose promotion policy requires a machine-readable PR declaration\ncan pass static text through `pull-request-body-prefix`. When the declaration\ndepends on the exact qualified delta, use `pull-request-body-prefix-renderer`\ninstead. It names a repository-relative Node.js file in the consumer checkout.\nThe read-only `observe` job checks out the selected SHA with credentials disabled,\nruns the renderer with a reduced environment, and requires it to write UTF-8 text\nto `BUILDCHAIN_CHANNEL_PATROL_PR_BODY_PREFIX_OUTPUT`. The renderer also receives\nthe selected SHA plus source and target branch names. It may derive a declaration\nfrom the exact checkout and `origin/<target-branch>` without receiving the\npromotion token.\n\nStatic and rendered prefixes are mutually exclusive. A renderer failure, path\nescape, source-SHA mismatch, empty or oversized result, invalid UTF-8, or managed\ncontroller-marker injection fails before the write-permission job can run. The\nrendered bytes are retained with the read-only observation artifact and passed\nto `settle` as a job output, so the candidate PR is created with the correct\ndeclaration on its first write. Buildchain preserves that repository-owned text\nwhen later observations update only the managed state marker. Before any write,\n`settle` also requires its fresh observation to select the same SHA that produced\nthe rendered bytes. Concurrent qualification progress therefore fails closed\nand is recomputed by the next patrol instead of attaching a declaration to the\nwrong candidate.\n\nThe separately permissioned `settle` job checks out the exact Buildchain runtime\ncommit used by `observe`, re-runs the exact observation, and compare-and-swap\nchecks the selected SHA, prior controller root and Release Cut root before any\nwrite. With no active managed candidate, it reads the candidate tree and creates\none rooted Release Cut before it creates one branch named from\nthe target branch and the first 12 characters of the full source SHA. An\nexisting branch must point to the same full SHA or the run fails. With one\nactive managed candidate, it validates the candidate ref, tree, Alpha base and\nruntime before returning that same SHA to every checkout/build consumer. It only\nupdates the machine-readable state marker when a new dev observation or hold\nreceipt must be persisted. Repeated events and rapid dev progress cannot create\nanother candidate PR or another heavy candidate build. Foreign human-authored\nAlpha PRs are ignored. More than one open Buildchain-managed candidate fails\nclosed.\n\nThe PR body is the bounded durable controller state: it preserves the active\nRelease Train without introducing an always-on service. Once the active PR\nsettles, is explicitly superseded, or is abandoned, the next execution may\nrecompute current exact-SHA qualification and cut a new generation under the\nRelease Train contract. It never trusts a `workflow_run` trigger SHA as\nevidence.\n\nThe workflow exposes `train-root`, `cut-root`, `candidate-generation`,\n`candidate-tree-sha`, `runtime-sha`, `drift-root` and `hold-root` alongside the\nselected SHA. Alpha build orchestration should bind to those outputs and treat\na non-empty hold root as a fail-closed result.\n\nThe caller may additionally set `auto-merge: true` and choose `merge-method`\nfrom `merge`, `squash`, or `rebase`. Buildchain only arms GitHub auto-merge for\nthe single managed, open, exact-source candidate after the write-permission\nsettlement has revalidated the observation. GitHub still owns every required\nreview, required check, branch-protection, and merge-queue gate; Buildchain does\nnot approve or directly merge the PR. Invalid merge methods and GraphQL\nrefusals fail the patrol run.\n\nConsumers should invoke this workflow after relevant qualification workflow\ncompletion and from an offset periodic fallback. GitHub may delay scheduled\nruns, so the event path supplies low latency while the fallback supplies\nrecovery. Workflow concurrency plus the server-side open-PR reconciliation\nmakes duplicate or delayed events idempotent.\n\nThe workflow never moves the Alpha ref directly, directly merges the pull\nrequest, approves it, publishes npm, creates a Git tag or GitHub Release, or\nchanges branch protection. Optional auto-merge only registers repository-owned\nintent with GitHub; protected settlement remains authoritative."
    },
    {
      "id": "manual:dev-delivery-warrant",
      "title": "Dev Delivery Warrant Queue",
      "route": "/docs/dev-delivery-warrant",
      "category": "manual",
      "capabilityGroup": "getting-started",
      "audience": [
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "docs/dev-delivery-warrant.md",
      "digest": "sha256:0667f7a40c8abb37b91a9c0fa8c85a033c2b477bcba2d15cf70cd8528bb64a71",
      "headings": [
        {
          "level": 1,
          "title": "Dev Delivery Warrant Queue",
          "anchor": "dev-delivery-warrant-queue"
        },
        {
          "level": 2,
          "title": "Contract",
          "anchor": "contract"
        },
        {
          "level": 2,
          "title": "Split proof authority",
          "anchor": "split-proof-authority"
        },
        {
          "level": 2,
          "title": "CLI",
          "anchor": "cli"
        },
        {
          "level": 2,
          "title": "Workflow rollout and rollback",
          "anchor": "workflow-rollout-and-rollback"
        }
      ],
      "markdown": "---\nstatus: draft\nperiod: ongoing\ntheme: dev-delivery-warrant\ndoc_type: technical-reference\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-08-11\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-08-11\n  invisible_context: not asserted\n---\n\n# Dev Delivery Warrant Queue\n\nBuildchain's Dev Delivery Warrant Queue gives a qualified slow pull request a\ndurable, non-preemptive delivery turn without replacing GitHub Merge Queue as\nthe final protected-ref authority.\n\nThe queue is stored on a dedicated Git ref below\n`buildchain/dev-delivery-warrant/`. Every update creates a child Git commit and\nadvances the ref without force. The transition receipt binds the expected old\nstate root; a competing controller receives a visible non-fast-forward failure\ninstead of a second authority claim.\n\n## Contract\n\nA submission binds the repository, protected dev line, pull request, semantic\nsource identity, exact source head, native Assignment and Initiative roots,\nsource patch or tree intent, reusable Source Qualification Proof, plan,\naffected closure, dependencies, toolchain, delivery class, priority, attempts,\nand retained enqueue time.\n\nSelection is deterministic FIFO plus aging with bounded priority. Priority may\nreorder queued work, but it cannot preempt the active Warrant. Exactly one\ncandidate receives a leased Warrant containing a fencing token, lease\ngeneration, expected-old state root, expiry, and the complete exact source\nbinding. Heartbeat extends only that generation. Expiry recovery rejects the\nold token, retains queue age, and returns the candidate to selection.\n\nA terminal event may cancel a candidate before selection without minting a\nWarrant. This transition is limited to an exact non-active queued candidate and\nbinds its candidate root, pull request, recorded source head, event-observed\nsource head, terminal event action, evidence root, and expected-old queue root.\nAn active candidate still requires its current fencing token and lease\ngeneration. Exact duplicate cancellation evidence is a visible no-op; identity,\nstate, event, or evidence drift fails closed.\n\nThe reusable terminal controller uses one `settle` operation for active,\nqueued, already-terminal, and never-admitted pull requests. An active Warrant\nstill requires its exact fence and evidence. A matching queued cancellation is\npersisted normally. A duplicate terminal event or a pull request that never\nentered Warrant authority returns a rooted explicit no-op instead of failing\nthe workflow or inventing queue state.\n\nThe supported priority classes are `ordinary`, `expedited`, and `emergency`.\nThe queue does not infer an emergency: callers must choose it explicitly under\ntheir reviewed policy. Delivery classes are `non-native-fast`,\n`native-proof-required`, `cross-platform`, and `release`.\n\nA release-blocker candidate may additionally carry a rooted priority claim\ncreated from a settled Release Train dual landing. The claim binds the exact\nAssignment, Initiative, repair, prior and successor cuts, candidate generation,\ncut candidate, Dev head, semantic patch, both landing evidence roots, and\npublication gate. Only a claim whose repository, protected base, Work roots,\nhead, patch, and claim root match the queued candidate enters the blocker lane.\nThat lane outranks not-yet-leased ordinary work, but never preempts or rewrites\nan active Warrant; unrelated, conflicted, mismatched, or fabricated claims fail\nclosed before selection.\n\n## Split proof authority\n\nSource Qualification Proof is independent of the moving dev base. It binds the\nsemantic source, exact source head and patch/tree intent, plan, affected\nclosure, dependencies, toolchain, covered paths, and shard evidence.\n\nBefore reuse, the consumer classifies the dev delta:\n\n- unchanged roots plus an unrelated attributed delta reuse source\n  qualification and run only a cheap Project Cut replay. GitHub's `behind`\n  state is accepted only when a rooted replay proof binds the exact current\n  protected base, unchanged PR head and source patch, replay tree, required\n  context roots, and a qualified `project.cut.merge-queue-admission/v1`\n  receipt;\n- an overlapping delta reruns the affected source shards;\n- an unknown graph or changed source, plan, closure, dependency, or toolchain\n  root fails closed to full source qualification.\n\nIntegration Delivery Proof is separate and cannot be cached across candidates.\nIt binds the exact current dev base, replay tree, GitHub `merge_group` head and\ntree, active Warrant fencing generation, Source Qualification Proof root, and\nfinal required-context roots. GitHub's exact merge-group checks remain the\nfinal integration authority.\n\n## CLI\n\nQueue commands are dry-run by default:\n\n```sh\nbuildchain dev warrant submit --repository owner/repository \\\n  --branch dev/v4/v4.0 --pull-request 123 --source-head <sha> \\\n  --assignment-root <root> --initiative-root <root> \\\n  --source-identity-root <root> --source-patch-root <root> \\\n  --source-proof-root <root> --plan-root <root> --closure-root <root> \\\n  --dependency-root <root> --toolchain-root <root> \\\n  --delivery-class native-proof-required\n\nbuildchain dev warrant select --repository owner/repository \\\n  --branch dev/v4/v4.0 --execute\n\nbuildchain dev warrant cancel-queued --repository owner/repository \\\n  --branch dev/v4/v4.0 --candidate-id <root> --pull-request 123 \\\n  --expected-source-head <queued-sha> --observed-source-head <event-sha> \\\n  --expected-old <queue-root> --event-action closed --outcome cancelled \\\n  --evidence-root <terminal-event-root> --execute\n```\n\n`heartbeat`, `recover`, `close`, `settle`, `cancel-queued`, and `observe` use the same durable authority.\nWarrant-scoped mutations require the exact fencing token and lease generation.\n`close` also requires a rooted terminal evidence object.\n\nOn the v4 preview line, `observe` alone has an explicit `--read-mode v4`\ncandidate. It requires a retained exact semantic-diff qualification and source\nbinding, invokes an effect-disabled Rust state projection, retains parity\nevidence, and returns the existing v3 observation shape. The default and\nrollback mode is `v3`; mutation commands ignore the read switch. See\n[`v4-delivery-warrant-read-candidate.md`](v4-delivery-warrant-read-candidate.md).\n\nProof commands create, verify, classify, and compose the two proof layers:\n\n```sh\nbuildchain dev proof source ...\nbuildchain dev proof classify --source-proof source-proof.json ...\nbuildchain dev proof replay ...\nbuildchain dev proof replay-proof \\\n  --qualification-receipt project-cut-admission.json ...\nbuildchain dev proof integration --warrant-result warrant.json ...\n```\n\n## Workflow rollout and rollback\n\nThe reusable `dev-pr-auto-merge.yml` supports three explicit rollout modes:\n\n- `off` preserves the previous exact-head admission controller;\n- `shadow` qualifies the source and emits a read-only queue submission plan;\n- `required` persists the submission, selects the Warrant, and refuses GitHub\n  enqueue unless the immutable queue commit, state root, active Warrant, and\n  selected candidate all pass exact readback validation.\n\nConsumers should deploy `shadow` first, inspect receipts, then change their\nprotected caller to `required`. Rollback is a reviewed caller change back to\n`off`; it does not delete queue history or reinterpret old receipts. The\nterminal reusable workflow creates the exact Integration Delivery Proof for a\nmerged candidate (or accepts explicit evidence for another terminal outcome),\nthen closes only the current fencing generation. The separate queued\ncancellation reusable workflow cannot close an active generation; it advances\nthe state ref only when the caller's complete terminal binding and expected-old\nroot still match.\n\nBuildchain uses the same contract for its own protected dev line through\n`buildchain-dev-delivery.yml`. The manual caller requires the exact PR head and\nall native/source proof roots, pins the runtime to the caller commit, selects\n`delivery-warrant-mode: required`, and targets GitHub Merge Queue. It does not\noffer an `off` switch: rollback is a reviewed change to this caller, not an\noperator-time weakening of a specific delivery attempt.\n\nThis mechanism schedules protected delivery only. It does not serialize local\ndevelopment, source-only checks, unrelated channels, release publication, or\nrunner provisioning. It never grants authority to enable cloud runner\ncampaigns."
    },
    {
      "id": "manual:dev-qualification-patrol",
      "title": "Dev Qualification Patrol",
      "route": "/docs/dev-qualification-patrol",
      "category": "manual",
      "capabilityGroup": "governance-versioning",
      "audience": [
        "release-operator",
        "consumer",
        "agent"
      ],
      "maturity": "preview",
      "sourcePath": "docs/dev-qualification-patrol.md",
      "digest": "sha256:656298caae798479653f2b46c4d4dad684fdbcc67c3ffa384f436339434fbe21",
      "headings": [
        {
          "level": 1,
          "title": "Dev Qualification Patrol",
          "anchor": "dev-qualification-patrol"
        },
        {
          "level": 2,
          "title": "Exact-source and priority contract",
          "anchor": "exact-source-and-priority-contract"
        },
        {
          "level": 2,
          "title": "Bounded local retry",
          "anchor": "bounded-local-retry"
        },
        {
          "level": 2,
          "title": "Permission and mutation boundary",
          "anchor": "permission-and-mutation-boundary"
        }
      ],
      "markdown": "---\nstatus: preview\nperiod: ongoing\ntheme: dev-qualification-patrol\ndoc_type: architecture-and-usage\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: self-reviewed\nlast_reviewed: 2026-08-03\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-08-03\n  visible_context: Existing Buildchain Shifu Gate receipts, Kungfu Dev Patrol, Alpha preflight, candidate patrol, and GitHub failed-job rerun semantics.\n  invisible_context_boundary: No credentials, private logs, or private configuration were used.\n---\n\n# Dev Qualification Patrol\n\nBuildchain provides a reusable controller for repositories whose development\nbranch advances faster than a heavy cross-platform qualification workflow can\nsettle. The controller keeps no external queue. On every wakeup it derives the\nonly pending item from the current source-branch head and maintains these\nstates:\n\n- `qualified`: the current source SHA already has a successful Dev run;\n- `running`: one Dev run is active, with a different current SHA retained as\n  the implicit latest pending item;\n- `waiting-preflight`: the current SHA has not passed its lightweight exact-SHA\n  preflight;\n- `waiting-priority`: a declared Alpha or release workflow is queued or active;\n- `dispatch-ready`: the latest SHA is preflight-qualified and no Dev or\n  priority run is active;\n- `retry-ready`: the latest exact-SHA Dev run failed only at a classified\n  external boundary and remains inside the attempt limit; or\n- `blocked`: the failure was deterministic, unknown, or exhausted its bounded\n  retry policy.\n\nThis is an event-driven, coalescing controller rather than a FIFO build queue.\nIf ten commits arrive during one slow Dev run, the next reconciliation observes\nonly the newest branch head. Intermediate unqualified SHAs are superseded\nwithout consuming the shared native runners.\n\n## Exact-source and priority contract\n\nCall `.github/workflows/dev-qualification-patrol.yml` from a thin consumer\nworkflow after the lightweight preflight, Dev Patrol, and declared priority\nworkflows complete. Add an offset schedule as recovery for delayed or missed\nGitHub events. Repeated wakeups are idempotent.\n\nThe controller requires a successful preflight whose `head_sha` equals the\ncurrent source head. It dispatches the heavy workflow on the source branch and\nadds a controller-owned `source-sha` input. The consumer must reject the run\nbefore qualification if that input differs from the workflow event SHA. This\ncloses the race where the branch advances between observation and workflow\nstartup. The heavy reusable Gate workflow then receives the exact SHA as its\n`source-ref`, so every platform receipt remains source-bound.\n\n`priority-workflows-json` is a JSON array of workflow paths. Any queued,\nwaiting, pending, requested, or in-progress run in those workflows prevents a\nnew Dev dispatch or automatic retry. This lets Alpha and release work keep\npriority on shared self-hosted runners. A successful current Dev result remains\nqualified even when priority work is active; priority only governs new heavy\nwork.\n\n## Bounded local retry\n\nThe controller uses GitHub's failed-jobs rerun endpoint, not a fresh workflow\ndispatch, for classified transient failures. Successful matrix jobs and their\nexact-source receipts remain in the same workflow-run transaction. Failed jobs\nand dependent aggregation run again. The Shifu Gate profile uploads platform,\ndiagnostic, aggregate, and controller artifacts with overwrite enabled so a\nlater attempt can replace only the same-run artifact names.\n\nAutomatic retry is deliberately narrow:\n\n- whole-run `cancelled`, `timed_out`, or `startup_failure` conclusions qualify;\n- checkout, setup, toolchain, download, upload, environment exposure, and\n  runner-workspace reset steps qualify;\n- Gate execution, Gate enforcement, aggregation, and controller-receipt\n  failures never qualify; and\n- an unknown failing step fails closed.\n\n`max-attempts` counts the original attempt. The default `2` therefore permits\nat most one automatic failed-jobs rerun. This policy reduces retry friction for\nnetwork, runner, and provider failures without laundering a product or Gate\nfailure into an infrastructure retry.\n\n## Permission and mutation boundary\n\nThe reusable workflow always performs `observe` with Actions and contents read\npermissions. The separate `mutate` job runs only when the observation proposes\n`dispatch` or `rerun-failed-jobs`, `mutation-authorized` is true, and `dry-run`\nis false. Before writing, it re-resolves the branch and all workflow state and\nrequires the action and source SHA to match the read-only observation. A race\nfails closed and the next event recomputes from current truth.\n\nStart a consumer in dry-run mode. Its observation and mutation decisions are\nretained as exact-source artifacts with a canonical decision root. Enabling\nmutation requires a repository token that can write Actions; no contents,\npull-request, tag, release, package, or publication permission is used.\n\nThe controller does not merge a PR, publish an Alpha, create a tag, create a\nrelease, or settle a Release Passport. Once Dev and Alpha preflight evidence\nboth succeed for one SHA, the separate\n[Dev to Alpha Candidate Patrol](dev-alpha-candidate-patrol.md) may select it."
    },
    {
      "id": "manual:engineering-housekeeper",
      "title": "Engineering Housekeeper",
      "route": "/docs/engineering-housekeeper",
      "category": "manual",
      "capabilityGroup": "governance-versioning",
      "audience": [
        "maintainer",
        "consumer",
        "agent"
      ],
      "maturity": "preview",
      "sourcePath": "docs/engineering-housekeeper.md",
      "digest": "sha256:7e515db156ff7725fab08db051ea70097c7c5324239531fc80f3e701564d007c",
      "headings": [
        {
          "level": 1,
          "title": "Engineering Housekeeper",
          "anchor": "engineering-housekeeper"
        },
        {
          "level": 2,
          "title": "Report mode",
          "anchor": "report-mode"
        },
        {
          "level": 2,
          "title": "Apply mode",
          "anchor": "apply-mode"
        },
        {
          "level": 2,
          "title": "Inputs and outputs",
          "anchor": "inputs-and-outputs"
        },
        {
          "level": 2,
          "title": "Caller-owned authentication",
          "anchor": "caller-owned-authentication"
        },
        {
          "level": 2,
          "title": "Scheduled callers",
          "anchor": "scheduled-callers"
        }
      ],
      "markdown": "---\nstatus: preview\nperiod: ongoing\ntheme: engineering-housekeeper\ndoc_type: operational-contract\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: reviewed\nlast_reviewed: 2026-08-10\n---\n\n# Engineering Housekeeper\n\nEngineering Housekeeper is a reusable GitHub workflow for evidence-backed\nbranch and pull-request hygiene. It inventories the complete GitHub branch and\nopen pull-request surfaces, discovers the repository default branch and all\nprotected version/release mainlines, and produces a rooted plan. The reusable\nworkflow defaults to report-only execution; a repository may opt its scheduled\ncallers into unattended apply. It never closes pull requests and never deletes\na branch from its name alone.\n\nBranch deletion uses a positive allowlist. Only `feature/**`, `fix/**`,\n`chore/**`, `docs/**`, `ci/**`, and `refactor/**` are temporary development\nfamilies by default. Unknown families are inventoried and retained, even when\ntheir heads are already ancestors of a mainline.\n\nThe reusable entrypoint is:\n\n```yaml\nuses: kungfu-systems/buildchain/.github/workflows/engineering-housekeeper.yml@v4\n```\n\nThe v4 surface is a traceable forward-port of protected v3 merge\n`c9d53c69e90393b2178ad7cdbf00f17e403e17f9` and exact source\n`518990c4118a12562eb9847cb2e1b704983909a0`. It preserves the same `v1`\ncontract, temporary-family allowlist, provider adapter, mutation fences, and\nevidence roots. The v4 manifest records that TypeScript remains the sole\nlegacy-authoritative writer; the forward-port does not create another contract\nor provider authority. Existing v3 callers retain their original interface.\n\n## Report mode\n\n`report` is the default. The caller grants only read permissions and receives\nseparate plan, Markdown report, and dry-run receipt artifacts:\n\n```yaml\njobs:\n  housekeeper:\n    uses: kungfu-systems/buildchain/.github/workflows/engineering-housekeeper.yml@v4\n    permissions:\n      contents: read\n      pull-requests: read\n    with:\n      mode: report\n```\n\nWith no `target-branch`, the plan uses the repository default as its primary\ntarget and discovers every provider-protected or protected-pattern-matching\nmainline repository-wide. Each eligible temporary branch is bound to the exact\nmainline OID that proves it merged. The plan also records every observed branch\nand open pull request, each retain/delete/report/label decision, and stable\nreason codes. The report receipt records dry-run outcomes and binds them to the\nplan root.\n\nTo keep complete-repository patrols within normal GitHub API budgets, the\nengine paginates closed pull requests once, indexes merged associations by the\nexact source branch and OID, and then prioritizes the matching base without a\nper-branch association request. Exact ancestry comparisons run with a fixed\nmaximum of eight concurrent requests while preserving deterministic branch\nordering. A temporary branch without an exact same-repository, same-name,\nsame-OID merged pull request association is retained and reported without\nancestry requests. The association is only a candidate selector: the source\nOID must still be an ancestor of the selected mainline OID. This matches the\nprotected-mainline delivery contract and keeps ambiguous or direct historical\nrefs fail-closed.\n\n## Apply mode\n\nMutation has a two-part positive gate. The caller must set both `mode: apply`\nand `apply-enabled: true`; either value alone fails closed. Apply jobs consume\nthe uploaded exact plan, re-read provider state, and revalidate exact branch\nand target OIDs, ancestry, protection, retention, active pull requests, rename\nstate, pull-request state, and staleness before each mutation.\nThese are reusable-workflow contract inputs, not an interactive approval step.\nAn unattended scheduled caller can set both values in committed policy.\n\n```yaml\njobs:\n  housekeeper:\n    uses: kungfu-systems/buildchain/.github/workflows/engineering-housekeeper.yml@v4\n    permissions:\n      contents: write\n      pull-requests: write\n    with:\n      mode: apply\n      apply-enabled: true\n      stale-pull-request-label: stale-housekeeping\n      max-actions: 10\n```\n\nBranch deletion and pull-request labeling run in separate jobs. The branch job\nhas `contents: write` plus `pull-requests: read` for the final active-PR fence.\nThe labeling job has `contents: read` and `pull-requests: write`. Inventory is a\nseparate read-only job. The reusable workflow declares no workflow-level write\npermission.\n\nThe action limit applies to the globally ordered plan before actions are split\nby permission surface. A race, missing branch, advanced head, target movement,\nnew pull request, new protection, ambiguous ancestry, provider error, or stale\nplan/input mismatch is an explicit receipt outcome rather than permission to\ncontinue.\n\n## Inputs and outputs\n\n| Input                       | Type    | Default                     | Contract                                                                          |\n| --------------------------- | ------- | --------------------------- | --------------------------------------------------------------------------------- |\n| `repository`                | string  | caller repository           | Exact `owner/repo` target.                                                        |\n| `target-branch`             | string  | empty                       | Optional primary target; empty discovers all protected mainlines repository-wide. |\n| `mode`                      | string  | `report`                    | `report` or `apply`. Other values fail.                                           |\n| `apply-enabled`             | boolean | `false`                     | Required positive gate for `apply`. Invalid with `report`.                        |\n| `protected-patterns`        | string  | version/release families    | Comma or newline separated branch globs.                                          |\n| `retained-patterns`         | string  | train/authority families    | Comma or newline separated retention globs.                                       |\n| `temporary-branch-patterns` | string  | six development families    | Positive allowlist; unmatched branch families are always retained.                |\n| `stale-days`                | number  | `30`                        | Positive stale pull-request age.                                                  |\n| `stale-pull-request-label`  | string  | empty                       | Empty keeps pull requests report-only; non-empty permits labeling, never closure. |\n| `max-actions`               | number  | `20`                        | Positive global apply limit.                                                      |\n| `artifact-retention-days`   | number  | `30`                        | Retention for plan, report, and receipts.                                         |\n| `buildchain-repository`     | string  | `kungfu-systems/buildchain` | Runtime source repository.                                                        |\n| `buildchain-ref`            | string  | `v4`                        | Runtime ref; trusted qualification may pass a train or exact SHA.                 |\n\nStable outputs are `plan-root`, `report-receipt-root`, optional\n`branch-receipt-root` and `pull-request-receipt-root`, `action-count`,\n`outcome`, and the plan/report/default-receipt artifact names. Apply receipts\nare uploaded under the same caller-selected artifact prefix with branch and\npull-request scope names.\n\nArtifacts and job summaries contain exact repository coordinates, observed\nrefs, decisions, reason codes, outcomes, and semantic roots. They never contain\ntokens, application private keys, or authorization headers.\n\n## Caller-owned authentication\n\nThe default credential is the caller-scoped `github.token`. A caller may pass\nan alternative token as `github_token`, or pass the paired `github_app_id` and\n`github_app_private_key` secrets to mint an installation token for the exact\ntarget repository. The workflow contains no repository-specific personal\ncredential name or value.\n\nGitHub App credentials must be supplied as a pair. The caller owns App\ninstallation and permission policy and should grant only repository contents\nread/write and pull-request read/write scopes required by its selected mode.\nSecrets are used only as step environment or action inputs and are not written\nto plans, reports, receipts, summaries, or artifacts.\n\n## Scheduled callers\n\nBuildchain dogfoods the reusable contract through three thin callers:\n\n- `engineering-housekeeper-daily.yml` uses a 30-day window and a 10-action cap;\n- `engineering-housekeeper-weekly.yml` uses a 45-day window and a 20-action cap;\n- `engineering-housekeeper-monthly.yml` uses a 60-day window and a 50-action cap.\n\nAll three schedules run unattended apply with repository-wide mainline\ndiscovery. They delete only exact merged heads from the positive temporary\nbranch allowlist and automatically add `engineering-housekeeper:stale` to stale\nopen pull requests; they never close a pull request. Manual dispatch remains a\ndiagnostic interface, not a prerequisite for scheduled execution. Each caller\nuses the exact scheduling commit as its runtime, so activation never waits for a\nfloating runtime ref to catch up. The callers contain schedules and policy\nvalues only; inventory, planning, revalidation, mutation, evidence, and\nauthentication stay in the reusable workflow and its runtime.\n\nIf a deleted merged branch must be restored during artifact retention, use the\nrecorded `expectedHeadOid` and branch name from the rooted plan to recreate the\nref with a normal non-force push. A rejected or provider-error receipt means no\nsuccessful deletion should be inferred; re-run report mode against current\nprovider state before taking recovery action."
    },
    {
      "id": "manual:getting-started",
      "title": "Buildchain Golden Path",
      "route": "/docs/getting-started",
      "category": "manual",
      "capabilityGroup": "getting-started",
      "audience": [
        "consumer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "docs/getting-started.md",
      "digest": "sha256:72adec660d001a3fb77cd990f2bacdb6f46c8eb4927533d408c3755dab02a94e",
      "headings": [
        {
          "level": 1,
          "title": "Buildchain Golden Path",
          "anchor": "buildchain-golden-path"
        },
        {
          "level": 2,
          "title": "1. Create a clean consumer and install an exact version",
          "anchor": "1-create-a-clean-consumer-and-install-an-exact-version"
        },
        {
          "level": 2,
          "title": "2. Choose the project type and initialize",
          "anchor": "2-choose-the-project-type-and-initialize"
        },
        {
          "level": 2,
          "title": "3. Validate the local contract",
          "anchor": "3-validate-the-local-contract"
        },
        {
          "level": 2,
          "title": "4. Inspect the reusable workflow and release dry-run",
          "anchor": "4-inspect-the-reusable-workflow-and-release-dry-run"
        },
        {
          "level": 2,
          "title": "5. Create and inspect a local Release Passport example",
          "anchor": "5-create-and-inspect-a-local-release-passport-example"
        },
        {
          "level": 2,
          "title": "You are done when",
          "anchor": "you-are-done-when"
        },
        {
          "level": 2,
          "title": "Choose the next manual",
          "anchor": "choose-the-next-manual"
        },
        {
          "level": 2,
          "title": "Troubleshooting",
          "anchor": "troubleshooting"
        },
        {
          "level": 2,
          "title": "Small glossary",
          "anchor": "small-glossary"
        }
      ],
      "markdown": "---\nstatus: active\nperiod: ongoing\ntheme: buildchain-golden-path\ndoc_type: technical-guide\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: self-reviewed\nlast_reviewed: 2026-08-01\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-08-01\n  invisible_context: not asserted\n---\n\n# Buildchain Golden Path\n\nThis path is for a repository maintainer adopting Buildchain for the first\ntime. It takes about 15–30 minutes and ends with five inspectable outcomes: an\nexact package pin, a declared project type, a valid local configuration, a thin\nreusable workflow caller, and a Release Passport inspection.\n\nUse this page for the first successful pass. Move to the advanced manuals only\nafter the local checks below are green.\n\n## 1. Create a clean consumer and install an exact version\n\n```bash\nconsumer_dir=\"$(mktemp -d)\"\ncd \"$consumer_dir\"\nnpm init -y\nbuildchain_version=\"$(npm view @kungfu-tech/buildchain version)\"\npnpm add -D \"@kungfu-tech/buildchain@$buildchain_version\"\npnpm exec buildchain --version\n```\n\nThe package manager records the exact resolved version in `package.json` and\nthe lockfile. Review that version before committing it; do not leave a floating\nrange in a release repository.\n\n## 2. Choose the project type and initialize\n\nStart with `package` for a Node package. Other supported types are `native`,\n`web-surface`, `infra-contract`, `publication-artifact`, and\n`anchored-package`.\n\n```bash\npnpm exec buildchain init --type package --package-manager pnpm\n```\n\nInspect the two generated files before continuing:\n\n```bash\nsed -n '1,220p' .buildchain/buildchain.toml\nsed -n '1,220p' .github/workflows/build.yml\n```\n\n`buildchain.toml` owns repository lifecycle declarations. The workflow is a\nthin caller of Buildchain's reusable workflow; it is not a second release\nimplementation.\n\n## 3. Validate the local contract\n\n```bash\npnpm exec buildchain validate \\\n  --require-version-state \\\n  --require-lifecycle-stages install,build,verify\npnpm exec buildchain doctor --json\n```\n\nIf the generated lifecycle commands do not match the repository, edit only\n`.buildchain/buildchain.toml`, then rerun both checks. See\n[Lifecycle Protocol](lifecycle-protocol.md) for the normative fields.\n\n## 4. Inspect the reusable workflow and release dry-run\n\nThe generated caller should contain one reusable `uses:` edge and a manual\n`buildchain-ref` input for bounded train validation:\n\n```bash\nrg -n 'uses:|buildchain-ref:' .github/workflows/build.yml\npnpm exec buildchain release --dry-run \\\n  --target-ref alpha/v4/v4.0 \\\n  --json\n```\n\nThe dry-run explains legal source refs, tags, version state, and publication\neffects. It does not move refs, edit files, or publish packages.\n\n## 5. Create and inspect a local Release Passport example\n\nThis example creates a source-bound local Passport through the public Node API,\nthen reads it through the CLI. It is learning evidence, not publication\nauthority.\n\n```bash\nmkdir -p .buildchain/golden-path\nnode --input-type=module <<'EOF'\nimport fs from \"node:fs\";\nimport { createReleasePassport } from \"@kungfu-tech/buildchain\";\n\nconst passport = createReleasePassport({\n  repository: \"example/consumer\",\n  tag: \"v0.1.0-alpha.0\",\n  sourceSha: \"a\".repeat(40),\n  assets: [{ name: \"consumer.tgz\", sha256: \"b\".repeat(64) }],\n});\nfs.writeFileSync(\n  \".buildchain/golden-path/buildchain.release.json\",\n  `${JSON.stringify(passport, null, 2)}\\n`,\n);\nEOF\n\npnpm exec buildchain inspect release \\\n  --passport .buildchain/golden-path/buildchain.release.json \\\n  --json\n```\n\nFor a real release, the protected Buildchain workflow creates the Passport from\nthe exact source, artifact, controller, and publication evidence. See\n[Release Passport](release-passport.md); do not promote this local example.\n\n## You are done when\n\n- the dependency and lockfile contain one exact Buildchain version;\n- `.buildchain/buildchain.toml` declares the intended project type and lifecycle;\n- `validate` and `doctor` succeed;\n- `.github/workflows/build.yml` remains a thin reusable-workflow caller;\n- the release dry-run and local Passport inspection both return structured output.\n\nThe repository test `pnpm run check:golden-path` reproduces this path in a new\ntemporary consumer using the locally packed Buildchain package.\n\n## Choose the next manual\n\n| Intent | Next page |\n| --- | --- |\n| Change lifecycle commands or version files | [Lifecycle Protocol](lifecycle-protocol.md) |\n| Configure native matrices, runners, caches, or artifacts | [Reusable Build Surface](reusable-build-surface.md) |\n| Look up a command | [Generated CLI Reference](cli-reference.md) |\n| Import the Node toolkit | [Generated Node API Reference](node-api-reference.md) |\n| Understand protected branches and tags | [Release Flow](release-flow.md) |\n| Verify published evidence | [Release Passport](release-passport.md) |\n\n## Troubleshooting\n\n- `already exists`: initialization is no-overwrite by default. Inspect the\n  existing files; use `--force` only for an intentional replacement.\n- missing lifecycle stage: add the named stage to\n  `.buildchain/buildchain.toml`; do not weaken the validation command.\n- package release-age policy: add a temporary, package-and-version-specific\n  `minimumReleaseAgeExclude`, then remove it after the normal window.\n- unsure about syntax: run `buildchain <path> --help`. Help is intercepted\n  before command dispatch and is side-effect free at every governed path.\n\n## Small glossary\n\n- **project type**: the repository shape selected by `buildchain init`.\n- **lifecycle**: repository-owned install, build, verify, and publish commands.\n- **reusable workflow**: Buildchain-owned GitHub Actions control plane called by\n  a thin consumer workflow.\n- **Release Passport**: source- and artifact-bound release evidence, not a\n  release trigger.\n- **train ref**: a temporary validation runtime; never a production dependency."
    },
    {
      "id": "manual:github-artifact-attestation",
      "title": "GitHub-native Linux Artifact Attestation",
      "route": "/docs/github-artifact-attestation",
      "category": "manual",
      "capabilityGroup": "release-passport-trust",
      "audience": [
        "release-operator",
        "agent"
      ],
      "maturity": "preview",
      "sourcePath": "docs/github-artifact-attestation.md",
      "digest": "sha256:51f28b0b01fae4e3f80a7433f6c491d0c795bd091bff64ca1264c5cc0819c545",
      "headings": [
        {
          "level": 1,
          "title": "GitHub-native Linux Artifact Attestation",
          "anchor": "github-native-linux-artifact-attestation"
        },
        {
          "level": 2,
          "title": "Trust Boundary",
          "anchor": "trust-boundary"
        },
        {
          "level": 2,
          "title": "Non-circular Passport Binding",
          "anchor": "non-circular-passport-binding"
        },
        {
          "level": 2,
          "title": "GitHub Permissions and Runtime Pins",
          "anchor": "github-permissions-and-runtime-pins"
        },
        {
          "level": 2,
          "title": "Prepare the Release Passport",
          "anchor": "prepare-the-release-passport"
        },
        {
          "level": 2,
          "title": "Verify Online and Offline",
          "anchor": "verify-online-and-offline"
        },
        {
          "level": 2,
          "title": "Qualification Policy",
          "anchor": "qualification-policy"
        }
      ],
      "markdown": "---\nstatus: draft\nperiod: 2026-07\ntheme: buildchain-linux-artifact-provenance\ndoc_type: protocol\nsource_level: code-and-official-docs\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-07-24\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-24\n  visible_context: Buildchain source, tests, GitHub Actions documentation, and actions/attest documentation\n  invisible_context: Model internals and provider-side implementation details are not visible\n---\n\n# GitHub-native Linux Artifact Attestation\n\nBuildchain can bind a Linux release artifact to its original compiler run, exact\nsource revision, platform manifest, Release Passport, and an immutable\nBuildchain attester workflow. GitHub's OIDC identity and artifact attestation\nservice provide the keyless signature; Buildchain provides the release contract\nand fail-closed local verification.\n\nThis capability proves provenance and integrity. It does not prove that source\ncode is safe, that a compiler was uncompromised, or that a self-hosted build\nrunner had no privileged observer.\n\n## Trust Boundary\n\nThe original Linux runner remains the compiler identity. The reusable attester\nruns on `ubuntu-24.04` only after the artifact, platform manifest, and Release\nPassport have been sealed and uploaded. It downloads those files as data and\nnever checks out or executes consumer source.\n\nThe attester checks out only\n`actions/github-artifact-attestation` from an exact Buildchain commit. It\nrejects a floating Buildchain ref, a different caller repository, a different\nsource SHA, a different workflow run, a non-Linux platform manifest, or a\nsubject digest absent from the Release Passport.\n\nThe protected Environment defaults to `buildchain-artifact-attestation`.\nConsumer repositories should require review or restrict deployment branches on\nthat Environment when their release policy requires an independent gate.\n\n## Non-circular Passport Binding\n\nThe Release Passport first records\n`githubArtifactAttestations[]`, an immutable expected-attestation policy:\n\n- artifact name, relative path, byte size, and SHA-256;\n- caller repository, source commit, and source tree;\n- original Linux platform and platform-manifest digest; the initial v3 contract\n  requires the runner receipt root to equal that exact manifest digest;\n- Buildchain signer workflow path and exact signer-bootstrap commit;\n- exact Buildchain runtime commit used to build and release the artifact;\n- exact GitHub permission set.\n\nThe GitHub attestation predicate then records the completed Release Passport\nfile digest. The returned attestation id, URL, Sigstore bundle digest, and\npredicate root are written to a separate\n`buildchain.github-artifact-attestation-evidence/v1` document. Keeping dynamic\nprovider evidence outside the Passport avoids a self-referential hash while\nstill binding both directions.\n\n## GitHub Permissions and Runtime Pins\n\nBoth caller and reusable workflow grant only:\n\n```yaml\npermissions:\n  actions: read\n  artifact-metadata: write\n  attestations: write\n  contents: read\n  id-token: write\n```\n\nThe reusable workflow pins `actions/checkout`, `actions/download-artifact`,\n`actions/upload-artifact`, and `actions/attest` by full commit SHA. The workflow\nitself must also be called at its exact signer-bootstrap commit. The signer\ncommit and the later Buildchain runtime commit are separately bound so the\nfirst v3 integration never relies on a mutable or self-referential workflow ref.\n\n## Prepare the Release Passport\n\nCreate one input document for each Linux artifact and seal it as a policy:\n\n```bash\nbuildchain create github-artifact-attestation-policy \\\n  --input-json .buildchain/github-artifact-attestation/policy-input.json \\\n  --output .buildchain/github-artifact-attestation/policy.json\n```\n\nThe input object contains `subject`, `caller`, `signer`, and `build` objects.\nThe CLI computes no trusted values implicitly: the caller supplies the already\nmeasured subject size/digest, source commit/tree, platform-manifest digest,\nrunner receipt root, and exact Buildchain workflow commit.\n\nPass the policy into Release Passport collection:\n\n```bash\nbuildchain collect github-release \\\n  --github-artifact-attestation-policy-json \\\n    .buildchain/github-artifact-attestation/policy.json \\\n  --output-dir .buildchain/release-passport \\\n  # ...the existing release inputs\n```\n\nThe build, Passport, and attestation jobs must stay in the same workflow run.\nThe release-candidate build declares both the subject and the already-merged\nsigner bootstrap commit. The Buildchain runtime remains the exact runtime ref\nused by the build workflow and may be a later commit:\n\n```yaml\nwith:\n  github-artifact-attestation-subject-path: dist/kungfu-linux-x64.tar.gz\n  github-artifact-attestation-signer-sha: <exact-signer-bootstrap-sha>\n  github-artifact-attestation-platform-id: linux-x64\n```\n\nFor release promotion, prefer the integrated v3 route. The policy must already\nbe present in the downloaded release-candidate payload:\n\n```yaml\npermissions:\n  actions: write\n  artifact-metadata: write\n  attestations: write\n  checks: write\n  contents: write\n  id-token: write\n  issues: write\n\njobs:\n  promote:\n    uses: kungfu-systems/buildchain/.github/workflows/release-candidate-promote.yml@<exact-buildchain-v3-runtime-sha>\n    with:\n      buildchain-ref: <exact-buildchain-v3-runtime-sha>\n      github-release: true\n      release-passport: true\n      github-artifact-attestation-policy-json: .buildchain/release-candidate/payload/<artifact>/policy.json\n      github-artifact-attestation-environment: buildchain-artifact-attestation\n```\n\nPromotion binds the policy into the Passport, stages only digest-matching data,\ncalls the exact v3 signer, verifies the provider identity a second time, and\npublishes immutable bundle, predicate, verification, evidence, and receipt\nassets beside the release artifact. A same-name Release asset with different\nbytes is rejected instead of overwritten.\n\nLow-level callers may call the reusable attester directly after their Passport\njob. Both the reusable workflow ref and `buildchain-ref` use the same exact\n40-hex signer-bootstrap commit and fail closed if the provider identity differs:\n\n```yaml\njobs:\n  attest-linux:\n    needs: [build-linux, release-passport]\n    permissions:\n      actions: read\n      artifact-metadata: write\n      attestations: write\n      contents: read\n      id-token: write\n    uses: kungfu-systems/buildchain/.github/workflows/github-artifact-attestation.yml@<exact-signer-bootstrap-sha>\n    with:\n      buildchain-ref: <exact-signer-bootstrap-sha>\n      evidence-run-id: ${{ github.run_id }}\n      source-sha: ${{ github.sha }}\n      subject-artifact-name: linux-release\n      subject-relative-path: libnode-linux-x64.tar.gz\n      platform-manifest-artifact-name: linux-platform-manifest\n      platform-manifest-relative-path: manifest.json\n      release-passport-artifact-name: release-passport\n      release-passport-relative-path: buildchain.release.json\n      policy-json: ${{ needs.release-passport.outputs.github-attestation-policy-json }}\n      evidence-artifact-name: linux-attestation-evidence\n```\n\n## Verify Online and Offline\n\nThe Buildchain verifier reconstructs exact `gh attestation verify` arguments\nfrom the policy, including repository, signer workflow, signer digest, source\ndigest, predicate type, and self-hosted-runner denial. It then verifies the\nlocal artifact, platform manifest, Release Passport, retained Sigstore bundle,\ncustom predicate, and Buildchain evidence root:\n\nThe reusable workflow runs that same exact signer/source verification\nimmediately after `actions/attest` and before it finalizes or uploads evidence.\nPassing a different `buildchain-ref` than the commit used to invoke the reusable\nworkflow therefore fails in the signer job, not only during later consumption.\nThe policy additionally retains the distinct Buildchain runtime SHA that\ncreated the build and release evidence.\n\n```bash\nbuildchain verify github-artifact-attestation \\\n  libnode-linux-x64.tar.gz \\\n  --platform-manifest manifest.json \\\n  --release-passport buildchain.release.json \\\n  --bundle attestation.sigstore.json \\\n  --evidence github-artifact-attestation.evidence.json\n```\n\nVerification fails if a single artifact byte changes, the source commit or\nrepository differs, the signer workflow or Buildchain commit differs, the\nPassport was replaced, the platform manifest drifts, the bundle omits the\nexpected statement, or GitHub reports a self-hosted signer.\n\n## Qualification Policy\n\nNew protocol work qualifies on the Buildchain v3 alpha line first. The v2\ndevelopment branch is not a supported landing target. Production\nadoption waits for the exact v3 implementation commit to pass the repository\nsuite and a real GitHub OIDC/Sigstore qualification run, including the negative\ncases above. A successful local fixture is necessary but not sufficient."
    },
    {
      "id": "manual:github-governance-authority",
      "title": "GitHub Governance Authority",
      "route": "/docs/github-governance-authority",
      "category": "manual",
      "capabilityGroup": "governance-versioning",
      "audience": [
        "maintainer",
        "release-operator",
        "agent"
      ],
      "maturity": "preview",
      "sourcePath": "docs/github-governance-authority.md",
      "digest": "sha256:197ae7a949817f60f46b67b060731df14d0343d9daecd7d6eacfae9a526b6a12",
      "headings": [
        {
          "level": 1,
          "title": "GitHub Governance Authority",
          "anchor": "github-governance-authority"
        },
        {
          "level": 2,
          "title": "Trust boundary and non-claims",
          "anchor": "trust-boundary-and-non-claims"
        },
        {
          "level": 2,
          "title": "Effective policy",
          "anchor": "effective-policy"
        },
        {
          "level": 2,
          "title": "Repository and plan admission",
          "anchor": "repository-and-plan-admission"
        },
        {
          "level": 2,
          "title": "Read-only audit",
          "anchor": "read-only-audit"
        },
        {
          "level": 2,
          "title": "Mutation and rollback boundary",
          "anchor": "mutation-and-rollback-boundary"
        }
      ],
      "markdown": "---\nstatus: draft\nperiod: ongoing\ntheme: github-governance-authority\ndoc_type: protocol\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: B\nreview_state: unreviewed\nlast_reviewed: 2026-07-31\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-30\n  limits: Live GitHub state and account recovery remain provider-controlled and must be re-audited.\n---\n\n# GitHub Governance Authority\n\nBuildchain treats GitHub governance as an independently verified, fail-closed\nauthority boundary. A green CI run, a CODEOWNERS file, an API success response,\nor an administrator's assertion is not sufficient by itself. The verifier\ncombines the exact CODEOWNERS bytes from the target base branch, classic branch\nprotection, every applicable repository or organization ruleset, account role\nclasses, plan capability, required checks, and provider-read completeness into\none short-lived immutable receipt.\n\nThe machine contract is\n`@kungfu-tech/buildchain/github-governance-authority`. Its policy root covers\nthe managed-zone repository and target-ref admission rules, the exact\nrequired-check context/App bindings and strict-update semantics for every\npublic authoritative target, the dual-account authority split, protected\nverifier paths, native review requirements, break-glass constraints, and the\nexplicit trust boundary.\n\n## Trust boundary and non-claims\n\nThe trusted computing base contains GitHub service integrity, retained\norganization-owner recovery custody, the `kungfu-origin` review/governance\nidentity, the exact Buildchain verifier, and official publication identities.\nThe protocol does not claim resistance to compromise of GitHub itself,\ncompromise of all retained owner and recovery anchors, or malicious control of\nall independent trust anchors. A governance receipt grants no GitHub\npermission and is not a bearer credential.\n\n`dongkeren` is the development and pull-request author identity.\n`kungfu-origin` is the independent Code Owner and governance identity. A\nqualifying receipt requires the development identity to be active without an\nadministrator or maintainer role and requires the review identity to retain the\nadmitted governance role. Account recovery and retained root custody remain\noutside normal contributor and workflow paths.\n\n## Effective policy\n\nThe verifier evaluates native provider layers together. Every authoritative\ntarget must require:\n\n- a pull request, at least one independent Code Owner approval, and a fresh\n  approval after the latest reviewable push;\n- administrator enforcement, resolved review conversations, and a non-empty\n  required-check set whose exact contexts, GitHub App producer identities, and\n  strict-update setting match the versioned target policy;\n- no unapproved bypass actor, force push, or protected-ref deletion. Managed\n  dev/alpha/release ref bookkeeping may admit only the exact GitHub Actions App\n  identity versioned for that target; user and team bypass actors remain\n  non-qualifying;\n- exact last-match ownership of CODEOWNERS and the governance descriptor,\n  collector, rollout planner, and scheduled audit workflow;\n- complete readable GitHub API evidence. Missing, forbidden, ambiguous, or\n  malformed provider state is non-qualifying.\n\nRepository and organization rulesets are additive to classic branch\nprotection. Inspecting only one layer is insufficient because an applicable\nbypass or weaker update path in another layer can invalidate the effective\npolicy.\n\nWhen an admitted default development branch uses GitHub merge queue, its\ncandidate-source, queue-lease, and final build checks are one exact authority\nset. The queue lease may remain intentionally unbound while workflow-produced\nchecks retain their GitHub Actions App binding; strictness must match the live\nqueue ruleset.\n\n## Repository and plan admission\n\nThe 2026-07-30 baseline contains 16 managed public repositories. The descriptor\nsets `managedVisibilities` to `public`; private repositories are outside the\nmanaged-zone inventory and do not produce governance receipts. Public\nrepository names are versioned in the descriptor. A newly discovered public\nrepository or target ref is non-authoritative until explicitly admitted.\n\nThe descriptor also versions every active public merge target. The full audit\nevaluates one receipt per authoritative target rather than assuming the default\nbranch represents dev, alpha, release, or major publish-gate branches. The live\ndefault branch is always included even if it drifts outside the registry, in\nwhich case it is non-qualifying. Retained historical channels and generated\nper-release publish-gate refs are not silently deleted or promoted to current\nauthority; they require an explicit registry revision before they can qualify.\n\nPublic repositories can qualify on supported Free, Team, or Enterprise\nenforcement. Organization-wide rules require Team or Enterprise capability.\nThe verifier does not reinterpret an excluded private repository as qualifying,\nreplace missing native enforcement with CI or documentation, or make a private\nrepository public as a workaround.\n\n## Read-only audit\n\nRun the organization audit without mutation:\n\n```bash\nbuildchain audit github-governance \\\n  --organization kungfu-systems \\\n  --output github-governance.json \\\n  --json\n```\n\nLimit a canary to one repository:\n\n```bash\nbuildchain audit github-governance \\\n  --repository kungfu-systems/buildchain \\\n  --target-ref dev/v3/v3.0 \\\n  --require-qualifying \\\n  --json\n```\n\nProtected merge and publication consumers verify the receipt against the exact\nrepository, target base ref, policy root, freshness window, and exact\nBuildchain verifier source revision. Non-dry-run publication does not trust a\ncaller-supplied JSON hash: it mints a bounded token for the dedicated read-only\ngovernance auditor GitHub App, recollects live provider state with the exact\nBuildchain runtime, requires the resulting single-repository/single-target\naudit to qualify, and consumes that independently generated receipt. Missing\nApp configuration or unreadable provider state denies publication before\nprovider mutation. The publication authority workflow is itself an explicit\nCode Owner path.\n\nThe publication authority job and every reusable-workflow caller grant the\nbuilt-in `GITHUB_TOKEN` only `actions: read`, `checks: read`, `contents: read`,\nand `pull-requests: read`. The dedicated auditor App independently recollects\nthe organization-wide governance receipt, while these job-scoped permissions\nallow the exact publication transaction audit to resolve required check runs\nand merged pull-request review lineage. Omitting either read permission makes\nthe transaction evidence incomplete and therefore non-qualifying.\n\nThe output is sanitized. Managed public repositories retain their public\nidentity. Excluded private repositories produce no receipt or diagnostic.\nTokens, cookies, recovery material, private CODEOWNERS bytes, raw permission\npayloads, and credential-bearing URLs are never included.\n\n## Mutation and rollback boundary\n\nLive role, ruleset, branch-protection, Actions, Environment, or repository\nchanges are separate from audit. Every mutation starts from a read-only\ninventory and a frozen rollback snapshot. A rollout plan binds both roots and\nlists the exact API operation, impact, expected observation, and inverse\noperation. Apply must stop on the first unexplained drift and must perform a\npost-change read-back before continuing to the next bounded canary.\n\nPlan one exact branch without mutation:\n\n```bash\nbuildchain github-governance plan \\\n  --repository kungfu-systems/buildchain \\\n  --branch dev/v3/v3.0 \\\n  --required-check check \\\n  --required-check-app-id check=15368 \\\n  --required-approvals 1 \\\n  --snapshot-output rollback.json \\\n  --plan-output rollout.json\n```\n\nAn already protected check preserves its observed GitHub App binding. Every new\nrequired check must declare `--required-check-app-id <context>=<app-id>`;\ncontext-only replacement is rejected because it would broaden which producer\ncan satisfy the gate.\n\nClassic branch-protection bypass allowances and ruleset bypass actors are both\npart of the effective policy. Reconciliation writes explicit empty user, team,\nand App bypass lists and verifies those lists after apply; omitting the provider\nfield is not treated as removal because GitHub may preserve the prior value.\n\nThe plan prints a `planRoot`. Apply requires that exact root and stops if live\nprotection no longer matches the frozen inventory:\n\n```bash\nbuildchain github-governance apply \\\n  --plan-json rollout.json \\\n  --confirm-plan-root sha256:...\n```\n\nRollback is separately explicit and root-bound:\n\n```bash\nbuildchain github-governance rollback \\\n  --plan-json rollout.json \\\n  --confirm-rollback-root sha256:...\n```\n\nFor an admitted exact target, classic branch protection can also be compiled\ndirectly from the authority descriptor. This mode preserves both App-bound\nchecks and intentionally unbound check contexts such as Kungfu release's\nlegacy `build`, rather than guessing a provider App identity.\n\n```bash\nbuildchain github-governance protection-policy-plan \\\n  --repository kungfu-systems/kungfu \\\n  --branch alpha/v4/v4.0 \\\n  --snapshot-output protection-rollback.json \\\n  --plan-output protection-rollout.json\n\nbuildchain github-governance protection-policy-apply \\\n  --plan-json protection-rollout.json \\\n  --confirm-plan-root sha256:...\n\nbuildchain github-governance protection-policy-rollback \\\n  --plan-json protection-rollout.json \\\n  --confirm-rollback-root sha256:...\n```\n\nFor an admitted exact target, repository ruleset reconciliation compiles the\ntarget descriptor into the provider body. It replaces bypass actors with the\nexact provider-admitted desired set, requires fresh Code Owner approval and\nresolved review threads, and binds required checks plus strict-update semantics\nto the target policy. Newly synthesized managed rules include GitHub's explicit\ncanonical defaults so the frozen expected root matches provider read-back.\nRepository rulesets default to no bypass actors. The\ndescriptor's target-bound GitHub Actions allowance is an upper bound on\neffective provider state, not a requirement to add that actor to every\nprotection layer; when needed, the built-in App allowance is expressed by\nclassic branch protection. The target condition must contain exactly one\nbranch; unrelated rules and conditions are preserved in place.\n\n```bash\nbuildchain github-governance ruleset-policy-plan \\\n  --repository kungfu-systems/buildchain \\\n  --branch alpha/v3/v3.0 \\\n  --ruleset-id 19518955 \\\n  --snapshot-output ruleset-rollback.json \\\n  --plan-output ruleset-rollout.json\n\nbuildchain github-governance ruleset-policy-apply \\\n  --plan-json ruleset-rollout.json \\\n  --confirm-plan-root sha256:...\n\nbuildchain github-governance ruleset-policy-rollback \\\n  --plan-json ruleset-rollout.json \\\n  --confirm-rollback-root sha256:...\n```\n\nThe narrower `ruleset-plan` mode changes only `bypass_actors`; it remains\navailable for a bypass-only canary, but it cannot prove that an effective\nruleset matches the target descriptor. Both modes require the frozen ruleset\nsnapshot root for rollback.\n\nPaid-plan purchase, billing, legal/account-owner decisions, and any operation\nthat could remove the last recoverable owner remain external human gates.\nBreak-glass is disabled by default and, if ever admitted, must be separately\nauthenticated, reason-bound, time-bounded, independently receipted, and\nfollowed by mandatory restoration and root comparison."
    },
    {
      "id": "manual:homebrew",
      "title": "Homebrew Distribution Indexes",
      "route": "/docs/homebrew",
      "category": "manual",
      "capabilityGroup": "distribution-indexes",
      "audience": [
        "consumer",
        "release-operator"
      ],
      "maturity": "stable",
      "sourcePath": "docs/homebrew.md",
      "digest": "sha256:e690ea465d4289f2246d93765776b057c6aca1c68dc290abcee94c947e5d5c47",
      "headings": [
        {
          "level": 1,
          "title": "Homebrew Distribution Indexes",
          "anchor": "homebrew-distribution-indexes"
        },
        {
          "level": 2,
          "title": "Configuration",
          "anchor": "configuration"
        },
        {
          "level": 2,
          "title": "CLI",
          "anchor": "cli"
        },
        {
          "level": 2,
          "title": "Node API",
          "anchor": "node-api"
        },
        {
          "level": 2,
          "title": "Trust Model",
          "anchor": "trust-model"
        }
      ],
      "markdown": "# Homebrew Distribution Indexes\n\nBuildchain treats a Homebrew tap as a distribution-index project: the tap\ncontains Formula or Cask files, but those files are projections of upstream\nrelease passports. Version, download URLs, SHA-256 digests, KFD status, and\nevidence links come from the upstream product release, not from hand-maintained\ntap prose.\n\n## Configuration\n\nUse `project.type = \"distribution-index\"` for tap repositories:\n\n```toml\nschema = 1\n\n[project]\ntype = \"distribution-index\"\nname = \"homebrew-tap\"\n\n[lifecycle.verify]\ncommand = \"buildchain homebrew check\"\n```\n\nBuildchain v3.0.0 currently publishes evidence assets but no standalone platform archives, so the Buildchain formula continues to index the latest verified legacy binary line, v2.14.16. This does not change the tap repository's v3 management workflow.\n\nThe tap manifest is the repository-owned declaration of which upstream releases\nare indexed. Buildchain writes `tap-manifest.json` as a machine-readable\nprojection:\n\n```json\n{\n  \"schema\": 1,\n  \"contract\": \"kungfu-buildchain-homebrew-tap-manifest\",\n  \"kind\": \"homebrew-tap\",\n  \"entries\": [\n    {\n      \"type\": \"formula\",\n      \"name\": \"buildchain\",\n      \"path\": \"Formula/buildchain.rb\",\n      \"upstream\": {\n        \"repository\": \"kungfu-systems/buildchain\",\n        \"tag\": \"v2.14.16\",\n        \"releasePassportUrl\": \"https://github.com/kungfu-systems/buildchain/releases/download/v2.14.16/buildchain.release.json\"\n      },\n      \"version\": \"2.14.16\",\n      \"kfd\": {\n        \"kfd-1\": \"passed\",\n        \"kfd-2\": \"passed\",\n        \"kfd-3\": \"passed\"\n      },\n      \"artifacts\": [\n        {\n          \"platform\": \"darwin-arm64\",\n          \"url\": \"https://github.com/kungfu-systems/buildchain/releases/download/v2.14.16/buildchain-aarch64-apple-darwin.tar.gz\",\n          \"sha256\": \"...\"\n        }\n      ]\n    }\n  ]\n}\n```\n\n## CLI\n\nUpdate a formula and manifest from an upstream passport:\n\n```bash\nbuildchain homebrew update-formula \\\n  --package buildchain \\\n  --release-passport https://github.com/kungfu-systems/buildchain/releases/download/v2.14.16/buildchain.release.json \\\n  --write\n```\n\nCheck that the tap still matches upstream evidence:\n\n```bash\nbuildchain homebrew check --json\n```\n\n`check` fails closed when:\n\n- the upstream release passport or its sibling evidence does not verify;\n- `Formula/buildchain.rb` drifts from the projected version, URLs, or SHA-256\n  digests;\n- `tap-manifest.json` drifts from the projected upstream evidence;\n- the tap claims KFD-1, KFD-2, or KFD-3 passed without a verified upstream\n  passport section.\n\n## Node API\n\nUse the public `@kungfu-tech/buildchain/homebrew` export:\n\n```js\nimport {\n  collectHomebrewTapFacts,\n  renderHomebrewFormula,\n  checkHomebrewTap,\n  updateHomebrewTap,\n} from \"@kungfu-tech/buildchain/homebrew\";\n```\n\nThe API is the single implementation source. The CLI is a thin wrapper over\nthese functions, so CI and local update commands evaluate the same facts.\n\n## Trust Model\n\nFormula metadata is not source of truth. A tap entry may claim `kfd-1`,\n`kfd-2`, or `kfd-3` passed only when the upstream release passport verifies and\nthe corresponding passport section is `status = \"passed\"`. If verification\nfails, Buildchain downgrades the projected KFD status to `unverified` and\n`buildchain homebrew check` fails.\n\nIn short: KFD passed in a tap means the upstream release passport passed, not\nthat the tap author typed a passing status.\n\nThis makes Homebrew taps suitable for automated distribution-index CI: the tap\ncan move quickly while still proving that every download URL and digest is\nbound to release passport evidence."
    },
    {
      "id": "manual:infra-contract",
      "title": "Infra Contract",
      "route": "/docs/infra-contract",
      "category": "manual",
      "capabilityGroup": "governance-versioning",
      "audience": [
        "maintainer",
        "consumer"
      ],
      "maturity": "preview",
      "sourcePath": "docs/infra-contract.md",
      "digest": "sha256:7826e8c70ac2d90ddd8d4e38bcdd1bcfa36eef5106431d7ad94b2fe9c8d3d5dc",
      "headings": [
        {
          "level": 1,
          "title": "Infra Contract",
          "anchor": "infra-contract"
        },
        {
          "level": 2,
          "title": "Configuration",
          "anchor": "configuration"
        },
        {
          "level": 2,
          "title": "CLI",
          "anchor": "cli"
        },
        {
          "level": 2,
          "title": "Safety",
          "anchor": "safety"
        }
      ],
      "markdown": "# Infra Contract\n\n`project.type = \"infra-contract\"` models infrastructure release responsibility\nwithout binding Buildchain core to one infrastructure tool. The state machine is:\n\n```text\ndesired -> validate -> plan -> approval -> apply -> observe -> contract -> propagate\n```\n\nThe first supported surface is mutation-free: Buildchain validates declarations,\ncreates a normalized plan, reads reviewed or adapter-shaped observed outputs,\npublishes a deterministic contract artifact, and plans downstream consumer pull\nrequests. Propagation execution is also dry-run by default. Real infrastructure\nmutation and real consumer pull request creation are not PR or ordinary push side\neffects.\n\nAfter apply and propagation produce their own result JSON, Buildchain can also\nwrite a lifecycle evidence bundle. The bundle references the immutable contract\nartifact by `artifactHash`, verifies that any apply result matches the artifact's\n`sourceSha` and plan hash, verifies that propagation results target the same\nartifact, and then hashes the combined desired, plan, approval, apply, observe,\ncontract, and propagation evidence.\n\n## Configuration\n\n```toml\nschema = 1\n\n[project]\ntype = \"infra-contract\"\nname = \"infra-kungfu-sites\"\n\n[infra]\nadapter = \"manual-observed\"\nadoption_mode = \"manual-observed\"\napply = \"disabled\"\nenvironment = \"staging\"\ndesired = [\"desired/site-kungfu-tech.json\"]\ncontract = [\"outputs/site-kungfu-tech.json\"]\n\n[[consumers]]\nrepo = \"kungfu-systems/site-kungfu-tech\"\npath = \"infra/outputs.json\"\nsource = \"outputs/site-kungfu-tech.json\"\n```\n\nSupported adapters:\n\n```text\nmanual-observed\naws-cloudformation\nterraform\nopentofu\npulumi\naws-cdk\naws-cli\ncustom-command\n```\n\nBuildchain's safe fixture set covers the provider-neutral shape without live\nprovider calls:\n\n- `manual-observed` for existing reviewed resources;\n- `aws-cloudformation` for template plus stack output shapes;\n- `terraform` for plan/output JSON shapes;\n- `opentofu` for plan/output JSON shapes;\n- `pulumi` for preview/output JSON shapes;\n- `aws-cdk` for synthesized assembly plus stack output shapes;\n- `aws-cli` for generic desired request plus observed response shapes;\n- `custom-command` for user-defined validate, plan, observe, and approved apply\n  hooks.\n\nFor built-in provider adapters, Buildchain records planned adapter command\nevidence for `validate`, `plan`, `apply`, and `observe` when a stage is\nsupported. These entries are command plans, not execution. They make the\nadapter handoff auditable before a repository opts in to concrete commands,\nand they stay `executed: false` even when `--execute-adapter-commands true` is\npassed.\n\nAny adapter can declare concrete command hooks under `[infra.commands]`.\nConfigured commands are the only executable provider surface. Buildchain records\nthem as planned adapter evidence by default. Passing\n`--execute-adapter-commands true` to `plan` or `contract` executes the\nnon-mutating `validate`, `plan`, or `observe` hooks and stores their exit\nstatus, stdout/stderr, and JSON stdout when present. The `apply` hook is only\navailable through the saved-plan apply path and is never executed by ordinary\nPR validation.\n\nSupported adoption modes:\n\n```text\nvalidate-only\nplan-only\nobserve-only\nmanual-observed\nimport-planned\nmanaged-apply\n```\n\n`apply = \"disabled\"` is the default. Non-disabled apply requires\n`adoption_mode = \"managed-apply\"`, a non-empty `environment`, a non-empty\n`identity_ref`, and an explicit approval id before mutation. `identity_ref` is a\nprovider-neutral reference to the runtime role, service account, or environment\ncredential name; it is not a secret value. Apply also requires a saved plan\nartifact whose `sourceSha`, `plannedAt`, and input hash still match the current\nrepository. Real apply execution requires a configured `[infra.commands].apply`\ncommand, `--dry-run false`, and `--execute-adapter-commands true`. Without a\nconfigured apply command, built-in provider adapters still fail closed before\nmutation execution.\n\nFor managed apply, bind the target and runtime identity explicitly:\n\n```toml\nadoption_mode = \"managed-apply\"\napply = \"manual-approval\"\nenvironment = \"preview\"\nidentity_ref = \"AWS_ROLE_ARN\"\n```\n\n## CLI\n\n```sh\nbuildchain infra-contract --mode validate\nbuildchain infra-contract --mode ci --source-sha \"$GITHUB_SHA\"\nbuildchain infra-contract --mode plan --source-sha \"$GITHUB_SHA\" \\\n  --output .buildchain/infra-contract-plan.json\nbuildchain infra-contract --mode plan --source-sha \"$GITHUB_SHA\" \\\n  --execute-adapter-commands true \\\n  --output .buildchain/infra-contract-plan.json\nbuildchain infra-contract --mode contract \\\n  --plan .buildchain/infra-contract-plan.json \\\n  --source-sha \"$GITHUB_SHA\" \\\n  --output .buildchain/buildchain.infra-contract.json\nbuildchain infra-contract --mode propagation-plan \\\n  --artifact .buildchain/buildchain.infra-contract.json \\\n  --output .buildchain/infra-contract-propagation.json\nbuildchain infra-contract --mode propagation-apply \\\n  --propagation-plan .buildchain/infra-contract-propagation.json \\\n  --dry-run true \\\n  --output .buildchain/infra-contract-propagation-apply.json\nbuildchain infra-contract --mode apply \\\n  --plan .buildchain/infra-contract-plan.json \\\n  --source-sha \"$GITHUB_SHA\" \\\n  --approval-id \"$APPROVAL_ID\" \\\n  --dry-run true \\\n  --output .buildchain/infra-contract-apply.json\nbuildchain infra-contract --mode apply \\\n  --plan .buildchain/infra-contract-plan.json \\\n  --source-sha \"$GITHUB_SHA\" \\\n  --approval-id \"$APPROVAL_ID\" \\\n  --dry-run false \\\n  --execute-adapter-commands true \\\n  --output .buildchain/infra-contract-apply.json\nbuildchain infra-contract --mode evidence-bundle \\\n  --artifact .buildchain/buildchain.infra-contract.json \\\n  --apply-result .buildchain/infra-contract-apply.json \\\n  --propagation-result .buildchain/infra-contract-propagation-apply.json \\\n  --output .buildchain/infra-contract-evidence-bundle.json\nbuildchain verify infra-contract-evidence-bundle \\\n  .buildchain/infra-contract-evidence-bundle.json\n```\n\n`ci` is the default mutation-free lifecycle entrypoint for repositories created\nwith `buildchain init --type infra-contract`. It validates the project, writes a\nplan, writes an observed contract artifact, writes a propagation plan, runs\npropagation apply in dry-run mode, creates an evidence bundle, and verifies that\nbundle. It does not execute provider apply commands or open consumer PRs.\n\nFor projects where apply is disabled, omit `--apply-result`. For projects with\nno consumers, omit `--propagation-result`.\n\nThe evidence-bundle verifier is read-only. It recomputes the bundle hash,\nchecks the contract artifact hash, verifies that desired, plan, approval,\napply, observe, contract, and propagate evidence are all present, recomputes\nthe bundle validation summary, and fails closed when apply or propagation\nresults are not bound to the same artifact.\n\n## Safety\n\n- PR validation is mutation-free.\n- `buildchain infra-contract --mode ci` is mutation-free by default and produces\n  auditable `.buildchain/infra-contract*.json` evidence for reusable workflow\n  artifacts.\n- `manual-observed` and observe-only modes cannot apply.\n- Apply fails before mutation unless approval, target environment, identity\n  reference, adapter capability, and ownership mode are explicit.\n- Apply rejects missing, stale, source-mismatched, or input-drifted plan\n  artifacts before any adapter mutation can run.\n- Built-in provider adapter command evidence is planned-only unless the\n  repository declares a concrete command for that stage under `[infra.commands]`.\n- Provider apply requires saved plan freshness, an approval id, target\n  environment, identity reference, a configured apply command,\n  `--dry-run false`, and `--execute-adapter-commands true`; nonzero adapter\n  exits fail closed and are recorded as adapter evidence.\n- Terraform/OpenTofu state files and Pulumi state or secret JSON files are not\n  accepted as contract inputs.\n- Consumers are represented as pull request plans. `propagation-apply` defaults\n  to dry-run; real PR creation requires `--dry-run false`, `--approval-id`, and\n  explicit `--consumer-workspace owner/repo=/path/to/checkout` mappings.\n- Buildchain never pushes mirrored contract files directly to consumer main\n  branches. Real propagation creates reviewable branches and calls\n  `gh pr create`.\n- Evidence bundles do not execute adapters, mutate infrastructure, or open PRs.\n  They only verify and hash already saved contract, apply, and propagation\n  outputs.\n- `buildchain verify infra-contract-evidence-bundle` is read-only and fails\n  closed when the lifecycle evidence chain is incomplete, tampered, or carries\n  a stale validation summary."
    },
    {
      "id": "manual:install",
      "title": "Install and Verify Buildchain",
      "route": "/docs/install",
      "category": "manual",
      "capabilityGroup": "getting-started",
      "audience": [
        "consumer"
      ],
      "maturity": "stable",
      "sourcePath": "docs/install.md",
      "digest": "sha256:c04ba24a8bed696c02f68af4dd05bd2363fa06b85c54d49a4316efb36b7cf865",
      "headings": [
        {
          "level": 1,
          "title": "Install and Verify Buildchain",
          "anchor": "install-and-verify-buildchain"
        },
        {
          "level": 2,
          "title": "Standalone Binary",
          "anchor": "standalone-binary"
        },
        {
          "level": 2,
          "title": "npm Package",
          "anchor": "npm-package"
        },
        {
          "level": 2,
          "title": "Repository Integration",
          "anchor": "repository-integration"
        },
        {
          "level": 2,
          "title": "Verify a Release Passport",
          "anchor": "verify-a-release-passport"
        }
      ],
      "markdown": "# Install and Verify Buildchain\n\nBuildchain can be consumed as a standalone binary, an npm package, or a\nrepository workflow surface. In every case, verify the release record before\nadopting a new version.\n\n## Standalone Binary\n\nBuildchain v4.0.0 does not publish standalone platform archives. This section\ndocuments the verified legacy binary release contract; v4 consumers should use\nthe npm package or repository workflow surface below.\n\nUse the archive that matches the platform:\n\n| Platform | Asset |\n| --- | --- |\n| Linux x64 | `buildchain-x86_64-unknown-linux-gnu.tar.gz` |\n| macOS arm64 | `buildchain-aarch64-apple-darwin.tar.gz` |\n| Windows x64 | `buildchain-x86_64-pc-windows-msvc.zip` |\n\nLinux example:\n\n```bash\ntag=v2.2.1\nbase=\"https://github.com/kungfu-systems/buildchain/releases/download/${tag}\"\ncurl -LO \"${base}/buildchain-x86_64-unknown-linux-gnu.tar.gz\"\ncurl -LO \"${base}/buildchain.release.json\"\ncurl -LO \"${base}/artifact-evidence.json\"\nnpx @kungfu-tech/buildchain verify release-passport buildchain.release.json\ntar -xzf buildchain-x86_64-unknown-linux-gnu.tar.gz\n./buildchain version\n```\n\nWindows example:\n\n```powershell\n$tag = \"v2.2.1\"\n$base = \"https://github.com/kungfu-systems/buildchain/releases/download/$tag\"\nInvoke-WebRequest \"$base/buildchain-x86_64-pc-windows-msvc.zip\" -OutFile buildchain.zip\nInvoke-WebRequest \"$base/buildchain.release.json\" -OutFile buildchain.release.json\nInvoke-WebRequest \"$base/artifact-evidence.json\" -OutFile artifact-evidence.json\nnpx @kungfu-tech/buildchain verify release-passport buildchain.release.json\nExpand-Archive buildchain.zip -DestinationPath .\n.\\buildchain.exe version\n```\n\nThe GitHub Release page does not publish loose top-level `buildchain` or\n`buildchain.exe` files. The executable is inside each platform archive.\n\n## npm Package\n\n```bash\nnpm install -D @kungfu-tech/buildchain\nnpx buildchain version\nnpx buildchain doctor --json\n```\n\nThe highest alpha minor publishes to the `alpha` npm dist-tag; older maintenance\nminor alphas use `vX.Y-alpha` so they cannot roll the global alpha channel back.\nStable releases publish to\n`latest`. Both are created by the protected Buildchain promotion transaction.\n\nStable consumers should pin the exact Buildchain version they have validated,\nfor example:\n\n```bash\npnpm add -D @kungfu-tech/buildchain@4.0.0\n```\n\nIf a repository dogfoods a just-published Buildchain version and pnpm's release\nage policy blocks the install, use a temporary package/version-specific\n`minimumReleaseAgeExclude` entry instead of weakening the registry policy for\nall packages:\n\n```yaml\nminimumReleaseAgeExclude:\n  - '@kungfu-tech/buildchain@4.0.0'\n```\n\nRemove that entry after the package is old enough for the repository's normal\npolicy. Do not use a broad exclude such as `@kungfu-tech/*` for this case.\nBuildchain-managed Paper scaffold and migration commands maintain this exact\nversion entry in `pnpm-workspace.yaml` so an immediately published, verified\nruntime can refresh the lockfile without weakening the policy for other\npackages.\n\n## Repository Integration\n\n```bash\nnpx @kungfu-tech/buildchain init --type package --package-manager pnpm\nnpx @kungfu-tech/buildchain validate --require-version-state\nnpx @kungfu-tech/buildchain release --dry-run --target-ref alpha/v4/v4.0\n```\n\nUse `.buildchain/buildchain.toml` to declare lifecycle commands. The commands may use Node\npackage managers or non-Node tools such as pip, Conan, CMake, Make, or project\nscripts.\n\n## Verify a Release Passport\n\n```bash\nbuildchain verify release-passport buildchain.release.json\nbuildchain explain release --passport buildchain.release.json --for agent --json\n```\n\nThe verifier fails closed when the passport or its sibling evidence files are\nmissing required fields or mismatching artifact digests."
    },
    {
      "id": "manual:kfd-agent-hub",
      "title": "KFD Agent Hub Builder Flow",
      "route": "/docs/kfd-agent-hub",
      "category": "manual",
      "capabilityGroup": "kfd-trust",
      "audience": [
        "agent",
        "consumer",
        "maintainer"
      ],
      "maturity": "preview",
      "sourcePath": "docs/kfd-agent-hub.md",
      "digest": "sha256:9bfba0a872590bb1b4f260ddbe71b54572ef291f3fc11d32bcd04e79f5e740ff",
      "headings": [
        {
          "level": 1,
          "title": "KFD Agent Hub Builder Flow",
          "anchor": "kfd-agent-hub-builder-flow"
        },
        {
          "level": 2,
          "title": "Declare one adapter",
          "anchor": "declare-one-adapter"
        },
        {
          "level": 2,
          "title": "Inspect, test, and explain",
          "anchor": "inspect-test-and-explain"
        },
        {
          "level": 2,
          "title": "Use the reusable workflow",
          "anchor": "use-the-reusable-workflow"
        },
        {
          "level": 2,
          "title": "Bind Release Passport",
          "anchor": "bind-release-passport"
        }
      ],
      "markdown": "# KFD Agent Hub Builder Flow\n\nBuildchain reduces Agent Hub adoption to one consumer declaration and one\nadapter artifact. KFD owns the conformance profile, fixed suite, runner,\nverifier, report schema, and failure codes. Buildchain owns orchestration,\nsource-cut locking, declaration-to-observation comparison, workflow artifacts,\nagent explanations, and Release Passport binding.\n\n## Declare one adapter\n\nCreate `.buildchain/kfd/agent-hub.json`:\n\n```json\n{\n  \"$schema\": \"https://buildchain.libkungfu.dev/schemas/kfd-agent-hub-adoption.schema.json\",\n  \"schemaVersion\": 1,\n  \"contract\": \"kungfu-buildchain-kfd-agent-hub-adoption/v1\",\n  \"profile\": {\n    \"package\": \"@kungfu-tech/kfd\",\n    \"id\": \"kfd-agent-hub-conformance\"\n  },\n  \"adapter\": {\n    \"id\": \"example-agent-hub-adapter\",\n    \"version\": \"0.1.0\",\n    \"path\": \"dist/agent-hub-adapter.mjs\",\n    \"build\": [\"pnpm\", \"run\", \"build:agent-hub\"]\n  },\n  \"capabilities\": {\n    \"operations\": [\"capability-advertisement\", \"fact-admission\"],\n    \"topologies\": [\"local-peer\"],\n    \"hubBindings\": [\"local-file-bundle\"]\n  }\n}\n```\n\n`adapter.build` is an argv array, not a shell command. Buildchain does not\naccept a consumer-provided verifier command. It always invokes the installed\nKFD package's fixed public commands:\n\n```text\nkfd test agent-hub --adapter <entry> --output <report.json>\nkfd verify agent-hub-report <report.json> --adapter <entry> --json\n```\n\n`jsonl-stdio/v1` is the KFD runner-to-adapter invocation binding. It is locked\nfrom the KFD profile and is deliberately separate from\n`capabilities.hubBindings`, which declares product transport or file bindings\nsuch as `local-file-bundle`.\n\n## Inspect, test, and explain\n\n```bash\nbuildchain kfd hub init --write\nbuildchain kfd hub inspect --for agent\nbuildchain kfd hub test --for agent\nbuildchain kfd hub explain --for agent\n```\n\n`inspect` resolves the installed `@kungfu-tech/kfd` package and locks its exact\npackage version, package manifest, release anchor, profile manifest, protocol\nmanifest, fixed suite root, failure inventory root, declaration, and adapter\nartifact. Placeholder roots and KFD packages without the public Agent Hub\nprofile fail closed.\n\n`test` runs the declared adapter build, delegates all semantic decisions to\nKFD, verifies the KFD report, and then checks that every observed Hub\ncapability document exactly matches the declared operations, topologies, and\nHub bindings. Scope widening is a failure.\n\nEvidence is written under `.buildchain/artifacts/kfd-agent-hub/`:\n\n- `report.json`: the KFD-owned Agent Hub report.\n- `adoption-lock.json`: exact KFD cut, declaration, adapter, and capability lock.\n- `verification.json`: Buildchain's binding of the KFD verifier verdict to the lock.\n- `evidence.json`: the portable, nonqualifying, non-certifying release evidence index.\n\nThe evidence proves only the named adapter artifact, KFD package cut, platform,\nfixed suite, observed capability documents, and retained residual risks. It is\nnot KFD certification, a security assessment, or production-fitness evidence.\n\n## Use the reusable workflow\n\n```yaml\njobs:\n  build:\n    uses: kungfu-systems/buildchain/.github/workflows/build.yml@v3\n    with:\n      kfd-agent-hub: auto\n```\n\n`auto` runs the fixed Builder flow after the consumer verify lifecycle on every\nselected platform and uploads\n`<artifact>-kfd-agent-hub-<platform>-<source-sha>`. `off` is the default.\n\n## Bind Release Passport\n\nPass the generated evidence index to the normal collector:\n\n```bash\nbuildchain collect github-release \\\n  --tag \"$TAG\" \\\n  --assets-dir dist \\\n  --kfd-agent-hub-evidence-json .buildchain/artifacts/kfd-agent-hub/evidence.json\n```\n\nThe collector embeds a `kfdAgentHub` section and bundles\n`kfd-agent-hub-evidence.json`. `buildchain verify release-passport` resolves\nthat sibling asset and rejects report, lock, source-cut, scope, or claim-boundary\ntampering."
    },
    {
      "id": "manual:kfd-support",
      "title": "KFD Support",
      "route": "/docs/kfd-support",
      "category": "manual",
      "capabilityGroup": "kfd-trust",
      "audience": [
        "agent",
        "maintainer"
      ],
      "maturity": "stable",
      "sourcePath": "docs/kfd-support.md",
      "digest": "sha256:4efc8fb6f94293b75606aa0631dfa122edccc970c2cfc00c7e35f81817ea8335",
      "headings": [
        {
          "level": 1,
          "title": "KFD Support",
          "anchor": "kfd-support"
        },
        {
          "level": 2,
          "title": "Unified Namespace",
          "anchor": "unified-namespace"
        },
        {
          "level": 2,
          "title": "KFD-4 / KFD-5 / KFD-7 Product Gates",
          "anchor": "kfd-4-kfd-5-kfd-7-product-gates"
        },
        {
          "level": 2,
          "title": "KFD-1",
          "anchor": "kfd-1"
        },
        {
          "level": 2,
          "title": "KFD-2",
          "anchor": "kfd-2"
        },
        {
          "level": 2,
          "title": "Upstream KFD Aggregation",
          "anchor": "upstream-kfd-aggregation"
        },
        {
          "level": 3,
          "title": "Upstream Roles",
          "anchor": "upstream-roles"
        },
        {
          "level": 2,
          "title": "KFD-3",
          "anchor": "kfd-3"
        },
        {
          "level": 2,
          "title": "Shifu Discovery and Distribution Declarations",
          "anchor": "shifu-discovery-and-distribution-declarations"
        },
        {
          "level": 2,
          "title": "Detected, Declared, Enforced",
          "anchor": "detected-declared-enforced"
        },
        {
          "level": 2,
          "title": "CLI",
          "anchor": "cli"
        },
        {
          "level": 2,
          "title": "Node API",
          "anchor": "node-api"
        },
        {
          "level": 2,
          "title": "Standard Detectors",
          "anchor": "standard-detectors"
        },
        {
          "level": 2,
          "title": "Buildchain Self Dogfood",
          "anchor": "buildchain-self-dogfood"
        },
        {
          "level": 2,
          "title": "Known Gaps",
          "anchor": "known-gaps"
        }
      ],
      "markdown": "# KFD Support\n\nBuildchain implements KFD support as release evidence and product capability\nfacts, not as README prose. The machine-readable sources are:\n\n- `dist/site/kfd-claims.json` for Buildchain-owned public claims and KFD-3\n  collaboration surfaces;\n- `dist/site/public-surface-audit.json` for reverse enumeration of exposed CLI,\n  workflow, action, site, and documented command surfaces;\n- `buildchain.release.json` plus its `kfd-support.json` sibling for\n  release-specific KFD-1/2/3 evidence and the exact KFD-1..13 support\n  projection;\n- `.buildchain/buildchain.toml` for repository-owned Buildchain configuration;\n- `.buildchain/kfd/kfd-2/registry.json` for product-owned KFD-2 public claim\n  declarations;\n- `.buildchain/kfd/kfd-3/surfaces.json` for product-owned KFD-3 surface\n  registration;\n- `.buildchain/contract-lock.json` for accepted floating runtime contracts.\n\nBuildchain still reads the legacy root files `buildchain.toml`,\n`buildchain.contract-lock.json`, `buildchain.kfd3.json`, and the historical\n`.buildchain/kfd/kfd-3-surfaces.json` registry so existing consumers can run\n`buildchain kfd migrate-layout --write`. New repositories should keep\nrepo-owned Buildchain files under `.buildchain/`, with all KFD evidence under\n`.buildchain/kfd/`.\n\n## Unified Namespace\n\nKFD support is exposed through one first-class namespace:\n\n```bash\nbuildchain kfd status --json\nbuildchain kfd migrate-layout --write\nbuildchain kfd schema list --json\nbuildchain kfd 1 witness --json\nbuildchain kfd 2 claims --json\nbuildchain kfd 2 trust-claims --json\nbuildchain kfd 2 trust-assessment --json\nbuildchain kfd upstream roles --json\nbuildchain kfd upstream collect --json\nbuildchain kfd upstream check --json\nbuildchain kfd aggregate --json\nbuildchain kfd 3 query buildchain --json\nbuildchain kfd 4 schema --json\nbuildchain kfd 4 gate --input-json kfd-4-gate-input.json --json\nbuildchain kfd 5 gate --input-json kfd-5-gate-input.json --json\nbuildchain kfd 7 gate --input-json kfd-7-gate-input.json --json\nbuildchain kfd support project --manifest-json adopter-manifest.json \\\n  --manifest-gate-json adopter-manifest-gate.json --json\n```\n\nKFD-1, KFD-2, and KFD-3 have concrete Buildchain workflows. KFD-4, KFD-5, and\nKFD-7 additionally have product-evidence gates backed by the installed KFD\npackage and its offline WASM verifier. These gates verify exact source,\nfreshness, record bytes, negative evidence, and product-owned responsibility;\nthey do not self-qualify, self-certify, activate, or silently widen support.\nKFD-6 remains an explicit unsupported barrier. KFD-8 through KFD-13 remain\ndraft adopter-evidence barriers until their standards and product gates mature.\n\n## KFD-4 / KFD-5 / KFD-7 Product Gates\n\nEach gate input uses\n`kungfu-buildchain-kfd-product-gate-input` version 1 and binds repository-relative\nKFD records and evidence by SHA-256. The result uses\n`kungfu-buildchain-kfd-product-gate` version 1 and always records\n`qualifying: false` and `selfCertified: false`.\n\n- KFD-4 requires a verified observer perspective, contrastive perspective\n  replay, declared loss, preserved evidence boundaries, projection fsck, and a\n  negative fixture.\n- KFD-5 requires an accepted Primitive discovery record whose minimum-closure,\n  deletion, fuse, and dogfood tests pass with retained evidence, plus explicit\n  falsifiers and a negative fixture.\n- KFD-7 requires a qualified and activated Domain Profile, independent review,\n  product witnesses, all 13 evidence obligations, and negative evidence.\n\n`buildchain kfd support project` derives a compatibility projection from the\nstandard adopter manifest and its exact passing gate. The adopter manifest is\nthe sole KFD-1..13 declaration authority; the command rejects stale package,\nsource, witness, registry, verifier-set, and KFD-4/5/7 gate roots. The emitted\nmatrix is not an independent declaration and cannot widen adopter claims.\n\n## KFD-1\n\nKFD-1 proves that a product release is bound to one contract world. Buildchain\nuses KFD-1 for its runtime contract, release-passport schemas, packaged docs,\nNode exports, workflows, actions, and site-consumption facts.\n\nFor Buildchain itself, the source registry lives in\n`packages/core/buildchain-kfd-claims.js` and is projected to\n`dist/site/kfd-claims.json`. Release promotion binds that registry to exact\nsource and artifact hashes in the release passport.\n\nBuildchain exposes KFD-1 through:\n\n```bash\nbuildchain kfd 1 schema --json\nbuildchain kfd 1 witness --json\nbuildchain kfd 1 gate --witness-json kfd-1-witness.json --json\nbuildchain kfd 1 verify --gate-json kfd-1-gate.json --json\n```\n\n## KFD-2\n\nKFD-2 requires public trust claims to be backed by machine-readable evidence.\nBuildchain release passports fail or downgrade claims that only have prose.\n\nEvery public claim binds:\n\n- declared source files;\n- machine-readable evidence;\n- source, evidence, and artifact hashes;\n- artifact coordinates;\n- verification result;\n- audit boundary;\n- responsibility state;\n- residual risk.\n\nBuildchain exposes KFD-2 through:\n\n```bash\nbuildchain kfd 2 schema --json\nbuildchain kfd 2 taxonomy --entry-json residual-risk.json --kind residualRisk --json\nbuildchain kfd 2 claims --json\nbuildchain kfd 2 product-claims check --json\nbuildchain kfd 2 product-claims write --json\nbuildchain kfd 2 product-claims render --json\nbuildchain kfd 2 trust-claims --json\nbuildchain kfd 2 trust-assessment --json\n```\n\nProducts declare their own public trust intent once in the canonical tracked\nregistry:\n\n```text\n.buildchain/kfd/kfd-2/registry.json\n```\n\nThe registry uses\n`kungfu-buildchain-kfd-2-product-claims-registry/v1` and binds each claim to a\nsource, machine-readable evidence, artifact coordinates, verification command,\naudit boundary, responsibility, residual risk, and canonical status. Buildchain\ndoes not invent product claims from prose. It validates the declaration, hashes\nthe referenced files, and renders the release-facing outputs:\n\n```text\n.buildchain/kfd/kfd-2/release-claims.json\n.buildchain/kfd/kfd-2/claims/<claim-id>.json\n.buildchain/kfd/kfd-2/buildchain-claim-args.txt\n```\n\n`product-claims check` is read-only and fails on missing, stale, or unexpected\nclaim projections. `write` updates only the declared KFD-2 output set and\nremoves stale generated claim JSON files; unrelated files are preserved.\n`render` prints the expected document set without writing it. Version is read\nfrom the repository's configured Buildchain version state unless explicitly\noverridden. Release pipelines may override channel, tag, or source SHA while\nthe registry remains the stable product-intent source.\n\n`claims` generates Buildchain's release-passport public claim inputs. The\n`trust-claims` and `trust-assessment` commands expose the latest KFD package's\nfoundation KFD-2 facts from `@kungfu-tech/kfd` and validate their taxonomy\nvalues against the KFD-owned `trust-taxonomy` schema. Unknown `riskType`,\n`trustImpact`, `machineProvability`, or `agentAction` values fail validation;\nnew values must be requested upstream in `kungfu-systems/kfd`, not invented in\nBuildchain.\n\n`@kungfu-tech/kfd` is a runtime dependency of Buildchain, not a development-only\ndependency. The public `buildchain kfd ...` CLI and `@kungfu-tech/buildchain/kfd`\nNode API read KFD-owned standards metadata, schemas, foundation trust claims,\nfoundation trust assessments, and taxonomy values at runtime. Moving KFD to\n`devDependencies` would make installed Buildchain packages unable to answer KFD\nqueries in consumer repositories.\n\n## Upstream KFD Aggregation\n\nProducts often depend on multiple KFD-aware upstream components. A product's own\nKFD status is not the same thing as the status of those upstreams, but agents\nstill need one machine-readable view of the upstream trust surface.\n\nBuildchain exposes that view through:\n\n```bash\nbuildchain kfd upstream roles --json\nbuildchain kfd upstream collect --json\nbuildchain kfd upstream check --json\nbuildchain kfd aggregate --json\n```\n\n`upstream collect` reads `.buildchain/buildchain.toml`, resolves declared\npackages from the caller repository, hashes declared evidence assets, and emits\na `kungfu-buildchain-kfd-upstream-aggregate` document. `upstream check` validates\nthat aggregate. `aggregate` combines the product's own Buildchain KFD status\nwith the upstream aggregate.\n\nThis works in development before the consuming repository has published an\nalpha or release. In that state Buildchain can collect and check upstream\nfacts, versions, hashes, roles, and residual risk, but the consuming product\nmust not claim its own KFD status as `passed` until a release passport verifies\nthat product release.\n\nThe repository-owned declaration is intentionally small. Consumers normally\ndeclare the upstream package identity, not Buildchain's inferred role or a\nduplicate semver:\n\n```toml\n[kfd.upstream]\nauto_discover = false\n\n[[kfd.upstream.components]]\nid = \"kfd\"\npackage = \"@kungfu-tech/kfd\"\nrepository = \"kungfu-systems/kfd\"\nevidence = [\n  \"package:kfd.release.json\",\n  \"package:.buildchain/kfd/kfd-1/contract-world.witness.json\",\n  \"package:.buildchain/kfd/kfd-2/release-claims.json\",\n  \"package:.buildchain/kfd/kfd-3/collaboration-interface.json\",\n  \"package:standards.json\",\n]\n```\n\nThe upstream package version is a single source of truth owned by the package\nmanager. Put the dependency in `package.json` / the lockfile, then let\nBuildchain read the installed package's real `package.json`:\n\n```json\n{\n  \"devDependencies\": {\n    \"@kungfu-tech/kfd\": \"1.0.0-alpha.21\"\n  }\n}\n```\n\nMost consumers should keep `@kungfu-tech/kfd` in `devDependencies`: Buildchain\nuses it during CI, development checks, release evidence collection, and site\ngeneration. Move it to `dependencies` only if the product's own runtime imports\nKFD directly. Buildchain itself keeps KFD in `dependencies` because its public\nCLI and Node API resolve KFD standards, schemas, taxonomy, and foundation trust\nfacts at runtime.\n\nDo not repeat upstream semver values in `.buildchain/buildchain.toml`. Repeating\nversions in both `package.json` and Buildchain config creates stale facts.\n`upstream collect` records the actual installed package version and evidence\nhashes in the aggregate output.\n\n`kfd_1`, `kfd_2`, `kfd_3`, and `kfd_4` are optional capability-state hints. When\nomitted, Buildchain treats the component as `declared`. Use explicit values only\nwhen the upstream package really exposes the corresponding machine evidence,\nfor example:\n\n```toml\nkfd_1 = \"exported-witness\"\nkfd_2 = \"exported-claim\"\nkfd_3 = \"exported-collaboration-interface\"\nkfd_4 = \"schema-metadata\"\n```\n\nAn upstream component may be `declared`, `aligned`, `exported-*`, or another\nexplicit non-passed state when the evidence is package-local. A component may\nclaim `passed` only when the aggregate also binds that component to a release\npassport. Upstream `passed` never upgrades the product's own KFD status; it only\ndescribes the upstream trust surface consumed by the product.\n\n### Upstream Roles\n\nConsumers should normally omit `role`. Buildchain owns the role vocabulary and\ninfers the role from package identity and evidence. The aggregate records:\n\n- `role` - the normalized Buildchain-managed role;\n- `roleSource` - `known-package`, `evidence`, `default`, or `explicit`;\n- `roleReason` - the machine-readable explanation for the chosen role.\n\nThe managed role registry is queryable:\n\n```bash\nbuildchain kfd upstream roles --json\n```\n\nCurrent roles are:\n\n| Role | Meaning |\n| --- | --- |\n| `standard-and-schema-provider` | Provides KFD standards, schemas, taxonomy, or standard-owned witness and claim facts. |\n| `release-passport-and-kfd-gate-provider` | Provides release passport, KFD gate, release claim, or release governance machinery consumed by the product. |\n| `kfd-aware-product-component` | A product component that exposes KFD witness, claim, collaboration-interface, or package evidence without being core KFD infrastructure. |\n| `site-consumption-provider` | Provides site-consumption facts such as site manifests, site bundles, or downstream page-content contracts. |\n| `unknown-kfd-upstream` | Fallback for a declared upstream that has not matched a Buildchain-known package or role-specific evidence. |\n\nIf a consumer explicitly writes `role`, it must be one of that registry. Unknown\nexplicit values fail closed during `upstream check`; Buildchain will not let\nrepositories invent local role spellings that later fragment aggregate reports.\n\nBuildchain dogfoods this model with `@kungfu-tech/kfd` as its upstream\nstandard-and-schema provider. The generated site bundle includes\n`dist/site/kfd-upstream-aggregate.json` so downstream sites and agents can read\nBuildchain's upstream KFD facts from the npm package instead of scraping\nrepository scripts.\n\n## KFD-3\n\nKFD-3 closes participant-facing collaboration surfaces over a declared public\ninterface. Buildchain supports two complementary KFD-3 layers.\n\nThe first layer is Buildchain self-verification. Buildchain reverse-enumerates\nreal CLI commands, reusable workflow inputs, action inputs, site pages, and\ndocumented command references, then compares those facts with the generated\nregistries in `dist/site/`. A missing registry entry fails `pnpm run check`.\n\nThe second layer is product surface registration. Products can ask Buildchain to\ndetect standard public surfaces, write a small product-owned registry, audit the\nregistry against the current artifact/source tree, generate a release-passport\ncompatible witness, and query the resulting capability map.\n\n## Shifu Discovery and Distribution Declarations\n\nBuildchain owns the repository-layout question; product tools must not copy its\ninternal paths. Shifu and other consumers use this sequence:\n\n1. read the welded `.buildchain-version` pin to select Buildchain;\n2. run `buildchain layout --cwd <repository> --json`;\n3. read the returned `kfd.registries[\"kfd-3\"].path`;\n4. treat a surface as Shifu-managed only when its declaration contains\n   `distribution.registrar=\"shifu\"`.\n\nThe layout response uses the\n`kungfu-buildchain-layout-discovery` contract with an explicit schema version.\nChanging or removing its fields is a public contract change. Consumers must not\nfall back to a hard-coded registry location when the command is unavailable or\nreturns an unsupported contract.\n\nA Shifu distribution declaration must contain at least one task and one\nartifact. Every artifact declares `kind`, `platform`, and `pathGlob`; an\noptional `sha256` is a lowercase 64-character hexadecimal digest. This makes\nartifact form and platform machine-readable without asking Shifu to infer them\nfrom filenames:\n\n```json\n{\n  \"distribution\": {\n    \"registrar\": \"shifu\",\n    \"tasks\": [\"binary:build\"],\n    \"artifacts\": [\n      {\n        \"kind\": \"binary\",\n        \"platform\": \"linux\",\n        \"pathGlob\": \"dist/binary/example-x86_64-unknown-linux-gnu.tar.gz\"\n      }\n    ]\n  }\n}\n```\n\nBuildchain validates this shape whenever a KFD-3 registry is read or written.\nRepositories that do not declare the registrar remain outside Shifu's\ndistribution jurisdiction.\n\nKFD-3 surface audits also bind a detected artifact to its owning declared\nsurface when the detected kind and path match one of these distribution\nartifacts. This lets one participant-facing CLI remain the declared interface\nwhile its platform binaries are proved as distributions of that interface,\ninstead of being reported as unrelated unregistered surfaces.\n\n## Detected, Declared, Enforced\n\nKFD-3 surface registration uses three states.\n\n| State | Meaning |\n| --- | --- |\n| `detected` | Buildchain found a candidate public surface from package metadata, wheel metadata, CLI bins, binary artifacts, docs, or site bundle facts. |\n| `declared` | The product owner accepted that candidate into `.buildchain/kfd/kfd-3/surfaces.json`. |\n| `enforced` | The product has promoted a declared surface to a hard release boundary. Missing enforced surfaces fail release verification. |\n\nDetection does not silently become product intent. `register` is the boundary\ndecision. Existing consumers are unaffected until they opt in.\n\n## CLI\n\nInspect KFD-owned schema facts:\n\n```bash\nbuildchain kfd schema list --json\nbuildchain kfd schema show kfd-1 --json\nbuildchain kfd 4 schema --json\nbuildchain kfd 5 schema --json\nbuildchain kfd 7 schema --json\n```\n\nThe KFD schema namespace is discovered from `@kungfu-tech/kfd/standards.json`.\nFor KFD-2 this includes `trustClaims`, `trustAssessment`, `trustTaxonomy`,\n`releaseClaims`, and `releaseTrustPassport`. KFD-4 exposes both\n`observerPerspective` and `perspectiveReplay`; KFD-5 exposes\n`primitiveDiscovery`; KFD-7 exposes `domainProfileDeclaration`.\n\nDetect public surface candidates:\n\n```bash\nbuildchain kfd 3 detect --json\nbuildchain kfd 3 detect --kind node-api --kind cli --json\n```\n\nRegister standard surface classes:\n\n```bash\nbuildchain kfd 3 register node-api --product Buildchain\nbuildchain kfd 3 register cli\nbuildchain kfd 3 register python-api --artifact dist/wheel-unpacked\n```\n\nAudit detected, declared, and enforced surfaces:\n\n```bash\nbuildchain kfd 3 audit --json\n```\n\nGenerate a witness for release passport collection:\n\n```bash\nbuildchain kfd 3 witness \\\n  --kind prebuild \\\n  --output .buildchain/kfd/kfd-3/collaboration-interface.prebuild.json\n```\n\nQuery capability facts for agents or downstream sites:\n\n```bash\nbuildchain kfd 3 query buildchain --json\nbuildchain kfd 3 query --passport .buildchain/release-passport/buildchain.release.json --json\n```\n\n## Node API\n\nThe CLI is a thin wrapper over the public Node API:\n\n```js\nimport {\n  kfd1,\n  kfd2,\n  kfd3,\n  kfd4,\n  upstream,\n  collectKfdAggregate,\n  collectKfdStatus,\n  collectKfdUpstreamFacts,\n  checkKfdUpstreamFacts,\n  listKfdUpstreamRoles,\n  listKfdSchemas,\n  readKfdSchema,\n} from \"@kungfu-tech/buildchain/kfd\";\n```\n\nAgents should start with `collectKfdStatus()` to learn which standards are\nimplemented and where the repository-owned Buildchain files live. For capability\nuse decisions, prefer `kfd3.queryCapabilities()`. The query result connects each\ncapability to:\n\n- KFD-3 surface identity and state;\n- KFD-1 basis facts such as source and artifact paths or digests;\n- KFD-2 trust evidence when a release passport is attached;\n- residual risk and recommended agent action.\n\n## Standard Detectors\n\nThe initial detector set is intentionally conservative:\n\n- npm packages: `package.json` `exports`, `main`, `types`, and `bin`;\n- Python wheels: unpacked `.dist-info/METADATA`, `RECORD`,\n  `entry_points.txt`, and `top_level.txt`;\n- CLI binaries: `package.json#bin` and files under `bin/`;\n- standalone binaries and archives: common binary/archive outputs under\n  artifact directories such as `dist/`;\n- documentation: `README.md`, `AGENTS.md`, and `docs/*.md`;\n- site bundles: `dist/site/*.json`.\n\nPython importability alone is not considered public API. A product can extend\nthe registry over time, but the first boundary is metadata-based.\n\n## Buildchain Self Dogfood\n\nBuildchain dogfoods this model in two ways:\n\n- `buildchain kfd 1 witness --json` generates Buildchain's own KFD-1 contract\n  world witness;\n- `buildchain kfd 2 claims --json` generates Buildchain's own KFD-2 public\n  claim evidence;\n- `buildchain kfd 2 trust-claims --json` and\n  `buildchain kfd 2 trust-assessment --json` expose and validate the KFD\n  package's foundation KFD-2 trust facts against the latest KFD taxonomy;\n- `dist/site/kfd-claims.json` declares Buildchain's own KFD-3 collaboration\n  interface, including a Shifu-owned standalone binary distribution surface;\n- `buildchain kfd 3 query buildchain --json` resolves the packaged\n  Buildchain capability map from that site fact source.\n\nThis lets downstream agents discover Buildchain's supported CLI, Node API,\nrelease passport, workflow, and site bundle surfaces from the npm package\ninstead of scraping source files or README examples.\n\n## Known Gaps\n\nArchive unpacking for `.whl`, `.tar.gz`, `.zip`, and platform-native installers\nis intentionally not part of the first detector. Callers can point\n`--artifact` at an unpacked artifact directory. Future Buildchain versions can\nadd archive readers without changing the registry contract."
    },
    {
      "id": "manual:lifecycle-protocol",
      "title": "Lifecycle Protocol",
      "route": "/docs/lifecycle-protocol",
      "category": "manual",
      "capabilityGroup": "reusable-build",
      "audience": [
        "consumer",
        "developer"
      ],
      "maturity": "stable",
      "sourcePath": "docs/lifecycle-protocol.md",
      "digest": "sha256:4b7a8efe1d22751ded069f46a23490db70cda9e9e14641acab600ab781245b19",
      "headings": [
        {
          "level": 1,
          "title": "Lifecycle Protocol",
          "anchor": "lifecycle-protocol"
        },
        {
          "level": 2,
          "title": "Minimal File",
          "anchor": "minimal-file"
        },
        {
          "level": 2,
          "title": "Version State",
          "anchor": "version-state"
        },
        {
          "level": 3,
          "title": "Anchored Manual Versions",
          "anchor": "anchored-manual-versions"
        },
        {
          "level": 2,
          "title": "Lifecycle Stages",
          "anchor": "lifecycle-stages"
        },
        {
          "level": 3,
          "title": "Publish Stage",
          "anchor": "publish-stage"
        },
        {
          "level": 2,
          "title": "Promotion Semantics",
          "anchor": "promotion-semantics"
        },
        {
          "level": 2,
          "title": "Migration Preflight",
          "anchor": "migration-preflight"
        },
        {
          "level": 2,
          "title": "Web-Surface Projects",
          "anchor": "web-surface-projects"
        },
        {
          "level": 2,
          "title": "Infra-Contract Projects",
          "anchor": "infra-contract-projects"
        },
        {
          "level": 2,
          "title": "Examples",
          "anchor": "examples"
        },
        {
          "level": 3,
          "title": "Node Workspace",
          "anchor": "node-workspace"
        },
        {
          "level": 3,
          "title": "Python Package",
          "anchor": "python-package"
        },
        {
          "level": 3,
          "title": "CMake and Conan",
          "anchor": "cmake-and-conan"
        },
        {
          "level": 3,
          "title": "Docker Image",
          "anchor": "docker-image"
        },
        {
          "level": 2,
          "title": "Design Boundaries",
          "anchor": "design-boundaries"
        }
      ],
      "markdown": "---\nstatus: active\nperiod: ongoing\ntheme: buildchain-lifecycle-protocol\ndoc_type: technical-reference\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-07-31\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-31\n  invisible_context: not asserted\n---\n\n# Lifecycle Protocol\n\nBuildchain uses `.buildchain/buildchain.toml` as the v3 repository configuration format.\nThe file is optional for simple JavaScript repositories, but it is the preferred\nway to describe release version state and lifecycle commands when a project is\nnot a plain pnpm, npm, or yarn workspace.\n\nFor compatibility, Buildchain still reads a legacy root `buildchain.toml` when\n`.buildchain/buildchain.toml` is absent. New repositories should use the\n`.buildchain/` layout so all Buildchain-owned local state lives under one\ndirectory.\n\nOnly TOML is supported in v3. YAML, JSON, and JavaScript config files are not\nloaded.\n\n## Minimal File\n\n```toml\nschema = 1\n\n[version]\nrequired = true\n\n[[version.files]]\ntype = \"json\"\npath = \"package.json\"\nkey = \"version\"\n\n[lifecycle.verify]\ncommands = [\n  \"pnpm run check\",\n]\n```\n\n`schema = 1` is required. Buildchain fails closed when the schema is missing or\nunknown.\n\n## Version State\n\nVersion state is the source file evidence that matches a release tag. During\npromotion, Buildchain writes the selected release or prerelease version into the\nconfigured files, verifies the resulting tree, creates a source version commit,\nthen moves exact and floating refs.\n\nSupported version file types:\n\n| Type | Use case | Required fields |\n| --- | --- | --- |\n| `json` | `package.json`, JSON manifests | `path`, `key` |\n| `toml` | `pyproject.toml`, other TOML manifests | `path`, `key` |\n| `regex` | `CMakeLists.txt`, `conanfile.py`, plain version files | `path`, `pattern`, `replacement` |\n\n`key` is a dotted key path:\n\n```toml\n[[version.files]]\ntype = \"toml\"\npath = \"pyproject.toml\"\nkey = \"project.version\"\n```\n\nConfigured JSON and TOML version files are semantic no-ops when the declared\nkey already equals the requested version. Buildchain preserves the repository's\noriginal TOML bytes in that case instead of serializing the whole document and\ncreating formatter-only release state. When a TOML version really changes,\nBuildchain applies a parser-verified lossless edit to that key and fails closed\nif it cannot prove a unique edit; unrelated arrays, comments, and formatting\nremain repository-owned.\n\nRegex files must expose the current version through a named capture group called\n`version`:\n\n```toml\n[[version.files]]\ntype = \"regex\"\npath = \"CMakeLists.txt\"\npattern = 'project\\([^)]* VERSION (?<version>[^ )]+)'\nreplacement = '${version}'\n```\n\nIf `version.required = true`, promotion fails when no configured version files\nare available.\n\n### Anchored Manual Versions\n\nSome repositories do not derive their package version from the Buildchain\nrelease tag. `libnode` is the canonical example: the package version is anchored\nto an explicitly selected upstream Node.js release such as `22.22.3-kf.0`, while\nthe channel line may be `release/v22/v22.22`.\n\nThose repositories can opt into anchored manual semantics:\n\n```toml\n[version]\nrequired = true\nstrategy = \"anchored\"\nnext = \"manual\"\nmanifest = \"libnode.release.json\"\nderived_files = [\n  \"dist/version-witness.json\",\n]\n\n[[version.files]]\ntype = \"json\"\npath = \"package.json\"\nkey = \"version\"\n```\n\nWith `strategy = \"anchored\"` and `next = \"manual\"`:\n\n- Buildchain validates the configured version files and anchor manifest, but it\n  does not rewrite those files to the Buildchain release tag.\n- `lifecycle.verify` is the project-owned truth gate. It should compare the\n  package version, anchor manifest, and upstream source/submodule state.\n- `version.derived_files` can declare committed witnesses or generated metadata\n  whose bytes are derived by `lifecycle.version-state`. The field is valid only\n  for anchored/manual projects that declare both `lifecycle.version-state` and\n  `lifecycle.verify`.\n- release-candidate builds rerun derivation and verification before heavy\n  platform builds, require the committed tree to remain unchanged, and bind the\n  alpha/release tree identities plus declared file digests into controller and\n  release-passport evidence.\n- release promotion permits differences from the tested alpha tree only in\n  `version.files`, the anchor manifest, and declared `version.derived_files`;\n  any other changed path fails closed before publication.\n- release promotion still creates the exact/floating production refs for the\n  current line;\n- release promotion does not auto-create the next alpha branch or tag;\n- the action output `next-anchor-required` is `true`, signaling that the next\n  upstream anchor line must be created explicitly by the repository.\n\nThe configured anchor manifest must be JSON or TOML. Buildchain does not\ninterpret project-specific field names; it only loads the manifest and exposes\nits top-level fields to validation summaries and lifecycle environment:\n\n```text\nBUILDCHAIN_VERSION_STRATEGY=anchored\nBUILDCHAIN_VERSION_NEXT=manual\nBUILDCHAIN_ANCHOR_MANIFEST=libnode.release.json\nBUILDCHAIN_ANCHOR_MANIFEST_JSON={\"nodeTag\":\"v22.22.3\",...}\n```\n\nThe upstream anchor decision remains outside Buildchain. A future line such as\n`dev/v24/v24.xx` should be created by an explicit repository workflow or human\ndecision after the upstream version has been selected and checked in.\n\n## Lifecycle Stages\n\nLifecycle stages are declarative shell commands. A stage can use exactly one of:\n\n- `command`: one shell command;\n- `commands`: multiple shell commands run in order;\n- `script`: a multiline shell script.\n\nAny command failure fails the stage. `timeout_minutes`, `retries`, `shell`, and\n`env` can be attached to a stage.\n\nDuring version-state verification, Buildchain also sets `BUILDCHAIN_VERSION` to\nthe release or prerelease version being verified.\n\n```toml\n[lifecycle.install]\ntimeout_minutes = 10\nretries = 3\ncommands = [\n  \"pnpm install --frozen-lockfile\",\n]\n\n[lifecycle.build]\ncommands = [\n  \"pnpm run build\",\n  \"pnpm run package\",\n]\n\n[lifecycle.check]\ncommand = \"pnpm run check:source\"\n\n[lifecycle.verify]\nshell = \"bash\"\nscript = \"\"\"\nset -euo pipefail\npnpm run check\ngit diff --check\n\"\"\"\n```\n\n`lifecycle.check` is the repository-owned source-acceptance gate. It should\nvalidate the checked-out source revision without entering the build, artifact,\nor release lifecycle. Consumers can run it on GitHub-hosted Linux through\n`.github/workflows/check.yml@v3` with `mode: source`; the reusable workflow runs\nonly `lifecycle.install` and `lifecycle.check`. The default `mode: verify`\ncontinues to run `lifecycle.install` and `lifecycle.verify` for existing callers.\nBoth executed stages receive `BUILDCHAIN_CHECK_MODE=source` or\n`BUILDCHAIN_CHECK_MODE=verify`, so a repository whose normal install path can\ncompile native tooling can select a provisioning-only install path for source\nacceptance without weakening promotion installs.\nThe reusable job name remains `check`, and `upload-artifacts: false` disables\nevidence upload without changing the job conclusion used by branch protection.\n\nShared environment variables can be declared once:\n\n```toml\n[lifecycle.env]\nPYTHONUNBUFFERED = \"1\"\n```\n\nStage-specific environment variables override shared lifecycle environment:\n\n```toml\n[lifecycle.test]\ncommand = \"pytest\"\n\n[lifecycle.test.env]\nPYTHONPATH = \"src\"\n```\n\n### Publish Stage\n\n`lifecycle.publish` is the project-owned side-effect stage. It may call npm,\nPyPI, Conan, CMake packaging scripts, Docker/OCI registries, S3 uploaders, or\nany other publisher. Buildchain does not assume the tool; it assumes the\nevidence contract.\n\n```toml\n[lifecycle.publish]\nscript = \"\"\"\nset -euo pipefail\npython scripts/publish_wheels.py\nnode scripts/publish-images.mjs\nnode scripts/write-publish-evidence.mjs\n\"\"\"\n```\n\nWhen `actions/promote-buildchain-ref` runs with `publish-transaction: \"true\"`,\nthe publish stage receives the transaction identity plus the resolved publish\ncontract:\n\n```text\nBUILDCHAIN_VERSION\nBUILDCHAIN_CHANNEL\nBUILDCHAIN_SOURCE_SHA\nBUILDCHAIN_TARGET_REF\nBUILDCHAIN_RELEASE_STATE\nBUILDCHAIN_EVIDENCE_DIR\nBUILDCHAIN_RELEASE_SHA\nBUILDCHAIN_RELEASE_MATERIAL_SHA\nBUILDCHAIN_PUBLISH_TOOLING_SHA\nBUILDCHAIN_PUBLISH_EVIDENCE\nBUILDCHAIN_PUBLISH_MODE\nBUILDCHAIN_PUBLISH_AUTH\nBUILDCHAIN_NPM_DIST_TAG\nBUILDCHAIN_PACKAGE_SET_ORDER\nBUILDCHAIN_PACKAGE_SET_MAIN_PACKAGE\n```\n\nThe stage must write publish evidence JSON. Buildchain validates that evidence\nbefore exact tags and floating refs move. In GitHub Actions, the promotion\naction also persists `state.json` and `evidence.json` to\n`refs/heads/buildchain/release-state/<version>` so fresh runners can recover\nwithout local workspace residue. See\n[`docs/publish-transaction.md`](publish-transaction.md) for the state machine,\nevidence schema, and recovery commands.\n\nFor npm packages, prefer:\n\n```toml\n[publish]\nmode = \"publish-final-version\"\nauth = \"trusted-publishing\"\ndist_tag = \"latest\"\n```\n\nUse `mode = \"promote-existing-version\"` only for explicit same-version\ndist-tag recovery, and pair it with `auth = \"npm-token\"`. Trusted Publishing\ndoes not authorize `npm dist-tag add`; Buildchain fails that combination before\nany publish transaction side effect.\n\n## Promotion Semantics\n\n`actions/promote-buildchain-ref` consumes `version.files`, `lifecycle.verify`,\nand optionally `lifecycle.publish`.\n\nThe verify stage runs after Buildchain has applied the generated version-state\nchanges to the local checkout, and before it creates release commits or moves\nrefs. After the command finishes, Buildchain checks that only declared\nversion-state files changed. This prevents verification from quietly adding\nextra source changes to the release commit.\n\nBuildchain-owned untracked runtime evidence is excluded only through an exact\ninternal allowlist. This includes contract-drift issue material under\n`.buildchain/contract-drift/` and the paper workflow's\n`.buildchain/publication-result.json`, alongside release-candidate, passport,\nrelease-state, KFD, and runtime evidence directories. Tracked changes, ordinary\nsource files, and undeclared `.buildchain/*` paths still fail version\nverification.\n\nOn protected alpha and release branches, the generated version-state commit is\napplied by the promotion automation after the reviewed channel PR has merged.\nBuildchain keeps review requirements, conversation resolution, strict status\nchecks, and admin enforcement for human channel changes, but admits only the\nexact GitHub Actions App to the target-bound bypass allowlist for generated\nrelease bookkeeping. Buildchain also creates the configured required\ncheck on the exact generated version-state commit before patching the protected\nref, then applies the protected ref update with the declared generated ref\nupdate token. The reusable wrapper uses the run-scoped `github.token` for that\nprotected bookkeeping update. If finalization bookkeeping is still rejected,\nBuildchain creates or reuses a same-repository `buildchain/version-state/*` PR\nand reports `finalization-needed=true` so a later idempotent promotion run can\nresume. This fallback also applies to strict alpha target and dev\nreconciliation. The generated PR must pass the repository's normal protected\nchecks, review, and merge-queue policy; Buildchain never weakens that policy or\ntreats PR creation as completed finalization.\n\nFor `version.strategy = \"anchored\"` with `version.next = \"manual\"`, release\npromotion does not generate a Buildchain-owned version-state commit. In that\nmode, a protected `alpha -> release` PR may carry the declared `version.files`\nfrom the tested alpha package version to the final package version, and may\ncarry the configured `version.manifest` with it. Buildchain only accepts that\nrelease tree difference when the PR is the valid channel-promotion PR, the\nchanged paths are limited to those declared version files plus the anchor\nmanifest, and `lifecycle.verify` or `verification-command` has validated the\nchecked-out release material. Any code or undeclared file change still fails the\nrelease tree gate.\n\nThe action input `verification-command` remains supported. When it is provided,\nit overrides `lifecycle.verify` for that invocation. The override inherits\n`[lifecycle.env]` and `lifecycle.verify.env`; when the configured stage declares\n`shell`, it also inherits that shell. If the stage has no explicit shell,\nBuildchain preserves the platform-default shell for compatibility.\n\n## Migration Preflight\n\nHeavy repositories can validate their Buildchain declaration before they are\nready to run the real build. `actions/validate-config` checks that\n`.buildchain/buildchain.toml` parses, configured version-state files exist, configured\nversion keys are strings, and required lifecycle stage names are declared.\nFor web-surface repositories it also validates `project`, `channels`, `deploy`,\n`retention`, and `security` declarations.\n\nIt does not run lifecycle commands. This is useful for repositories such as\n`libnode`, where `lifecycle.build` represents an expensive multi-platform native\nbuild and the first migration milestone is to prove the release metadata and\nlifecycle protocol without consuming build runners.\n\n```yaml\n- uses: kungfu-systems/buildchain/actions/validate-config@v3\n  with:\n    require-version-state: \"true\"\n    require-lifecycle-stages: \"install,build,verify\"\n```\n\nWeb-surface repositories can use the same action without requiring version\nstate:\n\n```yaml\n- uses: kungfu-systems/buildchain/actions/validate-config@v3\n  with:\n    require-lifecycle-stages: \"build,verify\"\n```\n\nThe action exposes project and deploy metadata through outputs such as\n`project-type`, `project-site`, `channels`, and `deploy-adapters-json`.\n\n## Web-Surface Projects\n\n`project.type = \"web-surface\"` is for sites, docs, browser apps, and operator\nconsoles whose release object is a deployed surface, not a package version.\n\n```toml\nschema = 1\n\n[project]\ntype = \"web-surface\"\nname = \"site-libkungfu-dev\"\nsite = \"libkungfu-dev\"\n\n[channels.preview]\nurl_pattern = \"https://{alias}.preview.libkungfu.dev\"\nvisibility = \"ephemeral\"\nnoindex = true\n\n[channels.staging]\nurl = \"https://staging.libkungfu.dev\"\nvisibility = \"protected\"\naccess_control = \"managed-network\"\nedge_auth = \"none\"\nnoindex = true\npromotable = true\n\n[channels.production]\nurl = \"https://libkungfu.dev\"\nvisibility = \"public\"\ncanonical = true\nnoindex = false\n\n[surfaces.hub]\npath = \"/\"\nproduction_url = \"https://libkungfu.dev\"\nstaging_url = \"https://staging.libkungfu.dev\"\npreview_url_pattern = \"https://{alias}.preview.libkungfu.dev\"\n\n[surfaces.core]\npath = \"/core/\"\nproduction_url = \"https://core.libkungfu.dev\"\nstaging_url = \"https://core.staging.libkungfu.dev\"\npreview_url_pattern = \"https://core-{alias}.preview.libkungfu.dev\"\n\n[deploy.production]\nadapter = \"aws-s3-cloudfront\"\nbucket = \"libkungfu-dev-production\"\nartifact_path = \"dist\"\nsecret_refs = [\"AWS_ROLE_ARN\"]\n```\n\nSee [Web-surface deployments](web-surface-deployments.md) for named surface host\nmappings, the manifest, preview alias, retention, cleanup, and dry-run deploy\ncontract.\n\n## Infra-Contract Projects\n\n`project.type = \"infra-contract\"` is for infrastructure contract repositories\nthat need provider-neutral desired, plan, approval, apply, observe, contract,\nand propagation evidence. `buildchain init --type infra-contract` wires\n`lifecycle.verify` to `buildchain infra-contract --mode ci`, which writes\nmutation-free plan, contract, propagation dry-run, evidence bundle, and\nverification artifacts under `.buildchain/`. The surface supports\nmanual-observed, observe-only, and mocked adapter fixtures without reading\ncloud state files or executing live infrastructure mutation. See\n[Infra Contract](infra-contract.md).\n\n## Examples\n\n### Node Workspace\n\n```toml\nschema = 1\n\n[version]\nrequired = true\n\n[[version.files]]\ntype = \"json\"\npath = \"package.json\"\nkey = \"version\"\n\n[lifecycle.verify]\ncommands = [\n  \"pnpm run check\",\n]\n```\n\n### Python Package\n\n```toml\nschema = 1\n\n[version]\nrequired = true\n\n[[version.files]]\ntype = \"toml\"\npath = \"pyproject.toml\"\nkey = \"project.version\"\n\n[lifecycle.install]\ncommand = \"python -m pip install -e .[test]\"\n\n[lifecycle.build]\ncommand = \"python -m build\"\n\n[lifecycle.verify]\ncommands = [\n  \"python -m build\",\n  \"pytest\",\n]\n```\n\n### CMake and Conan\n\n```toml\nschema = 1\n\n[[version.files]]\ntype = \"regex\"\npath = \"CMakeLists.txt\"\npattern = 'project\\([^)]* VERSION (?<version>[^ )]+)'\nreplacement = '${version}'\n\n[lifecycle.configure]\ncommands = [\n  \"conan install . --build=missing\",\n  \"cmake -S . -B build -DCMAKE_BUILD_TYPE=Release\",\n]\n\n[lifecycle.build]\ncommand = \"cmake --build build --config Release\"\n\n[lifecycle.verify]\ncommands = [\n  \"cmake --build build --config Release\",\n  \"ctest --test-dir build --output-on-failure\",\n]\n```\n\n### Docker Image\n\n```toml\nschema = 1\n\n[[version.files]]\ntype = \"json\"\npath = \"package.json\"\nkey = \"version\"\n\n[lifecycle.build]\ncommand = \"docker build -f Dockerfile -t kungfutrader/example:${BUILDCHAIN_VERSION} .\"\n\n[lifecycle.verify]\ncommand = \"docker build -f Dockerfile -t kungfutrader/example:verify .\"\n```\n\nDocker publishing is an external side effect and should be gated by a release\nworkflow after version-state promotion has been verified.\n\n## Design Boundaries\n\nThe lifecycle protocol is also the command source for the reusable build\nsurface. `.github/workflows/.build.yml` runs `lifecycle.install`,\n`lifecycle.build`, and `lifecycle.verify` by default, while allowing callers to\noverride each stage with explicit workflow inputs. The underlying\n`actions/run-lifecycle` action can be used directly by repositories that need a\ncustom workflow but still want Buildchain's lifecycle and deterministic manifest\ncontract.\n\nBuildchain lifecycle commands are data, not executable configuration files.\nThey make release behavior reviewable in pull requests and keep the release\nfact chain simple:\n\n1. choose the channel branch and release line;\n2. generate a source version commit from declared version files;\n3. verify that exact tree;\n4. move exact tags and floating refs only after verification succeeds;\n5. run publish or deployment side effects in separately gated workflows."
    },
    {
      "id": "manual:map",
      "title": "Documentation Map",
      "route": "/docs/map",
      "category": "manual",
      "capabilityGroup": "getting-started",
      "audience": [
        "agent",
        "consumer"
      ],
      "maturity": "stable",
      "sourcePath": "docs/MAP.md",
      "digest": "sha256:94a4866f5a44f97ab10ad460c4d9ff39c58aa28e231311425af2fcb857aa8c72",
      "headings": [
        {
          "level": 1,
          "title": "Documentation Map",
          "anchor": "documentation-map"
        },
        {
          "level": 2,
          "title": "Start by Role or Intent",
          "anchor": "start-by-role-or-intent"
        },
        {
          "level": 2,
          "title": "Capability Coverage",
          "anchor": "capability-coverage"
        },
        {
          "level": 2,
          "title": "Map",
          "anchor": "map"
        },
        {
          "level": 2,
          "title": "Also asking about",
          "anchor": "also-asking-about"
        },
        {
          "level": 2,
          "title": "How this map is maintained",
          "anchor": "how-this-map-is-maintained"
        }
      ],
      "markdown": "---\nstatus: active\nperiod: ongoing\ntheme: buildchain-documentation-map\ndoc_type: technical-reference\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-07-31\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-31\n  invisible_context: not asserted\n---\n\n# Documentation Map\n\nStart here. Find the question you have; follow it to the document that answers\nit. This map is meant to be readable by both a person skimming for the right doc\nand an agent grounding a specific claim.\n\nEach row carries a **plane** - *why* (intent / rationale), *verify* (trust the\nrunning artifact), *use* (consume / extend) - and a **status**:\n\n- `stable` - current and holds.\n- `draft` - exists, rough or incomplete.\n- `to write` - planned; the material exists but is not yet a single doc.\n- `retired` - intentionally not part of the active Buildchain v3 surface.\n\n## Start by Role or Intent\n\n| Role or intent | First entry | Then |\n| --- | --- | --- |\n| First-time repository adopter | [Golden Path](getting-started.md) | [Lifecycle Protocol](lifecycle-protocol.md) only when the generated defaults need changes |\n| CLI operator or agent | [Generated CLI Reference](cli-reference.md) | [CLI guide](cli.md) for concepts and worked examples |\n| Node toolkit developer | [Generated Node API Reference](node-api-reference.md) | [Core package guide](../packages/core/README.md) for recipes |\n| Build/release operator | [Reusable Build Surface](reusable-build-surface.md) | [Release Flow](release-flow.md) and [Release Passport](release-passport.md) |\n| Product/trust reviewer | [Product Mechanism](product-mechanism.md) | [Release Passport](release-passport.md) and [KFD Support](kfd-support.md) |\n\nThese entrypoints keep common destinations within three meaningful hops:\nREADME or this map, the role entry, and the normative contract or generated\nreference.\n\n## Capability Coverage\n\nThis package should be usable by an agent from the npm artifact alone. The\nmachine-readable `dist/site/` bundle is the first fact source; the Markdown\nmanuals explain those facts and give operator examples.\n\n`dist/site/capability-registry.json` is the capability navigation entrypoint.\nIt groups the public surface into stable product areas so sites and agents do\nnot have to infer structure from file names. Each page, manual, CLI command,\nworkflow, action, and Node API export also carries a `capabilityGroup`,\n`audience`, and `maturity` field in its own registry.\n\n| Capability group | Primary facts | Primary manuals |\n| --- | --- | --- |\n| Getting Started | `capability-registry.json`, `product-mechanism.json` | [`getting-started.md`](getting-started.md), [`install.md`](install.md), [`product-mechanism.md`](product-mechanism.md), [`cli.md`](cli.md) |\n| Release Passport and Trust | `release-model.json`, `artifact-schemas.json`, `publication-authority-registry.json`, `kfd-claims.json` | [`release-passport.md`](release-passport.md), [`github-artifact-attestation.md`](github-artifact-attestation.md), [`publication-authority.md`](publication-authority.md), [`release-candidate.md`](release-candidate.md), [`release-train.md`](release-train.md), [`publish-transaction.md`](publish-transaction.md), [`release-tail-contract.md`](release-tail-contract.md), [`binary-distribution.md`](binary-distribution.md) |\n| Reusable Build and Lifecycle | `workflow-registry.json`, `controller-registry.json`, `release-model.json` | [`reusable-build-surface.md`](reusable-build-surface.md), [`controller-evidence.md`](controller-evidence.md), [`shifu-gate-profiles.md`](shifu-gate-profiles.md), [`lifecycle-protocol.md`](lifecycle-protocol.md) |\n| KFD Trust and Surface Closure | `kfd-claims.json`, `public-surface-audit.json`, `cli-registry.json`, `node-api-registry.json` | [`kfd-support.md`](kfd-support.md), [`release-passport.md`](release-passport.md) |\n| Site Bundle, Web Surfaces, and Propagation | `buildchain-site.json`, `site-manifest.json`, `page-registry.json`, `release-model.json` | [`site-bundle-contract.md`](site-bundle-contract.md), [`web-surface-deployments.md`](web-surface-deployments.md), [`release-propagation.md`](release-propagation.md) |\n| Publication Artifacts | `publication-registry.json`, `workflow-registry.json`, `node-api-registry.json`, `manual-registry.json`, `kungfu-buildchain-publication-artifact-registry` | [`publication-artifacts.md`](publication-artifacts.md), [`reusable-build-surface.md`](reusable-build-surface.md) |\n| Distribution Indexes and Badges | `badge-endpoint-registry.json`, `node-api-registry.json`, `manual-registry.json` | [`readme-badges.md`](readme-badges.md), [`homebrew.md`](homebrew.md) |\n| Build Facts, Observability, and Diagnostics | `cli-registry.json`, `node-api-registry.json`, lifecycle artifacts | [`build-facts.md`](build-facts.md), [`toolkit-observability.md`](toolkit-observability.md), [`consumer-issue-reporting.md`](consumer-issue-reporting.md) |\n| Governance, Versioning, and Runtime Drift | `buildchain-contract.json`, `workflow-registry.json`, `release-model.json` | [`github-governance-authority.md`](github-governance-authority.md), [`release-governance.md`](release-governance.md), [`release-flow.md`](release-flow.md), [`versioning.md`](versioning.md), [`runtime-train-validation.md`](runtime-train-validation.md), [`cli.md`](cli.md) |\n| CLI and Node API Reference | `cli-registry.json`, `node-api-registry.json`, `workflow-registry.json`, `manual-registry.json` | [`cli-reference.md`](cli-reference.md), [`node-api-reference.md`](node-api-reference.md), [`cli.md`](cli.md), [`../packages/core/README.md`](../packages/core/README.md) |\n\n| Capability | Machine-readable entry | Manual entry |\n| --- | --- | --- |\n| Capability-grouped KFD navigation | `dist/site/capability-registry.json`, `dist/site/page-registry.json`, `dist/site/manual-registry.json`, `dist/site/cli-registry.json`, `dist/site/node-api-registry.json` | this map, [`site-bundle-contract.md`](site-bundle-contract.md), [`kfd-support.md`](kfd-support.md) |\n| KFD-1 / KFD-2 / KFD-3 release-passport gates | `dist/site/kfd-claims.json`, `dist/site/buildchain-contract.json`, `dist/site/artifact-schemas.json` | [`release-passport.md`](release-passport.md) |\n| Product invariant Passport release gate | `buildchain.release.json#invariantPassports`, `dist/site/buildchain-contract.json` | [`release-passport.md`](release-passport.md) |\n| GitHub keyless Linux artifact attestation | `buildchain.release.json#githubArtifactAttestations`, `dist/site/workflow-registry.json`, `dist/site/artifact-schemas.json` | [`github-artifact-attestation.md`](github-artifact-attestation.md) |\n| Declarative cross-platform artifact signing | `kungfu-buildchain-artifact-signing-request/v1`, `kungfu-buildchain-artifact-signing-result/v1` | [`reusable-build-surface.md`](reusable-build-surface.md#artifact-signing-authority) |\n| KFD-3 public surface reverse audit | `dist/site/public-surface-audit.json`, `dist/site/cli-registry.json`, `dist/site/workflow-registry.json`, `dist/site/page-registry.json` | [`cli.md`](cli.md), [`site-bundle-contract.md`](site-bundle-contract.md) |\n| KFD-1 / KFD-2 / KFD-3 first-class CLI and Node API | `.buildchain/kfd/kfd-3/surfaces.json`, `dist/site/kfd-claims.json`, `buildchain.release.json`, KFD schemas from `@kungfu-tech/kfd` | [`kfd-support.md`](kfd-support.md), [`cli.md`](cli.md#commands) |\n| Declarative KFD Agent Hub adapter conformance and Passport evidence | `.buildchain/kfd/agent-hub.json`, `.buildchain/artifacts/kfd-agent-hub/evidence.json`, `buildchain.release.json#kfdAgentHub` | [`kfd-agent-hub.md`](kfd-agent-hub.md) |\n| Floating `@v3` drift detection and compatibility issues | `dist/site/buildchain-contract.json` | [`reusable-build-surface.md`](reusable-build-surface.md#floating-ref-contract-lock) |\n| npm publish transactions, evidence, dist-tags, and recovery | `dist/site/release-model.json`, `dist/site/artifact-schemas.json` | [`publish-transaction.md`](publish-transaction.md) |\n| Git/source/version/module/product build facts | `dist/site/node-api-registry.json`, `dist/site/cli-registry.json`, `kungfu-buildchain-module-build-facts`, `kungfu-buildchain-product-build-facts` | [`build-facts.md`](build-facts.md) |\n| GitHub Release passport/evidence publication | `dist/site/release-model.json`, `dist/site/artifact-schemas.json` | [`release-governance.md`](release-governance.md), [`release-candidate.md`](release-candidate.md) |\n| GitHub ownership, effective protection, plan capability, and managed-zone governance receipts | `dist/site/node-api-registry.json`, `dist/site/cli-registry.json`, `kungfu-buildchain-github-governance-receipt` | [`github-governance-authority.md`](github-governance-authority.md) |\n| release propagation and the unified Paper/KFD/Buildchain/Core Site agent entry | `dist/site/release-model.json`, `dist/site/cli-registry.json`, `dist/site/node-api-registry.json` | [`release-propagation.md`](release-propagation.md) |\n| publication artifact manifests, immutable archive registries, source bundles, and paper repository workflows | `dist/site/publication-registry.json`, `dist/site/workflow-registry.json`, `dist/site/node-api-registry.json`, `kungfu-buildchain-publication-artifact-manifest`, `kungfu-buildchain-publication-artifact-registry` | [`publication-artifacts.md`](publication-artifacts.md) |\n| Generated badge bundles, README badge blocks, and badge facts | `dist/site/node-api-registry.json`, `dist/site/manual-registry.json`, `kungfu-buildchain-badge-bundle-facts`, `kungfu-buildchain-readme-badge-facts` | [`readme-badges.md`](readme-badges.md) |\n| Homebrew tap distribution indexes | `dist/site/node-api-registry.json`, `dist/site/buildchain-contract.json` | [`homebrew.md`](homebrew.md) |\n| Buildchain CLI manual | `dist/site/cli-registry.json`, `dist/site/manual-registry.json` | [`cli.md`](cli.md) |\n| Node API / package exports | `dist/site/node-api-registry.json`, `dist/site/release-provenance.json` | [`cli.md`](cli.md#node-api-and-package-exports) |\n\n`dist/site/kfd-claims.json` is generated from\n`packages/core/buildchain-kfd-claims.js`. Treat that module and JSON file as the\nsource claim registry; this map and the manuals explain those claims but do not\nreplace them.\n\n## Map\n\n| Your question | Document | Plane | Status |\n| --- | --- | --- | --- |\n| What is Buildchain, in one idea? | [`../README.md`](../README.md) | - | stable |\n| How do I complete a first clean adoption in 15–30 minutes? | [`getting-started.md`](getting-started.md) | use | stable |\n| Why is Buildchain a Release Passport mechanism rather than a generic workflow collection? | [`product-mechanism.md`](product-mechanism.md) | why | stable |\n| How do agents and contributors enter this repo? | [`../AGENTS.md`](../AGENTS.md) + [`../CONTRIBUTING.md`](../CONTRIBUTING.md) | use | stable |\n| How do I install a standalone binary or npm package? | [`install.md`](install.md) | use | stable |\n| How do I run or look up the `buildchain` CLI? | [`cli-reference.md`](cli-reference.md) + [`cli.md`](cli.md) | use | stable |\n| How do I import Buildchain toolkit APIs from JavaScript build code? | [`node-api-reference.md`](node-api-reference.md) + [`../packages/core/README.md`](../packages/core/README.md) | use | stable |\n| How do I initialize a new repository? | [`getting-started.md`](getting-started.md) + [`lifecycle-protocol.md`](lifecycle-protocol.md) | use | stable |\n| Why does Buildchain use branch-driven release governance? | [`release-governance.md`](release-governance.md) | why | stable |\n| What freezes the v4 dependency direction, writer authority, complexity budgets, exceptions, and N-1 qualification? | [`../architecture/v4-architecture-constitution.md`](../architecture/v4-architecture-constitution.md) | why/verify | preview |\n| How will Delivery Warrant move from the v3 writer through shadow, v4 read, single-writer cutover, and legacy removal? | [`../architecture/v4-delivery-warrant-shadow-bootstrap-plan.md`](../architecture/v4-delivery-warrant-shadow-bootstrap-plan.md) | why/verify | preview |\n| What exact canonical bytes, roots, clocks, event, receipt, and typed-fault contracts do Rust and JavaScript share in v4? | [`v4-canonical-contracts.md`](v4-canonical-contracts.md) | use/verify | preview |\n| How is one per-platform v4 build stage identified, retained, observed, and reused without provider identity or a second writer? | [`v4-stage-capsule.md`](v4-stage-capsule.md) | use/verify | preview |\n| How does a late platform failure deterministically reuse qualified Stage Capsules and rebuild only invalid or missing dependencies? | [`v4-stage-capsule.md`](v4-stage-capsule.md#deterministic-resume-planning) | use/verify | preview |\n| How do Rust and JavaScript read the same retained Delivery Warrant traces and emit one semantic projection? | [`v4-canonical-contracts.md`](v4-canonical-contracts.md#shared-delivery-warrant-fixture-runner) | use/verify | preview |\n| How does an explicit caller try the qualified v4 read projection and roll back without moving v3 writer authority? | [`v4-delivery-warrant-read-candidate.md`](v4-delivery-warrant-read-candidate.md) | use/verify | preview |\n| How do protected dev branches and scheduled ready-PR merging work? | [`release-governance.md`](release-governance.md#protected-dev-branches) | use | stable |\n| How do slow required checks land reliably on a busy dev channel? | [`release-governance.md`](release-governance.md#protected-dev-branches) + [`cli.md`](cli.md#commands) | use | preview |\n| How does the durable fair Dev Delivery Warrant Queue prevent slow-candidate starvation?                                                       | [`dev-delivery-warrant.md`](dev-delivery-warrant.md)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | use/verify | preview |\n| How do I coalesce rapid Dev changes, preserve release runner priority, and retry only transient failed jobs? | [`dev-qualification-patrol.md`](dev-qualification-patrol.md) | use/verify | preview |\n| How do I run daily, weekly, or monthly repository patrols? | [`release-governance.md`](release-governance.md#buildchain-patrol) | use | stable |\n| How do I report or safely apply branch and pull-request engineering hygiene? | [`engineering-housekeeper.md`](engineering-housekeeper.md) | use/verify | preview |\n| How does Buildchain decide patch, minor, and major release lines? | [`versioning.md`](versioning.md) | why | stable |\n| What exact branch/tag state machine runs on alpha, release, and major gate? | [`release-flow.md`](release-flow.md) | verify | stable |\n| What did Buildchain migrate or retire from old action repositories? | [`migration-inventory.md`](migration-inventory.md) | verify | stable |\n| What is the active action and workflow source of truth? | [`ownership.md`](ownership.md) | verify | stable |\n| How do I declare version files and custom lifecycle commands? | [`lifecycle-protocol.md`](lifecycle-protocol.md) | use | stable |\n| How does publish evidence, recovery, and finalization work? | [`publish-transaction.md`](publish-transaction.md) | verify | stable |\n| How are consumer-owned release-tail commands inventoried and replaced by declarative capabilities? | [`release-tail-contract.md`](release-tail-contract.md) | verify | draft |\n| How do I collect and verify module/product build facts from Git source, version files, and outputs? | [`build-facts.md`](build-facts.md) + [`cli.md`](cli.md) | use/verify | stable |\n| How do I publish or verify release passport artifacts? | [`release-passport.md`](release-passport.md) | use | stable |\n| How do I keylessly attest Linux release artifacts with GitHub and bind them to a Release Passport? | [`github-artifact-attestation.md`](github-artifact-attestation.md) | verify/use | preview |\n| How do I request detached, Developer ID, or Authenticode signing without consumer credentials? | [`reusable-build-surface.md`](reusable-build-surface.md#artifact-signing-authority) | verify/use | preview |\n| How do I seal exact artifact, identity, lifecycle, and KFD assessment roots for KFX admission? | [`artifact-verification-envelope.md`](artifact-verification-envelope.md) | verify/use | preview |\n| How is product publication authority sealed to an exact workflow, runner, control plane, nonce, and artifact? | [`publication-authority.md`](publication-authority.md) | verify | preview |\n| How are GitHub ownership, independent review, effective protection, and plan capability audited fail-closed? | [`github-governance-authority.md`](github-governance-authority.md) | verify | preview |\n| How do I gate release artifacts with KFD-1 contract-world witnesses? | [`release-passport.md`](release-passport.md#kfd-1-contract-world-release-gate) | verify/use | stable |\n| How do I declare, render, and audit product KFD-2 release trust claims? | [`kfd-support.md`](kfd-support.md#kfd-2) + [`release-passport.md`](release-passport.md#kfd-2-release-trust-passport-audit) + [`cli.md`](cli.md) | verify/use | stable |\n| How do I gate KFD-3 collaboration-interface releases? | [`release-passport.md`](release-passport.md#kfd-3-collaboration-interface-release-gate) + [`cli.md`](cli.md) | verify/use | stable |\n| How do I detect, register, audit, witness, or query KFD-3 product surfaces? | [`kfd-support.md`](kfd-support.md) + [`cli.md`](cli.md) | verify/use | stable |\n| How do I adopt the KFD Agent Hub profile with one declaration and one adapter? | [`kfd-agent-hub.md`](kfd-agent-hub.md) | verify/use | preview |\n| How do I keep `@v3` floating refs while detecting Buildchain contract drift? | [`reusable-build-surface.md`](reusable-build-surface.md#floating-ref-contract-lock) | verify/use | stable |\n| How do reusable workflows bind controller intent, source/runtime identity, outcomes, and receipt evidence? | [`controller-evidence.md`](controller-evidence.md) | verify/use | draft |\n| How does an Agent propagate a finalized upstream release through downstream PR, deployment, production readback, and Work Control completion? | [`release-propagation.md`](release-propagation.md) | use/verify | preview |\n| How do paper or report repositories publish PDFs, metadata, source bundles, site-consumable manifests, npm packages, and GitHub Releases? | [`publication-artifacts.md`](publication-artifacts.md) | use | stable |\n| How do I generate KFD / Release Passport badge bundles without hand-maintaining Markdown? | [`readme-badges.md`](readme-badges.md) + [`cli.md`](cli.md) | use | stable |\n| How do I generate and verify a Homebrew tap from release passport evidence? | [`homebrew.md`](homebrew.md) + [`cli.md`](cli.md) | use/verify | stable |\n| How do I prove a PR-stage reusable build is the artifact source promoted later? | [`release-candidate.md`](release-candidate.md) + [`reusable-build-surface.md`](reusable-build-surface.md) | verify | stable |\n| Why are binary release assets archived by platform, and where is the single bundle? | [`binary-distribution.md`](binary-distribution.md) | verify | stable |\n| How do I add timestamped logs inside build scripts? | [`toolkit-observability.md`](toolkit-observability.md) | use | stable |\n| What package-owned facts should buildchain.libkungfu.dev render? | [`site-bundle-contract.md`](site-bundle-contract.md) | use | stable |\n| How do I call the reusable build workflow? | [`reusable-build-surface.md`](reusable-build-surface.md) | use | stable |\n| How does Buildchain schedule and aggregate a project-owned Shifu Gate profile? | [`shifu-gate-profiles.md`](shifu-gate-profiles.md) | use/verify | draft |\n| How do exact build artifacts become qualified, transcript-traceable demo media? | [`auditable-demo.md`](auditable-demo.md) | use/verify | draft |\n| How do I use one build job that follows alpha during development and stable for releases? | [`reusable-build-surface.md`](reusable-build-surface.md#automatic-channel-router) | use | preview |\n| How do self-hosted runners relay large artifacts through S3 before GitHub artifacts? | [`reusable-build-surface.md`](reusable-build-surface.md#artifact-transfer-relay) | use | stable |\n| How do self-hosted runners reuse local Git checkout caches without weakening source locks? | [`reusable-build-surface.md`](reusable-build-surface.md#locked-source-checkout-cache) | use | stable |\n| How do ephemeral GitHub-hosted runners share exact dependency or compiler caches without fixed-runner affinity? | [`cli.md`](cli.md#commands) | use/verify | preview |\n| How do I validate an unreleased Buildchain runtime train while keeping `@v3`? | [`runtime-train-validation.md`](runtime-train-validation.md) | use | stable |\n| How do I automatically qualify alpha candidates and publish the newest non-revoked qualified candidate at a fixed window? | [`stable-candidate-patrol.md`](stable-candidate-patrol.md) | use | preview |\n| How do I deploy a site/app preview, staging, or production surface? | [`web-surface-deployments.md`](web-surface-deployments.md) | use | stable |\n| How do I publish observed infrastructure contracts for downstream consumers? | [`infra-contract.md`](infra-contract.md) | use | preview |\n| How do I operate a repeatable, disabled-by-default, budget-fail-closed AWS Windows JIT campaign? | [`aws-us-elastic-runner-burst-plane.md`](aws-us-elastic-runner-burst-plane.md#phase-2-operator-workflow) | use/verify | preview |\n| How do I use the active actions directly? | [`../actions/validate-config/README.md`](../actions/validate-config/README.md), [`../actions/run-lifecycle/README.md`](../actions/run-lifecycle/README.md), [`../actions/promote-buildchain-ref/README.md`](../actions/promote-buildchain-ref/README.md), [`../actions/report-buildchain-issue/README.md`](../actions/report-buildchain-issue/README.md), [`../actions/github-artifact-attestation/README.md`](../actions/github-artifact-attestation/README.md), [`../actions/macos-credential-island/README.md`](../actions/macos-credential-island/README.md), [`../actions/release-tail/README.md`](../actions/release-tail/README.md); `dist/site/workflow-registry.json#actions` is authoritative for the seven-entry inventory. | use | stable |\n| How can a consumer workflow report a Buildchain-owned failure back to Buildchain? | [`consumer-issue-reporting.md`](consumer-issue-reporting.md) + [`../actions/report-buildchain-issue/README.md`](../actions/report-buildchain-issue/README.md) | use | stable |\n| What do the fixture repositories demonstrate? | [`../fixtures/libnode-shaped/README.md`](../fixtures/libnode-shaped/README.md), [`../fixtures/publish-transaction-shaped/README.md`](../fixtures/publish-transaction-shaped/README.md), [`../fixtures/web-surface-shaped/README.md`](../fixtures/web-surface-shaped/README.md), [`../fixtures/publication-artifact-shaped/README.md`](../fixtures/publication-artifact-shaped/README.md) | verify | stable |\n| What license and contribution terms apply? | [`../LICENSE`](../LICENSE) + [`../LICENSE-POLICY.md`](../LICENSE-POLICY.md) | use | stable |\n| What trademark, official-service, and provider-compliance boundaries apply? | [`../TRADEMARK.md`](../TRADEMARK.md) + [`../ACCEPTABLE_USE.md`](../ACCEPTABLE_USE.md) + [`../PROVIDER_COMPLIANCE.md`](../PROVIDER_COMPLIANCE.md) | use | stable |\n| How do I report a vulnerability? | [`../SECURITY.md`](../SECURITY.md) | use | stable |\n\n## Also asking about\n\n- **ABV / old workflows / old action repositories** -> [`release-governance.md`](release-governance.md)\n  and [`migration-inventory.md`](migration-inventory.md).\n- **v3 / v3-alpha / v3.0 / v3.0-alpha / exact tags / floating tags** ->\n  [`release-governance.md`](release-governance.md) and\n  [`release-flow.md`](release-flow.md).\n- **Buildchain self-dogfood / released alpha canary / stable compatibility lane** ->\n  [`release-governance.md`](release-governance.md#buildchain-alpha-self-dogfood).\n- **qualified alpha ledger / scheduled stable selection / hold and revoke** ->\n  [`stable-candidate-patrol.md`](stable-candidate-patrol.md).\n- **v3.1 vs v3.2 / when to open a new minor line** ->\n  [`versioning.md`](versioning.md).\n- **dry-run / what would happen if this channel PR merges** -> [`cli.md`](cli.md)\n  and [`release-flow.md`](release-flow.md).\n- **protected dev branches / scheduled ready-PR merge / daily-weekly-monthly patrol** ->\n  [`release-governance.md`](release-governance.md#protected-dev-branches) and\n  [`release-governance.md`](release-governance.md#buildchain-patrol).\n- **Dev qualification coalescing / release-priority runners / failed-job retry** ->\n  [`dev-qualification-patrol.md`](dev-qualification-patrol.md).\n- **pnpm / npm / yarn / package-manager adapters** ->\n  [`lifecycle-protocol.md`](lifecycle-protocol.md).\n- **pip / Conan / CMake / custom commands** -> [`lifecycle-protocol.md`](lifecycle-protocol.md)\n  and [`reusable-build-surface.md`](reusable-build-surface.md).\n- **libnode / native artifacts / self-hosted runner matrix** ->\n  [`reusable-build-surface.md`](reusable-build-surface.md) and\n  [`../fixtures/libnode-shaped/README.md`](../fixtures/libnode-shaped/README.md).\n- **S3 artifact relay / self-hosted runner artifact transfer** ->\n  [`reusable-build-surface.md`](reusable-build-surface.md#artifact-transfer-relay).\n- **local Git checkout cache / self-hosted source transport** ->\n  [`reusable-build-surface.md`](reusable-build-surface.md#locked-source-checkout-cache).\n- **runtime train validation / temporary `buildchain-ref` override** ->\n  [`runtime-train-validation.md`](runtime-train-validation.md) and\n  [`reusable-build-surface.md`](reusable-build-surface.md).\n- **consumer workflow feedback / automatic Buildchain GitHub issues** ->\n  [`consumer-issue-reporting.md`](consumer-issue-reporting.md).\n- **PR-stage RC artifacts / promote-only release candidates** ->\n  [`release-candidate.md`](release-candidate.md) and\n  [`reusable-build-surface.md`](reusable-build-surface.md).\n- **infra contract / observed infrastructure outputs / downstream contract propagation** ->\n  [`infra-contract.md`](infra-contract.md).\n- **standalone binary install / platform archives / GitHub Release bundle** ->\n  [`install.md`](install.md), [`binary-distribution.md`](binary-distribution.md),\n  and [`release-passport.md`](release-passport.md).\n- **Trusted Publishing / npm / publish evidence / recovery** ->\n  [`cli.md`](cli.md) and [`publish-transaction.md`](publish-transaction.md).\n- **Git source digest / module build facts / product build facts / legacy\n  Kungfu build info** -> [`build-facts.md`](build-facts.md) and [`cli.md`](cli.md).\n- **release chains / upstream package or publication artifact as source of truth / site synchronization** ->\n  [`release-propagation.md`](release-propagation.md).\n- **paper repositories / PDFs / publication manifests / immutable archive registries / source bundles** ->\n  [`publication-artifacts.md`](publication-artifacts.md).\n- **README status badges / KFD badge bundles / badge facts JSON** ->\n  [`readme-badges.md`](readme-badges.md) and [`cli.md`](cli.md).\n- **Homebrew taps / distribution indexes / Formula drift checks** ->\n  [`homebrew.md`](homebrew.md) and [`cli.md`](cli.md).\n- **KFD-1 contract worlds / byte-for-byte release gates** ->\n  [`release-passport.md`](release-passport.md#kfd-1-contract-world-release-gate).\n- **KFD-2 public release trust claim audit** ->\n  [`release-passport.md`](release-passport.md#kfd-2-release-trust-passport-audit).\n- **KFD-3 collaboration-interface / agent-facing control surface closure** ->\n  [`release-passport.md`](release-passport.md#kfd-3-collaboration-interface-release-gate).\n- **floating `@v3` / contract lock / compatible drift issue** ->\n  [`reusable-build-surface.md`](reusable-build-surface.md#floating-ref-contract-lock).\n- **GitHub Release passport / binary assets / artifact evidence / agent release checks** ->\n  [`release-passport.md`](release-passport.md),\n  [`binary-distribution.md`](binary-distribution.md), and [`cli.md`](cli.md).\n- **Buildchain logging / timestamps / consumer build phase timing** ->\n  [`toolkit-observability.md`](toolkit-observability.md) for JavaScript API\n  imports, and [`cli.md`](cli.md) for workflow or shell command usage.\n- **buildchain.libkungfu.dev / package-owned site facts** ->\n  [`site-bundle-contract.md`](site-bundle-contract.md).\n- **sites / web previews / staging / production gates** ->\n  [`web-surface-deployments.md`](web-surface-deployments.md).\n- **trademark / fork / official service / provider compliance / release\n  evidence boundary** -> [`../TRADEMARK.md`](../TRADEMARK.md),\n  [`../ACCEPTABLE_USE.md`](../ACCEPTABLE_USE.md), and\n  [`../PROVIDER_COMPLIANCE.md`](../PROVIDER_COMPLIANCE.md).\n\n## How this map is maintained\n\n- A document becomes a row here when it is a stable entrypoint for a user,\n  contributor, or workflow consumer.\n- A row's status must never claim more than the artifact delivers.\n- `why` documents explain intent and design pressure; `verify` and `use`\n  documents should state what is guaranteed, where to verify it, and the current\n  maturity of that guarantee."
    },
    {
      "id": "manual:migration-inventory",
      "title": "Buildchain v2 Migration Inventory",
      "route": "/docs/migration-inventory",
      "category": "manual",
      "capabilityGroup": "governance-versioning",
      "audience": [
        "maintainer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "docs/migration-inventory.md",
      "digest": "sha256:25d896711f4efebffa9a8960b7eb97438d9fd4892aa08bef0339026e83a53bdf",
      "headings": [
        {
          "level": 1,
          "title": "Buildchain v2 Migration Inventory",
          "anchor": "buildchain-v2-migration-inventory"
        },
        {
          "level": 2,
          "title": "Workflow Sources",
          "anchor": "workflow-sources"
        },
        {
          "level": 2,
          "title": "Reusable Workflow Boundaries",
          "anchor": "reusable-workflow-boundaries"
        },
        {
          "level": 2,
          "title": "Migrated Actions",
          "anchor": "migrated-actions"
        },
        {
          "level": 2,
          "title": "Retired Actions Excluded From v2",
          "anchor": "retired-actions-excluded-from-v2"
        },
        {
          "level": 2,
          "title": "Retired Workflows Excluded From v2",
          "anchor": "retired-workflows-excluded-from-v2"
        },
        {
          "level": 2,
          "title": "Buildchain-Native Actions",
          "anchor": "buildchain-native-actions"
        },
        {
          "level": 2,
          "title": "Current v3 Refs",
          "anchor": "current-v3-refs"
        },
        {
          "level": 2,
          "title": "Verification Gates",
          "anchor": "verification-gates"
        }
      ],
      "markdown": "---\nstatus: historical\nperiod: 2026-07\ntheme: buildchain-v2-migration-inventory\ndoc_type: migration-inventory\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-07-31\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-31\n  invisible_context: not asserted\n---\n\n# Buildchain v2 Migration Inventory\n\nThis historical inventory records the Buildchain v2 consolidation boundary.\nBuildchain v3 is now the active monorepo source of truth for Kungfu repository\nworkflows, reusable build workflows, and Buildchain-native actions. The v2\nnames below preserve the migration decisions that v3 inherited; they are not a\ncurrent runtime baseline.\nStandalone `workflows` and `action-*` repositories are historical rollback\nanchors, not active Buildchain migration targets.\n\n## Workflow Sources\n\n| Source repository | Previous branch | Buildchain v2 disposition |\n| --- | --- | --- |\n| `workflows` | `dev/v2/v2.0` | root `.github/workflows` sources migrated; reusable workflows linted by actionlint |\n\n## Reusable Workflow Boundaries\n\nThe active Buildchain-native reusable surface is:\n\n| Workflow | Disposition |\n| --- | --- |\n| `.github/workflows/.build.yml` | active reusable build contract: runner presets, trusted event gate, publish source lock, lifecycle commands, deterministic artifacts, aggregate summary, and release manifest outputs |\n\nHidden reusable workflow files from the old `workflows` repository are retained\nonly when they still have an active compatibility or migration boundary. Retired\nPR orchestration paths are not kept in `.github/workflows`; they remain listed\nin the inventory as excluded legacy surfaces. In particular,\n`.batch-pull-request.yml` is removed with the retired batch PR action family,\nand the legacy `.release-new-version.yml` path is not the modern publish\nsurface. New publish integrations should use `.build.yml`, `buildchain.toml`,\n`lifecycle.publish`, and publish transaction evidence.\n\nRelease templates that previously performed direct publishing or deployment are\nnow fail-closed when retained for compatibility discovery. They do not call\nlegacy publish actions, `npm publish`, or deploy providers directly. Callers must\nmigrate to `release-candidate-promote.yml@v3` or a project-owned\n`lifecycle.publish` command behind a publish-gate source lock, so floating\n`@v3` consumers cannot bypass source-lock drift protection.\n\nThe public promotion workflow is now a generated dual-channel router. Existing\ncallers remain source-compatible, while callers that want alpha workflow-shell\nfixes before stable promotion should add `buildchain-channel: auto` plus\n`buildchain-alpha-contract-lock-path` and\n`buildchain-stable-contract-lock-path`. Keep one common promotion declaration;\ndo not duplicate alpha and stable jobs or call\n`.release-candidate-promote.yml` directly.\n\nBuildchain also keeps the workflow-file layout transition declarative in\n`.buildchain/promotion-shell-routing.json`. Stable `v2.14.13` contains the hidden\nadvanced workflow, so the stable lane is pinned to that implementation's\nimmutable release SHA and forwards the full internal identity surface. This is\nprovider-owned compatibility state; consumers still keep the same single public\npromotion job.\n\n## Migrated Actions\n\nNo standalone `action-*` repository is shipped as a Buildchain action anymore.\nOld product, operations, PR-helper, page-generation, dependency-sync, and\nversion-bump actions have either been retired or absorbed into Buildchain's\nnative lifecycle, reusable workflow, and promotion scripts.\n\n## Retired Actions Excluded From v2\n\nThese legacy action repositories are intentionally not shipped as buildchain v2\nactions because the corresponding workflows now reject the retired mechanism or\nbecause the action is part of that retired path.\n\n| Previous repository | Reason |\n| --- | --- |\n| `action-approve` | retired GitHub issue/PR helper; use repository-native GitHub automation |\n| `action-batch-pull-request` | retired PR orchestration helper; not part of the Buildchain reusable contract |\n| `action-bump-version` | replaced by Buildchain release-line scripts and `actions/promote-buildchain-ref` |\n| `action-check-format` | replaced by project-owned `lifecycle.verify` commands |\n| `action-find-dependencies` | retired in workflows v2 or backed by retired Airtable/dependency/collaborator/purge mechanism |\n| `action-generate-download-page` | retired product page generator; model as project-owned lifecycle/deploy work if needed |\n| `action-generate-release-page` | retired product page generator; model as project-owned lifecycle/deploy work if needed |\n| `action-merge-close-issue` | retired GitHub issue/PR helper; use repository-native GitHub automation |\n| `action-package-dependency` | retired in workflows v2 or backed by retired Airtable/dependency/collaborator/purge mechanism |\n| `action-publish-prebuilt` | retired S3 prebuilt publisher; use lifecycle publish plus publish transaction evidence |\n| `action-purge-artifacts` | retired in workflows v2 or backed by retired Airtable/dependency/collaborator/purge mechanism |\n| `action-qa-automated` | retired external QA trigger; model as project-owned lifecycle or workflow logic |\n| `action-release-note` | retired in workflows v2 or backed by retired Airtable/dependency/collaborator/purge mechanism |\n| `action-rollback-release` | replaced by Buildchain publish transaction recover/finalize/repair semantics |\n| `action-set-collaborators` | retired in workflows v2 or backed by retired Airtable/dependency/collaborator/purge mechanism |\n| `action-sync-airtable` | retired in workflows v2 or backed by retired Airtable/dependency/collaborator/purge mechanism |\n| `action-sync-extensions-version` | retired in workflows v2 or backed by retired Airtable/dependency/collaborator/purge mechanism |\n| `action-sync-pr` | retired PR synchronization helper; not part of the Buildchain reusable contract |\n| `action-update-dependencies-version` | retired dependency-version helper; use package-manager adapters and lifecycle commands |\n\n## Retired Workflows Excluded From v2\n\nThese legacy workflow entrypoints are intentionally not shipped from the root\n`.github/workflows` directory.\n\n| Previous workflow | Reason |\n| --- | --- |\n| `.batch-pull-request.yml` | retired PR orchestration helper; v2.5 dev integration governance will use a new protected-dev PR protocol instead |\n| `.release-new-version.yml` | retained as a fail-closed compatibility stub; direct publish model replaced by source-locked release-candidate promotion |\n| `.release-elastic-beanstalk.yml` | retained as a fail-closed compatibility stub; deploy side effects must move behind project lifecycle publish and publish-gate source locks |\n| `.sam-release.yml` | retained as a fail-closed compatibility stub; deploy side effects must move behind project lifecycle publish and publish-gate source locks |\n| `.wheel-release.yml` | retained as a fail-closed compatibility stub; package publish side effects must move behind project lifecycle publish and publish-gate source locks |\n\n## Buildchain-Native Actions\n\nThese actions are new Buildchain v2 surfaces rather than migrations from an\nolder standalone action repository.\n\n| Buildchain path | Purpose |\n| --- | --- |\n| `actions/promote-buildchain-ref` | governance-closed Buildchain release ref promotion |\n| `actions/run-lifecycle` | lifecycle command execution and deterministic artifact manifest generation |\n| `actions/validate-config` | `buildchain.toml` version-state and lifecycle preflight without executing lifecycle commands |\n\n## Current v3 Refs\n\n- Actions: `kungfu-systems/buildchain/actions/<name>@v3`\n- Reusable workflows: `kungfu-systems/buildchain/.github/workflows/<workflow>.yml@v3`\n\n## Verification Gates\n\n- `pnpm install --frozen-lockfile`\n- `pnpm run check`\n- GitHub-hosted `Verify` workflow\n- Manual `Self-hosted Runner Smoke` workflow for trusted self-hosted runner validation"
    },
    {
      "id": "manual:node-api-reference",
      "title": "Buildchain Node API Reference",
      "route": "/docs/node-api-reference",
      "category": "manual",
      "capabilityGroup": "api-cli-reference",
      "audience": [
        "agent",
        "developer"
      ],
      "maturity": "stable",
      "sourcePath": "docs/node-api-reference.md",
      "digest": "sha256:f8200ba1fbe5779408b4a1e82a0e28a5e8f696b05f97efd2d286d3008755fdbb",
      "headings": [
        {
          "level": 1,
          "title": "Buildchain Node API Reference",
          "anchor": "buildchain-node-api-reference"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain`",
          "anchor": "kungfu-tech-buildchain"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/badges`",
          "anchor": "kungfu-tech-buildchain-badges"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/build-facts`",
          "anchor": "kungfu-tech-buildchain-build-facts"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/core`",
          "anchor": "kungfu-tech-buildchain-core"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/artifact-passport`",
          "anchor": "kungfu-tech-buildchain-artifact-passport"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/artifact-verification-envelope`",
          "anchor": "kungfu-tech-buildchain-artifact-verification-envelope"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/github-artifact-attestation`",
          "anchor": "kungfu-tech-buildchain-github-artifact-attestation"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/artifact-signing`",
          "anchor": "kungfu-tech-buildchain-artifact-signing"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/artifact-signing-result`",
          "anchor": "kungfu-tech-buildchain-artifact-signing-result"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/detached-artifact-signature`",
          "anchor": "kungfu-tech-buildchain-detached-artifact-signature"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/anchored-version-material`",
          "anchor": "kungfu-tech-buildchain-anchored-version-material"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/buildchain-contract`",
          "anchor": "kungfu-tech-buildchain-buildchain-contract"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/candidate-timeline`",
          "anchor": "kungfu-tech-buildchain-candidate-timeline"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/channel-candidate`",
          "anchor": "kungfu-tech-buildchain-channel-candidate"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/cache-evidence`",
          "anchor": "kungfu-tech-buildchain-cache-evidence"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/controller-evidence`",
          "anchor": "kungfu-tech-buildchain-controller-evidence"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/diagnostics`",
          "anchor": "kungfu-tech-buildchain-diagnostics"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/dev-delivery-warrant`",
          "anchor": "kungfu-tech-buildchain-dev-delivery-warrant"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/homebrew`",
          "anchor": "kungfu-tech-buildchain-homebrew"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/issue-reporting`",
          "anchor": "kungfu-tech-buildchain-issue-reporting"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/kfd`",
          "anchor": "kungfu-tech-buildchain-kfd"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/kfd-product-gates`",
          "anchor": "kungfu-tech-buildchain-kfd-product-gates"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/kfd-adopter-manifest`",
          "anchor": "kungfu-tech-buildchain-kfd-adopter-manifest"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/kfd-adopter-release-binding`",
          "anchor": "kungfu-tech-buildchain-kfd-adopter-release-binding"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/kfd-agent-hub`",
          "anchor": "kungfu-tech-buildchain-kfd-agent-hub"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/buildchain-layout`",
          "anchor": "kungfu-tech-buildchain-buildchain-layout"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/release-line-bootstrap`",
          "anchor": "kungfu-tech-buildchain-release-line-bootstrap"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/readme-badges`",
          "anchor": "kungfu-tech-buildchain-readme-badges"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/public-surface-audit`",
          "anchor": "kungfu-tech-buildchain-public-surface-audit"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/logging`",
          "anchor": "kungfu-tech-buildchain-logging"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/portable-dev-cache`",
          "anchor": "kungfu-tech-buildchain-portable-dev-cache"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/publication-artifact`",
          "anchor": "kungfu-tech-buildchain-publication-artifact"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/publication-package`",
          "anchor": "kungfu-tech-buildchain-publication-package"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/publication-reproducibility`",
          "anchor": "kungfu-tech-buildchain-publication-reproducibility"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/publication-sealed-bundle`",
          "anchor": "kungfu-tech-buildchain-publication-sealed-bundle"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/paper`",
          "anchor": "kungfu-tech-buildchain-paper"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/publication-authority`",
          "anchor": "kungfu-tech-buildchain-publication-authority"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/publication-control-plane-audit`",
          "anchor": "kungfu-tech-buildchain-publication-control-plane-audit"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/buildchain-publication-authority`",
          "anchor": "kungfu-tech-buildchain-buildchain-publication-authority"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/github-governance-authority`",
          "anchor": "kungfu-tech-buildchain-github-governance-authority"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/engineering-housekeeper`",
          "anchor": "kungfu-tech-buildchain-engineering-housekeeper"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/engineering-housekeeper-github`",
          "anchor": "kungfu-tech-buildchain-engineering-housekeeper-github"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/kfd-gate`",
          "anchor": "kungfu-tech-buildchain-kfd-gate"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/release-candidate`",
          "anchor": "kungfu-tech-buildchain-release-candidate"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/release-candidate-recovery`",
          "anchor": "kungfu-tech-buildchain-release-candidate-recovery"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/release-train`",
          "anchor": "kungfu-tech-buildchain-release-train"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/stable-candidate-ledger`",
          "anchor": "kungfu-tech-buildchain-stable-candidate-ledger"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/release-passport`",
          "anchor": "kungfu-tech-buildchain-release-passport"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/release-passport-contract`",
          "anchor": "kungfu-tech-buildchain-release-passport-contract"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/release-propagation`",
          "anchor": "kungfu-tech-buildchain-release-propagation"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/release-activation-transaction`",
          "anchor": "kungfu-tech-buildchain-release-activation-transaction"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/release-tail-provider-plane`",
          "anchor": "kungfu-tech-buildchain-release-tail-provider-plane"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/release-tail-provider-adapters`",
          "anchor": "kungfu-tech-buildchain-release-tail-provider-adapters"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/release-tail-compatibility`",
          "anchor": "kungfu-tech-buildchain-release-tail-compatibility"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/surface-manifest`",
          "anchor": "kungfu-tech-buildchain-surface-manifest"
        },
        {
          "level": 2,
          "title": "`@kungfu-tech/buildchain/buildchain-kfd-claims`",
          "anchor": "kungfu-tech-buildchain-buildchain-kfd-claims"
        }
      ],
      "markdown": "---\nstatus: active\nperiod: ongoing\ntheme: buildchain-generated-reference\ndoc_type: technical-reference\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: generated\nlast_reviewed: 2026-08-01\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-08-01\n  invisible_context: not asserted\n---\n\n# Buildchain Node API Reference\n\n> Generated from `package.json#exports` and the exported ESM symbols in each target. Do not edit this file by hand.\n\nSignatures and source locations are mechanical. JavaScript return types remain conservative where the source declares no static type.\n\n## `@kungfu-tech/buildchain`\n\nTarget: `./packages/core/index.js`. Public symbols: 608.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `abortReleaseActivationTransaction` | function: function abortReleaseActivationTransaction(transaction, reason) | transaction, reason | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { abortReleaseActivationTransaction } from \"@kungfu-tech/buildchain\";` | `packages/core/release-activation-transaction.js:277` |\n| `AGENT_INDEX_CONTRACT` | constant: const AGENT_INDEX_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { AGENT_INDEX_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport.js:40` |\n| `aggregateBuildFacts` | function: function aggregateBuildFacts({ cwd = process.cwd(), productId = \"\", moduleFacts = [], artifacts = [], now = nowIso(), } = {}) | { cwd = process.cwd(), productId = \"\", moduleFacts = [], artifacts = [], now = nowIso(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | subprocess | `import { aggregateBuildFacts } from \"@kungfu-tech/buildchain\";` | `packages/core/build-facts.js:466` |\n| `aggregateControllerReceipts` | function: function aggregateControllerReceipts({ plans = [], receipts = [] } = {}) | { plans = [], receipts = [] } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { aggregateControllerReceipts } from \"@kungfu-tech/buildchain\";` | `packages/core/controller-evidence.js:449` |\n| `ANCHORED_VERSION_MATERIAL_CONTRACT` | constant: const ANCHORED_VERSION_MATERIAL_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ANCHORED_VERSION_MATERIAL_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/anchored-version-material.js:15` |\n| `appendBuildchainLogEvent` | function: function appendBuildchainLogEvent(filePath, event) | filePath, event | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write | `import { appendBuildchainLogEvent } from \"@kungfu-tech/buildchain\";` | `packages/core/logging.js:67` |\n| `applyGitHubHousekeeperPlan` | function: async function applyGitHubHousekeeperPlan({ client, plan, dryRun = true, priorReceipt, appliedAt = new Date().toISOString(), staleDays = DEFAULT_STALE_DAYS, maxActions = DEFAULT_MAX_ACTIONS, }) | { client, plan, dryRun = true, priorReceipt, appliedAt = new Date().toISOString(), staleDays = DEFAULT_STALE_DAYS, maxActions = DEFAULT_MAX_ACTIONS, } | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { applyGitHubHousekeeperPlan } from \"@kungfu-tech/buildchain\";` | `packages/core/engineering-housekeeper-github.js:615` |\n| `applySurfaceTimestampPolicy` | function: function applySurfaceTimestampPolicy(manifest, options = {}) | manifest, options = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { applySurfaceTimestampPolicy } from \"@kungfu-tech/buildchain\";` | `packages/core/surface-manifest.js:79` |\n| `ARTIFACT_EVIDENCE_CONTRACT` | constant: const ARTIFACT_EVIDENCE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_EVIDENCE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport.js:38` |\n| `ARTIFACT_PASSPORT_LOCATOR_CONTRACT` | constant: const ARTIFACT_PASSPORT_LOCATOR_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_PASSPORT_LOCATOR_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-passport.js:11` |\n| `ARTIFACT_PASSPORT_POINTER_CONTRACT` | constant: const ARTIFACT_PASSPORT_POINTER_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_PASSPORT_POINTER_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-passport.js:10` |\n| `ARTIFACT_SIGNING_AUTHORITY_CONTRACT` | constant: const ARTIFACT_SIGNING_AUTHORITY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_SIGNING_AUTHORITY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-signing.js:7` |\n| `ARTIFACT_SIGNING_RECEIPT_CONTRACT` | constant: const ARTIFACT_SIGNING_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_SIGNING_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-signing.js:5` |\n| `ARTIFACT_SIGNING_REQUEST_CONTRACT` | constant: const ARTIFACT_SIGNING_REQUEST_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_SIGNING_REQUEST_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-signing.js:3` |\n| `ARTIFACT_SIGNING_RESULT_CONTRACT` | constant: const ARTIFACT_SIGNING_RESULT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_SIGNING_RESULT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-signing-result.js:12` |\n| `ARTIFACT_VERIFICATION_CONTRACT` | constant: const ARTIFACT_VERIFICATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_VERIFICATION_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-passport.js:9` |\n| `ARTIFACT_VERIFICATION_ENVELOPE_CHECK_CONTRACT` | constant: const ARTIFACT_VERIFICATION_ENVELOPE_CHECK_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_VERIFICATION_ENVELOPE_CHECK_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-verification-envelope.js:12` |\n| `ARTIFACT_VERIFICATION_ENVELOPE_CONTRACT` | constant: const ARTIFACT_VERIFICATION_ENVELOPE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_VERIFICATION_ENVELOPE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-verification-envelope.js:10` |\n| `artifactSigningDigest` | function: function artifactSigningDigest(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { artifactSigningDigest } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-signing.js:60` |\n| `artifactSigningEvidenceDigest` | function: function artifactSigningEvidenceDigest(evidence = []) | evidence = [] | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { artifactSigningEvidenceDigest } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-signing-result.js:58` |\n| `artifactVerificationEnvelopeDigest` | function: function artifactVerificationEnvelopeDigest(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { artifactVerificationEnvelopeDigest } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-verification-envelope.js:59` |\n| `assertPackageManager` | function: function assertPackageManager(manager) | manager | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { assertPackageManager } from \"@kungfu-tech/buildchain\";` | `packages/core/package-manager.js:49` |\n| `assertPublicSurfaceReverseAudit` | function: function assertPublicSurfaceReverseAudit(report) | report | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { assertPublicSurfaceReverseAudit } from \"@kungfu-tech/buildchain\";` | `packages/core/public-surface-audit.js:261` |\n| `auditKfd3Surfaces` | function: function auditKfd3Surfaces({ cwd = process.cwd(), registryPath = \"\", kinds = [], artifactPath = \"\", } = {}) | { cwd = process.cwd(), registryPath = \"\", kinds = [], artifactPath = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { auditKfd3Surfaces } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd3-surface-register.js:547` |\n| `BADGE_BUNDLE_DEFAULT_CLAIMS` | constant: const BADGE_BUNDLE_DEFAULT_CLAIMS | none | value | Import does not declare a throw contract. | none-on-import | `import { BADGE_BUNDLE_DEFAULT_CLAIMS } from \"@kungfu-tech/buildchain\";` | `packages/core/readme-badges.js:17` |\n| `BADGE_BUNDLE_FACTS_CONTRACT` | constant: const BADGE_BUNDLE_FACTS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BADGE_BUNDLE_FACTS_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/readme-badges.js:13` |\n| `BUILD_FACTS_GIT_CONTRACT` | constant: const BUILD_FACTS_GIT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILD_FACTS_GIT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/build-facts.js:9` |\n| `BUILD_FACTS_LEGACY_KUNGFU_BUILDINFO_CONTRACT` | constant: const BUILD_FACTS_LEGACY_KUNGFU_BUILDINFO_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILD_FACTS_LEGACY_KUNGFU_BUILDINFO_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/build-facts.js:14` |\n| `BUILD_FACTS_MODULE_CONTRACT` | constant: const BUILD_FACTS_MODULE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILD_FACTS_MODULE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/build-facts.js:11` |\n| `BUILD_FACTS_PRODUCT_CONTRACT` | constant: const BUILD_FACTS_PRODUCT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILD_FACTS_PRODUCT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/build-facts.js:12` |\n| `BUILD_FACTS_VERIFY_CONTRACT` | constant: const BUILD_FACTS_VERIFY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILD_FACTS_VERIFY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/build-facts.js:13` |\n| `BUILD_FACTS_VERSION_CONTRACT` | constant: const BUILD_FACTS_VERSION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILD_FACTS_VERSION_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/build-facts.js:10` |\n| `BUILDCHAIN_AGENT_MANUALS` | constant: const BUILDCHAIN_AGENT_MANUALS | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_AGENT_MANUALS } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-agent-manuals.js:1` |\n| `BUILDCHAIN_ANCHORED_PACKAGE_RELEASE_VALIDATION_CONTRACT` | constant: const BUILDCHAIN_ANCHORED_PACKAGE_RELEASE_VALIDATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_ANCHORED_PACKAGE_RELEASE_VALIDATION_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:31` |\n| `BUILDCHAIN_CACHE_EVIDENCE_SET_CONTRACT` | constant: const BUILDCHAIN_CACHE_EVIDENCE_SET_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CACHE_EVIDENCE_SET_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/cache-evidence.js:5` |\n| `BUILDCHAIN_CACHE_OPERATION_RECEIPT_CONTRACT` | constant: const BUILDCHAIN_CACHE_OPERATION_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CACHE_OPERATION_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/cache-evidence.js:3` |\n| `BUILDCHAIN_CANDIDATE_TIMELINE_CONTRACT` | constant: const BUILDCHAIN_CANDIDATE_TIMELINE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CANDIDATE_TIMELINE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/candidate-timeline.js:1` |\n| `BUILDCHAIN_CANDIDATE_TIMELINE_EVENT_CONTRACT` | constant: const BUILDCHAIN_CANDIDATE_TIMELINE_EVENT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CANDIDATE_TIMELINE_EVENT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/candidate-timeline.js:3` |\n| `BUILDCHAIN_CONFIG_PATH` | constant: const BUILDCHAIN_CONFIG_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONFIG_PATH } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:7` |\n| `BUILDCHAIN_CONSUMER_ISSUE_CONTRACT` | constant: const BUILDCHAIN_CONSUMER_ISSUE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONSUMER_ISSUE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/issue-reporting.js:4` |\n| `BUILDCHAIN_CONTRACT_LOCK` | constant: const BUILDCHAIN_CONTRACT_LOCK | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONTRACT_LOCK } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-contract.js:21` |\n| `BUILDCHAIN_CONTRACT_LOCK_PATH` | constant: const BUILDCHAIN_CONTRACT_LOCK_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONTRACT_LOCK_PATH } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:9` |\n| `BUILDCHAIN_CONTROLLER_AGGREGATE_CONTRACT` | constant: const BUILDCHAIN_CONTROLLER_AGGREGATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONTROLLER_AGGREGATE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/controller-evidence.js:6` |\n| `BUILDCHAIN_CONTROLLER_DESCRIPTOR_CONTRACT` | constant: const BUILDCHAIN_CONTROLLER_DESCRIPTOR_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONTROLLER_DESCRIPTOR_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/controller-evidence.js:4` |\n| `BUILDCHAIN_CONTROLLER_EVIDENCE_CONTRACT` | constant: const BUILDCHAIN_CONTROLLER_EVIDENCE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONTROLLER_EVIDENCE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/controller-evidence.js:3` |\n| `BUILDCHAIN_CONTROLLER_REGISTRY_CONTRACT` | constant: const BUILDCHAIN_CONTROLLER_REGISTRY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONTROLLER_REGISTRY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/controller-evidence.js:5` |\n| `BUILDCHAIN_DIAGNOSTICS_CONTRACT` | constant: const BUILDCHAIN_DIAGNOSTICS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_DIAGNOSTICS_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:28` |\n| `BUILDCHAIN_DIAGNOSTICS_MANIFEST_CONTRACT` | constant: const BUILDCHAIN_DIAGNOSTICS_MANIFEST_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_DIAGNOSTICS_MANIFEST_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:33` |\n| `BUILDCHAIN_DIAGNOSTICS_SUMMARY_CONTRACT` | constant: const BUILDCHAIN_DIAGNOSTICS_SUMMARY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_DIAGNOSTICS_SUMMARY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:35` |\n| `BUILDCHAIN_DIR` | constant: const BUILDCHAIN_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_DIR } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:4` |\n| `BUILDCHAIN_GENERATED_DIRS` | constant: const BUILDCHAIN_GENERATED_DIRS | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_GENERATED_DIRS } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:36` |\n| `BUILDCHAIN_GITHUB_GOVERNANCE_AUTHORITY` | constant: const BUILDCHAIN_GITHUB_GOVERNANCE_AUTHORITY | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_GITHUB_GOVERNANCE_AUTHORITY } from \"@kungfu-tech/buildchain\";` | `packages/core/github-governance-authority.js:1365` |\n| `BUILDCHAIN_GITHUB_GOVERNANCE_PROTECTED_PATHS` | constant: const BUILDCHAIN_GITHUB_GOVERNANCE_PROTECTED_PATHS | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_GITHUB_GOVERNANCE_PROTECTED_PATHS } from \"@kungfu-tech/buildchain\";` | `packages/core/github-governance-authority.js:1367` |\n| `BUILDCHAIN_JSON_FORMATTING_POLICY` | constant: const BUILDCHAIN_JSON_FORMATTING_POLICY | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_JSON_FORMATTING_POLICY } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-gate.js:14` |\n| `BUILDCHAIN_KFD_CLAIM_REGISTRY_CONTRACT` | constant: const BUILDCHAIN_KFD_CLAIM_REGISTRY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD_CLAIM_REGISTRY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-kfd-claims.js:14` |\n| `BUILDCHAIN_KFD_COLLABORATION_INTERFACE_CONTRACT` | constant: const BUILDCHAIN_KFD_COLLABORATION_INTERFACE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD_COLLABORATION_INTERFACE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-kfd-claims.js:15` |\n| `BUILDCHAIN_KFD_ROOT` | constant: const BUILDCHAIN_KFD_ROOT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD_ROOT } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:11` |\n| `BUILDCHAIN_KFD1_CONTRACT_WORLD_WITNESS_PATH` | constant: const BUILDCHAIN_KFD1_CONTRACT_WORLD_WITNESS_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD1_CONTRACT_WORLD_WITNESS_PATH } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:16` |\n| `BUILDCHAIN_KFD1_DIR` | constant: const BUILDCHAIN_KFD1_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD1_DIR } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:12` |\n| `BUILDCHAIN_KFD1_RELEASE_GATE_PATH` | constant: const BUILDCHAIN_KFD1_RELEASE_GATE_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD1_RELEASE_GATE_PATH } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:17` |\n| `BUILDCHAIN_KFD1_VERIFY_RESULT_PATH` | constant: const BUILDCHAIN_KFD1_VERIFY_RESULT_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD1_VERIFY_RESULT_PATH } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:18` |\n| `BUILDCHAIN_KFD2_CLAIM_ARGS_PATH` | constant: const BUILDCHAIN_KFD2_CLAIM_ARGS_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD2_CLAIM_ARGS_PATH } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:21` |\n| `BUILDCHAIN_KFD2_CLAIMS_DIR` | constant: const BUILDCHAIN_KFD2_CLAIMS_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD2_CLAIMS_DIR } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:22` |\n| `BUILDCHAIN_KFD2_DIR` | constant: const BUILDCHAIN_KFD2_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD2_DIR } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:13` |\n| `BUILDCHAIN_KFD2_REGISTRY_PATH` | constant: const BUILDCHAIN_KFD2_REGISTRY_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD2_REGISTRY_PATH } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:19` |\n| `BUILDCHAIN_KFD2_RELEASE_CLAIMS_PATH` | constant: const BUILDCHAIN_KFD2_RELEASE_CLAIMS_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD2_RELEASE_CLAIMS_PATH } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:20` |\n| `BUILDCHAIN_KFD3_ARTIFACT_WITNESS_PATH` | constant: const BUILDCHAIN_KFD3_ARTIFACT_WITNESS_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD3_ARTIFACT_WITNESS_PATH } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:26` |\n| `BUILDCHAIN_KFD3_CAPABILITY_QUERY_PATH` | constant: const BUILDCHAIN_KFD3_CAPABILITY_QUERY_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD3_CAPABILITY_QUERY_PATH } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:27` |\n| `BUILDCHAIN_KFD3_COLLABORATION_INTERFACE_PATH` | constant: const BUILDCHAIN_KFD3_COLLABORATION_INTERFACE_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD3_COLLABORATION_INTERFACE_PATH } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:24` |\n| `BUILDCHAIN_KFD3_DIR` | constant: const BUILDCHAIN_KFD3_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD3_DIR } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:14` |\n| `BUILDCHAIN_KFD3_PREBUILD_WITNESS_PATH` | constant: const BUILDCHAIN_KFD3_PREBUILD_WITNESS_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD3_PREBUILD_WITNESS_PATH } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:25` |\n| `BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATH` | constant: const BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATH } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:23` |\n| `BUILDCHAIN_KFD4_DIR` | constant: const BUILDCHAIN_KFD4_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD4_DIR } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:15` |\n| `BUILDCHAIN_LAYOUT_DISCOVERY_CONTRACT` | constant: const BUILDCHAIN_LAYOUT_DISCOVERY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_LAYOUT_DISCOVERY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:6` |\n| `BUILDCHAIN_LIFECYCLE_OBSERVABILITY_CONTRACT` | constant: const BUILDCHAIN_LIFECYCLE_OBSERVABILITY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_LIFECYCLE_OBSERVABILITY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:29` |\n| `BUILDCHAIN_LOCKED_SOURCE_CHECKOUT_CONTRACT` | constant: const BUILDCHAIN_LOCKED_SOURCE_CHECKOUT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_LOCKED_SOURCE_CHECKOUT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:41` |\n| `BUILDCHAIN_LOG_EVENT_CONTRACT` | constant: const BUILDCHAIN_LOG_EVENT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_LOG_EVENT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/logging.js:6` |\n| `BUILDCHAIN_LOG_SUMMARY_CONTRACT` | constant: const BUILDCHAIN_LOG_SUMMARY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_LOG_SUMMARY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/logging.js:7` |\n| `BUILDCHAIN_PROCESS_SAMPLE_REPORT_CONTRACT` | constant: const BUILDCHAIN_PROCESS_SAMPLE_REPORT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_PROCESS_SAMPLE_REPORT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:37` |\n| `BUILDCHAIN_PROCESS_SAMPLE_SUMMARY_CONTRACT` | constant: const BUILDCHAIN_PROCESS_SAMPLE_SUMMARY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_PROCESS_SAMPLE_SUMMARY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:39` |\n| `BUILDCHAIN_PUBLIC_SURFACE_AUDIT_CONTRACT` | constant: const BUILDCHAIN_PUBLIC_SURFACE_AUDIT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_PUBLIC_SURFACE_AUDIT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/public-surface-audit.js:12` |\n| `BUILDCHAIN_RELEASE_PASSPORT_PATH` | constant: const BUILDCHAIN_RELEASE_PASSPORT_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_RELEASE_PASSPORT_PATH } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:33` |\n| `BUILDCHAIN_RUNTIME_CONTRACT_WORLD` | constant: const BUILDCHAIN_RUNTIME_CONTRACT_WORLD | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_RUNTIME_CONTRACT_WORLD } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-contract.js:20` |\n| `BUILDCHAIN_VERSION_PIN_PATH` | constant: const BUILDCHAIN_VERSION_PIN_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_VERSION_PIN_PATH } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:5` |\n| `BUILDCHAIN_WORKFLOW_FRICTION_ISSUE_CONTRACT` | constant: const BUILDCHAIN_WORKFLOW_FRICTION_ISSUE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_WORKFLOW_FRICTION_ISSUE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/issue-reporting.js:5` |\n| `buildchainKfdClaims` | constant: const buildchainKfdClaims | none | value | Import does not declare a throw contract. | none-on-import | `import { buildchainKfdClaims } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd.js:896` |\n| `buildchainPublicationAuthorityDescriptors` | function: function buildchainPublicationAuthorityDescriptors() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { buildchainPublicationAuthorityDescriptors } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-publication-authority.js:62` |\n| `buildConsumerIssueReport` | function: function buildConsumerIssueReport(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { buildConsumerIssueReport } from \"@kungfu-tech/buildchain\";` | `packages/core/issue-reporting.js:104` |\n| `buildFactsDigest` | function: function buildFactsDigest(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write, subprocess | `import { buildFactsDigest } from \"@kungfu-tech/buildchain\";` | `packages/core/build-facts.js:45` |\n| `buildWorkflowFrictionIssueReport` | function: function buildWorkflowFrictionIssueReport(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { buildWorkflowFrictionIssueReport } from \"@kungfu-tech/buildchain\";` | `packages/core/issue-reporting.js:199` |\n| `cacheEvidenceDigest` | function: function cacheEvidenceDigest(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { cacheEvidenceDigest } from \"@kungfu-tech/buildchain\";` | `packages/core/cache-evidence.js:48` |\n| `CHANNEL_CANDIDATE_DECISION_SCHEMA` | constant: const CHANNEL_CANDIDATE_DECISION_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { CHANNEL_CANDIDATE_DECISION_SCHEMA } from \"@kungfu-tech/buildchain\";` | `packages/core/channel-candidate.js:6` |\n| `channelCandidateSourceLockRef` | function: function channelCandidateSourceLockRef(targetBranch, sourceSha) | targetBranch, sourceSha | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { channelCandidateSourceLockRef } from \"@kungfu-tech/buildchain\";` | `packages/core/channel-candidate.js:85` |\n| `checkBadgeBundleBlock` | function: function checkBadgeBundleBlock({ readmeText, facts } = {}) | { readmeText, facts } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { checkBadgeBundleBlock } from \"@kungfu-tech/buildchain\";` | `packages/core/readme-badges.js:867` |\n| `checkHomebrewTap` | function: async function checkHomebrewTap({ cwd = process.cwd(), packageName = \"buildchain\", releasePassport = \"\", manifestPath = DEFAULT_MANIFEST_PATH, formulaPath = \"\", } = {}) | { cwd = process.cwd(), packageName = \"buildchain\", releasePassport = \"\", manifestPath = DEFAULT_MANIFEST_PATH, formulaPath = \"\", } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { checkHomebrewTap } from \"@kungfu-tech/buildchain\";` | `packages/core/homebrew.js:335` |\n| `checkKfd2ProductClaimOutputs` | function: function checkKfd2ProductClaimOutputs(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { checkKfd2ProductClaimOutputs } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd2-product-claims.js:415` |\n| `checkReadmeBadgeBlock` | function: function checkReadmeBadgeBlock({ readmeText, facts } = {}) | { readmeText, facts } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { checkReadmeBadgeBlock } from \"@kungfu-tech/buildchain\";` | `packages/core/readme-badges.js:848` |\n| `claimReleasePropagationWork` | function: function claimReleasePropagationWork({ work, expectedWorkRoot, authority, familyState, } = {}) | { work, expectedWorkRoot, authority, familyState, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { claimReleasePropagationWork } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-work-transitions.js:17` |\n| `classifyHousekeeperBranch` | function: function classifyHousekeeperBranch(branch, policyInput = {}) | branch, policyInput = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { classifyHousekeeperBranch } from \"@kungfu-tech/buildchain\";` | `packages/core/engineering-housekeeper.js:105` |\n| `classifyHousekeeperPullRequest` | function: function classifyHousekeeperPullRequest(pullRequest, policyInput = {}) | pullRequest, policyInput = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { classifyHousekeeperPullRequest } from \"@kungfu-tech/buildchain\";` | `packages/core/engineering-housekeeper.js:144` |\n| `classifyHousekeeperReplay` | function: function classifyHousekeeperReplay(plan, priorReceipt) | plan, priorReceipt | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { classifyHousekeeperReplay } from \"@kungfu-tech/buildchain\";` | `packages/core/engineering-housekeeper.js:265` |\n| `classifyProcessCommand` | function: function classifyProcessCommand(command = \"\") | command = \"\" | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { classifyProcessCommand } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:1085` |\n| `classifyReleasePropagationCondition` | function: function classifyReleasePropagationCondition(condition) | condition | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { classifyReleasePropagationCondition } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-agent-entry.js:171` |\n| `codeownersForPath` | function: function codeownersForPath(source, candidatePath) | source, candidatePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { codeownersForPath } from \"@kungfu-tech/buildchain\";` | `packages/core/github-governance-authority.js:419` |\n| `collectBadgeBundleFacts` | function: async function collectBadgeBundleFacts({ cwd = process.cwd(), claims = undefined } = {}) | { cwd = process.cwd(), claims = undefined } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectBadgeBundleFacts } from \"@kungfu-tech/buildchain\";` | `packages/core/readme-badges.js:790` |\n| `collectBuildchainDiagnostics` | function: function collectBuildchainDiagnostics({ cwd = process.cwd(), artifactPaths = [] } = {}) | { cwd = process.cwd(), artifactPaths = [] } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectBuildchainDiagnostics } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:248` |\n| `collectCacheDiagnostics` | function: function collectCacheDiagnostics({ cwd = process.cwd(), cacheDirs = [], runCommand = defaultDiagnosticCommandRunner } = {}) | { cwd = process.cwd(), cacheDirs = [], runCommand = defaultDiagnosticCommandRunner } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectCacheDiagnostics } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:922` |\n| `collectCompilerCacheDiagnostics` | function: function collectCompilerCacheDiagnostics({ cwd = process.cwd(), runCommand = defaultDiagnosticCommandRunner, env = process.env, } = {}) | { cwd = process.cwd(), runCommand = defaultDiagnosticCommandRunner, env = process.env, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectCompilerCacheDiagnostics } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:573` |\n| `collectGitDiagnostics` | function: function collectGitDiagnostics({ cwd = process.cwd() } = {}) | { cwd = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectGitDiagnostics } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:944` |\n| `collectGitHubHousekeeperInventory` | function: async function collectGitHubHousekeeperInventory({ client, repository, targetBranch, observedAt, staleDays = DEFAULT_STALE_DAYS, policy = {}, }) | { client, repository, targetBranch, observedAt, staleDays = DEFAULT_STALE_DAYS, policy = {}, } | Promise<unknown> | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { collectGitHubHousekeeperInventory } from \"@kungfu-tech/buildchain\";` | `packages/core/engineering-housekeeper-github.js:246` |\n| `collectGitHubReleasePassport` | function: function collectGitHubReleasePassport({ cwd = process.cwd(), tag = \"\", repository = process.env.GITHUB_REPOSITORY \\|\\| \"\", sourceSha = process.env.GITHUB_SHA \\|\\| \"\", line = \"\", outputDir = \".buildchain/release-passport\", assetsJson = \"\", assetsDir = \"\", releaseJson = \"\", productName = \"Buildchain\", packageName = \"@kungfu-tech/buildchain\", packageVersion = \"\", packageSetJson = \"\", publishEvidenceJson = \"\", trustedPublishingJson = \"\", transactionJson = \"\", anchorManifestJson = \"\", versionMaterialJson = \"\", impactJson = \"\", buildSummaryJson = \"\", buildFactsJsons = [], platformManifestJsons = [], distTagEvidenceJson = \"\", kfd1WitnessJsons = [], kfd2ClaimJsons = [], kfd3PrebuildWitnessJsons = [], kfd3ArtifactWitnessJsons = [], kfd3ArtifactVerifyCommand = \"\", kfdAdopterManifestJson = \"\", kfdSupportMatrixJson = \"\", kfdProductGateJsons = [], invariantPassportJsons = [], invariantPassportCommand = \"\", releaseEvidenceJsons = [], kfdAgentHubEvidenceJson = \"\", controllerReceiptReferences = [], githubArtifactAttestationPolicyJsons = [], basePassportJson = \"\", requireBaseKfd = false, releaseJsonExtra = \"\", publishJson = \"\", workflow = {}, checkedAt = \"\", } = {}) | { cwd = process.cwd(), tag = \"\", repository = process.env.GITHUB_REPOSITORY \\|\\| \"\", sourceSha = process.env.GITHUB_SHA \\|\\| \"\", line = \"\", outputDir = \".buildchain/release-passport\", assetsJson = \"\", assetsDir = \"\", releaseJson = \"\", productName = \"Buildchain\", packageName = \"@kungfu-tech/buildchain\", packageVersion = \"\", packageSetJson = \"\", publishEvidenceJson = \"\", trustedPublishingJson = \"\", transactionJson = \"\", anchorManifestJson = \"\", versionMaterialJson = \"\", impactJson = \"\", buildSummaryJson = \"\", buildFactsJsons = [], platformManifestJsons = [], distTagEvidenceJson = \"\", kfd1WitnessJsons = [], kfd2ClaimJsons = [], kfd3PrebuildWitnessJsons = [], kfd3ArtifactWitnessJsons = [], kfd3ArtifactVerifyCommand = \"\", kfdAdopterManifestJson = \"\", kfdSupportMatrixJson = \"\", kfdProductGateJsons = [], invariantPassportJsons = [], invariantPassportCommand = \"\", releaseEvidenceJsons = [], kfdAgentHubEvidenceJson = \"\", controllerReceiptReferences = [], githubArtifactAttestationPolicyJsons = [], basePassportJson = \"\", requireBaseKfd = false, releaseJsonExtra = \"\", publishJson = \"\", workflow = {}, checkedAt = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectGitHubReleasePassport } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport.js:1424` |\n| `collectGitSourceFacts` | function: function collectGitSourceFacts({ cwd = process.cwd(), root = \".\" } = {}) | { cwd = process.cwd(), root = \".\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectGitSourceFacts } from \"@kungfu-tech/buildchain\";` | `packages/core/build-facts.js:154` |\n| `collectHomebrewTapFacts` | function: async function collectHomebrewTapFacts({ cwd = process.cwd(), packageName = \"buildchain\", releasePassport = \"\", manifestPath = DEFAULT_MANIFEST_PATH, formulaPath = \"\", } = {}) | { cwd = process.cwd(), packageName = \"buildchain\", releasePassport = \"\", manifestPath = DEFAULT_MANIFEST_PATH, formulaPath = \"\", } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectHomebrewTapFacts } from \"@kungfu-tech/buildchain\";` | `packages/core/homebrew.js:223` |\n| `collectKfdStatus` | function: function collectKfdStatus({ cwd = process.cwd() } = {}) | { cwd = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectKfdStatus } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd.js:902` |\n| `collectModuleBuildFacts` | function: function collectModuleBuildFacts({ cwd = process.cwd(), moduleId = \"\", moduleRoot = \"\", scope = \"\", versionSource = undefined, versionSourceId = \"\", outputs = [], lifecycle = \"\", platform = currentPlatform(), dependencies = [], now = nowIso(), } = {}) | { cwd = process.cwd(), moduleId = \"\", moduleRoot = \"\", scope = \"\", versionSource = undefined, versionSourceId = \"\", outputs = [], lifecycle = \"\", platform = currentPlatform(), dependencies = [], now = nowIso(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectModuleBuildFacts } from \"@kungfu-tech/buildchain\";` | `packages/core/build-facts.js:310` |\n| `collectNativeDiagnostics` | function: function collectNativeDiagnostics({ cwd = process.cwd(), profile = undefined, runCommand = defaultDiagnosticCommandRunner, } = {}) | { cwd = process.cwd(), profile = undefined, runCommand = defaultDiagnosticCommandRunner, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectNativeDiagnostics } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:295` |\n| `collectPaperFleetAudit` | function: function collectPaperFleetAudit({ root = process.cwd(), repositories = [], buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainSha = \"\", governance = {}, } = {}) | { root = process.cwd(), repositories = [], buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainSha = \"\", governance = {}, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectPaperFleetAudit } from \"@kungfu-tech/buildchain\";` | `packages/core/paper-fleet.js:158` |\n| `collectPaperPreflight` | function: function collectPaperPreflight({ cwd = process.cwd(), buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainRef = \"v3\", buildchainSha = \"\", registry = NPM_REGISTRY, offline = false, agentEntryMode = \"contract\", } = {}) | { cwd = process.cwd(), buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainRef = \"v3\", buildchainSha = \"\", registry = NPM_REGISTRY, offline = false, agentEntryMode = \"contract\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectPaperPreflight } from \"@kungfu-tech/buildchain\";` | `packages/core/paper.js:2414` |\n| `collectPaperStatus` | function: function collectPaperStatus({ cwd = process.cwd() } = {}) | { cwd = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectPaperStatus } from \"@kungfu-tech/buildchain\";` | `packages/core/paper.js:1472` |\n| `collectProcessTreeSnapshot` | function: function collectProcessTreeSnapshot({ rootPid = process.pid, cwd = process.cwd(), platform = process.platform, runCommand = defaultDiagnosticCommandRunner, } = {}) | { rootPid = process.pid, cwd = process.cwd(), platform = process.platform, runCommand = defaultDiagnosticCommandRunner, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectProcessTreeSnapshot } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:1029` |\n| `collectPublicationArtifact` | function: function collectPublicationArtifact({ cwd = process.cwd(), sourceSha = \"\", sourceBundle = true, sourceBundlePath = \"\", generatedAt = \"\", manifestPath = \"\", passportPath = \"\", } = {}) | { cwd = process.cwd(), sourceSha = \"\", sourceBundle = true, sourceBundlePath = \"\", generatedAt = \"\", manifestPath = \"\", passportPath = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { collectPublicationArtifact } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-artifact.js:271` |\n| `collectPublicationPackageFacts` | function: function collectPublicationPackageFacts({ cwd = process.cwd(), packageName = \"\", outputDir = \".buildchain/publication/npm-package\", } = {}) | { cwd = process.cwd(), packageName = \"\", outputDir = \".buildchain/publication/npm-package\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { collectPublicationPackageFacts } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-package.js:74` |\n| `collectPublicSurfaceReverseAudit` | function: function collectPublicSurfaceReverseAudit({ root = process.cwd(), cliRegistry: suppliedCliRegistry = undefined, workflowRegistry: suppliedWorkflowRegistry = undefined, pageRegistry: suppliedPageRegistry = undefined, } = {}) | { root = process.cwd(), cliRegistry: suppliedCliRegistry = undefined, workflowRegistry: suppliedWorkflowRegistry = undefined, pageRegistry: suppliedPageRegistry = undefined, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectPublicSurfaceReverseAudit } from \"@kungfu-tech/buildchain\";` | `packages/core/public-surface-audit.js:161` |\n| `collectReadmeBadgeFacts` | function: async function collectReadmeBadgeFacts({ cwd = process.cwd() } = {}) | { cwd = process.cwd() } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectReadmeBadgeFacts } from \"@kungfu-tech/buildchain\";` | `packages/core/readme-badges.js:700` |\n| `collectRunnerDiagnostics` | function: function collectRunnerDiagnostics() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectRunnerDiagnostics } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:468` |\n| `collectToolDiagnostics` | function: function collectToolDiagnostics({ cwd = process.cwd(), tools = [\"node\", \"pnpm\", \"npm\", \"git\", \"cmake\", \"ninja\", \"ccache\", \"sccache\"] } = {}) | { cwd = process.cwd(), tools = [\"node\", \"pnpm\", \"npm\", \"git\", \"cmake\", \"ninja\", \"ccache\", \"sccache\"] } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectToolDiagnostics } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:495` |\n| `collectVersionSourceFact` | function: function collectVersionSourceFact({ cwd = process.cwd(), source = undefined, sourceId = \"\", now = nowIso() } = {}) | { cwd = process.cwd(), source = undefined, sourceId = \"\", now = nowIso() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | subprocess | `import { collectVersionSourceFact } from \"@kungfu-tech/buildchain\";` | `packages/core/build-facts.js:181` |\n| `commandForKungfuUpgrade` | function: function commandForKungfuUpgrade(manager, scope = \"@kungfu-trader\") | manager, scope = \"@kungfu-trader\" | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { commandForKungfuUpgrade } from \"@kungfu-tech/buildchain\";` | `packages/core/package-manager.js:121` |\n| `commandForRunScript` | function: function commandForRunScript(manager, script) | manager, script | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { commandForRunScript } from \"@kungfu-tech/buildchain\";` | `packages/core/package-manager.js:89` |\n| `commandForVersion` | function: function commandForVersion(manager, keyword, options = {}) | manager, keyword, options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { commandForVersion } from \"@kungfu-tech/buildchain\";` | `packages/core/package-manager.js:100` |\n| `compileEffectiveGithubGovernancePolicy` | function: function compileEffectiveGithubGovernancePolicy({ branch, defaultBranch, protectedBranch = false, protection, rulesets = [], } = {}) | { branch, defaultBranch, protectedBranch = false, protection, rulesets = [], } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { compileEffectiveGithubGovernancePolicy } from \"@kungfu-tech/buildchain\";` | `packages/core/github-governance-authority.js:313` |\n| `compileReleaseTailDeclaration` | function: function compileReleaseTailDeclaration(input) | input | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { compileReleaseTailDeclaration } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-plane.js:584` |\n| `completeReleasePropagationWork` | function: function completeReleasePropagationWork({ work, expectedWorkRoot, receipt, completionDecision, } = {}) | { work, expectedWorkRoot, receipt, completionDecision, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { completeReleasePropagationWork } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-work-transitions.js:110` |\n| `computeConsumerIssueFingerprint` | function: function computeConsumerIssueFingerprint(fields = {}) | fields = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { computeConsumerIssueFingerprint } from \"@kungfu-tech/buildchain\";` | `packages/core/issue-reporting.js:64` |\n| `CONSUMER_PUBLICATION_DECISION_CONTRACT` | constant: const CONSUMER_PUBLICATION_DECISION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { CONSUMER_PUBLICATION_DECISION_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:20` |\n| `consumerIssueMarker` | function: function consumerIssueMarker(fingerprint) | fingerprint | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { consumerIssueMarker } from \"@kungfu-tech/buildchain\";` | `packages/core/issue-reporting.js:76` |\n| `contractSummary` | function: function contractSummary(contractWorld, runtimeRef = \"\", runtimeSha = \"\") | contractWorld, runtimeRef = \"\", runtimeSha = \"\" | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { contractSummary } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-contract.js:1031` |\n| `controllerEvidenceDigest` | function: function controllerEvidenceDigest(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { controllerEvidenceDigest } from \"@kungfu-tech/buildchain\";` | `packages/core/controller-evidence.js:151` |\n| `createActivationReceiptProjectorAdapter` | function: function createActivationReceiptProjectorAdapter(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createActivationReceiptProjectorAdapter } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-adapters.js:181` |\n| `createAnchoredVersionMaterialEvidence` | function: function createAnchoredVersionMaterialEvidence({ cwd = process.cwd(), targetChannel = \"\", targetRef = \"\", alphaRef = \"\", releaseRef = \"HEAD\", runLifecycle = true, } = {}) | { cwd = process.cwd(), targetChannel = \"\", targetRef = \"\", alphaRef = \"\", releaseRef = \"HEAD\", runLifecycle = true, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createAnchoredVersionMaterialEvidence } from \"@kungfu-tech/buildchain\";` | `packages/core/anchored-version-material.js:118` |\n| `createArtifactEvidence` | function: function createArtifactEvidence({ assets = [], repository = \"\", tag = \"\", sourceSha = \"\", workflow = {}, kfdAdopter = undefined } = {}) | { assets = [], repository = \"\", tag = \"\", sourceSha = \"\", workflow = {}, kfdAdopter = undefined } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createArtifactEvidence } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport.js:1088` |\n| `createArtifactSigningReceipt` | function: function createArtifactSigningReceipt({ request, status = \"passed\", authority = {}, result = {}, signatures = [], reason = \"\", } = {}) | { request, status = \"passed\", authority = {}, result = {}, signatures = [], reason = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createArtifactSigningReceipt } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-signing.js:313` |\n| `createArtifactSigningRequest` | function: function createArtifactSigningRequest({ source = {}, runtime = {}, artifact = {}, signature = {}, delivery = {}, } = {}) | { source = {}, runtime = {}, artifact = {}, signature = {}, delivery = {}, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createArtifactSigningRequest } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-signing.js:167` |\n| `createArtifactSigningResult` | function: function createArtifactSigningResult({ request, receipt, receiptPath = \"receipt.json\", payload = {}, evidence = [], verification = {}, } = {}) | { request, receipt, receiptPath = \"receipt.json\", payload = {}, evidence = [], verification = {}, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createArtifactSigningResult } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-signing-result.js:68` |\n| `createBuildchainContractLock` | function: function createBuildchainContractLock({ buildchainRef = \"v3\", resolvedSha = \"\", contractWorld, compatibilityPolicy = DEFAULT_POLICY, acceptedAt = new Date().toISOString(), } = {}) | { buildchainRef = \"v3\", resolvedSha = \"\", contractWorld, compatibilityPolicy = DEFAULT_POLICY, acceptedAt = new Date().toISOString(), } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createBuildchainContractLock } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-contract.js:830` |\n| `createBuildchainContractWorld` | function: function createBuildchainContractWorld({ root = process.cwd(), packageJson = undefined, controllerRegistry = undefined, } = {}) | { root = process.cwd(), packageJson = undefined, controllerRegistry = undefined, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainContractWorld } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-contract.js:123` |\n| `createBuildchainGithubGovernanceAuthority` | function: function createBuildchainGithubGovernanceAuthority() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainGithubGovernanceAuthority } from \"@kungfu-tech/buildchain\";` | `packages/core/github-governance-authority.js:452` |\n| `createBuildchainKfd1Witness` | function: function createBuildchainKfd1Witness({ root = process.cwd(), sourceSha = \"\" } = {}) | { root = process.cwd(), sourceSha = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainKfd1Witness } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-kfd-claims.js:530` |\n| `createBuildchainKfd2Claims` | function: function createBuildchainKfd2Claims({ root = process.cwd(), witnessFiles = {} } = {}) | { root = process.cwd(), witnessFiles = {} } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainKfd2Claims } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-kfd-claims.js:687` |\n| `createBuildchainKfd3ArtifactWitness` | function: function createBuildchainKfd3ArtifactWitness({ root = process.cwd(), sourceSha = \"\" } = {}) | { root = process.cwd(), sourceSha = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainKfd3ArtifactWitness } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-kfd-claims.js:647` |\n| `createBuildchainKfd3PrebuildWitness` | function: function createBuildchainKfd3PrebuildWitness({ root = process.cwd(), sourceSha = \"\" } = {}) | { root = process.cwd(), sourceSha = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainKfd3PrebuildWitness } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-kfd-claims.js:583` |\n| `createBuildchainKfdClaimRegistry` | function: function createBuildchainKfdClaimRegistry({ root = process.cwd(), sourceSha = \"\" } = {}) | { root = process.cwd(), sourceSha = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainKfdClaimRegistry } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-kfd-claims.js:510` |\n| `createBuildchainKfdSurfaceRegistry` | function: function createBuildchainKfdSurfaceRegistry({ root = process.cwd() } = {}) | { root = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainKfdSurfaceRegistry } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-kfd-claims.js:411` |\n| `createBuildchainLayoutDiscovery` | function: function createBuildchainLayoutDiscovery({ cwd = process.cwd(), buildchainVersion = \"\", } = {}) | { cwd = process.cwd(), buildchainVersion = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainLayoutDiscovery } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:99` |\n| `createBuildchainLogger` | function: function createBuildchainLogger(options = {}) | options = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | subprocess | `import { createBuildchainLogger } from \"@kungfu-tech/buildchain\";` | `packages/core/logging.js:300` |\n| `createBuildchainPublicationAuthorityRegistry` | function: function createBuildchainPublicationAuthorityRegistry({ root = process.cwd() } = {}) | { root = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainPublicationAuthorityRegistry } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-publication-authority.js:86` |\n| `createBuildchainPublicClaimDefinitions` | function: function createBuildchainPublicClaimDefinitions() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainPublicClaimDefinitions } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-kfd-claims.js:226` |\n| `createCacheEvidenceSet` | function: function createCacheEvidenceSet({ repository, sourceCommit, sourceTree = \"\", runtimeCommit = \"\", platform, operations = [], } = {}) | { repository, sourceCommit, sourceTree = \"\", runtimeCommit = \"\", platform, operations = [], } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createCacheEvidenceSet } from \"@kungfu-tech/buildchain\";` | `packages/core/cache-evidence.js:244` |\n| `createCacheOperationReceipt` | function: function createCacheOperationReceipt({ operationId, operation, provider, producer, platform, cacheKey, cacheRoot, outcome, bindings = {}, metrics, evidence, } = {}) | { operationId, operation, provider, producer, platform, cacheKey, cacheRoot, outcome, bindings = {}, metrics, evidence, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createCacheOperationReceipt } from \"@kungfu-tech/buildchain\";` | `packages/core/cache-evidence.js:169` |\n| `createCandidateTimeline` | function: function createCandidateTimeline({ candidate = {}, events = [], generatedAt, } = {}) | { candidate = {}, events = [], generatedAt, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createCandidateTimeline } from \"@kungfu-tech/buildchain\";` | `packages/core/candidate-timeline.js:381` |\n| `createConsumerPublicationDecision` | function: function createConsumerPublicationDecision({ capability, gateAggregate, decision, predicateId, predicateDigest, evidence = {}, now = new Date(), } = {}) | { capability, gateAggregate, decision, predicateId, predicateDigest, evidence = {}, now = new Date(), } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createConsumerPublicationDecision } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:991` |\n| `createControllerPlan` | function: function createControllerPlan({ descriptor, source = {}, runtime = {}, inputs = {} } = {}) | { descriptor, source = {}, runtime = {}, inputs = {} } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createControllerPlan } from \"@kungfu-tech/buildchain\";` | `packages/core/controller-evidence.js:287` |\n| `createControllerReceipt` | function: function createControllerReceipt({ plan, stages = [], evidence = [], reason = undefined, artifact = \"\" } = {}) | { plan, stages = [], evidence = [], reason = undefined, artifact = \"\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createControllerReceipt } from \"@kungfu-tech/buildchain\";` | `packages/core/controller-evidence.js:363` |\n| `createControllerReceiptReference` | function: function createControllerReceiptReference(receipt) | receipt | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createControllerReceiptReference } from \"@kungfu-tech/buildchain\";` | `packages/core/controller-evidence.js:491` |\n| `createControllerRegistry` | function: function createControllerRegistry({ workflows = [] } = {}) | { workflows = [] } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createControllerRegistry } from \"@kungfu-tech/buildchain\";` | `packages/core/controller-evidence.js:197` |\n| `createDiagnosticsArtifact` | function: function createDiagnosticsArtifact({ cwd = process.cwd(), logPath = \"\", artifactPaths = [], cacheDirs = [], lifecycleObservability = undefined, processSamples = [], processSummary = undefined, requestedParallelism = 0, sourceCheckout = undefined, compilerCachePreparation = undefined, links = {}, } = {}) | { cwd = process.cwd(), logPath = \"\", artifactPaths = [], cacheDirs = [], lifecycleObservability = undefined, processSamples = [], processSummary = undefined, requestedParallelism = 0, sourceCheckout = undefined, compilerCachePreparation = undefined, links = {}, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createDiagnosticsArtifact } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:1408` |\n| `createEngineeringHousekeeperPlan` | function: function createEngineeringHousekeeperPlan({ repository, target, branches = [], pullRequests = [], policy = {}, observedAt, }) | { repository, target, branches = [], pullRequests = [], policy = {}, observedAt, } | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createEngineeringHousekeeperPlan } from \"@kungfu-tech/buildchain\";` | `packages/core/engineering-housekeeper.js:170` |\n| `createEngineeringHousekeeperReceipt` | function: function createEngineeringHousekeeperReceipt({ plan, outcomes, appliedAt, }) | { plan, outcomes, appliedAt, } | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createEngineeringHousekeeperReceipt } from \"@kungfu-tech/buildchain\";` | `packages/core/engineering-housekeeper.js:246` |\n| `createGitHubArtifactAttestationEvidence` | function: function createGitHubArtifactAttestationEvidence({ preparation, attestationId, attestationUrl, bundlePath, workflow = {}, } = {}) | { preparation, attestationId, attestationUrl, bundlePath, workflow = {}, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createGitHubArtifactAttestationEvidence } from \"@kungfu-tech/buildchain\";` | `packages/core/github-artifact-attestation.js:474` |\n| `createGitHubArtifactAttestationPolicy` | function: function createGitHubArtifactAttestationPolicy(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGitHubArtifactAttestationPolicy } from \"@kungfu-tech/buildchain\";` | `packages/core/github-artifact-attestation.js:204` |\n| `createGitHubArtifactAttestationVerificationPlan` | function: function createGitHubArtifactAttestationVerificationPlan({ artifactPath, bundlePath, evidence, } = {}) | { artifactPath, bundlePath, evidence, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGitHubArtifactAttestationVerificationPlan } from \"@kungfu-tech/buildchain\";` | `packages/core/github-artifact-attestation.js:524` |\n| `createGithubGovernanceRolloutPlan` | function: function createGithubGovernanceRolloutPlan({ repository, targetRef, inventory, rollbackSnapshot, rollbackProtectionExists = true, desiredProtection, } = {}) | { repository, targetRef, inventory, rollbackSnapshot, rollbackProtectionExists = true, desiredProtection, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGithubGovernanceRolloutPlan } from \"@kungfu-tech/buildchain\";` | `packages/core/github-governance-authority.js:934` |\n| `createGitHubIssueRequest` | function: function createGitHubIssueRequest({ token, apiUrl = process.env.GITHUB_API_URL \\|\\| \"https://api.github.com\", fetchImpl = globalThis.fetch, retryDelaysMs = DEFAULT_RETRY_DELAYS_MS, } = {}) | { token, apiUrl = process.env.GITHUB_API_URL \\|\\| \"https://api.github.com\", fetchImpl = globalThis.fetch, retryDelaysMs = DEFAULT_RETRY_DELAYS_MS, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGitHubIssueRequest } from \"@kungfu-tech/buildchain\";` | `packages/core/issue-reporting.js:393` |\n| `createGitHubReleaseAssetsAdapter` | function: function createGitHubReleaseAssetsAdapter({ octokit, resolveArtifact, } = {}) | { octokit, resolveArtifact, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGitHubReleaseAssetsAdapter } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-adapters.js:310` |\n| `createGithubRulesetBypassRolloutPlan` | function: function createGithubRulesetBypassRolloutPlan({ repository, rulesetId, inventory, rollbackSnapshot, } = {}) | { repository, rulesetId, inventory, rollbackSnapshot, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGithubRulesetBypassRolloutPlan } from \"@kungfu-tech/buildchain\";` | `packages/core/github-governance-authority.js:1112` |\n| `createGithubRulesetGovernanceRolloutPlan` | function: function createGithubRulesetGovernanceRolloutPlan({ repository, targetRef, rulesetId, rulesetName, inventory, rollbackSnapshot, desiredProtection, } = {}) | { repository, targetRef, rulesetId, rulesetName, inventory, rollbackSnapshot, desiredProtection, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGithubRulesetGovernanceRolloutPlan } from \"@kungfu-tech/buildchain\";` | `packages/core/github-governance-authority.js:1191` |\n| `createHttpJsonReadback` | function: function createHttpJsonReadback({ fetchImpl = globalThis.fetch } = {}) | { fetchImpl = globalThis.fetch } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createHttpJsonReadback } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-adapters.js:191` |\n| `createKfd1ReleaseGateEvidence` | function: function createKfd1ReleaseGateEvidence({ cwd = process.cwd(), artifactRoot = \"\", artifacts = [], witnesses = [], verifiedAt = new Date().toISOString(), metadata = resolveKfd1Metadata(), } = {}) | { cwd = process.cwd(), artifactRoot = \"\", artifacts = [], witnesses = [], verifiedAt = new Date().toISOString(), metadata = resolveKfd1Metadata(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createKfd1ReleaseGateEvidence } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-gate.js:977` |\n| `createKfd3CollaborationInterfaceReleaseGateEvidence` | function: function createKfd3CollaborationInterfaceReleaseGateEvidence({ prebuildWitnesses = [], artifactWitnesses = [], prebuildWitnessMetas = [], artifactWitnessMetas = [], artifactCommandMeta = undefined, verifiedAt = new Date().toISOString(), metadata = resolveKfd3Metadata(), } = {}) | { prebuildWitnesses = [], artifactWitnesses = [], prebuildWitnessMetas = [], artifactWitnessMetas = [], artifactCommandMeta = undefined, verifiedAt = new Date().toISOString(), metadata = resolveKfd3Metadata(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createKfd3CollaborationInterfaceReleaseGateEvidence } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-gate.js:1132` |\n| `createKfd3SurfaceWitness` | function: function createKfd3SurfaceWitness({ cwd = process.cwd(), registryPath = \"\", kind = \"prebuild\", sourceSha = \"\", artifactPath = \"\", } = {}) | { cwd = process.cwd(), registryPath = \"\", kind = \"prebuild\", sourceSha = \"\", artifactPath = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | network | `import { createKfd3SurfaceWitness } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd3-surface-register.js:702` |\n| `createKfdAdopterReleaseBinding` | function: function createKfdAdopterReleaseBinding({ manifest, manifestGate, legacyProjection, manifestPath = \"kfd-adopter-manifest.json\", gatePath = \"kfd-adopter-manifest-gate.json\", legacyProjectionPath = \"kfd-support.json\", expectedSourceSha = \"\", } = {}) | { manifest, manifestGate, legacyProjection, manifestPath = \"kfd-adopter-manifest.json\", gatePath = \"kfd-adopter-manifest-gate.json\", legacyProjectionPath = \"kfd-support.json\", expectedSourceSha = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createKfdAdopterReleaseBinding } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-verification-envelope.js:441` |\n| `createKfdBadgeSpecsFromStandards` | function: function createKfdBadgeSpecsFromStandards(standardsMetadata) | standardsMetadata | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createKfdBadgeSpecsFromStandards } from \"@kungfu-tech/buildchain\";` | `packages/core/readme-badges.js:126` |\n| `createKungfuBuildInfoProjection` | function: function createKungfuBuildInfoProjection({ moduleFact, cwd = process.cwd(), now = nowIso() } = {}) | { moduleFact, cwd = process.cwd(), now = nowIso() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createKungfuBuildInfoProjection } from \"@kungfu-tech/buildchain\";` | `packages/core/build-facts.js:528` |\n| `createManualUpstreamPickupCapture` | function: function createManualUpstreamPickupCapture({ plan, expectedDownstreamBaseSha, }) | { plan, expectedDownstreamBaseSha, } | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createManualUpstreamPickupCapture } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-pickup.js:361` |\n| `createManualUpstreamPickupPlan` | function: function createManualUpstreamPickupPlan({ config: configInput, sourceId, channel, currentVersion, upstreamRelease, }) | { config: configInput, sourceId, channel, currentVersion, upstreamRelease, } | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createManualUpstreamPickupPlan } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-pickup.js:303` |\n| `createPackageReleasePropagationCapture` | function: function createPackageReleasePropagationCapture({ config: configInput, upstreamRelease: upstreamReleaseInput, expectedBaseShas = {}, } = {}) | { config: configInput, upstreamRelease: upstreamReleaseInput, expectedBaseShas = {}, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPackageReleasePropagationCapture } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-capture.js:101` |\n| `createPaperAlphaPlan` | function: function createPaperAlphaPlan({ cwd = process.cwd(), sourceRef = \"\", targetRef = \"\", } = {}) | { cwd = process.cwd(), sourceRef = \"\", targetRef = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPaperAlphaPlan } from \"@kungfu-tech/buildchain\";` | `packages/core/paper.js:2656` |\n| `createPaperBuildPlan` | function: function createPaperBuildPlan({ cwd = process.cwd(), sourceSha = \"\", pullToolchain = true, } = {}) | { cwd = process.cwd(), sourceSha = \"\", pullToolchain = true, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPaperBuildPlan } from \"@kungfu-tech/buildchain\";` | `packages/core/paper.js:2593` |\n| `createPaperResumePlan` | function: function createPaperResumePlan({ cwd = process.cwd(), buildchainRef = \"\", } = {}) | { cwd = process.cwd(), buildchainRef = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write | `import { createPaperResumePlan } from \"@kungfu-tech/buildchain\";` | `packages/core/paper.js:2714` |\n| `createPaperWorkStartPlan` | function: function createPaperWorkStartPlan({ cwd = process.cwd(), topic = \"\", branch = \"\", buildchainSha = \"\", } = {}) | { cwd = process.cwd(), topic = \"\", branch = \"\", buildchainSha = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createPaperWorkStartPlan } from \"@kungfu-tech/buildchain\";` | `packages/core/paper-work.js:41` |\n| `createPaperWorkSubmitPlan` | function: function createPaperWorkSubmitPlan({ cwd = process.cwd(), pullRequests = [], pullRequestObservation = { ok: true }, buildchainSha = \"\", } = {}) | { cwd = process.cwd(), pullRequests = [], pullRequestObservation = { ok: true }, buildchainSha = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createPaperWorkSubmitPlan } from \"@kungfu-tech/buildchain\";` | `packages/core/paper-work.js:207` |\n| `createPortableDevCachePlan` | function: function createPortableDevCachePlan(manifest) | manifest | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createPortableDevCachePlan } from \"@kungfu-tech/buildchain\";` | `packages/core/portable-dev-cache.js:172` |\n| `createPortableDevCacheReceipt` | function: function createPortableDevCacheReceipt({ plan, matchedKey = \"\", cacheHit = \"\", validationStatus = \"pass\", validationReason = \"\", coldFallbackStatus = \"not-run\", }) | { plan, matchedKey = \"\", cacheHit = \"\", validationStatus = \"pass\", validationReason = \"\", coldFallbackStatus = \"not-run\", } | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPortableDevCacheReceipt } from \"@kungfu-tech/buildchain\";` | `packages/core/portable-dev-cache.js:226` |\n| `createPublicationAdmission` | function: function createPublicationAdmission(input = {}) | input = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createPublicationAdmission } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:236` |\n| `createPublicationArtifactCandidate` | function: function createPublicationArtifactCandidate({ repository, sourceSha, sourceTreeSha, runtimeSha, manifest, passport, controllerReceipt, files = [], } = {}) | { repository, sourceSha, sourceTreeSha, runtimeSha, manifest, passport, controllerReceipt, files = [], } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPublicationArtifactCandidate } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-artifact-candidate.js:55` |\n| `createPublicationArtifactManifestSet` | function: function createPublicationArtifactManifestSet({ repository, sourceSha, sourceTreeSha, manifests = [], payloads = [], } = {}) | { repository, sourceSha, sourceTreeSha, manifests = [], payloads = [], } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPublicationArtifactManifestSet } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:303` |\n| `createPublicationAuthorityRegistry` | function: function createPublicationAuthorityRegistry({ descriptors = [], workflows = [] } = {}) | { descriptors = [], workflows = [] } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPublicationAuthorityRegistry } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:121` |\n| `createPublicationControlPlaneAudit` | function: function createPublicationControlPlaneAudit({ repository, workflowPath, publisherWorkflowPath, environment, facts = [], observedAt, expiresAt, } = {}) | { repository, workflowPath, publisherWorkflowPath, environment, facts = [], observedAt, expiresAt, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createPublicationControlPlaneAudit } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:208` |\n| `createPublicationGateDecision` | function: function createPublicationGateDecision({ sourceSha, profile, required = false, rationale, policy = {}, } = {}) | { sourceSha, profile, required = false, rationale, policy = {}, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createPublicationGateDecision } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:280` |\n| `createPublicationQualificationReceipt` | function: function createPublicationQualificationReceipt({ capability, gateAggregate, consumerDecision, now = new Date(), } = {}) | { capability, gateAggregate, consumerDecision, now = new Date(), } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPublicationQualificationReceipt } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:1035` |\n| `createPublicationSealedBundle` | function: function createPublicationSealedBundle({ candidate, packageName, packageVersion, npmTarballPath, npmIntegrity, releaseAssetPaths = [], githubReleaseRequired = true, } = {}) | { candidate, packageName, packageVersion, npmTarballPath, npmIntegrity, releaseAssetPaths = [], githubReleaseRequired = true, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPublicationSealedBundle } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-sealed-bundle.js:84` |\n| `createPublicationSourceBundle` | function: function createPublicationSourceBundle({ cwd = process.cwd(), sourcePaths = [], output = \".buildchain/publication/source.tar.gz\", } = {}) | { cwd = process.cwd(), sourcePaths = [], output = \".buildchain/publication/source.tar.gz\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write, subprocess | `import { createPublicationSourceBundle } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-artifact.js:249` |\n| `createReadmeBadgeEndpointRegistry` | function: function createReadmeBadgeEndpointRegistry({ kfdSpecs = undefined, kfdStandards = undefined } = {}) | { kfdSpecs = undefined, kfdStandards = undefined } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | subprocess | `import { createReadmeBadgeEndpointRegistry } from \"@kungfu-tech/buildchain\";` | `packages/core/readme-badges.js:133` |\n| `createReleaseActivationReceiptSet` | function: function createReleaseActivationReceiptSet({ transaction, receipts = [], } = {}) | { transaction, receipts = [], } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createReleaseActivationReceiptSet } from \"@kungfu-tech/buildchain\";` | `packages/core/release-activation-transaction.js:311` |\n| `createReleaseActivationTransaction` | function: function createReleaseActivationTransaction({ transactionId, mode = \"shadow\", bindings, owners, } = {}) | { transactionId, mode = \"shadow\", bindings, owners, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createReleaseActivationTransaction } from \"@kungfu-tech/buildchain\";` | `packages/core/release-activation-transaction.js:103` |\n| `createReleaseCandidatePassport` | function: function createReleaseCandidatePassport({ repository = \"\", pullRequest = {}, targetChannel = \"\", version = \"\", sourceHeadSha = \"\", baseSha = \"\", mergeRefSha = \"\", sourceTreeHash = \"\", buildSummary = {}, buildchain = {}, gateAggregate = undefined, familyEvidence = undefined, controllerReceipts = [], controllerReceiptReferences = [], workflow = {}, createdAt = nowIso(), } = {}) | { repository = \"\", pullRequest = {}, targetChannel = \"\", version = \"\", sourceHeadSha = \"\", baseSha = \"\", mergeRefSha = \"\", sourceTreeHash = \"\", buildSummary = {}, buildchain = {}, gateAggregate = undefined, familyEvidence = undefined, controllerReceipts = [], controllerReceiptReferences = [], workflow = {}, createdAt = nowIso(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createReleaseCandidatePassport } from \"@kungfu-tech/buildchain\";` | `packages/core/release-candidate.js:310` |\n| `createReleaseCheckReport` | function: function createReleaseCheckReport({ passport, artifactEvidence, publishEvidence, impact, agentIndex, productMechanism, kfdAgentHubEvidence, kfdSupportEvidence, kfdAdopterManifest, kfdAdopterManifestGate, releaseEvidenceDocuments = [], checkedAt = nowIso(), } = {}) | { passport, artifactEvidence, publishEvidence, impact, agentIndex, productMechanism, kfdAgentHubEvidence, kfdSupportEvidence, kfdAdopterManifest, kfdAdopterManifestGate, releaseEvidenceDocuments = [], checkedAt = nowIso(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createReleaseCheckReport } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport.js:2555` |\n| `createReleasePassport` | function: function createReleasePassport({ cwd = process.cwd(), repository = \"\", tag = \"\", sourceSha = \"\", line = \"\", productName = \"Buildchain\", packageName = \"@kungfu-tech/buildchain\", packageVersion = \"\", productMechanismPath = \"product-mechanism.json\", artifactEvidencePath = \"artifact-evidence.json\", impactPath = \"impact.json\", agentIndexPath = \"agent-index.json\", checkReportPath = \"check-report.json\", publishEvidencePath = \"\", transactionStatePath = \"\", assets = [], packageSet = undefined, anchorManifest = undefined, versionMaterial = undefined, publishEvidence = undefined, trustedPublishing = undefined, transaction = undefined, buildSummary = undefined, buildFacts = [], platformArtifactManifests = [], distTagPromotionEvidence = undefined, release = {}, publish = {}, impact = undefined, workflow = {}, kfd1 = undefined, kfd2Claims = [], kfd3 = undefined, kfdAdopter = undefined, kfdAdopterManifestEvidencePath = \"\", kfdAdopterGateEvidencePath = \"\", kfdSupport = undefined, kfdSupportEvidencePath = \"\", invariantPassports = undefined, releaseEvidence = [], kfdAgentHubEvidence = undefined, kfdAgentHubEvidencePath = \"\", controllerReceipts = [], controllerReceiptReferences = [], githubArtifactAttestations = [], checkedAt = \"\", } = {}) | { cwd = process.cwd(), repository = \"\", tag = \"\", sourceSha = \"\", line = \"\", productName = \"Buildchain\", packageName = \"@kungfu-tech/buildchain\", packageVersion = \"\", productMechanismPath = \"product-mechanism.json\", artifactEvidencePath = \"artifact-evidence.json\", impactPath = \"impact.json\", agentIndexPath = \"agent-index.json\", checkReportPath = \"check-report.json\", publishEvidencePath = \"\", transactionStatePath = \"\", assets = [], packageSet = undefined, anchorManifest = undefined, versionMaterial = undefined, publishEvidence = undefined, trustedPublishing = undefined, transaction = undefined, buildSummary = undefined, buildFacts = [], platformArtifactManifests = [], distTagPromotionEvidence = undefined, release = {}, publish = {}, impact = undefined, workflow = {}, kfd1 = undefined, kfd2Claims = [], kfd3 = undefined, kfdAdopter = undefined, kfdAdopterManifestEvidencePath = \"\", kfdAdopterGateEvidencePath = \"\", kfdSupport = undefined, kfdSupportEvidencePath = \"\", invariantPassports = undefined, releaseEvidence = [], kfdAgentHubEvidence = undefined, kfdAgentHubEvidencePath = \"\", controllerReceipts = [], controllerReceiptReferences = [], githubArtifactAttestations = [], checkedAt = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { createReleasePassport } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport.js:1123` |\n| `createReleasePassportCheckManifest` | function: function createReleasePassportCheckManifest({ standards = kfdStandards } = {}) | { standards = kfdStandards } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createReleasePassportCheckManifest } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport-contract.js:159` |\n| `createReleasePropagationLock` | function: function createReleasePropagationLock({ graph, edge, sourceNode, targetNode, upstreamRelease, downstreamChannel, } = {}) | { graph, edge, sourceNode, targetNode, upstreamRelease, downstreamChannel, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createReleasePropagationLock } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation.js:199` |\n| `createReleasePropagationPushPlan` | function: function createReleasePropagationPushPlan({ work: workInput, expectedWorkRoot, repositoryState: stateInput, } = {}) | { work: workInput, expectedWorkRoot, repositoryState: stateInput, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | subprocess | `import { createReleasePropagationPushPlan } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-push.js:77` |\n| `createReleasePropagationReceipt` | function: function createReleasePropagationReceipt({ plan, target = \"\", lockResult, prOutcome, stagingState = \"pending\", productionState = \"not-requested\", observedAt = \"\", } = {}) | { plan, target = \"\", lockResult, prOutcome, stagingState = \"pending\", productionState = \"not-requested\", observedAt = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createReleasePropagationReceipt } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation.js:371` |\n| `createReleasePropagationStageReceipt` | function: function createReleasePropagationStageReceipt({ work, stage, outcome = \"success\", observedAt, actor, summary, evidence, failure = null, } = {}) | { work, stage, outcome = \"success\", observedAt, actor, summary, evidence, failure = null, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createReleasePropagationStageReceipt } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-work.js:214` |\n| `createReleasePropagationWork` | function: function createReleasePropagationWork({ plan, target = \"\", workContext, expectedDownstreamBaseSha, } = {}) | { plan, target = \"\", workContext, expectedDownstreamBaseSha, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createReleasePropagationWork } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-work.js:111` |\n| `createReleaseTailAdapterSet` | function: function createReleaseTailAdapterSet(declaration, adapters) | declaration, adapters | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createReleaseTailAdapterSet } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-plane.js:1217` |\n| `createReleaseTailTransaction` | function: function createReleaseTailTransaction(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createReleaseTailTransaction } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-plane.js:697` |\n| `createReleaseTransaction` | function: function createReleaseTransaction({ repository, version, exactTag = \"\", channel, line = \"\", sourceSha, targetRef, releaseSha, releaseMaterialSha = releaseSha, publishToolingSha = \"\", lifecycleIdentity = \"lifecycle.publish\", statePath = \"\", evidencePath = \"\", actor = \"\", runId = \"\", } = {}) | { repository, version, exactTag = \"\", channel, line = \"\", sourceSha, targetRef, releaseSha, releaseMaterialSha = releaseSha, publishToolingSha = \"\", lifecycleIdentity = \"lifecycle.publish\", statePath = \"\", evidencePath = \"\", actor = \"\", runId = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createReleaseTransaction } from \"@kungfu-tech/buildchain\";` | `packages/core/publish-transaction.js:197` |\n| `createRunnerProvenance` | function: function createRunnerProvenance({ runnerClass, os, architecture, imageDigest, measurementDigest, baselineDigest = \"\", toolchainDigest = \"\", cacheContractDigest = \"\", taskIsolationDigest = \"\", cleanBaselineProven = false, isolation = \"\", } = {}) | { runnerClass, os, architecture, imageDigest, measurementDigest, baselineDigest = \"\", toolchainDigest = \"\", cacheContractDigest = \"\", taskIsolationDigest = \"\", cleanBaselineProven = false, isolation = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createRunnerProvenance } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:166` |\n| `createSignedStaticChannelAdapter` | function: function createSignedStaticChannelAdapter(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createSignedStaticChannelAdapter } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-adapters.js:161` |\n| `createSiteReleaseActivationAdapter` | function: function createSiteReleaseActivationAdapter(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createSiteReleaseActivationAdapter } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-adapters.js:171` |\n| `createStableCandidateLedger` | function: function createStableCandidateLedger({ repository, targetBranch, now = new Date().toISOString() } = {}) | { repository, targetBranch, now = new Date().toISOString() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createStableCandidateLedger } from \"@kungfu-tech/buildchain\";` | `packages/core/stable-candidate-ledger.js:56` |\n| `createSurfaceTimestampPolicy` | function: function createSurfaceTimestampPolicy({ generatedAt = \"\", publishedAt = \"\", sourceDateEpoch = process.env.SOURCE_DATE_EPOCH \\|\\| DEFAULT_SOURCE_DATE_EPOCH, sourceRevision = \"\", deterministicInputs = [], timestampPolicy = \"\", timestampFields = [\"generatedAt\", \"publishedAt\"], timestampFieldsParticipateInArtifactDigest = true, artifactDigestScope = \"manifest-and-artifact\", reproducible = true, } = {}) | { generatedAt = \"\", publishedAt = \"\", sourceDateEpoch = process.env.SOURCE_DATE_EPOCH \\|\\| DEFAULT_SOURCE_DATE_EPOCH, sourceRevision = \"\", deterministicInputs = [], timestampPolicy = \"\", timestampFields = [\"generatedAt\", \"publishedAt\"], timestampFieldsParticipateInArtifactDigest = true, artifactDigestScope = \"manifest-and-artifact\", reproducible = true, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createSurfaceTimestampPolicy } from \"@kungfu-tech/buildchain\";` | `packages/core/surface-manifest.js:34` |\n| `createWebSurfaceProductionDecision` | function: function createWebSurfaceProductionDecision({ approved, kind, repository, sourceSha, actor, actorPermission = \"\", releasePr = 0, releaseSource = \"\", reason, } = {}) | { approved, kind, repository, sourceSha, actor, actorPermission = \"\", releasePr = 0, releaseSource = \"\", reason, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createWebSurfaceProductionDecision } from \"@kungfu-tech/buildchain\";` | `packages/core/web-surface-publication-candidate.js:45` |\n| `createWebSurfacePublicationCandidate` | function: function createWebSurfacePublicationCandidate({ repository, sourceSha, sourceTreeSha, runtimeSha, plan, planFileDigest, controllerReceipt, decision, } = {}) | { repository, sourceSha, sourceTreeSha, runtimeSha, plan, planFileDigest, controllerReceipt, decision, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createWebSurfacePublicationCandidate } from \"@kungfu-tech/buildchain\";` | `packages/core/web-surface-publication-candidate.js:79` |\n| `decideChannelCandidate` | function: function decideChannelCandidate(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { decideChannelCandidate } from \"@kungfu-tech/buildchain\";` | `packages/core/channel-candidate.js:91` |\n| `DEFAULT_BUILDCHAIN_ISSUE_REPOSITORY` | constant: const DEFAULT_BUILDCHAIN_ISSUE_REPOSITORY | none | value | Import does not declare a throw contract. | none-on-import | `import { DEFAULT_BUILDCHAIN_ISSUE_REPOSITORY } from \"@kungfu-tech/buildchain\";` | `packages/core/issue-reporting.js:6` |\n| `DEFAULT_HOUSEKEEPER_POLICY` | constant: const DEFAULT_HOUSEKEEPER_POLICY | none | value | Import does not declare a throw contract. | none-on-import | `import { DEFAULT_HOUSEKEEPER_POLICY } from \"@kungfu-tech/buildchain\";` | `packages/core/engineering-housekeeper.js:29` |\n| `defaultBuildchainLogPath` | function: function defaultBuildchainLogPath({ cwd = process.cwd() } = {}) | { cwd = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { defaultBuildchainLogPath } from \"@kungfu-tech/buildchain\";` | `packages/core/logging.js:41` |\n| `defaultPublishEvidencePath` | function: function defaultPublishEvidencePath(version, workspace = process.cwd()) | version, workspace = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { defaultPublishEvidencePath } from \"@kungfu-tech/buildchain\";` | `packages/core/publish-transaction.js:193` |\n| `defaultReleaseStatePath` | function: function defaultReleaseStatePath(version, workspace = process.cwd()) | version, workspace = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { defaultReleaseStatePath } from \"@kungfu-tech/buildchain\";` | `packages/core/publish-transaction.js:185` |\n| `DETACHED_ARTIFACT_SIGNATURE_CONTRACT` | constant: const DETACHED_ARTIFACT_SIGNATURE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { DETACHED_ARTIFACT_SIGNATURE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/detached-artifact-signature.js:10` |\n| `detectKfd3Surfaces` | function: function detectKfd3Surfaces({ cwd = process.cwd(), kinds = [], artifactPath = \"\" } = {}) | { cwd = process.cwd(), kinds = [], artifactPath = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { detectKfd3Surfaces } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd3-surface-register.js:423` |\n| `detectLockfile` | function: function detectLockfile(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { detectLockfile } from \"@kungfu-tech/buildchain\";` | `packages/core/package-manager.js:237` |\n| `detectPackageManager` | function: function detectPackageManager(cwd = process.cwd()) | cwd = process.cwd() | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { detectPackageManager } from \"@kungfu-tech/buildchain\";` | `packages/core/package-manager.js:56` |\n| `detectPublicationAuthoritySignals` | function: function detectPublicationAuthoritySignals(workflowText = \"\") | workflowText = \"\" | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { detectPublicationAuthoritySignals } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:104` |\n| `detectRequestedParallelism` | function: function detectRequestedParallelism({ command = \"\", args = [], env = process.env, } = {}) | { command = \"\", args = [], env = process.env, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { detectRequestedParallelism } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:1188` |\n| `detectRequestedParallelismFromProcessSamples` | function: function detectRequestedParallelismFromProcessSamples(samples = []) | samples = [] | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { detectRequestedParallelismFromProcessSamples } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:1223` |\n| `diagnoseLegacyReleaseTailHooks` | function: function diagnoseLegacyReleaseTailHooks(hooks = {}) | hooks = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { diagnoseLegacyReleaseTailHooks } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-compatibility.js:23` |\n| `discoverArtifactPassport` | function: async function discoverArtifactPassport({ subject, cwd = process.cwd(), passportLocation = \"\", locatorConfig = \"\", repository = \"\", tag = \"\", githubReleaseBaseUrl = \"\", } = {}) | { subject, cwd = process.cwd(), passportLocation = \"\", locatorConfig = \"\", repository = \"\", tag = \"\", githubReleaseBaseUrl = \"\", } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { discoverArtifactPassport } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-passport.js:499` |\n| `discoverBuildchainRepoFiles` | function: function discoverBuildchainRepoFiles(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { discoverBuildchainRepoFiles } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:143` |\n| `discoverConfiguredDerivedVersionMaterial` | function: function discoverConfiguredDerivedVersionMaterial(cwd = process.cwd(), loadedConfig = loadBuildchainConfig(cwd)) | cwd = process.cwd(), loadedConfig = loadBuildchainConfig(cwd) | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { discoverConfiguredDerivedVersionMaterial } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-config.js:1462` |\n| `discoverConfiguredVersionStateFiles` | function: function discoverConfiguredVersionStateFiles(cwd = process.cwd(), loadedConfig = loadBuildchainConfig(cwd)) | cwd = process.cwd(), loadedConfig = loadBuildchainConfig(cwd) | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { discoverConfiguredVersionStateFiles } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-config.js:1423` |\n| `discoverKfdStandards` | function: function discoverKfdStandards() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { discoverKfdStandards } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd.js:464` |\n| `discoverPaperFleet` | function: function discoverPaperFleet(root = process.cwd()) | root = process.cwd() | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { discoverPaperFleet } from \"@kungfu-tech/buildchain\";` | `packages/core/paper-fleet.js:23` |\n| `ENGINEERING_HOUSEKEEPER_CONTRACT` | constant: const ENGINEERING_HOUSEKEEPER_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ENGINEERING_HOUSEKEEPER_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/engineering-housekeeper.js:3` |\n| `ENGINEERING_HOUSEKEEPER_SCHEMA_VERSION` | constant: const ENGINEERING_HOUSEKEEPER_SCHEMA_VERSION | none | value | Import does not declare a throw contract. | none-on-import | `import { ENGINEERING_HOUSEKEEPER_SCHEMA_VERSION } from \"@kungfu-tech/buildchain\";` | `packages/core/engineering-housekeeper.js:5` |\n| `engineeringHousekeeperRoot` | function: function engineeringHousekeeperRoot(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { engineeringHousekeeperRoot } from \"@kungfu-tech/buildchain\";` | `packages/core/engineering-housekeeper.js:58` |\n| `enumerateActionInputs` | function: function enumerateActionInputs({ root = process.cwd() } = {}) | { root = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { enumerateActionInputs } from \"@kungfu-tech/buildchain\";` | `packages/core/public-surface-audit.js:91` |\n| `enumerateCliCommandsFromBin` | function: function enumerateCliCommandsFromBin({ root = process.cwd(), binPath = \"bin/buildchain.mjs\", } = {}) | { root = process.cwd(), binPath = \"bin/buildchain.mjs\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { enumerateCliCommandsFromBin } from \"@kungfu-tech/buildchain\";` | `packages/core/public-surface-cli.js:93` |\n| `enumerateDocCommandRefs` | function: function enumerateDocCommandRefs({ root = process.cwd() } = {}) | { root = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { enumerateDocCommandRefs } from \"@kungfu-tech/buildchain\";` | `packages/core/public-surface-audit.js:115` |\n| `enumerateSitePages` | function: function enumerateSitePages({ root = process.cwd() } = {}) | { root = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { enumerateSitePages } from \"@kungfu-tech/buildchain\";` | `packages/core/public-surface-audit.js:106` |\n| `enumerateWorkflowInputs` | function: function enumerateWorkflowInputs({ root = process.cwd() } = {}) | { root = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { enumerateWorkflowInputs } from \"@kungfu-tech/buildchain\";` | `packages/core/public-surface-audit.js:74` |\n| `evaluateBuildchainContractLock` | function: function evaluateBuildchainContractLock({ lock, current, runtimeRef = \"\", runtimeSha = \"\", runtimeClass = \"\", compatibilityPolicy = \"\", workflowShellRef = \"\", expectedChannel = \"\", expectedMajor = \"\", allowOpaqueRuntime = false, } = {}) | { lock, current, runtimeRef = \"\", runtimeSha = \"\", runtimeClass = \"\", compatibilityPolicy = \"\", workflowShellRef = \"\", expectedChannel = \"\", expectedMajor = \"\", allowOpaqueRuntime = false, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { evaluateBuildchainContractLock } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-contract.js:916` |\n| `evaluateCodeownersAuthority` | function: function evaluateCodeownersAuthority({ source = \"\", sourcePath = \"\", reviewAuthority = \"kungfu-origin\", protectedPaths = PROTECTED_AUTHORITY_PATHS, } = {}) | { source = \"\", sourcePath = \"\", reviewAuthority = \"kungfu-origin\", protectedPaths = PROTECTED_AUTHORITY_PATHS, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { evaluateCodeownersAuthority } from \"@kungfu-tech/buildchain\";` | `packages/core/github-governance-authority.js:427` |\n| `evaluateGithubGovernanceSnapshot` | function: function evaluateGithubGovernanceSnapshot({ descriptor = createBuildchainGithubGovernanceAuthority(), repository, targetRef, organizationPlan, codeowners, effectivePolicy, memberships, apiEvidence = {}, observedAt, expiresAt, verifier = {}, } = {}) | { descriptor = createBuildchainGithubGovernanceAuthority(), repository, targetRef, organizationPlan, codeowners, effectivePolicy, memberships, apiEvidence = {}, observedAt, expiresAt, verifier = {}, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { evaluateGithubGovernanceSnapshot } from \"@kungfu-tech/buildchain\";` | `packages/core/github-governance-authority.js:696` |\n| `evaluateKfdProductGate` | function: async function evaluateKfdProductGate({ cwd = process.cwd(), input, expectedSourceSha = \"\", checkedAt = new Date().toISOString(), } = {}) | { cwd = process.cwd(), input, expectedSourceSha = \"\", checkedAt = new Date().toISOString(), } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { evaluateKfdProductGate } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-product-gates.js:419` |\n| `evaluatePublicationControlPlaneSnapshot` | function: function evaluatePublicationControlPlaneSnapshot({ repository, workflowPath, publisherWorkflowPath = workflowPath, environment, branch, packageName, publisherMode = \"npm-trusted-publisher\", requiredStatusCheck = \"check\", snapshot, observedAt, expiresAt, } = {}) | { repository, workflowPath, publisherWorkflowPath = workflowPath, environment, branch, packageName, publisherMode = \"npm-trusted-publisher\", requiredStatusCheck = \"check\", snapshot, observedAt, expiresAt, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { evaluatePublicationControlPlaneSnapshot } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-control-plane-audit.js:75` |\n| `executePaperNpmBootstrap` | function: function executePaperNpmBootstrap(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { executePaperNpmBootstrap } from \"@kungfu-tech/buildchain\";` | `packages/core/paper.js:2841` |\n| `executePaperWorkStart` | function: function executePaperWorkStart(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { executePaperWorkStart } from \"@kungfu-tech/buildchain\";` | `packages/core/paper-work.js:169` |\n| `executePaperWorkSubmitPush` | function: function executePaperWorkSubmitPush(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { executePaperWorkSubmitPush } from \"@kungfu-tech/buildchain\";` | `packages/core/paper-work.js:357` |\n| `executeReleasePropagationPush` | function: function executeReleasePropagationPush({ work, expectedWorkRoot, cwd = process.cwd(), remote = \"origin\", } = {}) | { work, expectedWorkRoot, cwd = process.cwd(), remote = \"origin\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { executeReleasePropagationPush } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-push.js:231` |\n| `executeReleaseTailTransaction` | function: async function executeReleaseTailTransaction(transaction, { adapters, checkpoint: checkpointCallback } = {}) | transaction, { adapters, checkpoint: checkpointCallback } = {} | Promise<unknown> | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { executeReleaseTailTransaction } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-plane.js:1016` |\n| `explainArtifactPassport` | function: async function explainArtifactPassport(options = {}) | options = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { explainArtifactPassport } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-passport.js:827` |\n| `explainKfdAgentHub` | function: function explainKfdAgentHub({ cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, kfdRoot = \"\" } = {}) | { cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, kfdRoot = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { explainKfdAgentHub } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-agent-hub.js:470` |\n| `explainReleaseLineDryRun` | function: function explainReleaseLineDryRun({ cwd = process.cwd(), targetRef, sha = \"\", sourceRef = \"\", tags, publishTransaction = false, publishCommand = \"\", } = {}) | { cwd = process.cwd(), targetRef, sha = \"\", sourceRef = \"\", tags, publishTransaction = false, publishCommand = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { explainReleaseLineDryRun } from \"@kungfu-tech/buildchain\";` | `packages/core/release-line-dry-run.js:127` |\n| `explainReleasePassport` | function: async function explainReleasePassport({ passportLocation, forAudience = \"human\" } = {}) | { passportLocation, forAudience = \"human\" } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { explainReleasePassport } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport.js:2709` |\n| `FAMILY_RELEASE_EVIDENCE_CONTRACT` | constant: const FAMILY_RELEASE_EVIDENCE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { FAMILY_RELEASE_EVIDENCE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-candidate.js:5` |\n| `finalizeBuildchainContractWorld` | function: function finalizeBuildchainContractWorld(contractWorld) | contractWorld | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { finalizeBuildchainContractWorld } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-contract.js:805` |\n| `formatCandidateTimelineReport` | function: function formatCandidateTimelineReport(timeline) | timeline | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { formatCandidateTimelineReport } from \"@kungfu-tech/buildchain\";` | `packages/core/candidate-timeline.js:438` |\n| `formatDiagnosticsSummaryTable` | function: function formatDiagnosticsSummaryTable(summary = {}) | summary = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { formatDiagnosticsSummaryTable } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:1786` |\n| `formatGitHubHousekeeperPlan` | function: function formatGitHubHousekeeperPlan(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { formatGitHubHousekeeperPlan } from \"@kungfu-tech/buildchain\";` | `packages/core/engineering-housekeeper-github.js:697` |\n| `formatReleaseLineDryRun` | function: function formatReleaseLineDryRun(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { formatReleaseLineDryRun } from \"@kungfu-tech/buildchain\";` | `packages/core/release-line-dry-run.js:267` |\n| `getLifecycleStage` | function: function getLifecycleStage(loadedConfig, name) | loadedConfig, name | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { getLifecycleStage } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-config.js:1367` |\n| `getNativeDiagnosticsProfile` | function: function getNativeDiagnosticsProfile(loadedConfig) | loadedConfig | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { getNativeDiagnosticsProfile } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-config.js:520` |\n| `getPublishContract` | function: function getPublishContract(loadedConfig) | loadedConfig | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { getPublishContract } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-config.js:1371` |\n| `getStableReleasePolicy` | function: function getStableReleasePolicy(loadedConfig) | loadedConfig | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { getStableReleasePolicy } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-config.js:328` |\n| `getVersionStrategy` | function: function getVersionStrategy(loadedConfig) | loadedConfig | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { getVersionStrategy } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-config.js:1495` |\n| `getWorkspaceInfo` | function: function getWorkspaceInfo(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { getWorkspaceInfo } from \"@kungfu-tech/buildchain\";` | `packages/core/package-manager.js:211` |\n| `GITHUB_ARTIFACT_ATTESTATION_EVIDENCE_CONTRACT` | constant: const GITHUB_ARTIFACT_ATTESTATION_EVIDENCE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_ARTIFACT_ATTESTATION_EVIDENCE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/github-artifact-attestation.js:9` |\n| `GITHUB_ARTIFACT_ATTESTATION_POLICY_CONTRACT` | constant: const GITHUB_ARTIFACT_ATTESTATION_POLICY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_ARTIFACT_ATTESTATION_POLICY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/github-artifact-attestation.js:5` |\n| `GITHUB_ARTIFACT_ATTESTATION_PREDICATE_CONTRACT` | constant: const GITHUB_ARTIFACT_ATTESTATION_PREDICATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_ARTIFACT_ATTESTATION_PREDICATE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/github-artifact-attestation.js:7` |\n| `GITHUB_ARTIFACT_ATTESTATION_PREDICATE_TYPE` | constant: const GITHUB_ARTIFACT_ATTESTATION_PREDICATE_TYPE | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_ARTIFACT_ATTESTATION_PREDICATE_TYPE } from \"@kungfu-tech/buildchain\";` | `packages/core/github-artifact-attestation.js:13` |\n| `GITHUB_ARTIFACT_ATTESTATION_VERIFICATION_CONTRACT` | constant: const GITHUB_ARTIFACT_ATTESTATION_VERIFICATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_ARTIFACT_ATTESTATION_VERIFICATION_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/github-artifact-attestation.js:11` |\n| `GITHUB_ARTIFACT_ATTESTATION_WORKFLOW` | constant: const GITHUB_ARTIFACT_ATTESTATION_WORKFLOW | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_ARTIFACT_ATTESTATION_WORKFLOW } from \"@kungfu-tech/buildchain\";` | `packages/core/github-artifact-attestation.js:15` |\n| `GITHUB_GOVERNANCE_AUTHORITY_CONTRACT` | constant: const GITHUB_GOVERNANCE_AUTHORITY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_GOVERNANCE_AUTHORITY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/github-governance-authority.js:3` |\n| `GITHUB_GOVERNANCE_RECEIPT_CONTRACT` | constant: const GITHUB_GOVERNANCE_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_GOVERNANCE_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/github-governance-authority.js:5` |\n| `GITHUB_GOVERNANCE_ROLLOUT_CONTRACT` | constant: const GITHUB_GOVERNANCE_ROLLOUT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_GOVERNANCE_ROLLOUT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/github-governance-authority.js:7` |\n| `GITHUB_GOVERNANCE_RULESET_ROLLOUT_CONTRACT` | constant: const GITHUB_GOVERNANCE_RULESET_ROLLOUT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_GOVERNANCE_RULESET_ROLLOUT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/github-governance-authority.js:9` |\n| `githubArtifactAttestationRequiredPermissions` | function: function githubArtifactAttestationRequiredPermissions() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { githubArtifactAttestationRequiredPermissions } from \"@kungfu-tech/buildchain\";` | `packages/core/github-artifact-attestation.js:640` |\n| `githubArtifactAttestationSemanticRoot` | function: function githubArtifactAttestationSemanticRoot(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { githubArtifactAttestationSemanticRoot } from \"@kungfu-tech/buildchain\";` | `packages/core/github-artifact-attestation.js:91` |\n| `githubArtifactAttestationSha256Buffer` | function: function githubArtifactAttestationSha256Buffer(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { githubArtifactAttestationSha256Buffer } from \"@kungfu-tech/buildchain\";` | `packages/core/github-artifact-attestation.js:83` |\n| `githubArtifactAttestationSha256File` | function: function githubArtifactAttestationSha256File(filePath) | filePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { githubArtifactAttestationSha256File } from \"@kungfu-tech/buildchain\";` | `packages/core/github-artifact-attestation.js:87` |\n| `githubGovernanceDigest` | function: function githubGovernanceDigest(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { githubGovernanceDigest } from \"@kungfu-tech/buildchain\";` | `packages/core/github-governance-authority.js:165` |\n| `GitHubHousekeeperClient` | class: class GitHubHousekeeperClient | none | GitHubHousekeeperClient | Construction and method errors follow the linked source implementation. | class-dependent | `import { GitHubHousekeeperClient } from \"@kungfu-tech/buildchain\";` | `packages/core/engineering-housekeeper-github-client.js:54` |\n| `GitHubHousekeeperProviderError` | class: class GitHubHousekeeperProviderError | none | GitHubHousekeeperProviderError | Construction and method errors follow the linked source implementation. | class-dependent | `import { GitHubHousekeeperProviderError } from \"@kungfu-tech/buildchain\";` | `packages/core/engineering-housekeeper-github-client.js:37` |\n| `GitHubIssueRequestError` | class: class GitHubIssueRequestError | none | GitHubIssueRequestError | Construction and method errors follow the linked source implementation. | class-dependent | `import { GitHubIssueRequestError } from \"@kungfu-tech/buildchain\";` | `packages/core/issue-reporting.js:23` |\n| `githubReleaseAssetsTargetRoot` | function: function githubReleaseAssetsTargetRoot({ destination, artifacts }) | { destination, artifacts } | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { githubReleaseAssetsTargetRoot } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-adapters.js:297` |\n| `HOMEBREW_TAP_CHECK_CONTRACT` | constant: const HOMEBREW_TAP_CHECK_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { HOMEBREW_TAP_CHECK_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/homebrew.js:6` |\n| `HOMEBREW_TAP_FACTS_CONTRACT` | constant: const HOMEBREW_TAP_FACTS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { HOMEBREW_TAP_FACTS_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/homebrew.js:5` |\n| `HOMEBREW_TAP_MANIFEST_CONTRACT` | constant: const HOMEBREW_TAP_MANIFEST_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { HOMEBREW_TAP_MANIFEST_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/homebrew.js:7` |\n| `HOUSEKEEPER_REASON_CODES` | constant: const HOUSEKEEPER_REASON_CODES | none | value | Import does not declare a throw contract. | none-on-import | `import { HOUSEKEEPER_REASON_CODES } from \"@kungfu-tech/buildchain\";` | `packages/core/engineering-housekeeper.js:7` |\n| `IMPACT_LEDGER_CONTRACT` | constant: const IMPACT_LEDGER_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { IMPACT_LEDGER_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport.js:39` |\n| `initKfdAgentHub` | function: function initKfdAgentHub({ cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, write = false, force = false } = {}) | { cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, write = false, force = false } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { initKfdAgentHub } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-agent-hub.js:363` |\n| `inspectKfdAgentHub` | function: function inspectKfdAgentHub({ cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, kfdRoot = \"\" } = {}) | { cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, kfdRoot = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { inspectKfdAgentHub } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-agent-hub.js:384` |\n| `inspectReleasePropagationPushState` | function: function inspectReleasePropagationPushState({ work: workInput, cwd = process.cwd(), remote = \"origin\", } = {}) | { work: workInput, cwd = process.cwd(), remote = \"origin\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | subprocess | `import { inspectReleasePropagationPushState } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-push.js:174` |\n| `installedKfdPackageArtifactRoot` | function: function installedKfdPackageArtifactRoot() | none | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { installedKfdPackageArtifactRoot } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-verification-envelope.js:397` |\n| `KFD_ADOPTER_RELEASE_BINDING_CONTRACT` | constant: const KFD_ADOPTER_RELEASE_BINDING_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_ADOPTER_RELEASE_BINDING_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-verification-envelope.js:16` |\n| `KFD_AGENT_HUB_ADOPTION_CONTRACT` | constant: const KFD_AGENT_HUB_ADOPTION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_AGENT_HUB_ADOPTION_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-agent-hub.js:9` |\n| `KFD_AGENT_HUB_ADOPTION_SCHEMA` | constant: const KFD_AGENT_HUB_ADOPTION_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_AGENT_HUB_ADOPTION_SCHEMA } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-agent-hub.js:12` |\n| `KFD_AGENT_HUB_DECLARATION` | constant: const KFD_AGENT_HUB_DECLARATION | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_AGENT_HUB_DECLARATION } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-agent-hub.js:7` |\n| `KFD_AGENT_HUB_LOCK_CONTRACT` | constant: const KFD_AGENT_HUB_LOCK_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_AGENT_HUB_LOCK_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-agent-hub.js:10` |\n| `KFD_AGENT_HUB_OUTPUT_DIR` | constant: const KFD_AGENT_HUB_OUTPUT_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_AGENT_HUB_OUTPUT_DIR } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-agent-hub.js:8` |\n| `KFD_AGENT_HUB_VERIFICATION_CONTRACT` | constant: const KFD_AGENT_HUB_VERIFICATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_AGENT_HUB_VERIFICATION_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-agent-hub.js:11` |\n| `KFD_PRODUCT_GATE_CONTRACT` | constant: const KFD_PRODUCT_GATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_PRODUCT_GATE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-product-gates.js:11` |\n| `KFD_PRODUCT_GATE_INPUT_CONTRACT` | constant: const KFD_PRODUCT_GATE_INPUT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_PRODUCT_GATE_INPUT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-product-gates.js:9` |\n| `KFD_PRODUCT_GATE_INPUT_SCHEMA` | constant: const KFD_PRODUCT_GATE_INPUT_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_PRODUCT_GATE_INPUT_SCHEMA } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-product-gates.js:51` |\n| `KFD_PRODUCT_GATE_INPUT_SCHEMA_ID` | constant: const KFD_PRODUCT_GATE_INPUT_SCHEMA_ID | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_PRODUCT_GATE_INPUT_SCHEMA_ID } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-product-gates.js:13` |\n| `kfd1` | constant: const kfd1 | none | value | Import does not declare a throw contract. | none-on-import | `import { kfd1 } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd.js:546` |\n| `KFD1_RELEASE_GATE_CONTRACT` | constant: const KFD1_RELEASE_GATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD1_RELEASE_GATE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-gate.js:9` |\n| `KFD1_WITNESS_SET_CONTRACT` | constant: const KFD1_WITNESS_SET_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD1_WITNESS_SET_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-gate.js:10` |\n| `kfd2` | constant: const kfd2 | none | value | Import does not declare a throw contract. | none-on-import | `import { kfd2 } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd.js:561` |\n| `KFD2_PRODUCT_CLAIMS_OUTPUT_CONTRACT` | constant: const KFD2_PRODUCT_CLAIMS_OUTPUT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD2_PRODUCT_CLAIMS_OUTPUT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd2-product-claims.js:23` |\n| `KFD2_PRODUCT_CLAIMS_REGISTRY_CONTRACT` | constant: const KFD2_PRODUCT_CLAIMS_REGISTRY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD2_PRODUCT_CLAIMS_REGISTRY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd2-product-claims.js:19` |\n| `KFD2_PRODUCT_CLAIMS_VALIDATION_CONTRACT` | constant: const KFD2_PRODUCT_CLAIMS_VALIDATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD2_PRODUCT_CLAIMS_VALIDATION_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd2-product-claims.js:21` |\n| `KFD2_RELEASE_TRUST_PASSPORT_CONTRACT` | constant: const KFD2_RELEASE_TRUST_PASSPORT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD2_RELEASE_TRUST_PASSPORT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport.js:43` |\n| `KFD2_TRUST_PROOF_CONTRACT` | constant: const KFD2_TRUST_PROOF_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD2_TRUST_PROOF_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport.js:44` |\n| `kfd3` | constant: const kfd3 | none | value | Import does not declare a throw contract. | none-on-import | `import { kfd3 } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd.js:663` |\n| `KFD3_ARTIFACT_WITNESS_CONTRACT` | constant: const KFD3_ARTIFACT_WITNESS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD3_ARTIFACT_WITNESS_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-gate.js:13` |\n| `KFD3_CAPABILITY_QUERY_CONTRACT` | constant: const KFD3_CAPABILITY_QUERY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD3_CAPABILITY_QUERY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd3-surface-register.js:9` |\n| `KFD3_DEFAULT_REGISTRY_PATH` | constant: const KFD3_DEFAULT_REGISTRY_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD3_DEFAULT_REGISTRY_PATH } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd3-surface-register.js:10` |\n| `KFD3_PREBUILD_WITNESS_CONTRACT` | constant: const KFD3_PREBUILD_WITNESS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD3_PREBUILD_WITNESS_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-gate.js:12` |\n| `KFD3_RELEASE_GATE_CONTRACT` | constant: const KFD3_RELEASE_GATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD3_RELEASE_GATE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-gate.js:11` |\n| `KFD3_SURFACE_AUDIT_CONTRACT` | constant: const KFD3_SURFACE_AUDIT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD3_SURFACE_AUDIT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd3-surface-register.js:8` |\n| `KFD3_SURFACE_DETECTION_CONTRACT` | constant: const KFD3_SURFACE_DETECTION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD3_SURFACE_DETECTION_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd3-surface-register.js:7` |\n| `KFD3_SURFACE_REGISTRY_CONTRACT` | constant: const KFD3_SURFACE_REGISTRY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD3_SURFACE_REGISTRY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd3-surface-register.js:6` |\n| `kfd4` | constant: const kfd4 | none | value | Import does not declare a throw contract. | none-on-import | `import { kfd4 } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd.js:681` |\n| `kfdProductGateDigest` | function: function kfdProductGateDigest(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { kfdProductGateDigest } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-product-gates.js:142` |\n| `kfdProductGates` | constant: const kfdProductGates | none | value | Import does not declare a throw contract. | none-on-import | `import { kfdProductGates } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-product-gates.js:561` |\n| `KFX_ADMISSION_INPUTS_CONTRACT` | constant: const KFX_ADMISSION_INPUTS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFX_ADMISSION_INPUTS_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-verification-envelope.js:14` |\n| `layout` | constant: const layout | none | value | Import does not declare a throw contract. | none-on-import | `import { layout } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd.js:905` |\n| `LEGACY_BUILDCHAIN_CONFIG_PATH` | constant: const LEGACY_BUILDCHAIN_CONFIG_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { LEGACY_BUILDCHAIN_CONFIG_PATH } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:8` |\n| `LEGACY_BUILDCHAIN_CONTRACT_LOCK_PATH` | constant: const LEGACY_BUILDCHAIN_CONTRACT_LOCK_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { LEGACY_BUILDCHAIN_CONTRACT_LOCK_PATH } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:10` |\n| `LEGACY_BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATH` | constant: const LEGACY_BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { LEGACY_BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATH } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:28` |\n| `LEGACY_BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATHS` | constant: const LEGACY_BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATHS | none | value | Import does not declare a throw contract. | none-on-import | `import { LEGACY_BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATHS } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:29` |\n| `LEGACY_BUILDCHAIN_RELEASE_PASSPORT_PATH` | constant: const LEGACY_BUILDCHAIN_RELEASE_PASSPORT_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { LEGACY_BUILDCHAIN_RELEASE_PASSPORT_PATH } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:34` |\n| `listArtifactSigningProfiles` | function: function listArtifactSigningProfiles() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { listArtifactSigningProfiles } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-signing.js:103` |\n| `listKfdSchemas` | function: function listKfdSchemas({ standard = \"\" } = {}) | { standard = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { listKfdSchemas } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd.js:492` |\n| `loadBuildchainConfig` | function: function loadBuildchainConfig(cwd = process.cwd()) | cwd = process.cwd() | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { loadBuildchainConfig } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-config.js:158` |\n| `loadConfiguredAnchorManifest` | function: function loadConfiguredAnchorManifest(cwd = process.cwd(), loadedConfig = loadBuildchainConfig(cwd)) | cwd = process.cwd(), loadedConfig = loadBuildchainConfig(cwd) | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { loadConfiguredAnchorManifest } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-config.js:1504` |\n| `makeReleasePassportFixtureAssets` | function: function makeReleasePassportFixtureAssets(dir) | dir | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write | `import { makeReleasePassportFixtureAssets } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport.js:2738` |\n| `MANUAL_UPSTREAM_PICKUP_CONFIG_CONTRACT` | constant: const MANUAL_UPSTREAM_PICKUP_CONFIG_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { MANUAL_UPSTREAM_PICKUP_CONFIG_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-pickup.js:16` |\n| `MANUAL_UPSTREAM_PICKUP_PLAN_CONTRACT` | constant: const MANUAL_UPSTREAM_PICKUP_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { MANUAL_UPSTREAM_PICKUP_PLAN_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-pickup.js:18` |\n| `markStableCandidatePromoted` | function: function markStableCandidatePromoted(ledgerInput, versionInput, { stableTag = \"\", stableSha = \"\", now = new Date().toISOString() } = {}) | ledgerInput, versionInput, { stableTag = \"\", stableSha = \"\", now = new Date().toISOString() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { markStableCandidatePromoted } from \"@kungfu-tech/buildchain\";` | `packages/core/stable-candidate-ledger.js:229` |\n| `migrateBuildchainLayout` | function: function migrateBuildchainLayout({ cwd = process.cwd(), write = false, force = false } = {}) | { cwd = process.cwd(), write = false, force = false } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { migrateBuildchainLayout } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:287` |\n| `normalizeBuildchainConfig` | function: function normalizeBuildchainConfig(config) | config | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeBuildchainConfig } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-config.js:181` |\n| `normalizeBuildchainLogEvent` | function: function normalizeBuildchainLogEvent(input = {}, defaults = {}) | input = {}, defaults = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { normalizeBuildchainLogEvent } from \"@kungfu-tech/buildchain\";` | `packages/core/logging.js:45` |\n| `normalizeCandidateTimelineEvent` | function: function normalizeCandidateTimelineEvent(input = {}) | input = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeCandidateTimelineEvent } from \"@kungfu-tech/buildchain\";` | `packages/core/candidate-timeline.js:74` |\n| `normalizeControllerReceiptReferences` | function: function normalizeControllerReceiptReferences({ receipts = [], references = [], expectedSourceSha = \"\", acceptedSourceShas = [], expectedRuntimeSha = \"\", requirePassed = false, } = {}) | { receipts = [], references = [], expectedSourceSha = \"\", acceptedSourceShas = [], expectedRuntimeSha = \"\", requirePassed = false, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeControllerReceiptReferences } from \"@kungfu-tech/buildchain\";` | `packages/core/controller-evidence.js:532` |\n| `normalizeGitHubArtifactAttestationPolicy` | function: function normalizeGitHubArtifactAttestationPolicy(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeGitHubArtifactAttestationPolicy } from \"@kungfu-tech/buildchain\";` | `packages/core/github-artifact-attestation.js:158` |\n| `normalizeGithubBranchProtectionSnapshot` | function: function normalizeGithubBranchProtectionSnapshot(protection = {}) | protection = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { normalizeGithubBranchProtectionSnapshot } from \"@kungfu-tech/buildchain\";` | `packages/core/github-governance-authority.js:1027` |\n| `normalizeGithubRulesetSnapshot` | function: function normalizeGithubRulesetSnapshot(ruleset = {}) | ruleset = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { normalizeGithubRulesetSnapshot } from \"@kungfu-tech/buildchain\";` | `packages/core/github-governance-authority.js:1097` |\n| `normalizeIssueRepository` | function: function normalizeIssueRepository(repository = DEFAULT_BUILDCHAIN_ISSUE_REPOSITORY) | repository = DEFAULT_BUILDCHAIN_ISSUE_REPOSITORY | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeIssueRepository } from \"@kungfu-tech/buildchain\";` | `packages/core/issue-reporting.js:33` |\n| `normalizeKfd1ContractWorldWitness` | function: function normalizeKfd1ContractWorldWitness(witness, { metadata = resolveKfd1Metadata() } = {}) | witness, { metadata = resolveKfd1Metadata() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeKfd1ContractWorldWitness } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-gate.js:897` |\n| `normalizeKfd3CollaborationInterfaceArtifactWitness` | function: function normalizeKfd3CollaborationInterfaceArtifactWitness(witness, { metadata = resolveKfd3Metadata() } = {}) | witness, { metadata = resolveKfd3Metadata() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeKfd3CollaborationInterfaceArtifactWitness } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-gate.js:738` |\n| `normalizeKfd3CollaborationInterfacePrebuildWitness` | function: function normalizeKfd3CollaborationInterfacePrebuildWitness(witness, { metadata = resolveKfd3Metadata() } = {}) | witness, { metadata = resolveKfd3Metadata() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeKfd3CollaborationInterfacePrebuildWitness } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-gate.js:667` |\n| `normalizeKfd3DistributionDeclaration` | function: function normalizeKfd3DistributionDeclaration(distribution, { surfaceId = \"surface\" } = {}) | distribution, { surfaceId = \"surface\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeKfd3DistributionDeclaration } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd3-surface-register.js:73` |\n| `normalizeKfdStandardId` | function: function normalizeKfdStandardId(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeKfdStandardId } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd.js:455` |\n| `normalizeLifecycleStage` | function: function normalizeLifecycleStage(stage, label = \"lifecycle stage\", lifecycle = {}) | stage, label = \"lifecycle stage\", lifecycle = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeLifecycleStage } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-config.js:1328` |\n| `normalizeManualUpstreamPickupConfig` | function: function normalizeManualUpstreamPickupConfig(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeManualUpstreamPickupConfig } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-pickup.js:118` |\n| `normalizePackageReleasePropagationConfig` | function: function normalizePackageReleasePropagationConfig(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizePackageReleasePropagationConfig } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-capture.js:63` |\n| `normalizeReleasePropagationGraph` | function: function normalizeReleasePropagationGraph(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeReleasePropagationGraph } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation.js:163` |\n| `normalizeSiteUpstreamIntent` | function: function normalizeSiteUpstreamIntent(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeSiteUpstreamIntent } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-agent-entry.js:77` |\n| `normalizeStableCandidateLedger` | function: function normalizeStableCandidateLedger(input, expected = {}) | input, expected = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeStableCandidateLedger } from \"@kungfu-tech/buildchain\";` | `packages/core/stable-candidate-ledger.js:76` |\n| `PACKAGE_RELEASE_PROPAGATION_CONFIG_CONTRACT` | constant: const PACKAGE_RELEASE_PROPAGATION_CONFIG_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PACKAGE_RELEASE_PROPAGATION_CONFIG_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-capture.js:17` |\n| `PAPER_ALPHA_PLAN_CONTRACT` | constant: const PAPER_ALPHA_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_ALPHA_PLAN_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/paper.js:90` |\n| `PAPER_BUILD_PLAN_CONTRACT` | constant: const PAPER_BUILD_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_BUILD_PLAN_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/paper.js:89` |\n| `PAPER_FLEET_AUDIT_CONTRACT` | constant: const PAPER_FLEET_AUDIT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_FLEET_AUDIT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/paper-fleet.js:19` |\n| `PAPER_FLEET_UPDATE_PLAN_CONTRACT` | constant: const PAPER_FLEET_UPDATE_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_FLEET_UPDATE_PLAN_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/paper-fleet.js:20` |\n| `PAPER_MIGRATION_CONTRACT` | constant: const PAPER_MIGRATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_MIGRATION_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/paper.js:82` |\n| `PAPER_NPM_BOOTSTRAP_CONTRACT` | constant: const PAPER_NPM_BOOTSTRAP_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_NPM_BOOTSTRAP_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/paper.js:85` |\n| `PAPER_PATHS` | constant: const PAPER_PATHS | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_PATHS } from \"@kungfu-tech/buildchain\";` | `packages/core/paper-repository.js:7` |\n| `PAPER_PREFLIGHT_CONTRACT` | constant: const PAPER_PREFLIGHT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_PREFLIGHT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/paper.js:83` |\n| `PAPER_RESUME_PLAN_CONTRACT` | constant: const PAPER_RESUME_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_RESUME_PLAN_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/paper.js:91` |\n| `PAPER_SCAFFOLD_CONTRACT` | constant: const PAPER_SCAFFOLD_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_SCAFFOLD_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/paper.js:81` |\n| `PAPER_STATE_ORDER` | constant: const PAPER_STATE_ORDER | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_STATE_ORDER } from \"@kungfu-tech/buildchain\";` | `packages/core/paper.js:94` |\n| `PAPER_STATUS_CONTRACT` | constant: const PAPER_STATUS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_STATUS_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/paper.js:84` |\n| `PAPER_VISIBILITY_CONTRACT` | constant: const PAPER_VISIBILITY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_VISIBILITY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/paper.js:92` |\n| `PAPER_WORK_START_PLAN_CONTRACT` | constant: const PAPER_WORK_START_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_WORK_START_PLAN_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/paper-work.js:17` |\n| `PAPER_WORK_SUBMIT_PLAN_CONTRACT` | constant: const PAPER_WORK_SUBMIT_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_WORK_SUBMIT_PLAN_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/paper-work.js:19` |\n| `paperFleetTransitionWorkspace` | function: function paperFleetTransitionWorkspace(workspaceText, lockText) | workspaceText, lockText | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { paperFleetTransitionWorkspace } from \"@kungfu-tech/buildchain\";` | `packages/core/paper-fleet.js:290` |\n| `parseCodeowners` | function: function parseCodeowners(source) | source | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { parseCodeowners } from \"@kungfu-tech/buildchain\";` | `packages/core/github-governance-authority.js:403` |\n| `parseIssueLabels` | function: function parseIssueLabels(input = DEFAULT_LABELS) | input = DEFAULT_LABELS | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { parseIssueLabels } from \"@kungfu-tech/buildchain\";` | `packages/core/issue-reporting.js:41` |\n| `parseReleaseTailDeclaration` | function: function parseReleaseTailDeclaration(input) | input | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { parseReleaseTailDeclaration } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-plane.js:491` |\n| `planBuildchainLayoutMigration` | function: function planBuildchainLayoutMigration({ cwd = process.cwd() } = {}) | { cwd = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { planBuildchainLayoutMigration } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:265` |\n| `planPaperFleetUpdate` | function: function planPaperFleetUpdate(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { planPaperFleetUpdate } from \"@kungfu-tech/buildchain\";` | `packages/core/paper-fleet.js:209` |\n| `planPaperMigration` | function: function planPaperMigration({ cwd = process.cwd(), buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainSha = \"\", } = {}) | { cwd = process.cwd(), buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainSha = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { planPaperMigration } from \"@kungfu-tech/buildchain\";` | `packages/core/paper.js:1013` |\n| `planPaperScaffold` | function: function planPaperScaffold({ cwd = process.cwd(), buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainRef = \"v3\", buildchainSha = \"\", name = path.basename(path.resolve(cwd)), title = \"\", packageName = \"\", repository = \"\", version = \"0.1.0-alpha.0\", siteBaseUrl = \"\", } = {}) | { cwd = process.cwd(), buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainRef = \"v3\", buildchainSha = \"\", name = path.basename(path.resolve(cwd)), title = \"\", packageName = \"\", repository = \"\", version = \"0.1.0-alpha.0\", siteBaseUrl = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { planPaperScaffold } from \"@kungfu-tech/buildchain\";` | `packages/core/paper.js:702` |\n| `planReleaseLineBootstrap` | function: function planReleaseLineBootstrap({ cwd = process.cwd(), major, minor, sourceRef = \"\", initialVersion = \"\", requiredStatusCheck = \"check\", setDefault = true, createAlphaPr = true, approvalCount = 1, bootstrapBranch = \"\", } = {}) | { cwd = process.cwd(), major, minor, sourceRef = \"\", initialVersion = \"\", requiredStatusCheck = \"check\", setDefault = true, createAlphaPr = true, approvalCount = 1, bootstrapBranch = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { planReleaseLineBootstrap } from \"@kungfu-tech/buildchain\";` | `packages/core/release-line-bootstrap.js:153` |\n| `planReleasePropagation` | function: function planReleasePropagation({ graph: graphInput, upstreamRelease: releaseInput, sourceNode = \"\" } = {}) | { graph: graphInput, upstreamRelease: releaseInput, sourceNode = \"\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { planReleasePropagation } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation.js:249` |\n| `planSiteUpstreamAgentEntry` | function: function planSiteUpstreamAgentEntry({ sourceId: sourceInput, channel = \"\", handoffWork = null, } = {}) | { sourceId: sourceInput, channel = \"\", handoffWork = null, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { planSiteUpstreamAgentEntry } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-agent-entry.js:134` |\n| `planTransactionRecovery` | function: function planTransactionRecovery({ transaction, evidence, validation, explicitOverride = false, } = {}) | { transaction, evidence, validation, explicitOverride = false, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { planTransactionRecovery } from \"@kungfu-tech/buildchain\";` | `packages/core/publish-transaction.js:769` |\n| `prepareGitHubArtifactAttestation` | function: function prepareGitHubArtifactAttestation({ subjectPath, platformManifestPath, releasePassportPath, policy, expectedBuildchainRef = \"\", expectedCallerRepository = \"\", expectedSourceSha = \"\", } = {}) | { subjectPath, platformManifestPath, releasePassportPath, policy, expectedBuildchainRef = \"\", expectedCallerRepository = \"\", expectedSourceSha = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { prepareGitHubArtifactAttestation } from \"@kungfu-tech/buildchain\";` | `packages/core/github-artifact-attestation.js:250` |\n| `preparePublicationNpmPackage` | function: function preparePublicationNpmPackage({ cwd = process.cwd(), outputDir = \".buildchain/publication/npm-package\", packageName = \"\", } = {}) | { cwd = process.cwd(), outputDir = \".buildchain/publication/npm-package\", packageName = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { preparePublicationNpmPackage } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-package.js:120` |\n| `PRODUCT_MECHANISM_CONTRACT` | constant: const PRODUCT_MECHANISM_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PRODUCT_MECHANISM_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport.js:41` |\n| `projectArtifactVerificationEnvelopeToKfx` | function: function projectArtifactVerificationEnvelopeToKfx({ envelope, assessmentTime = Math.floor(Date.now() / 1000), expectedEnvelopeRoot = \"\", expectedIssuer = \"\", expectedPublisher = \"\", expectedContractVersion = \"\", } = {}) | { envelope, assessmentTime = Math.floor(Date.now() / 1000), expectedEnvelopeRoot = \"\", expectedIssuer = \"\", expectedPublisher = \"\", expectedContractVersion = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { projectArtifactVerificationEnvelopeToKfx } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-verification-envelope.js:368` |\n| `PUBLICATION_ADMISSION_CONTRACT` | constant: const PUBLICATION_ADMISSION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_ADMISSION_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:10` |\n| `PUBLICATION_ARTIFACT_ARCHIVE_CONTRACT` | constant: const PUBLICATION_ARTIFACT_ARCHIVE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_ARTIFACT_ARCHIVE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-artifact.js:9` |\n| `PUBLICATION_ARTIFACT_CANDIDATE_CONTRACT` | constant: const PUBLICATION_ARTIFACT_CANDIDATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_ARTIFACT_CANDIDATE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-artifact-candidate.js:5` |\n| `PUBLICATION_ARTIFACT_MANIFEST_CONTRACT` | constant: const PUBLICATION_ARTIFACT_MANIFEST_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_ARTIFACT_MANIFEST_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-artifact.js:7` |\n| `PUBLICATION_ARTIFACT_MANIFEST_SET_CONTRACT` | constant: const PUBLICATION_ARTIFACT_MANIFEST_SET_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_ARTIFACT_MANIFEST_SET_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:24` |\n| `PUBLICATION_ARTIFACT_PASSPORT_CONTRACT` | constant: const PUBLICATION_ARTIFACT_PASSPORT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_ARTIFACT_PASSPORT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-artifact.js:8` |\n| `PUBLICATION_ARTIFACT_REGISTRY_CONTRACT` | constant: const PUBLICATION_ARTIFACT_REGISTRY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_ARTIFACT_REGISTRY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-artifact.js:10` |\n| `PUBLICATION_AUTHORITY_CLASSES` | constant: const PUBLICATION_AUTHORITY_CLASSES | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_AUTHORITY_CLASSES } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:27` |\n| `PUBLICATION_AUTHORITY_REGISTRY_CONTRACT` | constant: const PUBLICATION_AUTHORITY_REGISTRY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_AUTHORITY_REGISTRY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:8` |\n| `PUBLICATION_CAPABILITY_CONTRACT` | constant: const PUBLICATION_CAPABILITY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_CAPABILITY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:12` |\n| `PUBLICATION_CONTROL_PLANE_AUDIT_CONTRACT` | constant: const PUBLICATION_CONTROL_PLANE_AUDIT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_CONTROL_PLANE_AUDIT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:16` |\n| `PUBLICATION_GATE_DECISION_CONTRACT` | constant: const PUBLICATION_GATE_DECISION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_GATE_DECISION_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:18` |\n| `PUBLICATION_NPM_PACKAGE_CONTRACT` | constant: const PUBLICATION_NPM_PACKAGE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_NPM_PACKAGE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-package.js:6` |\n| `PUBLICATION_QUALIFICATION_RECEIPT_CONTRACT` | constant: const PUBLICATION_QUALIFICATION_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_QUALIFICATION_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:22` |\n| `PUBLICATION_REPRODUCIBILITY_RECEIPT_CONTRACT` | constant: const PUBLICATION_REPRODUCIBILITY_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_REPRODUCIBILITY_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-reproducibility.js:12` |\n| `PUBLICATION_SEALED_BUNDLE_CONTRACT` | constant: const PUBLICATION_SEALED_BUNDLE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_SEALED_BUNDLE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-sealed-bundle.js:10` |\n| `publicationArtifactCandidateDigest` | function: function publicationArtifactCandidateDigest(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { publicationArtifactCandidateDigest } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-artifact-candidate.js:19` |\n| `publicationAuthorityDigest` | function: function publicationAuthorityDigest(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { publicationAuthorityDigest } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:72` |\n| `publicationGateAggregateBindings` | function: function publicationGateAggregateBindings(gateAggregate) | gateAggregate | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { publicationGateAggregateBindings } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:408` |\n| `qualifyStableCandidate` | function: function qualifyStableCandidate(ledgerInput, observation, { minimumSoakSeconds = 3600, now = new Date().toISOString() } = {}) | ledgerInput, observation, { minimumSoakSeconds = 3600, now = new Date().toISOString() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { qualifyStableCandidate } from \"@kungfu-tech/buildchain\";` | `packages/core/stable-candidate-ledger.js:139` |\n| `queryKfd3Capabilities` | function: async function queryKfd3Capabilities({ cwd = process.cwd(), product = \"\", registryPath = \"\", passportLocation = \"\", artifactPath = \"\", } = {}) | { cwd = process.cwd(), product = \"\", registryPath = \"\", passportLocation = \"\", artifactPath = \"\", } = {} | Promise<unknown> | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { queryKfd3Capabilities } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd3-surface-register.js:824` |\n| `readBuildchainContractLock` | function: function readBuildchainContractLock(filePath) | filePath | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readBuildchainContractLock } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-contract.js:881` |\n| `readBuildchainContractWorld` | function: function readBuildchainContractWorld(filePath) | filePath | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readBuildchainContractWorld } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-contract.js:861` |\n| `readBuildchainLogEvents` | function: function readBuildchainLogEvents(filePath) | filePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { readBuildchainLogEvents } from \"@kungfu-tech/buildchain\";` | `packages/core/logging.js:75` |\n| `readDiagnosticsArtifact` | function: function readDiagnosticsArtifact(filePath) | filePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { readDiagnosticsArtifact } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:1468` |\n| `readJsonFromLocation` | function: async function readJsonFromLocation(location, redirectCount = 0, { timeoutMs = 15_000 } = {}) | location, redirectCount = 0, { timeoutMs = 15_000 } = {} | Promise<unknown> | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readJsonFromLocation } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport.js:2625` |\n| `readKfd2ProductClaimsRegistry` | function: function readKfd2ProductClaimsRegistry({ cwd = process.cwd(), registryPath = BUILDCHAIN_KFD2_REGISTRY_PATH, } = {}) | { cwd = process.cwd(), registryPath = BUILDCHAIN_KFD2_REGISTRY_PATH, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readKfd2ProductClaimsRegistry } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd2-product-claims.js:137` |\n| `readKfd3SurfaceRegistry` | function: function readKfd3SurfaceRegistry({ cwd = process.cwd(), registryPath = \"\" } = {}) | { cwd = process.cwd(), registryPath = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { readKfd3SurfaceRegistry } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd3-surface-register.js:455` |\n| `readKfdSchema` | function: function readKfdSchema({ standard, schema = \"\" } = {}) | { standard, schema = \"\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readKfdSchema } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd.js:520` |\n| `README_BADGE_BLOCK_END` | constant: const README_BADGE_BLOCK_END | none | value | Import does not declare a throw contract. | none-on-import | `import { README_BADGE_BLOCK_END } from \"@kungfu-tech/buildchain\";` | `packages/core/readme-badges.js:15` |\n| `README_BADGE_BLOCK_START` | constant: const README_BADGE_BLOCK_START | none | value | Import does not declare a throw contract. | none-on-import | `import { README_BADGE_BLOCK_START } from \"@kungfu-tech/buildchain\";` | `packages/core/readme-badges.js:14` |\n| `README_BADGE_FACTS_CONTRACT` | constant: const README_BADGE_FACTS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { README_BADGE_FACTS_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/readme-badges.js:12` |\n| `README_BADGE_HOSTED_BASE_URL` | constant: const README_BADGE_HOSTED_BASE_URL | none | value | Import does not declare a throw contract. | none-on-import | `import { README_BADGE_HOSTED_BASE_URL } from \"@kungfu-tech/buildchain\";` | `packages/core/readme-badges.js:16` |\n| `readOptionalIssueBodyFile` | function: function readOptionalIssueBodyFile(filePath) | filePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { readOptionalIssueBodyFile } from \"@kungfu-tech/buildchain\";` | `packages/core/issue-reporting.js:385` |\n| `readPublishEvidence` | function: function readPublishEvidence(filePath) | filePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { readPublishEvidence } from \"@kungfu-tech/buildchain\";` | `packages/core/publish-transaction.js:564` |\n| `readReadme` | function: function readReadme({ cwd = process.cwd(), readmePath = \"README.md\" } = {}) | { cwd = process.cwd(), readmePath = \"README.md\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { readReadme } from \"@kungfu-tech/buildchain\";` | `packages/core/readme-badges.js:891` |\n| `readReleasePropagationJson` | function: function readReleasePropagationJson(value, { cwd = process.cwd(), label = \"json\" } = {}) | value, { cwd = process.cwd(), label = \"json\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readReleasePropagationJson } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation.js:305` |\n| `readReleaseTailTransaction` | function: function readReleaseTailTransaction(filePath) | filePath | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readReleaseTailTransaction } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-plane.js:830` |\n| `readReleaseTransaction` | function: function readReleaseTransaction(filePath) | filePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { readReleaseTransaction } from \"@kungfu-tech/buildchain\";` | `packages/core/publish-transaction.js:367` |\n| `recordReleaseActivationPhase` | function: function recordReleaseActivationPhase(transaction, phaseId, { receiptRoots = [], failure = \"\" } = {}) | transaction, phaseId, { receiptRoots = [], failure = \"\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { recordReleaseActivationPhase } from \"@kungfu-tech/buildchain\";` | `packages/core/release-activation-transaction.js:217` |\n| `recordReleasePropagationStage` | function: function recordReleasePropagationStage({ work, expectedWorkRoot, receipt } = {}) | { work, expectedWorkRoot, receipt } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { recordReleasePropagationStage } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-work-transitions.js:45` |\n| `recoveryFailure` | function: function recoveryFailure(error) | error | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { recoveryFailure } from \"@kungfu-tech/buildchain\";` | `packages/core/release-candidate-recovery.js:529` |\n| `redactBuildchainLogAttributes` | function: function redactBuildchainLogAttributes(attributes = {}) | attributes = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { redactBuildchainLogAttributes } from \"@kungfu-tech/buildchain\";` | `packages/core/logging.js:33` |\n| `redactDiagnosticsValue` | function: function redactDiagnosticsValue(key, value, pattern = DEFAULT_SECRET_KEY_PATTERN) | key, value, pattern = DEFAULT_SECRET_KEY_PATTERN | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { redactDiagnosticsValue } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:953` |\n| `redactIssueText` | function: function redactIssueText(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { redactIssueText } from \"@kungfu-tech/buildchain\";` | `packages/core/issue-reporting.js:51` |\n| `registerKfd3Surfaces` | function: function registerKfd3Surfaces({ cwd = process.cwd(), registryPath = \"\", kinds = [], artifactPath = \"\", product = {}, } = {}) | { cwd = process.cwd(), registryPath = \"\", kinds = [], artifactPath = \"\", product = {}, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { registerKfd3Surfaces } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd3-surface-register.js:502` |\n| `registerStableCandidate` | function: function registerStableCandidate(ledgerInput, candidateInput, { now = new Date().toISOString() } = {}) | ledgerInput, candidateInput, { now = new Date().toISOString() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { registerStableCandidate } from \"@kungfu-tech/buildchain\";` | `packages/core/stable-candidate-ledger.js:106` |\n| `RELEASE_ACTIVATION_CONTRACT` | constant: const RELEASE_ACTIVATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_ACTIVATION_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-activation-transaction.js:3` |\n| `RELEASE_ACTIVATION_PHASES` | constant: const RELEASE_ACTIVATION_PHASES | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_ACTIVATION_PHASES } from \"@kungfu-tech/buildchain\";` | `packages/core/release-activation-transaction.js:8` |\n| `RELEASE_ACTIVATION_RECEIPT_SET_CONTRACT` | constant: const RELEASE_ACTIVATION_RECEIPT_SET_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_ACTIVATION_RECEIPT_SET_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-activation-transaction.js:5` |\n| `RELEASE_CANDIDATE_PASSPORT_CONTRACT` | constant: const RELEASE_CANDIDATE_PASSPORT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_CANDIDATE_PASSPORT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-candidate.js:4` |\n| `RELEASE_CANDIDATE_RECOVERY_CONTRACT` | constant: const RELEASE_CANDIDATE_RECOVERY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_CANDIDATE_RECOVERY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-candidate-recovery.js:15` |\n| `RELEASE_CHECK_REPORT_CONTRACT` | value: RELEASE_CHECK_REPORT_CONTRACT | none | unknown | No narrower error contract was mechanically discoverable. | unknown | `import { RELEASE_CHECK_REPORT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport.js:1` |\n| `RELEASE_EVIDENCE_ATTACHMENT_CONTRACT` | constant: const RELEASE_EVIDENCE_ATTACHMENT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_EVIDENCE_ATTACHMENT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport.js:42` |\n| `RELEASE_PASSPORT_CHECK_MANIFEST_CONTRACT` | constant: const RELEASE_PASSPORT_CHECK_MANIFEST_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PASSPORT_CHECK_MANIFEST_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport-contract.js:19` |\n| `RELEASE_PASSPORT_CONTRACT` | value: RELEASE_PASSPORT_CONTRACT | none | unknown | No narrower error contract was mechanically discoverable. | unknown | `import { RELEASE_PASSPORT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport.js:1` |\n| `RELEASE_PASSPORT_SCHEMA` | constant: const RELEASE_PASSPORT_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PASSPORT_SCHEMA } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport-contract.js:26` |\n| `RELEASE_PASSPORT_SCHEMA_ID` | constant: const RELEASE_PASSPORT_SCHEMA_ID | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PASSPORT_SCHEMA_ID } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport-contract.js:17` |\n| `RELEASE_PROPAGATION_FAILURE_MATRIX` | constant: const RELEASE_PROPAGATION_FAILURE_MATRIX | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_FAILURE_MATRIX } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-agent-entry.js:66` |\n| `RELEASE_PROPAGATION_FAILURE_MATRIX_CONTRACT` | constant: const RELEASE_PROPAGATION_FAILURE_MATRIX_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_FAILURE_MATRIX_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-agent-entry.js:11` |\n| `RELEASE_PROPAGATION_GRAPH_CONTRACT` | constant: const RELEASE_PROPAGATION_GRAPH_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_GRAPH_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation.js:15` |\n| `RELEASE_PROPAGATION_LOCK_CONTRACT` | constant: const RELEASE_PROPAGATION_LOCK_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_LOCK_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation.js:17` |\n| `RELEASE_PROPAGATION_PLAN_CONTRACT` | value: RELEASE_PROPAGATION_PLAN_CONTRACT | none | unknown | No narrower error contract was mechanically discoverable. | unknown | `import { RELEASE_PROPAGATION_PLAN_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation.js:1` |\n| `RELEASE_PROPAGATION_PUSH_PLAN_CONTRACT` | constant: const RELEASE_PROPAGATION_PUSH_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_PUSH_PLAN_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-push.js:14` |\n| `RELEASE_PROPAGATION_PUSH_RESULT_CONTRACT` | constant: const RELEASE_PROPAGATION_PUSH_RESULT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_PUSH_RESULT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-push.js:16` |\n| `RELEASE_PROPAGATION_RECEIPT_CONTRACT` | constant: const RELEASE_PROPAGATION_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation.js:18` |\n| `RELEASE_PROPAGATION_STAGE_RECEIPT_CONTRACT` | constant: const RELEASE_PROPAGATION_STAGE_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_STAGE_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-work-constants.js:2` |\n| `RELEASE_PROPAGATION_WORK_CONTRACT` | constant: const RELEASE_PROPAGATION_WORK_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_WORK_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-work-constants.js:1` |\n| `RELEASE_PROPAGATION_WORK_STAGES` | constant: const RELEASE_PROPAGATION_WORK_STAGES | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_WORK_STAGES } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-work-constants.js:4` |\n| `RELEASE_TAIL_CAPABILITY_REGISTRY` | constant: const RELEASE_TAIL_CAPABILITY_REGISTRY | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_CAPABILITY_REGISTRY } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-plane.js:31` |\n| `RELEASE_TAIL_COMPATIBILITY_CONTRACT` | constant: const RELEASE_TAIL_COMPATIBILITY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_COMPATIBILITY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-compatibility.js:1` |\n| `RELEASE_TAIL_DECLARATION_CONTRACT` | constant: const RELEASE_TAIL_DECLARATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_DECLARATION_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-plane.js:5` |\n| `RELEASE_TAIL_EFFECT_SCHEMA` | constant: const RELEASE_TAIL_EFFECT_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_EFFECT_SCHEMA } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-plane.js:10` |\n| `RELEASE_TAIL_LEGACY_HOOKS` | constant: const RELEASE_TAIL_LEGACY_HOOKS | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_LEGACY_HOOKS } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-compatibility.js:4` |\n| `RELEASE_TAIL_OBSERVATION_SCHEMA` | constant: const RELEASE_TAIL_OBSERVATION_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_OBSERVATION_SCHEMA } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-plane.js:12` |\n| `RELEASE_TAIL_RECEIPT_SCHEMA` | constant: const RELEASE_TAIL_RECEIPT_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_RECEIPT_SCHEMA } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-plane.js:14` |\n| `RELEASE_TAIL_STATES` | constant: const RELEASE_TAIL_STATES | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_STATES } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-plane.js:17` |\n| `RELEASE_TAIL_TRANSACTION_POLICY` | constant: const RELEASE_TAIL_TRANSACTION_POLICY | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_TRANSACTION_POLICY } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-plane.js:7` |\n| `RELEASE_TAIL_TRANSACTION_SCHEMA` | constant: const RELEASE_TAIL_TRANSACTION_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_TRANSACTION_SCHEMA } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-plane.js:8` |\n| `releaseActivationRoot` | function: function releaseActivationRoot(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { releaseActivationRoot } from \"@kungfu-tech/buildchain\";` | `packages/core/release-activation-transaction.js:38` |\n| `ReleaseCandidateRecoveryError` | class: class ReleaseCandidateRecoveryError | none | ReleaseCandidateRecoveryError | Construction and method errors follow the linked source implementation. | class-dependent | `import { ReleaseCandidateRecoveryError } from \"@kungfu-tech/buildchain\";` | `packages/core/release-candidate-recovery.js:56` |\n| `ReleaseTailProviderError` | class: class ReleaseTailProviderError | none | ReleaseTailProviderError | Construction and method errors follow the linked source implementation. | class-dependent | `import { ReleaseTailProviderError } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-adapters.js:9` |\n| `releaseTailRetryPolicyFromDeclaration` | function: function releaseTailRetryPolicyFromDeclaration(input) | input | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { releaseTailRetryPolicyFromDeclaration } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-plane.js:1207` |\n| `releaseTailRoot` | function: function releaseTailRoot(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { releaseTailRoot } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-plane.js:164` |\n| `releaseTailStableJson` | function: function releaseTailStableJson(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { releaseTailStableJson } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-plane.js:149` |\n| `renderBadgeBundleBlock` | function: function renderBadgeBundleBlock(facts) | facts | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { renderBadgeBundleBlock } from \"@kungfu-tech/buildchain\";` | `packages/core/readme-badges.js:840` |\n| `renderBuildchainContractDriftIssueBody` | function: function renderBuildchainContractDriftIssueBody({ repository = \"\", workflow = \"\", runUrl = \"\", lockPath = \"\", evaluation, } = {}) | { repository = \"\", workflow = \"\", runUrl = \"\", lockPath = \"\", evaluation, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { renderBuildchainContractDriftIssueBody } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-contract.js:1043` |\n| `renderHomebrewFormula` | function: function renderHomebrewFormula(facts) | facts | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { renderHomebrewFormula } from \"@kungfu-tech/buildchain\";` | `packages/core/homebrew.js:290` |\n| `renderKfd2ProductClaimOutputs` | function: function renderKfd2ProductClaimOutputs({ cwd = process.cwd(), registryPath = BUILDCHAIN_KFD2_REGISTRY_PATH, outputDir = BUILDCHAIN_KFD2_DIR, version = \"\", channel = \"\", tag = \"\", sourceSha = \"\", } = {}) | { cwd = process.cwd(), registryPath = BUILDCHAIN_KFD2_REGISTRY_PATH, outputDir = BUILDCHAIN_KFD2_DIR, version = \"\", channel = \"\", tag = \"\", sourceSha = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { renderKfd2ProductClaimOutputs } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd2-product-claims.js:321` |\n| `renderReadmeBadgeBlock` | function: function renderReadmeBadgeBlock(facts) | facts | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { renderReadmeBadgeBlock } from \"@kungfu-tech/buildchain\";` | `packages/core/readme-badges.js:836` |\n| `repairReleasePropagationWork` | function: function repairReleasePropagationWork({ work, expectedWorkRoot, receipt } = {}) | { work, expectedWorkRoot, receipt } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { repairReleasePropagationWork } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-work-transitions.js:88` |\n| `reportBuildchainIssue` | function: async function reportBuildchainIssue(options = {}) | options = {} | Promise<unknown> | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { reportBuildchainIssue } from \"@kungfu-tech/buildchain\";` | `packages/core/issue-reporting.js:292` |\n| `reportWorkflowFrictionIssue` | function: async function reportWorkflowFrictionIssue(options = {}) | options = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { reportWorkflowFrictionIssue } from \"@kungfu-tech/buildchain\";` | `packages/core/issue-reporting.js:378` |\n| `resolveArtifactSigningProfile` | function: function resolveArtifactSigningProfile({ profile = \"auto\", platform = \"\", artifactKind = \"binary\", } = {}) | { profile = \"auto\", platform = \"\", artifactKind = \"binary\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolveArtifactSigningProfile } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-signing.js:111` |\n| `resolveArtifactSubject` | function: async function resolveArtifactSubject(subject, { cwd = process.cwd(), subjectDigest = \"\", subjectKind = \"\", npmRegistryBaseUrl = \"\", } = {}) | subject, { cwd = process.cwd(), subjectDigest = \"\", subjectKind = \"\", npmRegistryBaseUrl = \"\", } = {} | Promise<unknown> | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolveArtifactSubject } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-passport.js:368` |\n| `resolveBuildchainConfigPath` | function: function resolveBuildchainConfigPath(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolveBuildchainConfigPath } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:67` |\n| `resolveBuildchainContractLockPath` | function: function resolveBuildchainContractLockPath(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolveBuildchainContractLockPath } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:74` |\n| `resolveGithubGovernanceTargetPolicy` | function: function resolveGithubGovernanceTargetPolicy({ descriptor = BUILDCHAIN_GITHUB_GOVERNANCE_AUTHORITY, repository, targetRef, } = {}) | { descriptor = BUILDCHAIN_GITHUB_GOVERNANCE_AUTHORITY, repository, targetRef, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolveGithubGovernanceTargetPolicy } from \"@kungfu-tech/buildchain\";` | `packages/core/github-governance-authority.js:609` |\n| `resolveKfd1Metadata` | function: function resolveKfd1Metadata() | none | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolveKfd1Metadata } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-gate.js:89` |\n| `resolveKfd2ProductClaimsRegistryPath` | function: function resolveKfd2ProductClaimsRegistryPath(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolveKfd2ProductClaimsRegistryPath } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:81` |\n| `resolveKfd3Metadata` | function: function resolveKfd3Metadata({ requireSchemas = false } = {}) | { requireSchemas = false } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolveKfd3Metadata } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-gate.js:128` |\n| `resolveKfd3SurfaceRegistryPath` | function: function resolveKfd3SurfaceRegistryPath(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolveKfd3SurfaceRegistryPath } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:85` |\n| `resolveNpmRegistryRelease` | function: function resolveNpmRegistryRelease({ source: sourceInput, channel, packageMetadata, attestations, }) | { source: sourceInput, channel, packageMetadata, attestations, } | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolveNpmRegistryRelease } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-pickup.js:167` |\n| `resolvePaperRepository` | function: function resolvePaperRepository(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolvePaperRepository } from \"@kungfu-tech/buildchain\";` | `packages/core/paper-repository.js:133` |\n| `resolvePropagationChannel` | function: function resolvePropagationChannel(edge, upstreamChannel) | edge, upstreamChannel | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolvePropagationChannel } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation.js:190` |\n| `resolvePublicationCandidateFile` | function: function resolvePublicationCandidateFile(files = [], candidatePath) | files = [], candidatePath | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolvePublicationCandidateFile } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-artifact-candidate.js:23` |\n| `resolveReleasePassportPath` | function: function resolveReleasePassportPath(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolveReleasePassportPath } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-layout.js:92` |\n| `resumeReleasePropagationWork` | function: function resumeReleasePropagationWork(work) | work | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resumeReleasePropagationWork } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-work.js:518` |\n| `revalidateHousekeeperBranchAction` | function: function revalidateHousekeeperBranchAction(action, current, policy = {}) | action, current, policy = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { revalidateHousekeeperBranchAction } from \"@kungfu-tech/buildchain\";` | `packages/core/engineering-housekeeper.js:223` |\n| `revokeStableCandidate` | function: function revokeStableCandidate(ledgerInput, versionInput, { reason, actor = \"\", now = new Date().toISOString() } = {}) | ledgerInput, versionInput, { reason, actor = \"\", now = new Date().toISOString() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { revokeStableCandidate } from \"@kungfu-tech/buildchain\";` | `packages/core/stable-candidate-ledger.js:185` |\n| `rollbackReleaseActivationTransaction` | function: function rollbackReleaseActivationTransaction(transaction, { toSiteSourceSha, reason } = {}) | transaction, { toSiteSourceSha, reason } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { rollbackReleaseActivationTransaction } from \"@kungfu-tech/buildchain\";` | `packages/core/release-activation-transaction.js:290` |\n| `runGitHubHousekeeper` | function: async function runGitHubHousekeeper(options) | options | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { runGitHubHousekeeper } from \"@kungfu-tech/buildchain\";` | `packages/core/engineering-housekeeper-github.js:691` |\n| `runLifecycleStage` | function: function runLifecycleStage({ cwd = process.cwd(), loadedConfig, name, stage, env: extraEnv, timeoutMinutes }) | { cwd = process.cwd(), loadedConfig, name, stage, env: extraEnv, timeoutMinutes } | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { runLifecycleStage } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-config.js:1375` |\n| `RUNNER_PROVENANCE_CLASSES` | constant: const RUNNER_PROVENANCE_CLASSES | none | value | Import does not declare a throw contract. | none-on-import | `import { RUNNER_PROVENANCE_CLASSES } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:36` |\n| `RUNNER_PROVENANCE_CONTRACT` | constant: const RUNNER_PROVENANCE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RUNNER_PROVENANCE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:14` |\n| `schemas` | constant: const schemas | none | value | Import does not declare a throw contract. | none-on-import | `import { schemas } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd.js:495` |\n| `sealArtifactVerificationReport` | function: function sealArtifactVerificationReport({ report, bindings, kfdAssessment, issuedAt, expiresAt, revocation, } = {}) | { report, bindings, kfdAssessment, issuedAt, expiresAt, revocation, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { sealArtifactVerificationReport } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-verification-envelope.js:323` |\n| `selectStableCandidate` | function: function selectStableCandidate(ledgerInput, { releaseNow = \"\", now = new Date().toISOString() } = {}) | ledgerInput, { releaseNow = \"\", now = new Date().toISOString() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { selectStableCandidate } from \"@kungfu-tech/buildchain\";` | `packages/core/stable-candidate-ledger.js:206` |\n| `setStableCandidateHold` | function: function setStableCandidateHold(ledgerInput, enabled, { reason = \"\", now = new Date().toISOString() } = {}) | ledgerInput, enabled, { reason = \"\", now = new Date().toISOString() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { setStableCandidateHold } from \"@kungfu-tech/buildchain\";` | `packages/core/stable-candidate-ledger.js:198` |\n| `sha256BuildchainContractJson` | function: function sha256Json(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { sha256BuildchainContractJson } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-contract.js:43` |\n| `sha256File` | function: function sha256File(filePath) | filePath | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write, subprocess | `import { sha256File } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport.js:224` |\n| `sha256Json` | function: function sha256Json(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { sha256Json } from \"@kungfu-tech/buildchain\";` | `packages/core/release-candidate.js:90` |\n| `sha256KfdJson` | function: function sha256Json(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { sha256KfdJson } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-gate.js:50` |\n| `sha256Text` | function: function sha256Text(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { sha256Text } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport.js:146` |\n| `sha512IntegrityBuffer` | function: function sha512IntegrityBuffer(buffer) | buffer | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { sha512IntegrityBuffer } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-passport.js:34` |\n| `sha512IntegrityFile` | function: function sha512IntegrityFile(filePath) | filePath | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { sha512IntegrityFile } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-passport.js:38` |\n| `shellJoin` | function: function shellJoin(command) | command | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { shellJoin } from \"@kungfu-tech/buildchain\";` | `packages/core/package-manager.js:114` |\n| `signDetachedArtifactRequest` | function: function signDetachedArtifactRequest({ request, privateKey, keyId, authority = {}, } = {}) | { request, privateKey, keyId, authority = {}, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { signDetachedArtifactRequest } from \"@kungfu-tech/buildchain\";` | `packages/core/detached-artifact-signature.js:36` |\n| `SITE_UPSTREAM_AGENT_ENTRY_CONTRACT` | constant: const SITE_UPSTREAM_AGENT_ENTRY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { SITE_UPSTREAM_AGENT_ENTRY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-agent-entry.js:9` |\n| `STABLE_CANDIDATE_LEDGER_CONTRACT` | constant: const STABLE_CANDIDATE_LEDGER_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { STABLE_CANDIDATE_LEDGER_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/stable-candidate-ledger.js:1` |\n| `STABLE_CANDIDATE_STATES` | constant: const STABLE_CANDIDATE_STATES | none | value | Import does not declare a throw contract. | none-on-import | `import { STABLE_CANDIDATE_STATES } from \"@kungfu-tech/buildchain\";` | `packages/core/stable-candidate-ledger.js:2` |\n| `stableCandidatePromotionRefs` | function: function stableCandidatePromotionRefs(candidateInput, targetBranch) | candidateInput, targetBranch | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { stableCandidatePromotionRefs } from \"@kungfu-tech/buildchain\";` | `packages/core/stable-candidate-ledger.js:264` |\n| `startProcessSampler` | function: function startProcessSampler({ rootPid = process.pid, intervalMs = 15000, label = \"\", command = \"\", args = [], env = process.env, requestedParallelism = 0, onSample = () => undefined, cwd = process.cwd(), } = {}) | { rootPid = process.pid, intervalMs = 15000, label = \"\", command = \"\", args = [], env = process.env, requestedParallelism = 0, onSample = () => undefined, cwd = process.cwd(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { startProcessSampler } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:1362` |\n| `summarizeBuildchainLogEvents` | function: function summarizeBuildchainLogEvents(input = {}) | input = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { summarizeBuildchainLogEvents } from \"@kungfu-tech/buildchain\";` | `packages/core/logging.js:192` |\n| `summarizeDiagnosticsArtifacts` | function: function summarizeDiagnosticsArtifacts(inputs = []) | inputs = [] | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { summarizeDiagnosticsArtifacts } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:1824` |\n| `summarizeLifecycleObservability` | function: function summarizeLifecycleObservability({ events = [], logPath = \"\", artifactScanDurationMs = 0, artifactUploadDurationMs = 0, totalBytes = 0, fileCount = 0, } = {}) | { events = [], logPath = \"\", artifactScanDurationMs = 0, artifactUploadDurationMs = 0, totalBytes = 0, fileCount = 0, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { summarizeLifecycleObservability } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:219` |\n| `summarizeProcessSamples` | function: function summarizeProcessSamples({ samples = [], requestedParallelism = 0, command = \"\", args = [], env = process.env, activeCpuThreshold = 0.1, } = {}) | { samples = [], requestedParallelism = 0, command = \"\", args = [], env = process.env, activeCpuThreshold = 0.1, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { summarizeProcessSamples } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:1254` |\n| `SURFACE_TIMESTAMP_POLICY_CONTRACT` | constant: const SURFACE_TIMESTAMP_POLICY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { SURFACE_TIMESTAMP_POLICY_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/surface-manifest.js:1` |\n| `testKfdAgentHub` | function: function testKfdAgentHub({ cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, outputDir = KFD_AGENT_HUB_OUTPUT_DIR, kfdRoot = \"\", run = defaultRun } = {}) | { cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, outputDir = KFD_AGENT_HUB_OUTPUT_DIR, kfdRoot = \"\", run = defaultRun } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { testKfdAgentHub } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-agent-hub.js:399` |\n| `transitionReleaseTransaction` | function: function transitionReleaseTransaction(record, nextState, metadata = {}) | record, nextState, metadata = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { transitionReleaseTransaction } from \"@kungfu-tech/buildchain\";` | `packages/core/publish-transaction.js:256` |\n| `truncateUtf8` | function: function truncateUtf8(text, maxBytes = DEFAULT_MAX_BODY_BYTES) | text, maxBytes = DEFAULT_MAX_BODY_BYTES | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { truncateUtf8 } from \"@kungfu-tech/buildchain\";` | `packages/core/issue-reporting.js:84` |\n| `updateBadgeBundleBlock` | function: function updateBadgeBundleBlock({ readmeText, facts } = {}) | { readmeText, facts } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { updateBadgeBundleBlock } from \"@kungfu-tech/buildchain\";` | `packages/core/readme-badges.js:887` |\n| `updateConfiguredVersionStateContents` | function: function updateConfiguredVersionStateContents(files, version) | files, version | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { updateConfiguredVersionStateContents } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-config.js:1675` |\n| `updateHomebrewTap` | function: async function updateHomebrewTap({ cwd = process.cwd(), packageName = \"buildchain\", releasePassport = \"\", manifestPath = DEFAULT_MANIFEST_PATH, formulaPath = \"\", write = true, } = {}) | { cwd = process.cwd(), packageName = \"buildchain\", releasePassport = \"\", manifestPath = DEFAULT_MANIFEST_PATH, formulaPath = \"\", write = true, } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { updateHomebrewTap } from \"@kungfu-tech/buildchain\";` | `packages/core/homebrew.js:390` |\n| `updateReadmeBadgeBlock` | function: function updateReadmeBadgeBlock({ readmeText, facts } = {}) | { readmeText, facts } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { updateReadmeBadgeBlock } from \"@kungfu-tech/buildchain\";` | `packages/core/readme-badges.js:874` |\n| `validateAnchoredPackageRelease` | function: function validateAnchoredPackageRelease({ cwd = process.cwd(), requireManifest = true, requirePackageSetOrder = \"platforms-first-main-last\", requireTrustedPublishing = true, requireLifecycleStages = [\"install\", \"build\", \"verify\", \"publish\"], requirePublishGateSourceLock = false, publishSource = undefined, env = process.env, } = {}) | { cwd = process.cwd(), requireManifest = true, requirePackageSetOrder = \"platforms-first-main-last\", requireTrustedPublishing = true, requireLifecycleStages = [\"install\", \"build\", \"verify\", \"publish\"], requirePublishGateSourceLock = false, publishSource = undefined, env = process.env, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateAnchoredPackageRelease } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:325` |\n| `validateArtifactSigningReceipt` | function: function validateArtifactSigningReceipt(receipt, { request } = {}) | receipt, { request } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { validateArtifactSigningReceipt } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-signing.js:374` |\n| `validateArtifactSigningRequest` | function: function validateArtifactSigningRequest(request) | request | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { validateArtifactSigningRequest } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-signing.js:291` |\n| `validateArtifactSigningResult` | function: function validateArtifactSigningResult(result, { request, receipt } = {}) | result, { request, receipt } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { validateArtifactSigningResult } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-signing-result.js:147` |\n| `validateBuildchainConfig` | function: function validateBuildchainConfig(cwd = process.cwd(), { requireConfig = true, requireVersionState = false, requireLifecycleStages = [], } = {}) | cwd = process.cwd(), { requireConfig = true, requireVersionState = false, requireLifecycleStages = [], } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { validateBuildchainConfig } from \"@kungfu-tech/buildchain\";` | `packages/core/buildchain-config.js:1542` |\n| `validateControllerPlan` | function: function validateControllerPlan(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateControllerPlan } from \"@kungfu-tech/buildchain\";` | `packages/core/controller-evidence.js:325` |\n| `validateControllerReceipt` | function: function validateControllerReceipt(receipt, { plan = undefined, expectedSourceSha = \"\", expectedRuntimeSha = \"\", expectedPlanDigest = \"\", } = {}) | receipt, { plan = undefined, expectedSourceSha = \"\", expectedRuntimeSha = \"\", expectedPlanDigest = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateControllerReceipt } from \"@kungfu-tech/buildchain\";` | `packages/core/controller-evidence.js:423` |\n| `validateControllerReceiptReference` | function: function validateControllerReceiptReference(reference, { expectedSourceSha = \"\", acceptedSourceShas = [], expectedRuntimeSha = \"\", requirePassed = false, } = {}) | reference, { expectedSourceSha = \"\", acceptedSourceShas = [], expectedRuntimeSha = \"\", requirePassed = false, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateControllerReceiptReference } from \"@kungfu-tech/buildchain\";` | `packages/core/controller-evidence.js:505` |\n| `validateKfd1ReleaseGateEvidence` | function: function validateKfd1ReleaseGateEvidence(section, { metadata = resolveKfd1Metadata() } = {}) | section, { metadata = resolveKfd1Metadata() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateKfd1ReleaseGateEvidence } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-gate.js:1337` |\n| `validateKfd2ProductClaimsRegistry` | function: function validateKfd2ProductClaimsRegistry(registry = {}) | registry = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { validateKfd2ProductClaimsRegistry } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd2-product-claims.js:152` |\n| `validateKfd3CollaborationInterfaceReleaseGateEvidence` | function: function validateKfd3CollaborationInterfaceReleaseGateEvidence(section, { metadata = resolveKfd3Metadata() } = {}) | section, { metadata = resolveKfd3Metadata() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateKfd3CollaborationInterfaceReleaseGateEvidence } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-gate.js:1470` |\n| `validateKfdAdopterReleaseBinding` | function: function validateKfdAdopterReleaseBinding(binding, { manifest, manifestGate, legacyProjection, expectedSourceSha = \"\", } = {}) | binding, { manifest, manifestGate, legacyProjection, expectedSourceSha = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateKfdAdopterReleaseBinding } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-verification-envelope.js:467` |\n| `validateKfdProductGateResult` | function: function validateKfdProductGateResult(result, { expectedSourceSha = \"\", checkedAt = new Date().toISOString(), } = {}) | result, { expectedSourceSha = \"\", checkedAt = new Date().toISOString(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateKfdProductGateResult } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-product-gates.js:519` |\n| `validateKnownReleasePassportContracts` | function: function validateKnownReleasePassportContracts() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateKnownReleasePassportContracts } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport.js:2750` |\n| `validatePackageManagerContract` | function: function validatePackageManagerContract({ cwd = process.cwd(), expectedManager = \"\" } = {}) | { cwd = process.cwd(), expectedManager = \"\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { validatePackageManagerContract } from \"@kungfu-tech/buildchain\";` | `packages/core/package-manager.js:18` |\n| `validatePublishEvidence` | function: function validatePublishEvidence({ evidence, version, channel, sourceSha, releaseSha, targetRef = \"\", releaseMaterialSha = releaseSha, publishToolingSha = \"\", requiredArtifacts = [], } = {}) | { evidence, version, channel, sourceSha, releaseSha, targetRef = \"\", releaseMaterialSha = releaseSha, publishToolingSha = \"\", requiredArtifacts = [], } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validatePublishEvidence } from \"@kungfu-tech/buildchain\";` | `packages/core/publish-transaction.js:674` |\n| `validateReleaseActivationReceiptSet` | function: function validateReleaseActivationReceiptSet(receiptSet, { allowShadow = true } = {}) | receiptSet, { allowShadow = true } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateReleaseActivationReceiptSet } from \"@kungfu-tech/buildchain\";` | `packages/core/release-activation-transaction.js:376` |\n| `validateReleaseActivationTransaction` | function: function validateReleaseActivationTransaction(transaction) | transaction | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateReleaseActivationTransaction } from \"@kungfu-tech/buildchain\";` | `packages/core/release-activation-transaction.js:146` |\n| `validateReleaseCandidatePassport` | function: function validateReleaseCandidatePassport({ passport, repository = \"\", targetChannel = \"\", version = \"\", sourceHeadSha = \"\", buildSummary = undefined, requirePlatforms = true, requireFamilyEvidence = false, familyEvidenceRoot = \"\", familyInitiativeId = \"\", familyAssignmentId = \"\", } = {}) | { passport, repository = \"\", targetChannel = \"\", version = \"\", sourceHeadSha = \"\", buildSummary = undefined, requirePlatforms = true, requireFamilyEvidence = false, familyEvidenceRoot = \"\", familyInitiativeId = \"\", familyAssignmentId = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateReleaseCandidatePassport } from \"@kungfu-tech/buildchain\";` | `packages/core/release-candidate.js:404` |\n| `validateReleasePassportSchema` | function: function validateReleasePassportSchema(passport) | passport | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateReleasePassportSchema } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport-contract.js:277` |\n| `validateReleaseTailEffectPlan` | function: function validateReleaseTailEffectPlan(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateReleaseTailEffectPlan } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-plane.js:602` |\n| `validateReleaseTailTransaction` | function: function validateReleaseTailTransaction(transaction) | transaction | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateReleaseTailTransaction } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-plane.js:744` |\n| `verifyArtifactPassport` | function: async function verifyArtifactPassport({ subject, cwd = process.cwd(), passportLocation = \"\", locatorConfig = \"\", repository = \"\", tag = \"\", githubReleaseBaseUrl = \"\", subjectDigest = \"\", subjectKind = \"\", npmRegistryBaseUrl = \"\", verificationEnvelope = undefined, } = {}) | { subject, cwd = process.cwd(), passportLocation = \"\", locatorConfig = \"\", repository = \"\", tag = \"\", githubReleaseBaseUrl = \"\", subjectDigest = \"\", subjectKind = \"\", npmRegistryBaseUrl = \"\", verificationEnvelope = undefined, } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyArtifactPassport } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-passport.js:701` |\n| `verifyArtifactSigningResultFiles` | function: function verifyArtifactSigningResultFiles({ root, request, receipt, result, } = {}) | { root, request, receipt, result, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyArtifactSigningResultFiles } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-signing-result.js:193` |\n| `verifyArtifactVerificationEnvelope` | function: function verifyArtifactVerificationEnvelope({ envelope, assessmentTime = Math.floor(Date.now() / 1000), expectedEnvelopeRoot = \"\", expectedIssuer = \"\", expectedPublisher = \"\", expectedContractVersion = \"\", } = {}) | { envelope, assessmentTime = Math.floor(Date.now() / 1000), expectedEnvelopeRoot = \"\", expectedIssuer = \"\", expectedPublisher = \"\", expectedContractVersion = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyArtifactVerificationEnvelope } from \"@kungfu-tech/buildchain\";` | `packages/core/artifact-verification-envelope.js:153` |\n| `verifyBuildchainLogEvents` | function: function verifyBuildchainLogEvents({ path: filePath = \"\", events: inputEvents = undefined, minEvents = 1, allowErrors = false, requirePhases = [], requireComponents = [], requireEvents = [], } = {}) | { path: filePath = \"\", events: inputEvents = undefined, minEvents = 1, allowErrors = false, requirePhases = [], requireComponents = [], requireEvents = [], } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyBuildchainLogEvents } from \"@kungfu-tech/buildchain\";` | `packages/core/logging.js:230` |\n| `verifyBuildFacts` | function: function verifyBuildFacts({ cwd = process.cwd(), fact, factPath = \"\" } = {}) | { cwd = process.cwd(), fact, factPath = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyBuildFacts } from \"@kungfu-tech/buildchain\";` | `packages/core/build-facts.js:431` |\n| `verifyCacheEvidenceSet` | function: function verifyCacheEvidenceSet(receipt) | receipt | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyCacheEvidenceSet } from \"@kungfu-tech/buildchain\";` | `packages/core/cache-evidence.js:273` |\n| `verifyCacheOperationReceipt` | function: function verifyCacheOperationReceipt(receipt) | receipt | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyCacheOperationReceipt } from \"@kungfu-tech/buildchain\";` | `packages/core/cache-evidence.js:226` |\n| `verifyDetachedArtifactSignature` | function: function verifyDetachedArtifactSignature({ request, envelope, publicKey, } = {}) | { request, envelope, publicKey, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyDetachedArtifactSignature } from \"@kungfu-tech/buildchain\";` | `packages/core/detached-artifact-signature.js:82` |\n| `verifyGitHubArtifactAttestationEvidence` | function: function verifyGitHubArtifactAttestationEvidence({ artifactPath, platformManifestPath, releasePassportPath, bundlePath, evidence, verificationResults, } = {}) | { artifactPath, platformManifestPath, releasePassportPath, bundlePath, evidence, verificationResults, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { verifyGitHubArtifactAttestationEvidence } from \"@kungfu-tech/buildchain\";` | `packages/core/github-artifact-attestation.js:563` |\n| `verifyGithubGovernanceReceipt` | function: function verifyGithubGovernanceReceipt(receipt, { expectedOrganization, expectedRepository, expectedRepositoryIdentityRoot, expectedTargetRef, expectedPolicyRoot, expectedVerifierSourceRevision, now = new Date().toISOString(), } = {}) | receipt, { expectedOrganization, expectedRepository, expectedRepositoryIdentityRoot, expectedTargetRef, expectedPolicyRoot, expectedVerifierSourceRevision, now = new Date().toISOString(), } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { verifyGithubGovernanceReceipt } from \"@kungfu-tech/buildchain\";` | `packages/core/github-governance-authority.js:886` |\n| `verifyKfdRecord` | function: async function verifyKfdRecord(record) | record | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyKfdRecord } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd-product-gates.js:262` |\n| `verifyPortableDevCachePlan` | function: function verifyPortableDevCachePlan(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyPortableDevCachePlan } from \"@kungfu-tech/buildchain\";` | `packages/core/portable-dev-cache.js:211` |\n| `verifyPublicationAdmission` | function: function verifyPublicationAdmission({ admission, registry, runnerProvenance, controlPlaneAudit, publicationEvidence, expected = {}, usedNonces = [], now = new Date(), } = {}) | { admission, registry, runnerProvenance, controlPlaneAudit, publicationEvidence, expected = {}, usedNonces = [], now = new Date(), } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { verifyPublicationAdmission } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:791` |\n| `verifyPublicationQualificationReceipt` | function: function verifyPublicationQualificationReceipt({ receipt, capability, gateAggregate, expected = {}, usedNonces = [], now = new Date(), } = {}) | { receipt, capability, gateAggregate, expected = {}, usedNonces = [], now = new Date(), } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { verifyPublicationQualificationReceipt } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-authority.js:1096` |\n| `verifyPublicationReproducibility` | function: function verifyPublicationReproducibility({ cwd = process.cwd(), sourceSha = \"\", output = DEFAULT_OUTPUT, promote = false, keepWorkspaces = false, pullToolchain = true, packageName = \"\", allowUnpinnedToolchain = false, overlayPaths = [DEFAULT_REGISTRY_INPUT_DIR, DEFAULT_REGISTRY_HYDRATION], } = {}) | { cwd = process.cwd(), sourceSha = \"\", output = DEFAULT_OUTPUT, promote = false, keepWorkspaces = false, pullToolchain = true, packageName = \"\", allowUnpinnedToolchain = false, overlayPaths = [DEFAULT_REGISTRY_INPUT_DIR, DEFAULT_REGISTRY_HYDRATION], } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { verifyPublicationReproducibility } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-reproducibility.js:869` |\n| `verifyPublicationSealedBundle` | function: function verifyPublicationSealedBundle({ bundleRoot, manifest } = {}) | { bundleRoot, manifest } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { verifyPublicationSealedBundle } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-sealed-bundle.js:133` |\n| `verifyReleaseCandidateRecovery` | function: function verifyReleaseCandidateRecovery({ candidateRepository, targetRepository, expectedRunId, expectedWorkflowFile, expectedWorkflowName, channel, targetRef, targetSha, targetRefSha = targetSha, targetTree, expectedSourceTree = \"\", expectedCandidateRoot = \"\", expectedRuntimeSha, expectedTransactionId = \"\", existingTransaction = undefined, run, workflow, pullRequest, ancestry, passport, buildSummary, controllerReceipts = [], platformManifests = [], platformManifestEvidence = [], productPayloadManifests = [], artifacts = [], publicationVersion = \"\", currentToolingSha, recoveryRunId = \"\", createdAt = new Date().toISOString(), } = {}) | { candidateRepository, targetRepository, expectedRunId, expectedWorkflowFile, expectedWorkflowName, channel, targetRef, targetSha, targetRefSha = targetSha, targetTree, expectedSourceTree = \"\", expectedCandidateRoot = \"\", expectedRuntimeSha, expectedTransactionId = \"\", existingTransaction = undefined, run, workflow, pullRequest, ancestry, passport, buildSummary, controllerReceipts = [], platformManifests = [], platformManifestEvidence = [], productPayloadManifests = [], artifacts = [], publicationVersion = \"\", currentToolingSha, recoveryRunId = \"\", createdAt = new Date().toISOString(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyReleaseCandidateRecovery } from \"@kungfu-tech/buildchain\";` | `packages/core/release-candidate-recovery.js:398` |\n| `verifyReleasePassport` | function: async function verifyReleasePassport({ passportLocation, artifactEvidenceLocation = \"\", publishEvidenceLocation = \"\", impactLocation = \"\", agentIndexLocation = \"\", productMechanismLocation = \"\", kfdAgentHubEvidenceLocation = \"\", kfdAdopterManifestLocation = \"\", kfdAdopterManifestGateLocation = \"\", kfdSupportEvidenceLocation = \"\", checkedAt = nowIso(), } = {}) | { passportLocation, artifactEvidenceLocation = \"\", publishEvidenceLocation = \"\", impactLocation = \"\", agentIndexLocation = \"\", productMechanismLocation = \"\", kfdAgentHubEvidenceLocation = \"\", kfdAdopterManifestLocation = \"\", kfdAdopterManifestGateLocation = \"\", kfdSupportEvidenceLocation = \"\", checkedAt = nowIso(), } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyReleasePassport } from \"@kungfu-tech/buildchain\";` | `packages/core/release-passport.js:2674` |\n| `verifyReleasePropagationWork` | function: function verifyReleasePropagationWork(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { verifyReleasePropagationWork } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation-work.js:486` |\n| `WEB_SURFACE_PRODUCTION_DECISION_CONTRACT` | constant: const WEB_SURFACE_PRODUCTION_DECISION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { WEB_SURFACE_PRODUCTION_DECISION_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/web-surface-publication-candidate.js:7` |\n| `WEB_SURFACE_PUBLICATION_CANDIDATE_CONTRACT` | constant: const WEB_SURFACE_PUBLICATION_CANDIDATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { WEB_SURFACE_PUBLICATION_CANDIDATE_CONTRACT } from \"@kungfu-tech/buildchain\";` | `packages/core/web-surface-publication-candidate.js:5` |\n| `webSurfacePublicationDigest` | function: function webSurfacePublicationDigest(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { webSurfacePublicationDigest } from \"@kungfu-tech/buildchain\";` | `packages/core/web-surface-publication-candidate.js:21` |\n| `workflowFrictionMarker` | function: function workflowFrictionMarker(fingerprint) | fingerprint | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { workflowFrictionMarker } from \"@kungfu-tech/buildchain\";` | `packages/core/issue-reporting.js:80` |\n| `writeBuildFacts` | function: function writeBuildFacts({ cwd = process.cwd(), fact, output = \"\" } = {}) | { cwd = process.cwd(), fact, output = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { writeBuildFacts } from \"@kungfu-tech/buildchain\";` | `packages/core/build-facts.js:557` |\n| `writeDiagnosticsArtifact` | function: function writeDiagnosticsArtifact(filePath, diagnostics) | filePath, diagnostics | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write | `import { writeDiagnosticsArtifact } from \"@kungfu-tech/buildchain\";` | `packages/core/diagnostics.js:1459` |\n| `writeKfd2ProductClaimOutputs` | function: function writeKfd2ProductClaimOutputs(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write | `import { writeKfd2ProductClaimOutputs } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd2-product-claims.js:426` |\n| `writeKfd3SurfaceRegistry` | function: function writeKfd3SurfaceRegistry({ cwd = process.cwd(), registryPath = \"\", registry }) | { cwd = process.cwd(), registryPath = \"\", registry } | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { writeKfd3SurfaceRegistry } from \"@kungfu-tech/buildchain\";` | `packages/core/kfd3-surface-register.js:478` |\n| `writeKungfuBuildInfoProjection` | function: function writeKungfuBuildInfoProjection({ cwd = process.cwd(), moduleFact, output } = {}) | { cwd = process.cwd(), moduleFact, output } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { writeKungfuBuildInfoProjection } from \"@kungfu-tech/buildchain\";` | `packages/core/build-facts.js:565` |\n| `writePaperFleetUpdate` | function: function writePaperFleetUpdate(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { writePaperFleetUpdate } from \"@kungfu-tech/buildchain\";` | `packages/core/paper-fleet.js:271` |\n| `writePaperMigration` | function: function writePaperMigration(plan) | plan | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { writePaperMigration } from \"@kungfu-tech/buildchain\";` | `packages/core/paper.js:1130` |\n| `writePaperScaffold` | function: function writePaperScaffold(plan) | plan | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { writePaperScaffold } from \"@kungfu-tech/buildchain\";` | `packages/core/paper.js:847` |\n| `writePublicationArtifact` | function: function writePublicationArtifact({ cwd = process.cwd(), output = \"\", passportOutput = \"\", registryOutput = \"\", registryInputs = [], sourceSha = \"\", sourceBundle = true, sourceBundlePath = \"\", generatedAt = \"\", } = {}) | { cwd = process.cwd(), output = \"\", passportOutput = \"\", registryOutput = \"\", registryInputs = [], sourceSha = \"\", sourceBundle = true, sourceBundlePath = \"\", generatedAt = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write | `import { writePublicationArtifact } from \"@kungfu-tech/buildchain\";` | `packages/core/publication-artifact.js:598` |\n| `writeReleaseLineBootstrapVersionState` | function: function writeReleaseLineBootstrapVersionState({ cwd = process.cwd(), major, minor, sourceRef = \"\", initialVersion = \"\", runVersionStateLifecycle = true, generatedAt = \"\", } = {}) | { cwd = process.cwd(), major, minor, sourceRef = \"\", initialVersion = \"\", runVersionStateLifecycle = true, generatedAt = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { writeReleaseLineBootstrapVersionState } from \"@kungfu-tech/buildchain\";` | `packages/core/release-line-bootstrap.js:250` |\n| `writeReleasePropagationLock` | function: function writeReleasePropagationLock({ plan, target = \"\", cwd = process.cwd(), output = \"\" } = {}) | { plan, target = \"\", cwd = process.cwd(), output = \"\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { writeReleasePropagationLock } from \"@kungfu-tech/buildchain\";` | `packages/core/release-propagation.js:317` |\n| `writeReleaseTailTransaction` | function: function writeReleaseTailTransaction(filePath, transaction) | filePath, transaction | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { writeReleaseTailTransaction } from \"@kungfu-tech/buildchain\";` | `packages/core/release-tail-provider-plane.js:841` |\n| `writeReleaseTransaction` | function: function writeReleaseTransaction(filePath, record) | filePath, record | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write | `import { writeReleaseTransaction } from \"@kungfu-tech/buildchain\";` | `packages/core/publish-transaction.js:376` |\n\n## `@kungfu-tech/buildchain/badges`\n\nTarget: `./packages/core/badges.js`. Public symbols: 17.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `BADGE_BUNDLE_DEFAULT_CLAIMS` | constant: const BADGE_BUNDLE_DEFAULT_CLAIMS | none | value | Import does not declare a throw contract. | none-on-import | `import { BADGE_BUNDLE_DEFAULT_CLAIMS } from \"@kungfu-tech/buildchain/badges\";` | `packages/core/readme-badges.js:17` |\n| `BADGE_BUNDLE_FACTS_CONTRACT` | constant: const BADGE_BUNDLE_FACTS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BADGE_BUNDLE_FACTS_CONTRACT } from \"@kungfu-tech/buildchain/badges\";` | `packages/core/readme-badges.js:13` |\n| `checkBadgeBundleBlock` | function: function checkBadgeBundleBlock({ readmeText, facts } = {}) | { readmeText, facts } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { checkBadgeBundleBlock } from \"@kungfu-tech/buildchain/badges\";` | `packages/core/readme-badges.js:867` |\n| `checkReadmeBadgeBlock` | function: function checkReadmeBadgeBlock({ readmeText, facts } = {}) | { readmeText, facts } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { checkReadmeBadgeBlock } from \"@kungfu-tech/buildchain/badges\";` | `packages/core/readme-badges.js:848` |\n| `collectBadgeBundleFacts` | function: async function collectBadgeBundleFacts({ cwd = process.cwd(), claims = undefined } = {}) | { cwd = process.cwd(), claims = undefined } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectBadgeBundleFacts } from \"@kungfu-tech/buildchain/badges\";` | `packages/core/readme-badges.js:790` |\n| `collectReadmeBadgeFacts` | function: async function collectReadmeBadgeFacts({ cwd = process.cwd() } = {}) | { cwd = process.cwd() } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectReadmeBadgeFacts } from \"@kungfu-tech/buildchain/badges\";` | `packages/core/readme-badges.js:700` |\n| `createKfdBadgeSpecsFromStandards` | function: function createKfdBadgeSpecsFromStandards(standardsMetadata) | standardsMetadata | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createKfdBadgeSpecsFromStandards } from \"@kungfu-tech/buildchain/badges\";` | `packages/core/readme-badges.js:126` |\n| `createReadmeBadgeEndpointRegistry` | function: function createReadmeBadgeEndpointRegistry({ kfdSpecs = undefined, kfdStandards = undefined } = {}) | { kfdSpecs = undefined, kfdStandards = undefined } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | subprocess | `import { createReadmeBadgeEndpointRegistry } from \"@kungfu-tech/buildchain/badges\";` | `packages/core/readme-badges.js:133` |\n| `README_BADGE_BLOCK_END` | constant: const README_BADGE_BLOCK_END | none | value | Import does not declare a throw contract. | none-on-import | `import { README_BADGE_BLOCK_END } from \"@kungfu-tech/buildchain/badges\";` | `packages/core/readme-badges.js:15` |\n| `README_BADGE_BLOCK_START` | constant: const README_BADGE_BLOCK_START | none | value | Import does not declare a throw contract. | none-on-import | `import { README_BADGE_BLOCK_START } from \"@kungfu-tech/buildchain/badges\";` | `packages/core/readme-badges.js:14` |\n| `README_BADGE_FACTS_CONTRACT` | constant: const README_BADGE_FACTS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { README_BADGE_FACTS_CONTRACT } from \"@kungfu-tech/buildchain/badges\";` | `packages/core/readme-badges.js:12` |\n| `README_BADGE_HOSTED_BASE_URL` | constant: const README_BADGE_HOSTED_BASE_URL | none | value | Import does not declare a throw contract. | none-on-import | `import { README_BADGE_HOSTED_BASE_URL } from \"@kungfu-tech/buildchain/badges\";` | `packages/core/readme-badges.js:16` |\n| `readReadme` | function: function readReadme({ cwd = process.cwd(), readmePath = \"README.md\" } = {}) | { cwd = process.cwd(), readmePath = \"README.md\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { readReadme } from \"@kungfu-tech/buildchain/badges\";` | `packages/core/readme-badges.js:891` |\n| `renderBadgeBundleBlock` | function: function renderBadgeBundleBlock(facts) | facts | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { renderBadgeBundleBlock } from \"@kungfu-tech/buildchain/badges\";` | `packages/core/readme-badges.js:840` |\n| `renderReadmeBadgeBlock` | function: function renderReadmeBadgeBlock(facts) | facts | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { renderReadmeBadgeBlock } from \"@kungfu-tech/buildchain/badges\";` | `packages/core/readme-badges.js:836` |\n| `updateBadgeBundleBlock` | function: function updateBadgeBundleBlock({ readmeText, facts } = {}) | { readmeText, facts } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { updateBadgeBundleBlock } from \"@kungfu-tech/buildchain/badges\";` | `packages/core/readme-badges.js:887` |\n| `updateReadmeBadgeBlock` | function: function updateReadmeBadgeBlock({ readmeText, facts } = {}) | { readmeText, facts } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { updateReadmeBadgeBlock } from \"@kungfu-tech/buildchain/badges\";` | `packages/core/readme-badges.js:874` |\n\n## `@kungfu-tech/buildchain/build-facts`\n\nTarget: `./packages/core/build-facts.js`. Public symbols: 15.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `aggregateBuildFacts` | function: function aggregateBuildFacts({ cwd = process.cwd(), productId = \"\", moduleFacts = [], artifacts = [], now = nowIso(), } = {}) | { cwd = process.cwd(), productId = \"\", moduleFacts = [], artifacts = [], now = nowIso(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | subprocess | `import { aggregateBuildFacts } from \"@kungfu-tech/buildchain/build-facts\";` | `packages/core/build-facts.js:466` |\n| `BUILD_FACTS_GIT_CONTRACT` | constant: const BUILD_FACTS_GIT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILD_FACTS_GIT_CONTRACT } from \"@kungfu-tech/buildchain/build-facts\";` | `packages/core/build-facts.js:9` |\n| `BUILD_FACTS_LEGACY_KUNGFU_BUILDINFO_CONTRACT` | constant: const BUILD_FACTS_LEGACY_KUNGFU_BUILDINFO_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILD_FACTS_LEGACY_KUNGFU_BUILDINFO_CONTRACT } from \"@kungfu-tech/buildchain/build-facts\";` | `packages/core/build-facts.js:14` |\n| `BUILD_FACTS_MODULE_CONTRACT` | constant: const BUILD_FACTS_MODULE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILD_FACTS_MODULE_CONTRACT } from \"@kungfu-tech/buildchain/build-facts\";` | `packages/core/build-facts.js:11` |\n| `BUILD_FACTS_PRODUCT_CONTRACT` | constant: const BUILD_FACTS_PRODUCT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILD_FACTS_PRODUCT_CONTRACT } from \"@kungfu-tech/buildchain/build-facts\";` | `packages/core/build-facts.js:12` |\n| `BUILD_FACTS_VERIFY_CONTRACT` | constant: const BUILD_FACTS_VERIFY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILD_FACTS_VERIFY_CONTRACT } from \"@kungfu-tech/buildchain/build-facts\";` | `packages/core/build-facts.js:13` |\n| `BUILD_FACTS_VERSION_CONTRACT` | constant: const BUILD_FACTS_VERSION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILD_FACTS_VERSION_CONTRACT } from \"@kungfu-tech/buildchain/build-facts\";` | `packages/core/build-facts.js:10` |\n| `buildFactsDigest` | function: function buildFactsDigest(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write, subprocess | `import { buildFactsDigest } from \"@kungfu-tech/buildchain/build-facts\";` | `packages/core/build-facts.js:45` |\n| `collectGitSourceFacts` | function: function collectGitSourceFacts({ cwd = process.cwd(), root = \".\" } = {}) | { cwd = process.cwd(), root = \".\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectGitSourceFacts } from \"@kungfu-tech/buildchain/build-facts\";` | `packages/core/build-facts.js:154` |\n| `collectModuleBuildFacts` | function: function collectModuleBuildFacts({ cwd = process.cwd(), moduleId = \"\", moduleRoot = \"\", scope = \"\", versionSource = undefined, versionSourceId = \"\", outputs = [], lifecycle = \"\", platform = currentPlatform(), dependencies = [], now = nowIso(), } = {}) | { cwd = process.cwd(), moduleId = \"\", moduleRoot = \"\", scope = \"\", versionSource = undefined, versionSourceId = \"\", outputs = [], lifecycle = \"\", platform = currentPlatform(), dependencies = [], now = nowIso(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectModuleBuildFacts } from \"@kungfu-tech/buildchain/build-facts\";` | `packages/core/build-facts.js:310` |\n| `collectVersionSourceFact` | function: function collectVersionSourceFact({ cwd = process.cwd(), source = undefined, sourceId = \"\", now = nowIso() } = {}) | { cwd = process.cwd(), source = undefined, sourceId = \"\", now = nowIso() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | subprocess | `import { collectVersionSourceFact } from \"@kungfu-tech/buildchain/build-facts\";` | `packages/core/build-facts.js:181` |\n| `createKungfuBuildInfoProjection` | function: function createKungfuBuildInfoProjection({ moduleFact, cwd = process.cwd(), now = nowIso() } = {}) | { moduleFact, cwd = process.cwd(), now = nowIso() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createKungfuBuildInfoProjection } from \"@kungfu-tech/buildchain/build-facts\";` | `packages/core/build-facts.js:528` |\n| `verifyBuildFacts` | function: function verifyBuildFacts({ cwd = process.cwd(), fact, factPath = \"\" } = {}) | { cwd = process.cwd(), fact, factPath = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyBuildFacts } from \"@kungfu-tech/buildchain/build-facts\";` | `packages/core/build-facts.js:431` |\n| `writeBuildFacts` | function: function writeBuildFacts({ cwd = process.cwd(), fact, output = \"\" } = {}) | { cwd = process.cwd(), fact, output = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { writeBuildFacts } from \"@kungfu-tech/buildchain/build-facts\";` | `packages/core/build-facts.js:557` |\n| `writeKungfuBuildInfoProjection` | function: function writeKungfuBuildInfoProjection({ cwd = process.cwd(), moduleFact, output } = {}) | { cwd = process.cwd(), moduleFact, output } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { writeKungfuBuildInfoProjection } from \"@kungfu-tech/buildchain/build-facts\";` | `packages/core/build-facts.js:565` |\n\n## `@kungfu-tech/buildchain/core`\n\nTarget: `./packages/core/index.js`. Public symbols: 608.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `abortReleaseActivationTransaction` | function: function abortReleaseActivationTransaction(transaction, reason) | transaction, reason | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { abortReleaseActivationTransaction } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-activation-transaction.js:277` |\n| `AGENT_INDEX_CONTRACT` | constant: const AGENT_INDEX_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { AGENT_INDEX_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport.js:40` |\n| `aggregateBuildFacts` | function: function aggregateBuildFacts({ cwd = process.cwd(), productId = \"\", moduleFacts = [], artifacts = [], now = nowIso(), } = {}) | { cwd = process.cwd(), productId = \"\", moduleFacts = [], artifacts = [], now = nowIso(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | subprocess | `import { aggregateBuildFacts } from \"@kungfu-tech/buildchain/core\";` | `packages/core/build-facts.js:466` |\n| `aggregateControllerReceipts` | function: function aggregateControllerReceipts({ plans = [], receipts = [] } = {}) | { plans = [], receipts = [] } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { aggregateControllerReceipts } from \"@kungfu-tech/buildchain/core\";` | `packages/core/controller-evidence.js:449` |\n| `ANCHORED_VERSION_MATERIAL_CONTRACT` | constant: const ANCHORED_VERSION_MATERIAL_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ANCHORED_VERSION_MATERIAL_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/anchored-version-material.js:15` |\n| `appendBuildchainLogEvent` | function: function appendBuildchainLogEvent(filePath, event) | filePath, event | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write | `import { appendBuildchainLogEvent } from \"@kungfu-tech/buildchain/core\";` | `packages/core/logging.js:67` |\n| `applyGitHubHousekeeperPlan` | function: async function applyGitHubHousekeeperPlan({ client, plan, dryRun = true, priorReceipt, appliedAt = new Date().toISOString(), staleDays = DEFAULT_STALE_DAYS, maxActions = DEFAULT_MAX_ACTIONS, }) | { client, plan, dryRun = true, priorReceipt, appliedAt = new Date().toISOString(), staleDays = DEFAULT_STALE_DAYS, maxActions = DEFAULT_MAX_ACTIONS, } | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { applyGitHubHousekeeperPlan } from \"@kungfu-tech/buildchain/core\";` | `packages/core/engineering-housekeeper-github.js:615` |\n| `applySurfaceTimestampPolicy` | function: function applySurfaceTimestampPolicy(manifest, options = {}) | manifest, options = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { applySurfaceTimestampPolicy } from \"@kungfu-tech/buildchain/core\";` | `packages/core/surface-manifest.js:79` |\n| `ARTIFACT_EVIDENCE_CONTRACT` | constant: const ARTIFACT_EVIDENCE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_EVIDENCE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport.js:38` |\n| `ARTIFACT_PASSPORT_LOCATOR_CONTRACT` | constant: const ARTIFACT_PASSPORT_LOCATOR_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_PASSPORT_LOCATOR_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-passport.js:11` |\n| `ARTIFACT_PASSPORT_POINTER_CONTRACT` | constant: const ARTIFACT_PASSPORT_POINTER_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_PASSPORT_POINTER_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-passport.js:10` |\n| `ARTIFACT_SIGNING_AUTHORITY_CONTRACT` | constant: const ARTIFACT_SIGNING_AUTHORITY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_SIGNING_AUTHORITY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-signing.js:7` |\n| `ARTIFACT_SIGNING_RECEIPT_CONTRACT` | constant: const ARTIFACT_SIGNING_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_SIGNING_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-signing.js:5` |\n| `ARTIFACT_SIGNING_REQUEST_CONTRACT` | constant: const ARTIFACT_SIGNING_REQUEST_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_SIGNING_REQUEST_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-signing.js:3` |\n| `ARTIFACT_SIGNING_RESULT_CONTRACT` | constant: const ARTIFACT_SIGNING_RESULT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_SIGNING_RESULT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-signing-result.js:12` |\n| `ARTIFACT_VERIFICATION_CONTRACT` | constant: const ARTIFACT_VERIFICATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_VERIFICATION_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-passport.js:9` |\n| `ARTIFACT_VERIFICATION_ENVELOPE_CHECK_CONTRACT` | constant: const ARTIFACT_VERIFICATION_ENVELOPE_CHECK_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_VERIFICATION_ENVELOPE_CHECK_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-verification-envelope.js:12` |\n| `ARTIFACT_VERIFICATION_ENVELOPE_CONTRACT` | constant: const ARTIFACT_VERIFICATION_ENVELOPE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_VERIFICATION_ENVELOPE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-verification-envelope.js:10` |\n| `artifactSigningDigest` | function: function artifactSigningDigest(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { artifactSigningDigest } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-signing.js:60` |\n| `artifactSigningEvidenceDigest` | function: function artifactSigningEvidenceDigest(evidence = []) | evidence = [] | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { artifactSigningEvidenceDigest } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-signing-result.js:58` |\n| `artifactVerificationEnvelopeDigest` | function: function artifactVerificationEnvelopeDigest(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { artifactVerificationEnvelopeDigest } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-verification-envelope.js:59` |\n| `assertPackageManager` | function: function assertPackageManager(manager) | manager | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { assertPackageManager } from \"@kungfu-tech/buildchain/core\";` | `packages/core/package-manager.js:49` |\n| `assertPublicSurfaceReverseAudit` | function: function assertPublicSurfaceReverseAudit(report) | report | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { assertPublicSurfaceReverseAudit } from \"@kungfu-tech/buildchain/core\";` | `packages/core/public-surface-audit.js:261` |\n| `auditKfd3Surfaces` | function: function auditKfd3Surfaces({ cwd = process.cwd(), registryPath = \"\", kinds = [], artifactPath = \"\", } = {}) | { cwd = process.cwd(), registryPath = \"\", kinds = [], artifactPath = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { auditKfd3Surfaces } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd3-surface-register.js:547` |\n| `BADGE_BUNDLE_DEFAULT_CLAIMS` | constant: const BADGE_BUNDLE_DEFAULT_CLAIMS | none | value | Import does not declare a throw contract. | none-on-import | `import { BADGE_BUNDLE_DEFAULT_CLAIMS } from \"@kungfu-tech/buildchain/core\";` | `packages/core/readme-badges.js:17` |\n| `BADGE_BUNDLE_FACTS_CONTRACT` | constant: const BADGE_BUNDLE_FACTS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BADGE_BUNDLE_FACTS_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/readme-badges.js:13` |\n| `BUILD_FACTS_GIT_CONTRACT` | constant: const BUILD_FACTS_GIT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILD_FACTS_GIT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/build-facts.js:9` |\n| `BUILD_FACTS_LEGACY_KUNGFU_BUILDINFO_CONTRACT` | constant: const BUILD_FACTS_LEGACY_KUNGFU_BUILDINFO_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILD_FACTS_LEGACY_KUNGFU_BUILDINFO_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/build-facts.js:14` |\n| `BUILD_FACTS_MODULE_CONTRACT` | constant: const BUILD_FACTS_MODULE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILD_FACTS_MODULE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/build-facts.js:11` |\n| `BUILD_FACTS_PRODUCT_CONTRACT` | constant: const BUILD_FACTS_PRODUCT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILD_FACTS_PRODUCT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/build-facts.js:12` |\n| `BUILD_FACTS_VERIFY_CONTRACT` | constant: const BUILD_FACTS_VERIFY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILD_FACTS_VERIFY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/build-facts.js:13` |\n| `BUILD_FACTS_VERSION_CONTRACT` | constant: const BUILD_FACTS_VERSION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILD_FACTS_VERSION_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/build-facts.js:10` |\n| `BUILDCHAIN_AGENT_MANUALS` | constant: const BUILDCHAIN_AGENT_MANUALS | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_AGENT_MANUALS } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-agent-manuals.js:1` |\n| `BUILDCHAIN_ANCHORED_PACKAGE_RELEASE_VALIDATION_CONTRACT` | constant: const BUILDCHAIN_ANCHORED_PACKAGE_RELEASE_VALIDATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_ANCHORED_PACKAGE_RELEASE_VALIDATION_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:31` |\n| `BUILDCHAIN_CACHE_EVIDENCE_SET_CONTRACT` | constant: const BUILDCHAIN_CACHE_EVIDENCE_SET_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CACHE_EVIDENCE_SET_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/cache-evidence.js:5` |\n| `BUILDCHAIN_CACHE_OPERATION_RECEIPT_CONTRACT` | constant: const BUILDCHAIN_CACHE_OPERATION_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CACHE_OPERATION_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/cache-evidence.js:3` |\n| `BUILDCHAIN_CANDIDATE_TIMELINE_CONTRACT` | constant: const BUILDCHAIN_CANDIDATE_TIMELINE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CANDIDATE_TIMELINE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/candidate-timeline.js:1` |\n| `BUILDCHAIN_CANDIDATE_TIMELINE_EVENT_CONTRACT` | constant: const BUILDCHAIN_CANDIDATE_TIMELINE_EVENT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CANDIDATE_TIMELINE_EVENT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/candidate-timeline.js:3` |\n| `BUILDCHAIN_CONFIG_PATH` | constant: const BUILDCHAIN_CONFIG_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONFIG_PATH } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:7` |\n| `BUILDCHAIN_CONSUMER_ISSUE_CONTRACT` | constant: const BUILDCHAIN_CONSUMER_ISSUE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONSUMER_ISSUE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/issue-reporting.js:4` |\n| `BUILDCHAIN_CONTRACT_LOCK` | constant: const BUILDCHAIN_CONTRACT_LOCK | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONTRACT_LOCK } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-contract.js:21` |\n| `BUILDCHAIN_CONTRACT_LOCK_PATH` | constant: const BUILDCHAIN_CONTRACT_LOCK_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONTRACT_LOCK_PATH } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:9` |\n| `BUILDCHAIN_CONTROLLER_AGGREGATE_CONTRACT` | constant: const BUILDCHAIN_CONTROLLER_AGGREGATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONTROLLER_AGGREGATE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/controller-evidence.js:6` |\n| `BUILDCHAIN_CONTROLLER_DESCRIPTOR_CONTRACT` | constant: const BUILDCHAIN_CONTROLLER_DESCRIPTOR_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONTROLLER_DESCRIPTOR_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/controller-evidence.js:4` |\n| `BUILDCHAIN_CONTROLLER_EVIDENCE_CONTRACT` | constant: const BUILDCHAIN_CONTROLLER_EVIDENCE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONTROLLER_EVIDENCE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/controller-evidence.js:3` |\n| `BUILDCHAIN_CONTROLLER_REGISTRY_CONTRACT` | constant: const BUILDCHAIN_CONTROLLER_REGISTRY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONTROLLER_REGISTRY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/controller-evidence.js:5` |\n| `BUILDCHAIN_DIAGNOSTICS_CONTRACT` | constant: const BUILDCHAIN_DIAGNOSTICS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_DIAGNOSTICS_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:28` |\n| `BUILDCHAIN_DIAGNOSTICS_MANIFEST_CONTRACT` | constant: const BUILDCHAIN_DIAGNOSTICS_MANIFEST_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_DIAGNOSTICS_MANIFEST_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:33` |\n| `BUILDCHAIN_DIAGNOSTICS_SUMMARY_CONTRACT` | constant: const BUILDCHAIN_DIAGNOSTICS_SUMMARY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_DIAGNOSTICS_SUMMARY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:35` |\n| `BUILDCHAIN_DIR` | constant: const BUILDCHAIN_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_DIR } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:4` |\n| `BUILDCHAIN_GENERATED_DIRS` | constant: const BUILDCHAIN_GENERATED_DIRS | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_GENERATED_DIRS } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:36` |\n| `BUILDCHAIN_GITHUB_GOVERNANCE_AUTHORITY` | constant: const BUILDCHAIN_GITHUB_GOVERNANCE_AUTHORITY | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_GITHUB_GOVERNANCE_AUTHORITY } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-governance-authority.js:1365` |\n| `BUILDCHAIN_GITHUB_GOVERNANCE_PROTECTED_PATHS` | constant: const BUILDCHAIN_GITHUB_GOVERNANCE_PROTECTED_PATHS | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_GITHUB_GOVERNANCE_PROTECTED_PATHS } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-governance-authority.js:1367` |\n| `BUILDCHAIN_JSON_FORMATTING_POLICY` | constant: const BUILDCHAIN_JSON_FORMATTING_POLICY | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_JSON_FORMATTING_POLICY } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-gate.js:14` |\n| `BUILDCHAIN_KFD_CLAIM_REGISTRY_CONTRACT` | constant: const BUILDCHAIN_KFD_CLAIM_REGISTRY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD_CLAIM_REGISTRY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-kfd-claims.js:14` |\n| `BUILDCHAIN_KFD_COLLABORATION_INTERFACE_CONTRACT` | constant: const BUILDCHAIN_KFD_COLLABORATION_INTERFACE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD_COLLABORATION_INTERFACE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-kfd-claims.js:15` |\n| `BUILDCHAIN_KFD_ROOT` | constant: const BUILDCHAIN_KFD_ROOT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD_ROOT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:11` |\n| `BUILDCHAIN_KFD1_CONTRACT_WORLD_WITNESS_PATH` | constant: const BUILDCHAIN_KFD1_CONTRACT_WORLD_WITNESS_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD1_CONTRACT_WORLD_WITNESS_PATH } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:16` |\n| `BUILDCHAIN_KFD1_DIR` | constant: const BUILDCHAIN_KFD1_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD1_DIR } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:12` |\n| `BUILDCHAIN_KFD1_RELEASE_GATE_PATH` | constant: const BUILDCHAIN_KFD1_RELEASE_GATE_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD1_RELEASE_GATE_PATH } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:17` |\n| `BUILDCHAIN_KFD1_VERIFY_RESULT_PATH` | constant: const BUILDCHAIN_KFD1_VERIFY_RESULT_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD1_VERIFY_RESULT_PATH } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:18` |\n| `BUILDCHAIN_KFD2_CLAIM_ARGS_PATH` | constant: const BUILDCHAIN_KFD2_CLAIM_ARGS_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD2_CLAIM_ARGS_PATH } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:21` |\n| `BUILDCHAIN_KFD2_CLAIMS_DIR` | constant: const BUILDCHAIN_KFD2_CLAIMS_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD2_CLAIMS_DIR } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:22` |\n| `BUILDCHAIN_KFD2_DIR` | constant: const BUILDCHAIN_KFD2_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD2_DIR } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:13` |\n| `BUILDCHAIN_KFD2_REGISTRY_PATH` | constant: const BUILDCHAIN_KFD2_REGISTRY_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD2_REGISTRY_PATH } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:19` |\n| `BUILDCHAIN_KFD2_RELEASE_CLAIMS_PATH` | constant: const BUILDCHAIN_KFD2_RELEASE_CLAIMS_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD2_RELEASE_CLAIMS_PATH } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:20` |\n| `BUILDCHAIN_KFD3_ARTIFACT_WITNESS_PATH` | constant: const BUILDCHAIN_KFD3_ARTIFACT_WITNESS_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD3_ARTIFACT_WITNESS_PATH } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:26` |\n| `BUILDCHAIN_KFD3_CAPABILITY_QUERY_PATH` | constant: const BUILDCHAIN_KFD3_CAPABILITY_QUERY_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD3_CAPABILITY_QUERY_PATH } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:27` |\n| `BUILDCHAIN_KFD3_COLLABORATION_INTERFACE_PATH` | constant: const BUILDCHAIN_KFD3_COLLABORATION_INTERFACE_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD3_COLLABORATION_INTERFACE_PATH } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:24` |\n| `BUILDCHAIN_KFD3_DIR` | constant: const BUILDCHAIN_KFD3_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD3_DIR } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:14` |\n| `BUILDCHAIN_KFD3_PREBUILD_WITNESS_PATH` | constant: const BUILDCHAIN_KFD3_PREBUILD_WITNESS_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD3_PREBUILD_WITNESS_PATH } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:25` |\n| `BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATH` | constant: const BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATH } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:23` |\n| `BUILDCHAIN_KFD4_DIR` | constant: const BUILDCHAIN_KFD4_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD4_DIR } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:15` |\n| `BUILDCHAIN_LAYOUT_DISCOVERY_CONTRACT` | constant: const BUILDCHAIN_LAYOUT_DISCOVERY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_LAYOUT_DISCOVERY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:6` |\n| `BUILDCHAIN_LIFECYCLE_OBSERVABILITY_CONTRACT` | constant: const BUILDCHAIN_LIFECYCLE_OBSERVABILITY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_LIFECYCLE_OBSERVABILITY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:29` |\n| `BUILDCHAIN_LOCKED_SOURCE_CHECKOUT_CONTRACT` | constant: const BUILDCHAIN_LOCKED_SOURCE_CHECKOUT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_LOCKED_SOURCE_CHECKOUT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:41` |\n| `BUILDCHAIN_LOG_EVENT_CONTRACT` | constant: const BUILDCHAIN_LOG_EVENT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_LOG_EVENT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/logging.js:6` |\n| `BUILDCHAIN_LOG_SUMMARY_CONTRACT` | constant: const BUILDCHAIN_LOG_SUMMARY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_LOG_SUMMARY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/logging.js:7` |\n| `BUILDCHAIN_PROCESS_SAMPLE_REPORT_CONTRACT` | constant: const BUILDCHAIN_PROCESS_SAMPLE_REPORT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_PROCESS_SAMPLE_REPORT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:37` |\n| `BUILDCHAIN_PROCESS_SAMPLE_SUMMARY_CONTRACT` | constant: const BUILDCHAIN_PROCESS_SAMPLE_SUMMARY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_PROCESS_SAMPLE_SUMMARY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:39` |\n| `BUILDCHAIN_PUBLIC_SURFACE_AUDIT_CONTRACT` | constant: const BUILDCHAIN_PUBLIC_SURFACE_AUDIT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_PUBLIC_SURFACE_AUDIT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/public-surface-audit.js:12` |\n| `BUILDCHAIN_RELEASE_PASSPORT_PATH` | constant: const BUILDCHAIN_RELEASE_PASSPORT_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_RELEASE_PASSPORT_PATH } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:33` |\n| `BUILDCHAIN_RUNTIME_CONTRACT_WORLD` | constant: const BUILDCHAIN_RUNTIME_CONTRACT_WORLD | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_RUNTIME_CONTRACT_WORLD } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-contract.js:20` |\n| `BUILDCHAIN_VERSION_PIN_PATH` | constant: const BUILDCHAIN_VERSION_PIN_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_VERSION_PIN_PATH } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:5` |\n| `BUILDCHAIN_WORKFLOW_FRICTION_ISSUE_CONTRACT` | constant: const BUILDCHAIN_WORKFLOW_FRICTION_ISSUE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_WORKFLOW_FRICTION_ISSUE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/issue-reporting.js:5` |\n| `buildchainKfdClaims` | constant: const buildchainKfdClaims | none | value | Import does not declare a throw contract. | none-on-import | `import { buildchainKfdClaims } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd.js:896` |\n| `buildchainPublicationAuthorityDescriptors` | function: function buildchainPublicationAuthorityDescriptors() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { buildchainPublicationAuthorityDescriptors } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-publication-authority.js:62` |\n| `buildConsumerIssueReport` | function: function buildConsumerIssueReport(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { buildConsumerIssueReport } from \"@kungfu-tech/buildchain/core\";` | `packages/core/issue-reporting.js:104` |\n| `buildFactsDigest` | function: function buildFactsDigest(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write, subprocess | `import { buildFactsDigest } from \"@kungfu-tech/buildchain/core\";` | `packages/core/build-facts.js:45` |\n| `buildWorkflowFrictionIssueReport` | function: function buildWorkflowFrictionIssueReport(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { buildWorkflowFrictionIssueReport } from \"@kungfu-tech/buildchain/core\";` | `packages/core/issue-reporting.js:199` |\n| `cacheEvidenceDigest` | function: function cacheEvidenceDigest(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { cacheEvidenceDigest } from \"@kungfu-tech/buildchain/core\";` | `packages/core/cache-evidence.js:48` |\n| `CHANNEL_CANDIDATE_DECISION_SCHEMA` | constant: const CHANNEL_CANDIDATE_DECISION_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { CHANNEL_CANDIDATE_DECISION_SCHEMA } from \"@kungfu-tech/buildchain/core\";` | `packages/core/channel-candidate.js:6` |\n| `channelCandidateSourceLockRef` | function: function channelCandidateSourceLockRef(targetBranch, sourceSha) | targetBranch, sourceSha | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { channelCandidateSourceLockRef } from \"@kungfu-tech/buildchain/core\";` | `packages/core/channel-candidate.js:85` |\n| `checkBadgeBundleBlock` | function: function checkBadgeBundleBlock({ readmeText, facts } = {}) | { readmeText, facts } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { checkBadgeBundleBlock } from \"@kungfu-tech/buildchain/core\";` | `packages/core/readme-badges.js:867` |\n| `checkHomebrewTap` | function: async function checkHomebrewTap({ cwd = process.cwd(), packageName = \"buildchain\", releasePassport = \"\", manifestPath = DEFAULT_MANIFEST_PATH, formulaPath = \"\", } = {}) | { cwd = process.cwd(), packageName = \"buildchain\", releasePassport = \"\", manifestPath = DEFAULT_MANIFEST_PATH, formulaPath = \"\", } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { checkHomebrewTap } from \"@kungfu-tech/buildchain/core\";` | `packages/core/homebrew.js:335` |\n| `checkKfd2ProductClaimOutputs` | function: function checkKfd2ProductClaimOutputs(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { checkKfd2ProductClaimOutputs } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd2-product-claims.js:415` |\n| `checkReadmeBadgeBlock` | function: function checkReadmeBadgeBlock({ readmeText, facts } = {}) | { readmeText, facts } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { checkReadmeBadgeBlock } from \"@kungfu-tech/buildchain/core\";` | `packages/core/readme-badges.js:848` |\n| `claimReleasePropagationWork` | function: function claimReleasePropagationWork({ work, expectedWorkRoot, authority, familyState, } = {}) | { work, expectedWorkRoot, authority, familyState, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { claimReleasePropagationWork } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-work-transitions.js:17` |\n| `classifyHousekeeperBranch` | function: function classifyHousekeeperBranch(branch, policyInput = {}) | branch, policyInput = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { classifyHousekeeperBranch } from \"@kungfu-tech/buildchain/core\";` | `packages/core/engineering-housekeeper.js:105` |\n| `classifyHousekeeperPullRequest` | function: function classifyHousekeeperPullRequest(pullRequest, policyInput = {}) | pullRequest, policyInput = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { classifyHousekeeperPullRequest } from \"@kungfu-tech/buildchain/core\";` | `packages/core/engineering-housekeeper.js:144` |\n| `classifyHousekeeperReplay` | function: function classifyHousekeeperReplay(plan, priorReceipt) | plan, priorReceipt | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { classifyHousekeeperReplay } from \"@kungfu-tech/buildchain/core\";` | `packages/core/engineering-housekeeper.js:265` |\n| `classifyProcessCommand` | function: function classifyProcessCommand(command = \"\") | command = \"\" | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { classifyProcessCommand } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:1085` |\n| `classifyReleasePropagationCondition` | function: function classifyReleasePropagationCondition(condition) | condition | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { classifyReleasePropagationCondition } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-agent-entry.js:171` |\n| `codeownersForPath` | function: function codeownersForPath(source, candidatePath) | source, candidatePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { codeownersForPath } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-governance-authority.js:419` |\n| `collectBadgeBundleFacts` | function: async function collectBadgeBundleFacts({ cwd = process.cwd(), claims = undefined } = {}) | { cwd = process.cwd(), claims = undefined } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectBadgeBundleFacts } from \"@kungfu-tech/buildchain/core\";` | `packages/core/readme-badges.js:790` |\n| `collectBuildchainDiagnostics` | function: function collectBuildchainDiagnostics({ cwd = process.cwd(), artifactPaths = [] } = {}) | { cwd = process.cwd(), artifactPaths = [] } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectBuildchainDiagnostics } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:248` |\n| `collectCacheDiagnostics` | function: function collectCacheDiagnostics({ cwd = process.cwd(), cacheDirs = [], runCommand = defaultDiagnosticCommandRunner } = {}) | { cwd = process.cwd(), cacheDirs = [], runCommand = defaultDiagnosticCommandRunner } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectCacheDiagnostics } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:922` |\n| `collectCompilerCacheDiagnostics` | function: function collectCompilerCacheDiagnostics({ cwd = process.cwd(), runCommand = defaultDiagnosticCommandRunner, env = process.env, } = {}) | { cwd = process.cwd(), runCommand = defaultDiagnosticCommandRunner, env = process.env, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectCompilerCacheDiagnostics } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:573` |\n| `collectGitDiagnostics` | function: function collectGitDiagnostics({ cwd = process.cwd() } = {}) | { cwd = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectGitDiagnostics } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:944` |\n| `collectGitHubHousekeeperInventory` | function: async function collectGitHubHousekeeperInventory({ client, repository, targetBranch, observedAt, staleDays = DEFAULT_STALE_DAYS, policy = {}, }) | { client, repository, targetBranch, observedAt, staleDays = DEFAULT_STALE_DAYS, policy = {}, } | Promise<unknown> | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { collectGitHubHousekeeperInventory } from \"@kungfu-tech/buildchain/core\";` | `packages/core/engineering-housekeeper-github.js:246` |\n| `collectGitHubReleasePassport` | function: function collectGitHubReleasePassport({ cwd = process.cwd(), tag = \"\", repository = process.env.GITHUB_REPOSITORY \\|\\| \"\", sourceSha = process.env.GITHUB_SHA \\|\\| \"\", line = \"\", outputDir = \".buildchain/release-passport\", assetsJson = \"\", assetsDir = \"\", releaseJson = \"\", productName = \"Buildchain\", packageName = \"@kungfu-tech/buildchain\", packageVersion = \"\", packageSetJson = \"\", publishEvidenceJson = \"\", trustedPublishingJson = \"\", transactionJson = \"\", anchorManifestJson = \"\", versionMaterialJson = \"\", impactJson = \"\", buildSummaryJson = \"\", buildFactsJsons = [], platformManifestJsons = [], distTagEvidenceJson = \"\", kfd1WitnessJsons = [], kfd2ClaimJsons = [], kfd3PrebuildWitnessJsons = [], kfd3ArtifactWitnessJsons = [], kfd3ArtifactVerifyCommand = \"\", kfdAdopterManifestJson = \"\", kfdSupportMatrixJson = \"\", kfdProductGateJsons = [], invariantPassportJsons = [], invariantPassportCommand = \"\", releaseEvidenceJsons = [], kfdAgentHubEvidenceJson = \"\", controllerReceiptReferences = [], githubArtifactAttestationPolicyJsons = [], basePassportJson = \"\", requireBaseKfd = false, releaseJsonExtra = \"\", publishJson = \"\", workflow = {}, checkedAt = \"\", } = {}) | { cwd = process.cwd(), tag = \"\", repository = process.env.GITHUB_REPOSITORY \\|\\| \"\", sourceSha = process.env.GITHUB_SHA \\|\\| \"\", line = \"\", outputDir = \".buildchain/release-passport\", assetsJson = \"\", assetsDir = \"\", releaseJson = \"\", productName = \"Buildchain\", packageName = \"@kungfu-tech/buildchain\", packageVersion = \"\", packageSetJson = \"\", publishEvidenceJson = \"\", trustedPublishingJson = \"\", transactionJson = \"\", anchorManifestJson = \"\", versionMaterialJson = \"\", impactJson = \"\", buildSummaryJson = \"\", buildFactsJsons = [], platformManifestJsons = [], distTagEvidenceJson = \"\", kfd1WitnessJsons = [], kfd2ClaimJsons = [], kfd3PrebuildWitnessJsons = [], kfd3ArtifactWitnessJsons = [], kfd3ArtifactVerifyCommand = \"\", kfdAdopterManifestJson = \"\", kfdSupportMatrixJson = \"\", kfdProductGateJsons = [], invariantPassportJsons = [], invariantPassportCommand = \"\", releaseEvidenceJsons = [], kfdAgentHubEvidenceJson = \"\", controllerReceiptReferences = [], githubArtifactAttestationPolicyJsons = [], basePassportJson = \"\", requireBaseKfd = false, releaseJsonExtra = \"\", publishJson = \"\", workflow = {}, checkedAt = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectGitHubReleasePassport } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport.js:1424` |\n| `collectGitSourceFacts` | function: function collectGitSourceFacts({ cwd = process.cwd(), root = \".\" } = {}) | { cwd = process.cwd(), root = \".\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectGitSourceFacts } from \"@kungfu-tech/buildchain/core\";` | `packages/core/build-facts.js:154` |\n| `collectHomebrewTapFacts` | function: async function collectHomebrewTapFacts({ cwd = process.cwd(), packageName = \"buildchain\", releasePassport = \"\", manifestPath = DEFAULT_MANIFEST_PATH, formulaPath = \"\", } = {}) | { cwd = process.cwd(), packageName = \"buildchain\", releasePassport = \"\", manifestPath = DEFAULT_MANIFEST_PATH, formulaPath = \"\", } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectHomebrewTapFacts } from \"@kungfu-tech/buildchain/core\";` | `packages/core/homebrew.js:223` |\n| `collectKfdStatus` | function: function collectKfdStatus({ cwd = process.cwd() } = {}) | { cwd = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectKfdStatus } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd.js:902` |\n| `collectModuleBuildFacts` | function: function collectModuleBuildFacts({ cwd = process.cwd(), moduleId = \"\", moduleRoot = \"\", scope = \"\", versionSource = undefined, versionSourceId = \"\", outputs = [], lifecycle = \"\", platform = currentPlatform(), dependencies = [], now = nowIso(), } = {}) | { cwd = process.cwd(), moduleId = \"\", moduleRoot = \"\", scope = \"\", versionSource = undefined, versionSourceId = \"\", outputs = [], lifecycle = \"\", platform = currentPlatform(), dependencies = [], now = nowIso(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectModuleBuildFacts } from \"@kungfu-tech/buildchain/core\";` | `packages/core/build-facts.js:310` |\n| `collectNativeDiagnostics` | function: function collectNativeDiagnostics({ cwd = process.cwd(), profile = undefined, runCommand = defaultDiagnosticCommandRunner, } = {}) | { cwd = process.cwd(), profile = undefined, runCommand = defaultDiagnosticCommandRunner, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectNativeDiagnostics } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:295` |\n| `collectPaperFleetAudit` | function: function collectPaperFleetAudit({ root = process.cwd(), repositories = [], buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainSha = \"\", governance = {}, } = {}) | { root = process.cwd(), repositories = [], buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainSha = \"\", governance = {}, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectPaperFleetAudit } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper-fleet.js:158` |\n| `collectPaperPreflight` | function: function collectPaperPreflight({ cwd = process.cwd(), buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainRef = \"v3\", buildchainSha = \"\", registry = NPM_REGISTRY, offline = false, agentEntryMode = \"contract\", } = {}) | { cwd = process.cwd(), buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainRef = \"v3\", buildchainSha = \"\", registry = NPM_REGISTRY, offline = false, agentEntryMode = \"contract\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectPaperPreflight } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper.js:2414` |\n| `collectPaperStatus` | function: function collectPaperStatus({ cwd = process.cwd() } = {}) | { cwd = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectPaperStatus } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper.js:1472` |\n| `collectProcessTreeSnapshot` | function: function collectProcessTreeSnapshot({ rootPid = process.pid, cwd = process.cwd(), platform = process.platform, runCommand = defaultDiagnosticCommandRunner, } = {}) | { rootPid = process.pid, cwd = process.cwd(), platform = process.platform, runCommand = defaultDiagnosticCommandRunner, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectProcessTreeSnapshot } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:1029` |\n| `collectPublicationArtifact` | function: function collectPublicationArtifact({ cwd = process.cwd(), sourceSha = \"\", sourceBundle = true, sourceBundlePath = \"\", generatedAt = \"\", manifestPath = \"\", passportPath = \"\", } = {}) | { cwd = process.cwd(), sourceSha = \"\", sourceBundle = true, sourceBundlePath = \"\", generatedAt = \"\", manifestPath = \"\", passportPath = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { collectPublicationArtifact } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-artifact.js:271` |\n| `collectPublicationPackageFacts` | function: function collectPublicationPackageFacts({ cwd = process.cwd(), packageName = \"\", outputDir = \".buildchain/publication/npm-package\", } = {}) | { cwd = process.cwd(), packageName = \"\", outputDir = \".buildchain/publication/npm-package\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { collectPublicationPackageFacts } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-package.js:74` |\n| `collectPublicSurfaceReverseAudit` | function: function collectPublicSurfaceReverseAudit({ root = process.cwd(), cliRegistry: suppliedCliRegistry = undefined, workflowRegistry: suppliedWorkflowRegistry = undefined, pageRegistry: suppliedPageRegistry = undefined, } = {}) | { root = process.cwd(), cliRegistry: suppliedCliRegistry = undefined, workflowRegistry: suppliedWorkflowRegistry = undefined, pageRegistry: suppliedPageRegistry = undefined, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectPublicSurfaceReverseAudit } from \"@kungfu-tech/buildchain/core\";` | `packages/core/public-surface-audit.js:161` |\n| `collectReadmeBadgeFacts` | function: async function collectReadmeBadgeFacts({ cwd = process.cwd() } = {}) | { cwd = process.cwd() } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectReadmeBadgeFacts } from \"@kungfu-tech/buildchain/core\";` | `packages/core/readme-badges.js:700` |\n| `collectRunnerDiagnostics` | function: function collectRunnerDiagnostics() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectRunnerDiagnostics } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:468` |\n| `collectToolDiagnostics` | function: function collectToolDiagnostics({ cwd = process.cwd(), tools = [\"node\", \"pnpm\", \"npm\", \"git\", \"cmake\", \"ninja\", \"ccache\", \"sccache\"] } = {}) | { cwd = process.cwd(), tools = [\"node\", \"pnpm\", \"npm\", \"git\", \"cmake\", \"ninja\", \"ccache\", \"sccache\"] } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectToolDiagnostics } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:495` |\n| `collectVersionSourceFact` | function: function collectVersionSourceFact({ cwd = process.cwd(), source = undefined, sourceId = \"\", now = nowIso() } = {}) | { cwd = process.cwd(), source = undefined, sourceId = \"\", now = nowIso() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | subprocess | `import { collectVersionSourceFact } from \"@kungfu-tech/buildchain/core\";` | `packages/core/build-facts.js:181` |\n| `commandForKungfuUpgrade` | function: function commandForKungfuUpgrade(manager, scope = \"@kungfu-trader\") | manager, scope = \"@kungfu-trader\" | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { commandForKungfuUpgrade } from \"@kungfu-tech/buildchain/core\";` | `packages/core/package-manager.js:121` |\n| `commandForRunScript` | function: function commandForRunScript(manager, script) | manager, script | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { commandForRunScript } from \"@kungfu-tech/buildchain/core\";` | `packages/core/package-manager.js:89` |\n| `commandForVersion` | function: function commandForVersion(manager, keyword, options = {}) | manager, keyword, options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { commandForVersion } from \"@kungfu-tech/buildchain/core\";` | `packages/core/package-manager.js:100` |\n| `compileEffectiveGithubGovernancePolicy` | function: function compileEffectiveGithubGovernancePolicy({ branch, defaultBranch, protectedBranch = false, protection, rulesets = [], } = {}) | { branch, defaultBranch, protectedBranch = false, protection, rulesets = [], } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { compileEffectiveGithubGovernancePolicy } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-governance-authority.js:313` |\n| `compileReleaseTailDeclaration` | function: function compileReleaseTailDeclaration(input) | input | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { compileReleaseTailDeclaration } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-plane.js:584` |\n| `completeReleasePropagationWork` | function: function completeReleasePropagationWork({ work, expectedWorkRoot, receipt, completionDecision, } = {}) | { work, expectedWorkRoot, receipt, completionDecision, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { completeReleasePropagationWork } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-work-transitions.js:110` |\n| `computeConsumerIssueFingerprint` | function: function computeConsumerIssueFingerprint(fields = {}) | fields = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { computeConsumerIssueFingerprint } from \"@kungfu-tech/buildchain/core\";` | `packages/core/issue-reporting.js:64` |\n| `CONSUMER_PUBLICATION_DECISION_CONTRACT` | constant: const CONSUMER_PUBLICATION_DECISION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { CONSUMER_PUBLICATION_DECISION_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:20` |\n| `consumerIssueMarker` | function: function consumerIssueMarker(fingerprint) | fingerprint | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { consumerIssueMarker } from \"@kungfu-tech/buildchain/core\";` | `packages/core/issue-reporting.js:76` |\n| `contractSummary` | function: function contractSummary(contractWorld, runtimeRef = \"\", runtimeSha = \"\") | contractWorld, runtimeRef = \"\", runtimeSha = \"\" | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { contractSummary } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-contract.js:1031` |\n| `controllerEvidenceDigest` | function: function controllerEvidenceDigest(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { controllerEvidenceDigest } from \"@kungfu-tech/buildchain/core\";` | `packages/core/controller-evidence.js:151` |\n| `createActivationReceiptProjectorAdapter` | function: function createActivationReceiptProjectorAdapter(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createActivationReceiptProjectorAdapter } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-adapters.js:181` |\n| `createAnchoredVersionMaterialEvidence` | function: function createAnchoredVersionMaterialEvidence({ cwd = process.cwd(), targetChannel = \"\", targetRef = \"\", alphaRef = \"\", releaseRef = \"HEAD\", runLifecycle = true, } = {}) | { cwd = process.cwd(), targetChannel = \"\", targetRef = \"\", alphaRef = \"\", releaseRef = \"HEAD\", runLifecycle = true, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createAnchoredVersionMaterialEvidence } from \"@kungfu-tech/buildchain/core\";` | `packages/core/anchored-version-material.js:118` |\n| `createArtifactEvidence` | function: function createArtifactEvidence({ assets = [], repository = \"\", tag = \"\", sourceSha = \"\", workflow = {}, kfdAdopter = undefined } = {}) | { assets = [], repository = \"\", tag = \"\", sourceSha = \"\", workflow = {}, kfdAdopter = undefined } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createArtifactEvidence } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport.js:1088` |\n| `createArtifactSigningReceipt` | function: function createArtifactSigningReceipt({ request, status = \"passed\", authority = {}, result = {}, signatures = [], reason = \"\", } = {}) | { request, status = \"passed\", authority = {}, result = {}, signatures = [], reason = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createArtifactSigningReceipt } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-signing.js:313` |\n| `createArtifactSigningRequest` | function: function createArtifactSigningRequest({ source = {}, runtime = {}, artifact = {}, signature = {}, delivery = {}, } = {}) | { source = {}, runtime = {}, artifact = {}, signature = {}, delivery = {}, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createArtifactSigningRequest } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-signing.js:167` |\n| `createArtifactSigningResult` | function: function createArtifactSigningResult({ request, receipt, receiptPath = \"receipt.json\", payload = {}, evidence = [], verification = {}, } = {}) | { request, receipt, receiptPath = \"receipt.json\", payload = {}, evidence = [], verification = {}, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createArtifactSigningResult } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-signing-result.js:68` |\n| `createBuildchainContractLock` | function: function createBuildchainContractLock({ buildchainRef = \"v3\", resolvedSha = \"\", contractWorld, compatibilityPolicy = DEFAULT_POLICY, acceptedAt = new Date().toISOString(), } = {}) | { buildchainRef = \"v3\", resolvedSha = \"\", contractWorld, compatibilityPolicy = DEFAULT_POLICY, acceptedAt = new Date().toISOString(), } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createBuildchainContractLock } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-contract.js:830` |\n| `createBuildchainContractWorld` | function: function createBuildchainContractWorld({ root = process.cwd(), packageJson = undefined, controllerRegistry = undefined, } = {}) | { root = process.cwd(), packageJson = undefined, controllerRegistry = undefined, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainContractWorld } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-contract.js:123` |\n| `createBuildchainGithubGovernanceAuthority` | function: function createBuildchainGithubGovernanceAuthority() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainGithubGovernanceAuthority } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-governance-authority.js:452` |\n| `createBuildchainKfd1Witness` | function: function createBuildchainKfd1Witness({ root = process.cwd(), sourceSha = \"\" } = {}) | { root = process.cwd(), sourceSha = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainKfd1Witness } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-kfd-claims.js:530` |\n| `createBuildchainKfd2Claims` | function: function createBuildchainKfd2Claims({ root = process.cwd(), witnessFiles = {} } = {}) | { root = process.cwd(), witnessFiles = {} } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainKfd2Claims } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-kfd-claims.js:687` |\n| `createBuildchainKfd3ArtifactWitness` | function: function createBuildchainKfd3ArtifactWitness({ root = process.cwd(), sourceSha = \"\" } = {}) | { root = process.cwd(), sourceSha = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainKfd3ArtifactWitness } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-kfd-claims.js:647` |\n| `createBuildchainKfd3PrebuildWitness` | function: function createBuildchainKfd3PrebuildWitness({ root = process.cwd(), sourceSha = \"\" } = {}) | { root = process.cwd(), sourceSha = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainKfd3PrebuildWitness } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-kfd-claims.js:583` |\n| `createBuildchainKfdClaimRegistry` | function: function createBuildchainKfdClaimRegistry({ root = process.cwd(), sourceSha = \"\" } = {}) | { root = process.cwd(), sourceSha = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainKfdClaimRegistry } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-kfd-claims.js:510` |\n| `createBuildchainKfdSurfaceRegistry` | function: function createBuildchainKfdSurfaceRegistry({ root = process.cwd() } = {}) | { root = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainKfdSurfaceRegistry } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-kfd-claims.js:411` |\n| `createBuildchainLayoutDiscovery` | function: function createBuildchainLayoutDiscovery({ cwd = process.cwd(), buildchainVersion = \"\", } = {}) | { cwd = process.cwd(), buildchainVersion = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainLayoutDiscovery } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:99` |\n| `createBuildchainLogger` | function: function createBuildchainLogger(options = {}) | options = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | subprocess | `import { createBuildchainLogger } from \"@kungfu-tech/buildchain/core\";` | `packages/core/logging.js:300` |\n| `createBuildchainPublicationAuthorityRegistry` | function: function createBuildchainPublicationAuthorityRegistry({ root = process.cwd() } = {}) | { root = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainPublicationAuthorityRegistry } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-publication-authority.js:86` |\n| `createBuildchainPublicClaimDefinitions` | function: function createBuildchainPublicClaimDefinitions() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainPublicClaimDefinitions } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-kfd-claims.js:226` |\n| `createCacheEvidenceSet` | function: function createCacheEvidenceSet({ repository, sourceCommit, sourceTree = \"\", runtimeCommit = \"\", platform, operations = [], } = {}) | { repository, sourceCommit, sourceTree = \"\", runtimeCommit = \"\", platform, operations = [], } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createCacheEvidenceSet } from \"@kungfu-tech/buildchain/core\";` | `packages/core/cache-evidence.js:244` |\n| `createCacheOperationReceipt` | function: function createCacheOperationReceipt({ operationId, operation, provider, producer, platform, cacheKey, cacheRoot, outcome, bindings = {}, metrics, evidence, } = {}) | { operationId, operation, provider, producer, platform, cacheKey, cacheRoot, outcome, bindings = {}, metrics, evidence, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createCacheOperationReceipt } from \"@kungfu-tech/buildchain/core\";` | `packages/core/cache-evidence.js:169` |\n| `createCandidateTimeline` | function: function createCandidateTimeline({ candidate = {}, events = [], generatedAt, } = {}) | { candidate = {}, events = [], generatedAt, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createCandidateTimeline } from \"@kungfu-tech/buildchain/core\";` | `packages/core/candidate-timeline.js:381` |\n| `createConsumerPublicationDecision` | function: function createConsumerPublicationDecision({ capability, gateAggregate, decision, predicateId, predicateDigest, evidence = {}, now = new Date(), } = {}) | { capability, gateAggregate, decision, predicateId, predicateDigest, evidence = {}, now = new Date(), } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createConsumerPublicationDecision } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:991` |\n| `createControllerPlan` | function: function createControllerPlan({ descriptor, source = {}, runtime = {}, inputs = {} } = {}) | { descriptor, source = {}, runtime = {}, inputs = {} } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createControllerPlan } from \"@kungfu-tech/buildchain/core\";` | `packages/core/controller-evidence.js:287` |\n| `createControllerReceipt` | function: function createControllerReceipt({ plan, stages = [], evidence = [], reason = undefined, artifact = \"\" } = {}) | { plan, stages = [], evidence = [], reason = undefined, artifact = \"\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createControllerReceipt } from \"@kungfu-tech/buildchain/core\";` | `packages/core/controller-evidence.js:363` |\n| `createControllerReceiptReference` | function: function createControllerReceiptReference(receipt) | receipt | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createControllerReceiptReference } from \"@kungfu-tech/buildchain/core\";` | `packages/core/controller-evidence.js:491` |\n| `createControllerRegistry` | function: function createControllerRegistry({ workflows = [] } = {}) | { workflows = [] } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createControllerRegistry } from \"@kungfu-tech/buildchain/core\";` | `packages/core/controller-evidence.js:197` |\n| `createDiagnosticsArtifact` | function: function createDiagnosticsArtifact({ cwd = process.cwd(), logPath = \"\", artifactPaths = [], cacheDirs = [], lifecycleObservability = undefined, processSamples = [], processSummary = undefined, requestedParallelism = 0, sourceCheckout = undefined, compilerCachePreparation = undefined, links = {}, } = {}) | { cwd = process.cwd(), logPath = \"\", artifactPaths = [], cacheDirs = [], lifecycleObservability = undefined, processSamples = [], processSummary = undefined, requestedParallelism = 0, sourceCheckout = undefined, compilerCachePreparation = undefined, links = {}, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createDiagnosticsArtifact } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:1408` |\n| `createEngineeringHousekeeperPlan` | function: function createEngineeringHousekeeperPlan({ repository, target, branches = [], pullRequests = [], policy = {}, observedAt, }) | { repository, target, branches = [], pullRequests = [], policy = {}, observedAt, } | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createEngineeringHousekeeperPlan } from \"@kungfu-tech/buildchain/core\";` | `packages/core/engineering-housekeeper.js:170` |\n| `createEngineeringHousekeeperReceipt` | function: function createEngineeringHousekeeperReceipt({ plan, outcomes, appliedAt, }) | { plan, outcomes, appliedAt, } | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createEngineeringHousekeeperReceipt } from \"@kungfu-tech/buildchain/core\";` | `packages/core/engineering-housekeeper.js:246` |\n| `createGitHubArtifactAttestationEvidence` | function: function createGitHubArtifactAttestationEvidence({ preparation, attestationId, attestationUrl, bundlePath, workflow = {}, } = {}) | { preparation, attestationId, attestationUrl, bundlePath, workflow = {}, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createGitHubArtifactAttestationEvidence } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-artifact-attestation.js:474` |\n| `createGitHubArtifactAttestationPolicy` | function: function createGitHubArtifactAttestationPolicy(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGitHubArtifactAttestationPolicy } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-artifact-attestation.js:204` |\n| `createGitHubArtifactAttestationVerificationPlan` | function: function createGitHubArtifactAttestationVerificationPlan({ artifactPath, bundlePath, evidence, } = {}) | { artifactPath, bundlePath, evidence, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGitHubArtifactAttestationVerificationPlan } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-artifact-attestation.js:524` |\n| `createGithubGovernanceRolloutPlan` | function: function createGithubGovernanceRolloutPlan({ repository, targetRef, inventory, rollbackSnapshot, rollbackProtectionExists = true, desiredProtection, } = {}) | { repository, targetRef, inventory, rollbackSnapshot, rollbackProtectionExists = true, desiredProtection, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGithubGovernanceRolloutPlan } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-governance-authority.js:934` |\n| `createGitHubIssueRequest` | function: function createGitHubIssueRequest({ token, apiUrl = process.env.GITHUB_API_URL \\|\\| \"https://api.github.com\", fetchImpl = globalThis.fetch, retryDelaysMs = DEFAULT_RETRY_DELAYS_MS, } = {}) | { token, apiUrl = process.env.GITHUB_API_URL \\|\\| \"https://api.github.com\", fetchImpl = globalThis.fetch, retryDelaysMs = DEFAULT_RETRY_DELAYS_MS, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGitHubIssueRequest } from \"@kungfu-tech/buildchain/core\";` | `packages/core/issue-reporting.js:393` |\n| `createGitHubReleaseAssetsAdapter` | function: function createGitHubReleaseAssetsAdapter({ octokit, resolveArtifact, } = {}) | { octokit, resolveArtifact, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGitHubReleaseAssetsAdapter } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-adapters.js:310` |\n| `createGithubRulesetBypassRolloutPlan` | function: function createGithubRulesetBypassRolloutPlan({ repository, rulesetId, inventory, rollbackSnapshot, } = {}) | { repository, rulesetId, inventory, rollbackSnapshot, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGithubRulesetBypassRolloutPlan } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-governance-authority.js:1112` |\n| `createGithubRulesetGovernanceRolloutPlan` | function: function createGithubRulesetGovernanceRolloutPlan({ repository, targetRef, rulesetId, rulesetName, inventory, rollbackSnapshot, desiredProtection, } = {}) | { repository, targetRef, rulesetId, rulesetName, inventory, rollbackSnapshot, desiredProtection, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGithubRulesetGovernanceRolloutPlan } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-governance-authority.js:1191` |\n| `createHttpJsonReadback` | function: function createHttpJsonReadback({ fetchImpl = globalThis.fetch } = {}) | { fetchImpl = globalThis.fetch } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createHttpJsonReadback } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-adapters.js:191` |\n| `createKfd1ReleaseGateEvidence` | function: function createKfd1ReleaseGateEvidence({ cwd = process.cwd(), artifactRoot = \"\", artifacts = [], witnesses = [], verifiedAt = new Date().toISOString(), metadata = resolveKfd1Metadata(), } = {}) | { cwd = process.cwd(), artifactRoot = \"\", artifacts = [], witnesses = [], verifiedAt = new Date().toISOString(), metadata = resolveKfd1Metadata(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createKfd1ReleaseGateEvidence } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-gate.js:977` |\n| `createKfd3CollaborationInterfaceReleaseGateEvidence` | function: function createKfd3CollaborationInterfaceReleaseGateEvidence({ prebuildWitnesses = [], artifactWitnesses = [], prebuildWitnessMetas = [], artifactWitnessMetas = [], artifactCommandMeta = undefined, verifiedAt = new Date().toISOString(), metadata = resolveKfd3Metadata(), } = {}) | { prebuildWitnesses = [], artifactWitnesses = [], prebuildWitnessMetas = [], artifactWitnessMetas = [], artifactCommandMeta = undefined, verifiedAt = new Date().toISOString(), metadata = resolveKfd3Metadata(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createKfd3CollaborationInterfaceReleaseGateEvidence } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-gate.js:1132` |\n| `createKfd3SurfaceWitness` | function: function createKfd3SurfaceWitness({ cwd = process.cwd(), registryPath = \"\", kind = \"prebuild\", sourceSha = \"\", artifactPath = \"\", } = {}) | { cwd = process.cwd(), registryPath = \"\", kind = \"prebuild\", sourceSha = \"\", artifactPath = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | network | `import { createKfd3SurfaceWitness } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd3-surface-register.js:702` |\n| `createKfdAdopterReleaseBinding` | function: function createKfdAdopterReleaseBinding({ manifest, manifestGate, legacyProjection, manifestPath = \"kfd-adopter-manifest.json\", gatePath = \"kfd-adopter-manifest-gate.json\", legacyProjectionPath = \"kfd-support.json\", expectedSourceSha = \"\", } = {}) | { manifest, manifestGate, legacyProjection, manifestPath = \"kfd-adopter-manifest.json\", gatePath = \"kfd-adopter-manifest-gate.json\", legacyProjectionPath = \"kfd-support.json\", expectedSourceSha = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createKfdAdopterReleaseBinding } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-verification-envelope.js:441` |\n| `createKfdBadgeSpecsFromStandards` | function: function createKfdBadgeSpecsFromStandards(standardsMetadata) | standardsMetadata | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createKfdBadgeSpecsFromStandards } from \"@kungfu-tech/buildchain/core\";` | `packages/core/readme-badges.js:126` |\n| `createKungfuBuildInfoProjection` | function: function createKungfuBuildInfoProjection({ moduleFact, cwd = process.cwd(), now = nowIso() } = {}) | { moduleFact, cwd = process.cwd(), now = nowIso() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createKungfuBuildInfoProjection } from \"@kungfu-tech/buildchain/core\";` | `packages/core/build-facts.js:528` |\n| `createManualUpstreamPickupCapture` | function: function createManualUpstreamPickupCapture({ plan, expectedDownstreamBaseSha, }) | { plan, expectedDownstreamBaseSha, } | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createManualUpstreamPickupCapture } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-pickup.js:361` |\n| `createManualUpstreamPickupPlan` | function: function createManualUpstreamPickupPlan({ config: configInput, sourceId, channel, currentVersion, upstreamRelease, }) | { config: configInput, sourceId, channel, currentVersion, upstreamRelease, } | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createManualUpstreamPickupPlan } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-pickup.js:303` |\n| `createPackageReleasePropagationCapture` | function: function createPackageReleasePropagationCapture({ config: configInput, upstreamRelease: upstreamReleaseInput, expectedBaseShas = {}, } = {}) | { config: configInput, upstreamRelease: upstreamReleaseInput, expectedBaseShas = {}, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPackageReleasePropagationCapture } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-capture.js:101` |\n| `createPaperAlphaPlan` | function: function createPaperAlphaPlan({ cwd = process.cwd(), sourceRef = \"\", targetRef = \"\", } = {}) | { cwd = process.cwd(), sourceRef = \"\", targetRef = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPaperAlphaPlan } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper.js:2656` |\n| `createPaperBuildPlan` | function: function createPaperBuildPlan({ cwd = process.cwd(), sourceSha = \"\", pullToolchain = true, } = {}) | { cwd = process.cwd(), sourceSha = \"\", pullToolchain = true, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPaperBuildPlan } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper.js:2593` |\n| `createPaperResumePlan` | function: function createPaperResumePlan({ cwd = process.cwd(), buildchainRef = \"\", } = {}) | { cwd = process.cwd(), buildchainRef = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write | `import { createPaperResumePlan } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper.js:2714` |\n| `createPaperWorkStartPlan` | function: function createPaperWorkStartPlan({ cwd = process.cwd(), topic = \"\", branch = \"\", buildchainSha = \"\", } = {}) | { cwd = process.cwd(), topic = \"\", branch = \"\", buildchainSha = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createPaperWorkStartPlan } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper-work.js:41` |\n| `createPaperWorkSubmitPlan` | function: function createPaperWorkSubmitPlan({ cwd = process.cwd(), pullRequests = [], pullRequestObservation = { ok: true }, buildchainSha = \"\", } = {}) | { cwd = process.cwd(), pullRequests = [], pullRequestObservation = { ok: true }, buildchainSha = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createPaperWorkSubmitPlan } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper-work.js:207` |\n| `createPortableDevCachePlan` | function: function createPortableDevCachePlan(manifest) | manifest | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createPortableDevCachePlan } from \"@kungfu-tech/buildchain/core\";` | `packages/core/portable-dev-cache.js:172` |\n| `createPortableDevCacheReceipt` | function: function createPortableDevCacheReceipt({ plan, matchedKey = \"\", cacheHit = \"\", validationStatus = \"pass\", validationReason = \"\", coldFallbackStatus = \"not-run\", }) | { plan, matchedKey = \"\", cacheHit = \"\", validationStatus = \"pass\", validationReason = \"\", coldFallbackStatus = \"not-run\", } | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPortableDevCacheReceipt } from \"@kungfu-tech/buildchain/core\";` | `packages/core/portable-dev-cache.js:226` |\n| `createPublicationAdmission` | function: function createPublicationAdmission(input = {}) | input = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createPublicationAdmission } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:236` |\n| `createPublicationArtifactCandidate` | function: function createPublicationArtifactCandidate({ repository, sourceSha, sourceTreeSha, runtimeSha, manifest, passport, controllerReceipt, files = [], } = {}) | { repository, sourceSha, sourceTreeSha, runtimeSha, manifest, passport, controllerReceipt, files = [], } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPublicationArtifactCandidate } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-artifact-candidate.js:55` |\n| `createPublicationArtifactManifestSet` | function: function createPublicationArtifactManifestSet({ repository, sourceSha, sourceTreeSha, manifests = [], payloads = [], } = {}) | { repository, sourceSha, sourceTreeSha, manifests = [], payloads = [], } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPublicationArtifactManifestSet } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:303` |\n| `createPublicationAuthorityRegistry` | function: function createPublicationAuthorityRegistry({ descriptors = [], workflows = [] } = {}) | { descriptors = [], workflows = [] } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPublicationAuthorityRegistry } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:121` |\n| `createPublicationControlPlaneAudit` | function: function createPublicationControlPlaneAudit({ repository, workflowPath, publisherWorkflowPath, environment, facts = [], observedAt, expiresAt, } = {}) | { repository, workflowPath, publisherWorkflowPath, environment, facts = [], observedAt, expiresAt, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createPublicationControlPlaneAudit } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:208` |\n| `createPublicationGateDecision` | function: function createPublicationGateDecision({ sourceSha, profile, required = false, rationale, policy = {}, } = {}) | { sourceSha, profile, required = false, rationale, policy = {}, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createPublicationGateDecision } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:280` |\n| `createPublicationQualificationReceipt` | function: function createPublicationQualificationReceipt({ capability, gateAggregate, consumerDecision, now = new Date(), } = {}) | { capability, gateAggregate, consumerDecision, now = new Date(), } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPublicationQualificationReceipt } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:1035` |\n| `createPublicationSealedBundle` | function: function createPublicationSealedBundle({ candidate, packageName, packageVersion, npmTarballPath, npmIntegrity, releaseAssetPaths = [], githubReleaseRequired = true, } = {}) | { candidate, packageName, packageVersion, npmTarballPath, npmIntegrity, releaseAssetPaths = [], githubReleaseRequired = true, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPublicationSealedBundle } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-sealed-bundle.js:84` |\n| `createPublicationSourceBundle` | function: function createPublicationSourceBundle({ cwd = process.cwd(), sourcePaths = [], output = \".buildchain/publication/source.tar.gz\", } = {}) | { cwd = process.cwd(), sourcePaths = [], output = \".buildchain/publication/source.tar.gz\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write, subprocess | `import { createPublicationSourceBundle } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-artifact.js:249` |\n| `createReadmeBadgeEndpointRegistry` | function: function createReadmeBadgeEndpointRegistry({ kfdSpecs = undefined, kfdStandards = undefined } = {}) | { kfdSpecs = undefined, kfdStandards = undefined } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | subprocess | `import { createReadmeBadgeEndpointRegistry } from \"@kungfu-tech/buildchain/core\";` | `packages/core/readme-badges.js:133` |\n| `createReleaseActivationReceiptSet` | function: function createReleaseActivationReceiptSet({ transaction, receipts = [], } = {}) | { transaction, receipts = [], } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createReleaseActivationReceiptSet } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-activation-transaction.js:311` |\n| `createReleaseActivationTransaction` | function: function createReleaseActivationTransaction({ transactionId, mode = \"shadow\", bindings, owners, } = {}) | { transactionId, mode = \"shadow\", bindings, owners, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createReleaseActivationTransaction } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-activation-transaction.js:103` |\n| `createReleaseCandidatePassport` | function: function createReleaseCandidatePassport({ repository = \"\", pullRequest = {}, targetChannel = \"\", version = \"\", sourceHeadSha = \"\", baseSha = \"\", mergeRefSha = \"\", sourceTreeHash = \"\", buildSummary = {}, buildchain = {}, gateAggregate = undefined, familyEvidence = undefined, controllerReceipts = [], controllerReceiptReferences = [], workflow = {}, createdAt = nowIso(), } = {}) | { repository = \"\", pullRequest = {}, targetChannel = \"\", version = \"\", sourceHeadSha = \"\", baseSha = \"\", mergeRefSha = \"\", sourceTreeHash = \"\", buildSummary = {}, buildchain = {}, gateAggregate = undefined, familyEvidence = undefined, controllerReceipts = [], controllerReceiptReferences = [], workflow = {}, createdAt = nowIso(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createReleaseCandidatePassport } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-candidate.js:310` |\n| `createReleaseCheckReport` | function: function createReleaseCheckReport({ passport, artifactEvidence, publishEvidence, impact, agentIndex, productMechanism, kfdAgentHubEvidence, kfdSupportEvidence, kfdAdopterManifest, kfdAdopterManifestGate, releaseEvidenceDocuments = [], checkedAt = nowIso(), } = {}) | { passport, artifactEvidence, publishEvidence, impact, agentIndex, productMechanism, kfdAgentHubEvidence, kfdSupportEvidence, kfdAdopterManifest, kfdAdopterManifestGate, releaseEvidenceDocuments = [], checkedAt = nowIso(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createReleaseCheckReport } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport.js:2555` |\n| `createReleasePassport` | function: function createReleasePassport({ cwd = process.cwd(), repository = \"\", tag = \"\", sourceSha = \"\", line = \"\", productName = \"Buildchain\", packageName = \"@kungfu-tech/buildchain\", packageVersion = \"\", productMechanismPath = \"product-mechanism.json\", artifactEvidencePath = \"artifact-evidence.json\", impactPath = \"impact.json\", agentIndexPath = \"agent-index.json\", checkReportPath = \"check-report.json\", publishEvidencePath = \"\", transactionStatePath = \"\", assets = [], packageSet = undefined, anchorManifest = undefined, versionMaterial = undefined, publishEvidence = undefined, trustedPublishing = undefined, transaction = undefined, buildSummary = undefined, buildFacts = [], platformArtifactManifests = [], distTagPromotionEvidence = undefined, release = {}, publish = {}, impact = undefined, workflow = {}, kfd1 = undefined, kfd2Claims = [], kfd3 = undefined, kfdAdopter = undefined, kfdAdopterManifestEvidencePath = \"\", kfdAdopterGateEvidencePath = \"\", kfdSupport = undefined, kfdSupportEvidencePath = \"\", invariantPassports = undefined, releaseEvidence = [], kfdAgentHubEvidence = undefined, kfdAgentHubEvidencePath = \"\", controllerReceipts = [], controllerReceiptReferences = [], githubArtifactAttestations = [], checkedAt = \"\", } = {}) | { cwd = process.cwd(), repository = \"\", tag = \"\", sourceSha = \"\", line = \"\", productName = \"Buildchain\", packageName = \"@kungfu-tech/buildchain\", packageVersion = \"\", productMechanismPath = \"product-mechanism.json\", artifactEvidencePath = \"artifact-evidence.json\", impactPath = \"impact.json\", agentIndexPath = \"agent-index.json\", checkReportPath = \"check-report.json\", publishEvidencePath = \"\", transactionStatePath = \"\", assets = [], packageSet = undefined, anchorManifest = undefined, versionMaterial = undefined, publishEvidence = undefined, trustedPublishing = undefined, transaction = undefined, buildSummary = undefined, buildFacts = [], platformArtifactManifests = [], distTagPromotionEvidence = undefined, release = {}, publish = {}, impact = undefined, workflow = {}, kfd1 = undefined, kfd2Claims = [], kfd3 = undefined, kfdAdopter = undefined, kfdAdopterManifestEvidencePath = \"\", kfdAdopterGateEvidencePath = \"\", kfdSupport = undefined, kfdSupportEvidencePath = \"\", invariantPassports = undefined, releaseEvidence = [], kfdAgentHubEvidence = undefined, kfdAgentHubEvidencePath = \"\", controllerReceipts = [], controllerReceiptReferences = [], githubArtifactAttestations = [], checkedAt = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { createReleasePassport } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport.js:1123` |\n| `createReleasePassportCheckManifest` | function: function createReleasePassportCheckManifest({ standards = kfdStandards } = {}) | { standards = kfdStandards } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createReleasePassportCheckManifest } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport-contract.js:159` |\n| `createReleasePropagationLock` | function: function createReleasePropagationLock({ graph, edge, sourceNode, targetNode, upstreamRelease, downstreamChannel, } = {}) | { graph, edge, sourceNode, targetNode, upstreamRelease, downstreamChannel, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createReleasePropagationLock } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation.js:199` |\n| `createReleasePropagationPushPlan` | function: function createReleasePropagationPushPlan({ work: workInput, expectedWorkRoot, repositoryState: stateInput, } = {}) | { work: workInput, expectedWorkRoot, repositoryState: stateInput, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | subprocess | `import { createReleasePropagationPushPlan } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-push.js:77` |\n| `createReleasePropagationReceipt` | function: function createReleasePropagationReceipt({ plan, target = \"\", lockResult, prOutcome, stagingState = \"pending\", productionState = \"not-requested\", observedAt = \"\", } = {}) | { plan, target = \"\", lockResult, prOutcome, stagingState = \"pending\", productionState = \"not-requested\", observedAt = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createReleasePropagationReceipt } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation.js:371` |\n| `createReleasePropagationStageReceipt` | function: function createReleasePropagationStageReceipt({ work, stage, outcome = \"success\", observedAt, actor, summary, evidence, failure = null, } = {}) | { work, stage, outcome = \"success\", observedAt, actor, summary, evidence, failure = null, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createReleasePropagationStageReceipt } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-work.js:214` |\n| `createReleasePropagationWork` | function: function createReleasePropagationWork({ plan, target = \"\", workContext, expectedDownstreamBaseSha, } = {}) | { plan, target = \"\", workContext, expectedDownstreamBaseSha, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createReleasePropagationWork } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-work.js:111` |\n| `createReleaseTailAdapterSet` | function: function createReleaseTailAdapterSet(declaration, adapters) | declaration, adapters | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createReleaseTailAdapterSet } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-plane.js:1217` |\n| `createReleaseTailTransaction` | function: function createReleaseTailTransaction(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createReleaseTailTransaction } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-plane.js:697` |\n| `createReleaseTransaction` | function: function createReleaseTransaction({ repository, version, exactTag = \"\", channel, line = \"\", sourceSha, targetRef, releaseSha, releaseMaterialSha = releaseSha, publishToolingSha = \"\", lifecycleIdentity = \"lifecycle.publish\", statePath = \"\", evidencePath = \"\", actor = \"\", runId = \"\", } = {}) | { repository, version, exactTag = \"\", channel, line = \"\", sourceSha, targetRef, releaseSha, releaseMaterialSha = releaseSha, publishToolingSha = \"\", lifecycleIdentity = \"lifecycle.publish\", statePath = \"\", evidencePath = \"\", actor = \"\", runId = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createReleaseTransaction } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publish-transaction.js:197` |\n| `createRunnerProvenance` | function: function createRunnerProvenance({ runnerClass, os, architecture, imageDigest, measurementDigest, baselineDigest = \"\", toolchainDigest = \"\", cacheContractDigest = \"\", taskIsolationDigest = \"\", cleanBaselineProven = false, isolation = \"\", } = {}) | { runnerClass, os, architecture, imageDigest, measurementDigest, baselineDigest = \"\", toolchainDigest = \"\", cacheContractDigest = \"\", taskIsolationDigest = \"\", cleanBaselineProven = false, isolation = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createRunnerProvenance } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:166` |\n| `createSignedStaticChannelAdapter` | function: function createSignedStaticChannelAdapter(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createSignedStaticChannelAdapter } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-adapters.js:161` |\n| `createSiteReleaseActivationAdapter` | function: function createSiteReleaseActivationAdapter(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createSiteReleaseActivationAdapter } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-adapters.js:171` |\n| `createStableCandidateLedger` | function: function createStableCandidateLedger({ repository, targetBranch, now = new Date().toISOString() } = {}) | { repository, targetBranch, now = new Date().toISOString() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createStableCandidateLedger } from \"@kungfu-tech/buildchain/core\";` | `packages/core/stable-candidate-ledger.js:56` |\n| `createSurfaceTimestampPolicy` | function: function createSurfaceTimestampPolicy({ generatedAt = \"\", publishedAt = \"\", sourceDateEpoch = process.env.SOURCE_DATE_EPOCH \\|\\| DEFAULT_SOURCE_DATE_EPOCH, sourceRevision = \"\", deterministicInputs = [], timestampPolicy = \"\", timestampFields = [\"generatedAt\", \"publishedAt\"], timestampFieldsParticipateInArtifactDigest = true, artifactDigestScope = \"manifest-and-artifact\", reproducible = true, } = {}) | { generatedAt = \"\", publishedAt = \"\", sourceDateEpoch = process.env.SOURCE_DATE_EPOCH \\|\\| DEFAULT_SOURCE_DATE_EPOCH, sourceRevision = \"\", deterministicInputs = [], timestampPolicy = \"\", timestampFields = [\"generatedAt\", \"publishedAt\"], timestampFieldsParticipateInArtifactDigest = true, artifactDigestScope = \"manifest-and-artifact\", reproducible = true, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createSurfaceTimestampPolicy } from \"@kungfu-tech/buildchain/core\";` | `packages/core/surface-manifest.js:34` |\n| `createWebSurfaceProductionDecision` | function: function createWebSurfaceProductionDecision({ approved, kind, repository, sourceSha, actor, actorPermission = \"\", releasePr = 0, releaseSource = \"\", reason, } = {}) | { approved, kind, repository, sourceSha, actor, actorPermission = \"\", releasePr = 0, releaseSource = \"\", reason, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createWebSurfaceProductionDecision } from \"@kungfu-tech/buildchain/core\";` | `packages/core/web-surface-publication-candidate.js:45` |\n| `createWebSurfacePublicationCandidate` | function: function createWebSurfacePublicationCandidate({ repository, sourceSha, sourceTreeSha, runtimeSha, plan, planFileDigest, controllerReceipt, decision, } = {}) | { repository, sourceSha, sourceTreeSha, runtimeSha, plan, planFileDigest, controllerReceipt, decision, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createWebSurfacePublicationCandidate } from \"@kungfu-tech/buildchain/core\";` | `packages/core/web-surface-publication-candidate.js:79` |\n| `decideChannelCandidate` | function: function decideChannelCandidate(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { decideChannelCandidate } from \"@kungfu-tech/buildchain/core\";` | `packages/core/channel-candidate.js:91` |\n| `DEFAULT_BUILDCHAIN_ISSUE_REPOSITORY` | constant: const DEFAULT_BUILDCHAIN_ISSUE_REPOSITORY | none | value | Import does not declare a throw contract. | none-on-import | `import { DEFAULT_BUILDCHAIN_ISSUE_REPOSITORY } from \"@kungfu-tech/buildchain/core\";` | `packages/core/issue-reporting.js:6` |\n| `DEFAULT_HOUSEKEEPER_POLICY` | constant: const DEFAULT_HOUSEKEEPER_POLICY | none | value | Import does not declare a throw contract. | none-on-import | `import { DEFAULT_HOUSEKEEPER_POLICY } from \"@kungfu-tech/buildchain/core\";` | `packages/core/engineering-housekeeper.js:29` |\n| `defaultBuildchainLogPath` | function: function defaultBuildchainLogPath({ cwd = process.cwd() } = {}) | { cwd = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { defaultBuildchainLogPath } from \"@kungfu-tech/buildchain/core\";` | `packages/core/logging.js:41` |\n| `defaultPublishEvidencePath` | function: function defaultPublishEvidencePath(version, workspace = process.cwd()) | version, workspace = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { defaultPublishEvidencePath } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publish-transaction.js:193` |\n| `defaultReleaseStatePath` | function: function defaultReleaseStatePath(version, workspace = process.cwd()) | version, workspace = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { defaultReleaseStatePath } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publish-transaction.js:185` |\n| `DETACHED_ARTIFACT_SIGNATURE_CONTRACT` | constant: const DETACHED_ARTIFACT_SIGNATURE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { DETACHED_ARTIFACT_SIGNATURE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/detached-artifact-signature.js:10` |\n| `detectKfd3Surfaces` | function: function detectKfd3Surfaces({ cwd = process.cwd(), kinds = [], artifactPath = \"\" } = {}) | { cwd = process.cwd(), kinds = [], artifactPath = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { detectKfd3Surfaces } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd3-surface-register.js:423` |\n| `detectLockfile` | function: function detectLockfile(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { detectLockfile } from \"@kungfu-tech/buildchain/core\";` | `packages/core/package-manager.js:237` |\n| `detectPackageManager` | function: function detectPackageManager(cwd = process.cwd()) | cwd = process.cwd() | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { detectPackageManager } from \"@kungfu-tech/buildchain/core\";` | `packages/core/package-manager.js:56` |\n| `detectPublicationAuthoritySignals` | function: function detectPublicationAuthoritySignals(workflowText = \"\") | workflowText = \"\" | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { detectPublicationAuthoritySignals } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:104` |\n| `detectRequestedParallelism` | function: function detectRequestedParallelism({ command = \"\", args = [], env = process.env, } = {}) | { command = \"\", args = [], env = process.env, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { detectRequestedParallelism } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:1188` |\n| `detectRequestedParallelismFromProcessSamples` | function: function detectRequestedParallelismFromProcessSamples(samples = []) | samples = [] | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { detectRequestedParallelismFromProcessSamples } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:1223` |\n| `diagnoseLegacyReleaseTailHooks` | function: function diagnoseLegacyReleaseTailHooks(hooks = {}) | hooks = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { diagnoseLegacyReleaseTailHooks } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-compatibility.js:23` |\n| `discoverArtifactPassport` | function: async function discoverArtifactPassport({ subject, cwd = process.cwd(), passportLocation = \"\", locatorConfig = \"\", repository = \"\", tag = \"\", githubReleaseBaseUrl = \"\", } = {}) | { subject, cwd = process.cwd(), passportLocation = \"\", locatorConfig = \"\", repository = \"\", tag = \"\", githubReleaseBaseUrl = \"\", } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { discoverArtifactPassport } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-passport.js:499` |\n| `discoverBuildchainRepoFiles` | function: function discoverBuildchainRepoFiles(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { discoverBuildchainRepoFiles } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:143` |\n| `discoverConfiguredDerivedVersionMaterial` | function: function discoverConfiguredDerivedVersionMaterial(cwd = process.cwd(), loadedConfig = loadBuildchainConfig(cwd)) | cwd = process.cwd(), loadedConfig = loadBuildchainConfig(cwd) | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { discoverConfiguredDerivedVersionMaterial } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-config.js:1462` |\n| `discoverConfiguredVersionStateFiles` | function: function discoverConfiguredVersionStateFiles(cwd = process.cwd(), loadedConfig = loadBuildchainConfig(cwd)) | cwd = process.cwd(), loadedConfig = loadBuildchainConfig(cwd) | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { discoverConfiguredVersionStateFiles } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-config.js:1423` |\n| `discoverKfdStandards` | function: function discoverKfdStandards() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { discoverKfdStandards } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd.js:464` |\n| `discoverPaperFleet` | function: function discoverPaperFleet(root = process.cwd()) | root = process.cwd() | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { discoverPaperFleet } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper-fleet.js:23` |\n| `ENGINEERING_HOUSEKEEPER_CONTRACT` | constant: const ENGINEERING_HOUSEKEEPER_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ENGINEERING_HOUSEKEEPER_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/engineering-housekeeper.js:3` |\n| `ENGINEERING_HOUSEKEEPER_SCHEMA_VERSION` | constant: const ENGINEERING_HOUSEKEEPER_SCHEMA_VERSION | none | value | Import does not declare a throw contract. | none-on-import | `import { ENGINEERING_HOUSEKEEPER_SCHEMA_VERSION } from \"@kungfu-tech/buildchain/core\";` | `packages/core/engineering-housekeeper.js:5` |\n| `engineeringHousekeeperRoot` | function: function engineeringHousekeeperRoot(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { engineeringHousekeeperRoot } from \"@kungfu-tech/buildchain/core\";` | `packages/core/engineering-housekeeper.js:58` |\n| `enumerateActionInputs` | function: function enumerateActionInputs({ root = process.cwd() } = {}) | { root = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { enumerateActionInputs } from \"@kungfu-tech/buildchain/core\";` | `packages/core/public-surface-audit.js:91` |\n| `enumerateCliCommandsFromBin` | function: function enumerateCliCommandsFromBin({ root = process.cwd(), binPath = \"bin/buildchain.mjs\", } = {}) | { root = process.cwd(), binPath = \"bin/buildchain.mjs\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { enumerateCliCommandsFromBin } from \"@kungfu-tech/buildchain/core\";` | `packages/core/public-surface-cli.js:93` |\n| `enumerateDocCommandRefs` | function: function enumerateDocCommandRefs({ root = process.cwd() } = {}) | { root = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { enumerateDocCommandRefs } from \"@kungfu-tech/buildchain/core\";` | `packages/core/public-surface-audit.js:115` |\n| `enumerateSitePages` | function: function enumerateSitePages({ root = process.cwd() } = {}) | { root = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { enumerateSitePages } from \"@kungfu-tech/buildchain/core\";` | `packages/core/public-surface-audit.js:106` |\n| `enumerateWorkflowInputs` | function: function enumerateWorkflowInputs({ root = process.cwd() } = {}) | { root = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { enumerateWorkflowInputs } from \"@kungfu-tech/buildchain/core\";` | `packages/core/public-surface-audit.js:74` |\n| `evaluateBuildchainContractLock` | function: function evaluateBuildchainContractLock({ lock, current, runtimeRef = \"\", runtimeSha = \"\", runtimeClass = \"\", compatibilityPolicy = \"\", workflowShellRef = \"\", expectedChannel = \"\", expectedMajor = \"\", allowOpaqueRuntime = false, } = {}) | { lock, current, runtimeRef = \"\", runtimeSha = \"\", runtimeClass = \"\", compatibilityPolicy = \"\", workflowShellRef = \"\", expectedChannel = \"\", expectedMajor = \"\", allowOpaqueRuntime = false, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { evaluateBuildchainContractLock } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-contract.js:916` |\n| `evaluateCodeownersAuthority` | function: function evaluateCodeownersAuthority({ source = \"\", sourcePath = \"\", reviewAuthority = \"kungfu-origin\", protectedPaths = PROTECTED_AUTHORITY_PATHS, } = {}) | { source = \"\", sourcePath = \"\", reviewAuthority = \"kungfu-origin\", protectedPaths = PROTECTED_AUTHORITY_PATHS, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { evaluateCodeownersAuthority } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-governance-authority.js:427` |\n| `evaluateGithubGovernanceSnapshot` | function: function evaluateGithubGovernanceSnapshot({ descriptor = createBuildchainGithubGovernanceAuthority(), repository, targetRef, organizationPlan, codeowners, effectivePolicy, memberships, apiEvidence = {}, observedAt, expiresAt, verifier = {}, } = {}) | { descriptor = createBuildchainGithubGovernanceAuthority(), repository, targetRef, organizationPlan, codeowners, effectivePolicy, memberships, apiEvidence = {}, observedAt, expiresAt, verifier = {}, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { evaluateGithubGovernanceSnapshot } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-governance-authority.js:696` |\n| `evaluateKfdProductGate` | function: async function evaluateKfdProductGate({ cwd = process.cwd(), input, expectedSourceSha = \"\", checkedAt = new Date().toISOString(), } = {}) | { cwd = process.cwd(), input, expectedSourceSha = \"\", checkedAt = new Date().toISOString(), } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { evaluateKfdProductGate } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-product-gates.js:419` |\n| `evaluatePublicationControlPlaneSnapshot` | function: function evaluatePublicationControlPlaneSnapshot({ repository, workflowPath, publisherWorkflowPath = workflowPath, environment, branch, packageName, publisherMode = \"npm-trusted-publisher\", requiredStatusCheck = \"check\", snapshot, observedAt, expiresAt, } = {}) | { repository, workflowPath, publisherWorkflowPath = workflowPath, environment, branch, packageName, publisherMode = \"npm-trusted-publisher\", requiredStatusCheck = \"check\", snapshot, observedAt, expiresAt, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { evaluatePublicationControlPlaneSnapshot } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-control-plane-audit.js:75` |\n| `executePaperNpmBootstrap` | function: function executePaperNpmBootstrap(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { executePaperNpmBootstrap } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper.js:2841` |\n| `executePaperWorkStart` | function: function executePaperWorkStart(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { executePaperWorkStart } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper-work.js:169` |\n| `executePaperWorkSubmitPush` | function: function executePaperWorkSubmitPush(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { executePaperWorkSubmitPush } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper-work.js:357` |\n| `executeReleasePropagationPush` | function: function executeReleasePropagationPush({ work, expectedWorkRoot, cwd = process.cwd(), remote = \"origin\", } = {}) | { work, expectedWorkRoot, cwd = process.cwd(), remote = \"origin\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { executeReleasePropagationPush } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-push.js:231` |\n| `executeReleaseTailTransaction` | function: async function executeReleaseTailTransaction(transaction, { adapters, checkpoint: checkpointCallback } = {}) | transaction, { adapters, checkpoint: checkpointCallback } = {} | Promise<unknown> | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { executeReleaseTailTransaction } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-plane.js:1016` |\n| `explainArtifactPassport` | function: async function explainArtifactPassport(options = {}) | options = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { explainArtifactPassport } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-passport.js:827` |\n| `explainKfdAgentHub` | function: function explainKfdAgentHub({ cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, kfdRoot = \"\" } = {}) | { cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, kfdRoot = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { explainKfdAgentHub } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-agent-hub.js:470` |\n| `explainReleaseLineDryRun` | function: function explainReleaseLineDryRun({ cwd = process.cwd(), targetRef, sha = \"\", sourceRef = \"\", tags, publishTransaction = false, publishCommand = \"\", } = {}) | { cwd = process.cwd(), targetRef, sha = \"\", sourceRef = \"\", tags, publishTransaction = false, publishCommand = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { explainReleaseLineDryRun } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-line-dry-run.js:127` |\n| `explainReleasePassport` | function: async function explainReleasePassport({ passportLocation, forAudience = \"human\" } = {}) | { passportLocation, forAudience = \"human\" } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { explainReleasePassport } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport.js:2709` |\n| `FAMILY_RELEASE_EVIDENCE_CONTRACT` | constant: const FAMILY_RELEASE_EVIDENCE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { FAMILY_RELEASE_EVIDENCE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-candidate.js:5` |\n| `finalizeBuildchainContractWorld` | function: function finalizeBuildchainContractWorld(contractWorld) | contractWorld | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { finalizeBuildchainContractWorld } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-contract.js:805` |\n| `formatCandidateTimelineReport` | function: function formatCandidateTimelineReport(timeline) | timeline | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { formatCandidateTimelineReport } from \"@kungfu-tech/buildchain/core\";` | `packages/core/candidate-timeline.js:438` |\n| `formatDiagnosticsSummaryTable` | function: function formatDiagnosticsSummaryTable(summary = {}) | summary = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { formatDiagnosticsSummaryTable } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:1786` |\n| `formatGitHubHousekeeperPlan` | function: function formatGitHubHousekeeperPlan(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { formatGitHubHousekeeperPlan } from \"@kungfu-tech/buildchain/core\";` | `packages/core/engineering-housekeeper-github.js:697` |\n| `formatReleaseLineDryRun` | function: function formatReleaseLineDryRun(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { formatReleaseLineDryRun } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-line-dry-run.js:267` |\n| `getLifecycleStage` | function: function getLifecycleStage(loadedConfig, name) | loadedConfig, name | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { getLifecycleStage } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-config.js:1367` |\n| `getNativeDiagnosticsProfile` | function: function getNativeDiagnosticsProfile(loadedConfig) | loadedConfig | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { getNativeDiagnosticsProfile } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-config.js:520` |\n| `getPublishContract` | function: function getPublishContract(loadedConfig) | loadedConfig | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { getPublishContract } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-config.js:1371` |\n| `getStableReleasePolicy` | function: function getStableReleasePolicy(loadedConfig) | loadedConfig | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { getStableReleasePolicy } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-config.js:328` |\n| `getVersionStrategy` | function: function getVersionStrategy(loadedConfig) | loadedConfig | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { getVersionStrategy } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-config.js:1495` |\n| `getWorkspaceInfo` | function: function getWorkspaceInfo(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { getWorkspaceInfo } from \"@kungfu-tech/buildchain/core\";` | `packages/core/package-manager.js:211` |\n| `GITHUB_ARTIFACT_ATTESTATION_EVIDENCE_CONTRACT` | constant: const GITHUB_ARTIFACT_ATTESTATION_EVIDENCE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_ARTIFACT_ATTESTATION_EVIDENCE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-artifact-attestation.js:9` |\n| `GITHUB_ARTIFACT_ATTESTATION_POLICY_CONTRACT` | constant: const GITHUB_ARTIFACT_ATTESTATION_POLICY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_ARTIFACT_ATTESTATION_POLICY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-artifact-attestation.js:5` |\n| `GITHUB_ARTIFACT_ATTESTATION_PREDICATE_CONTRACT` | constant: const GITHUB_ARTIFACT_ATTESTATION_PREDICATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_ARTIFACT_ATTESTATION_PREDICATE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-artifact-attestation.js:7` |\n| `GITHUB_ARTIFACT_ATTESTATION_PREDICATE_TYPE` | constant: const GITHUB_ARTIFACT_ATTESTATION_PREDICATE_TYPE | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_ARTIFACT_ATTESTATION_PREDICATE_TYPE } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-artifact-attestation.js:13` |\n| `GITHUB_ARTIFACT_ATTESTATION_VERIFICATION_CONTRACT` | constant: const GITHUB_ARTIFACT_ATTESTATION_VERIFICATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_ARTIFACT_ATTESTATION_VERIFICATION_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-artifact-attestation.js:11` |\n| `GITHUB_ARTIFACT_ATTESTATION_WORKFLOW` | constant: const GITHUB_ARTIFACT_ATTESTATION_WORKFLOW | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_ARTIFACT_ATTESTATION_WORKFLOW } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-artifact-attestation.js:15` |\n| `GITHUB_GOVERNANCE_AUTHORITY_CONTRACT` | constant: const GITHUB_GOVERNANCE_AUTHORITY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_GOVERNANCE_AUTHORITY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-governance-authority.js:3` |\n| `GITHUB_GOVERNANCE_RECEIPT_CONTRACT` | constant: const GITHUB_GOVERNANCE_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_GOVERNANCE_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-governance-authority.js:5` |\n| `GITHUB_GOVERNANCE_ROLLOUT_CONTRACT` | constant: const GITHUB_GOVERNANCE_ROLLOUT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_GOVERNANCE_ROLLOUT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-governance-authority.js:7` |\n| `GITHUB_GOVERNANCE_RULESET_ROLLOUT_CONTRACT` | constant: const GITHUB_GOVERNANCE_RULESET_ROLLOUT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_GOVERNANCE_RULESET_ROLLOUT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-governance-authority.js:9` |\n| `githubArtifactAttestationRequiredPermissions` | function: function githubArtifactAttestationRequiredPermissions() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { githubArtifactAttestationRequiredPermissions } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-artifact-attestation.js:640` |\n| `githubArtifactAttestationSemanticRoot` | function: function githubArtifactAttestationSemanticRoot(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { githubArtifactAttestationSemanticRoot } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-artifact-attestation.js:91` |\n| `githubArtifactAttestationSha256Buffer` | function: function githubArtifactAttestationSha256Buffer(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { githubArtifactAttestationSha256Buffer } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-artifact-attestation.js:83` |\n| `githubArtifactAttestationSha256File` | function: function githubArtifactAttestationSha256File(filePath) | filePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { githubArtifactAttestationSha256File } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-artifact-attestation.js:87` |\n| `githubGovernanceDigest` | function: function githubGovernanceDigest(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { githubGovernanceDigest } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-governance-authority.js:165` |\n| `GitHubHousekeeperClient` | class: class GitHubHousekeeperClient | none | GitHubHousekeeperClient | Construction and method errors follow the linked source implementation. | class-dependent | `import { GitHubHousekeeperClient } from \"@kungfu-tech/buildchain/core\";` | `packages/core/engineering-housekeeper-github-client.js:54` |\n| `GitHubHousekeeperProviderError` | class: class GitHubHousekeeperProviderError | none | GitHubHousekeeperProviderError | Construction and method errors follow the linked source implementation. | class-dependent | `import { GitHubHousekeeperProviderError } from \"@kungfu-tech/buildchain/core\";` | `packages/core/engineering-housekeeper-github-client.js:37` |\n| `GitHubIssueRequestError` | class: class GitHubIssueRequestError | none | GitHubIssueRequestError | Construction and method errors follow the linked source implementation. | class-dependent | `import { GitHubIssueRequestError } from \"@kungfu-tech/buildchain/core\";` | `packages/core/issue-reporting.js:23` |\n| `githubReleaseAssetsTargetRoot` | function: function githubReleaseAssetsTargetRoot({ destination, artifacts }) | { destination, artifacts } | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { githubReleaseAssetsTargetRoot } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-adapters.js:297` |\n| `HOMEBREW_TAP_CHECK_CONTRACT` | constant: const HOMEBREW_TAP_CHECK_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { HOMEBREW_TAP_CHECK_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/homebrew.js:6` |\n| `HOMEBREW_TAP_FACTS_CONTRACT` | constant: const HOMEBREW_TAP_FACTS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { HOMEBREW_TAP_FACTS_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/homebrew.js:5` |\n| `HOMEBREW_TAP_MANIFEST_CONTRACT` | constant: const HOMEBREW_TAP_MANIFEST_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { HOMEBREW_TAP_MANIFEST_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/homebrew.js:7` |\n| `HOUSEKEEPER_REASON_CODES` | constant: const HOUSEKEEPER_REASON_CODES | none | value | Import does not declare a throw contract. | none-on-import | `import { HOUSEKEEPER_REASON_CODES } from \"@kungfu-tech/buildchain/core\";` | `packages/core/engineering-housekeeper.js:7` |\n| `IMPACT_LEDGER_CONTRACT` | constant: const IMPACT_LEDGER_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { IMPACT_LEDGER_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport.js:39` |\n| `initKfdAgentHub` | function: function initKfdAgentHub({ cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, write = false, force = false } = {}) | { cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, write = false, force = false } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { initKfdAgentHub } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-agent-hub.js:363` |\n| `inspectKfdAgentHub` | function: function inspectKfdAgentHub({ cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, kfdRoot = \"\" } = {}) | { cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, kfdRoot = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { inspectKfdAgentHub } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-agent-hub.js:384` |\n| `inspectReleasePropagationPushState` | function: function inspectReleasePropagationPushState({ work: workInput, cwd = process.cwd(), remote = \"origin\", } = {}) | { work: workInput, cwd = process.cwd(), remote = \"origin\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | subprocess | `import { inspectReleasePropagationPushState } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-push.js:174` |\n| `installedKfdPackageArtifactRoot` | function: function installedKfdPackageArtifactRoot() | none | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { installedKfdPackageArtifactRoot } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-verification-envelope.js:397` |\n| `KFD_ADOPTER_RELEASE_BINDING_CONTRACT` | constant: const KFD_ADOPTER_RELEASE_BINDING_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_ADOPTER_RELEASE_BINDING_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-verification-envelope.js:16` |\n| `KFD_AGENT_HUB_ADOPTION_CONTRACT` | constant: const KFD_AGENT_HUB_ADOPTION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_AGENT_HUB_ADOPTION_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-agent-hub.js:9` |\n| `KFD_AGENT_HUB_ADOPTION_SCHEMA` | constant: const KFD_AGENT_HUB_ADOPTION_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_AGENT_HUB_ADOPTION_SCHEMA } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-agent-hub.js:12` |\n| `KFD_AGENT_HUB_DECLARATION` | constant: const KFD_AGENT_HUB_DECLARATION | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_AGENT_HUB_DECLARATION } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-agent-hub.js:7` |\n| `KFD_AGENT_HUB_LOCK_CONTRACT` | constant: const KFD_AGENT_HUB_LOCK_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_AGENT_HUB_LOCK_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-agent-hub.js:10` |\n| `KFD_AGENT_HUB_OUTPUT_DIR` | constant: const KFD_AGENT_HUB_OUTPUT_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_AGENT_HUB_OUTPUT_DIR } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-agent-hub.js:8` |\n| `KFD_AGENT_HUB_VERIFICATION_CONTRACT` | constant: const KFD_AGENT_HUB_VERIFICATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_AGENT_HUB_VERIFICATION_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-agent-hub.js:11` |\n| `KFD_PRODUCT_GATE_CONTRACT` | constant: const KFD_PRODUCT_GATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_PRODUCT_GATE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-product-gates.js:11` |\n| `KFD_PRODUCT_GATE_INPUT_CONTRACT` | constant: const KFD_PRODUCT_GATE_INPUT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_PRODUCT_GATE_INPUT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-product-gates.js:9` |\n| `KFD_PRODUCT_GATE_INPUT_SCHEMA` | constant: const KFD_PRODUCT_GATE_INPUT_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_PRODUCT_GATE_INPUT_SCHEMA } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-product-gates.js:51` |\n| `KFD_PRODUCT_GATE_INPUT_SCHEMA_ID` | constant: const KFD_PRODUCT_GATE_INPUT_SCHEMA_ID | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_PRODUCT_GATE_INPUT_SCHEMA_ID } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-product-gates.js:13` |\n| `kfd1` | constant: const kfd1 | none | value | Import does not declare a throw contract. | none-on-import | `import { kfd1 } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd.js:546` |\n| `KFD1_RELEASE_GATE_CONTRACT` | constant: const KFD1_RELEASE_GATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD1_RELEASE_GATE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-gate.js:9` |\n| `KFD1_WITNESS_SET_CONTRACT` | constant: const KFD1_WITNESS_SET_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD1_WITNESS_SET_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-gate.js:10` |\n| `kfd2` | constant: const kfd2 | none | value | Import does not declare a throw contract. | none-on-import | `import { kfd2 } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd.js:561` |\n| `KFD2_PRODUCT_CLAIMS_OUTPUT_CONTRACT` | constant: const KFD2_PRODUCT_CLAIMS_OUTPUT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD2_PRODUCT_CLAIMS_OUTPUT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd2-product-claims.js:23` |\n| `KFD2_PRODUCT_CLAIMS_REGISTRY_CONTRACT` | constant: const KFD2_PRODUCT_CLAIMS_REGISTRY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD2_PRODUCT_CLAIMS_REGISTRY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd2-product-claims.js:19` |\n| `KFD2_PRODUCT_CLAIMS_VALIDATION_CONTRACT` | constant: const KFD2_PRODUCT_CLAIMS_VALIDATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD2_PRODUCT_CLAIMS_VALIDATION_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd2-product-claims.js:21` |\n| `KFD2_RELEASE_TRUST_PASSPORT_CONTRACT` | constant: const KFD2_RELEASE_TRUST_PASSPORT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD2_RELEASE_TRUST_PASSPORT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport.js:43` |\n| `KFD2_TRUST_PROOF_CONTRACT` | constant: const KFD2_TRUST_PROOF_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD2_TRUST_PROOF_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport.js:44` |\n| `kfd3` | constant: const kfd3 | none | value | Import does not declare a throw contract. | none-on-import | `import { kfd3 } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd.js:663` |\n| `KFD3_ARTIFACT_WITNESS_CONTRACT` | constant: const KFD3_ARTIFACT_WITNESS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD3_ARTIFACT_WITNESS_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-gate.js:13` |\n| `KFD3_CAPABILITY_QUERY_CONTRACT` | constant: const KFD3_CAPABILITY_QUERY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD3_CAPABILITY_QUERY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd3-surface-register.js:9` |\n| `KFD3_DEFAULT_REGISTRY_PATH` | constant: const KFD3_DEFAULT_REGISTRY_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD3_DEFAULT_REGISTRY_PATH } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd3-surface-register.js:10` |\n| `KFD3_PREBUILD_WITNESS_CONTRACT` | constant: const KFD3_PREBUILD_WITNESS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD3_PREBUILD_WITNESS_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-gate.js:12` |\n| `KFD3_RELEASE_GATE_CONTRACT` | constant: const KFD3_RELEASE_GATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD3_RELEASE_GATE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-gate.js:11` |\n| `KFD3_SURFACE_AUDIT_CONTRACT` | constant: const KFD3_SURFACE_AUDIT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD3_SURFACE_AUDIT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd3-surface-register.js:8` |\n| `KFD3_SURFACE_DETECTION_CONTRACT` | constant: const KFD3_SURFACE_DETECTION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD3_SURFACE_DETECTION_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd3-surface-register.js:7` |\n| `KFD3_SURFACE_REGISTRY_CONTRACT` | constant: const KFD3_SURFACE_REGISTRY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD3_SURFACE_REGISTRY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd3-surface-register.js:6` |\n| `kfd4` | constant: const kfd4 | none | value | Import does not declare a throw contract. | none-on-import | `import { kfd4 } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd.js:681` |\n| `kfdProductGateDigest` | function: function kfdProductGateDigest(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { kfdProductGateDigest } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-product-gates.js:142` |\n| `kfdProductGates` | constant: const kfdProductGates | none | value | Import does not declare a throw contract. | none-on-import | `import { kfdProductGates } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-product-gates.js:561` |\n| `KFX_ADMISSION_INPUTS_CONTRACT` | constant: const KFX_ADMISSION_INPUTS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFX_ADMISSION_INPUTS_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-verification-envelope.js:14` |\n| `layout` | constant: const layout | none | value | Import does not declare a throw contract. | none-on-import | `import { layout } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd.js:905` |\n| `LEGACY_BUILDCHAIN_CONFIG_PATH` | constant: const LEGACY_BUILDCHAIN_CONFIG_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { LEGACY_BUILDCHAIN_CONFIG_PATH } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:8` |\n| `LEGACY_BUILDCHAIN_CONTRACT_LOCK_PATH` | constant: const LEGACY_BUILDCHAIN_CONTRACT_LOCK_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { LEGACY_BUILDCHAIN_CONTRACT_LOCK_PATH } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:10` |\n| `LEGACY_BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATH` | constant: const LEGACY_BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { LEGACY_BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATH } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:28` |\n| `LEGACY_BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATHS` | constant: const LEGACY_BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATHS | none | value | Import does not declare a throw contract. | none-on-import | `import { LEGACY_BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATHS } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:29` |\n| `LEGACY_BUILDCHAIN_RELEASE_PASSPORT_PATH` | constant: const LEGACY_BUILDCHAIN_RELEASE_PASSPORT_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { LEGACY_BUILDCHAIN_RELEASE_PASSPORT_PATH } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:34` |\n| `listArtifactSigningProfiles` | function: function listArtifactSigningProfiles() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { listArtifactSigningProfiles } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-signing.js:103` |\n| `listKfdSchemas` | function: function listKfdSchemas({ standard = \"\" } = {}) | { standard = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { listKfdSchemas } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd.js:492` |\n| `loadBuildchainConfig` | function: function loadBuildchainConfig(cwd = process.cwd()) | cwd = process.cwd() | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { loadBuildchainConfig } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-config.js:158` |\n| `loadConfiguredAnchorManifest` | function: function loadConfiguredAnchorManifest(cwd = process.cwd(), loadedConfig = loadBuildchainConfig(cwd)) | cwd = process.cwd(), loadedConfig = loadBuildchainConfig(cwd) | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { loadConfiguredAnchorManifest } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-config.js:1504` |\n| `makeReleasePassportFixtureAssets` | function: function makeReleasePassportFixtureAssets(dir) | dir | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write | `import { makeReleasePassportFixtureAssets } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport.js:2738` |\n| `MANUAL_UPSTREAM_PICKUP_CONFIG_CONTRACT` | constant: const MANUAL_UPSTREAM_PICKUP_CONFIG_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { MANUAL_UPSTREAM_PICKUP_CONFIG_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-pickup.js:16` |\n| `MANUAL_UPSTREAM_PICKUP_PLAN_CONTRACT` | constant: const MANUAL_UPSTREAM_PICKUP_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { MANUAL_UPSTREAM_PICKUP_PLAN_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-pickup.js:18` |\n| `markStableCandidatePromoted` | function: function markStableCandidatePromoted(ledgerInput, versionInput, { stableTag = \"\", stableSha = \"\", now = new Date().toISOString() } = {}) | ledgerInput, versionInput, { stableTag = \"\", stableSha = \"\", now = new Date().toISOString() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { markStableCandidatePromoted } from \"@kungfu-tech/buildchain/core\";` | `packages/core/stable-candidate-ledger.js:229` |\n| `migrateBuildchainLayout` | function: function migrateBuildchainLayout({ cwd = process.cwd(), write = false, force = false } = {}) | { cwd = process.cwd(), write = false, force = false } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { migrateBuildchainLayout } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:287` |\n| `normalizeBuildchainConfig` | function: function normalizeBuildchainConfig(config) | config | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeBuildchainConfig } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-config.js:181` |\n| `normalizeBuildchainLogEvent` | function: function normalizeBuildchainLogEvent(input = {}, defaults = {}) | input = {}, defaults = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { normalizeBuildchainLogEvent } from \"@kungfu-tech/buildchain/core\";` | `packages/core/logging.js:45` |\n| `normalizeCandidateTimelineEvent` | function: function normalizeCandidateTimelineEvent(input = {}) | input = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeCandidateTimelineEvent } from \"@kungfu-tech/buildchain/core\";` | `packages/core/candidate-timeline.js:74` |\n| `normalizeControllerReceiptReferences` | function: function normalizeControllerReceiptReferences({ receipts = [], references = [], expectedSourceSha = \"\", acceptedSourceShas = [], expectedRuntimeSha = \"\", requirePassed = false, } = {}) | { receipts = [], references = [], expectedSourceSha = \"\", acceptedSourceShas = [], expectedRuntimeSha = \"\", requirePassed = false, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeControllerReceiptReferences } from \"@kungfu-tech/buildchain/core\";` | `packages/core/controller-evidence.js:532` |\n| `normalizeGitHubArtifactAttestationPolicy` | function: function normalizeGitHubArtifactAttestationPolicy(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeGitHubArtifactAttestationPolicy } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-artifact-attestation.js:158` |\n| `normalizeGithubBranchProtectionSnapshot` | function: function normalizeGithubBranchProtectionSnapshot(protection = {}) | protection = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { normalizeGithubBranchProtectionSnapshot } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-governance-authority.js:1027` |\n| `normalizeGithubRulesetSnapshot` | function: function normalizeGithubRulesetSnapshot(ruleset = {}) | ruleset = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { normalizeGithubRulesetSnapshot } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-governance-authority.js:1097` |\n| `normalizeIssueRepository` | function: function normalizeIssueRepository(repository = DEFAULT_BUILDCHAIN_ISSUE_REPOSITORY) | repository = DEFAULT_BUILDCHAIN_ISSUE_REPOSITORY | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeIssueRepository } from \"@kungfu-tech/buildchain/core\";` | `packages/core/issue-reporting.js:33` |\n| `normalizeKfd1ContractWorldWitness` | function: function normalizeKfd1ContractWorldWitness(witness, { metadata = resolveKfd1Metadata() } = {}) | witness, { metadata = resolveKfd1Metadata() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeKfd1ContractWorldWitness } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-gate.js:897` |\n| `normalizeKfd3CollaborationInterfaceArtifactWitness` | function: function normalizeKfd3CollaborationInterfaceArtifactWitness(witness, { metadata = resolveKfd3Metadata() } = {}) | witness, { metadata = resolveKfd3Metadata() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeKfd3CollaborationInterfaceArtifactWitness } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-gate.js:738` |\n| `normalizeKfd3CollaborationInterfacePrebuildWitness` | function: function normalizeKfd3CollaborationInterfacePrebuildWitness(witness, { metadata = resolveKfd3Metadata() } = {}) | witness, { metadata = resolveKfd3Metadata() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeKfd3CollaborationInterfacePrebuildWitness } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-gate.js:667` |\n| `normalizeKfd3DistributionDeclaration` | function: function normalizeKfd3DistributionDeclaration(distribution, { surfaceId = \"surface\" } = {}) | distribution, { surfaceId = \"surface\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeKfd3DistributionDeclaration } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd3-surface-register.js:73` |\n| `normalizeKfdStandardId` | function: function normalizeKfdStandardId(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeKfdStandardId } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd.js:455` |\n| `normalizeLifecycleStage` | function: function normalizeLifecycleStage(stage, label = \"lifecycle stage\", lifecycle = {}) | stage, label = \"lifecycle stage\", lifecycle = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeLifecycleStage } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-config.js:1328` |\n| `normalizeManualUpstreamPickupConfig` | function: function normalizeManualUpstreamPickupConfig(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeManualUpstreamPickupConfig } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-pickup.js:118` |\n| `normalizePackageReleasePropagationConfig` | function: function normalizePackageReleasePropagationConfig(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizePackageReleasePropagationConfig } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-capture.js:63` |\n| `normalizeReleasePropagationGraph` | function: function normalizeReleasePropagationGraph(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeReleasePropagationGraph } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation.js:163` |\n| `normalizeSiteUpstreamIntent` | function: function normalizeSiteUpstreamIntent(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeSiteUpstreamIntent } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-agent-entry.js:77` |\n| `normalizeStableCandidateLedger` | function: function normalizeStableCandidateLedger(input, expected = {}) | input, expected = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeStableCandidateLedger } from \"@kungfu-tech/buildchain/core\";` | `packages/core/stable-candidate-ledger.js:76` |\n| `PACKAGE_RELEASE_PROPAGATION_CONFIG_CONTRACT` | constant: const PACKAGE_RELEASE_PROPAGATION_CONFIG_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PACKAGE_RELEASE_PROPAGATION_CONFIG_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-capture.js:17` |\n| `PAPER_ALPHA_PLAN_CONTRACT` | constant: const PAPER_ALPHA_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_ALPHA_PLAN_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper.js:90` |\n| `PAPER_BUILD_PLAN_CONTRACT` | constant: const PAPER_BUILD_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_BUILD_PLAN_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper.js:89` |\n| `PAPER_FLEET_AUDIT_CONTRACT` | constant: const PAPER_FLEET_AUDIT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_FLEET_AUDIT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper-fleet.js:19` |\n| `PAPER_FLEET_UPDATE_PLAN_CONTRACT` | constant: const PAPER_FLEET_UPDATE_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_FLEET_UPDATE_PLAN_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper-fleet.js:20` |\n| `PAPER_MIGRATION_CONTRACT` | constant: const PAPER_MIGRATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_MIGRATION_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper.js:82` |\n| `PAPER_NPM_BOOTSTRAP_CONTRACT` | constant: const PAPER_NPM_BOOTSTRAP_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_NPM_BOOTSTRAP_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper.js:85` |\n| `PAPER_PATHS` | constant: const PAPER_PATHS | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_PATHS } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper-repository.js:7` |\n| `PAPER_PREFLIGHT_CONTRACT` | constant: const PAPER_PREFLIGHT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_PREFLIGHT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper.js:83` |\n| `PAPER_RESUME_PLAN_CONTRACT` | constant: const PAPER_RESUME_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_RESUME_PLAN_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper.js:91` |\n| `PAPER_SCAFFOLD_CONTRACT` | constant: const PAPER_SCAFFOLD_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_SCAFFOLD_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper.js:81` |\n| `PAPER_STATE_ORDER` | constant: const PAPER_STATE_ORDER | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_STATE_ORDER } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper.js:94` |\n| `PAPER_STATUS_CONTRACT` | constant: const PAPER_STATUS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_STATUS_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper.js:84` |\n| `PAPER_VISIBILITY_CONTRACT` | constant: const PAPER_VISIBILITY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_VISIBILITY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper.js:92` |\n| `PAPER_WORK_START_PLAN_CONTRACT` | constant: const PAPER_WORK_START_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_WORK_START_PLAN_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper-work.js:17` |\n| `PAPER_WORK_SUBMIT_PLAN_CONTRACT` | constant: const PAPER_WORK_SUBMIT_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_WORK_SUBMIT_PLAN_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper-work.js:19` |\n| `paperFleetTransitionWorkspace` | function: function paperFleetTransitionWorkspace(workspaceText, lockText) | workspaceText, lockText | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { paperFleetTransitionWorkspace } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper-fleet.js:290` |\n| `parseCodeowners` | function: function parseCodeowners(source) | source | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { parseCodeowners } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-governance-authority.js:403` |\n| `parseIssueLabels` | function: function parseIssueLabels(input = DEFAULT_LABELS) | input = DEFAULT_LABELS | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { parseIssueLabels } from \"@kungfu-tech/buildchain/core\";` | `packages/core/issue-reporting.js:41` |\n| `parseReleaseTailDeclaration` | function: function parseReleaseTailDeclaration(input) | input | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { parseReleaseTailDeclaration } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-plane.js:491` |\n| `planBuildchainLayoutMigration` | function: function planBuildchainLayoutMigration({ cwd = process.cwd() } = {}) | { cwd = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { planBuildchainLayoutMigration } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:265` |\n| `planPaperFleetUpdate` | function: function planPaperFleetUpdate(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { planPaperFleetUpdate } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper-fleet.js:209` |\n| `planPaperMigration` | function: function planPaperMigration({ cwd = process.cwd(), buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainSha = \"\", } = {}) | { cwd = process.cwd(), buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainSha = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { planPaperMigration } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper.js:1013` |\n| `planPaperScaffold` | function: function planPaperScaffold({ cwd = process.cwd(), buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainRef = \"v3\", buildchainSha = \"\", name = path.basename(path.resolve(cwd)), title = \"\", packageName = \"\", repository = \"\", version = \"0.1.0-alpha.0\", siteBaseUrl = \"\", } = {}) | { cwd = process.cwd(), buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainRef = \"v3\", buildchainSha = \"\", name = path.basename(path.resolve(cwd)), title = \"\", packageName = \"\", repository = \"\", version = \"0.1.0-alpha.0\", siteBaseUrl = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { planPaperScaffold } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper.js:702` |\n| `planReleaseLineBootstrap` | function: function planReleaseLineBootstrap({ cwd = process.cwd(), major, minor, sourceRef = \"\", initialVersion = \"\", requiredStatusCheck = \"check\", setDefault = true, createAlphaPr = true, approvalCount = 1, bootstrapBranch = \"\", } = {}) | { cwd = process.cwd(), major, minor, sourceRef = \"\", initialVersion = \"\", requiredStatusCheck = \"check\", setDefault = true, createAlphaPr = true, approvalCount = 1, bootstrapBranch = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { planReleaseLineBootstrap } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-line-bootstrap.js:153` |\n| `planReleasePropagation` | function: function planReleasePropagation({ graph: graphInput, upstreamRelease: releaseInput, sourceNode = \"\" } = {}) | { graph: graphInput, upstreamRelease: releaseInput, sourceNode = \"\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { planReleasePropagation } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation.js:249` |\n| `planSiteUpstreamAgentEntry` | function: function planSiteUpstreamAgentEntry({ sourceId: sourceInput, channel = \"\", handoffWork = null, } = {}) | { sourceId: sourceInput, channel = \"\", handoffWork = null, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { planSiteUpstreamAgentEntry } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-agent-entry.js:134` |\n| `planTransactionRecovery` | function: function planTransactionRecovery({ transaction, evidence, validation, explicitOverride = false, } = {}) | { transaction, evidence, validation, explicitOverride = false, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { planTransactionRecovery } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publish-transaction.js:769` |\n| `prepareGitHubArtifactAttestation` | function: function prepareGitHubArtifactAttestation({ subjectPath, platformManifestPath, releasePassportPath, policy, expectedBuildchainRef = \"\", expectedCallerRepository = \"\", expectedSourceSha = \"\", } = {}) | { subjectPath, platformManifestPath, releasePassportPath, policy, expectedBuildchainRef = \"\", expectedCallerRepository = \"\", expectedSourceSha = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { prepareGitHubArtifactAttestation } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-artifact-attestation.js:250` |\n| `preparePublicationNpmPackage` | function: function preparePublicationNpmPackage({ cwd = process.cwd(), outputDir = \".buildchain/publication/npm-package\", packageName = \"\", } = {}) | { cwd = process.cwd(), outputDir = \".buildchain/publication/npm-package\", packageName = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { preparePublicationNpmPackage } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-package.js:120` |\n| `PRODUCT_MECHANISM_CONTRACT` | constant: const PRODUCT_MECHANISM_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PRODUCT_MECHANISM_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport.js:41` |\n| `projectArtifactVerificationEnvelopeToKfx` | function: function projectArtifactVerificationEnvelopeToKfx({ envelope, assessmentTime = Math.floor(Date.now() / 1000), expectedEnvelopeRoot = \"\", expectedIssuer = \"\", expectedPublisher = \"\", expectedContractVersion = \"\", } = {}) | { envelope, assessmentTime = Math.floor(Date.now() / 1000), expectedEnvelopeRoot = \"\", expectedIssuer = \"\", expectedPublisher = \"\", expectedContractVersion = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { projectArtifactVerificationEnvelopeToKfx } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-verification-envelope.js:368` |\n| `PUBLICATION_ADMISSION_CONTRACT` | constant: const PUBLICATION_ADMISSION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_ADMISSION_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:10` |\n| `PUBLICATION_ARTIFACT_ARCHIVE_CONTRACT` | constant: const PUBLICATION_ARTIFACT_ARCHIVE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_ARTIFACT_ARCHIVE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-artifact.js:9` |\n| `PUBLICATION_ARTIFACT_CANDIDATE_CONTRACT` | constant: const PUBLICATION_ARTIFACT_CANDIDATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_ARTIFACT_CANDIDATE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-artifact-candidate.js:5` |\n| `PUBLICATION_ARTIFACT_MANIFEST_CONTRACT` | constant: const PUBLICATION_ARTIFACT_MANIFEST_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_ARTIFACT_MANIFEST_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-artifact.js:7` |\n| `PUBLICATION_ARTIFACT_MANIFEST_SET_CONTRACT` | constant: const PUBLICATION_ARTIFACT_MANIFEST_SET_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_ARTIFACT_MANIFEST_SET_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:24` |\n| `PUBLICATION_ARTIFACT_PASSPORT_CONTRACT` | constant: const PUBLICATION_ARTIFACT_PASSPORT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_ARTIFACT_PASSPORT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-artifact.js:8` |\n| `PUBLICATION_ARTIFACT_REGISTRY_CONTRACT` | constant: const PUBLICATION_ARTIFACT_REGISTRY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_ARTIFACT_REGISTRY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-artifact.js:10` |\n| `PUBLICATION_AUTHORITY_CLASSES` | constant: const PUBLICATION_AUTHORITY_CLASSES | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_AUTHORITY_CLASSES } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:27` |\n| `PUBLICATION_AUTHORITY_REGISTRY_CONTRACT` | constant: const PUBLICATION_AUTHORITY_REGISTRY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_AUTHORITY_REGISTRY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:8` |\n| `PUBLICATION_CAPABILITY_CONTRACT` | constant: const PUBLICATION_CAPABILITY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_CAPABILITY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:12` |\n| `PUBLICATION_CONTROL_PLANE_AUDIT_CONTRACT` | constant: const PUBLICATION_CONTROL_PLANE_AUDIT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_CONTROL_PLANE_AUDIT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:16` |\n| `PUBLICATION_GATE_DECISION_CONTRACT` | constant: const PUBLICATION_GATE_DECISION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_GATE_DECISION_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:18` |\n| `PUBLICATION_NPM_PACKAGE_CONTRACT` | constant: const PUBLICATION_NPM_PACKAGE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_NPM_PACKAGE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-package.js:6` |\n| `PUBLICATION_QUALIFICATION_RECEIPT_CONTRACT` | constant: const PUBLICATION_QUALIFICATION_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_QUALIFICATION_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:22` |\n| `PUBLICATION_REPRODUCIBILITY_RECEIPT_CONTRACT` | constant: const PUBLICATION_REPRODUCIBILITY_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_REPRODUCIBILITY_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-reproducibility.js:12` |\n| `PUBLICATION_SEALED_BUNDLE_CONTRACT` | constant: const PUBLICATION_SEALED_BUNDLE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_SEALED_BUNDLE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-sealed-bundle.js:10` |\n| `publicationArtifactCandidateDigest` | function: function publicationArtifactCandidateDigest(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { publicationArtifactCandidateDigest } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-artifact-candidate.js:19` |\n| `publicationAuthorityDigest` | function: function publicationAuthorityDigest(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { publicationAuthorityDigest } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:72` |\n| `publicationGateAggregateBindings` | function: function publicationGateAggregateBindings(gateAggregate) | gateAggregate | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { publicationGateAggregateBindings } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:408` |\n| `qualifyStableCandidate` | function: function qualifyStableCandidate(ledgerInput, observation, { minimumSoakSeconds = 3600, now = new Date().toISOString() } = {}) | ledgerInput, observation, { minimumSoakSeconds = 3600, now = new Date().toISOString() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { qualifyStableCandidate } from \"@kungfu-tech/buildchain/core\";` | `packages/core/stable-candidate-ledger.js:139` |\n| `queryKfd3Capabilities` | function: async function queryKfd3Capabilities({ cwd = process.cwd(), product = \"\", registryPath = \"\", passportLocation = \"\", artifactPath = \"\", } = {}) | { cwd = process.cwd(), product = \"\", registryPath = \"\", passportLocation = \"\", artifactPath = \"\", } = {} | Promise<unknown> | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { queryKfd3Capabilities } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd3-surface-register.js:824` |\n| `readBuildchainContractLock` | function: function readBuildchainContractLock(filePath) | filePath | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readBuildchainContractLock } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-contract.js:881` |\n| `readBuildchainContractWorld` | function: function readBuildchainContractWorld(filePath) | filePath | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readBuildchainContractWorld } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-contract.js:861` |\n| `readBuildchainLogEvents` | function: function readBuildchainLogEvents(filePath) | filePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { readBuildchainLogEvents } from \"@kungfu-tech/buildchain/core\";` | `packages/core/logging.js:75` |\n| `readDiagnosticsArtifact` | function: function readDiagnosticsArtifact(filePath) | filePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { readDiagnosticsArtifact } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:1468` |\n| `readJsonFromLocation` | function: async function readJsonFromLocation(location, redirectCount = 0, { timeoutMs = 15_000 } = {}) | location, redirectCount = 0, { timeoutMs = 15_000 } = {} | Promise<unknown> | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readJsonFromLocation } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport.js:2625` |\n| `readKfd2ProductClaimsRegistry` | function: function readKfd2ProductClaimsRegistry({ cwd = process.cwd(), registryPath = BUILDCHAIN_KFD2_REGISTRY_PATH, } = {}) | { cwd = process.cwd(), registryPath = BUILDCHAIN_KFD2_REGISTRY_PATH, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readKfd2ProductClaimsRegistry } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd2-product-claims.js:137` |\n| `readKfd3SurfaceRegistry` | function: function readKfd3SurfaceRegistry({ cwd = process.cwd(), registryPath = \"\" } = {}) | { cwd = process.cwd(), registryPath = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { readKfd3SurfaceRegistry } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd3-surface-register.js:455` |\n| `readKfdSchema` | function: function readKfdSchema({ standard, schema = \"\" } = {}) | { standard, schema = \"\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readKfdSchema } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd.js:520` |\n| `README_BADGE_BLOCK_END` | constant: const README_BADGE_BLOCK_END | none | value | Import does not declare a throw contract. | none-on-import | `import { README_BADGE_BLOCK_END } from \"@kungfu-tech/buildchain/core\";` | `packages/core/readme-badges.js:15` |\n| `README_BADGE_BLOCK_START` | constant: const README_BADGE_BLOCK_START | none | value | Import does not declare a throw contract. | none-on-import | `import { README_BADGE_BLOCK_START } from \"@kungfu-tech/buildchain/core\";` | `packages/core/readme-badges.js:14` |\n| `README_BADGE_FACTS_CONTRACT` | constant: const README_BADGE_FACTS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { README_BADGE_FACTS_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/readme-badges.js:12` |\n| `README_BADGE_HOSTED_BASE_URL` | constant: const README_BADGE_HOSTED_BASE_URL | none | value | Import does not declare a throw contract. | none-on-import | `import { README_BADGE_HOSTED_BASE_URL } from \"@kungfu-tech/buildchain/core\";` | `packages/core/readme-badges.js:16` |\n| `readOptionalIssueBodyFile` | function: function readOptionalIssueBodyFile(filePath) | filePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { readOptionalIssueBodyFile } from \"@kungfu-tech/buildchain/core\";` | `packages/core/issue-reporting.js:385` |\n| `readPublishEvidence` | function: function readPublishEvidence(filePath) | filePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { readPublishEvidence } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publish-transaction.js:564` |\n| `readReadme` | function: function readReadme({ cwd = process.cwd(), readmePath = \"README.md\" } = {}) | { cwd = process.cwd(), readmePath = \"README.md\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { readReadme } from \"@kungfu-tech/buildchain/core\";` | `packages/core/readme-badges.js:891` |\n| `readReleasePropagationJson` | function: function readReleasePropagationJson(value, { cwd = process.cwd(), label = \"json\" } = {}) | value, { cwd = process.cwd(), label = \"json\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readReleasePropagationJson } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation.js:305` |\n| `readReleaseTailTransaction` | function: function readReleaseTailTransaction(filePath) | filePath | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readReleaseTailTransaction } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-plane.js:830` |\n| `readReleaseTransaction` | function: function readReleaseTransaction(filePath) | filePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { readReleaseTransaction } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publish-transaction.js:367` |\n| `recordReleaseActivationPhase` | function: function recordReleaseActivationPhase(transaction, phaseId, { receiptRoots = [], failure = \"\" } = {}) | transaction, phaseId, { receiptRoots = [], failure = \"\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { recordReleaseActivationPhase } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-activation-transaction.js:217` |\n| `recordReleasePropagationStage` | function: function recordReleasePropagationStage({ work, expectedWorkRoot, receipt } = {}) | { work, expectedWorkRoot, receipt } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { recordReleasePropagationStage } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-work-transitions.js:45` |\n| `recoveryFailure` | function: function recoveryFailure(error) | error | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { recoveryFailure } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-candidate-recovery.js:529` |\n| `redactBuildchainLogAttributes` | function: function redactBuildchainLogAttributes(attributes = {}) | attributes = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { redactBuildchainLogAttributes } from \"@kungfu-tech/buildchain/core\";` | `packages/core/logging.js:33` |\n| `redactDiagnosticsValue` | function: function redactDiagnosticsValue(key, value, pattern = DEFAULT_SECRET_KEY_PATTERN) | key, value, pattern = DEFAULT_SECRET_KEY_PATTERN | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { redactDiagnosticsValue } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:953` |\n| `redactIssueText` | function: function redactIssueText(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { redactIssueText } from \"@kungfu-tech/buildchain/core\";` | `packages/core/issue-reporting.js:51` |\n| `registerKfd3Surfaces` | function: function registerKfd3Surfaces({ cwd = process.cwd(), registryPath = \"\", kinds = [], artifactPath = \"\", product = {}, } = {}) | { cwd = process.cwd(), registryPath = \"\", kinds = [], artifactPath = \"\", product = {}, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { registerKfd3Surfaces } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd3-surface-register.js:502` |\n| `registerStableCandidate` | function: function registerStableCandidate(ledgerInput, candidateInput, { now = new Date().toISOString() } = {}) | ledgerInput, candidateInput, { now = new Date().toISOString() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { registerStableCandidate } from \"@kungfu-tech/buildchain/core\";` | `packages/core/stable-candidate-ledger.js:106` |\n| `RELEASE_ACTIVATION_CONTRACT` | constant: const RELEASE_ACTIVATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_ACTIVATION_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-activation-transaction.js:3` |\n| `RELEASE_ACTIVATION_PHASES` | constant: const RELEASE_ACTIVATION_PHASES | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_ACTIVATION_PHASES } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-activation-transaction.js:8` |\n| `RELEASE_ACTIVATION_RECEIPT_SET_CONTRACT` | constant: const RELEASE_ACTIVATION_RECEIPT_SET_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_ACTIVATION_RECEIPT_SET_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-activation-transaction.js:5` |\n| `RELEASE_CANDIDATE_PASSPORT_CONTRACT` | constant: const RELEASE_CANDIDATE_PASSPORT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_CANDIDATE_PASSPORT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-candidate.js:4` |\n| `RELEASE_CANDIDATE_RECOVERY_CONTRACT` | constant: const RELEASE_CANDIDATE_RECOVERY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_CANDIDATE_RECOVERY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-candidate-recovery.js:15` |\n| `RELEASE_CHECK_REPORT_CONTRACT` | value: RELEASE_CHECK_REPORT_CONTRACT | none | unknown | No narrower error contract was mechanically discoverable. | unknown | `import { RELEASE_CHECK_REPORT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport.js:1` |\n| `RELEASE_EVIDENCE_ATTACHMENT_CONTRACT` | constant: const RELEASE_EVIDENCE_ATTACHMENT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_EVIDENCE_ATTACHMENT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport.js:42` |\n| `RELEASE_PASSPORT_CHECK_MANIFEST_CONTRACT` | constant: const RELEASE_PASSPORT_CHECK_MANIFEST_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PASSPORT_CHECK_MANIFEST_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport-contract.js:19` |\n| `RELEASE_PASSPORT_CONTRACT` | value: RELEASE_PASSPORT_CONTRACT | none | unknown | No narrower error contract was mechanically discoverable. | unknown | `import { RELEASE_PASSPORT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport.js:1` |\n| `RELEASE_PASSPORT_SCHEMA` | constant: const RELEASE_PASSPORT_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PASSPORT_SCHEMA } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport-contract.js:26` |\n| `RELEASE_PASSPORT_SCHEMA_ID` | constant: const RELEASE_PASSPORT_SCHEMA_ID | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PASSPORT_SCHEMA_ID } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport-contract.js:17` |\n| `RELEASE_PROPAGATION_FAILURE_MATRIX` | constant: const RELEASE_PROPAGATION_FAILURE_MATRIX | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_FAILURE_MATRIX } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-agent-entry.js:66` |\n| `RELEASE_PROPAGATION_FAILURE_MATRIX_CONTRACT` | constant: const RELEASE_PROPAGATION_FAILURE_MATRIX_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_FAILURE_MATRIX_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-agent-entry.js:11` |\n| `RELEASE_PROPAGATION_GRAPH_CONTRACT` | constant: const RELEASE_PROPAGATION_GRAPH_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_GRAPH_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation.js:15` |\n| `RELEASE_PROPAGATION_LOCK_CONTRACT` | constant: const RELEASE_PROPAGATION_LOCK_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_LOCK_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation.js:17` |\n| `RELEASE_PROPAGATION_PLAN_CONTRACT` | value: RELEASE_PROPAGATION_PLAN_CONTRACT | none | unknown | No narrower error contract was mechanically discoverable. | unknown | `import { RELEASE_PROPAGATION_PLAN_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation.js:1` |\n| `RELEASE_PROPAGATION_PUSH_PLAN_CONTRACT` | constant: const RELEASE_PROPAGATION_PUSH_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_PUSH_PLAN_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-push.js:14` |\n| `RELEASE_PROPAGATION_PUSH_RESULT_CONTRACT` | constant: const RELEASE_PROPAGATION_PUSH_RESULT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_PUSH_RESULT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-push.js:16` |\n| `RELEASE_PROPAGATION_RECEIPT_CONTRACT` | constant: const RELEASE_PROPAGATION_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation.js:18` |\n| `RELEASE_PROPAGATION_STAGE_RECEIPT_CONTRACT` | constant: const RELEASE_PROPAGATION_STAGE_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_STAGE_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-work-constants.js:2` |\n| `RELEASE_PROPAGATION_WORK_CONTRACT` | constant: const RELEASE_PROPAGATION_WORK_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_WORK_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-work-constants.js:1` |\n| `RELEASE_PROPAGATION_WORK_STAGES` | constant: const RELEASE_PROPAGATION_WORK_STAGES | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_WORK_STAGES } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-work-constants.js:4` |\n| `RELEASE_TAIL_CAPABILITY_REGISTRY` | constant: const RELEASE_TAIL_CAPABILITY_REGISTRY | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_CAPABILITY_REGISTRY } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-plane.js:31` |\n| `RELEASE_TAIL_COMPATIBILITY_CONTRACT` | constant: const RELEASE_TAIL_COMPATIBILITY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_COMPATIBILITY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-compatibility.js:1` |\n| `RELEASE_TAIL_DECLARATION_CONTRACT` | constant: const RELEASE_TAIL_DECLARATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_DECLARATION_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-plane.js:5` |\n| `RELEASE_TAIL_EFFECT_SCHEMA` | constant: const RELEASE_TAIL_EFFECT_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_EFFECT_SCHEMA } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-plane.js:10` |\n| `RELEASE_TAIL_LEGACY_HOOKS` | constant: const RELEASE_TAIL_LEGACY_HOOKS | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_LEGACY_HOOKS } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-compatibility.js:4` |\n| `RELEASE_TAIL_OBSERVATION_SCHEMA` | constant: const RELEASE_TAIL_OBSERVATION_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_OBSERVATION_SCHEMA } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-plane.js:12` |\n| `RELEASE_TAIL_RECEIPT_SCHEMA` | constant: const RELEASE_TAIL_RECEIPT_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_RECEIPT_SCHEMA } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-plane.js:14` |\n| `RELEASE_TAIL_STATES` | constant: const RELEASE_TAIL_STATES | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_STATES } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-plane.js:17` |\n| `RELEASE_TAIL_TRANSACTION_POLICY` | constant: const RELEASE_TAIL_TRANSACTION_POLICY | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_TRANSACTION_POLICY } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-plane.js:7` |\n| `RELEASE_TAIL_TRANSACTION_SCHEMA` | constant: const RELEASE_TAIL_TRANSACTION_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_TRANSACTION_SCHEMA } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-plane.js:8` |\n| `releaseActivationRoot` | function: function releaseActivationRoot(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { releaseActivationRoot } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-activation-transaction.js:38` |\n| `ReleaseCandidateRecoveryError` | class: class ReleaseCandidateRecoveryError | none | ReleaseCandidateRecoveryError | Construction and method errors follow the linked source implementation. | class-dependent | `import { ReleaseCandidateRecoveryError } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-candidate-recovery.js:56` |\n| `ReleaseTailProviderError` | class: class ReleaseTailProviderError | none | ReleaseTailProviderError | Construction and method errors follow the linked source implementation. | class-dependent | `import { ReleaseTailProviderError } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-adapters.js:9` |\n| `releaseTailRetryPolicyFromDeclaration` | function: function releaseTailRetryPolicyFromDeclaration(input) | input | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { releaseTailRetryPolicyFromDeclaration } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-plane.js:1207` |\n| `releaseTailRoot` | function: function releaseTailRoot(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { releaseTailRoot } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-plane.js:164` |\n| `releaseTailStableJson` | function: function releaseTailStableJson(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { releaseTailStableJson } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-plane.js:149` |\n| `renderBadgeBundleBlock` | function: function renderBadgeBundleBlock(facts) | facts | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { renderBadgeBundleBlock } from \"@kungfu-tech/buildchain/core\";` | `packages/core/readme-badges.js:840` |\n| `renderBuildchainContractDriftIssueBody` | function: function renderBuildchainContractDriftIssueBody({ repository = \"\", workflow = \"\", runUrl = \"\", lockPath = \"\", evaluation, } = {}) | { repository = \"\", workflow = \"\", runUrl = \"\", lockPath = \"\", evaluation, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { renderBuildchainContractDriftIssueBody } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-contract.js:1043` |\n| `renderHomebrewFormula` | function: function renderHomebrewFormula(facts) | facts | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { renderHomebrewFormula } from \"@kungfu-tech/buildchain/core\";` | `packages/core/homebrew.js:290` |\n| `renderKfd2ProductClaimOutputs` | function: function renderKfd2ProductClaimOutputs({ cwd = process.cwd(), registryPath = BUILDCHAIN_KFD2_REGISTRY_PATH, outputDir = BUILDCHAIN_KFD2_DIR, version = \"\", channel = \"\", tag = \"\", sourceSha = \"\", } = {}) | { cwd = process.cwd(), registryPath = BUILDCHAIN_KFD2_REGISTRY_PATH, outputDir = BUILDCHAIN_KFD2_DIR, version = \"\", channel = \"\", tag = \"\", sourceSha = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { renderKfd2ProductClaimOutputs } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd2-product-claims.js:321` |\n| `renderReadmeBadgeBlock` | function: function renderReadmeBadgeBlock(facts) | facts | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { renderReadmeBadgeBlock } from \"@kungfu-tech/buildchain/core\";` | `packages/core/readme-badges.js:836` |\n| `repairReleasePropagationWork` | function: function repairReleasePropagationWork({ work, expectedWorkRoot, receipt } = {}) | { work, expectedWorkRoot, receipt } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { repairReleasePropagationWork } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-work-transitions.js:88` |\n| `reportBuildchainIssue` | function: async function reportBuildchainIssue(options = {}) | options = {} | Promise<unknown> | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { reportBuildchainIssue } from \"@kungfu-tech/buildchain/core\";` | `packages/core/issue-reporting.js:292` |\n| `reportWorkflowFrictionIssue` | function: async function reportWorkflowFrictionIssue(options = {}) | options = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { reportWorkflowFrictionIssue } from \"@kungfu-tech/buildchain/core\";` | `packages/core/issue-reporting.js:378` |\n| `resolveArtifactSigningProfile` | function: function resolveArtifactSigningProfile({ profile = \"auto\", platform = \"\", artifactKind = \"binary\", } = {}) | { profile = \"auto\", platform = \"\", artifactKind = \"binary\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolveArtifactSigningProfile } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-signing.js:111` |\n| `resolveArtifactSubject` | function: async function resolveArtifactSubject(subject, { cwd = process.cwd(), subjectDigest = \"\", subjectKind = \"\", npmRegistryBaseUrl = \"\", } = {}) | subject, { cwd = process.cwd(), subjectDigest = \"\", subjectKind = \"\", npmRegistryBaseUrl = \"\", } = {} | Promise<unknown> | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolveArtifactSubject } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-passport.js:368` |\n| `resolveBuildchainConfigPath` | function: function resolveBuildchainConfigPath(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolveBuildchainConfigPath } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:67` |\n| `resolveBuildchainContractLockPath` | function: function resolveBuildchainContractLockPath(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolveBuildchainContractLockPath } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:74` |\n| `resolveGithubGovernanceTargetPolicy` | function: function resolveGithubGovernanceTargetPolicy({ descriptor = BUILDCHAIN_GITHUB_GOVERNANCE_AUTHORITY, repository, targetRef, } = {}) | { descriptor = BUILDCHAIN_GITHUB_GOVERNANCE_AUTHORITY, repository, targetRef, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolveGithubGovernanceTargetPolicy } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-governance-authority.js:609` |\n| `resolveKfd1Metadata` | function: function resolveKfd1Metadata() | none | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolveKfd1Metadata } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-gate.js:89` |\n| `resolveKfd2ProductClaimsRegistryPath` | function: function resolveKfd2ProductClaimsRegistryPath(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolveKfd2ProductClaimsRegistryPath } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:81` |\n| `resolveKfd3Metadata` | function: function resolveKfd3Metadata({ requireSchemas = false } = {}) | { requireSchemas = false } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolveKfd3Metadata } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-gate.js:128` |\n| `resolveKfd3SurfaceRegistryPath` | function: function resolveKfd3SurfaceRegistryPath(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolveKfd3SurfaceRegistryPath } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:85` |\n| `resolveNpmRegistryRelease` | function: function resolveNpmRegistryRelease({ source: sourceInput, channel, packageMetadata, attestations, }) | { source: sourceInput, channel, packageMetadata, attestations, } | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolveNpmRegistryRelease } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-pickup.js:167` |\n| `resolvePaperRepository` | function: function resolvePaperRepository(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolvePaperRepository } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper-repository.js:133` |\n| `resolvePropagationChannel` | function: function resolvePropagationChannel(edge, upstreamChannel) | edge, upstreamChannel | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolvePropagationChannel } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation.js:190` |\n| `resolvePublicationCandidateFile` | function: function resolvePublicationCandidateFile(files = [], candidatePath) | files = [], candidatePath | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolvePublicationCandidateFile } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-artifact-candidate.js:23` |\n| `resolveReleasePassportPath` | function: function resolveReleasePassportPath(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolveReleasePassportPath } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-layout.js:92` |\n| `resumeReleasePropagationWork` | function: function resumeReleasePropagationWork(work) | work | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resumeReleasePropagationWork } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-work.js:518` |\n| `revalidateHousekeeperBranchAction` | function: function revalidateHousekeeperBranchAction(action, current, policy = {}) | action, current, policy = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { revalidateHousekeeperBranchAction } from \"@kungfu-tech/buildchain/core\";` | `packages/core/engineering-housekeeper.js:223` |\n| `revokeStableCandidate` | function: function revokeStableCandidate(ledgerInput, versionInput, { reason, actor = \"\", now = new Date().toISOString() } = {}) | ledgerInput, versionInput, { reason, actor = \"\", now = new Date().toISOString() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { revokeStableCandidate } from \"@kungfu-tech/buildchain/core\";` | `packages/core/stable-candidate-ledger.js:185` |\n| `rollbackReleaseActivationTransaction` | function: function rollbackReleaseActivationTransaction(transaction, { toSiteSourceSha, reason } = {}) | transaction, { toSiteSourceSha, reason } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { rollbackReleaseActivationTransaction } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-activation-transaction.js:290` |\n| `runGitHubHousekeeper` | function: async function runGitHubHousekeeper(options) | options | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { runGitHubHousekeeper } from \"@kungfu-tech/buildchain/core\";` | `packages/core/engineering-housekeeper-github.js:691` |\n| `runLifecycleStage` | function: function runLifecycleStage({ cwd = process.cwd(), loadedConfig, name, stage, env: extraEnv, timeoutMinutes }) | { cwd = process.cwd(), loadedConfig, name, stage, env: extraEnv, timeoutMinutes } | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { runLifecycleStage } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-config.js:1375` |\n| `RUNNER_PROVENANCE_CLASSES` | constant: const RUNNER_PROVENANCE_CLASSES | none | value | Import does not declare a throw contract. | none-on-import | `import { RUNNER_PROVENANCE_CLASSES } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:36` |\n| `RUNNER_PROVENANCE_CONTRACT` | constant: const RUNNER_PROVENANCE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RUNNER_PROVENANCE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:14` |\n| `schemas` | constant: const schemas | none | value | Import does not declare a throw contract. | none-on-import | `import { schemas } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd.js:495` |\n| `sealArtifactVerificationReport` | function: function sealArtifactVerificationReport({ report, bindings, kfdAssessment, issuedAt, expiresAt, revocation, } = {}) | { report, bindings, kfdAssessment, issuedAt, expiresAt, revocation, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { sealArtifactVerificationReport } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-verification-envelope.js:323` |\n| `selectStableCandidate` | function: function selectStableCandidate(ledgerInput, { releaseNow = \"\", now = new Date().toISOString() } = {}) | ledgerInput, { releaseNow = \"\", now = new Date().toISOString() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { selectStableCandidate } from \"@kungfu-tech/buildchain/core\";` | `packages/core/stable-candidate-ledger.js:206` |\n| `setStableCandidateHold` | function: function setStableCandidateHold(ledgerInput, enabled, { reason = \"\", now = new Date().toISOString() } = {}) | ledgerInput, enabled, { reason = \"\", now = new Date().toISOString() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { setStableCandidateHold } from \"@kungfu-tech/buildchain/core\";` | `packages/core/stable-candidate-ledger.js:198` |\n| `sha256BuildchainContractJson` | function: function sha256Json(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { sha256BuildchainContractJson } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-contract.js:43` |\n| `sha256File` | function: function sha256File(filePath) | filePath | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write, subprocess | `import { sha256File } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport.js:224` |\n| `sha256Json` | function: function sha256Json(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { sha256Json } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-candidate.js:90` |\n| `sha256KfdJson` | function: function sha256Json(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { sha256KfdJson } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-gate.js:50` |\n| `sha256Text` | function: function sha256Text(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { sha256Text } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport.js:146` |\n| `sha512IntegrityBuffer` | function: function sha512IntegrityBuffer(buffer) | buffer | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { sha512IntegrityBuffer } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-passport.js:34` |\n| `sha512IntegrityFile` | function: function sha512IntegrityFile(filePath) | filePath | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { sha512IntegrityFile } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-passport.js:38` |\n| `shellJoin` | function: function shellJoin(command) | command | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { shellJoin } from \"@kungfu-tech/buildchain/core\";` | `packages/core/package-manager.js:114` |\n| `signDetachedArtifactRequest` | function: function signDetachedArtifactRequest({ request, privateKey, keyId, authority = {}, } = {}) | { request, privateKey, keyId, authority = {}, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { signDetachedArtifactRequest } from \"@kungfu-tech/buildchain/core\";` | `packages/core/detached-artifact-signature.js:36` |\n| `SITE_UPSTREAM_AGENT_ENTRY_CONTRACT` | constant: const SITE_UPSTREAM_AGENT_ENTRY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { SITE_UPSTREAM_AGENT_ENTRY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-agent-entry.js:9` |\n| `STABLE_CANDIDATE_LEDGER_CONTRACT` | constant: const STABLE_CANDIDATE_LEDGER_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { STABLE_CANDIDATE_LEDGER_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/stable-candidate-ledger.js:1` |\n| `STABLE_CANDIDATE_STATES` | constant: const STABLE_CANDIDATE_STATES | none | value | Import does not declare a throw contract. | none-on-import | `import { STABLE_CANDIDATE_STATES } from \"@kungfu-tech/buildchain/core\";` | `packages/core/stable-candidate-ledger.js:2` |\n| `stableCandidatePromotionRefs` | function: function stableCandidatePromotionRefs(candidateInput, targetBranch) | candidateInput, targetBranch | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { stableCandidatePromotionRefs } from \"@kungfu-tech/buildchain/core\";` | `packages/core/stable-candidate-ledger.js:264` |\n| `startProcessSampler` | function: function startProcessSampler({ rootPid = process.pid, intervalMs = 15000, label = \"\", command = \"\", args = [], env = process.env, requestedParallelism = 0, onSample = () => undefined, cwd = process.cwd(), } = {}) | { rootPid = process.pid, intervalMs = 15000, label = \"\", command = \"\", args = [], env = process.env, requestedParallelism = 0, onSample = () => undefined, cwd = process.cwd(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { startProcessSampler } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:1362` |\n| `summarizeBuildchainLogEvents` | function: function summarizeBuildchainLogEvents(input = {}) | input = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { summarizeBuildchainLogEvents } from \"@kungfu-tech/buildchain/core\";` | `packages/core/logging.js:192` |\n| `summarizeDiagnosticsArtifacts` | function: function summarizeDiagnosticsArtifacts(inputs = []) | inputs = [] | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { summarizeDiagnosticsArtifacts } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:1824` |\n| `summarizeLifecycleObservability` | function: function summarizeLifecycleObservability({ events = [], logPath = \"\", artifactScanDurationMs = 0, artifactUploadDurationMs = 0, totalBytes = 0, fileCount = 0, } = {}) | { events = [], logPath = \"\", artifactScanDurationMs = 0, artifactUploadDurationMs = 0, totalBytes = 0, fileCount = 0, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { summarizeLifecycleObservability } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:219` |\n| `summarizeProcessSamples` | function: function summarizeProcessSamples({ samples = [], requestedParallelism = 0, command = \"\", args = [], env = process.env, activeCpuThreshold = 0.1, } = {}) | { samples = [], requestedParallelism = 0, command = \"\", args = [], env = process.env, activeCpuThreshold = 0.1, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { summarizeProcessSamples } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:1254` |\n| `SURFACE_TIMESTAMP_POLICY_CONTRACT` | constant: const SURFACE_TIMESTAMP_POLICY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { SURFACE_TIMESTAMP_POLICY_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/surface-manifest.js:1` |\n| `testKfdAgentHub` | function: function testKfdAgentHub({ cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, outputDir = KFD_AGENT_HUB_OUTPUT_DIR, kfdRoot = \"\", run = defaultRun } = {}) | { cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, outputDir = KFD_AGENT_HUB_OUTPUT_DIR, kfdRoot = \"\", run = defaultRun } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { testKfdAgentHub } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-agent-hub.js:399` |\n| `transitionReleaseTransaction` | function: function transitionReleaseTransaction(record, nextState, metadata = {}) | record, nextState, metadata = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { transitionReleaseTransaction } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publish-transaction.js:256` |\n| `truncateUtf8` | function: function truncateUtf8(text, maxBytes = DEFAULT_MAX_BODY_BYTES) | text, maxBytes = DEFAULT_MAX_BODY_BYTES | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { truncateUtf8 } from \"@kungfu-tech/buildchain/core\";` | `packages/core/issue-reporting.js:84` |\n| `updateBadgeBundleBlock` | function: function updateBadgeBundleBlock({ readmeText, facts } = {}) | { readmeText, facts } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { updateBadgeBundleBlock } from \"@kungfu-tech/buildchain/core\";` | `packages/core/readme-badges.js:887` |\n| `updateConfiguredVersionStateContents` | function: function updateConfiguredVersionStateContents(files, version) | files, version | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { updateConfiguredVersionStateContents } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-config.js:1675` |\n| `updateHomebrewTap` | function: async function updateHomebrewTap({ cwd = process.cwd(), packageName = \"buildchain\", releasePassport = \"\", manifestPath = DEFAULT_MANIFEST_PATH, formulaPath = \"\", write = true, } = {}) | { cwd = process.cwd(), packageName = \"buildchain\", releasePassport = \"\", manifestPath = DEFAULT_MANIFEST_PATH, formulaPath = \"\", write = true, } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { updateHomebrewTap } from \"@kungfu-tech/buildchain/core\";` | `packages/core/homebrew.js:390` |\n| `updateReadmeBadgeBlock` | function: function updateReadmeBadgeBlock({ readmeText, facts } = {}) | { readmeText, facts } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { updateReadmeBadgeBlock } from \"@kungfu-tech/buildchain/core\";` | `packages/core/readme-badges.js:874` |\n| `validateAnchoredPackageRelease` | function: function validateAnchoredPackageRelease({ cwd = process.cwd(), requireManifest = true, requirePackageSetOrder = \"platforms-first-main-last\", requireTrustedPublishing = true, requireLifecycleStages = [\"install\", \"build\", \"verify\", \"publish\"], requirePublishGateSourceLock = false, publishSource = undefined, env = process.env, } = {}) | { cwd = process.cwd(), requireManifest = true, requirePackageSetOrder = \"platforms-first-main-last\", requireTrustedPublishing = true, requireLifecycleStages = [\"install\", \"build\", \"verify\", \"publish\"], requirePublishGateSourceLock = false, publishSource = undefined, env = process.env, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateAnchoredPackageRelease } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:325` |\n| `validateArtifactSigningReceipt` | function: function validateArtifactSigningReceipt(receipt, { request } = {}) | receipt, { request } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { validateArtifactSigningReceipt } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-signing.js:374` |\n| `validateArtifactSigningRequest` | function: function validateArtifactSigningRequest(request) | request | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { validateArtifactSigningRequest } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-signing.js:291` |\n| `validateArtifactSigningResult` | function: function validateArtifactSigningResult(result, { request, receipt } = {}) | result, { request, receipt } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { validateArtifactSigningResult } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-signing-result.js:147` |\n| `validateBuildchainConfig` | function: function validateBuildchainConfig(cwd = process.cwd(), { requireConfig = true, requireVersionState = false, requireLifecycleStages = [], } = {}) | cwd = process.cwd(), { requireConfig = true, requireVersionState = false, requireLifecycleStages = [], } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { validateBuildchainConfig } from \"@kungfu-tech/buildchain/core\";` | `packages/core/buildchain-config.js:1542` |\n| `validateControllerPlan` | function: function validateControllerPlan(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateControllerPlan } from \"@kungfu-tech/buildchain/core\";` | `packages/core/controller-evidence.js:325` |\n| `validateControllerReceipt` | function: function validateControllerReceipt(receipt, { plan = undefined, expectedSourceSha = \"\", expectedRuntimeSha = \"\", expectedPlanDigest = \"\", } = {}) | receipt, { plan = undefined, expectedSourceSha = \"\", expectedRuntimeSha = \"\", expectedPlanDigest = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateControllerReceipt } from \"@kungfu-tech/buildchain/core\";` | `packages/core/controller-evidence.js:423` |\n| `validateControllerReceiptReference` | function: function validateControllerReceiptReference(reference, { expectedSourceSha = \"\", acceptedSourceShas = [], expectedRuntimeSha = \"\", requirePassed = false, } = {}) | reference, { expectedSourceSha = \"\", acceptedSourceShas = [], expectedRuntimeSha = \"\", requirePassed = false, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateControllerReceiptReference } from \"@kungfu-tech/buildchain/core\";` | `packages/core/controller-evidence.js:505` |\n| `validateKfd1ReleaseGateEvidence` | function: function validateKfd1ReleaseGateEvidence(section, { metadata = resolveKfd1Metadata() } = {}) | section, { metadata = resolveKfd1Metadata() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateKfd1ReleaseGateEvidence } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-gate.js:1337` |\n| `validateKfd2ProductClaimsRegistry` | function: function validateKfd2ProductClaimsRegistry(registry = {}) | registry = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { validateKfd2ProductClaimsRegistry } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd2-product-claims.js:152` |\n| `validateKfd3CollaborationInterfaceReleaseGateEvidence` | function: function validateKfd3CollaborationInterfaceReleaseGateEvidence(section, { metadata = resolveKfd3Metadata() } = {}) | section, { metadata = resolveKfd3Metadata() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateKfd3CollaborationInterfaceReleaseGateEvidence } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-gate.js:1470` |\n| `validateKfdAdopterReleaseBinding` | function: function validateKfdAdopterReleaseBinding(binding, { manifest, manifestGate, legacyProjection, expectedSourceSha = \"\", } = {}) | binding, { manifest, manifestGate, legacyProjection, expectedSourceSha = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateKfdAdopterReleaseBinding } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-verification-envelope.js:467` |\n| `validateKfdProductGateResult` | function: function validateKfdProductGateResult(result, { expectedSourceSha = \"\", checkedAt = new Date().toISOString(), } = {}) | result, { expectedSourceSha = \"\", checkedAt = new Date().toISOString(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateKfdProductGateResult } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-product-gates.js:519` |\n| `validateKnownReleasePassportContracts` | function: function validateKnownReleasePassportContracts() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateKnownReleasePassportContracts } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport.js:2750` |\n| `validatePackageManagerContract` | function: function validatePackageManagerContract({ cwd = process.cwd(), expectedManager = \"\" } = {}) | { cwd = process.cwd(), expectedManager = \"\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { validatePackageManagerContract } from \"@kungfu-tech/buildchain/core\";` | `packages/core/package-manager.js:18` |\n| `validatePublishEvidence` | function: function validatePublishEvidence({ evidence, version, channel, sourceSha, releaseSha, targetRef = \"\", releaseMaterialSha = releaseSha, publishToolingSha = \"\", requiredArtifacts = [], } = {}) | { evidence, version, channel, sourceSha, releaseSha, targetRef = \"\", releaseMaterialSha = releaseSha, publishToolingSha = \"\", requiredArtifacts = [], } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validatePublishEvidence } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publish-transaction.js:674` |\n| `validateReleaseActivationReceiptSet` | function: function validateReleaseActivationReceiptSet(receiptSet, { allowShadow = true } = {}) | receiptSet, { allowShadow = true } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateReleaseActivationReceiptSet } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-activation-transaction.js:376` |\n| `validateReleaseActivationTransaction` | function: function validateReleaseActivationTransaction(transaction) | transaction | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateReleaseActivationTransaction } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-activation-transaction.js:146` |\n| `validateReleaseCandidatePassport` | function: function validateReleaseCandidatePassport({ passport, repository = \"\", targetChannel = \"\", version = \"\", sourceHeadSha = \"\", buildSummary = undefined, requirePlatforms = true, requireFamilyEvidence = false, familyEvidenceRoot = \"\", familyInitiativeId = \"\", familyAssignmentId = \"\", } = {}) | { passport, repository = \"\", targetChannel = \"\", version = \"\", sourceHeadSha = \"\", buildSummary = undefined, requirePlatforms = true, requireFamilyEvidence = false, familyEvidenceRoot = \"\", familyInitiativeId = \"\", familyAssignmentId = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateReleaseCandidatePassport } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-candidate.js:404` |\n| `validateReleasePassportSchema` | function: function validateReleasePassportSchema(passport) | passport | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateReleasePassportSchema } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport-contract.js:277` |\n| `validateReleaseTailEffectPlan` | function: function validateReleaseTailEffectPlan(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateReleaseTailEffectPlan } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-plane.js:602` |\n| `validateReleaseTailTransaction` | function: function validateReleaseTailTransaction(transaction) | transaction | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateReleaseTailTransaction } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-plane.js:744` |\n| `verifyArtifactPassport` | function: async function verifyArtifactPassport({ subject, cwd = process.cwd(), passportLocation = \"\", locatorConfig = \"\", repository = \"\", tag = \"\", githubReleaseBaseUrl = \"\", subjectDigest = \"\", subjectKind = \"\", npmRegistryBaseUrl = \"\", verificationEnvelope = undefined, } = {}) | { subject, cwd = process.cwd(), passportLocation = \"\", locatorConfig = \"\", repository = \"\", tag = \"\", githubReleaseBaseUrl = \"\", subjectDigest = \"\", subjectKind = \"\", npmRegistryBaseUrl = \"\", verificationEnvelope = undefined, } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyArtifactPassport } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-passport.js:701` |\n| `verifyArtifactSigningResultFiles` | function: function verifyArtifactSigningResultFiles({ root, request, receipt, result, } = {}) | { root, request, receipt, result, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyArtifactSigningResultFiles } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-signing-result.js:193` |\n| `verifyArtifactVerificationEnvelope` | function: function verifyArtifactVerificationEnvelope({ envelope, assessmentTime = Math.floor(Date.now() / 1000), expectedEnvelopeRoot = \"\", expectedIssuer = \"\", expectedPublisher = \"\", expectedContractVersion = \"\", } = {}) | { envelope, assessmentTime = Math.floor(Date.now() / 1000), expectedEnvelopeRoot = \"\", expectedIssuer = \"\", expectedPublisher = \"\", expectedContractVersion = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyArtifactVerificationEnvelope } from \"@kungfu-tech/buildchain/core\";` | `packages/core/artifact-verification-envelope.js:153` |\n| `verifyBuildchainLogEvents` | function: function verifyBuildchainLogEvents({ path: filePath = \"\", events: inputEvents = undefined, minEvents = 1, allowErrors = false, requirePhases = [], requireComponents = [], requireEvents = [], } = {}) | { path: filePath = \"\", events: inputEvents = undefined, minEvents = 1, allowErrors = false, requirePhases = [], requireComponents = [], requireEvents = [], } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyBuildchainLogEvents } from \"@kungfu-tech/buildchain/core\";` | `packages/core/logging.js:230` |\n| `verifyBuildFacts` | function: function verifyBuildFacts({ cwd = process.cwd(), fact, factPath = \"\" } = {}) | { cwd = process.cwd(), fact, factPath = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyBuildFacts } from \"@kungfu-tech/buildchain/core\";` | `packages/core/build-facts.js:431` |\n| `verifyCacheEvidenceSet` | function: function verifyCacheEvidenceSet(receipt) | receipt | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyCacheEvidenceSet } from \"@kungfu-tech/buildchain/core\";` | `packages/core/cache-evidence.js:273` |\n| `verifyCacheOperationReceipt` | function: function verifyCacheOperationReceipt(receipt) | receipt | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyCacheOperationReceipt } from \"@kungfu-tech/buildchain/core\";` | `packages/core/cache-evidence.js:226` |\n| `verifyDetachedArtifactSignature` | function: function verifyDetachedArtifactSignature({ request, envelope, publicKey, } = {}) | { request, envelope, publicKey, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyDetachedArtifactSignature } from \"@kungfu-tech/buildchain/core\";` | `packages/core/detached-artifact-signature.js:82` |\n| `verifyGitHubArtifactAttestationEvidence` | function: function verifyGitHubArtifactAttestationEvidence({ artifactPath, platformManifestPath, releasePassportPath, bundlePath, evidence, verificationResults, } = {}) | { artifactPath, platformManifestPath, releasePassportPath, bundlePath, evidence, verificationResults, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { verifyGitHubArtifactAttestationEvidence } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-artifact-attestation.js:563` |\n| `verifyGithubGovernanceReceipt` | function: function verifyGithubGovernanceReceipt(receipt, { expectedOrganization, expectedRepository, expectedRepositoryIdentityRoot, expectedTargetRef, expectedPolicyRoot, expectedVerifierSourceRevision, now = new Date().toISOString(), } = {}) | receipt, { expectedOrganization, expectedRepository, expectedRepositoryIdentityRoot, expectedTargetRef, expectedPolicyRoot, expectedVerifierSourceRevision, now = new Date().toISOString(), } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { verifyGithubGovernanceReceipt } from \"@kungfu-tech/buildchain/core\";` | `packages/core/github-governance-authority.js:886` |\n| `verifyKfdRecord` | function: async function verifyKfdRecord(record) | record | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyKfdRecord } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd-product-gates.js:262` |\n| `verifyPortableDevCachePlan` | function: function verifyPortableDevCachePlan(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyPortableDevCachePlan } from \"@kungfu-tech/buildchain/core\";` | `packages/core/portable-dev-cache.js:211` |\n| `verifyPublicationAdmission` | function: function verifyPublicationAdmission({ admission, registry, runnerProvenance, controlPlaneAudit, publicationEvidence, expected = {}, usedNonces = [], now = new Date(), } = {}) | { admission, registry, runnerProvenance, controlPlaneAudit, publicationEvidence, expected = {}, usedNonces = [], now = new Date(), } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { verifyPublicationAdmission } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:791` |\n| `verifyPublicationQualificationReceipt` | function: function verifyPublicationQualificationReceipt({ receipt, capability, gateAggregate, expected = {}, usedNonces = [], now = new Date(), } = {}) | { receipt, capability, gateAggregate, expected = {}, usedNonces = [], now = new Date(), } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { verifyPublicationQualificationReceipt } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-authority.js:1096` |\n| `verifyPublicationReproducibility` | function: function verifyPublicationReproducibility({ cwd = process.cwd(), sourceSha = \"\", output = DEFAULT_OUTPUT, promote = false, keepWorkspaces = false, pullToolchain = true, packageName = \"\", allowUnpinnedToolchain = false, overlayPaths = [DEFAULT_REGISTRY_INPUT_DIR, DEFAULT_REGISTRY_HYDRATION], } = {}) | { cwd = process.cwd(), sourceSha = \"\", output = DEFAULT_OUTPUT, promote = false, keepWorkspaces = false, pullToolchain = true, packageName = \"\", allowUnpinnedToolchain = false, overlayPaths = [DEFAULT_REGISTRY_INPUT_DIR, DEFAULT_REGISTRY_HYDRATION], } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { verifyPublicationReproducibility } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-reproducibility.js:869` |\n| `verifyPublicationSealedBundle` | function: function verifyPublicationSealedBundle({ bundleRoot, manifest } = {}) | { bundleRoot, manifest } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { verifyPublicationSealedBundle } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-sealed-bundle.js:133` |\n| `verifyReleaseCandidateRecovery` | function: function verifyReleaseCandidateRecovery({ candidateRepository, targetRepository, expectedRunId, expectedWorkflowFile, expectedWorkflowName, channel, targetRef, targetSha, targetRefSha = targetSha, targetTree, expectedSourceTree = \"\", expectedCandidateRoot = \"\", expectedRuntimeSha, expectedTransactionId = \"\", existingTransaction = undefined, run, workflow, pullRequest, ancestry, passport, buildSummary, controllerReceipts = [], platformManifests = [], platformManifestEvidence = [], productPayloadManifests = [], artifacts = [], publicationVersion = \"\", currentToolingSha, recoveryRunId = \"\", createdAt = new Date().toISOString(), } = {}) | { candidateRepository, targetRepository, expectedRunId, expectedWorkflowFile, expectedWorkflowName, channel, targetRef, targetSha, targetRefSha = targetSha, targetTree, expectedSourceTree = \"\", expectedCandidateRoot = \"\", expectedRuntimeSha, expectedTransactionId = \"\", existingTransaction = undefined, run, workflow, pullRequest, ancestry, passport, buildSummary, controllerReceipts = [], platformManifests = [], platformManifestEvidence = [], productPayloadManifests = [], artifacts = [], publicationVersion = \"\", currentToolingSha, recoveryRunId = \"\", createdAt = new Date().toISOString(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyReleaseCandidateRecovery } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-candidate-recovery.js:398` |\n| `verifyReleasePassport` | function: async function verifyReleasePassport({ passportLocation, artifactEvidenceLocation = \"\", publishEvidenceLocation = \"\", impactLocation = \"\", agentIndexLocation = \"\", productMechanismLocation = \"\", kfdAgentHubEvidenceLocation = \"\", kfdAdopterManifestLocation = \"\", kfdAdopterManifestGateLocation = \"\", kfdSupportEvidenceLocation = \"\", checkedAt = nowIso(), } = {}) | { passportLocation, artifactEvidenceLocation = \"\", publishEvidenceLocation = \"\", impactLocation = \"\", agentIndexLocation = \"\", productMechanismLocation = \"\", kfdAgentHubEvidenceLocation = \"\", kfdAdopterManifestLocation = \"\", kfdAdopterManifestGateLocation = \"\", kfdSupportEvidenceLocation = \"\", checkedAt = nowIso(), } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyReleasePassport } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-passport.js:2674` |\n| `verifyReleasePropagationWork` | function: function verifyReleasePropagationWork(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { verifyReleasePropagationWork } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation-work.js:486` |\n| `WEB_SURFACE_PRODUCTION_DECISION_CONTRACT` | constant: const WEB_SURFACE_PRODUCTION_DECISION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { WEB_SURFACE_PRODUCTION_DECISION_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/web-surface-publication-candidate.js:7` |\n| `WEB_SURFACE_PUBLICATION_CANDIDATE_CONTRACT` | constant: const WEB_SURFACE_PUBLICATION_CANDIDATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { WEB_SURFACE_PUBLICATION_CANDIDATE_CONTRACT } from \"@kungfu-tech/buildchain/core\";` | `packages/core/web-surface-publication-candidate.js:5` |\n| `webSurfacePublicationDigest` | function: function webSurfacePublicationDigest(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { webSurfacePublicationDigest } from \"@kungfu-tech/buildchain/core\";` | `packages/core/web-surface-publication-candidate.js:21` |\n| `workflowFrictionMarker` | function: function workflowFrictionMarker(fingerprint) | fingerprint | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { workflowFrictionMarker } from \"@kungfu-tech/buildchain/core\";` | `packages/core/issue-reporting.js:80` |\n| `writeBuildFacts` | function: function writeBuildFacts({ cwd = process.cwd(), fact, output = \"\" } = {}) | { cwd = process.cwd(), fact, output = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { writeBuildFacts } from \"@kungfu-tech/buildchain/core\";` | `packages/core/build-facts.js:557` |\n| `writeDiagnosticsArtifact` | function: function writeDiagnosticsArtifact(filePath, diagnostics) | filePath, diagnostics | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write | `import { writeDiagnosticsArtifact } from \"@kungfu-tech/buildchain/core\";` | `packages/core/diagnostics.js:1459` |\n| `writeKfd2ProductClaimOutputs` | function: function writeKfd2ProductClaimOutputs(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write | `import { writeKfd2ProductClaimOutputs } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd2-product-claims.js:426` |\n| `writeKfd3SurfaceRegistry` | function: function writeKfd3SurfaceRegistry({ cwd = process.cwd(), registryPath = \"\", registry }) | { cwd = process.cwd(), registryPath = \"\", registry } | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { writeKfd3SurfaceRegistry } from \"@kungfu-tech/buildchain/core\";` | `packages/core/kfd3-surface-register.js:478` |\n| `writeKungfuBuildInfoProjection` | function: function writeKungfuBuildInfoProjection({ cwd = process.cwd(), moduleFact, output } = {}) | { cwd = process.cwd(), moduleFact, output } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { writeKungfuBuildInfoProjection } from \"@kungfu-tech/buildchain/core\";` | `packages/core/build-facts.js:565` |\n| `writePaperFleetUpdate` | function: function writePaperFleetUpdate(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { writePaperFleetUpdate } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper-fleet.js:271` |\n| `writePaperMigration` | function: function writePaperMigration(plan) | plan | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { writePaperMigration } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper.js:1130` |\n| `writePaperScaffold` | function: function writePaperScaffold(plan) | plan | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { writePaperScaffold } from \"@kungfu-tech/buildchain/core\";` | `packages/core/paper.js:847` |\n| `writePublicationArtifact` | function: function writePublicationArtifact({ cwd = process.cwd(), output = \"\", passportOutput = \"\", registryOutput = \"\", registryInputs = [], sourceSha = \"\", sourceBundle = true, sourceBundlePath = \"\", generatedAt = \"\", } = {}) | { cwd = process.cwd(), output = \"\", passportOutput = \"\", registryOutput = \"\", registryInputs = [], sourceSha = \"\", sourceBundle = true, sourceBundlePath = \"\", generatedAt = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write | `import { writePublicationArtifact } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publication-artifact.js:598` |\n| `writeReleaseLineBootstrapVersionState` | function: function writeReleaseLineBootstrapVersionState({ cwd = process.cwd(), major, minor, sourceRef = \"\", initialVersion = \"\", runVersionStateLifecycle = true, generatedAt = \"\", } = {}) | { cwd = process.cwd(), major, minor, sourceRef = \"\", initialVersion = \"\", runVersionStateLifecycle = true, generatedAt = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { writeReleaseLineBootstrapVersionState } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-line-bootstrap.js:250` |\n| `writeReleasePropagationLock` | function: function writeReleasePropagationLock({ plan, target = \"\", cwd = process.cwd(), output = \"\" } = {}) | { plan, target = \"\", cwd = process.cwd(), output = \"\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { writeReleasePropagationLock } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-propagation.js:317` |\n| `writeReleaseTailTransaction` | function: function writeReleaseTailTransaction(filePath, transaction) | filePath, transaction | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { writeReleaseTailTransaction } from \"@kungfu-tech/buildchain/core\";` | `packages/core/release-tail-provider-plane.js:841` |\n| `writeReleaseTransaction` | function: function writeReleaseTransaction(filePath, record) | filePath, record | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write | `import { writeReleaseTransaction } from \"@kungfu-tech/buildchain/core\";` | `packages/core/publish-transaction.js:376` |\n\n## `@kungfu-tech/buildchain/artifact-passport`\n\nTarget: `./packages/core/artifact-passport.js`. Public symbols: 10.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `ARTIFACT_PASSPORT_LOCATOR_CONTRACT` | constant: const ARTIFACT_PASSPORT_LOCATOR_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_PASSPORT_LOCATOR_CONTRACT } from \"@kungfu-tech/buildchain/artifact-passport\";` | `packages/core/artifact-passport.js:11` |\n| `ARTIFACT_PASSPORT_POINTER_CONTRACT` | constant: const ARTIFACT_PASSPORT_POINTER_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_PASSPORT_POINTER_CONTRACT } from \"@kungfu-tech/buildchain/artifact-passport\";` | `packages/core/artifact-passport.js:10` |\n| `ARTIFACT_VERIFICATION_CONTRACT` | constant: const ARTIFACT_VERIFICATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_VERIFICATION_CONTRACT } from \"@kungfu-tech/buildchain/artifact-passport\";` | `packages/core/artifact-passport.js:9` |\n| `DEFAULT_NPM_REGISTRY_BASE_URL` | constant: const DEFAULT_NPM_REGISTRY_BASE_URL | none | value | Import does not declare a throw contract. | none-on-import | `import { DEFAULT_NPM_REGISTRY_BASE_URL } from \"@kungfu-tech/buildchain/artifact-passport\";` | `packages/core/artifact-passport.js:12` |\n| `discoverArtifactPassport` | function: async function discoverArtifactPassport({ subject, cwd = process.cwd(), passportLocation = \"\", locatorConfig = \"\", repository = \"\", tag = \"\", githubReleaseBaseUrl = \"\", } = {}) | { subject, cwd = process.cwd(), passportLocation = \"\", locatorConfig = \"\", repository = \"\", tag = \"\", githubReleaseBaseUrl = \"\", } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { discoverArtifactPassport } from \"@kungfu-tech/buildchain/artifact-passport\";` | `packages/core/artifact-passport.js:499` |\n| `explainArtifactPassport` | function: async function explainArtifactPassport(options = {}) | options = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { explainArtifactPassport } from \"@kungfu-tech/buildchain/artifact-passport\";` | `packages/core/artifact-passport.js:827` |\n| `resolveArtifactSubject` | function: async function resolveArtifactSubject(subject, { cwd = process.cwd(), subjectDigest = \"\", subjectKind = \"\", npmRegistryBaseUrl = \"\", } = {}) | subject, { cwd = process.cwd(), subjectDigest = \"\", subjectKind = \"\", npmRegistryBaseUrl = \"\", } = {} | Promise<unknown> | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolveArtifactSubject } from \"@kungfu-tech/buildchain/artifact-passport\";` | `packages/core/artifact-passport.js:368` |\n| `sha512IntegrityBuffer` | function: function sha512IntegrityBuffer(buffer) | buffer | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { sha512IntegrityBuffer } from \"@kungfu-tech/buildchain/artifact-passport\";` | `packages/core/artifact-passport.js:34` |\n| `sha512IntegrityFile` | function: function sha512IntegrityFile(filePath) | filePath | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { sha512IntegrityFile } from \"@kungfu-tech/buildchain/artifact-passport\";` | `packages/core/artifact-passport.js:38` |\n| `verifyArtifactPassport` | function: async function verifyArtifactPassport({ subject, cwd = process.cwd(), passportLocation = \"\", locatorConfig = \"\", repository = \"\", tag = \"\", githubReleaseBaseUrl = \"\", subjectDigest = \"\", subjectKind = \"\", npmRegistryBaseUrl = \"\", verificationEnvelope = undefined, } = {}) | { subject, cwd = process.cwd(), passportLocation = \"\", locatorConfig = \"\", repository = \"\", tag = \"\", githubReleaseBaseUrl = \"\", subjectDigest = \"\", subjectKind = \"\", npmRegistryBaseUrl = \"\", verificationEnvelope = undefined, } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyArtifactPassport } from \"@kungfu-tech/buildchain/artifact-passport\";` | `packages/core/artifact-passport.js:701` |\n\n## `@kungfu-tech/buildchain/artifact-verification-envelope`\n\nTarget: `./packages/core/artifact-verification-envelope.js`. Public symbols: 11.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `ARTIFACT_VERIFICATION_ENVELOPE_CHECK_CONTRACT` | constant: const ARTIFACT_VERIFICATION_ENVELOPE_CHECK_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_VERIFICATION_ENVELOPE_CHECK_CONTRACT } from \"@kungfu-tech/buildchain/artifact-verification-envelope\";` | `packages/core/artifact-verification-envelope.js:12` |\n| `ARTIFACT_VERIFICATION_ENVELOPE_CONTRACT` | constant: const ARTIFACT_VERIFICATION_ENVELOPE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_VERIFICATION_ENVELOPE_CONTRACT } from \"@kungfu-tech/buildchain/artifact-verification-envelope\";` | `packages/core/artifact-verification-envelope.js:10` |\n| `artifactVerificationEnvelopeDigest` | function: function artifactVerificationEnvelopeDigest(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { artifactVerificationEnvelopeDigest } from \"@kungfu-tech/buildchain/artifact-verification-envelope\";` | `packages/core/artifact-verification-envelope.js:59` |\n| `createKfdAdopterReleaseBinding` | function: function createKfdAdopterReleaseBinding({ manifest, manifestGate, legacyProjection, manifestPath = \"kfd-adopter-manifest.json\", gatePath = \"kfd-adopter-manifest-gate.json\", legacyProjectionPath = \"kfd-support.json\", expectedSourceSha = \"\", } = {}) | { manifest, manifestGate, legacyProjection, manifestPath = \"kfd-adopter-manifest.json\", gatePath = \"kfd-adopter-manifest-gate.json\", legacyProjectionPath = \"kfd-support.json\", expectedSourceSha = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createKfdAdopterReleaseBinding } from \"@kungfu-tech/buildchain/artifact-verification-envelope\";` | `packages/core/artifact-verification-envelope.js:441` |\n| `installedKfdPackageArtifactRoot` | function: function installedKfdPackageArtifactRoot() | none | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { installedKfdPackageArtifactRoot } from \"@kungfu-tech/buildchain/artifact-verification-envelope\";` | `packages/core/artifact-verification-envelope.js:397` |\n| `KFD_ADOPTER_RELEASE_BINDING_CONTRACT` | constant: const KFD_ADOPTER_RELEASE_BINDING_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_ADOPTER_RELEASE_BINDING_CONTRACT } from \"@kungfu-tech/buildchain/artifact-verification-envelope\";` | `packages/core/artifact-verification-envelope.js:16` |\n| `KFX_ADMISSION_INPUTS_CONTRACT` | constant: const KFX_ADMISSION_INPUTS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFX_ADMISSION_INPUTS_CONTRACT } from \"@kungfu-tech/buildchain/artifact-verification-envelope\";` | `packages/core/artifact-verification-envelope.js:14` |\n| `projectArtifactVerificationEnvelopeToKfx` | function: function projectArtifactVerificationEnvelopeToKfx({ envelope, assessmentTime = Math.floor(Date.now() / 1000), expectedEnvelopeRoot = \"\", expectedIssuer = \"\", expectedPublisher = \"\", expectedContractVersion = \"\", } = {}) | { envelope, assessmentTime = Math.floor(Date.now() / 1000), expectedEnvelopeRoot = \"\", expectedIssuer = \"\", expectedPublisher = \"\", expectedContractVersion = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { projectArtifactVerificationEnvelopeToKfx } from \"@kungfu-tech/buildchain/artifact-verification-envelope\";` | `packages/core/artifact-verification-envelope.js:368` |\n| `sealArtifactVerificationReport` | function: function sealArtifactVerificationReport({ report, bindings, kfdAssessment, issuedAt, expiresAt, revocation, } = {}) | { report, bindings, kfdAssessment, issuedAt, expiresAt, revocation, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { sealArtifactVerificationReport } from \"@kungfu-tech/buildchain/artifact-verification-envelope\";` | `packages/core/artifact-verification-envelope.js:323` |\n| `validateKfdAdopterReleaseBinding` | function: function validateKfdAdopterReleaseBinding(binding, { manifest, manifestGate, legacyProjection, expectedSourceSha = \"\", } = {}) | binding, { manifest, manifestGate, legacyProjection, expectedSourceSha = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateKfdAdopterReleaseBinding } from \"@kungfu-tech/buildchain/artifact-verification-envelope\";` | `packages/core/artifact-verification-envelope.js:467` |\n| `verifyArtifactVerificationEnvelope` | function: function verifyArtifactVerificationEnvelope({ envelope, assessmentTime = Math.floor(Date.now() / 1000), expectedEnvelopeRoot = \"\", expectedIssuer = \"\", expectedPublisher = \"\", expectedContractVersion = \"\", } = {}) | { envelope, assessmentTime = Math.floor(Date.now() / 1000), expectedEnvelopeRoot = \"\", expectedIssuer = \"\", expectedPublisher = \"\", expectedContractVersion = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyArtifactVerificationEnvelope } from \"@kungfu-tech/buildchain/artifact-verification-envelope\";` | `packages/core/artifact-verification-envelope.js:153` |\n\n## `@kungfu-tech/buildchain/github-artifact-attestation`\n\nTarget: `./packages/core/github-artifact-attestation.js`. Public symbols: 18.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `createGitHubArtifactAttestationEvidence` | function: function createGitHubArtifactAttestationEvidence({ preparation, attestationId, attestationUrl, bundlePath, workflow = {}, } = {}) | { preparation, attestationId, attestationUrl, bundlePath, workflow = {}, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createGitHubArtifactAttestationEvidence } from \"@kungfu-tech/buildchain/github-artifact-attestation\";` | `packages/core/github-artifact-attestation.js:474` |\n| `createGitHubArtifactAttestationPolicy` | function: function createGitHubArtifactAttestationPolicy(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGitHubArtifactAttestationPolicy } from \"@kungfu-tech/buildchain/github-artifact-attestation\";` | `packages/core/github-artifact-attestation.js:204` |\n| `createGitHubArtifactAttestationVerificationPlan` | function: function createGitHubArtifactAttestationVerificationPlan({ artifactPath, bundlePath, evidence, } = {}) | { artifactPath, bundlePath, evidence, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGitHubArtifactAttestationVerificationPlan } from \"@kungfu-tech/buildchain/github-artifact-attestation\";` | `packages/core/github-artifact-attestation.js:524` |\n| `GITHUB_ARTIFACT_ATTESTATION_EVIDENCE_CONTRACT` | constant: const GITHUB_ARTIFACT_ATTESTATION_EVIDENCE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_ARTIFACT_ATTESTATION_EVIDENCE_CONTRACT } from \"@kungfu-tech/buildchain/github-artifact-attestation\";` | `packages/core/github-artifact-attestation.js:9` |\n| `GITHUB_ARTIFACT_ATTESTATION_POLICY_CONTRACT` | constant: const GITHUB_ARTIFACT_ATTESTATION_POLICY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_ARTIFACT_ATTESTATION_POLICY_CONTRACT } from \"@kungfu-tech/buildchain/github-artifact-attestation\";` | `packages/core/github-artifact-attestation.js:5` |\n| `GITHUB_ARTIFACT_ATTESTATION_PREDICATE_CONTRACT` | constant: const GITHUB_ARTIFACT_ATTESTATION_PREDICATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_ARTIFACT_ATTESTATION_PREDICATE_CONTRACT } from \"@kungfu-tech/buildchain/github-artifact-attestation\";` | `packages/core/github-artifact-attestation.js:7` |\n| `GITHUB_ARTIFACT_ATTESTATION_PREDICATE_TYPE` | constant: const GITHUB_ARTIFACT_ATTESTATION_PREDICATE_TYPE | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_ARTIFACT_ATTESTATION_PREDICATE_TYPE } from \"@kungfu-tech/buildchain/github-artifact-attestation\";` | `packages/core/github-artifact-attestation.js:13` |\n| `GITHUB_ARTIFACT_ATTESTATION_VERIFICATION_CONTRACT` | constant: const GITHUB_ARTIFACT_ATTESTATION_VERIFICATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_ARTIFACT_ATTESTATION_VERIFICATION_CONTRACT } from \"@kungfu-tech/buildchain/github-artifact-attestation\";` | `packages/core/github-artifact-attestation.js:11` |\n| `GITHUB_ARTIFACT_ATTESTATION_WORKFLOW` | constant: const GITHUB_ARTIFACT_ATTESTATION_WORKFLOW | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_ARTIFACT_ATTESTATION_WORKFLOW } from \"@kungfu-tech/buildchain/github-artifact-attestation\";` | `packages/core/github-artifact-attestation.js:15` |\n| `githubArtifactAttestationRequiredPermissions` | function: function githubArtifactAttestationRequiredPermissions() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { githubArtifactAttestationRequiredPermissions } from \"@kungfu-tech/buildchain/github-artifact-attestation\";` | `packages/core/github-artifact-attestation.js:640` |\n| `githubArtifactAttestationSemanticRoot` | function: function githubArtifactAttestationSemanticRoot(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { githubArtifactAttestationSemanticRoot } from \"@kungfu-tech/buildchain/github-artifact-attestation\";` | `packages/core/github-artifact-attestation.js:91` |\n| `githubArtifactAttestationSha256Buffer` | function: function githubArtifactAttestationSha256Buffer(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { githubArtifactAttestationSha256Buffer } from \"@kungfu-tech/buildchain/github-artifact-attestation\";` | `packages/core/github-artifact-attestation.js:83` |\n| `githubArtifactAttestationSha256File` | function: function githubArtifactAttestationSha256File(filePath) | filePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { githubArtifactAttestationSha256File } from \"@kungfu-tech/buildchain/github-artifact-attestation\";` | `packages/core/github-artifact-attestation.js:87` |\n| `normalizeGitHubArtifactAttestationPolicy` | function: function normalizeGitHubArtifactAttestationPolicy(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeGitHubArtifactAttestationPolicy } from \"@kungfu-tech/buildchain/github-artifact-attestation\";` | `packages/core/github-artifact-attestation.js:158` |\n| `prepareGitHubArtifactAttestation` | function: function prepareGitHubArtifactAttestation({ subjectPath, platformManifestPath, releasePassportPath, policy, expectedBuildchainRef = \"\", expectedCallerRepository = \"\", expectedSourceSha = \"\", } = {}) | { subjectPath, platformManifestPath, releasePassportPath, policy, expectedBuildchainRef = \"\", expectedCallerRepository = \"\", expectedSourceSha = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { prepareGitHubArtifactAttestation } from \"@kungfu-tech/buildchain/github-artifact-attestation\";` | `packages/core/github-artifact-attestation.js:250` |\n| `stableJson` | function: function stableJson(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { stableJson } from \"@kungfu-tech/buildchain/github-artifact-attestation\";` | `packages/core/github-artifact-attestation.js:72` |\n| `stageGitHubArtifactAttestationInputs` | function: function stageGitHubArtifactAttestationInputs({ policy, subjectRoots = [], platformManifestPaths = [], releasePassportPath, outputDir = \".buildchain/github-artifact-attestation-input\", } = {}) | { policy, subjectRoots = [], platformManifestPaths = [], releasePassportPath, outputDir = \".buildchain/github-artifact-attestation-input\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { stageGitHubArtifactAttestationInputs } from \"@kungfu-tech/buildchain/github-artifact-attestation\";` | `packages/core/github-artifact-attestation.js:389` |\n| `verifyGitHubArtifactAttestationEvidence` | function: function verifyGitHubArtifactAttestationEvidence({ artifactPath, platformManifestPath, releasePassportPath, bundlePath, evidence, verificationResults, } = {}) | { artifactPath, platformManifestPath, releasePassportPath, bundlePath, evidence, verificationResults, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { verifyGitHubArtifactAttestationEvidence } from \"@kungfu-tech/buildchain/github-artifact-attestation\";` | `packages/core/github-artifact-attestation.js:563` |\n\n## `@kungfu-tech/buildchain/artifact-signing`\n\nTarget: `./packages/core/artifact-signing.js`. Public symbols: 10.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `ARTIFACT_SIGNING_AUTHORITY_CONTRACT` | constant: const ARTIFACT_SIGNING_AUTHORITY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_SIGNING_AUTHORITY_CONTRACT } from \"@kungfu-tech/buildchain/artifact-signing\";` | `packages/core/artifact-signing.js:7` |\n| `ARTIFACT_SIGNING_RECEIPT_CONTRACT` | constant: const ARTIFACT_SIGNING_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_SIGNING_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain/artifact-signing\";` | `packages/core/artifact-signing.js:5` |\n| `ARTIFACT_SIGNING_REQUEST_CONTRACT` | constant: const ARTIFACT_SIGNING_REQUEST_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_SIGNING_REQUEST_CONTRACT } from \"@kungfu-tech/buildchain/artifact-signing\";` | `packages/core/artifact-signing.js:3` |\n| `artifactSigningDigest` | function: function artifactSigningDigest(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { artifactSigningDigest } from \"@kungfu-tech/buildchain/artifact-signing\";` | `packages/core/artifact-signing.js:60` |\n| `createArtifactSigningReceipt` | function: function createArtifactSigningReceipt({ request, status = \"passed\", authority = {}, result = {}, signatures = [], reason = \"\", } = {}) | { request, status = \"passed\", authority = {}, result = {}, signatures = [], reason = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createArtifactSigningReceipt } from \"@kungfu-tech/buildchain/artifact-signing\";` | `packages/core/artifact-signing.js:313` |\n| `createArtifactSigningRequest` | function: function createArtifactSigningRequest({ source = {}, runtime = {}, artifact = {}, signature = {}, delivery = {}, } = {}) | { source = {}, runtime = {}, artifact = {}, signature = {}, delivery = {}, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createArtifactSigningRequest } from \"@kungfu-tech/buildchain/artifact-signing\";` | `packages/core/artifact-signing.js:167` |\n| `listArtifactSigningProfiles` | function: function listArtifactSigningProfiles() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { listArtifactSigningProfiles } from \"@kungfu-tech/buildchain/artifact-signing\";` | `packages/core/artifact-signing.js:103` |\n| `resolveArtifactSigningProfile` | function: function resolveArtifactSigningProfile({ profile = \"auto\", platform = \"\", artifactKind = \"binary\", } = {}) | { profile = \"auto\", platform = \"\", artifactKind = \"binary\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolveArtifactSigningProfile } from \"@kungfu-tech/buildchain/artifact-signing\";` | `packages/core/artifact-signing.js:111` |\n| `validateArtifactSigningReceipt` | function: function validateArtifactSigningReceipt(receipt, { request } = {}) | receipt, { request } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { validateArtifactSigningReceipt } from \"@kungfu-tech/buildchain/artifact-signing\";` | `packages/core/artifact-signing.js:374` |\n| `validateArtifactSigningRequest` | function: function validateArtifactSigningRequest(request) | request | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { validateArtifactSigningRequest } from \"@kungfu-tech/buildchain/artifact-signing\";` | `packages/core/artifact-signing.js:291` |\n\n## `@kungfu-tech/buildchain/artifact-signing-result`\n\nTarget: `./packages/core/artifact-signing-result.js`. Public symbols: 5.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `ARTIFACT_SIGNING_RESULT_CONTRACT` | constant: const ARTIFACT_SIGNING_RESULT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_SIGNING_RESULT_CONTRACT } from \"@kungfu-tech/buildchain/artifact-signing-result\";` | `packages/core/artifact-signing-result.js:12` |\n| `artifactSigningEvidenceDigest` | function: function artifactSigningEvidenceDigest(evidence = []) | evidence = [] | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { artifactSigningEvidenceDigest } from \"@kungfu-tech/buildchain/artifact-signing-result\";` | `packages/core/artifact-signing-result.js:58` |\n| `createArtifactSigningResult` | function: function createArtifactSigningResult({ request, receipt, receiptPath = \"receipt.json\", payload = {}, evidence = [], verification = {}, } = {}) | { request, receipt, receiptPath = \"receipt.json\", payload = {}, evidence = [], verification = {}, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createArtifactSigningResult } from \"@kungfu-tech/buildchain/artifact-signing-result\";` | `packages/core/artifact-signing-result.js:68` |\n| `validateArtifactSigningResult` | function: function validateArtifactSigningResult(result, { request, receipt } = {}) | result, { request, receipt } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { validateArtifactSigningResult } from \"@kungfu-tech/buildchain/artifact-signing-result\";` | `packages/core/artifact-signing-result.js:147` |\n| `verifyArtifactSigningResultFiles` | function: function verifyArtifactSigningResultFiles({ root, request, receipt, result, } = {}) | { root, request, receipt, result, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyArtifactSigningResultFiles } from \"@kungfu-tech/buildchain/artifact-signing-result\";` | `packages/core/artifact-signing-result.js:193` |\n\n## `@kungfu-tech/buildchain/detached-artifact-signature`\n\nTarget: `./packages/core/detached-artifact-signature.js`. Public symbols: 3.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `DETACHED_ARTIFACT_SIGNATURE_CONTRACT` | constant: const DETACHED_ARTIFACT_SIGNATURE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { DETACHED_ARTIFACT_SIGNATURE_CONTRACT } from \"@kungfu-tech/buildchain/detached-artifact-signature\";` | `packages/core/detached-artifact-signature.js:10` |\n| `signDetachedArtifactRequest` | function: function signDetachedArtifactRequest({ request, privateKey, keyId, authority = {}, } = {}) | { request, privateKey, keyId, authority = {}, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { signDetachedArtifactRequest } from \"@kungfu-tech/buildchain/detached-artifact-signature\";` | `packages/core/detached-artifact-signature.js:36` |\n| `verifyDetachedArtifactSignature` | function: function verifyDetachedArtifactSignature({ request, envelope, publicKey, } = {}) | { request, envelope, publicKey, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyDetachedArtifactSignature } from \"@kungfu-tech/buildchain/detached-artifact-signature\";` | `packages/core/detached-artifact-signature.js:82` |\n\n## `@kungfu-tech/buildchain/anchored-version-material`\n\nTarget: `./packages/core/anchored-version-material.js`. Public symbols: 2.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `ANCHORED_VERSION_MATERIAL_CONTRACT` | constant: const ANCHORED_VERSION_MATERIAL_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ANCHORED_VERSION_MATERIAL_CONTRACT } from \"@kungfu-tech/buildchain/anchored-version-material\";` | `packages/core/anchored-version-material.js:15` |\n| `createAnchoredVersionMaterialEvidence` | function: function createAnchoredVersionMaterialEvidence({ cwd = process.cwd(), targetChannel = \"\", targetRef = \"\", alphaRef = \"\", releaseRef = \"HEAD\", runLifecycle = true, } = {}) | { cwd = process.cwd(), targetChannel = \"\", targetRef = \"\", alphaRef = \"\", releaseRef = \"HEAD\", runLifecycle = true, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createAnchoredVersionMaterialEvidence } from \"@kungfu-tech/buildchain/anchored-version-material\";` | `packages/core/anchored-version-material.js:118` |\n\n## `@kungfu-tech/buildchain/buildchain-contract`\n\nTarget: `./packages/core/buildchain-contract.js`. Public symbols: 16.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `BUILDCHAIN_CHANNELS` | value: BUILDCHAIN_CHANNELS | none | unknown | No narrower error contract was mechanically discoverable. | unknown | `import { BUILDCHAIN_CHANNELS } from \"@kungfu-tech/buildchain/buildchain-contract\";` | `packages/core/buildchain-contract.js:1` |\n| `BUILDCHAIN_CONTRACT_LOCK` | constant: const BUILDCHAIN_CONTRACT_LOCK | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONTRACT_LOCK } from \"@kungfu-tech/buildchain/buildchain-contract\";` | `packages/core/buildchain-contract.js:21` |\n| `BUILDCHAIN_RUNTIME_CONTRACT_WORLD` | constant: const BUILDCHAIN_RUNTIME_CONTRACT_WORLD | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_RUNTIME_CONTRACT_WORLD } from \"@kungfu-tech/buildchain/buildchain-contract\";` | `packages/core/buildchain-contract.js:20` |\n| `contractSummary` | function: function contractSummary(contractWorld, runtimeRef = \"\", runtimeSha = \"\") | contractWorld, runtimeRef = \"\", runtimeSha = \"\" | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { contractSummary } from \"@kungfu-tech/buildchain/buildchain-contract\";` | `packages/core/buildchain-contract.js:1031` |\n| `createBuildchainContractLock` | function: function createBuildchainContractLock({ buildchainRef = \"v3\", resolvedSha = \"\", contractWorld, compatibilityPolicy = DEFAULT_POLICY, acceptedAt = new Date().toISOString(), } = {}) | { buildchainRef = \"v3\", resolvedSha = \"\", contractWorld, compatibilityPolicy = DEFAULT_POLICY, acceptedAt = new Date().toISOString(), } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createBuildchainContractLock } from \"@kungfu-tech/buildchain/buildchain-contract\";` | `packages/core/buildchain-contract.js:830` |\n| `createBuildchainContractWorld` | function: function createBuildchainContractWorld({ root = process.cwd(), packageJson = undefined, controllerRegistry = undefined, } = {}) | { root = process.cwd(), packageJson = undefined, controllerRegistry = undefined, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainContractWorld } from \"@kungfu-tech/buildchain/buildchain-contract\";` | `packages/core/buildchain-contract.js:123` |\n| `evaluateBuildchainChannelBinding` | value: evaluateBuildchainChannelBinding | none | unknown | No narrower error contract was mechanically discoverable. | unknown | `import { evaluateBuildchainChannelBinding } from \"@kungfu-tech/buildchain/buildchain-contract\";` | `packages/core/buildchain-contract.js:1` |\n| `evaluateBuildchainContractLock` | function: function evaluateBuildchainContractLock({ lock, current, runtimeRef = \"\", runtimeSha = \"\", runtimeClass = \"\", compatibilityPolicy = \"\", workflowShellRef = \"\", expectedChannel = \"\", expectedMajor = \"\", allowOpaqueRuntime = false, } = {}) | { lock, current, runtimeRef = \"\", runtimeSha = \"\", runtimeClass = \"\", compatibilityPolicy = \"\", workflowShellRef = \"\", expectedChannel = \"\", expectedMajor = \"\", allowOpaqueRuntime = false, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { evaluateBuildchainContractLock } from \"@kungfu-tech/buildchain/buildchain-contract\";` | `packages/core/buildchain-contract.js:916` |\n| `finalizeBuildchainContractWorld` | function: function finalizeBuildchainContractWorld(contractWorld) | contractWorld | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { finalizeBuildchainContractWorld } from \"@kungfu-tech/buildchain/buildchain-contract\";` | `packages/core/buildchain-contract.js:805` |\n| `normalizeBuildchainRef` | value: normalizeBuildchainRef | none | unknown | No narrower error contract was mechanically discoverable. | unknown | `import { normalizeBuildchainRef } from \"@kungfu-tech/buildchain/buildchain-contract\";` | `packages/core/buildchain-contract.js:1` |\n| `parseBuildchainRefIdentity` | value: parseBuildchainRefIdentity | none | unknown | No narrower error contract was mechanically discoverable. | unknown | `import { parseBuildchainRefIdentity } from \"@kungfu-tech/buildchain/buildchain-contract\";` | `packages/core/buildchain-contract.js:1` |\n| `readBuildchainContractLock` | function: function readBuildchainContractLock(filePath) | filePath | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readBuildchainContractLock } from \"@kungfu-tech/buildchain/buildchain-contract\";` | `packages/core/buildchain-contract.js:881` |\n| `readBuildchainContractWorld` | function: function readBuildchainContractWorld(filePath) | filePath | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readBuildchainContractWorld } from \"@kungfu-tech/buildchain/buildchain-contract\";` | `packages/core/buildchain-contract.js:861` |\n| `renderBuildchainContractDriftIssueBody` | function: function renderBuildchainContractDriftIssueBody({ repository = \"\", workflow = \"\", runUrl = \"\", lockPath = \"\", evaluation, } = {}) | { repository = \"\", workflow = \"\", runUrl = \"\", lockPath = \"\", evaluation, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { renderBuildchainContractDriftIssueBody } from \"@kungfu-tech/buildchain/buildchain-contract\";` | `packages/core/buildchain-contract.js:1043` |\n| `sha256File` | function: function sha256File(filePath) | filePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { sha256File } from \"@kungfu-tech/buildchain/buildchain-contract\";` | `packages/core/buildchain-contract.js:47` |\n| `sha256Json` | function: function sha256Json(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { sha256Json } from \"@kungfu-tech/buildchain/buildchain-contract\";` | `packages/core/buildchain-contract.js:43` |\n\n## `@kungfu-tech/buildchain/candidate-timeline`\n\nTarget: `./packages/core/candidate-timeline.js`. Public symbols: 5.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `BUILDCHAIN_CANDIDATE_TIMELINE_CONTRACT` | constant: const BUILDCHAIN_CANDIDATE_TIMELINE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CANDIDATE_TIMELINE_CONTRACT } from \"@kungfu-tech/buildchain/candidate-timeline\";` | `packages/core/candidate-timeline.js:1` |\n| `BUILDCHAIN_CANDIDATE_TIMELINE_EVENT_CONTRACT` | constant: const BUILDCHAIN_CANDIDATE_TIMELINE_EVENT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CANDIDATE_TIMELINE_EVENT_CONTRACT } from \"@kungfu-tech/buildchain/candidate-timeline\";` | `packages/core/candidate-timeline.js:3` |\n| `createCandidateTimeline` | function: function createCandidateTimeline({ candidate = {}, events = [], generatedAt, } = {}) | { candidate = {}, events = [], generatedAt, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createCandidateTimeline } from \"@kungfu-tech/buildchain/candidate-timeline\";` | `packages/core/candidate-timeline.js:381` |\n| `formatCandidateTimelineReport` | function: function formatCandidateTimelineReport(timeline) | timeline | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { formatCandidateTimelineReport } from \"@kungfu-tech/buildchain/candidate-timeline\";` | `packages/core/candidate-timeline.js:438` |\n| `normalizeCandidateTimelineEvent` | function: function normalizeCandidateTimelineEvent(input = {}) | input = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeCandidateTimelineEvent } from \"@kungfu-tech/buildchain/candidate-timeline\";` | `packages/core/candidate-timeline.js:74` |\n\n## `@kungfu-tech/buildchain/channel-candidate`\n\nTarget: `./packages/core/channel-candidate.js`. Public symbols: 3.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `CHANNEL_CANDIDATE_DECISION_SCHEMA` | constant: const CHANNEL_CANDIDATE_DECISION_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { CHANNEL_CANDIDATE_DECISION_SCHEMA } from \"@kungfu-tech/buildchain/channel-candidate\";` | `packages/core/channel-candidate.js:6` |\n| `channelCandidateSourceLockRef` | function: function channelCandidateSourceLockRef(targetBranch, sourceSha) | targetBranch, sourceSha | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { channelCandidateSourceLockRef } from \"@kungfu-tech/buildchain/channel-candidate\";` | `packages/core/channel-candidate.js:85` |\n| `decideChannelCandidate` | function: function decideChannelCandidate(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { decideChannelCandidate } from \"@kungfu-tech/buildchain/channel-candidate\";` | `packages/core/channel-candidate.js:91` |\n\n## `@kungfu-tech/buildchain/cache-evidence`\n\nTarget: `./packages/core/cache-evidence.js`. Public symbols: 7.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `BUILDCHAIN_CACHE_EVIDENCE_SET_CONTRACT` | constant: const BUILDCHAIN_CACHE_EVIDENCE_SET_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CACHE_EVIDENCE_SET_CONTRACT } from \"@kungfu-tech/buildchain/cache-evidence\";` | `packages/core/cache-evidence.js:5` |\n| `BUILDCHAIN_CACHE_OPERATION_RECEIPT_CONTRACT` | constant: const BUILDCHAIN_CACHE_OPERATION_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CACHE_OPERATION_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain/cache-evidence\";` | `packages/core/cache-evidence.js:3` |\n| `cacheEvidenceDigest` | function: function cacheEvidenceDigest(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { cacheEvidenceDigest } from \"@kungfu-tech/buildchain/cache-evidence\";` | `packages/core/cache-evidence.js:48` |\n| `createCacheEvidenceSet` | function: function createCacheEvidenceSet({ repository, sourceCommit, sourceTree = \"\", runtimeCommit = \"\", platform, operations = [], } = {}) | { repository, sourceCommit, sourceTree = \"\", runtimeCommit = \"\", platform, operations = [], } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createCacheEvidenceSet } from \"@kungfu-tech/buildchain/cache-evidence\";` | `packages/core/cache-evidence.js:244` |\n| `createCacheOperationReceipt` | function: function createCacheOperationReceipt({ operationId, operation, provider, producer, platform, cacheKey, cacheRoot, outcome, bindings = {}, metrics, evidence, } = {}) | { operationId, operation, provider, producer, platform, cacheKey, cacheRoot, outcome, bindings = {}, metrics, evidence, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createCacheOperationReceipt } from \"@kungfu-tech/buildchain/cache-evidence\";` | `packages/core/cache-evidence.js:169` |\n| `verifyCacheEvidenceSet` | function: function verifyCacheEvidenceSet(receipt) | receipt | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyCacheEvidenceSet } from \"@kungfu-tech/buildchain/cache-evidence\";` | `packages/core/cache-evidence.js:273` |\n| `verifyCacheOperationReceipt` | function: function verifyCacheOperationReceipt(receipt) | receipt | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyCacheOperationReceipt } from \"@kungfu-tech/buildchain/cache-evidence\";` | `packages/core/cache-evidence.js:226` |\n\n## `@kungfu-tech/buildchain/controller-evidence`\n\nTarget: `./packages/core/controller-evidence.js`. Public symbols: 14.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `aggregateControllerReceipts` | function: function aggregateControllerReceipts({ plans = [], receipts = [] } = {}) | { plans = [], receipts = [] } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { aggregateControllerReceipts } from \"@kungfu-tech/buildchain/controller-evidence\";` | `packages/core/controller-evidence.js:449` |\n| `BUILDCHAIN_CONTROLLER_AGGREGATE_CONTRACT` | constant: const BUILDCHAIN_CONTROLLER_AGGREGATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONTROLLER_AGGREGATE_CONTRACT } from \"@kungfu-tech/buildchain/controller-evidence\";` | `packages/core/controller-evidence.js:6` |\n| `BUILDCHAIN_CONTROLLER_DESCRIPTOR_CONTRACT` | constant: const BUILDCHAIN_CONTROLLER_DESCRIPTOR_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONTROLLER_DESCRIPTOR_CONTRACT } from \"@kungfu-tech/buildchain/controller-evidence\";` | `packages/core/controller-evidence.js:4` |\n| `BUILDCHAIN_CONTROLLER_EVIDENCE_CONTRACT` | constant: const BUILDCHAIN_CONTROLLER_EVIDENCE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONTROLLER_EVIDENCE_CONTRACT } from \"@kungfu-tech/buildchain/controller-evidence\";` | `packages/core/controller-evidence.js:3` |\n| `BUILDCHAIN_CONTROLLER_REGISTRY_CONTRACT` | constant: const BUILDCHAIN_CONTROLLER_REGISTRY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONTROLLER_REGISTRY_CONTRACT } from \"@kungfu-tech/buildchain/controller-evidence\";` | `packages/core/controller-evidence.js:5` |\n| `controllerEvidenceDigest` | function: function controllerEvidenceDigest(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { controllerEvidenceDigest } from \"@kungfu-tech/buildchain/controller-evidence\";` | `packages/core/controller-evidence.js:151` |\n| `createControllerPlan` | function: function createControllerPlan({ descriptor, source = {}, runtime = {}, inputs = {} } = {}) | { descriptor, source = {}, runtime = {}, inputs = {} } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createControllerPlan } from \"@kungfu-tech/buildchain/controller-evidence\";` | `packages/core/controller-evidence.js:287` |\n| `createControllerReceipt` | function: function createControllerReceipt({ plan, stages = [], evidence = [], reason = undefined, artifact = \"\" } = {}) | { plan, stages = [], evidence = [], reason = undefined, artifact = \"\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createControllerReceipt } from \"@kungfu-tech/buildchain/controller-evidence\";` | `packages/core/controller-evidence.js:363` |\n| `createControllerReceiptReference` | function: function createControllerReceiptReference(receipt) | receipt | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createControllerReceiptReference } from \"@kungfu-tech/buildchain/controller-evidence\";` | `packages/core/controller-evidence.js:491` |\n| `createControllerRegistry` | function: function createControllerRegistry({ workflows = [] } = {}) | { workflows = [] } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createControllerRegistry } from \"@kungfu-tech/buildchain/controller-evidence\";` | `packages/core/controller-evidence.js:197` |\n| `normalizeControllerReceiptReferences` | function: function normalizeControllerReceiptReferences({ receipts = [], references = [], expectedSourceSha = \"\", acceptedSourceShas = [], expectedRuntimeSha = \"\", requirePassed = false, } = {}) | { receipts = [], references = [], expectedSourceSha = \"\", acceptedSourceShas = [], expectedRuntimeSha = \"\", requirePassed = false, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeControllerReceiptReferences } from \"@kungfu-tech/buildchain/controller-evidence\";` | `packages/core/controller-evidence.js:532` |\n| `validateControllerPlan` | function: function validateControllerPlan(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateControllerPlan } from \"@kungfu-tech/buildchain/controller-evidence\";` | `packages/core/controller-evidence.js:325` |\n| `validateControllerReceipt` | function: function validateControllerReceipt(receipt, { plan = undefined, expectedSourceSha = \"\", expectedRuntimeSha = \"\", expectedPlanDigest = \"\", } = {}) | receipt, { plan = undefined, expectedSourceSha = \"\", expectedRuntimeSha = \"\", expectedPlanDigest = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateControllerReceipt } from \"@kungfu-tech/buildchain/controller-evidence\";` | `packages/core/controller-evidence.js:423` |\n| `validateControllerReceiptReference` | function: function validateControllerReceiptReference(reference, { expectedSourceSha = \"\", acceptedSourceShas = [], expectedRuntimeSha = \"\", requirePassed = false, } = {}) | reference, { expectedSourceSha = \"\", acceptedSourceShas = [], expectedRuntimeSha = \"\", requirePassed = false, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateControllerReceiptReference } from \"@kungfu-tech/buildchain/controller-evidence\";` | `packages/core/controller-evidence.js:505` |\n\n## `@kungfu-tech/buildchain/diagnostics`\n\nTarget: `./packages/core/diagnostics.js`. Public symbols: 30.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `BUILDCHAIN_ANCHORED_PACKAGE_RELEASE_VALIDATION_CONTRACT` | constant: const BUILDCHAIN_ANCHORED_PACKAGE_RELEASE_VALIDATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_ANCHORED_PACKAGE_RELEASE_VALIDATION_CONTRACT } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:31` |\n| `BUILDCHAIN_DIAGNOSTICS_CONTRACT` | constant: const BUILDCHAIN_DIAGNOSTICS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_DIAGNOSTICS_CONTRACT } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:28` |\n| `BUILDCHAIN_DIAGNOSTICS_MANIFEST_CONTRACT` | constant: const BUILDCHAIN_DIAGNOSTICS_MANIFEST_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_DIAGNOSTICS_MANIFEST_CONTRACT } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:33` |\n| `BUILDCHAIN_DIAGNOSTICS_SUMMARY_CONTRACT` | constant: const BUILDCHAIN_DIAGNOSTICS_SUMMARY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_DIAGNOSTICS_SUMMARY_CONTRACT } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:35` |\n| `BUILDCHAIN_LIFECYCLE_OBSERVABILITY_CONTRACT` | constant: const BUILDCHAIN_LIFECYCLE_OBSERVABILITY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_LIFECYCLE_OBSERVABILITY_CONTRACT } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:29` |\n| `BUILDCHAIN_LOCKED_SOURCE_CHECKOUT_CONTRACT` | constant: const BUILDCHAIN_LOCKED_SOURCE_CHECKOUT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_LOCKED_SOURCE_CHECKOUT_CONTRACT } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:41` |\n| `BUILDCHAIN_PROCESS_SAMPLE_REPORT_CONTRACT` | constant: const BUILDCHAIN_PROCESS_SAMPLE_REPORT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_PROCESS_SAMPLE_REPORT_CONTRACT } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:37` |\n| `BUILDCHAIN_PROCESS_SAMPLE_SUMMARY_CONTRACT` | constant: const BUILDCHAIN_PROCESS_SAMPLE_SUMMARY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_PROCESS_SAMPLE_SUMMARY_CONTRACT } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:39` |\n| `classifyProcessCommand` | function: function classifyProcessCommand(command = \"\") | command = \"\" | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { classifyProcessCommand } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:1085` |\n| `collectBuildchainDiagnostics` | function: function collectBuildchainDiagnostics({ cwd = process.cwd(), artifactPaths = [] } = {}) | { cwd = process.cwd(), artifactPaths = [] } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectBuildchainDiagnostics } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:248` |\n| `collectCacheDiagnostics` | function: function collectCacheDiagnostics({ cwd = process.cwd(), cacheDirs = [], runCommand = defaultDiagnosticCommandRunner } = {}) | { cwd = process.cwd(), cacheDirs = [], runCommand = defaultDiagnosticCommandRunner } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectCacheDiagnostics } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:922` |\n| `collectCompilerCacheDiagnostics` | function: function collectCompilerCacheDiagnostics({ cwd = process.cwd(), runCommand = defaultDiagnosticCommandRunner, env = process.env, } = {}) | { cwd = process.cwd(), runCommand = defaultDiagnosticCommandRunner, env = process.env, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectCompilerCacheDiagnostics } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:573` |\n| `collectGitDiagnostics` | function: function collectGitDiagnostics({ cwd = process.cwd() } = {}) | { cwd = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectGitDiagnostics } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:944` |\n| `collectNativeDiagnostics` | function: function collectNativeDiagnostics({ cwd = process.cwd(), profile = undefined, runCommand = defaultDiagnosticCommandRunner, } = {}) | { cwd = process.cwd(), profile = undefined, runCommand = defaultDiagnosticCommandRunner, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectNativeDiagnostics } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:295` |\n| `collectProcessTreeSnapshot` | function: function collectProcessTreeSnapshot({ rootPid = process.pid, cwd = process.cwd(), platform = process.platform, runCommand = defaultDiagnosticCommandRunner, } = {}) | { rootPid = process.pid, cwd = process.cwd(), platform = process.platform, runCommand = defaultDiagnosticCommandRunner, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectProcessTreeSnapshot } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:1029` |\n| `collectRunnerDiagnostics` | function: function collectRunnerDiagnostics() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectRunnerDiagnostics } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:468` |\n| `collectToolDiagnostics` | function: function collectToolDiagnostics({ cwd = process.cwd(), tools = [\"node\", \"pnpm\", \"npm\", \"git\", \"cmake\", \"ninja\", \"ccache\", \"sccache\"] } = {}) | { cwd = process.cwd(), tools = [\"node\", \"pnpm\", \"npm\", \"git\", \"cmake\", \"ninja\", \"ccache\", \"sccache\"] } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectToolDiagnostics } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:495` |\n| `createDiagnosticsArtifact` | function: function createDiagnosticsArtifact({ cwd = process.cwd(), logPath = \"\", artifactPaths = [], cacheDirs = [], lifecycleObservability = undefined, processSamples = [], processSummary = undefined, requestedParallelism = 0, sourceCheckout = undefined, compilerCachePreparation = undefined, links = {}, } = {}) | { cwd = process.cwd(), logPath = \"\", artifactPaths = [], cacheDirs = [], lifecycleObservability = undefined, processSamples = [], processSummary = undefined, requestedParallelism = 0, sourceCheckout = undefined, compilerCachePreparation = undefined, links = {}, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createDiagnosticsArtifact } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:1408` |\n| `createStructuredCacheEvidence` | function: function createStructuredCacheEvidence({ sourceCheckout, compilerCaches, compilerCachePreparation, platform, env = process.env, }) | { sourceCheckout, compilerCaches, compilerCachePreparation, platform, env = process.env, } | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createStructuredCacheEvidence } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:722` |\n| `detectRequestedParallelism` | function: function detectRequestedParallelism({ command = \"\", args = [], env = process.env, } = {}) | { command = \"\", args = [], env = process.env, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { detectRequestedParallelism } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:1188` |\n| `detectRequestedParallelismFromProcessSamples` | function: function detectRequestedParallelismFromProcessSamples(samples = []) | samples = [] | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { detectRequestedParallelismFromProcessSamples } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:1223` |\n| `formatDiagnosticsSummaryTable` | function: function formatDiagnosticsSummaryTable(summary = {}) | summary = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { formatDiagnosticsSummaryTable } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:1786` |\n| `readDiagnosticsArtifact` | function: function readDiagnosticsArtifact(filePath) | filePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { readDiagnosticsArtifact } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:1468` |\n| `redactDiagnosticsValue` | function: function redactDiagnosticsValue(key, value, pattern = DEFAULT_SECRET_KEY_PATTERN) | key, value, pattern = DEFAULT_SECRET_KEY_PATTERN | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { redactDiagnosticsValue } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:953` |\n| `startProcessSampler` | function: function startProcessSampler({ rootPid = process.pid, intervalMs = 15000, label = \"\", command = \"\", args = [], env = process.env, requestedParallelism = 0, onSample = () => undefined, cwd = process.cwd(), } = {}) | { rootPid = process.pid, intervalMs = 15000, label = \"\", command = \"\", args = [], env = process.env, requestedParallelism = 0, onSample = () => undefined, cwd = process.cwd(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { startProcessSampler } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:1362` |\n| `summarizeDiagnosticsArtifacts` | function: function summarizeDiagnosticsArtifacts(inputs = []) | inputs = [] | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { summarizeDiagnosticsArtifacts } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:1824` |\n| `summarizeLifecycleObservability` | function: function summarizeLifecycleObservability({ events = [], logPath = \"\", artifactScanDurationMs = 0, artifactUploadDurationMs = 0, totalBytes = 0, fileCount = 0, } = {}) | { events = [], logPath = \"\", artifactScanDurationMs = 0, artifactUploadDurationMs = 0, totalBytes = 0, fileCount = 0, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { summarizeLifecycleObservability } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:219` |\n| `summarizeProcessSamples` | function: function summarizeProcessSamples({ samples = [], requestedParallelism = 0, command = \"\", args = [], env = process.env, activeCpuThreshold = 0.1, } = {}) | { samples = [], requestedParallelism = 0, command = \"\", args = [], env = process.env, activeCpuThreshold = 0.1, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { summarizeProcessSamples } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:1254` |\n| `validateAnchoredPackageRelease` | function: function validateAnchoredPackageRelease({ cwd = process.cwd(), requireManifest = true, requirePackageSetOrder = \"platforms-first-main-last\", requireTrustedPublishing = true, requireLifecycleStages = [\"install\", \"build\", \"verify\", \"publish\"], requirePublishGateSourceLock = false, publishSource = undefined, env = process.env, } = {}) | { cwd = process.cwd(), requireManifest = true, requirePackageSetOrder = \"platforms-first-main-last\", requireTrustedPublishing = true, requireLifecycleStages = [\"install\", \"build\", \"verify\", \"publish\"], requirePublishGateSourceLock = false, publishSource = undefined, env = process.env, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateAnchoredPackageRelease } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:325` |\n| `writeDiagnosticsArtifact` | function: function writeDiagnosticsArtifact(filePath, diagnostics) | filePath, diagnostics | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write | `import { writeDiagnosticsArtifact } from \"@kungfu-tech/buildchain/diagnostics\";` | `packages/core/diagnostics.js:1459` |\n\n## `@kungfu-tech/buildchain/dev-delivery-warrant`\n\nTarget: `./packages/core/dev-delivery-warrant.js`. Public symbols: 34.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `cancelQueuedDevDeliveryCandidate` | function: function cancelQueuedDevDeliveryCandidate(queueInput, input, options) | queueInput, input, options | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { cancelQueuedDevDeliveryCandidate } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-warrant.js:573` |\n| `classifyDevDeliveryDelta` | function: function classifyDevDeliveryDelta({ proof, current = {} } = {}) | { proof, current = {} } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { classifyDevDeliveryDelta } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-proof.js:75` |\n| `closeDevDeliveryWarrant` | function: function closeDevDeliveryWarrant(queueInput, warrant, { outcome, evidenceRoot, reason = \"\", now = new Date().toISOString() } = {}) | queueInput, warrant, { outcome, evidenceRoot, reason = \"\", now = new Date().toISOString() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { closeDevDeliveryWarrant } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-warrant.js:525` |\n| `createDevDeliveryQueue` | function: function createDevDeliveryQueue({ repository: repositoryInput, protectedBase: protectedBaseInput, policy = {}, now = new Date().toISOString() } = {}) | { repository: repositoryInput, protectedBase: protectedBaseInput, policy = {}, now = new Date().toISOString() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createDevDeliveryQueue } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-warrant.js:99` |\n| `createIntegrationDeliveryProof` | function: function createIntegrationDeliveryProof(input = {}) | input = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createIntegrationDeliveryProof } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-proof.js:207` |\n| `createProjectCutReplayPlan` | function: function createProjectCutReplayPlan(input = {}) | input = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createProjectCutReplayPlan } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-proof.js:121` |\n| `createProjectCutReplayProof` | function: function createProjectCutReplayProof(input = {}) | input = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createProjectCutReplayProof } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-proof.js:141` |\n| `createReleaseBlockerPriorityClaim` | function: function createReleaseBlockerPriorityClaim(repairInput, input = {}) | repairInput, input = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createReleaseBlockerPriorityClaim } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/release-blocker-priority.js:32` |\n| `createSourceQualificationProof` | function: function createSourceQualificationProof(input = {}) | input = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createSourceQualificationProof } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-proof.js:31` |\n| `DEV_DELIVERY_CANCELLATION_RECEIPT_SCHEMA` | value: DEV_DELIVERY_CANCELLATION_RECEIPT_SCHEMA | none | unknown | No narrower error contract was mechanically discoverable. | unknown | `import { DEV_DELIVERY_CANCELLATION_RECEIPT_SCHEMA } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-warrant.js:1` |\n| `DEV_DELIVERY_CLASSES` | constant: const DEV_DELIVERY_CLASSES | none | value | Import does not declare a throw contract. | none-on-import | `import { DEV_DELIVERY_CLASSES } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-warrant.js:22` |\n| `DEV_DELIVERY_LEASE_RECEIPT_SCHEMA` | constant: const DEV_DELIVERY_LEASE_RECEIPT_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { DEV_DELIVERY_LEASE_RECEIPT_SCHEMA } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-warrant.js:14` |\n| `DEV_DELIVERY_PRIORITIES` | constant: const DEV_DELIVERY_PRIORITIES | none | value | Import does not declare a throw contract. | none-on-import | `import { DEV_DELIVERY_PRIORITIES } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-warrant.js:16` |\n| `DEV_DELIVERY_QUEUE_CONTRACT` | constant: const DEV_DELIVERY_QUEUE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { DEV_DELIVERY_QUEUE_CONTRACT } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-warrant.js:10` |\n| `DEV_DELIVERY_SELECTION_RECEIPT_SCHEMA` | constant: const DEV_DELIVERY_SELECTION_RECEIPT_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { DEV_DELIVERY_SELECTION_RECEIPT_SCHEMA } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-warrant.js:13` |\n| `DEV_DELIVERY_SETTLEMENT_RECEIPT_SCHEMA` | value: DEV_DELIVERY_SETTLEMENT_RECEIPT_SCHEMA | none | unknown | No narrower error contract was mechanically discoverable. | unknown | `import { DEV_DELIVERY_SETTLEMENT_RECEIPT_SCHEMA } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-warrant.js:1` |\n| `DEV_DELIVERY_SUBMISSION_RECEIPT_SCHEMA` | constant: const DEV_DELIVERY_SUBMISSION_RECEIPT_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { DEV_DELIVERY_SUBMISSION_RECEIPT_SCHEMA } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-warrant.js:12` |\n| `DEV_DELIVERY_WARRANT_SCHEMA` | constant: const DEV_DELIVERY_WARRANT_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { DEV_DELIVERY_WARRANT_SCHEMA } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-warrant.js:11` |\n| `devDeliveryContentRoot` | function: function devDeliveryContentRoot(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { devDeliveryContentRoot } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-common.js:27` |\n| `heartbeatDevDeliveryWarrant` | function: function heartbeatDevDeliveryWarrant(queueInput, warrant, { now = new Date().toISOString(), leaseSeconds } = {}) | queueInput, warrant, { now = new Date().toISOString(), leaseSeconds } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { heartbeatDevDeliveryWarrant } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-warrant.js:442` |\n| `INTEGRATION_DELIVERY_PROOF_SCHEMA` | constant: const INTEGRATION_DELIVERY_PROOF_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { INTEGRATION_DELIVERY_PROOF_SCHEMA } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-proof.js:5` |\n| `normalizeDevDeliveryQueue` | function: function normalizeDevDeliveryQueue(input, expected = {}) | input, expected = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeDevDeliveryQueue } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-warrant.js:114` |\n| `observeDevDeliveryQueue` | function: function observeDevDeliveryQueue(queueInput, { now = new Date().toISOString() } = {}) | queueInput, { now = new Date().toISOString() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { observeDevDeliveryQueue } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-warrant.js:576` |\n| `PROJECT_CUT_REPLAY_PROOF_SCHEMA` | constant: const PROJECT_CUT_REPLAY_PROOF_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { PROJECT_CUT_REPLAY_PROOF_SCHEMA } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-proof.js:4` |\n| `rankDevDeliveryCandidates` | function: function rankDevDeliveryCandidates(queueInput, { now = new Date().toISOString() } = {}) | queueInput, { now = new Date().toISOString() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { rankDevDeliveryCandidates } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-warrant.js:279` |\n| `recoverExpiredDevDeliveryWarrant` | function: function recoverExpiredDevDeliveryWarrant(queueInput, { now = new Date().toISOString() } = {}) | queueInput, { now = new Date().toISOString() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { recoverExpiredDevDeliveryWarrant } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-warrant.js:475` |\n| `RELEASE_BLOCKER_PRIORITY_CLAIM_SCHEMA` | constant: const RELEASE_BLOCKER_PRIORITY_CLAIM_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_BLOCKER_PRIORITY_CLAIM_SCHEMA } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/release-blocker-priority.js:15` |\n| `selectDevDeliveryWarrant` | function: function selectDevDeliveryWarrant(queueInput, { now = new Date().toISOString(), leaseSeconds } = {}) | queueInput, { now = new Date().toISOString(), leaseSeconds } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { selectDevDeliveryWarrant } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-warrant.js:303` |\n| `settleDevDeliveryTerminalEvent` | constant: const settleDevDeliveryTerminalEvent | none | value | Import does not declare a throw contract. | none-on-import | `import { settleDevDeliveryTerminalEvent } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-warrant.js:574` |\n| `SOURCE_QUALIFICATION_PROOF_SCHEMA` | constant: const SOURCE_QUALIFICATION_PROOF_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { SOURCE_QUALIFICATION_PROOF_SCHEMA } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-proof.js:3` |\n| `submitDevDeliveryCandidate` | function: function submitDevDeliveryCandidate(queueInput, input, { now = new Date().toISOString() } = {}) | queueInput, input, { now = new Date().toISOString() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { submitDevDeliveryCandidate } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-warrant.js:200` |\n| `verifyIntegrationDeliveryProof` | function: function verifyIntegrationDeliveryProof(proofInput, expected = {}) | proofInput, expected = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyIntegrationDeliveryProof } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-proof.js:228` |\n| `verifyProjectCutReplayProof` | function: function verifyProjectCutReplayProof(proofInput, expected = {}) | proofInput, expected = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyProjectCutReplayProof } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-proof.js:187` |\n| `verifySourceQualificationProof` | function: function verifySourceQualificationProof(proofInput, expected = {}) | proofInput, expected = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifySourceQualificationProof } from \"@kungfu-tech/buildchain/dev-delivery-warrant\";` | `packages/core/dev-delivery-proof.js:52` |\n\n## `@kungfu-tech/buildchain/homebrew`\n\nTarget: `./packages/core/homebrew.js`. Public symbols: 7.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `checkHomebrewTap` | function: async function checkHomebrewTap({ cwd = process.cwd(), packageName = \"buildchain\", releasePassport = \"\", manifestPath = DEFAULT_MANIFEST_PATH, formulaPath = \"\", } = {}) | { cwd = process.cwd(), packageName = \"buildchain\", releasePassport = \"\", manifestPath = DEFAULT_MANIFEST_PATH, formulaPath = \"\", } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { checkHomebrewTap } from \"@kungfu-tech/buildchain/homebrew\";` | `packages/core/homebrew.js:335` |\n| `collectHomebrewTapFacts` | function: async function collectHomebrewTapFacts({ cwd = process.cwd(), packageName = \"buildchain\", releasePassport = \"\", manifestPath = DEFAULT_MANIFEST_PATH, formulaPath = \"\", } = {}) | { cwd = process.cwd(), packageName = \"buildchain\", releasePassport = \"\", manifestPath = DEFAULT_MANIFEST_PATH, formulaPath = \"\", } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectHomebrewTapFacts } from \"@kungfu-tech/buildchain/homebrew\";` | `packages/core/homebrew.js:223` |\n| `HOMEBREW_TAP_CHECK_CONTRACT` | constant: const HOMEBREW_TAP_CHECK_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { HOMEBREW_TAP_CHECK_CONTRACT } from \"@kungfu-tech/buildchain/homebrew\";` | `packages/core/homebrew.js:6` |\n| `HOMEBREW_TAP_FACTS_CONTRACT` | constant: const HOMEBREW_TAP_FACTS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { HOMEBREW_TAP_FACTS_CONTRACT } from \"@kungfu-tech/buildchain/homebrew\";` | `packages/core/homebrew.js:5` |\n| `HOMEBREW_TAP_MANIFEST_CONTRACT` | constant: const HOMEBREW_TAP_MANIFEST_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { HOMEBREW_TAP_MANIFEST_CONTRACT } from \"@kungfu-tech/buildchain/homebrew\";` | `packages/core/homebrew.js:7` |\n| `renderHomebrewFormula` | function: function renderHomebrewFormula(facts) | facts | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { renderHomebrewFormula } from \"@kungfu-tech/buildchain/homebrew\";` | `packages/core/homebrew.js:290` |\n| `updateHomebrewTap` | function: async function updateHomebrewTap({ cwd = process.cwd(), packageName = \"buildchain\", releasePassport = \"\", manifestPath = DEFAULT_MANIFEST_PATH, formulaPath = \"\", write = true, } = {}) | { cwd = process.cwd(), packageName = \"buildchain\", releasePassport = \"\", manifestPath = DEFAULT_MANIFEST_PATH, formulaPath = \"\", write = true, } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { updateHomebrewTap } from \"@kungfu-tech/buildchain/homebrew\";` | `packages/core/homebrew.js:390` |\n\n## `@kungfu-tech/buildchain/issue-reporting`\n\nTarget: `./packages/core/issue-reporting.js`. Public symbols: 17.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `BUILDCHAIN_CONSUMER_ISSUE_CONTRACT` | constant: const BUILDCHAIN_CONSUMER_ISSUE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONSUMER_ISSUE_CONTRACT } from \"@kungfu-tech/buildchain/issue-reporting\";` | `packages/core/issue-reporting.js:4` |\n| `BUILDCHAIN_WORKFLOW_FRICTION_ISSUE_CONTRACT` | constant: const BUILDCHAIN_WORKFLOW_FRICTION_ISSUE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_WORKFLOW_FRICTION_ISSUE_CONTRACT } from \"@kungfu-tech/buildchain/issue-reporting\";` | `packages/core/issue-reporting.js:5` |\n| `buildConsumerIssueReport` | function: function buildConsumerIssueReport(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { buildConsumerIssueReport } from \"@kungfu-tech/buildchain/issue-reporting\";` | `packages/core/issue-reporting.js:104` |\n| `buildWorkflowFrictionIssueReport` | function: function buildWorkflowFrictionIssueReport(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { buildWorkflowFrictionIssueReport } from \"@kungfu-tech/buildchain/issue-reporting\";` | `packages/core/issue-reporting.js:199` |\n| `computeConsumerIssueFingerprint` | function: function computeConsumerIssueFingerprint(fields = {}) | fields = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { computeConsumerIssueFingerprint } from \"@kungfu-tech/buildchain/issue-reporting\";` | `packages/core/issue-reporting.js:64` |\n| `consumerIssueMarker` | function: function consumerIssueMarker(fingerprint) | fingerprint | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { consumerIssueMarker } from \"@kungfu-tech/buildchain/issue-reporting\";` | `packages/core/issue-reporting.js:76` |\n| `createGitHubIssueRequest` | function: function createGitHubIssueRequest({ token, apiUrl = process.env.GITHUB_API_URL \\|\\| \"https://api.github.com\", fetchImpl = globalThis.fetch, retryDelaysMs = DEFAULT_RETRY_DELAYS_MS, } = {}) | { token, apiUrl = process.env.GITHUB_API_URL \\|\\| \"https://api.github.com\", fetchImpl = globalThis.fetch, retryDelaysMs = DEFAULT_RETRY_DELAYS_MS, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGitHubIssueRequest } from \"@kungfu-tech/buildchain/issue-reporting\";` | `packages/core/issue-reporting.js:393` |\n| `DEFAULT_BUILDCHAIN_ISSUE_REPOSITORY` | constant: const DEFAULT_BUILDCHAIN_ISSUE_REPOSITORY | none | value | Import does not declare a throw contract. | none-on-import | `import { DEFAULT_BUILDCHAIN_ISSUE_REPOSITORY } from \"@kungfu-tech/buildchain/issue-reporting\";` | `packages/core/issue-reporting.js:6` |\n| `GitHubIssueRequestError` | class: class GitHubIssueRequestError | none | GitHubIssueRequestError | Construction and method errors follow the linked source implementation. | class-dependent | `import { GitHubIssueRequestError } from \"@kungfu-tech/buildchain/issue-reporting\";` | `packages/core/issue-reporting.js:23` |\n| `normalizeIssueRepository` | function: function normalizeIssueRepository(repository = DEFAULT_BUILDCHAIN_ISSUE_REPOSITORY) | repository = DEFAULT_BUILDCHAIN_ISSUE_REPOSITORY | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeIssueRepository } from \"@kungfu-tech/buildchain/issue-reporting\";` | `packages/core/issue-reporting.js:33` |\n| `parseIssueLabels` | function: function parseIssueLabels(input = DEFAULT_LABELS) | input = DEFAULT_LABELS | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { parseIssueLabels } from \"@kungfu-tech/buildchain/issue-reporting\";` | `packages/core/issue-reporting.js:41` |\n| `readOptionalIssueBodyFile` | function: function readOptionalIssueBodyFile(filePath) | filePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { readOptionalIssueBodyFile } from \"@kungfu-tech/buildchain/issue-reporting\";` | `packages/core/issue-reporting.js:385` |\n| `redactIssueText` | function: function redactIssueText(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { redactIssueText } from \"@kungfu-tech/buildchain/issue-reporting\";` | `packages/core/issue-reporting.js:51` |\n| `reportBuildchainIssue` | function: async function reportBuildchainIssue(options = {}) | options = {} | Promise<unknown> | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { reportBuildchainIssue } from \"@kungfu-tech/buildchain/issue-reporting\";` | `packages/core/issue-reporting.js:292` |\n| `reportWorkflowFrictionIssue` | function: async function reportWorkflowFrictionIssue(options = {}) | options = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { reportWorkflowFrictionIssue } from \"@kungfu-tech/buildchain/issue-reporting\";` | `packages/core/issue-reporting.js:378` |\n| `truncateUtf8` | function: function truncateUtf8(text, maxBytes = DEFAULT_MAX_BODY_BYTES) | text, maxBytes = DEFAULT_MAX_BODY_BYTES | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { truncateUtf8 } from \"@kungfu-tech/buildchain/issue-reporting\";` | `packages/core/issue-reporting.js:84` |\n| `workflowFrictionMarker` | function: function workflowFrictionMarker(fingerprint) | fingerprint | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { workflowFrictionMarker } from \"@kungfu-tech/buildchain/issue-reporting\";` | `packages/core/issue-reporting.js:80` |\n\n## `@kungfu-tech/buildchain/kfd`\n\nTarget: `./packages/core/kfd.js`. Public symbols: 17.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `buildchainKfdClaims` | constant: const buildchainKfdClaims | none | value | Import does not declare a throw contract. | none-on-import | `import { buildchainKfdClaims } from \"@kungfu-tech/buildchain/kfd\";` | `packages/core/kfd.js:896` |\n| `checkKfdUpstreamFacts` | function: function checkKfdUpstreamFacts(aggregate = {}) | aggregate = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { checkKfdUpstreamFacts } from \"@kungfu-tech/buildchain/kfd\";` | `packages/core/kfd.js:798` |\n| `collectKfdAggregate` | function: function collectKfdAggregate({ cwd = process.cwd() } = {}) | { cwd = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectKfdAggregate } from \"@kungfu-tech/buildchain/kfd\";` | `packages/core/kfd.js:868` |\n| `collectKfdStatus` | function: function collectKfdStatus({ cwd = process.cwd() } = {}) | { cwd = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectKfdStatus } from \"@kungfu-tech/buildchain/kfd\";` | `packages/core/kfd.js:902` |\n| `collectKfdUpstreamFacts` | function: function collectKfdUpstreamFacts({ cwd = process.cwd(), components = undefined, includeOwn = true } = {}) | { cwd = process.cwd(), components = undefined, includeOwn = true } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectKfdUpstreamFacts } from \"@kungfu-tech/buildchain/kfd\";` | `packages/core/kfd.js:689` |\n| `discoverKfdStandards` | function: function discoverKfdStandards() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { discoverKfdStandards } from \"@kungfu-tech/buildchain/kfd\";` | `packages/core/kfd.js:464` |\n| `kfd1` | constant: const kfd1 | none | value | Import does not declare a throw contract. | none-on-import | `import { kfd1 } from \"@kungfu-tech/buildchain/kfd\";` | `packages/core/kfd.js:546` |\n| `kfd2` | constant: const kfd2 | none | value | Import does not declare a throw contract. | none-on-import | `import { kfd2 } from \"@kungfu-tech/buildchain/kfd\";` | `packages/core/kfd.js:561` |\n| `kfd3` | constant: const kfd3 | none | value | Import does not declare a throw contract. | none-on-import | `import { kfd3 } from \"@kungfu-tech/buildchain/kfd\";` | `packages/core/kfd.js:663` |\n| `kfd4` | constant: const kfd4 | none | value | Import does not declare a throw contract. | none-on-import | `import { kfd4 } from \"@kungfu-tech/buildchain/kfd\";` | `packages/core/kfd.js:681` |\n| `layout` | constant: const layout | none | value | Import does not declare a throw contract. | none-on-import | `import { layout } from \"@kungfu-tech/buildchain/kfd\";` | `packages/core/kfd.js:905` |\n| `listKfdSchemas` | function: function listKfdSchemas({ standard = \"\" } = {}) | { standard = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { listKfdSchemas } from \"@kungfu-tech/buildchain/kfd\";` | `packages/core/kfd.js:492` |\n| `listKfdUpstreamRoles` | function: function listKfdUpstreamRoles() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { listKfdUpstreamRoles } from \"@kungfu-tech/buildchain/kfd\";` | `packages/core/kfd.js:771` |\n| `normalizeKfdStandardId` | function: function normalizeKfdStandardId(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeKfdStandardId } from \"@kungfu-tech/buildchain/kfd\";` | `packages/core/kfd.js:455` |\n| `readKfdSchema` | function: function readKfdSchema({ standard, schema = \"\" } = {}) | { standard, schema = \"\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readKfdSchema } from \"@kungfu-tech/buildchain/kfd\";` | `packages/core/kfd.js:520` |\n| `schemas` | constant: const schemas | none | value | Import does not declare a throw contract. | none-on-import | `import { schemas } from \"@kungfu-tech/buildchain/kfd\";` | `packages/core/kfd.js:495` |\n| `upstream` | constant: const upstream | none | value | Import does not declare a throw contract. | none-on-import | `import { upstream } from \"@kungfu-tech/buildchain/kfd\";` | `packages/core/kfd.js:300` |\n\n## `@kungfu-tech/buildchain/kfd-product-gates`\n\nTarget: `./packages/core/kfd-product-gates.js`. Public symbols: 9.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `evaluateKfdProductGate` | function: async function evaluateKfdProductGate({ cwd = process.cwd(), input, expectedSourceSha = \"\", checkedAt = new Date().toISOString(), } = {}) | { cwd = process.cwd(), input, expectedSourceSha = \"\", checkedAt = new Date().toISOString(), } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { evaluateKfdProductGate } from \"@kungfu-tech/buildchain/kfd-product-gates\";` | `packages/core/kfd-product-gates.js:419` |\n| `KFD_PRODUCT_GATE_CONTRACT` | constant: const KFD_PRODUCT_GATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_PRODUCT_GATE_CONTRACT } from \"@kungfu-tech/buildchain/kfd-product-gates\";` | `packages/core/kfd-product-gates.js:11` |\n| `KFD_PRODUCT_GATE_INPUT_CONTRACT` | constant: const KFD_PRODUCT_GATE_INPUT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_PRODUCT_GATE_INPUT_CONTRACT } from \"@kungfu-tech/buildchain/kfd-product-gates\";` | `packages/core/kfd-product-gates.js:9` |\n| `KFD_PRODUCT_GATE_INPUT_SCHEMA` | constant: const KFD_PRODUCT_GATE_INPUT_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_PRODUCT_GATE_INPUT_SCHEMA } from \"@kungfu-tech/buildchain/kfd-product-gates\";` | `packages/core/kfd-product-gates.js:51` |\n| `KFD_PRODUCT_GATE_INPUT_SCHEMA_ID` | constant: const KFD_PRODUCT_GATE_INPUT_SCHEMA_ID | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_PRODUCT_GATE_INPUT_SCHEMA_ID } from \"@kungfu-tech/buildchain/kfd-product-gates\";` | `packages/core/kfd-product-gates.js:13` |\n| `kfdProductGateDigest` | function: function kfdProductGateDigest(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { kfdProductGateDigest } from \"@kungfu-tech/buildchain/kfd-product-gates\";` | `packages/core/kfd-product-gates.js:142` |\n| `kfdProductGates` | constant: const kfdProductGates | none | value | Import does not declare a throw contract. | none-on-import | `import { kfdProductGates } from \"@kungfu-tech/buildchain/kfd-product-gates\";` | `packages/core/kfd-product-gates.js:561` |\n| `validateKfdProductGateResult` | function: function validateKfdProductGateResult(result, { expectedSourceSha = \"\", checkedAt = new Date().toISOString(), } = {}) | result, { expectedSourceSha = \"\", checkedAt = new Date().toISOString(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateKfdProductGateResult } from \"@kungfu-tech/buildchain/kfd-product-gates\";` | `packages/core/kfd-product-gates.js:519` |\n| `verifyKfdRecord` | function: async function verifyKfdRecord(record) | record | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyKfdRecord } from \"@kungfu-tech/buildchain/kfd-product-gates\";` | `packages/core/kfd-product-gates.js:262` |\n\n## `@kungfu-tech/buildchain/kfd-adopter-manifest`\n\nTarget: `./packages/core/kfd-adopter-manifest.js`. Public symbols: 6.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `createKfdAdopterManifestGate` | function: function createKfdAdopterManifestGate({ manifest, packageArtifactRoot = \"\", gateResults = [], authorityPath = \".buildchain/kfd/adopter-manifest.json\", expectedSourceSha = \"\", checkedAt = new Date().toISOString(), maxAgeSeconds = 86400, } = {}) | { manifest, packageArtifactRoot = \"\", gateResults = [], authorityPath = \".buildchain/kfd/adopter-manifest.json\", expectedSourceSha = \"\", checkedAt = new Date().toISOString(), maxAgeSeconds = 86400, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createKfdAdopterManifestGate } from \"@kungfu-tech/buildchain/kfd-adopter-manifest\";` | `packages/core/kfd-adopter-manifest.js:209` |\n| `createKfdLegacySupportMatrixProjection` | function: function createKfdLegacySupportMatrixProjection({ manifest, manifestGate } = {}) | { manifest, manifestGate } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createKfdLegacySupportMatrixProjection } from \"@kungfu-tech/buildchain/kfd-adopter-manifest\";` | `packages/core/kfd-adopter-manifest.js:327` |\n| `KFD_ADOPTER_MANIFEST_GATE_CONTRACT` | constant: const KFD_ADOPTER_MANIFEST_GATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_ADOPTER_MANIFEST_GATE_CONTRACT } from \"@kungfu-tech/buildchain/kfd-adopter-manifest\";` | `packages/core/kfd-adopter-manifest.js:18` |\n| `KFD_LEGACY_SUPPORT_MATRIX_CONTRACT` | constant: const KFD_LEGACY_SUPPORT_MATRIX_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_LEGACY_SUPPORT_MATRIX_CONTRACT } from \"@kungfu-tech/buildchain/kfd-adopter-manifest\";` | `packages/core/kfd-adopter-manifest.js:20` |\n| `validateKfdAdopterManifestGate` | function: function validateKfdAdopterManifestGate(gate, { expectedSourceSha = \"\", checkedAt = gate?.checkedAt \\|\\| new Date().toISOString(), } = {}) | gate, { expectedSourceSha = \"\", checkedAt = gate?.checkedAt \\|\\| new Date().toISOString(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateKfdAdopterManifestGate } from \"@kungfu-tech/buildchain/kfd-adopter-manifest\";` | `packages/core/kfd-adopter-manifest.js:279` |\n| `validateKfdLegacySupportMatrixProjection` | function: function validateKfdLegacySupportMatrixProjection(matrix, { manifest, manifestGate } = {}) | matrix, { manifest, manifestGate } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateKfdLegacySupportMatrixProjection } from \"@kungfu-tech/buildchain/kfd-adopter-manifest\";` | `packages/core/kfd-adopter-manifest.js:381` |\n\n## `@kungfu-tech/buildchain/kfd-adopter-release-binding`\n\nTarget: `./packages/core/artifact-verification-envelope.js`. Public symbols: 11.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `ARTIFACT_VERIFICATION_ENVELOPE_CHECK_CONTRACT` | constant: const ARTIFACT_VERIFICATION_ENVELOPE_CHECK_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_VERIFICATION_ENVELOPE_CHECK_CONTRACT } from \"@kungfu-tech/buildchain/kfd-adopter-release-binding\";` | `packages/core/artifact-verification-envelope.js:12` |\n| `ARTIFACT_VERIFICATION_ENVELOPE_CONTRACT` | constant: const ARTIFACT_VERIFICATION_ENVELOPE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_VERIFICATION_ENVELOPE_CONTRACT } from \"@kungfu-tech/buildchain/kfd-adopter-release-binding\";` | `packages/core/artifact-verification-envelope.js:10` |\n| `artifactVerificationEnvelopeDigest` | function: function artifactVerificationEnvelopeDigest(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { artifactVerificationEnvelopeDigest } from \"@kungfu-tech/buildchain/kfd-adopter-release-binding\";` | `packages/core/artifact-verification-envelope.js:59` |\n| `createKfdAdopterReleaseBinding` | function: function createKfdAdopterReleaseBinding({ manifest, manifestGate, legacyProjection, manifestPath = \"kfd-adopter-manifest.json\", gatePath = \"kfd-adopter-manifest-gate.json\", legacyProjectionPath = \"kfd-support.json\", expectedSourceSha = \"\", } = {}) | { manifest, manifestGate, legacyProjection, manifestPath = \"kfd-adopter-manifest.json\", gatePath = \"kfd-adopter-manifest-gate.json\", legacyProjectionPath = \"kfd-support.json\", expectedSourceSha = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createKfdAdopterReleaseBinding } from \"@kungfu-tech/buildchain/kfd-adopter-release-binding\";` | `packages/core/artifact-verification-envelope.js:441` |\n| `installedKfdPackageArtifactRoot` | function: function installedKfdPackageArtifactRoot() | none | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { installedKfdPackageArtifactRoot } from \"@kungfu-tech/buildchain/kfd-adopter-release-binding\";` | `packages/core/artifact-verification-envelope.js:397` |\n| `KFD_ADOPTER_RELEASE_BINDING_CONTRACT` | constant: const KFD_ADOPTER_RELEASE_BINDING_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_ADOPTER_RELEASE_BINDING_CONTRACT } from \"@kungfu-tech/buildchain/kfd-adopter-release-binding\";` | `packages/core/artifact-verification-envelope.js:16` |\n| `KFX_ADMISSION_INPUTS_CONTRACT` | constant: const KFX_ADMISSION_INPUTS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFX_ADMISSION_INPUTS_CONTRACT } from \"@kungfu-tech/buildchain/kfd-adopter-release-binding\";` | `packages/core/artifact-verification-envelope.js:14` |\n| `projectArtifactVerificationEnvelopeToKfx` | function: function projectArtifactVerificationEnvelopeToKfx({ envelope, assessmentTime = Math.floor(Date.now() / 1000), expectedEnvelopeRoot = \"\", expectedIssuer = \"\", expectedPublisher = \"\", expectedContractVersion = \"\", } = {}) | { envelope, assessmentTime = Math.floor(Date.now() / 1000), expectedEnvelopeRoot = \"\", expectedIssuer = \"\", expectedPublisher = \"\", expectedContractVersion = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { projectArtifactVerificationEnvelopeToKfx } from \"@kungfu-tech/buildchain/kfd-adopter-release-binding\";` | `packages/core/artifact-verification-envelope.js:368` |\n| `sealArtifactVerificationReport` | function: function sealArtifactVerificationReport({ report, bindings, kfdAssessment, issuedAt, expiresAt, revocation, } = {}) | { report, bindings, kfdAssessment, issuedAt, expiresAt, revocation, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { sealArtifactVerificationReport } from \"@kungfu-tech/buildchain/kfd-adopter-release-binding\";` | `packages/core/artifact-verification-envelope.js:323` |\n| `validateKfdAdopterReleaseBinding` | function: function validateKfdAdopterReleaseBinding(binding, { manifest, manifestGate, legacyProjection, expectedSourceSha = \"\", } = {}) | binding, { manifest, manifestGate, legacyProjection, expectedSourceSha = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateKfdAdopterReleaseBinding } from \"@kungfu-tech/buildchain/kfd-adopter-release-binding\";` | `packages/core/artifact-verification-envelope.js:467` |\n| `verifyArtifactVerificationEnvelope` | function: function verifyArtifactVerificationEnvelope({ envelope, assessmentTime = Math.floor(Date.now() / 1000), expectedEnvelopeRoot = \"\", expectedIssuer = \"\", expectedPublisher = \"\", expectedContractVersion = \"\", } = {}) | { envelope, assessmentTime = Math.floor(Date.now() / 1000), expectedEnvelopeRoot = \"\", expectedIssuer = \"\", expectedPublisher = \"\", expectedContractVersion = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyArtifactVerificationEnvelope } from \"@kungfu-tech/buildchain/kfd-adopter-release-binding\";` | `packages/core/artifact-verification-envelope.js:153` |\n\n## `@kungfu-tech/buildchain/kfd-agent-hub`\n\nTarget: `./packages/core/kfd-agent-hub.js`. Public symbols: 10.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `explainKfdAgentHub` | function: function explainKfdAgentHub({ cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, kfdRoot = \"\" } = {}) | { cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, kfdRoot = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { explainKfdAgentHub } from \"@kungfu-tech/buildchain/kfd-agent-hub\";` | `packages/core/kfd-agent-hub.js:470` |\n| `initKfdAgentHub` | function: function initKfdAgentHub({ cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, write = false, force = false } = {}) | { cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, write = false, force = false } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { initKfdAgentHub } from \"@kungfu-tech/buildchain/kfd-agent-hub\";` | `packages/core/kfd-agent-hub.js:363` |\n| `inspectKfdAgentHub` | function: function inspectKfdAgentHub({ cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, kfdRoot = \"\" } = {}) | { cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, kfdRoot = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { inspectKfdAgentHub } from \"@kungfu-tech/buildchain/kfd-agent-hub\";` | `packages/core/kfd-agent-hub.js:384` |\n| `KFD_AGENT_HUB_ADOPTION_CONTRACT` | constant: const KFD_AGENT_HUB_ADOPTION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_AGENT_HUB_ADOPTION_CONTRACT } from \"@kungfu-tech/buildchain/kfd-agent-hub\";` | `packages/core/kfd-agent-hub.js:9` |\n| `KFD_AGENT_HUB_ADOPTION_SCHEMA` | constant: const KFD_AGENT_HUB_ADOPTION_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_AGENT_HUB_ADOPTION_SCHEMA } from \"@kungfu-tech/buildchain/kfd-agent-hub\";` | `packages/core/kfd-agent-hub.js:12` |\n| `KFD_AGENT_HUB_DECLARATION` | constant: const KFD_AGENT_HUB_DECLARATION | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_AGENT_HUB_DECLARATION } from \"@kungfu-tech/buildchain/kfd-agent-hub\";` | `packages/core/kfd-agent-hub.js:7` |\n| `KFD_AGENT_HUB_LOCK_CONTRACT` | constant: const KFD_AGENT_HUB_LOCK_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_AGENT_HUB_LOCK_CONTRACT } from \"@kungfu-tech/buildchain/kfd-agent-hub\";` | `packages/core/kfd-agent-hub.js:10` |\n| `KFD_AGENT_HUB_OUTPUT_DIR` | constant: const KFD_AGENT_HUB_OUTPUT_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_AGENT_HUB_OUTPUT_DIR } from \"@kungfu-tech/buildchain/kfd-agent-hub\";` | `packages/core/kfd-agent-hub.js:8` |\n| `KFD_AGENT_HUB_VERIFICATION_CONTRACT` | constant: const KFD_AGENT_HUB_VERIFICATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_AGENT_HUB_VERIFICATION_CONTRACT } from \"@kungfu-tech/buildchain/kfd-agent-hub\";` | `packages/core/kfd-agent-hub.js:11` |\n| `testKfdAgentHub` | function: function testKfdAgentHub({ cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, outputDir = KFD_AGENT_HUB_OUTPUT_DIR, kfdRoot = \"\", run = defaultRun } = {}) | { cwd = process.cwd(), declarationPath = KFD_AGENT_HUB_DECLARATION, outputDir = KFD_AGENT_HUB_OUTPUT_DIR, kfdRoot = \"\", run = defaultRun } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { testKfdAgentHub } from \"@kungfu-tech/buildchain/kfd-agent-hub\";` | `packages/core/kfd-agent-hub.js:399` |\n\n## `@kungfu-tech/buildchain/buildchain-layout`\n\nTarget: `./packages/core/buildchain-layout.js`. Public symbols: 41.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `BUILDCHAIN_CONFIG_PATH` | constant: const BUILDCHAIN_CONFIG_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONFIG_PATH } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:7` |\n| `BUILDCHAIN_CONTRACT_LOCK_PATH` | constant: const BUILDCHAIN_CONTRACT_LOCK_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONTRACT_LOCK_PATH } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:9` |\n| `BUILDCHAIN_DIR` | constant: const BUILDCHAIN_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_DIR } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:4` |\n| `BUILDCHAIN_GENERATED_DIRS` | constant: const BUILDCHAIN_GENERATED_DIRS | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_GENERATED_DIRS } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:36` |\n| `BUILDCHAIN_KFD_ROOT` | constant: const BUILDCHAIN_KFD_ROOT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD_ROOT } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:11` |\n| `BUILDCHAIN_KFD1_CONTRACT_WORLD_WITNESS_PATH` | constant: const BUILDCHAIN_KFD1_CONTRACT_WORLD_WITNESS_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD1_CONTRACT_WORLD_WITNESS_PATH } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:16` |\n| `BUILDCHAIN_KFD1_DIR` | constant: const BUILDCHAIN_KFD1_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD1_DIR } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:12` |\n| `BUILDCHAIN_KFD1_RELEASE_GATE_PATH` | constant: const BUILDCHAIN_KFD1_RELEASE_GATE_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD1_RELEASE_GATE_PATH } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:17` |\n| `BUILDCHAIN_KFD1_VERIFY_RESULT_PATH` | constant: const BUILDCHAIN_KFD1_VERIFY_RESULT_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD1_VERIFY_RESULT_PATH } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:18` |\n| `BUILDCHAIN_KFD2_CLAIM_ARGS_PATH` | constant: const BUILDCHAIN_KFD2_CLAIM_ARGS_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD2_CLAIM_ARGS_PATH } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:21` |\n| `BUILDCHAIN_KFD2_CLAIMS_DIR` | constant: const BUILDCHAIN_KFD2_CLAIMS_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD2_CLAIMS_DIR } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:22` |\n| `BUILDCHAIN_KFD2_DIR` | constant: const BUILDCHAIN_KFD2_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD2_DIR } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:13` |\n| `BUILDCHAIN_KFD2_REGISTRY_PATH` | constant: const BUILDCHAIN_KFD2_REGISTRY_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD2_REGISTRY_PATH } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:19` |\n| `BUILDCHAIN_KFD2_RELEASE_CLAIMS_PATH` | constant: const BUILDCHAIN_KFD2_RELEASE_CLAIMS_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD2_RELEASE_CLAIMS_PATH } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:20` |\n| `BUILDCHAIN_KFD3_ARTIFACT_WITNESS_PATH` | constant: const BUILDCHAIN_KFD3_ARTIFACT_WITNESS_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD3_ARTIFACT_WITNESS_PATH } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:26` |\n| `BUILDCHAIN_KFD3_CAPABILITY_QUERY_PATH` | constant: const BUILDCHAIN_KFD3_CAPABILITY_QUERY_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD3_CAPABILITY_QUERY_PATH } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:27` |\n| `BUILDCHAIN_KFD3_COLLABORATION_INTERFACE_PATH` | constant: const BUILDCHAIN_KFD3_COLLABORATION_INTERFACE_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD3_COLLABORATION_INTERFACE_PATH } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:24` |\n| `BUILDCHAIN_KFD3_DIR` | constant: const BUILDCHAIN_KFD3_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD3_DIR } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:14` |\n| `BUILDCHAIN_KFD3_PREBUILD_WITNESS_PATH` | constant: const BUILDCHAIN_KFD3_PREBUILD_WITNESS_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD3_PREBUILD_WITNESS_PATH } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:25` |\n| `BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATH` | constant: const BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATH } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:23` |\n| `BUILDCHAIN_KFD4_DIR` | constant: const BUILDCHAIN_KFD4_DIR | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD4_DIR } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:15` |\n| `BUILDCHAIN_LAYOUT_DISCOVERY_CONTRACT` | constant: const BUILDCHAIN_LAYOUT_DISCOVERY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_LAYOUT_DISCOVERY_CONTRACT } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:6` |\n| `BUILDCHAIN_RELEASE_PASSPORT_PATH` | constant: const BUILDCHAIN_RELEASE_PASSPORT_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_RELEASE_PASSPORT_PATH } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:33` |\n| `BUILDCHAIN_VERSION_PIN_PATH` | constant: const BUILDCHAIN_VERSION_PIN_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_VERSION_PIN_PATH } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:5` |\n| `createBuildchainLayoutDiscovery` | function: function createBuildchainLayoutDiscovery({ cwd = process.cwd(), buildchainVersion = \"\", } = {}) | { cwd = process.cwd(), buildchainVersion = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainLayoutDiscovery } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:99` |\n| `discoverBuildchainRepoFiles` | function: function discoverBuildchainRepoFiles(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { discoverBuildchainRepoFiles } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:143` |\n| `firstExistingRepoPath` | function: function firstExistingRepoPath(cwd, candidates = []) | cwd, candidates = [] | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { firstExistingRepoPath } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:58` |\n| `LEGACY_BUILDCHAIN_CONFIG_PATH` | constant: const LEGACY_BUILDCHAIN_CONFIG_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { LEGACY_BUILDCHAIN_CONFIG_PATH } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:8` |\n| `LEGACY_BUILDCHAIN_CONTRACT_LOCK_PATH` | constant: const LEGACY_BUILDCHAIN_CONTRACT_LOCK_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { LEGACY_BUILDCHAIN_CONTRACT_LOCK_PATH } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:10` |\n| `LEGACY_BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATH` | constant: const LEGACY_BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { LEGACY_BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATH } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:28` |\n| `LEGACY_BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATHS` | constant: const LEGACY_BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATHS | none | value | Import does not declare a throw contract. | none-on-import | `import { LEGACY_BUILDCHAIN_KFD3_SURFACE_REGISTRY_PATHS } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:29` |\n| `LEGACY_BUILDCHAIN_RELEASE_PASSPORT_PATH` | constant: const LEGACY_BUILDCHAIN_RELEASE_PASSPORT_PATH | none | value | Import does not declare a throw contract. | none-on-import | `import { LEGACY_BUILDCHAIN_RELEASE_PASSPORT_PATH } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:34` |\n| `migrateBuildchainLayout` | function: function migrateBuildchainLayout({ cwd = process.cwd(), write = false, force = false } = {}) | { cwd = process.cwd(), write = false, force = false } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { migrateBuildchainLayout } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:287` |\n| `planBuildchainLayoutMigration` | function: function planBuildchainLayoutMigration({ cwd = process.cwd() } = {}) | { cwd = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { planBuildchainLayoutMigration } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:265` |\n| `repoPath` | function: function repoPath(cwd, relativePath) | cwd, relativePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { repoPath } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:54` |\n| `resolveBuildchainConfigPath` | function: function resolveBuildchainConfigPath(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolveBuildchainConfigPath } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:67` |\n| `resolveBuildchainContractLockPath` | function: function resolveBuildchainContractLockPath(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolveBuildchainContractLockPath } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:74` |\n| `resolveKfd2ProductClaimsRegistryPath` | function: function resolveKfd2ProductClaimsRegistryPath(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolveKfd2ProductClaimsRegistryPath } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:81` |\n| `resolveKfd3SurfaceRegistryPath` | function: function resolveKfd3SurfaceRegistryPath(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolveKfd3SurfaceRegistryPath } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:85` |\n| `resolveReleasePassportPath` | function: function resolveReleasePassportPath(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolveReleasePassportPath } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:92` |\n| `toPosixPath` | function: function toPosixPath(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { toPosixPath } from \"@kungfu-tech/buildchain/buildchain-layout\";` | `packages/core/buildchain-layout.js:50` |\n\n## `@kungfu-tech/buildchain/release-line-bootstrap`\n\nTarget: `./packages/core/release-line-bootstrap.js`. Public symbols: 2.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `planReleaseLineBootstrap` | function: function planReleaseLineBootstrap({ cwd = process.cwd(), major, minor, sourceRef = \"\", initialVersion = \"\", requiredStatusCheck = \"check\", setDefault = true, createAlphaPr = true, approvalCount = 1, bootstrapBranch = \"\", } = {}) | { cwd = process.cwd(), major, minor, sourceRef = \"\", initialVersion = \"\", requiredStatusCheck = \"check\", setDefault = true, createAlphaPr = true, approvalCount = 1, bootstrapBranch = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { planReleaseLineBootstrap } from \"@kungfu-tech/buildchain/release-line-bootstrap\";` | `packages/core/release-line-bootstrap.js:153` |\n| `writeReleaseLineBootstrapVersionState` | function: function writeReleaseLineBootstrapVersionState({ cwd = process.cwd(), major, minor, sourceRef = \"\", initialVersion = \"\", runVersionStateLifecycle = true, generatedAt = \"\", } = {}) | { cwd = process.cwd(), major, minor, sourceRef = \"\", initialVersion = \"\", runVersionStateLifecycle = true, generatedAt = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { writeReleaseLineBootstrapVersionState } from \"@kungfu-tech/buildchain/release-line-bootstrap\";` | `packages/core/release-line-bootstrap.js:250` |\n\n## `@kungfu-tech/buildchain/readme-badges`\n\nTarget: `./packages/core/readme-badges.js`. Public symbols: 17.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `BADGE_BUNDLE_DEFAULT_CLAIMS` | constant: const BADGE_BUNDLE_DEFAULT_CLAIMS | none | value | Import does not declare a throw contract. | none-on-import | `import { BADGE_BUNDLE_DEFAULT_CLAIMS } from \"@kungfu-tech/buildchain/readme-badges\";` | `packages/core/readme-badges.js:17` |\n| `BADGE_BUNDLE_FACTS_CONTRACT` | constant: const BADGE_BUNDLE_FACTS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BADGE_BUNDLE_FACTS_CONTRACT } from \"@kungfu-tech/buildchain/readme-badges\";` | `packages/core/readme-badges.js:13` |\n| `checkBadgeBundleBlock` | function: function checkBadgeBundleBlock({ readmeText, facts } = {}) | { readmeText, facts } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { checkBadgeBundleBlock } from \"@kungfu-tech/buildchain/readme-badges\";` | `packages/core/readme-badges.js:867` |\n| `checkReadmeBadgeBlock` | function: function checkReadmeBadgeBlock({ readmeText, facts } = {}) | { readmeText, facts } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { checkReadmeBadgeBlock } from \"@kungfu-tech/buildchain/readme-badges\";` | `packages/core/readme-badges.js:848` |\n| `collectBadgeBundleFacts` | function: async function collectBadgeBundleFacts({ cwd = process.cwd(), claims = undefined } = {}) | { cwd = process.cwd(), claims = undefined } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectBadgeBundleFacts } from \"@kungfu-tech/buildchain/readme-badges\";` | `packages/core/readme-badges.js:790` |\n| `collectReadmeBadgeFacts` | function: async function collectReadmeBadgeFacts({ cwd = process.cwd() } = {}) | { cwd = process.cwd() } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectReadmeBadgeFacts } from \"@kungfu-tech/buildchain/readme-badges\";` | `packages/core/readme-badges.js:700` |\n| `createKfdBadgeSpecsFromStandards` | function: function createKfdBadgeSpecsFromStandards(standardsMetadata) | standardsMetadata | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createKfdBadgeSpecsFromStandards } from \"@kungfu-tech/buildchain/readme-badges\";` | `packages/core/readme-badges.js:126` |\n| `createReadmeBadgeEndpointRegistry` | function: function createReadmeBadgeEndpointRegistry({ kfdSpecs = undefined, kfdStandards = undefined } = {}) | { kfdSpecs = undefined, kfdStandards = undefined } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | subprocess | `import { createReadmeBadgeEndpointRegistry } from \"@kungfu-tech/buildchain/readme-badges\";` | `packages/core/readme-badges.js:133` |\n| `README_BADGE_BLOCK_END` | constant: const README_BADGE_BLOCK_END | none | value | Import does not declare a throw contract. | none-on-import | `import { README_BADGE_BLOCK_END } from \"@kungfu-tech/buildchain/readme-badges\";` | `packages/core/readme-badges.js:15` |\n| `README_BADGE_BLOCK_START` | constant: const README_BADGE_BLOCK_START | none | value | Import does not declare a throw contract. | none-on-import | `import { README_BADGE_BLOCK_START } from \"@kungfu-tech/buildchain/readme-badges\";` | `packages/core/readme-badges.js:14` |\n| `README_BADGE_FACTS_CONTRACT` | constant: const README_BADGE_FACTS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { README_BADGE_FACTS_CONTRACT } from \"@kungfu-tech/buildchain/readme-badges\";` | `packages/core/readme-badges.js:12` |\n| `README_BADGE_HOSTED_BASE_URL` | constant: const README_BADGE_HOSTED_BASE_URL | none | value | Import does not declare a throw contract. | none-on-import | `import { README_BADGE_HOSTED_BASE_URL } from \"@kungfu-tech/buildchain/readme-badges\";` | `packages/core/readme-badges.js:16` |\n| `readReadme` | function: function readReadme({ cwd = process.cwd(), readmePath = \"README.md\" } = {}) | { cwd = process.cwd(), readmePath = \"README.md\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { readReadme } from \"@kungfu-tech/buildchain/readme-badges\";` | `packages/core/readme-badges.js:891` |\n| `renderBadgeBundleBlock` | function: function renderBadgeBundleBlock(facts) | facts | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { renderBadgeBundleBlock } from \"@kungfu-tech/buildchain/readme-badges\";` | `packages/core/readme-badges.js:840` |\n| `renderReadmeBadgeBlock` | function: function renderReadmeBadgeBlock(facts) | facts | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { renderReadmeBadgeBlock } from \"@kungfu-tech/buildchain/readme-badges\";` | `packages/core/readme-badges.js:836` |\n| `updateBadgeBundleBlock` | function: function updateBadgeBundleBlock({ readmeText, facts } = {}) | { readmeText, facts } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { updateBadgeBundleBlock } from \"@kungfu-tech/buildchain/readme-badges\";` | `packages/core/readme-badges.js:887` |\n| `updateReadmeBadgeBlock` | function: function updateReadmeBadgeBlock({ readmeText, facts } = {}) | { readmeText, facts } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { updateReadmeBadgeBlock } from \"@kungfu-tech/buildchain/readme-badges\";` | `packages/core/readme-badges.js:874` |\n\n## `@kungfu-tech/buildchain/public-surface-audit`\n\nTarget: `./packages/core/public-surface-audit.js`. Public symbols: 8.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `assertPublicSurfaceReverseAudit` | function: function assertPublicSurfaceReverseAudit(report) | report | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { assertPublicSurfaceReverseAudit } from \"@kungfu-tech/buildchain/public-surface-audit\";` | `packages/core/public-surface-audit.js:261` |\n| `BUILDCHAIN_PUBLIC_SURFACE_AUDIT_CONTRACT` | constant: const BUILDCHAIN_PUBLIC_SURFACE_AUDIT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_PUBLIC_SURFACE_AUDIT_CONTRACT } from \"@kungfu-tech/buildchain/public-surface-audit\";` | `packages/core/public-surface-audit.js:12` |\n| `collectPublicSurfaceReverseAudit` | function: function collectPublicSurfaceReverseAudit({ root = process.cwd(), cliRegistry: suppliedCliRegistry = undefined, workflowRegistry: suppliedWorkflowRegistry = undefined, pageRegistry: suppliedPageRegistry = undefined, } = {}) | { root = process.cwd(), cliRegistry: suppliedCliRegistry = undefined, workflowRegistry: suppliedWorkflowRegistry = undefined, pageRegistry: suppliedPageRegistry = undefined, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectPublicSurfaceReverseAudit } from \"@kungfu-tech/buildchain/public-surface-audit\";` | `packages/core/public-surface-audit.js:161` |\n| `enumerateActionInputs` | function: function enumerateActionInputs({ root = process.cwd() } = {}) | { root = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { enumerateActionInputs } from \"@kungfu-tech/buildchain/public-surface-audit\";` | `packages/core/public-surface-audit.js:91` |\n| `enumerateCliCommandsFromBin` | function: function enumerateCliCommandsFromBin({ root = process.cwd(), binPath = \"bin/buildchain.mjs\", } = {}) | { root = process.cwd(), binPath = \"bin/buildchain.mjs\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { enumerateCliCommandsFromBin } from \"@kungfu-tech/buildchain/public-surface-audit\";` | `packages/core/public-surface-cli.js:93` |\n| `enumerateDocCommandRefs` | function: function enumerateDocCommandRefs({ root = process.cwd() } = {}) | { root = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { enumerateDocCommandRefs } from \"@kungfu-tech/buildchain/public-surface-audit\";` | `packages/core/public-surface-audit.js:115` |\n| `enumerateSitePages` | function: function enumerateSitePages({ root = process.cwd() } = {}) | { root = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { enumerateSitePages } from \"@kungfu-tech/buildchain/public-surface-audit\";` | `packages/core/public-surface-audit.js:106` |\n| `enumerateWorkflowInputs` | function: function enumerateWorkflowInputs({ root = process.cwd() } = {}) | { root = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { enumerateWorkflowInputs } from \"@kungfu-tech/buildchain/public-surface-audit\";` | `packages/core/public-surface-audit.js:74` |\n\n## `@kungfu-tech/buildchain/logging`\n\nTarget: `./packages/core/logging.js`. Public symbols: 13.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `appendBuildchainLogEvent` | function: function appendBuildchainLogEvent(filePath, event) | filePath, event | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write | `import { appendBuildchainLogEvent } from \"@kungfu-tech/buildchain/logging\";` | `packages/core/logging.js:67` |\n| `BUILDCHAIN_CONTROL_PLANE_SUMMARY_CONTRACT` | constant: const BUILDCHAIN_CONTROL_PLANE_SUMMARY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_CONTROL_PLANE_SUMMARY_CONTRACT } from \"@kungfu-tech/buildchain/logging\";` | `packages/core/logging.js:8` |\n| `BUILDCHAIN_LOG_EVENT_CONTRACT` | constant: const BUILDCHAIN_LOG_EVENT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_LOG_EVENT_CONTRACT } from \"@kungfu-tech/buildchain/logging\";` | `packages/core/logging.js:6` |\n| `BUILDCHAIN_LOG_SUMMARY_CONTRACT` | constant: const BUILDCHAIN_LOG_SUMMARY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_LOG_SUMMARY_CONTRACT } from \"@kungfu-tech/buildchain/logging\";` | `packages/core/logging.js:7` |\n| `createBuildchainLogger` | function: function createBuildchainLogger(options = {}) | options = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | subprocess | `import { createBuildchainLogger } from \"@kungfu-tech/buildchain/logging\";` | `packages/core/logging.js:300` |\n| `defaultBuildchainLogPath` | function: function defaultBuildchainLogPath({ cwd = process.cwd() } = {}) | { cwd = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { defaultBuildchainLogPath } from \"@kungfu-tech/buildchain/logging\";` | `packages/core/logging.js:41` |\n| `normalizeBuildchainLogEvent` | function: function normalizeBuildchainLogEvent(input = {}, defaults = {}) | input = {}, defaults = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { normalizeBuildchainLogEvent } from \"@kungfu-tech/buildchain/logging\";` | `packages/core/logging.js:45` |\n| `readBuildchainLogEvents` | function: function readBuildchainLogEvents(filePath) | filePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { readBuildchainLogEvents } from \"@kungfu-tech/buildchain/logging\";` | `packages/core/logging.js:75` |\n| `recordBuildchainControlPlaneOutcome` | function: function recordBuildchainControlPlaneOutcome({ domain, action = \"\", outcome = \"\", reason = \"\", attributes = {}, } = {}, options = {}) | { domain, action = \"\", outcome = \"\", reason = \"\", attributes = {}, } = {}, options = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { recordBuildchainControlPlaneOutcome } from \"@kungfu-tech/buildchain/logging\";` | `packages/core/logging.js:160` |\n| `redactBuildchainLogAttributes` | function: function redactBuildchainLogAttributes(attributes = {}) | attributes = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { redactBuildchainLogAttributes } from \"@kungfu-tech/buildchain/logging\";` | `packages/core/logging.js:33` |\n| `summarizeBuildchainControlPlaneEvents` | function: function summarizeBuildchainControlPlaneEvents(input = {}) | input = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { summarizeBuildchainControlPlaneEvents } from \"@kungfu-tech/buildchain/logging\";` | `packages/core/logging.js:115` |\n| `summarizeBuildchainLogEvents` | function: function summarizeBuildchainLogEvents(input = {}) | input = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { summarizeBuildchainLogEvents } from \"@kungfu-tech/buildchain/logging\";` | `packages/core/logging.js:192` |\n| `verifyBuildchainLogEvents` | function: function verifyBuildchainLogEvents({ path: filePath = \"\", events: inputEvents = undefined, minEvents = 1, allowErrors = false, requirePhases = [], requireComponents = [], requireEvents = [], } = {}) | { path: filePath = \"\", events: inputEvents = undefined, minEvents = 1, allowErrors = false, requirePhases = [], requireComponents = [], requireEvents = [], } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyBuildchainLogEvents } from \"@kungfu-tech/buildchain/logging\";` | `packages/core/logging.js:230` |\n\n## `@kungfu-tech/buildchain/portable-dev-cache`\n\nTarget: `./packages/core/portable-dev-cache.js`. Public symbols: 3.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `createPortableDevCachePlan` | function: function createPortableDevCachePlan(manifest) | manifest | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createPortableDevCachePlan } from \"@kungfu-tech/buildchain/portable-dev-cache\";` | `packages/core/portable-dev-cache.js:172` |\n| `createPortableDevCacheReceipt` | function: function createPortableDevCacheReceipt({ plan, matchedKey = \"\", cacheHit = \"\", validationStatus = \"pass\", validationReason = \"\", coldFallbackStatus = \"not-run\", }) | { plan, matchedKey = \"\", cacheHit = \"\", validationStatus = \"pass\", validationReason = \"\", coldFallbackStatus = \"not-run\", } | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPortableDevCacheReceipt } from \"@kungfu-tech/buildchain/portable-dev-cache\";` | `packages/core/portable-dev-cache.js:226` |\n| `verifyPortableDevCachePlan` | function: function verifyPortableDevCachePlan(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyPortableDevCachePlan } from \"@kungfu-tech/buildchain/portable-dev-cache\";` | `packages/core/portable-dev-cache.js:211` |\n\n## `@kungfu-tech/buildchain/publication-artifact`\n\nTarget: `./packages/core/publication-artifact.js`. Public symbols: 7.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `collectPublicationArtifact` | function: function collectPublicationArtifact({ cwd = process.cwd(), sourceSha = \"\", sourceBundle = true, sourceBundlePath = \"\", generatedAt = \"\", manifestPath = \"\", passportPath = \"\", } = {}) | { cwd = process.cwd(), sourceSha = \"\", sourceBundle = true, sourceBundlePath = \"\", generatedAt = \"\", manifestPath = \"\", passportPath = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { collectPublicationArtifact } from \"@kungfu-tech/buildchain/publication-artifact\";` | `packages/core/publication-artifact.js:271` |\n| `createPublicationSourceBundle` | function: function createPublicationSourceBundle({ cwd = process.cwd(), sourcePaths = [], output = \".buildchain/publication/source.tar.gz\", } = {}) | { cwd = process.cwd(), sourcePaths = [], output = \".buildchain/publication/source.tar.gz\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write, subprocess | `import { createPublicationSourceBundle } from \"@kungfu-tech/buildchain/publication-artifact\";` | `packages/core/publication-artifact.js:249` |\n| `PUBLICATION_ARTIFACT_ARCHIVE_CONTRACT` | constant: const PUBLICATION_ARTIFACT_ARCHIVE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_ARTIFACT_ARCHIVE_CONTRACT } from \"@kungfu-tech/buildchain/publication-artifact\";` | `packages/core/publication-artifact.js:9` |\n| `PUBLICATION_ARTIFACT_MANIFEST_CONTRACT` | constant: const PUBLICATION_ARTIFACT_MANIFEST_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_ARTIFACT_MANIFEST_CONTRACT } from \"@kungfu-tech/buildchain/publication-artifact\";` | `packages/core/publication-artifact.js:7` |\n| `PUBLICATION_ARTIFACT_PASSPORT_CONTRACT` | constant: const PUBLICATION_ARTIFACT_PASSPORT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_ARTIFACT_PASSPORT_CONTRACT } from \"@kungfu-tech/buildchain/publication-artifact\";` | `packages/core/publication-artifact.js:8` |\n| `PUBLICATION_ARTIFACT_REGISTRY_CONTRACT` | constant: const PUBLICATION_ARTIFACT_REGISTRY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_ARTIFACT_REGISTRY_CONTRACT } from \"@kungfu-tech/buildchain/publication-artifact\";` | `packages/core/publication-artifact.js:10` |\n| `writePublicationArtifact` | function: function writePublicationArtifact({ cwd = process.cwd(), output = \"\", passportOutput = \"\", registryOutput = \"\", registryInputs = [], sourceSha = \"\", sourceBundle = true, sourceBundlePath = \"\", generatedAt = \"\", } = {}) | { cwd = process.cwd(), output = \"\", passportOutput = \"\", registryOutput = \"\", registryInputs = [], sourceSha = \"\", sourceBundle = true, sourceBundlePath = \"\", generatedAt = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write | `import { writePublicationArtifact } from \"@kungfu-tech/buildchain/publication-artifact\";` | `packages/core/publication-artifact.js:598` |\n\n## `@kungfu-tech/buildchain/publication-package`\n\nTarget: `./packages/core/publication-package.js`. Public symbols: 3.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `collectPublicationPackageFacts` | function: function collectPublicationPackageFacts({ cwd = process.cwd(), packageName = \"\", outputDir = \".buildchain/publication/npm-package\", } = {}) | { cwd = process.cwd(), packageName = \"\", outputDir = \".buildchain/publication/npm-package\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { collectPublicationPackageFacts } from \"@kungfu-tech/buildchain/publication-package\";` | `packages/core/publication-package.js:74` |\n| `preparePublicationNpmPackage` | function: function preparePublicationNpmPackage({ cwd = process.cwd(), outputDir = \".buildchain/publication/npm-package\", packageName = \"\", } = {}) | { cwd = process.cwd(), outputDir = \".buildchain/publication/npm-package\", packageName = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { preparePublicationNpmPackage } from \"@kungfu-tech/buildchain/publication-package\";` | `packages/core/publication-package.js:120` |\n| `PUBLICATION_NPM_PACKAGE_CONTRACT` | constant: const PUBLICATION_NPM_PACKAGE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_NPM_PACKAGE_CONTRACT } from \"@kungfu-tech/buildchain/publication-package\";` | `packages/core/publication-package.js:6` |\n\n## `@kungfu-tech/buildchain/publication-reproducibility`\n\nTarget: `./packages/core/publication-reproducibility.js`. Public symbols: 2.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `PUBLICATION_REPRODUCIBILITY_RECEIPT_CONTRACT` | constant: const PUBLICATION_REPRODUCIBILITY_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_REPRODUCIBILITY_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain/publication-reproducibility\";` | `packages/core/publication-reproducibility.js:12` |\n| `verifyPublicationReproducibility` | function: function verifyPublicationReproducibility({ cwd = process.cwd(), sourceSha = \"\", output = DEFAULT_OUTPUT, promote = false, keepWorkspaces = false, pullToolchain = true, packageName = \"\", allowUnpinnedToolchain = false, overlayPaths = [DEFAULT_REGISTRY_INPUT_DIR, DEFAULT_REGISTRY_HYDRATION], } = {}) | { cwd = process.cwd(), sourceSha = \"\", output = DEFAULT_OUTPUT, promote = false, keepWorkspaces = false, pullToolchain = true, packageName = \"\", allowUnpinnedToolchain = false, overlayPaths = [DEFAULT_REGISTRY_INPUT_DIR, DEFAULT_REGISTRY_HYDRATION], } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { verifyPublicationReproducibility } from \"@kungfu-tech/buildchain/publication-reproducibility\";` | `packages/core/publication-reproducibility.js:869` |\n\n## `@kungfu-tech/buildchain/publication-sealed-bundle`\n\nTarget: `./packages/core/publication-sealed-bundle.js`. Public symbols: 3.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `createPublicationSealedBundle` | function: function createPublicationSealedBundle({ candidate, packageName, packageVersion, npmTarballPath, npmIntegrity, releaseAssetPaths = [], githubReleaseRequired = true, } = {}) | { candidate, packageName, packageVersion, npmTarballPath, npmIntegrity, releaseAssetPaths = [], githubReleaseRequired = true, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPublicationSealedBundle } from \"@kungfu-tech/buildchain/publication-sealed-bundle\";` | `packages/core/publication-sealed-bundle.js:84` |\n| `PUBLICATION_SEALED_BUNDLE_CONTRACT` | constant: const PUBLICATION_SEALED_BUNDLE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_SEALED_BUNDLE_CONTRACT } from \"@kungfu-tech/buildchain/publication-sealed-bundle\";` | `packages/core/publication-sealed-bundle.js:10` |\n| `verifyPublicationSealedBundle` | function: function verifyPublicationSealedBundle({ bundleRoot, manifest } = {}) | { bundleRoot, manifest } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { verifyPublicationSealedBundle } from \"@kungfu-tech/buildchain/publication-sealed-bundle\";` | `packages/core/publication-sealed-bundle.js:133` |\n\n## `@kungfu-tech/buildchain/paper`\n\nTarget: `./packages/core/paper.js`. Public symbols: 48.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `collectPaperAgentEntry` | function: function collectPaperAgentEntry({ cwd = process.cwd(), buildchainSha = \"\", mode = \"contract\", env = process.env, } = {}) | { cwd = process.cwd(), buildchainSha = \"\", mode = \"contract\", env = process.env, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectPaperAgentEntry } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-agent-entry.js:248` |\n| `collectPaperFleetAudit` | function: function collectPaperFleetAudit({ root = process.cwd(), repositories = [], buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainSha = \"\", governance = {}, } = {}) | { root = process.cwd(), repositories = [], buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainSha = \"\", governance = {}, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectPaperFleetAudit } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-fleet.js:158` |\n| `collectPaperPreflight` | function: function collectPaperPreflight({ cwd = process.cwd(), buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainRef = \"v3\", buildchainSha = \"\", registry = NPM_REGISTRY, offline = false, agentEntryMode = \"contract\", } = {}) | { cwd = process.cwd(), buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainRef = \"v3\", buildchainSha = \"\", registry = NPM_REGISTRY, offline = false, agentEntryMode = \"contract\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectPaperPreflight } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:2414` |\n| `collectPaperStatus` | function: function collectPaperStatus({ cwd = process.cwd() } = {}) | { cwd = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectPaperStatus } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:1472` |\n| `createPaperAgentEntry` | function: function createPaperAgentEntry({ buildchainVersion, buildchainSha, developmentRef, }) | { buildchainVersion, buildchainSha, developmentRef, } | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPaperAgentEntry } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-agent-entry.js:93` |\n| `createPaperAlphaPlan` | function: function createPaperAlphaPlan({ cwd = process.cwd(), sourceRef = \"\", targetRef = \"\", } = {}) | { cwd = process.cwd(), sourceRef = \"\", targetRef = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPaperAlphaPlan } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:2656` |\n| `createPaperBuildPlan` | function: function createPaperBuildPlan({ cwd = process.cwd(), sourceSha = \"\", pullToolchain = true, } = {}) | { cwd = process.cwd(), sourceSha = \"\", pullToolchain = true, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPaperBuildPlan } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:2593` |\n| `createPaperProvisioningAuthority` | function: function createPaperProvisioningAuthority({ repository, packageName, buildchainVersion, buildchainSha, contractLock, buildWorkflow, verifyWorkflow, releaseWorkflow, agentEntry, agentInstructions, environment = \"\", }) | { repository, packageName, buildchainVersion, buildchainSha, contractLock, buildWorkflow, verifyWorkflow, releaseWorkflow, agentEntry, agentInstructions, environment = \"\", } | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createPaperProvisioningAuthority } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:519` |\n| `createPaperResumePlan` | function: function createPaperResumePlan({ cwd = process.cwd(), buildchainRef = \"\", } = {}) | { cwd = process.cwd(), buildchainRef = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write | `import { createPaperResumePlan } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:2714` |\n| `createPaperWorkStartPlan` | function: function createPaperWorkStartPlan({ cwd = process.cwd(), topic = \"\", branch = \"\", buildchainSha = \"\", } = {}) | { cwd = process.cwd(), topic = \"\", branch = \"\", buildchainSha = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createPaperWorkStartPlan } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-work.js:41` |\n| `createPaperWorkSubmitPlan` | function: function createPaperWorkSubmitPlan({ cwd = process.cwd(), pullRequests = [], pullRequestObservation = { ok: true }, buildchainSha = \"\", } = {}) | { cwd = process.cwd(), pullRequests = [], pullRequestObservation = { ok: true }, buildchainSha = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createPaperWorkSubmitPlan } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-work.js:207` |\n| `discoverPaperFleet` | function: function discoverPaperFleet(root = process.cwd()) | root = process.cwd() | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { discoverPaperFleet } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-fleet.js:23` |\n| `executePaperNpmBootstrap` | function: function executePaperNpmBootstrap(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { executePaperNpmBootstrap } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:2841` |\n| `executePaperWorkStart` | function: function executePaperWorkStart(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { executePaperWorkStart } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-work.js:169` |\n| `executePaperWorkSubmitPush` | function: function executePaperWorkSubmitPush(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { executePaperWorkSubmitPush } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-work.js:357` |\n| `mergePaperAgentEntryInstructions` | function: function mergePaperAgentEntryInstructions(current = \"\", { developmentRef }) | current = \"\", { developmentRef } | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { mergePaperAgentEntryInstructions } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-agent-entry.js:61` |\n| `PAPER_AGENT_ENTRY_CONTRACT` | constant: const PAPER_AGENT_ENTRY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_AGENT_ENTRY_CONTRACT } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-agent-entry.js:16` |\n| `PAPER_AGENT_ENTRY_SCHEMA_VERSION` | constant: const PAPER_AGENT_ENTRY_SCHEMA_VERSION | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_AGENT_ENTRY_SCHEMA_VERSION } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-agent-entry.js:17` |\n| `PAPER_AGENT_ENTRY_SECTION_END` | constant: const PAPER_AGENT_ENTRY_SECTION_END | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_AGENT_ENTRY_SECTION_END } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-agent-entry.js:20` |\n| `PAPER_AGENT_ENTRY_SECTION_START` | constant: const PAPER_AGENT_ENTRY_SECTION_START | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_AGENT_ENTRY_SECTION_START } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-agent-entry.js:18` |\n| `PAPER_ALPHA_PLAN_CONTRACT` | constant: const PAPER_ALPHA_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_ALPHA_PLAN_CONTRACT } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:90` |\n| `PAPER_BUILD_PLAN_CONTRACT` | constant: const PAPER_BUILD_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_BUILD_PLAN_CONTRACT } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:89` |\n| `PAPER_FLEET_AUDIT_CONTRACT` | constant: const PAPER_FLEET_AUDIT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_FLEET_AUDIT_CONTRACT } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-fleet.js:19` |\n| `PAPER_FLEET_UPDATE_PLAN_CONTRACT` | constant: const PAPER_FLEET_UPDATE_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_FLEET_UPDATE_PLAN_CONTRACT } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-fleet.js:20` |\n| `PAPER_MIGRATION_CONTRACT` | constant: const PAPER_MIGRATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_MIGRATION_CONTRACT } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:82` |\n| `PAPER_NPM_BOOTSTRAP_CONTRACT` | constant: const PAPER_NPM_BOOTSTRAP_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_NPM_BOOTSTRAP_CONTRACT } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:85` |\n| `PAPER_PATHS` | constant: const PAPER_PATHS | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_PATHS } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-repository.js:7` |\n| `PAPER_PREFLIGHT_CONTRACT` | constant: const PAPER_PREFLIGHT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_PREFLIGHT_CONTRACT } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:83` |\n| `PAPER_PROVISIONING_CONTRACT` | constant: const PAPER_PROVISIONING_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_PROVISIONING_CONTRACT } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:87` |\n| `PAPER_RESUME_PLAN_CONTRACT` | constant: const PAPER_RESUME_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_RESUME_PLAN_CONTRACT } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:91` |\n| `PAPER_SCAFFOLD_CONTRACT` | constant: const PAPER_SCAFFOLD_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_SCAFFOLD_CONTRACT } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:81` |\n| `PAPER_STATE_ORDER` | constant: const PAPER_STATE_ORDER | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_STATE_ORDER } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:94` |\n| `PAPER_STATUS_CONTRACT` | constant: const PAPER_STATUS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_STATUS_CONTRACT } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:84` |\n| `PAPER_VISIBILITY_CONTRACT` | constant: const PAPER_VISIBILITY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_VISIBILITY_CONTRACT } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:92` |\n| `PAPER_WORK_START_PLAN_CONTRACT` | constant: const PAPER_WORK_START_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_WORK_START_PLAN_CONTRACT } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-work.js:17` |\n| `PAPER_WORK_SUBMIT_PLAN_CONTRACT` | constant: const PAPER_WORK_SUBMIT_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PAPER_WORK_SUBMIT_PLAN_CONTRACT } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-work.js:19` |\n| `paperAgentEntryFiles` | function: function paperAgentEntryFiles({ cwd, buildchainVersion, buildchainSha, developmentRef = \"\", }) | { cwd, buildchainVersion, buildchainSha, developmentRef = \"\", } | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { paperAgentEntryFiles } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-agent-entry.js:150` |\n| `paperAgentEntryInstructions` | function: function paperAgentEntryInstructions({ developmentRef }) | { developmentRef } | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { paperAgentEntryInstructions } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-agent-entry.js:36` |\n| `paperFleetTransitionWorkspace` | function: function paperFleetTransitionWorkspace(workspaceText, lockText) | workspaceText, lockText | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { paperFleetTransitionWorkspace } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-fleet.js:290` |\n| `planPaperFleetUpdate` | function: function planPaperFleetUpdate(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { planPaperFleetUpdate } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-fleet.js:209` |\n| `planPaperMigration` | function: function planPaperMigration({ cwd = process.cwd(), buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainSha = \"\", } = {}) | { cwd = process.cwd(), buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainSha = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { planPaperMigration } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:1013` |\n| `planPaperScaffold` | function: function planPaperScaffold({ cwd = process.cwd(), buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainRef = \"v3\", buildchainSha = \"\", name = path.basename(path.resolve(cwd)), title = \"\", packageName = \"\", repository = \"\", version = \"0.1.0-alpha.0\", siteBaseUrl = \"\", } = {}) | { cwd = process.cwd(), buildchainRoot = process.cwd(), buildchainVersion = \"\", buildchainRef = \"v3\", buildchainSha = \"\", name = path.basename(path.resolve(cwd)), title = \"\", packageName = \"\", repository = \"\", version = \"0.1.0-alpha.0\", siteBaseUrl = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { planPaperScaffold } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:702` |\n| `resolvePaperBuildchainSha` | function: function resolvePaperBuildchainSha(buildchainRoot, buildchainSha = \"\") | buildchainRoot, buildchainSha = \"\" | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolvePaperBuildchainSha } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-agent-entry.js:177` |\n| `resolvePaperRepository` | function: function resolvePaperRepository(cwd = process.cwd()) | cwd = process.cwd() | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolvePaperRepository } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-repository.js:133` |\n| `resolvePaperRuntimeGitSha` | function: function resolvePaperRuntimeGitSha(buildchainRoot, buildchainVersion = \"\") | buildchainRoot, buildchainVersion = \"\" | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolvePaperRuntimeGitSha } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:245` |\n| `writePaperFleetUpdate` | function: function writePaperFleetUpdate(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { writePaperFleetUpdate } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper-fleet.js:271` |\n| `writePaperMigration` | function: function writePaperMigration(plan) | plan | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { writePaperMigration } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:1130` |\n| `writePaperScaffold` | function: function writePaperScaffold(plan) | plan | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { writePaperScaffold } from \"@kungfu-tech/buildchain/paper\";` | `packages/core/paper.js:847` |\n\n## `@kungfu-tech/buildchain/publication-authority`\n\nTarget: `./packages/core/publication-authority.js`. Public symbols: 24.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `CONSUMER_PUBLICATION_DECISION_CONTRACT` | constant: const CONSUMER_PUBLICATION_DECISION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { CONSUMER_PUBLICATION_DECISION_CONTRACT } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:20` |\n| `createConsumerPublicationDecision` | function: function createConsumerPublicationDecision({ capability, gateAggregate, decision, predicateId, predicateDigest, evidence = {}, now = new Date(), } = {}) | { capability, gateAggregate, decision, predicateId, predicateDigest, evidence = {}, now = new Date(), } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createConsumerPublicationDecision } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:991` |\n| `createPublicationAdmission` | function: function createPublicationAdmission(input = {}) | input = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createPublicationAdmission } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:236` |\n| `createPublicationArtifactManifestSet` | function: function createPublicationArtifactManifestSet({ repository, sourceSha, sourceTreeSha, manifests = [], payloads = [], } = {}) | { repository, sourceSha, sourceTreeSha, manifests = [], payloads = [], } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPublicationArtifactManifestSet } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:303` |\n| `createPublicationAuthorityRegistry` | function: function createPublicationAuthorityRegistry({ descriptors = [], workflows = [] } = {}) | { descriptors = [], workflows = [] } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPublicationAuthorityRegistry } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:121` |\n| `createPublicationControlPlaneAudit` | function: function createPublicationControlPlaneAudit({ repository, workflowPath, publisherWorkflowPath, environment, facts = [], observedAt, expiresAt, } = {}) | { repository, workflowPath, publisherWorkflowPath, environment, facts = [], observedAt, expiresAt, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createPublicationControlPlaneAudit } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:208` |\n| `createPublicationGateDecision` | function: function createPublicationGateDecision({ sourceSha, profile, required = false, rationale, policy = {}, } = {}) | { sourceSha, profile, required = false, rationale, policy = {}, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createPublicationGateDecision } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:280` |\n| `createPublicationQualificationReceipt` | function: function createPublicationQualificationReceipt({ capability, gateAggregate, consumerDecision, now = new Date(), } = {}) | { capability, gateAggregate, consumerDecision, now = new Date(), } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPublicationQualificationReceipt } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:1035` |\n| `createRunnerProvenance` | function: function createRunnerProvenance({ runnerClass, os, architecture, imageDigest, measurementDigest, baselineDigest = \"\", toolchainDigest = \"\", cacheContractDigest = \"\", taskIsolationDigest = \"\", cleanBaselineProven = false, isolation = \"\", } = {}) | { runnerClass, os, architecture, imageDigest, measurementDigest, baselineDigest = \"\", toolchainDigest = \"\", cacheContractDigest = \"\", taskIsolationDigest = \"\", cleanBaselineProven = false, isolation = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createRunnerProvenance } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:166` |\n| `detectPublicationAuthoritySignals` | function: function detectPublicationAuthoritySignals(workflowText = \"\") | workflowText = \"\" | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { detectPublicationAuthoritySignals } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:104` |\n| `PUBLICATION_ADMISSION_CONTRACT` | constant: const PUBLICATION_ADMISSION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_ADMISSION_CONTRACT } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:10` |\n| `PUBLICATION_ARTIFACT_MANIFEST_SET_CONTRACT` | constant: const PUBLICATION_ARTIFACT_MANIFEST_SET_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_ARTIFACT_MANIFEST_SET_CONTRACT } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:24` |\n| `PUBLICATION_AUTHORITY_CLASSES` | constant: const PUBLICATION_AUTHORITY_CLASSES | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_AUTHORITY_CLASSES } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:27` |\n| `PUBLICATION_AUTHORITY_REGISTRY_CONTRACT` | constant: const PUBLICATION_AUTHORITY_REGISTRY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_AUTHORITY_REGISTRY_CONTRACT } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:8` |\n| `PUBLICATION_CAPABILITY_CONTRACT` | constant: const PUBLICATION_CAPABILITY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_CAPABILITY_CONTRACT } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:12` |\n| `PUBLICATION_CONTROL_PLANE_AUDIT_CONTRACT` | constant: const PUBLICATION_CONTROL_PLANE_AUDIT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_CONTROL_PLANE_AUDIT_CONTRACT } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:16` |\n| `PUBLICATION_GATE_DECISION_CONTRACT` | constant: const PUBLICATION_GATE_DECISION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_GATE_DECISION_CONTRACT } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:18` |\n| `PUBLICATION_QUALIFICATION_RECEIPT_CONTRACT` | constant: const PUBLICATION_QUALIFICATION_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PUBLICATION_QUALIFICATION_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:22` |\n| `publicationAuthorityDigest` | function: function publicationAuthorityDigest(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { publicationAuthorityDigest } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:72` |\n| `publicationGateAggregateBindings` | function: function publicationGateAggregateBindings(gateAggregate) | gateAggregate | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { publicationGateAggregateBindings } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:408` |\n| `RUNNER_PROVENANCE_CLASSES` | constant: const RUNNER_PROVENANCE_CLASSES | none | value | Import does not declare a throw contract. | none-on-import | `import { RUNNER_PROVENANCE_CLASSES } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:36` |\n| `RUNNER_PROVENANCE_CONTRACT` | constant: const RUNNER_PROVENANCE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RUNNER_PROVENANCE_CONTRACT } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:14` |\n| `verifyPublicationAdmission` | function: function verifyPublicationAdmission({ admission, registry, runnerProvenance, controlPlaneAudit, publicationEvidence, expected = {}, usedNonces = [], now = new Date(), } = {}) | { admission, registry, runnerProvenance, controlPlaneAudit, publicationEvidence, expected = {}, usedNonces = [], now = new Date(), } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { verifyPublicationAdmission } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:791` |\n| `verifyPublicationQualificationReceipt` | function: function verifyPublicationQualificationReceipt({ receipt, capability, gateAggregate, expected = {}, usedNonces = [], now = new Date(), } = {}) | { receipt, capability, gateAggregate, expected = {}, usedNonces = [], now = new Date(), } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { verifyPublicationQualificationReceipt } from \"@kungfu-tech/buildchain/publication-authority\";` | `packages/core/publication-authority.js:1096` |\n\n## `@kungfu-tech/buildchain/publication-control-plane-audit`\n\nTarget: `./packages/core/publication-control-plane-audit.js`. Public symbols: 4.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `BUILDCHAIN_RELEASE_RECONCILIATION_PATHS` | constant: const BUILDCHAIN_RELEASE_RECONCILIATION_PATHS | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_RELEASE_RECONCILIATION_PATHS } from \"@kungfu-tech/buildchain/publication-control-plane-audit\";` | `packages/core/publication-control-plane-audit.js:3` |\n| `evaluateBuildchainReleaseReconciliation` | function: function evaluateBuildchainReleaseReconciliation({ repository, publicationVersion, packageVersion, message, parentSha, changedPaths, } = {}) | { repository, publicationVersion, packageVersion, message, parentSha, changedPaths, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { evaluateBuildchainReleaseReconciliation } from \"@kungfu-tech/buildchain/publication-control-plane-audit\";` | `packages/core/publication-control-plane-audit.js:41` |\n| `evaluatePublicationControlPlaneSnapshot` | function: function evaluatePublicationControlPlaneSnapshot({ repository, workflowPath, publisherWorkflowPath = workflowPath, environment, branch, packageName, publisherMode = \"npm-trusted-publisher\", requiredStatusCheck = \"check\", snapshot, observedAt, expiresAt, } = {}) | { repository, workflowPath, publisherWorkflowPath = workflowPath, environment, branch, packageName, publisherMode = \"npm-trusted-publisher\", requiredStatusCheck = \"check\", snapshot, observedAt, expiresAt, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { evaluatePublicationControlPlaneSnapshot } from \"@kungfu-tech/buildchain/publication-control-plane-audit\";` | `packages/core/publication-control-plane-audit.js:75` |\n| `matchesGithubDeploymentPolicy` | function: function matchesGithubDeploymentPolicy(policy, { ref, refType = \"branch\" } = {}) | policy, { ref, refType = \"branch\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { matchesGithubDeploymentPolicy } from \"@kungfu-tech/buildchain/publication-control-plane-audit\";` | `packages/core/publication-control-plane-audit.js:31` |\n\n## `@kungfu-tech/buildchain/buildchain-publication-authority`\n\nTarget: `./packages/core/buildchain-publication-authority.js`. Public symbols: 2.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `buildchainPublicationAuthorityDescriptors` | function: function buildchainPublicationAuthorityDescriptors() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { buildchainPublicationAuthorityDescriptors } from \"@kungfu-tech/buildchain/buildchain-publication-authority\";` | `packages/core/buildchain-publication-authority.js:62` |\n| `createBuildchainPublicationAuthorityRegistry` | function: function createBuildchainPublicationAuthorityRegistry({ root = process.cwd() } = {}) | { root = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainPublicationAuthorityRegistry } from \"@kungfu-tech/buildchain/buildchain-publication-authority\";` | `packages/core/buildchain-publication-authority.js:86` |\n\n## `@kungfu-tech/buildchain/github-governance-authority`\n\nTarget: `./packages/core/github-governance-authority.js`. Public symbols: 22.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `BUILDCHAIN_GITHUB_GOVERNANCE_AUTHORITY` | constant: const BUILDCHAIN_GITHUB_GOVERNANCE_AUTHORITY | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_GITHUB_GOVERNANCE_AUTHORITY } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:1365` |\n| `BUILDCHAIN_GITHUB_GOVERNANCE_PROTECTED_PATHS` | constant: const BUILDCHAIN_GITHUB_GOVERNANCE_PROTECTED_PATHS | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_GITHUB_GOVERNANCE_PROTECTED_PATHS } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:1367` |\n| `codeownersForPath` | function: function codeownersForPath(source, candidatePath) | source, candidatePath | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { codeownersForPath } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:419` |\n| `compileEffectiveGithubGovernancePolicy` | function: function compileEffectiveGithubGovernancePolicy({ branch, defaultBranch, protectedBranch = false, protection, rulesets = [], } = {}) | { branch, defaultBranch, protectedBranch = false, protection, rulesets = [], } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { compileEffectiveGithubGovernancePolicy } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:313` |\n| `createBuildchainGithubGovernanceAuthority` | function: function createBuildchainGithubGovernanceAuthority() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainGithubGovernanceAuthority } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:452` |\n| `createGithubGovernanceRolloutPlan` | function: function createGithubGovernanceRolloutPlan({ repository, targetRef, inventory, rollbackSnapshot, rollbackProtectionExists = true, desiredProtection, } = {}) | { repository, targetRef, inventory, rollbackSnapshot, rollbackProtectionExists = true, desiredProtection, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGithubGovernanceRolloutPlan } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:934` |\n| `createGithubRulesetBypassRolloutPlan` | function: function createGithubRulesetBypassRolloutPlan({ repository, rulesetId, inventory, rollbackSnapshot, } = {}) | { repository, rulesetId, inventory, rollbackSnapshot, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGithubRulesetBypassRolloutPlan } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:1112` |\n| `createGithubRulesetGovernanceRolloutPlan` | function: function createGithubRulesetGovernanceRolloutPlan({ repository, targetRef, rulesetId, rulesetName, inventory, rollbackSnapshot, desiredProtection, } = {}) | { repository, targetRef, rulesetId, rulesetName, inventory, rollbackSnapshot, desiredProtection, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGithubRulesetGovernanceRolloutPlan } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:1191` |\n| `evaluateCodeownersAuthority` | function: function evaluateCodeownersAuthority({ source = \"\", sourcePath = \"\", reviewAuthority = \"kungfu-origin\", protectedPaths = PROTECTED_AUTHORITY_PATHS, } = {}) | { source = \"\", sourcePath = \"\", reviewAuthority = \"kungfu-origin\", protectedPaths = PROTECTED_AUTHORITY_PATHS, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { evaluateCodeownersAuthority } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:427` |\n| `evaluateGithubGovernanceSnapshot` | function: function evaluateGithubGovernanceSnapshot({ descriptor = createBuildchainGithubGovernanceAuthority(), repository, targetRef, organizationPlan, codeowners, effectivePolicy, memberships, apiEvidence = {}, observedAt, expiresAt, verifier = {}, } = {}) | { descriptor = createBuildchainGithubGovernanceAuthority(), repository, targetRef, organizationPlan, codeowners, effectivePolicy, memberships, apiEvidence = {}, observedAt, expiresAt, verifier = {}, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { evaluateGithubGovernanceSnapshot } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:696` |\n| `GITHUB_GOVERNANCE_AUTHORITY_CONTRACT` | constant: const GITHUB_GOVERNANCE_AUTHORITY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_GOVERNANCE_AUTHORITY_CONTRACT } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:3` |\n| `GITHUB_GOVERNANCE_RECEIPT_CONTRACT` | constant: const GITHUB_GOVERNANCE_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_GOVERNANCE_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:5` |\n| `GITHUB_GOVERNANCE_ROLLOUT_CONTRACT` | constant: const GITHUB_GOVERNANCE_ROLLOUT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_GOVERNANCE_ROLLOUT_CONTRACT } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:7` |\n| `GITHUB_GOVERNANCE_RULESET_ROLLOUT_CONTRACT` | constant: const GITHUB_GOVERNANCE_RULESET_ROLLOUT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { GITHUB_GOVERNANCE_RULESET_ROLLOUT_CONTRACT } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:9` |\n| `githubGovernanceDigest` | function: function githubGovernanceDigest(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { githubGovernanceDigest } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:165` |\n| `githubRepositoryIdentityRoot` | function: function githubRepositoryIdentityRoot({ provider = \"github\", providerRepositoryId, } = {}) | { provider = \"github\", providerRepositoryId, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { githubRepositoryIdentityRoot } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:542` |\n| `normalizeGithubBranchProtectionSnapshot` | function: function normalizeGithubBranchProtectionSnapshot(protection = {}) | protection = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { normalizeGithubBranchProtectionSnapshot } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:1027` |\n| `normalizeGithubRulesetSnapshot` | function: function normalizeGithubRulesetSnapshot(ruleset = {}) | ruleset = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { normalizeGithubRulesetSnapshot } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:1097` |\n| `parseCodeowners` | function: function parseCodeowners(source) | source | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { parseCodeowners } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:403` |\n| `resolveGithubGovernanceTargetPolicy` | function: function resolveGithubGovernanceTargetPolicy({ descriptor = BUILDCHAIN_GITHUB_GOVERNANCE_AUTHORITY, repository, targetRef, } = {}) | { descriptor = BUILDCHAIN_GITHUB_GOVERNANCE_AUTHORITY, repository, targetRef, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolveGithubGovernanceTargetPolicy } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:609` |\n| `resolveGithubGovernanceTargetRefs` | function: function resolveGithubGovernanceTargetRefs({ descriptor = BUILDCHAIN_GITHUB_GOVERNANCE_AUTHORITY, repository, availableRefs = [], requestedTargetRef = \"\", } = {}) | { descriptor = BUILDCHAIN_GITHUB_GOVERNANCE_AUTHORITY, repository, availableRefs = [], requestedTargetRef = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolveGithubGovernanceTargetRefs } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:632` |\n| `verifyGithubGovernanceReceipt` | function: function verifyGithubGovernanceReceipt(receipt, { expectedOrganization, expectedRepository, expectedRepositoryIdentityRoot, expectedTargetRef, expectedPolicyRoot, expectedVerifierSourceRevision, now = new Date().toISOString(), } = {}) | receipt, { expectedOrganization, expectedRepository, expectedRepositoryIdentityRoot, expectedTargetRef, expectedPolicyRoot, expectedVerifierSourceRevision, now = new Date().toISOString(), } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { verifyGithubGovernanceReceipt } from \"@kungfu-tech/buildchain/github-governance-authority\";` | `packages/core/github-governance-authority.js:886` |\n\n## `@kungfu-tech/buildchain/engineering-housekeeper`\n\nTarget: `./packages/core/engineering-housekeeper.js`. Public symbols: 11.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `classifyHousekeeperBranch` | function: function classifyHousekeeperBranch(branch, policyInput = {}) | branch, policyInput = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { classifyHousekeeperBranch } from \"@kungfu-tech/buildchain/engineering-housekeeper\";` | `packages/core/engineering-housekeeper.js:105` |\n| `classifyHousekeeperPullRequest` | function: function classifyHousekeeperPullRequest(pullRequest, policyInput = {}) | pullRequest, policyInput = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { classifyHousekeeperPullRequest } from \"@kungfu-tech/buildchain/engineering-housekeeper\";` | `packages/core/engineering-housekeeper.js:144` |\n| `classifyHousekeeperReplay` | function: function classifyHousekeeperReplay(plan, priorReceipt) | plan, priorReceipt | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { classifyHousekeeperReplay } from \"@kungfu-tech/buildchain/engineering-housekeeper\";` | `packages/core/engineering-housekeeper.js:265` |\n| `createEngineeringHousekeeperPlan` | function: function createEngineeringHousekeeperPlan({ repository, target, branches = [], pullRequests = [], policy = {}, observedAt, }) | { repository, target, branches = [], pullRequests = [], policy = {}, observedAt, } | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createEngineeringHousekeeperPlan } from \"@kungfu-tech/buildchain/engineering-housekeeper\";` | `packages/core/engineering-housekeeper.js:170` |\n| `createEngineeringHousekeeperReceipt` | function: function createEngineeringHousekeeperReceipt({ plan, outcomes, appliedAt, }) | { plan, outcomes, appliedAt, } | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createEngineeringHousekeeperReceipt } from \"@kungfu-tech/buildchain/engineering-housekeeper\";` | `packages/core/engineering-housekeeper.js:246` |\n| `DEFAULT_HOUSEKEEPER_POLICY` | constant: const DEFAULT_HOUSEKEEPER_POLICY | none | value | Import does not declare a throw contract. | none-on-import | `import { DEFAULT_HOUSEKEEPER_POLICY } from \"@kungfu-tech/buildchain/engineering-housekeeper\";` | `packages/core/engineering-housekeeper.js:29` |\n| `ENGINEERING_HOUSEKEEPER_CONTRACT` | constant: const ENGINEERING_HOUSEKEEPER_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ENGINEERING_HOUSEKEEPER_CONTRACT } from \"@kungfu-tech/buildchain/engineering-housekeeper\";` | `packages/core/engineering-housekeeper.js:3` |\n| `ENGINEERING_HOUSEKEEPER_SCHEMA_VERSION` | constant: const ENGINEERING_HOUSEKEEPER_SCHEMA_VERSION | none | value | Import does not declare a throw contract. | none-on-import | `import { ENGINEERING_HOUSEKEEPER_SCHEMA_VERSION } from \"@kungfu-tech/buildchain/engineering-housekeeper\";` | `packages/core/engineering-housekeeper.js:5` |\n| `engineeringHousekeeperRoot` | function: function engineeringHousekeeperRoot(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { engineeringHousekeeperRoot } from \"@kungfu-tech/buildchain/engineering-housekeeper\";` | `packages/core/engineering-housekeeper.js:58` |\n| `HOUSEKEEPER_REASON_CODES` | constant: const HOUSEKEEPER_REASON_CODES | none | value | Import does not declare a throw contract. | none-on-import | `import { HOUSEKEEPER_REASON_CODES } from \"@kungfu-tech/buildchain/engineering-housekeeper\";` | `packages/core/engineering-housekeeper.js:7` |\n| `revalidateHousekeeperBranchAction` | function: function revalidateHousekeeperBranchAction(action, current, policy = {}) | action, current, policy = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { revalidateHousekeeperBranchAction } from \"@kungfu-tech/buildchain/engineering-housekeeper\";` | `packages/core/engineering-housekeeper.js:223` |\n\n## `@kungfu-tech/buildchain/engineering-housekeeper-github`\n\nTarget: `./packages/core/engineering-housekeeper-github.js`. Public symbols: 6.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `applyGitHubHousekeeperPlan` | function: async function applyGitHubHousekeeperPlan({ client, plan, dryRun = true, priorReceipt, appliedAt = new Date().toISOString(), staleDays = DEFAULT_STALE_DAYS, maxActions = DEFAULT_MAX_ACTIONS, }) | { client, plan, dryRun = true, priorReceipt, appliedAt = new Date().toISOString(), staleDays = DEFAULT_STALE_DAYS, maxActions = DEFAULT_MAX_ACTIONS, } | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { applyGitHubHousekeeperPlan } from \"@kungfu-tech/buildchain/engineering-housekeeper-github\";` | `packages/core/engineering-housekeeper-github.js:615` |\n| `collectGitHubHousekeeperInventory` | function: async function collectGitHubHousekeeperInventory({ client, repository, targetBranch, observedAt, staleDays = DEFAULT_STALE_DAYS, policy = {}, }) | { client, repository, targetBranch, observedAt, staleDays = DEFAULT_STALE_DAYS, policy = {}, } | Promise<unknown> | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { collectGitHubHousekeeperInventory } from \"@kungfu-tech/buildchain/engineering-housekeeper-github\";` | `packages/core/engineering-housekeeper-github.js:246` |\n| `formatGitHubHousekeeperPlan` | function: function formatGitHubHousekeeperPlan(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { formatGitHubHousekeeperPlan } from \"@kungfu-tech/buildchain/engineering-housekeeper-github\";` | `packages/core/engineering-housekeeper-github.js:697` |\n| `GitHubHousekeeperClient` | class: class GitHubHousekeeperClient | none | GitHubHousekeeperClient | Construction and method errors follow the linked source implementation. | class-dependent | `import { GitHubHousekeeperClient } from \"@kungfu-tech/buildchain/engineering-housekeeper-github\";` | `packages/core/engineering-housekeeper-github-client.js:54` |\n| `GitHubHousekeeperProviderError` | class: class GitHubHousekeeperProviderError | none | GitHubHousekeeperProviderError | Construction and method errors follow the linked source implementation. | class-dependent | `import { GitHubHousekeeperProviderError } from \"@kungfu-tech/buildchain/engineering-housekeeper-github\";` | `packages/core/engineering-housekeeper-github-client.js:37` |\n| `runGitHubHousekeeper` | function: async function runGitHubHousekeeper(options) | options | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { runGitHubHousekeeper } from \"@kungfu-tech/buildchain/engineering-housekeeper-github\";` | `packages/core/engineering-housekeeper-github.js:691` |\n\n## `@kungfu-tech/buildchain/kfd-gate`\n\nTarget: `./packages/core/kfd-gate.js`. Public symbols: 19.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `BUILDCHAIN_JSON_FORMATTING_POLICY` | constant: const BUILDCHAIN_JSON_FORMATTING_POLICY | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_JSON_FORMATTING_POLICY } from \"@kungfu-tech/buildchain/kfd-gate\";` | `packages/core/kfd-gate.js:14` |\n| `createKfd1ReleaseGateEvidence` | function: function createKfd1ReleaseGateEvidence({ cwd = process.cwd(), artifactRoot = \"\", artifacts = [], witnesses = [], verifiedAt = new Date().toISOString(), metadata = resolveKfd1Metadata(), } = {}) | { cwd = process.cwd(), artifactRoot = \"\", artifacts = [], witnesses = [], verifiedAt = new Date().toISOString(), metadata = resolveKfd1Metadata(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createKfd1ReleaseGateEvidence } from \"@kungfu-tech/buildchain/kfd-gate\";` | `packages/core/kfd-gate.js:977` |\n| `createKfd3CollaborationInterfaceReleaseGateEvidence` | function: function createKfd3CollaborationInterfaceReleaseGateEvidence({ prebuildWitnesses = [], artifactWitnesses = [], prebuildWitnessMetas = [], artifactWitnessMetas = [], artifactCommandMeta = undefined, verifiedAt = new Date().toISOString(), metadata = resolveKfd3Metadata(), } = {}) | { prebuildWitnesses = [], artifactWitnesses = [], prebuildWitnessMetas = [], artifactWitnessMetas = [], artifactCommandMeta = undefined, verifiedAt = new Date().toISOString(), metadata = resolveKfd3Metadata(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createKfd3CollaborationInterfaceReleaseGateEvidence } from \"@kungfu-tech/buildchain/kfd-gate\";` | `packages/core/kfd-gate.js:1132` |\n| `KFD1_RELEASE_GATE_CONTRACT` | constant: const KFD1_RELEASE_GATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD1_RELEASE_GATE_CONTRACT } from \"@kungfu-tech/buildchain/kfd-gate\";` | `packages/core/kfd-gate.js:9` |\n| `KFD1_WITNESS_SET_CONTRACT` | constant: const KFD1_WITNESS_SET_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD1_WITNESS_SET_CONTRACT } from \"@kungfu-tech/buildchain/kfd-gate\";` | `packages/core/kfd-gate.js:10` |\n| `KFD3_ARTIFACT_WITNESS_CONTRACT` | constant: const KFD3_ARTIFACT_WITNESS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD3_ARTIFACT_WITNESS_CONTRACT } from \"@kungfu-tech/buildchain/kfd-gate\";` | `packages/core/kfd-gate.js:13` |\n| `KFD3_PREBUILD_WITNESS_CONTRACT` | constant: const KFD3_PREBUILD_WITNESS_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD3_PREBUILD_WITNESS_CONTRACT } from \"@kungfu-tech/buildchain/kfd-gate\";` | `packages/core/kfd-gate.js:12` |\n| `KFD3_RELEASE_GATE_CONTRACT` | constant: const KFD3_RELEASE_GATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD3_RELEASE_GATE_CONTRACT } from \"@kungfu-tech/buildchain/kfd-gate\";` | `packages/core/kfd-gate.js:11` |\n| `normalizeKfd1ContractWorldWitness` | function: function normalizeKfd1ContractWorldWitness(witness, { metadata = resolveKfd1Metadata() } = {}) | witness, { metadata = resolveKfd1Metadata() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeKfd1ContractWorldWitness } from \"@kungfu-tech/buildchain/kfd-gate\";` | `packages/core/kfd-gate.js:897` |\n| `normalizeKfd3CollaborationInterfaceArtifactWitness` | function: function normalizeKfd3CollaborationInterfaceArtifactWitness(witness, { metadata = resolveKfd3Metadata() } = {}) | witness, { metadata = resolveKfd3Metadata() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeKfd3CollaborationInterfaceArtifactWitness } from \"@kungfu-tech/buildchain/kfd-gate\";` | `packages/core/kfd-gate.js:738` |\n| `normalizeKfd3CollaborationInterfacePrebuildWitness` | function: function normalizeKfd3CollaborationInterfacePrebuildWitness(witness, { metadata = resolveKfd3Metadata() } = {}) | witness, { metadata = resolveKfd3Metadata() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeKfd3CollaborationInterfacePrebuildWitness } from \"@kungfu-tech/buildchain/kfd-gate\";` | `packages/core/kfd-gate.js:667` |\n| `resolveKfd1Metadata` | function: function resolveKfd1Metadata() | none | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolveKfd1Metadata } from \"@kungfu-tech/buildchain/kfd-gate\";` | `packages/core/kfd-gate.js:89` |\n| `resolveKfd2Metadata` | function: function resolveKfd2Metadata({ requireTrustTaxonomy = false } = {}) | { requireTrustTaxonomy = false } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolveKfd2Metadata } from \"@kungfu-tech/buildchain/kfd-gate\";` | `packages/core/kfd-gate.js:173` |\n| `resolveKfd3Metadata` | function: function resolveKfd3Metadata({ requireSchemas = false } = {}) | { requireSchemas = false } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolveKfd3Metadata } from \"@kungfu-tech/buildchain/kfd-gate\";` | `packages/core/kfd-gate.js:128` |\n| `sha256File` | function: function sha256File(filePath) | filePath | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { sha256File } from \"@kungfu-tech/buildchain/kfd-gate\";` | `packages/core/kfd-gate.js:54` |\n| `sha256Json` | function: function sha256Json(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { sha256Json } from \"@kungfu-tech/buildchain/kfd-gate\";` | `packages/core/kfd-gate.js:50` |\n| `validateKfd1ReleaseGateEvidence` | function: function validateKfd1ReleaseGateEvidence(section, { metadata = resolveKfd1Metadata() } = {}) | section, { metadata = resolveKfd1Metadata() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateKfd1ReleaseGateEvidence } from \"@kungfu-tech/buildchain/kfd-gate\";` | `packages/core/kfd-gate.js:1337` |\n| `validateKfd2TrustTaxonomyEntry` | function: function validateKfd2TrustTaxonomyEntry(entry, { kind = \"residualRisk\", label = kind, metadata = resolveKfd2Metadata({ requireTrustTaxonomy: true }), extensionRequests = [], } = {}) | entry, { kind = \"residualRisk\", label = kind, metadata = resolveKfd2Metadata({ requireTrustTaxonomy: true }), extensionRequests = [], } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { validateKfd2TrustTaxonomyEntry } from \"@kungfu-tech/buildchain/kfd-gate\";` | `packages/core/kfd-gate.js:506` |\n| `validateKfd3CollaborationInterfaceReleaseGateEvidence` | function: function validateKfd3CollaborationInterfaceReleaseGateEvidence(section, { metadata = resolveKfd3Metadata() } = {}) | section, { metadata = resolveKfd3Metadata() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateKfd3CollaborationInterfaceReleaseGateEvidence } from \"@kungfu-tech/buildchain/kfd-gate\";` | `packages/core/kfd-gate.js:1470` |\n\n## `@kungfu-tech/buildchain/release-candidate`\n\nTarget: `./packages/core/release-candidate.js`. Public symbols: 5.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `createReleaseCandidatePassport` | function: function createReleaseCandidatePassport({ repository = \"\", pullRequest = {}, targetChannel = \"\", version = \"\", sourceHeadSha = \"\", baseSha = \"\", mergeRefSha = \"\", sourceTreeHash = \"\", buildSummary = {}, buildchain = {}, gateAggregate = undefined, familyEvidence = undefined, controllerReceipts = [], controllerReceiptReferences = [], workflow = {}, createdAt = nowIso(), } = {}) | { repository = \"\", pullRequest = {}, targetChannel = \"\", version = \"\", sourceHeadSha = \"\", baseSha = \"\", mergeRefSha = \"\", sourceTreeHash = \"\", buildSummary = {}, buildchain = {}, gateAggregate = undefined, familyEvidence = undefined, controllerReceipts = [], controllerReceiptReferences = [], workflow = {}, createdAt = nowIso(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createReleaseCandidatePassport } from \"@kungfu-tech/buildchain/release-candidate\";` | `packages/core/release-candidate.js:310` |\n| `FAMILY_RELEASE_EVIDENCE_CONTRACT` | constant: const FAMILY_RELEASE_EVIDENCE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { FAMILY_RELEASE_EVIDENCE_CONTRACT } from \"@kungfu-tech/buildchain/release-candidate\";` | `packages/core/release-candidate.js:5` |\n| `RELEASE_CANDIDATE_PASSPORT_CONTRACT` | constant: const RELEASE_CANDIDATE_PASSPORT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_CANDIDATE_PASSPORT_CONTRACT } from \"@kungfu-tech/buildchain/release-candidate\";` | `packages/core/release-candidate.js:4` |\n| `sha256Json` | function: function sha256Json(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { sha256Json } from \"@kungfu-tech/buildchain/release-candidate\";` | `packages/core/release-candidate.js:90` |\n| `validateReleaseCandidatePassport` | function: function validateReleaseCandidatePassport({ passport, repository = \"\", targetChannel = \"\", version = \"\", sourceHeadSha = \"\", buildSummary = undefined, requirePlatforms = true, requireFamilyEvidence = false, familyEvidenceRoot = \"\", familyInitiativeId = \"\", familyAssignmentId = \"\", } = {}) | { passport, repository = \"\", targetChannel = \"\", version = \"\", sourceHeadSha = \"\", buildSummary = undefined, requirePlatforms = true, requireFamilyEvidence = false, familyEvidenceRoot = \"\", familyInitiativeId = \"\", familyAssignmentId = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateReleaseCandidatePassport } from \"@kungfu-tech/buildchain/release-candidate\";` | `packages/core/release-candidate.js:404` |\n\n## `@kungfu-tech/buildchain/release-candidate-recovery`\n\nTarget: `./packages/core/release-candidate-recovery.js`. Public symbols: 7.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `rebindPublicationGateAggregateForEquivalentTree` | function: function rebindPublicationGateAggregateForEquivalentTree(gateAggregate, { evidenceSourceSha = \"\", targetSourceSha = \"\", targetSourceTreeSha = \"\", expectedSourceTreeSha = \"\" } = {}) | gateAggregate, { evidenceSourceSha = \"\", targetSourceSha = \"\", targetSourceTreeSha = \"\", expectedSourceTreeSha = \"\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { rebindPublicationGateAggregateForEquivalentTree } from \"@kungfu-tech/buildchain/release-candidate-recovery\";` | `packages/core/release-candidate-recovery.js:18` |\n| `recoveryFailure` | function: function recoveryFailure(error) | error | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { recoveryFailure } from \"@kungfu-tech/buildchain/release-candidate-recovery\";` | `packages/core/release-candidate-recovery.js:529` |\n| `RELEASE_CANDIDATE_RECOVERY_CONTRACT` | constant: const RELEASE_CANDIDATE_RECOVERY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_CANDIDATE_RECOVERY_CONTRACT } from \"@kungfu-tech/buildchain/release-candidate-recovery\";` | `packages/core/release-candidate-recovery.js:15` |\n| `ReleaseCandidateRecoveryError` | class: class ReleaseCandidateRecoveryError | none | ReleaseCandidateRecoveryError | Construction and method errors follow the linked source implementation. | class-dependent | `import { ReleaseCandidateRecoveryError } from \"@kungfu-tech/buildchain/release-candidate-recovery\";` | `packages/core/release-candidate-recovery.js:56` |\n| `validateRecoveryTargetRef` | function: function validateRecoveryTargetRef({ targetSha, observedTargetSha, expectedTransactionId = \"\", existingTransaction = undefined, ancestry = undefined, } = {}) | { targetSha, observedTargetSha, expectedTransactionId = \"\", existingTransaction = undefined, ancestry = undefined, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateRecoveryTargetRef } from \"@kungfu-tech/buildchain/release-candidate-recovery\";` | `packages/core/release-candidate-recovery.js:134` |\n| `validateReleaseCandidateRecoveryReceipt` | function: function validateReleaseCandidateRecoveryReceipt({ receipt, passport, repository = \"\", targetChannel = \"\", targetRef = \"\", targetSha = \"\", targetTree = \"\", version = \"\", } = {}) | { receipt, passport, repository = \"\", targetChannel = \"\", targetRef = \"\", targetSha = \"\", targetTree = \"\", version = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateReleaseCandidateRecoveryReceipt } from \"@kungfu-tech/buildchain/release-candidate-recovery\";` | `packages/core/release-candidate-recovery.js:176` |\n| `verifyReleaseCandidateRecovery` | function: function verifyReleaseCandidateRecovery({ candidateRepository, targetRepository, expectedRunId, expectedWorkflowFile, expectedWorkflowName, channel, targetRef, targetSha, targetRefSha = targetSha, targetTree, expectedSourceTree = \"\", expectedCandidateRoot = \"\", expectedRuntimeSha, expectedTransactionId = \"\", existingTransaction = undefined, run, workflow, pullRequest, ancestry, passport, buildSummary, controllerReceipts = [], platformManifests = [], platformManifestEvidence = [], productPayloadManifests = [], artifacts = [], publicationVersion = \"\", currentToolingSha, recoveryRunId = \"\", createdAt = new Date().toISOString(), } = {}) | { candidateRepository, targetRepository, expectedRunId, expectedWorkflowFile, expectedWorkflowName, channel, targetRef, targetSha, targetRefSha = targetSha, targetTree, expectedSourceTree = \"\", expectedCandidateRoot = \"\", expectedRuntimeSha, expectedTransactionId = \"\", existingTransaction = undefined, run, workflow, pullRequest, ancestry, passport, buildSummary, controllerReceipts = [], platformManifests = [], platformManifestEvidence = [], productPayloadManifests = [], artifacts = [], publicationVersion = \"\", currentToolingSha, recoveryRunId = \"\", createdAt = new Date().toISOString(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyReleaseCandidateRecovery } from \"@kungfu-tech/buildchain/release-candidate-recovery\";` | `packages/core/release-candidate-recovery.js:398` |\n\n## `@kungfu-tech/buildchain/release-train`\n\nTarget: `./packages/core/release-train.js`. Public symbols: 19.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `createReleaseBlockerRepair` | function: function createReleaseBlockerRepair(activeTrainInput, input = {}) | activeTrainInput, input = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createReleaseBlockerRepair } from \"@kungfu-tech/buildchain/release-train\";` | `packages/core/release-train.js:668` |\n| `createReleaseCut` | function: function createReleaseCut(input = {}) | input = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createReleaseCut } from \"@kungfu-tech/buildchain/release-train\";` | `packages/core/release-train.js:182` |\n| `createReleaseTrain` | function: function createReleaseTrain(input = {}) | input = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createReleaseTrain } from \"@kungfu-tech/buildchain/release-train\";` | `packages/core/release-train.js:216` |\n| `LEGACY_DEV_ALPHA_CANDIDATE_STATE_SCHEMA` | constant: const LEGACY_DEV_ALPHA_CANDIDATE_STATE_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { LEGACY_DEV_ALPHA_CANDIDATE_STATE_SCHEMA } from \"@kungfu-tech/buildchain/release-train\";` | `packages/core/release-train.js:13` |\n| `observeReleaseTrain` | function: function observeReleaseTrain(trainInput, input = {}) | trainInput, input = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { observeReleaseTrain } from \"@kungfu-tech/buildchain/release-train\";` | `packages/core/release-train.js:361` |\n| `readReleaseTrain` | function: function readReleaseTrain(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readReleaseTrain } from \"@kungfu-tech/buildchain/release-train\";` | `packages/core/release-train.js:494` |\n| `RELEASE_BLOCKER_REPAIR_CONTRACT` | constant: const RELEASE_BLOCKER_REPAIR_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_BLOCKER_REPAIR_CONTRACT } from \"@kungfu-tech/buildchain/release-train\";` | `packages/core/release-train.js:11` |\n| `RELEASE_CUT_CONTRACT` | constant: const RELEASE_CUT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_CUT_CONTRACT } from \"@kungfu-tech/buildchain/release-train\";` | `packages/core/release-train.js:5` |\n| `RELEASE_TRAIN_CONTRACT` | constant: const RELEASE_TRAIN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TRAIN_CONTRACT } from \"@kungfu-tech/buildchain/release-train\";` | `packages/core/release-train.js:6` |\n| `RELEASE_TRAIN_OBSERVATION_CONTRACT` | constant: const RELEASE_TRAIN_OBSERVATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TRAIN_OBSERVATION_CONTRACT } from \"@kungfu-tech/buildchain/release-train\";` | `packages/core/release-train.js:9` |\n| `RELEASE_TRAIN_STATES` | constant: const RELEASE_TRAIN_STATES | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TRAIN_STATES } from \"@kungfu-tech/buildchain/release-train\";` | `packages/core/release-train.js:16` |\n| `RELEASE_TRAIN_SUPERSESSION_CAUSES` | constant: const RELEASE_TRAIN_SUPERSESSION_CAUSES | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TRAIN_SUPERSESSION_CAUSES } from \"@kungfu-tech/buildchain/release-train\";` | `packages/core/release-train.js:26` |\n| `RELEASE_TRAIN_TRANSITION_CONTRACT` | constant: const RELEASE_TRAIN_TRANSITION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TRAIN_TRANSITION_CONTRACT } from \"@kungfu-tech/buildchain/release-train\";` | `packages/core/release-train.js:7` |\n| `releaseTrainRoot` | function: function releaseTrainRoot(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { releaseTrainRoot } from \"@kungfu-tech/buildchain/release-train\";` | `packages/core/release-train.js:74` |\n| `settleReleaseBlockerDevLanding` | function: function settleReleaseBlockerDevLanding(repairInput, input = {}) | repairInput, input = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { settleReleaseBlockerDevLanding } from \"@kungfu-tech/buildchain/release-train\";` | `packages/core/release-train.js:708` |\n| `transitionReleaseTrain` | function: function transitionReleaseTrain(trainInput, input = {}) | trainInput, input = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | may-write-or-invoke-external-actions | `import { transitionReleaseTrain } from \"@kungfu-tech/buildchain/release-train\";` | `packages/core/release-train.js:339` |\n| `validateReleaseBlockerRepair` | function: function validateReleaseBlockerRepair(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { validateReleaseBlockerRepair } from \"@kungfu-tech/buildchain/release-train\";` | `packages/core/release-train.js:672` |\n| `validateReleaseCut` | function: function validateReleaseCut(cut) | cut | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { validateReleaseCut } from \"@kungfu-tech/buildchain/release-train\";` | `packages/core/release-train.js:232` |\n| `validateReleaseTrain` | function: function validateReleaseTrain(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { validateReleaseTrain } from \"@kungfu-tech/buildchain/release-train\";` | `packages/core/release-train.js:365` |\n\n## `@kungfu-tech/buildchain/stable-candidate-ledger`\n\nTarget: `./packages/core/stable-candidate-ledger.js`. Public symbols: 11.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `createStableCandidateLedger` | function: function createStableCandidateLedger({ repository, targetBranch, now = new Date().toISOString() } = {}) | { repository, targetBranch, now = new Date().toISOString() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createStableCandidateLedger } from \"@kungfu-tech/buildchain/stable-candidate-ledger\";` | `packages/core/stable-candidate-ledger.js:56` |\n| `markStableCandidatePromoted` | function: function markStableCandidatePromoted(ledgerInput, versionInput, { stableTag = \"\", stableSha = \"\", now = new Date().toISOString() } = {}) | ledgerInput, versionInput, { stableTag = \"\", stableSha = \"\", now = new Date().toISOString() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { markStableCandidatePromoted } from \"@kungfu-tech/buildchain/stable-candidate-ledger\";` | `packages/core/stable-candidate-ledger.js:229` |\n| `normalizeStableCandidateLedger` | function: function normalizeStableCandidateLedger(input, expected = {}) | input, expected = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeStableCandidateLedger } from \"@kungfu-tech/buildchain/stable-candidate-ledger\";` | `packages/core/stable-candidate-ledger.js:76` |\n| `qualifyStableCandidate` | function: function qualifyStableCandidate(ledgerInput, observation, { minimumSoakSeconds = 3600, now = new Date().toISOString() } = {}) | ledgerInput, observation, { minimumSoakSeconds = 3600, now = new Date().toISOString() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { qualifyStableCandidate } from \"@kungfu-tech/buildchain/stable-candidate-ledger\";` | `packages/core/stable-candidate-ledger.js:139` |\n| `registerStableCandidate` | function: function registerStableCandidate(ledgerInput, candidateInput, { now = new Date().toISOString() } = {}) | ledgerInput, candidateInput, { now = new Date().toISOString() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { registerStableCandidate } from \"@kungfu-tech/buildchain/stable-candidate-ledger\";` | `packages/core/stable-candidate-ledger.js:106` |\n| `revokeStableCandidate` | function: function revokeStableCandidate(ledgerInput, versionInput, { reason, actor = \"\", now = new Date().toISOString() } = {}) | ledgerInput, versionInput, { reason, actor = \"\", now = new Date().toISOString() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { revokeStableCandidate } from \"@kungfu-tech/buildchain/stable-candidate-ledger\";` | `packages/core/stable-candidate-ledger.js:185` |\n| `selectStableCandidate` | function: function selectStableCandidate(ledgerInput, { releaseNow = \"\", now = new Date().toISOString() } = {}) | ledgerInput, { releaseNow = \"\", now = new Date().toISOString() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { selectStableCandidate } from \"@kungfu-tech/buildchain/stable-candidate-ledger\";` | `packages/core/stable-candidate-ledger.js:206` |\n| `setStableCandidateHold` | function: function setStableCandidateHold(ledgerInput, enabled, { reason = \"\", now = new Date().toISOString() } = {}) | ledgerInput, enabled, { reason = \"\", now = new Date().toISOString() } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { setStableCandidateHold } from \"@kungfu-tech/buildchain/stable-candidate-ledger\";` | `packages/core/stable-candidate-ledger.js:198` |\n| `STABLE_CANDIDATE_LEDGER_CONTRACT` | constant: const STABLE_CANDIDATE_LEDGER_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { STABLE_CANDIDATE_LEDGER_CONTRACT } from \"@kungfu-tech/buildchain/stable-candidate-ledger\";` | `packages/core/stable-candidate-ledger.js:1` |\n| `STABLE_CANDIDATE_STATES` | constant: const STABLE_CANDIDATE_STATES | none | value | Import does not declare a throw contract. | none-on-import | `import { STABLE_CANDIDATE_STATES } from \"@kungfu-tech/buildchain/stable-candidate-ledger\";` | `packages/core/stable-candidate-ledger.js:2` |\n| `stableCandidatePromotionRefs` | function: function stableCandidatePromotionRefs(candidateInput, targetBranch) | candidateInput, targetBranch | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { stableCandidatePromotionRefs } from \"@kungfu-tech/buildchain/stable-candidate-ledger\";` | `packages/core/stable-candidate-ledger.js:264` |\n\n## `@kungfu-tech/buildchain/release-passport`\n\nTarget: `./packages/core/release-passport.js`. Public symbols: 23.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `AGENT_INDEX_CONTRACT` | constant: const AGENT_INDEX_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { AGENT_INDEX_CONTRACT } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:40` |\n| `ARTIFACT_EVIDENCE_CONTRACT` | constant: const ARTIFACT_EVIDENCE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { ARTIFACT_EVIDENCE_CONTRACT } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:38` |\n| `collectGitHubReleasePassport` | function: function collectGitHubReleasePassport({ cwd = process.cwd(), tag = \"\", repository = process.env.GITHUB_REPOSITORY \\|\\| \"\", sourceSha = process.env.GITHUB_SHA \\|\\| \"\", line = \"\", outputDir = \".buildchain/release-passport\", assetsJson = \"\", assetsDir = \"\", releaseJson = \"\", productName = \"Buildchain\", packageName = \"@kungfu-tech/buildchain\", packageVersion = \"\", packageSetJson = \"\", publishEvidenceJson = \"\", trustedPublishingJson = \"\", transactionJson = \"\", anchorManifestJson = \"\", versionMaterialJson = \"\", impactJson = \"\", buildSummaryJson = \"\", buildFactsJsons = [], platformManifestJsons = [], distTagEvidenceJson = \"\", kfd1WitnessJsons = [], kfd2ClaimJsons = [], kfd3PrebuildWitnessJsons = [], kfd3ArtifactWitnessJsons = [], kfd3ArtifactVerifyCommand = \"\", kfdAdopterManifestJson = \"\", kfdSupportMatrixJson = \"\", kfdProductGateJsons = [], invariantPassportJsons = [], invariantPassportCommand = \"\", releaseEvidenceJsons = [], kfdAgentHubEvidenceJson = \"\", controllerReceiptReferences = [], githubArtifactAttestationPolicyJsons = [], basePassportJson = \"\", requireBaseKfd = false, releaseJsonExtra = \"\", publishJson = \"\", workflow = {}, checkedAt = \"\", } = {}) | { cwd = process.cwd(), tag = \"\", repository = process.env.GITHUB_REPOSITORY \\|\\| \"\", sourceSha = process.env.GITHUB_SHA \\|\\| \"\", line = \"\", outputDir = \".buildchain/release-passport\", assetsJson = \"\", assetsDir = \"\", releaseJson = \"\", productName = \"Buildchain\", packageName = \"@kungfu-tech/buildchain\", packageVersion = \"\", packageSetJson = \"\", publishEvidenceJson = \"\", trustedPublishingJson = \"\", transactionJson = \"\", anchorManifestJson = \"\", versionMaterialJson = \"\", impactJson = \"\", buildSummaryJson = \"\", buildFactsJsons = [], platformManifestJsons = [], distTagEvidenceJson = \"\", kfd1WitnessJsons = [], kfd2ClaimJsons = [], kfd3PrebuildWitnessJsons = [], kfd3ArtifactWitnessJsons = [], kfd3ArtifactVerifyCommand = \"\", kfdAdopterManifestJson = \"\", kfdSupportMatrixJson = \"\", kfdProductGateJsons = [], invariantPassportJsons = [], invariantPassportCommand = \"\", releaseEvidenceJsons = [], kfdAgentHubEvidenceJson = \"\", controllerReceiptReferences = [], githubArtifactAttestationPolicyJsons = [], basePassportJson = \"\", requireBaseKfd = false, releaseJsonExtra = \"\", publishJson = \"\", workflow = {}, checkedAt = \"\", } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { collectGitHubReleasePassport } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:1424` |\n| `createArtifactEvidence` | function: function createArtifactEvidence({ assets = [], repository = \"\", tag = \"\", sourceSha = \"\", workflow = {}, kfdAdopter = undefined } = {}) | { assets = [], repository = \"\", tag = \"\", sourceSha = \"\", workflow = {}, kfdAdopter = undefined } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createArtifactEvidence } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:1088` |\n| `createInvariantPassportGate` | function: function createInvariantPassportGate(passportMetas = []) | passportMetas = [] | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createInvariantPassportGate } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:209` |\n| `createReleaseCheckReport` | function: function createReleaseCheckReport({ passport, artifactEvidence, publishEvidence, impact, agentIndex, productMechanism, kfdAgentHubEvidence, kfdSupportEvidence, kfdAdopterManifest, kfdAdopterManifestGate, releaseEvidenceDocuments = [], checkedAt = nowIso(), } = {}) | { passport, artifactEvidence, publishEvidence, impact, agentIndex, productMechanism, kfdAgentHubEvidence, kfdSupportEvidence, kfdAdopterManifest, kfdAdopterManifestGate, releaseEvidenceDocuments = [], checkedAt = nowIso(), } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createReleaseCheckReport } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:2555` |\n| `createReleasePassport` | function: function createReleasePassport({ cwd = process.cwd(), repository = \"\", tag = \"\", sourceSha = \"\", line = \"\", productName = \"Buildchain\", packageName = \"@kungfu-tech/buildchain\", packageVersion = \"\", productMechanismPath = \"product-mechanism.json\", artifactEvidencePath = \"artifact-evidence.json\", impactPath = \"impact.json\", agentIndexPath = \"agent-index.json\", checkReportPath = \"check-report.json\", publishEvidencePath = \"\", transactionStatePath = \"\", assets = [], packageSet = undefined, anchorManifest = undefined, versionMaterial = undefined, publishEvidence = undefined, trustedPublishing = undefined, transaction = undefined, buildSummary = undefined, buildFacts = [], platformArtifactManifests = [], distTagPromotionEvidence = undefined, release = {}, publish = {}, impact = undefined, workflow = {}, kfd1 = undefined, kfd2Claims = [], kfd3 = undefined, kfdAdopter = undefined, kfdAdopterManifestEvidencePath = \"\", kfdAdopterGateEvidencePath = \"\", kfdSupport = undefined, kfdSupportEvidencePath = \"\", invariantPassports = undefined, releaseEvidence = [], kfdAgentHubEvidence = undefined, kfdAgentHubEvidencePath = \"\", controllerReceipts = [], controllerReceiptReferences = [], githubArtifactAttestations = [], checkedAt = \"\", } = {}) | { cwd = process.cwd(), repository = \"\", tag = \"\", sourceSha = \"\", line = \"\", productName = \"Buildchain\", packageName = \"@kungfu-tech/buildchain\", packageVersion = \"\", productMechanismPath = \"product-mechanism.json\", artifactEvidencePath = \"artifact-evidence.json\", impactPath = \"impact.json\", agentIndexPath = \"agent-index.json\", checkReportPath = \"check-report.json\", publishEvidencePath = \"\", transactionStatePath = \"\", assets = [], packageSet = undefined, anchorManifest = undefined, versionMaterial = undefined, publishEvidence = undefined, trustedPublishing = undefined, transaction = undefined, buildSummary = undefined, buildFacts = [], platformArtifactManifests = [], distTagPromotionEvidence = undefined, release = {}, publish = {}, impact = undefined, workflow = {}, kfd1 = undefined, kfd2Claims = [], kfd3 = undefined, kfdAdopter = undefined, kfdAdopterManifestEvidencePath = \"\", kfdAdopterGateEvidencePath = \"\", kfdSupport = undefined, kfdSupportEvidencePath = \"\", invariantPassports = undefined, releaseEvidence = [], kfdAgentHubEvidence = undefined, kfdAgentHubEvidencePath = \"\", controllerReceipts = [], controllerReceiptReferences = [], githubArtifactAttestations = [], checkedAt = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { createReleasePassport } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:1123` |\n| `explainReleasePassport` | function: async function explainReleasePassport({ passportLocation, forAudience = \"human\" } = {}) | { passportLocation, forAudience = \"human\" } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { explainReleasePassport } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:2709` |\n| `IMPACT_LEDGER_CONTRACT` | constant: const IMPACT_LEDGER_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { IMPACT_LEDGER_CONTRACT } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:39` |\n| `INVARIANT_PASSPORT_GATE_CONTRACT` | constant: const INVARIANT_PASSPORT_GATE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { INVARIANT_PASSPORT_GATE_CONTRACT } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:45` |\n| `KFD_AGENT_HUB_RELEASE_EVIDENCE_CONTRACT` | constant: const KFD_AGENT_HUB_RELEASE_EVIDENCE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD_AGENT_HUB_RELEASE_EVIDENCE_CONTRACT } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:46` |\n| `KFD2_RELEASE_TRUST_PASSPORT_CONTRACT` | constant: const KFD2_RELEASE_TRUST_PASSPORT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD2_RELEASE_TRUST_PASSPORT_CONTRACT } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:43` |\n| `KFD2_TRUST_PROOF_CONTRACT` | constant: const KFD2_TRUST_PROOF_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { KFD2_TRUST_PROOF_CONTRACT } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:44` |\n| `makeReleasePassportFixtureAssets` | function: function makeReleasePassportFixtureAssets(dir) | dir | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | local-filesystem-write | `import { makeReleasePassportFixtureAssets } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:2738` |\n| `PRODUCT_MECHANISM_CONTRACT` | constant: const PRODUCT_MECHANISM_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PRODUCT_MECHANISM_CONTRACT } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:41` |\n| `readJsonFromLocation` | function: async function readJsonFromLocation(location, redirectCount = 0, { timeoutMs = 15_000 } = {}) | location, redirectCount = 0, { timeoutMs = 15_000 } = {} | Promise<unknown> | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readJsonFromLocation } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:2625` |\n| `RELEASE_CHECK_REPORT_CONTRACT` | value: RELEASE_CHECK_REPORT_CONTRACT | none | unknown | No narrower error contract was mechanically discoverable. | unknown | `import { RELEASE_CHECK_REPORT_CONTRACT } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:1` |\n| `RELEASE_EVIDENCE_ATTACHMENT_CONTRACT` | constant: const RELEASE_EVIDENCE_ATTACHMENT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_EVIDENCE_ATTACHMENT_CONTRACT } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:42` |\n| `RELEASE_PASSPORT_CONTRACT` | value: RELEASE_PASSPORT_CONTRACT | none | unknown | No narrower error contract was mechanically discoverable. | unknown | `import { RELEASE_PASSPORT_CONTRACT } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:1` |\n| `sha256File` | function: function sha256File(filePath) | filePath | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write, subprocess | `import { sha256File } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:224` |\n| `sha256Text` | function: function sha256Text(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { sha256Text } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:146` |\n| `validateKnownReleasePassportContracts` | function: function validateKnownReleasePassportContracts() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateKnownReleasePassportContracts } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:2750` |\n| `verifyReleasePassport` | function: async function verifyReleasePassport({ passportLocation, artifactEvidenceLocation = \"\", publishEvidenceLocation = \"\", impactLocation = \"\", agentIndexLocation = \"\", productMechanismLocation = \"\", kfdAgentHubEvidenceLocation = \"\", kfdAdopterManifestLocation = \"\", kfdAdopterManifestGateLocation = \"\", kfdSupportEvidenceLocation = \"\", checkedAt = nowIso(), } = {}) | { passportLocation, artifactEvidenceLocation = \"\", publishEvidenceLocation = \"\", impactLocation = \"\", agentIndexLocation = \"\", productMechanismLocation = \"\", kfdAgentHubEvidenceLocation = \"\", kfdAdopterManifestLocation = \"\", kfdAdopterManifestGateLocation = \"\", kfdSupportEvidenceLocation = \"\", checkedAt = nowIso(), } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { verifyReleasePassport } from \"@kungfu-tech/buildchain/release-passport\";` | `packages/core/release-passport.js:2674` |\n\n## `@kungfu-tech/buildchain/release-passport-contract`\n\nTarget: `./packages/core/release-passport-contract.js`. Public symbols: 16.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `buildReleaseArtifactEvidence` | function: function buildReleaseArtifactEvidence({ normalizedAssets = [], repository = \"\", tag = \"\", sourceSha = \"\", workflow = {}, kfdAdopter } = {}) | { normalizedAssets = [], repository = \"\", tag = \"\", sourceSha = \"\", workflow = {}, kfdAdopter } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { buildReleaseArtifactEvidence } from \"@kungfu-tech/buildchain/release-passport-contract\";` | `packages/core/release-passport-contract.js:359` |\n| `collectKfdAdopterReleaseEvidence` | function: function collectKfdAdopterReleaseEvidence({ manifest, gateResults = [], comparisonMatrix, sourceSha = \"\", checkedAt } = {}) | { manifest, gateResults = [], comparisonMatrix, sourceSha = \"\", checkedAt } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { collectKfdAdopterReleaseEvidence } from \"@kungfu-tech/buildchain/release-passport-contract\";` | `packages/core/release-passport-contract.js:408` |\n| `createReleasePassportCheckManifest` | function: function createReleasePassportCheckManifest({ standards = kfdStandards } = {}) | { standards = kfdStandards } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createReleasePassportCheckManifest } from \"@kungfu-tech/buildchain/release-passport-contract\";` | `packages/core/release-passport-contract.js:159` |\n| `defaultReleaseAgentIndex` | function: function defaultReleaseAgentIndex({ tag = \"\", passportPath = \"buildchain.release.json\" } = {}) | { tag = \"\", passportPath = \"buildchain.release.json\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { defaultReleaseAgentIndex } from \"@kungfu-tech/buildchain/release-passport-contract\";` | `packages/core/release-passport-contract.js:336` |\n| `defaultReleaseImpact` | function: function defaultReleaseImpact({ tag = \"\", line = \"\", decision = \"unknown\" } = {}) | { tag = \"\", line = \"\", decision = \"unknown\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { defaultReleaseImpact } from \"@kungfu-tech/buildchain/release-passport-contract\";` | `packages/core/release-passport-contract.js:318` |\n| `defaultReleaseLlmsText` | function: function defaultReleaseLlmsText({ tag = \"\", passportPath = \"buildchain.release.json\" } = {}) | { tag = \"\", passportPath = \"buildchain.release.json\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { defaultReleaseLlmsText } from \"@kungfu-tech/buildchain/release-passport-contract\";` | `packages/core/release-passport-contract.js:348` |\n| `defaultReleaseProductMechanism` | function: function defaultReleaseProductMechanism({ repository = \"\", productName = \"Buildchain\" } = {}) | { repository = \"\", productName = \"Buildchain\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { defaultReleaseProductMechanism } from \"@kungfu-tech/buildchain/release-passport-contract\";` | `packages/core/release-passport-contract.js:301` |\n| `prepareReleasePassportKfdSections` | function: function prepareReleasePassportKfdSections({ kfd1, kfd2Claims, kfd3, kfdAdopter, kfdSupport, kfd1DefaultKey, createKfd2, evidencePaths = {} } = {}) | { kfd1, kfd2Claims, kfd3, kfdAdopter, kfdSupport, kfd1DefaultKey, createKfd2, evidencePaths = {} } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { prepareReleasePassportKfdSections } from \"@kungfu-tech/buildchain/release-passport-contract\";` | `packages/core/release-passport-contract.js:388` |\n| `RELEASE_CHECK_REPORT_CONTRACT` | constant: const RELEASE_CHECK_REPORT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_CHECK_REPORT_CONTRACT } from \"@kungfu-tech/buildchain/release-passport-contract\";` | `packages/core/release-passport-contract.js:15` |\n| `RELEASE_PASSPORT_CHECK_MANIFEST_CONTRACT` | constant: const RELEASE_PASSPORT_CHECK_MANIFEST_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PASSPORT_CHECK_MANIFEST_CONTRACT } from \"@kungfu-tech/buildchain/release-passport-contract\";` | `packages/core/release-passport-contract.js:19` |\n| `RELEASE_PASSPORT_CONTRACT` | constant: const RELEASE_PASSPORT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PASSPORT_CONTRACT } from \"@kungfu-tech/buildchain/release-passport-contract\";` | `packages/core/release-passport-contract.js:14` |\n| `RELEASE_PASSPORT_SCHEMA` | constant: const RELEASE_PASSPORT_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PASSPORT_SCHEMA } from \"@kungfu-tech/buildchain/release-passport-contract\";` | `packages/core/release-passport-contract.js:26` |\n| `RELEASE_PASSPORT_SCHEMA_ID` | constant: const RELEASE_PASSPORT_SCHEMA_ID | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PASSPORT_SCHEMA_ID } from \"@kungfu-tech/buildchain/release-passport-contract\";` | `packages/core/release-passport-contract.js:17` |\n| `resolveReleasePassportVerificationInputs` | function: async function resolveReleasePassportVerificationInputs({ passportLocation, locations = {}, readJson, resolveSibling } = {}) | { passportLocation, locations = {}, readJson, resolveSibling } = {} | Promise<unknown> | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolveReleasePassportVerificationInputs } from \"@kungfu-tech/buildchain/release-passport-contract\";` | `packages/core/release-passport-contract.js:456` |\n| `validateKfdAdopterReleaseEvidence` | function: function validateKfdAdopterReleaseEvidence({ binding, artifactBinding, manifest, manifestGate, legacyProjection, passportLegacyProjection, expectedSourceSha = \"\" } = {}) | { binding, artifactBinding, manifest, manifestGate, legacyProjection, passportLegacyProjection, expectedSourceSha = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateKfdAdopterReleaseEvidence } from \"@kungfu-tech/buildchain/release-passport-contract\";` | `packages/core/release-passport-contract.js:432` |\n| `validateReleasePassportSchema` | function: function validateReleasePassportSchema(passport) | passport | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateReleasePassportSchema } from \"@kungfu-tech/buildchain/release-passport-contract\";` | `packages/core/release-passport-contract.js:277` |\n\n## `@kungfu-tech/buildchain/release-propagation`\n\nTarget: `./packages/core/release-propagation.js`. Public symbols: 42.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `claimReleasePropagationWork` | function: function claimReleasePropagationWork({ work, expectedWorkRoot, authority, familyState, } = {}) | { work, expectedWorkRoot, authority, familyState, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { claimReleasePropagationWork } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-work-transitions.js:17` |\n| `classifyReleasePropagationCondition` | function: function classifyReleasePropagationCondition(condition) | condition | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { classifyReleasePropagationCondition } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-agent-entry.js:171` |\n| `completeReleasePropagationWork` | function: function completeReleasePropagationWork({ work, expectedWorkRoot, receipt, completionDecision, } = {}) | { work, expectedWorkRoot, receipt, completionDecision, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { completeReleasePropagationWork } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-work-transitions.js:110` |\n| `createManualUpstreamPickupCapture` | function: function createManualUpstreamPickupCapture({ plan, expectedDownstreamBaseSha, }) | { plan, expectedDownstreamBaseSha, } | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createManualUpstreamPickupCapture } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-pickup.js:361` |\n| `createManualUpstreamPickupPlan` | function: function createManualUpstreamPickupPlan({ config: configInput, sourceId, channel, currentVersion, upstreamRelease, }) | { config: configInput, sourceId, channel, currentVersion, upstreamRelease, } | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createManualUpstreamPickupPlan } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-pickup.js:303` |\n| `createPackageReleasePropagationCapture` | function: function createPackageReleasePropagationCapture({ config: configInput, upstreamRelease: upstreamReleaseInput, expectedBaseShas = {}, } = {}) | { config: configInput, upstreamRelease: upstreamReleaseInput, expectedBaseShas = {}, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createPackageReleasePropagationCapture } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-capture.js:101` |\n| `createReleasePropagationLock` | function: function createReleasePropagationLock({ graph, edge, sourceNode, targetNode, upstreamRelease, downstreamChannel, } = {}) | { graph, edge, sourceNode, targetNode, upstreamRelease, downstreamChannel, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createReleasePropagationLock } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation.js:199` |\n| `createReleasePropagationPushPlan` | function: function createReleasePropagationPushPlan({ work: workInput, expectedWorkRoot, repositoryState: stateInput, } = {}) | { work: workInput, expectedWorkRoot, repositoryState: stateInput, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | subprocess | `import { createReleasePropagationPushPlan } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-push.js:77` |\n| `createReleasePropagationReceipt` | function: function createReleasePropagationReceipt({ plan, target = \"\", lockResult, prOutcome, stagingState = \"pending\", productionState = \"not-requested\", observedAt = \"\", } = {}) | { plan, target = \"\", lockResult, prOutcome, stagingState = \"pending\", productionState = \"not-requested\", observedAt = \"\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createReleasePropagationReceipt } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation.js:371` |\n| `createReleasePropagationStageReceipt` | function: function createReleasePropagationStageReceipt({ work, stage, outcome = \"success\", observedAt, actor, summary, evidence, failure = null, } = {}) | { work, stage, outcome = \"success\", observedAt, actor, summary, evidence, failure = null, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createReleasePropagationStageReceipt } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-work.js:214` |\n| `createReleasePropagationWork` | function: function createReleasePropagationWork({ plan, target = \"\", workContext, expectedDownstreamBaseSha, } = {}) | { plan, target = \"\", workContext, expectedDownstreamBaseSha, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createReleasePropagationWork } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-work.js:111` |\n| `executeReleasePropagationPush` | function: function executeReleasePropagationPush({ work, expectedWorkRoot, cwd = process.cwd(), remote = \"origin\", } = {}) | { work, expectedWorkRoot, cwd = process.cwd(), remote = \"origin\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { executeReleasePropagationPush } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-push.js:231` |\n| `inspectReleasePropagationPushState` | function: function inspectReleasePropagationPushState({ work: workInput, cwd = process.cwd(), remote = \"origin\", } = {}) | { work: workInput, cwd = process.cwd(), remote = \"origin\", } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | subprocess | `import { inspectReleasePropagationPushState } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-push.js:174` |\n| `MANUAL_UPSTREAM_PICKUP_CONFIG_CONTRACT` | constant: const MANUAL_UPSTREAM_PICKUP_CONFIG_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { MANUAL_UPSTREAM_PICKUP_CONFIG_CONTRACT } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-pickup.js:16` |\n| `MANUAL_UPSTREAM_PICKUP_PLAN_CONTRACT` | constant: const MANUAL_UPSTREAM_PICKUP_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { MANUAL_UPSTREAM_PICKUP_PLAN_CONTRACT } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-pickup.js:18` |\n| `normalizeManualUpstreamPickupConfig` | function: function normalizeManualUpstreamPickupConfig(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeManualUpstreamPickupConfig } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-pickup.js:118` |\n| `normalizePackageReleasePropagationConfig` | function: function normalizePackageReleasePropagationConfig(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizePackageReleasePropagationConfig } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-capture.js:63` |\n| `normalizeReleasePropagationGraph` | function: function normalizeReleasePropagationGraph(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeReleasePropagationGraph } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation.js:163` |\n| `normalizeSiteUpstreamIntent` | function: function normalizeSiteUpstreamIntent(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { normalizeSiteUpstreamIntent } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-agent-entry.js:77` |\n| `PACKAGE_RELEASE_PROPAGATION_CONFIG_CONTRACT` | constant: const PACKAGE_RELEASE_PROPAGATION_CONFIG_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { PACKAGE_RELEASE_PROPAGATION_CONFIG_CONTRACT } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-capture.js:17` |\n| `planReleasePropagation` | function: function planReleasePropagation({ graph: graphInput, upstreamRelease: releaseInput, sourceNode = \"\" } = {}) | { graph: graphInput, upstreamRelease: releaseInput, sourceNode = \"\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { planReleasePropagation } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation.js:249` |\n| `planSiteUpstreamAgentEntry` | function: function planSiteUpstreamAgentEntry({ sourceId: sourceInput, channel = \"\", handoffWork = null, } = {}) | { sourceId: sourceInput, channel = \"\", handoffWork = null, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { planSiteUpstreamAgentEntry } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-agent-entry.js:134` |\n| `readReleasePropagationJson` | function: function readReleasePropagationJson(value, { cwd = process.cwd(), label = \"json\" } = {}) | value, { cwd = process.cwd(), label = \"json\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readReleasePropagationJson } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation.js:305` |\n| `recordReleasePropagationStage` | function: function recordReleasePropagationStage({ work, expectedWorkRoot, receipt } = {}) | { work, expectedWorkRoot, receipt } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { recordReleasePropagationStage } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-work-transitions.js:45` |\n| `RELEASE_PROPAGATION_FAILURE_MATRIX` | constant: const RELEASE_PROPAGATION_FAILURE_MATRIX | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_FAILURE_MATRIX } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-agent-entry.js:66` |\n| `RELEASE_PROPAGATION_FAILURE_MATRIX_CONTRACT` | constant: const RELEASE_PROPAGATION_FAILURE_MATRIX_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_FAILURE_MATRIX_CONTRACT } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-agent-entry.js:11` |\n| `RELEASE_PROPAGATION_GRAPH_CONTRACT` | constant: const RELEASE_PROPAGATION_GRAPH_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_GRAPH_CONTRACT } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation.js:15` |\n| `RELEASE_PROPAGATION_LOCK_CONTRACT` | constant: const RELEASE_PROPAGATION_LOCK_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_LOCK_CONTRACT } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation.js:17` |\n| `RELEASE_PROPAGATION_PLAN_CONTRACT` | value: RELEASE_PROPAGATION_PLAN_CONTRACT | none | unknown | No narrower error contract was mechanically discoverable. | unknown | `import { RELEASE_PROPAGATION_PLAN_CONTRACT } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation.js:1` |\n| `RELEASE_PROPAGATION_PUSH_PLAN_CONTRACT` | constant: const RELEASE_PROPAGATION_PUSH_PLAN_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_PUSH_PLAN_CONTRACT } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-push.js:14` |\n| `RELEASE_PROPAGATION_PUSH_RESULT_CONTRACT` | constant: const RELEASE_PROPAGATION_PUSH_RESULT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_PUSH_RESULT_CONTRACT } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-push.js:16` |\n| `RELEASE_PROPAGATION_RECEIPT_CONTRACT` | constant: const RELEASE_PROPAGATION_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation.js:18` |\n| `RELEASE_PROPAGATION_STAGE_RECEIPT_CONTRACT` | constant: const RELEASE_PROPAGATION_STAGE_RECEIPT_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_STAGE_RECEIPT_CONTRACT } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-work-constants.js:2` |\n| `RELEASE_PROPAGATION_WORK_CONTRACT` | constant: const RELEASE_PROPAGATION_WORK_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_WORK_CONTRACT } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-work-constants.js:1` |\n| `RELEASE_PROPAGATION_WORK_STAGES` | constant: const RELEASE_PROPAGATION_WORK_STAGES | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_PROPAGATION_WORK_STAGES } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-work-constants.js:4` |\n| `repairReleasePropagationWork` | function: function repairReleasePropagationWork({ work, expectedWorkRoot, receipt } = {}) | { work, expectedWorkRoot, receipt } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { repairReleasePropagationWork } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-work-transitions.js:88` |\n| `resolveNpmRegistryRelease` | function: function resolveNpmRegistryRelease({ source: sourceInput, channel, packageMetadata, attestations, }) | { source: sourceInput, channel, packageMetadata, attestations, } | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { resolveNpmRegistryRelease } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-pickup.js:167` |\n| `resolvePropagationChannel` | function: function resolvePropagationChannel(edge, upstreamChannel) | edge, upstreamChannel | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resolvePropagationChannel } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation.js:190` |\n| `resumeReleasePropagationWork` | function: function resumeReleasePropagationWork(work) | work | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { resumeReleasePropagationWork } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-work.js:518` |\n| `SITE_UPSTREAM_AGENT_ENTRY_CONTRACT` | constant: const SITE_UPSTREAM_AGENT_ENTRY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { SITE_UPSTREAM_AGENT_ENTRY_CONTRACT } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-agent-entry.js:9` |\n| `verifyReleasePropagationWork` | function: function verifyReleasePropagationWork(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { verifyReleasePropagationWork } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation-work.js:486` |\n| `writeReleasePropagationLock` | function: function writeReleasePropagationLock({ plan, target = \"\", cwd = process.cwd(), output = \"\" } = {}) | { plan, target = \"\", cwd = process.cwd(), output = \"\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { writeReleasePropagationLock } from \"@kungfu-tech/buildchain/release-propagation\";` | `packages/core/release-propagation.js:317` |\n\n## `@kungfu-tech/buildchain/release-activation-transaction`\n\nTarget: `./packages/core/release-activation-transaction.js`. Public symbols: 11.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `abortReleaseActivationTransaction` | function: function abortReleaseActivationTransaction(transaction, reason) | transaction, reason | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { abortReleaseActivationTransaction } from \"@kungfu-tech/buildchain/release-activation-transaction\";` | `packages/core/release-activation-transaction.js:277` |\n| `createReleaseActivationReceiptSet` | function: function createReleaseActivationReceiptSet({ transaction, receipts = [], } = {}) | { transaction, receipts = [], } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createReleaseActivationReceiptSet } from \"@kungfu-tech/buildchain/release-activation-transaction\";` | `packages/core/release-activation-transaction.js:311` |\n| `createReleaseActivationTransaction` | function: function createReleaseActivationTransaction({ transactionId, mode = \"shadow\", bindings, owners, } = {}) | { transactionId, mode = \"shadow\", bindings, owners, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createReleaseActivationTransaction } from \"@kungfu-tech/buildchain/release-activation-transaction\";` | `packages/core/release-activation-transaction.js:103` |\n| `recordReleaseActivationPhase` | function: function recordReleaseActivationPhase(transaction, phaseId, { receiptRoots = [], failure = \"\" } = {}) | transaction, phaseId, { receiptRoots = [], failure = \"\" } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { recordReleaseActivationPhase } from \"@kungfu-tech/buildchain/release-activation-transaction\";` | `packages/core/release-activation-transaction.js:217` |\n| `RELEASE_ACTIVATION_CONTRACT` | constant: const RELEASE_ACTIVATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_ACTIVATION_CONTRACT } from \"@kungfu-tech/buildchain/release-activation-transaction\";` | `packages/core/release-activation-transaction.js:3` |\n| `RELEASE_ACTIVATION_PHASES` | constant: const RELEASE_ACTIVATION_PHASES | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_ACTIVATION_PHASES } from \"@kungfu-tech/buildchain/release-activation-transaction\";` | `packages/core/release-activation-transaction.js:8` |\n| `RELEASE_ACTIVATION_RECEIPT_SET_CONTRACT` | constant: const RELEASE_ACTIVATION_RECEIPT_SET_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_ACTIVATION_RECEIPT_SET_CONTRACT } from \"@kungfu-tech/buildchain/release-activation-transaction\";` | `packages/core/release-activation-transaction.js:5` |\n| `releaseActivationRoot` | function: function releaseActivationRoot(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { releaseActivationRoot } from \"@kungfu-tech/buildchain/release-activation-transaction\";` | `packages/core/release-activation-transaction.js:38` |\n| `rollbackReleaseActivationTransaction` | function: function rollbackReleaseActivationTransaction(transaction, { toSiteSourceSha, reason } = {}) | transaction, { toSiteSourceSha, reason } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { rollbackReleaseActivationTransaction } from \"@kungfu-tech/buildchain/release-activation-transaction\";` | `packages/core/release-activation-transaction.js:290` |\n| `validateReleaseActivationReceiptSet` | function: function validateReleaseActivationReceiptSet(receiptSet, { allowShadow = true } = {}) | receiptSet, { allowShadow = true } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateReleaseActivationReceiptSet } from \"@kungfu-tech/buildchain/release-activation-transaction\";` | `packages/core/release-activation-transaction.js:376` |\n| `validateReleaseActivationTransaction` | function: function validateReleaseActivationTransaction(transaction) | transaction | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateReleaseActivationTransaction } from \"@kungfu-tech/buildchain/release-activation-transaction\";` | `packages/core/release-activation-transaction.js:146` |\n\n## `@kungfu-tech/buildchain/release-tail-provider-plane`\n\nTarget: `./packages/core/release-tail-provider-plane.js`. Public symbols: 20.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `compileReleaseTailDeclaration` | function: function compileReleaseTailDeclaration(input) | input | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { compileReleaseTailDeclaration } from \"@kungfu-tech/buildchain/release-tail-provider-plane\";` | `packages/core/release-tail-provider-plane.js:584` |\n| `createReleaseTailAdapterSet` | function: function createReleaseTailAdapterSet(declaration, adapters) | declaration, adapters | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createReleaseTailAdapterSet } from \"@kungfu-tech/buildchain/release-tail-provider-plane\";` | `packages/core/release-tail-provider-plane.js:1217` |\n| `createReleaseTailTransaction` | function: function createReleaseTailTransaction(input) | input | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createReleaseTailTransaction } from \"@kungfu-tech/buildchain/release-tail-provider-plane\";` | `packages/core/release-tail-provider-plane.js:697` |\n| `executeReleaseTailTransaction` | function: async function executeReleaseTailTransaction(transaction, { adapters, checkpoint: checkpointCallback } = {}) | transaction, { adapters, checkpoint: checkpointCallback } = {} | Promise<unknown> | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { executeReleaseTailTransaction } from \"@kungfu-tech/buildchain/release-tail-provider-plane\";` | `packages/core/release-tail-provider-plane.js:1016` |\n| `parseReleaseTailDeclaration` | function: function parseReleaseTailDeclaration(input) | input | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { parseReleaseTailDeclaration } from \"@kungfu-tech/buildchain/release-tail-provider-plane\";` | `packages/core/release-tail-provider-plane.js:491` |\n| `readReleaseTailTransaction` | function: function readReleaseTailTransaction(filePath) | filePath | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { readReleaseTailTransaction } from \"@kungfu-tech/buildchain/release-tail-provider-plane\";` | `packages/core/release-tail-provider-plane.js:830` |\n| `RELEASE_TAIL_CAPABILITY_REGISTRY` | constant: const RELEASE_TAIL_CAPABILITY_REGISTRY | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_CAPABILITY_REGISTRY } from \"@kungfu-tech/buildchain/release-tail-provider-plane\";` | `packages/core/release-tail-provider-plane.js:31` |\n| `RELEASE_TAIL_DECLARATION_CONTRACT` | constant: const RELEASE_TAIL_DECLARATION_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_DECLARATION_CONTRACT } from \"@kungfu-tech/buildchain/release-tail-provider-plane\";` | `packages/core/release-tail-provider-plane.js:5` |\n| `RELEASE_TAIL_EFFECT_SCHEMA` | constant: const RELEASE_TAIL_EFFECT_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_EFFECT_SCHEMA } from \"@kungfu-tech/buildchain/release-tail-provider-plane\";` | `packages/core/release-tail-provider-plane.js:10` |\n| `RELEASE_TAIL_OBSERVATION_SCHEMA` | constant: const RELEASE_TAIL_OBSERVATION_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_OBSERVATION_SCHEMA } from \"@kungfu-tech/buildchain/release-tail-provider-plane\";` | `packages/core/release-tail-provider-plane.js:12` |\n| `RELEASE_TAIL_RECEIPT_SCHEMA` | constant: const RELEASE_TAIL_RECEIPT_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_RECEIPT_SCHEMA } from \"@kungfu-tech/buildchain/release-tail-provider-plane\";` | `packages/core/release-tail-provider-plane.js:14` |\n| `RELEASE_TAIL_STATES` | constant: const RELEASE_TAIL_STATES | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_STATES } from \"@kungfu-tech/buildchain/release-tail-provider-plane\";` | `packages/core/release-tail-provider-plane.js:17` |\n| `RELEASE_TAIL_TRANSACTION_POLICY` | constant: const RELEASE_TAIL_TRANSACTION_POLICY | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_TRANSACTION_POLICY } from \"@kungfu-tech/buildchain/release-tail-provider-plane\";` | `packages/core/release-tail-provider-plane.js:7` |\n| `RELEASE_TAIL_TRANSACTION_SCHEMA` | constant: const RELEASE_TAIL_TRANSACTION_SCHEMA | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_TRANSACTION_SCHEMA } from \"@kungfu-tech/buildchain/release-tail-provider-plane\";` | `packages/core/release-tail-provider-plane.js:8` |\n| `releaseTailRetryPolicyFromDeclaration` | function: function releaseTailRetryPolicyFromDeclaration(input) | input | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { releaseTailRetryPolicyFromDeclaration } from \"@kungfu-tech/buildchain/release-tail-provider-plane\";` | `packages/core/release-tail-provider-plane.js:1207` |\n| `releaseTailRoot` | function: function releaseTailRoot(value) | value | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { releaseTailRoot } from \"@kungfu-tech/buildchain/release-tail-provider-plane\";` | `packages/core/release-tail-provider-plane.js:164` |\n| `releaseTailStableJson` | function: function releaseTailStableJson(value) | value | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { releaseTailStableJson } from \"@kungfu-tech/buildchain/release-tail-provider-plane\";` | `packages/core/release-tail-provider-plane.js:149` |\n| `validateReleaseTailEffectPlan` | function: function validateReleaseTailEffectPlan(plan) | plan | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateReleaseTailEffectPlan } from \"@kungfu-tech/buildchain/release-tail-provider-plane\";` | `packages/core/release-tail-provider-plane.js:602` |\n| `validateReleaseTailTransaction` | function: function validateReleaseTailTransaction(transaction) | transaction | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { validateReleaseTailTransaction } from \"@kungfu-tech/buildchain/release-tail-provider-plane\";` | `packages/core/release-tail-provider-plane.js:744` |\n| `writeReleaseTailTransaction` | function: function writeReleaseTailTransaction(filePath, transaction) | filePath, transaction | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | local-filesystem-write | `import { writeReleaseTailTransaction } from \"@kungfu-tech/buildchain/release-tail-provider-plane\";` | `packages/core/release-tail-provider-plane.js:841` |\n\n## `@kungfu-tech/buildchain/release-tail-provider-adapters`\n\nTarget: `./packages/core/release-tail-provider-adapters.js`. Public symbols: 7.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `createActivationReceiptProjectorAdapter` | function: function createActivationReceiptProjectorAdapter(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createActivationReceiptProjectorAdapter } from \"@kungfu-tech/buildchain/release-tail-provider-adapters\";` | `packages/core/release-tail-provider-adapters.js:181` |\n| `createGitHubReleaseAssetsAdapter` | function: function createGitHubReleaseAssetsAdapter({ octokit, resolveArtifact, } = {}) | { octokit, resolveArtifact, } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createGitHubReleaseAssetsAdapter } from \"@kungfu-tech/buildchain/release-tail-provider-adapters\";` | `packages/core/release-tail-provider-adapters.js:310` |\n| `createHttpJsonReadback` | function: function createHttpJsonReadback({ fetchImpl = globalThis.fetch } = {}) | { fetchImpl = globalThis.fetch } = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { createHttpJsonReadback } from \"@kungfu-tech/buildchain/release-tail-provider-adapters\";` | `packages/core/release-tail-provider-adapters.js:191` |\n| `createSignedStaticChannelAdapter` | function: function createSignedStaticChannelAdapter(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createSignedStaticChannelAdapter } from \"@kungfu-tech/buildchain/release-tail-provider-adapters\";` | `packages/core/release-tail-provider-adapters.js:161` |\n| `createSiteReleaseActivationAdapter` | function: function createSiteReleaseActivationAdapter(options = {}) | options = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createSiteReleaseActivationAdapter } from \"@kungfu-tech/buildchain/release-tail-provider-adapters\";` | `packages/core/release-tail-provider-adapters.js:171` |\n| `githubReleaseAssetsTargetRoot` | function: function githubReleaseAssetsTargetRoot({ destination, artifacts }) | { destination, artifacts } | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { githubReleaseAssetsTargetRoot } from \"@kungfu-tech/buildchain/release-tail-provider-adapters\";` | `packages/core/release-tail-provider-adapters.js:297` |\n| `ReleaseTailProviderError` | class: class ReleaseTailProviderError | none | ReleaseTailProviderError | Construction and method errors follow the linked source implementation. | class-dependent | `import { ReleaseTailProviderError } from \"@kungfu-tech/buildchain/release-tail-provider-adapters\";` | `packages/core/release-tail-provider-adapters.js:9` |\n\n## `@kungfu-tech/buildchain/release-tail-compatibility`\n\nTarget: `./packages/core/release-tail-compatibility.js`. Public symbols: 3.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `diagnoseLegacyReleaseTailHooks` | function: function diagnoseLegacyReleaseTailHooks(hooks = {}) | hooks = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | none-detected-by-static-source-scan | `import { diagnoseLegacyReleaseTailHooks } from \"@kungfu-tech/buildchain/release-tail-compatibility\";` | `packages/core/release-tail-compatibility.js:23` |\n| `RELEASE_TAIL_COMPATIBILITY_CONTRACT` | constant: const RELEASE_TAIL_COMPATIBILITY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_COMPATIBILITY_CONTRACT } from \"@kungfu-tech/buildchain/release-tail-compatibility\";` | `packages/core/release-tail-compatibility.js:1` |\n| `RELEASE_TAIL_LEGACY_HOOKS` | constant: const RELEASE_TAIL_LEGACY_HOOKS | none | value | Import does not declare a throw contract. | none-on-import | `import { RELEASE_TAIL_LEGACY_HOOKS } from \"@kungfu-tech/buildchain/release-tail-compatibility\";` | `packages/core/release-tail-compatibility.js:4` |\n\n## `@kungfu-tech/buildchain/surface-manifest`\n\nTarget: `./packages/core/surface-manifest.js`. Public symbols: 3.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `applySurfaceTimestampPolicy` | function: function applySurfaceTimestampPolicy(manifest, options = {}) | manifest, options = {} | unknown | May throw an Error on rejected input or failed operations; follow the linked source contract. | may-write-or-invoke-external-actions | `import { applySurfaceTimestampPolicy } from \"@kungfu-tech/buildchain/surface-manifest\";` | `packages/core/surface-manifest.js:79` |\n| `createSurfaceTimestampPolicy` | function: function createSurfaceTimestampPolicy({ generatedAt = \"\", publishedAt = \"\", sourceDateEpoch = process.env.SOURCE_DATE_EPOCH \\|\\| DEFAULT_SOURCE_DATE_EPOCH, sourceRevision = \"\", deterministicInputs = [], timestampPolicy = \"\", timestampFields = [\"generatedAt\", \"publishedAt\"], timestampFieldsParticipateInArtifactDigest = true, artifactDigestScope = \"manifest-and-artifact\", reproducible = true, } = {}) | { generatedAt = \"\", publishedAt = \"\", sourceDateEpoch = process.env.SOURCE_DATE_EPOCH \\|\\| DEFAULT_SOURCE_DATE_EPOCH, sourceRevision = \"\", deterministicInputs = [], timestampPolicy = \"\", timestampFields = [\"generatedAt\", \"publishedAt\"], timestampFieldsParticipateInArtifactDigest = true, artifactDigestScope = \"manifest-and-artifact\", reproducible = true, } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createSurfaceTimestampPolicy } from \"@kungfu-tech/buildchain/surface-manifest\";` | `packages/core/surface-manifest.js:34` |\n| `SURFACE_TIMESTAMP_POLICY_CONTRACT` | constant: const SURFACE_TIMESTAMP_POLICY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { SURFACE_TIMESTAMP_POLICY_CONTRACT } from \"@kungfu-tech/buildchain/surface-manifest\";` | `packages/core/surface-manifest.js:1` |\n\n## `@kungfu-tech/buildchain/buildchain-kfd-claims`\n\nTarget: `./packages/core/buildchain-kfd-claims.js`. Public symbols: 10.\n\n| Symbol | Kind and signature | Parameters | Return | Errors | Side effects | Example | Source |\n| --- | --- | --- | --- | --- | --- | --- | --- |\n| `BUILDCHAIN_AGENT_MANUALS` | constant: const BUILDCHAIN_AGENT_MANUALS | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_AGENT_MANUALS } from \"@kungfu-tech/buildchain/buildchain-kfd-claims\";` | `packages/core/buildchain-agent-manuals.js:1` |\n| `BUILDCHAIN_KFD_CLAIM_REGISTRY_CONTRACT` | constant: const BUILDCHAIN_KFD_CLAIM_REGISTRY_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD_CLAIM_REGISTRY_CONTRACT } from \"@kungfu-tech/buildchain/buildchain-kfd-claims\";` | `packages/core/buildchain-kfd-claims.js:14` |\n| `BUILDCHAIN_KFD_COLLABORATION_INTERFACE_CONTRACT` | constant: const BUILDCHAIN_KFD_COLLABORATION_INTERFACE_CONTRACT | none | value | Import does not declare a throw contract. | none-on-import | `import { BUILDCHAIN_KFD_COLLABORATION_INTERFACE_CONTRACT } from \"@kungfu-tech/buildchain/buildchain-kfd-claims\";` | `packages/core/buildchain-kfd-claims.js:15` |\n| `createBuildchainKfd1Witness` | function: function createBuildchainKfd1Witness({ root = process.cwd(), sourceSha = \"\" } = {}) | { root = process.cwd(), sourceSha = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainKfd1Witness } from \"@kungfu-tech/buildchain/buildchain-kfd-claims\";` | `packages/core/buildchain-kfd-claims.js:530` |\n| `createBuildchainKfd2Claims` | function: function createBuildchainKfd2Claims({ root = process.cwd(), witnessFiles = {} } = {}) | { root = process.cwd(), witnessFiles = {} } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainKfd2Claims } from \"@kungfu-tech/buildchain/buildchain-kfd-claims\";` | `packages/core/buildchain-kfd-claims.js:687` |\n| `createBuildchainKfd3ArtifactWitness` | function: function createBuildchainKfd3ArtifactWitness({ root = process.cwd(), sourceSha = \"\" } = {}) | { root = process.cwd(), sourceSha = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainKfd3ArtifactWitness } from \"@kungfu-tech/buildchain/buildchain-kfd-claims\";` | `packages/core/buildchain-kfd-claims.js:647` |\n| `createBuildchainKfd3PrebuildWitness` | function: function createBuildchainKfd3PrebuildWitness({ root = process.cwd(), sourceSha = \"\" } = {}) | { root = process.cwd(), sourceSha = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainKfd3PrebuildWitness } from \"@kungfu-tech/buildchain/buildchain-kfd-claims\";` | `packages/core/buildchain-kfd-claims.js:583` |\n| `createBuildchainKfdClaimRegistry` | function: function createBuildchainKfdClaimRegistry({ root = process.cwd(), sourceSha = \"\" } = {}) | { root = process.cwd(), sourceSha = \"\" } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainKfdClaimRegistry } from \"@kungfu-tech/buildchain/buildchain-kfd-claims\";` | `packages/core/buildchain-kfd-claims.js:510` |\n| `createBuildchainKfdSurfaceRegistry` | function: function createBuildchainKfdSurfaceRegistry({ root = process.cwd() } = {}) | { root = process.cwd() } = {} | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainKfdSurfaceRegistry } from \"@kungfu-tech/buildchain/buildchain-kfd-claims\";` | `packages/core/buildchain-kfd-claims.js:411` |\n| `createBuildchainPublicClaimDefinitions` | function: function createBuildchainPublicClaimDefinitions() | none | unknown | Errors from called operations may propagate; no narrower throw contract is declared in source. | none-detected-by-static-source-scan | `import { createBuildchainPublicClaimDefinitions } from \"@kungfu-tech/buildchain/buildchain-kfd-claims\";` | `packages/core/buildchain-kfd-claims.js:226` |"
    },
    {
      "id": "manual:observed-evidence-patrol",
      "title": "Observed Evidence Patrol",
      "route": "/docs/observed-evidence-patrol",
      "category": "manual",
      "capabilityGroup": "governance-versioning",
      "audience": [
        "release-operator",
        "consumer",
        "agent"
      ],
      "maturity": "preview",
      "sourcePath": "docs/observed-evidence-patrol.md",
      "digest": "sha256:9e806efee048dd4fbaa68349ed4200c61d6408b0470ff81a4616a454cc32248c",
      "headings": [
        {
          "level": 1,
          "title": "Observed Evidence Patrol",
          "anchor": "observed-evidence-patrol"
        },
        {
          "level": 2,
          "title": "Trust boundary",
          "anchor": "trust-boundary"
        },
        {
          "level": 2,
          "title": "Ordinary site releases",
          "anchor": "ordinary-site-releases"
        },
        {
          "level": 2,
          "title": "Rollback and recovery",
          "anchor": "rollback-and-recovery"
        }
      ],
      "markdown": "---\nstatus: draft\nperiod: ongoing\ntheme: observed-evidence-patrol\ndoc_type: contract\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-07-30\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-30\n  invisible_context_boundary: No credentials, private logs, or unpublished evidence values are included.\n---\n\n# Observed Evidence Patrol\n\nObserved Evidence Patrol publishes a reproducible public observation without\ncreating a content PR for every refresh. It is for derived evidence whose\nmeaning is fully checked by the caller and whose publication safety can be\ndecided mechanically.\n\nThe caller generates a `kungfu-buildchain-observed-evidence-bundle`. The bundle\nbinds one `snapshot.id` to two byte-identical JSON files:\n\n- a versioned immutable object such as\n  `dogfood-evidence/snapshots/<snapshotId>.json`;\n- a mutable last-known-good alias such as `dogfood-evidence.json`.\n\nThe bundle may also declare up to 16 derived mutable projections under\n`publication.projections`. Each projection declares its artifact-relative\n`source`, bounded destination `key`, exact `sha256`, `contentType`, and\n`cacheControl`. This supports static HTML such as `dogfood/index.html` without\nchanging the existing immutable/latest JSON contract.\n\nBuildchain verifies both file digests and snapshot identities before receiving\nproduction authority. Apply then performs this order:\n\n1. conditionally create the immutable key with `If-None-Match: *`;\n2. read the immutable key back and verify its declared SHA-256 metadata;\n3. record preceding version metadata for every declared mutable key;\n4. write and read back each derived projection in manifest order;\n5. atomically replace the latest object;\n6. read latest back and verify the same snapshot and digest;\n7. invalidate only the declared viewer paths.\n\nProjection-enabled publication requires bucket versioning before replacing an\nexisting mutable key. If a later projection, latest update, or invalidation\nfails, Buildchain restores preceding object versions in reverse order and\nremoves newly introduced declared projection keys. Rollback never lists the\nbucket and never touches keys outside the manifest.\n\nAny generator, schema, digest, immutable-key, provider, or read-after-write\nfailure leaves the previous latest object in place. A colliding immutable key\nis reusable only when both snapshot identity and SHA-256 match; otherwise the\nrun fails without overwriting it.\n\n## Trust boundary\n\nThe reusable workflow admits only `schedule` or `workflow_dispatch` events on\nthe caller repository's default branch. It checks out that branch explicitly,\ndoes not persist Git credentials, and never runs pull-request or fork code. The\nconsumer owns its evidence semantics through the build and verify commands;\nBuildchain owns publication ordering and provider safety.\n\nProduction OIDC authority should be a dedicated role and Environment with no\nreview gate for steady-state refreshes. Its policy should allow only:\n\n- `s3:GetObject` and `s3:PutObject` on the exact latest key;\n- the same actions on the exact immutable snapshot prefix;\n- for projection-enabled bundles, `s3:GetObjectVersion` and bounded\n  `s3:DeleteObject` on the exact declared mutable keys;\n- `cloudfront:CreateInvalidation` on the one distribution.\n\nIt must not receive bucket-wide delete, list, repository write, GitHub PR, or\ngeneral deployment authority. One-time workflow, IAM, schema, and page changes\nstill use normal review and release governance.\n\n## Ordinary site releases\n\nA site artifact that contains\n`.buildchain/observed-evidence-ownership.json` declares the paths owned by the\nPatrol channel. Web-surface deploy adds those paths to the S3 sync exclusion\nset, so a later full-site release cannot delete the snapshot archive or replace\nlatest with an older build fixture. The HTML page should project the latest\nJSON at runtime, retaining its committed copy only as an explicitly labelled\nfallback.\n\n## Rollback and recovery\n\nEvery receipt records the previous latest and projection snapshot ids, digests,\nETags, and S3 version ids when available. A projection transaction rolls back\nautomatically when a later mutable step or CDN invalidation fails. Operators\ncan also regenerate a bundle whose latest file is the selected immutable\nsnapshot and republish it through the same validator; immutable history is\nnever overwritten or deleted. Legacy bundles without projections retain their\nexisting idempotent rerun behavior when CDN invalidation alone fails."
    },
    {
      "id": "manual:ownership",
      "title": "Ownership And Migration Rules",
      "route": "/docs/ownership",
      "category": "manual",
      "capabilityGroup": "governance-versioning",
      "audience": [
        "maintainer"
      ],
      "maturity": "stable",
      "sourcePath": "docs/ownership.md",
      "digest": "sha256:91a1b59f0f71067c58ffd685a23b29e14a4d6fe33c1a44f8708b7d0512e4baa5",
      "headings": [
        {
          "level": 1,
          "title": "Ownership And Migration Rules",
          "anchor": "ownership-and-migration-rules"
        },
        {
          "level": 2,
          "title": "Source Of Truth",
          "anchor": "source-of-truth"
        },
        {
          "level": 2,
          "title": "Compatibility Rule",
          "anchor": "compatibility-rule"
        },
        {
          "level": 2,
          "title": "Publishing Rule",
          "anchor": "publishing-rule"
        },
        {
          "level": 2,
          "title": "Candidate Ref Rule",
          "anchor": "candidate-ref-rule"
        },
        {
          "level": 2,
          "title": "Source-Locked Publish Rule",
          "anchor": "source-locked-publish-rule"
        }
      ],
      "markdown": "---\nstatus: active\nperiod: ongoing\ntheme: buildchain-ownership-and-migration\ndoc_type: technical-reference\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-07-31\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-31\n  invisible_context: not asserted\n---\n\n# Ownership And Migration Rules\n\n## Source Of Truth\n\nBuildchain v3 workflow and action design lands in this repository. Standalone\n`workflows` and `action-*` repositories are historical rollback anchors.\nBuildchain only ships the native action surface required for config validation,\nlifecycle execution, and release ref promotion.\n\n## Compatibility Rule\n\nDo not break existing stable reusable workflow refs during migration:\n\n- `kungfu-systems/workflows@v2`\n\nAny consumer migration must record:\n\n- old `uses:` refs;\n- new `uses:` refs;\n- workflow run ids;\n- rollback command or revert path.\n\nNew stable references should use:\n\n- `kungfu-systems/buildchain/actions/validate-config@v3`\n- `kungfu-systems/buildchain/actions/run-lifecycle@v3`\n- `kungfu-systems/buildchain/actions/promote-buildchain-ref@v3`\n- `kungfu-systems/buildchain/.github/workflows/<workflow>.yml@v3`\n\n## Publishing Rule\n\nPublishing paths stay disabled in buildchain's own verification workflows unless\nexplicitly enabled by a production release workflow. Any consumer cutover that\npublishes packages, S3 artifacts, release pages, or preview links must include\nrollback notes. Reusable workflow consumers should gate publish jobs with\n`needs.<build-job>.outputs.publish-allowed == 'true'` and record the requested\n`publish-channel`, rather than duplicating channel branch logic in every\nconsumer workflow.\n\n## Candidate Ref Rule\n\nCandidate refs are expected to resolve under `kungfu-systems/*`. Broader\nsources require an explicit trust decision before they can reach self-hosted\nrunners or secrets.\n\n## Source-Locked Publish Rule\n\nWhen a consumer uses `publish-gate/*` branches, publish jobs must use the\nresolved `publish-source-sha` and `release-manifest-json` emitted by the reusable\nbuild workflow. Before touching a package registry, S3 bucket, release page, or\nfloating alias, the publish job must verify that the gate branch still points at\nthe recorded SHA. A moved gate branch is a stale release decision, not a retry."
    },
    {
      "id": "manual:product-mechanism",
      "title": "Product Mechanism",
      "route": "/docs/product-mechanism",
      "category": "manual",
      "capabilityGroup": "getting-started",
      "audience": [
        "agent",
        "maintainer"
      ],
      "maturity": "stable",
      "sourcePath": "docs/product-mechanism.md",
      "digest": "sha256:da50022f96f8876bb275a7832190cb1f6ab0fa6aab9d045dda924a7abddc3edf",
      "headings": [
        {
          "level": 1,
          "title": "Product Mechanism",
          "anchor": "product-mechanism"
        },
        {
          "level": 2,
          "title": "Design Pressure",
          "anchor": "design-pressure"
        },
        {
          "level": 2,
          "title": "What the Passport Solves",
          "anchor": "what-the-passport-solves"
        },
        {
          "level": 2,
          "title": "Why Binary Distribution Matters",
          "anchor": "why-binary-distribution-matters"
        },
        {
          "level": 2,
          "title": "Naming",
          "anchor": "naming"
        }
      ],
      "markdown": "# Product Mechanism\n\nBuildchain's product boundary is the Release Passport: a mature product release\nrecord for artifacts that users or agents depend on.\n\n## Design Pressure\n\nMany repositories can already compile, test, and upload artifacts. The hard\nproblem is proving what a release means after it has been promoted:\n\n- which reviewed source state was released;\n- which exact version-state commit and tag represent that release;\n- which artifacts were created;\n- which checks and publish steps were allowed to run;\n- which floating channel refs now point at that release;\n- how another human or agent can verify, explain, mirror, or roll back the\n  release without asking the maintainer to reconstruct the story.\n\nBuildchain uses GitHub as the substrate for this proof. It does not require a\nproject to abandon its existing build system.\n\n## What the Passport Solves\n\nThe passport turns a release into a durable record:\n\n- exact tags are immutable release identities;\n- floating refs are explicitly machine-updated channel pointers;\n- version files are changed by version-state commits, not by unpublished local\n  edits;\n- build and publish evidence is machine-readable;\n- release checks fail closed when evidence is incomplete;\n- site and documentation facts can be generated from the package instead of\n  being copied by hand.\n\n## Why Binary Distribution Matters\n\nBinary artifacts are a strong proof case because users and agents may execute\nthem directly. That makes checksums, runner facts, package evidence, and\nrollback instructions more urgent.\n\nThe protocol is not binary-bound. The same release passport model applies to\nnpm packages, Python wheels, OCI images, native SDK archives, web-surface\ndeployments, and multi-artifact product releases.\n\n## Naming\n\nUse these names consistently:\n\n- Product name: `Buildchain`\n- Formal first mention: `Buildchain by Kungfu`\n- Category anchor: `Buildchain Release Passport`\n- Core release record: `buildchain.release.json`\n\nAvoid defining Buildchain as only a workflow collection, a binary distributor,\nor a replacement CI/CD platform."
    },
    {
      "id": "manual:publication-artifacts",
      "title": "Publication Artifact Workflow",
      "route": "/docs/publication-artifacts",
      "category": "manual",
      "capabilityGroup": "reusable-build",
      "audience": [
        "consumer",
        "site",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "docs/publication-artifacts.md",
      "digest": "sha256:bbe9aab15731a9145cacad8a9795c24a86a56fcdbf8cbf8ad3e9b5d4b6e57dba",
      "headings": [
        {
          "level": 1,
          "title": "Publication Artifact Workflow",
          "anchor": "publication-artifact-workflow"
        },
        {
          "level": 2,
          "title": "Configuration",
          "anchor": "configuration"
        },
        {
          "level": 2,
          "title": "Reproducibility Gate",
          "anchor": "reproducibility-gate"
        },
        {
          "level": 2,
          "title": "Reusable Workflow",
          "anchor": "reusable-workflow"
        },
        {
          "level": 2,
          "title": "Paper Release Preset",
          "anchor": "paper-release-preset"
        },
        {
          "level": 2,
          "title": "CLI And Node API",
          "anchor": "cli-and-node-api"
        },
        {
          "level": 3,
          "title": "Unified paper operator surface",
          "anchor": "unified-paper-operator-surface"
        },
        {
          "level": 1,
          "title": "edit, test, and commit paper source",
          "anchor": "edit-test-and-commit-paper-source"
        },
        {
          "level": 2,
          "title": "Site Consumption",
          "anchor": "site-consumption"
        }
      ],
      "markdown": "# Publication Artifact Workflow\n\nBuildchain supports `project.type = \"publication-artifact\"` for repositories\nthat produce auditable papers, reports, specifications, or similar publication\npackages. These repositories are artifact producers. They should not be forced\nto become `web-surface` repositories just because a downstream site later\nrenders the paper.\n\nThe split is:\n\n```text\npaper repo = source, PDF, metadata, source bundle, publication manifest\npapers site = layout, navigation, public web surface, downstream rendering\n```\n\n## Configuration\n\nThe paper repository owns `.buildchain/buildchain.toml`:\n\n```toml\nschema = 1\n\n[project]\ntype = \"publication-artifact\"\nname = \"paper-observer-declared-timelines\"\n\n[publication]\nkind = \"paper\"\ntitle = \"Observer-Declared Timelines for Real-World Agent Work\"\nversion = \"0.1.0\"\nprimary_artifact = \"_build/main.pdf\"\nartifact_paths = [\"_build/main.pdf\"]\nmetadata_paths = [\"README.md\", \"docs/MAP.md\"]\nsource_paths = [\"paper\", \"README.md\", \"LICENSE\", \"Makefile\"]\nsite_consumers = [\"papers.libkungfu.dev\"]\nmanifest_path = \".buildchain/publication/publication-artifact.json\"\nsource_bundle_path = \".buildchain/publication/source.tar.gz\"\n\n[publication.archive]\nid = \"observer-declared-timelines\"\ncanonical_url = \"https://papers.libkungfu.dev/observer-declared-timelines/\"\nlatest_url = \"https://papers.libkungfu.dev/observer-declared-timelines/latest/\"\nlatest_evidence_url = \"https://papers.libkungfu.dev/observer-declared-timelines/latest/buildchain.release.json\"\nimmutable_base_url = \"https://papers.libkungfu.dev/archive\"\nregistry_path = \".buildchain/publication/publication-registry.json\"\n\n[publication.toolchain]\ntype = \"latex-docker\"\nimage = \"ghcr.io/kungfu-systems/build-images/latex-pdf-builder\"\ndigest = \"sha256:c20f3809e96836c1c78e97c76939d12f1de3fed0ea9b7c40c43332ec2ea480f8\"\ncommand = \"latexmk -pdf -outdir=_build paper/main.tex\"\n\n[publish]\nkind = \"npm-paper-package\"\npackage = \"@kungfu-tech/paper-observer-declared-timelines\"\nauth = \"trusted-publishing\"\n\n[lifecycle.build]\ncommand = \"make pdf\"\n\n[lifecycle.verify]\ncommand = \"make check\"\n```\n\n`primary_artifact` is the human-facing publication output, usually a PDF.\n`source_paths` are archived into a source bundle. `metadata_paths` are hashed\nand recorded so a site can consume the paper facts without scraping prose.\n\n`publication.archive` turns the publication into an append-only public archive\ncontract:\n\n- `canonical_url` is the stable human reader page.\n- `latest_url` and `latest_evidence_url` are movable aliases for the latest\n  reader page and latest evidence.\n- `immutable_base_url` plus `id` and `publication.version` produce a versioned\n  prefix such as\n  `https://papers.libkungfu.dev/archive/observer-declared-timelines/v0.1.0/`.\n- `immutable_url_prefix` can be used instead when the repository already owns\n  the full version prefix.\n- `registry_path` records every published version and its manifest, passport,\n  source bundle, primary artifact, URLs, and SHA-256 digests.\n\nImmutable archive prefixes are append-only. Do not run site deployment commands\nwith `sync --delete` or equivalent deletion semantics over those prefixes. A\nsame-version republish is allowed only when the immutable digest is unchanged;\nif PDF, source bundle, route, metadata, or toolchain evidence changes for an\nexisting version, Buildchain fails before the registry is rewritten.\n\nThe Buildchain web-surface adapter consumes this boundary from a surface-local\n`manifest.json` whose `archivePolicy.contract` is\n`kungfu-buildchain-publication-archive-policy`. It excludes the derived archive\nroot from every owning or parent `sync --delete`, verifies existing object\ndigests, uploads only missing immutable files with `--no-overwrite`, and verifies\nthem again before mutable site content is synchronized. A current package set\ndoes not need to rebuild or enumerate every historical version: the protected\narchive root remains outside deletion even when older versions disappear from\nthe current artifact.\n\n`publication.toolchain` makes the source-to-PDF transformation part of the\nmachine-readable contract. `latex-docker` is the preferred LaTeX profile. The\nBuildchain paper scaffold and reusable workflow default to\n`ghcr.io/kungfu-systems/build-images/latex-pdf-builder:v1.2.0`, pinned by the\ndigest above. The workflow pulls the declared image by digest and runs the\ndeclared command in that pinned container. `custom-command` remains available\nfor compatibility, but the passport records it as lower trust because\nBuildchain can record the command boundary without proving the compiler or\nLaTeX distribution digest.\n\n## Reproducibility Gate\n\nAlpha and release admission require\n`.buildchain/publication/reproducibility-receipt.json`. Buildchain creates the\nreceipt by cloning the exact checked-out Git commit into two independent local\nrepositories, assigning each build a separate home and npm cache, and deriving\n`SOURCE_DATE_EPOCH` from the source commit. A pinned `latex-docker` build runs\nwith UTC, `C.UTF-8`, no build-time network, and the exact image digest declared\nin `[publication.toolchain]`.\n\nEach clean build independently creates the PDF set, source bundle, publication\nmanifest and passport, append-only registry, synthesized npm package directory,\nand an actual npm tarball. After qualification, Buildchain copies the first\nqualifying tarball into the promoted publication candidate instead of deleting\nit with the temporary clean build. The receipt compares exact bytes and records:\n\n- source repository, commit, tree, and `SOURCE_DATE_EPOCH`;\n- toolchain image, digest, command, and toolchain identity root;\n- every artifact and evidence path with byte size and SHA-256;\n- npm tarball SHA-256, SHA-1 shasum, and `sha512` integrity;\n- per-build output-set roots and the first differing field or artifact.\n\nThe gate is fail-closed. A build-only `custom-command` run can diagnose byte\ndrift and promote its byte-identical local output with\n`--allow-unpinned-toolchain`, but it is never a qualifying publication receipt.\nAny workflow that prepares a publishable paper package accepts only a\ndigest-pinned toolchain and promotes the first clean build into the publication\ncandidate only after both builds are byte-identical. The receipt remains\noutside the npm tarball to avoid a circular digest; it binds the tarball bytes\nfrom the surrounding sealed publication evidence.\n\n`publish.kind = \"npm-paper-package\"` declares that Buildchain, not the consumer\nrepository, owns the standard paper npm package shape and release transaction\nmechanics. `publish.package` is the public npm package that contains the PDF,\npublication manifest, publication passport, optional archive registry, source\nbundle, and declared metadata files.\n\n## Reusable Workflow\n\nConsumer repositories that only need to build and upload paper evidence can\ncall the build-only wrapper directly:\n\n```yaml\njobs:\n  publication:\n    uses: kungfu-systems/buildchain/.github/workflows/publication-artifact.yml@v3\n    with:\n      toolchain-type: config\n      verify-command: make check\n      artifact-name: observer-declared-timelines\n      buildchain-contract-lock-path: .buildchain/contract-lock.json\n```\n\nThe build-only workflow:\n\n- resolves the Buildchain runtime and checks the floating contract lock before\n  any paper build runs;\n- resolves the declared publication toolchain from `[publication.toolchain]` or\n  workflow inputs;\n- hydrates authenticated registry history before building so both clean\n  candidates include the same append-only history;\n- for `latex-docker`, pulls the pinned build-images LaTeX builder digest and\n  runs two independent clean builds with the reproducibility policy above;\n- for `custom-command`, runs the declared command and records the lower-trust\n  boundary in the passport, but refuses publication qualification;\n- runs the verify command;\n- creates a source bundle from `publication.source_paths`;\n- writes `.buildchain/publication/publication-artifact.json`;\n- writes `.buildchain/publication/publication-artifact-passport.json`;\n- writes a qualifying\n  `.buildchain/publication/reproducibility-receipt.json`;\n- when `[publication.archive]` is configured, writes\n  `.buildchain/publication/publication-registry.json` and verifies same-version\n  immutability;\n- uploads one GitHub artifact containing the PDF, manifest, passport, optional\n  registry, and source bundle.\n\nIt does not publish npm packages, deploy web pages, or create GitHub Releases.\n\nThe paper release preset additionally hydrates every prior published package\nregistry from the npm registry before generating the current manifest. npm\npackage integrity authenticates each downloaded source; Buildchain verifies the\nregistry self-digest, merges immutable records, and fails if a cumulative\nregistry drops an accepted version or changes immutable route/artifact facts.\nThe synthesized package therefore carries complete history even on a clean\nrunner. Its cumulative registry and file SHA-256 values are bound into the paper\nrelease build summary and release passport evidence.\n\n## Paper Release Preset\n\nPaper repositories that publish a versioned npm package should use the\nBuildchain-managed release preset instead of copying npm transaction scripts or\npromotion YAML:\n\n```yaml\nname: Paper Release\n\non:\n  push:\n    branches:\n      - alpha/v1/v1.0\n      - release/v1/v1.0\n  workflow_dispatch:\n\njobs:\n  paper-release:\n    uses: kungfu-systems/buildchain/.github/workflows/paper-release-sealed.yml@<exact-buildchain-sha>\n    permissions:\n      actions: read\n      checks: write\n      contents: read\n      id-token: write\n      issues: write\n    with:\n      buildchain-ref: <exact-buildchain-sha>\n      publisher-workflow-path: .github/workflows/paper-release.yml\n      toolchain-type: config\n      verify-command: make check\n      artifact-paths: _build/paper-name.pdf\n      buildchain-contract-lock-path: .buildchain/contract-lock.json\n    secrets:\n      BUILDCHAIN_GENERATED_WRITE_APP_CLIENT_ID: ${{ secrets.BUILDCHAIN_GENERATED_WRITE_APP_CLIENT_ID }}\n      BUILDCHAIN_GENERATED_WRITE_APP_PRIVATE_KEY: ${{ secrets.BUILDCHAIN_GENERATED_WRITE_APP_PRIVATE_KEY }}\n      BUILDCHAIN_GENERATED_WRITE_TOKEN: ${{ secrets.BUILDCHAIN_GENERATED_WRITE_TOKEN }}\n```\n\nThe sealed preset does not use a long-lived token for npm publication. It\nprefers a repository-scoped GitHub App installation token for generated\nrepository writes and accepts `BUILDCHAIN_GENERATED_WRITE_TOKEN` as an\nequivalent narrow compatibility authority. The deprecated\n`BUILDCHAIN_PROMOTION_TOKEN` name remains accepted for existing consumers, but\nthere is no `github.token` fallback for generated writes. npm publication\nremains bound to GitHub OIDC trusted publishing. The preset builds and packages the\npaper in a read-only job, then a credential-free authority job downloads that\nexact candidate, audits the external control plane, and seals a capability over\nthe source tree, Buildchain runtime, controller receipt, PDF, and npm package\nbytes. Only the final job receives write and OIDC permissions; it downloads the\nadmitted candidate, recomputes the capability binding, and publishes without\nexecuting consumer build commands. npm binds the OIDC identity to the consumer\nworkflow named by `publisher-workflow-path`.\n\nThe preset:\n\n- uses the exact Buildchain SHA admitted by the provisioning authority and\n  binds it into the caller bytes, contract lock, publication candidate, and\n  authority capability;\n- builds the PDF through the declared pinned LaTeX Docker toolchain or custom\n  command in a read-only job;\n- verifies the paper repository;\n- writes the publication manifest, publication passport, optional archive\n  registry, and source bundle;\n- synthesizes an npm package from `[publication]` and `[publish]` declarations\n  under `.buildchain/publication/npm-package`;\n- computes npm-style `sha512` integrity from `npm pack --dry-run` and passes\n  it as `publish-required-artifacts-json`;\n- creates a `publish-gate/<alpha|release>/.../<version>` source lock for the\n  channel commit and requires `promote-buildchain-ref` to verify that lock\n  before any publish side effect;\n- verifies the complete candidate again after authority and publishes the\n  package through npm Trusted Publishing without rebuilding or repacking it;\n- writes a typed sealed-bundle manifest that binds the candidate root, exact\n  npm tarball, every GitHub Release asset, durable storage path, and resume\n  command;\n- persists the complete binary bundle to the transaction's durable release-state\n  ref before npm receives credentials, allowing an empty runner to restore and\n  verify the same bytes after interruption;\n- writes Buildchain release/passport evidence; and\n- creates or updates the exact-version GitHub Release by default, uploading\n  every file declared by `publication.primary_artifact` and\n  `publication.artifact_paths` alongside the release evidence.\n\nConsumers can opt out of the GitHub Release with `github-release: false`, but\nthe default is on so downstream release propagation can observe\n`release.published` without hand-written `gh release` steps.\n\nThe transaction exposes a stable publication progression:\n\n```text\nprepared -> sealed -> package-published -> alpha-complete\n```\n\nStable publication ends at `release-complete`. If a run stops after npm but\nbefore GitHub Release completion, the next run starts from\n`package-published`, restores the sealed PDF and companion assets, and finishes\nthe release without invoking the paper build or `npm pack` again.\n\nDeclared publication artifacts are resolved from the generated publication\nmanifest rather than repeated in consumer workflow YAML. Publication fails\nbefore upload if a declared artifact is missing or if its basename would\ncollide with another GitHub Release asset.\n\nFor npm Trusted Publishing, register the consumer workflow file that calls this\npreset, for example `.github/workflows/paper-release.yml`, against the declared\npackage in npm. The trusted publisher is the consumer repository and workflow\nfile; the implementation still runs inside Buildchain's reusable workflow.\n\nStandard paper repositories should not carry local copies of\n`scripts/npm-publish-transaction.mjs`, package-generation scripts, or\npromotion/ref-lock YAML. If the default package shape is insufficient, extend\nBuildchain rather than forking the mechanics into each paper repository.\n\n## CLI And Node API\n\n### Unified paper operator surface\n\nThe `buildchain paper` command family assembles the existing publication\nprimitives into a resumable operator flow:\n\n```text\nscaffold/new or migrate/existing -> preflight -> bootstrap npm -> build -> alpha -> status -> resume\n```\n\nEach command emits a typed JSON envelope with `--json`. Dry-run is the default\nfor every external mutation. `scaffold --write` is limited to no-overwrite\nlocal file creation. `migrate --write` is limited to the Buildchain-owned\ncontract lock, version pin, thin workflows, and provisioning authority; paper\ncontent and publication configuration are preserved. `bootstrap npm --execute`, `alpha --execute`, and\n`resume --execute` cross external authority boundaries and therefore require\nexplicit execution.\n\nThe evidence model is intentionally non-inferential:\n\n| State                | Required evidence                                        |\n| -------------------- | -------------------------------------------------------- |\n| `scaffolded`         | Complete managed scaffold inventory                      |\n| `governed`           | Compatible Buildchain contract lock                      |\n| `admitted`           | Repository admission receipt                             |\n| `bootstrapped`       | Successful public npm bootstrap receipt or registry fact |\n| `trust-bound`        | Trusted publisher binding receipt                        |\n| `content-ready`      | Declared source paths present                            |\n| `artifact-sealed`    | Verified sealed publication bundle                       |\n| `package-published`  | Exact package version visible in npm                     |\n| `alpha-complete`     | Protected Alpha PR completion evidence                   |\n| `staging-visible`    | Staging route evidence                                   |\n| `production-visible` | Production route evidence                                |\n\n`paper status` reports `satisfied`, `not-reached`, `blocked`, or `unknown` for\neach state. It does not promote a state merely because a prior state is\ncomplete. This makes a later `paper resume` safe: the command dispatches the\nthin repository release workflow, while the workflow re-verifies durable\nevidence and remains the publication authority.\n\nOperationally, responsibility remains split:\n\n- the paper repository owns content, declared metadata, and its thin\n  build/release workflow;\n- Buildchain owns scaffold shape, evidence contracts, reproducibility, sealed\n  bundle mechanics, npm transaction mechanics, and resumption planning;\n- GitHub branch protection and trusted publishing own authority transitions;\n- the papers site consumes publication evidence and owns reader-facing\n  rendering.\n\nDaily work begins and ends through the repository-pinned v3 CLI:\n\n```sh\npnpm paper:work:start -- golden-path\n# edit, test, and commit paper source\npnpm paper:work:submit\n```\n\nThe start plan derives `dev/vN/vN.M` from `publication.version` and requires\nlocal HEAD to equal the exact canonical remote development SHA. The submit plan\nallows only a non-protected work branch containing that SHA, a clean committed\ntree, a normal fast-forward push, and a pull request back to the same derived\ndevelopment branch. Neither command force-pushes, guesses a fork target, or\nsilently fetches and merges stale state.\n\nMaintainers can inspect a sibling fleet without per-repository command copies:\n\n```sh\nbuildchain paper fleet audit --root /path/to/papers --json\nbuildchain paper fleet update --root /path/to/isolated-paper-worktrees --json\n```\n\nFleet update is dry-run first and accepts only isolated work branches. Its\ntyped plan carries exact-old and expected-new digests for the same owned\nsurfaces as `paper migrate`; `--write` also refreshes each pnpm lockfile. It\nnever rewrites paper content or publication configuration.\n\nRun a local readiness check without network observations:\n\n```sh\nbuildchain paper preflight --offline --json\nbuildchain paper status --json\n```\n\nBefore real npm bootstrap, first inspect the default dry-run result:\n\n```sh\nbuildchain paper bootstrap npm --json\n```\n\nOnly after reviewing the package, repository, workflow, and dry-run evidence:\n\n```sh\nbuildchain paper bootstrap npm \\\n  --execute \\\n  --confirm-public-package @kungfu-tech/paper-example \\\n  --json\n```\n\nGenerate the publication manifest locally or in CI:\n\n```sh\nbuildchain publication-artifact manifest --source-sha \"$(git rev-parse HEAD)\" --json\n```\n\nProve the complete candidate from two clean builds:\n\n```sh\nbuildchain publication-artifact reproducibility \\\n  --source-sha \"$(git rev-parse HEAD)\" \\\n  --promote \\\n  --json\n```\n\nGenerate the npm package contents after the manifest exists:\n\n```sh\nbuildchain publication-artifact npm-package --json\n```\n\nNode API:\n\n```js\nimport {\n  collectPublicationArtifact,\n  writePublicationArtifact,\n} from \"@kungfu-tech/buildchain/publication-artifact\";\n\nimport {\n  collectPublicationPackageFacts,\n  preparePublicationNpmPackage,\n} from \"@kungfu-tech/buildchain/publication-package\";\n\nimport { verifyPublicationReproducibility } from \"@kungfu-tech/buildchain/publication-reproducibility\";\n\nimport {\n  createPublicationSealedBundle,\n  verifyPublicationSealedBundle,\n} from \"@kungfu-tech/buildchain/publication-sealed-bundle\";\n```\n\n`writePublicationArtifact()` is the single implementation used by the CLI and\nthe reusable workflow. The generated manifest records:\n\n- publication title, kind, authors, and primary artifact;\n- artifact paths, byte sizes, and SHA-256 digests;\n- metadata paths and SHA-256 digests;\n- source SHA, tree SHA, source files, and source bundle digest;\n- publication toolchain type, image, digest, command, invocation mode, and trust\n  classification;\n- timestamp and reproducibility policy;\n- downstream site-consumption hints;\n- optional archive routes for canonical, latest, latest evidence, immutable\n  version prefix, and public artifact URLs.\n\nThe companion publication artifact passport records the same source and\nartifact evidence plus an explicit responsibility split. Buildchain proves\ndeclared files and hashes; it does not peer-review paper claims.\n\nWhen archive config is present, the registry uses the\n`kungfu-buildchain-publication-artifact-registry` contract. A site repository\ncan render latest pages and historical version indexes from that registry\nwithout rebuilding old PDFs from the latest npm package or paper source.\n\n## Site Consumption\n\nA downstream papers site should treat the publication manifest as the single\nfact source for the artifact. The site owns rendering and navigation; it should\nnot reinterpret the paper repository as a web deployment source.\nFor registry-level routing, sites should first consume the package-owned\nBuildchain fact source:\n\n```text\nnode_modules/@kungfu-tech/buildchain/dist/site/publication-registry.json\n```\n\nor the equivalent package export:\n\n```js\nimport registry from \"@kungfu-tech/buildchain/site/publication-registry.json\" with { type: \"json\" };\n```\n\nThat registry uses the `kungfu-buildchain-publication-release-registry`\ncontract. It separates mutable canonical/latest reader routes from immutable\nversion prefixes, publication artifacts, source bundles, and passport evidence\nso site repositories can render `/papers/**` without maintaining a parallel\nfixture truth source.\n\nFor `paper-observer-declared-timelines`, the expected adoption path is:\n\n```text\npaper repo builds PDF + manifest + source bundle\npaper repo updates publication-registry.json\npapers site consumes publication-artifact.json\npapers site consumes publication-registry.json for history\nsite renders paper page and links the PDF/source bundle\n```\n\nThis mirrors web-surface governance without mixing producer and renderer\nresponsibilities."
    },
    {
      "id": "manual:publication-authority",
      "title": "Sealed Publication Authority",
      "route": "/docs/publication-authority",
      "category": "manual",
      "capabilityGroup": "release-passport-trust",
      "audience": [
        "release-operator",
        "agent"
      ],
      "maturity": "preview",
      "sourcePath": "docs/publication-authority.md",
      "digest": "sha256:a1650158943d95b979d164ca98a73d7919fda577d648e4a4a9d04588ec698796",
      "headings": [
        {
          "level": 1,
          "title": "Sealed Publication Authority",
          "anchor": "sealed-publication-authority"
        },
        {
          "level": 2,
          "title": "Evidence chain",
          "anchor": "evidence-chain"
        },
        {
          "level": 2,
          "title": "Runner and control-plane evidence",
          "anchor": "runner-and-control-plane-evidence"
        },
        {
          "level": 2,
          "title": "Managed web-surface production",
          "anchor": "managed-web-surface-production"
        },
        {
          "level": 2,
          "title": "Consumer qualification handoff",
          "anchor": "consumer-qualification-handoff"
        },
        {
          "level": 2,
          "title": "API and CLI",
          "anchor": "api-and-cli"
        },
        {
          "level": 1,
          "title": "Optional stronger external evidence; generate the JSON outside the workflow.",
          "anchor": "optional-stronger-external-evidence-generate-the-json-outside-the-workflow"
        },
        {
          "level": 2,
          "title": "Publication lanes",
          "anchor": "publication-lanes"
        }
      ],
      "markdown": "---\nstatus: draft\nperiod: ongoing\ntheme: sealed-publication-authority\ndoc_type: protocol\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: B\nreview_state: unreviewed\nlast_reviewed: 2026-07-31\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-15\n  limits: Live provider configuration must be re-audited; no credential values are represented.\n---\n\n# Sealed Publication Authority\n\nBuildchain publication authority is a closed-world, fail-closed protocol. It does\nnot mint registry or cloud credentials. It independently verifies whether an\nalready protected publication job is allowed to request a short-lived provider\ncredential for one exact product, target, version, channel, and artifact digest.\n\nThe machine-readable authority inventory is\n`dist/site/publication-authority-registry.json`. Any workflow with a write,\nenvironment, OIDC, cloud credential, registry publish, release, or Git push\nsignal must have an explicit descriptor. A new authority-bearing workflow that\nis absent from the inventory fails site generation. Unknown workflows and every\ndescriptor not marked `product-publication` are denied product publication.\n\n## Evidence chain\n\nA qualifying admission binds exact source and runtime SHAs; contract, consumer\npolicy, qualifying controller receipt, Shifu/Gate aggregate, artifact, runner,\nand control-plane digests; repository, authority workflow, provider publisher\nworkflow, Environment policy,\nproduct, target, version, and channel; plus a unique nonce and a lifetime of no\nmore than 15 minutes. Every expected binding is mandatory at verification time;\nan omitted expected field is not a wildcard.\n\nThe independent verifier recomputes every digest and ignores a producer's own\nallow/deny conclusion. It fetches the exact evidence run, validates the actual\nrelease-candidate passport and referenced qualifying controller receipt,\nrecomputes the Shifu Gate aggregate or explicit consumer-owned no-Gate policy,\nrecomputes the downloaded artifact manifests, and hashes every declared product\npayload file against those manifests. The `.buildchain/` diagnostics envelope is\nbound by the manifest digest but excluded from the product-byte set because it can\nbe finalized after the lifecycle scan. The verifier also compares the PR evidence tree to the\nadmitted post-merge source commit tree. It rejects an unknown\nworkflow, stale or replayed nonce, runner downgrade, control-plane drift,\nsource/runtime mismatch, and artifact substitution. A successful result is a\nscoped capability receipt, not a bearer credential.\n\n## Runner and control-plane evidence\n\nRunner evidence uses exactly four classes: `ephemeral`, `reimaged`,\n`persistent-measured`, and `unqualified`. Ephemeral runners also record their\njob-isolation boundary. Reimaged and persistent runners qualify only when a\nclean baseline is proven and baseline, toolchain, cache-contract, and task-\nisolation digests are all present. Otherwise they still emit diagnostic\nevidence with `qualificationStatus = unqualified`, but cannot receive a product\ncapability.\n\nThe external audit records digests and pass/fail status for repository Actions\ndefaults, classic branch protection or an active matching repository ruleset,\ndeclared protected Environment policy or an explicit no-Environment binding,\njob-scoped credentials,\nabsence of long-lived workflow publication credentials, provider authority,\nand authorized runner class. Provider modes are `npm-trusted-publisher`,\n`github-token`, and `oidc-role`. The OIDC-role mode consumes only a sanitized\nprovider audit containing a role digest and qualifying decision; raw IAM policy,\ntokens, or credentials are rejected. Package-owner, cloud-root, GitHub\nadministrator, and registry-root credentials remain outside Buildchain's trust\nboundary. Missing or unreadable facts fail closed.\n\nAn unauthenticated local npm CLI is not evidence that Trusted Publishing is\nmissing. `npm whoami` reports only the local CLI session and does not report the\nOIDC identity that npm creates during `npm publish`. The default read-only audit\ntherefore binds the exact provider, repository, caller workflow, optional\nEnvironment, job-scoped OIDC permission, and absence of long-lived credentials,\nthen records `provider-at-transaction`: npm makes the final authorization\ndecision when `npm publish` exchanges the job's OIDC token. A missing or drifted\ntrusted-publisher configuration consequently denies the transaction safely; it\nis not preflighted through an unrelated long-lived npm login.\n\nAn authenticated external auditor can add stronger point-in-time evidence by\nsupplying sanitized `npm trust list --json` output with `--npm-trust-json`. This\nchanges the publisher fact to `audited-control-plane`; the workflow never runs\n`npm trust list` itself and never receives that auditor's npm credential.\n\nThe credential-free collector proves effective Actions and runner scope from\nthe publication workflow fetched at `--workflow-ref`: explicit read-only\nworkflow defaults, job-scoped write/OIDC permissions, and an exact GitHub-hosted\nrunner label. It does not call repository Actions-default or self-hosted-runner\nadministration endpoints. Branch/ruleset and OIDC subject facts remain live\nread-only provider queries. When the detailed branch-protection endpoint is not\nreadable with the workflow token, `--source-sha` binds the provider's public\nprotected-branch summary to the exact merged PR, independent approval, required\nsuccessful check, same-repository lineage, and current branch head. This records\nprovider-enforced transaction evidence without treating an unavailable\nadministration endpoint as an unprotected branch. It avoids turning a\nrepository-admin token into a publication prerequisite.\nWhen a legacy caller declares a reusable job id such as `build`, the collector\naccepts it only if the protected branch exposes exactly one required context\nunder `build / ...`; it then verifies that exact context, configured app, and PR\nhead SHA. Exact declarations remain unchanged, and ambiguous prefixes fail\nclosed.\n\nFor non-dry-run workflows, missing admission, runner, control-plane, Gate, or\nexpected-binding evidence is rejected before Buildchain downloads candidate\nartifacts. The denial explicitly records that npm Trusted Publishing and OIDC\nwere not evaluated, so downstream diagnostics cannot misclassify an admission\nassembly failure as an npm authentication failure.\n\nAn explicitly opted-in managed `workflow_run` promotion lane may assemble those\ninputs from evidence owned by its caller repository. It downloads the exact prior RC passport,\nsummary, referenced controller receipt, manifests, and product payloads; proves\nthe admitted channel commit has the same Git tree as the RC; performs the live\nread-only control-plane audit; records the GitHub-hosted job as ephemeral runner\nprovenance; and consumes either a caller-supplied Gate aggregate or an explicit\ncaller no-Gate decision. The\nindependent verifier then recomputes every receipt and payload digest exactly as\nit does for externally supplied admission. Automatic assembly keeps Buildchain\nas the canonical authority repository, requires evidence to belong to the\ncaller, binds a repository-local publisher workflow, and rejects unknown refs,\nnon-exact source SHAs, package/target mismatches, or an undeclared Gate policy.\nManual apply and consumers that do not opt in still require their own explicit\nadmission inputs.\n\nBefore authority verification, the reusable promotion controller runs the same\nrelease transaction selector in read-only mode. That plan supplies one exact\npublication version and tag to the admission verifier, the publish-gate source\nlock, and the real promotion action. The verifier rejects a capability for a\ndifferent version, and the promotion action rechecks the planned version before\nany publish transaction side effect. Release-candidate fixture versions are\nartifact evidence only; they never name Buildchain's own source-lock or\npublication capability.\n\nEvidence publication is a separate authority class and never grants product\npublication.\n\n## Managed web-surface production\n\nThe reusable web-surface controller owns a complete standard producer path for\nits documented production mechanisms. A reviewed matching release-PR merge or a\nmanual dispatch by an actor with current repository write authority creates a\nsigned decision bound to the exact source SHA. After build, verify, and\nproduction planning, the workflow creates a qualifying pre-publication\ncontroller receipt and assembles a ten-minute admission over the source tree,\nimmutable Buildchain runtime, deployment plan, artifact hash, production\nEnvironment, AWS role/deploy target, runner provenance, decision digest, and\nnonce. The independent verifier emits the scoped `web-production` capability.\n\nThe production job rechecks the capability and candidate against the same plan\nbefore downloading product artifacts. AWS authorization is deliberately\nrecorded as `provider-at-transaction`: the capability binds the exact role and\nEnvironment, while `configure-aws-credentials` performs the live OIDC exchange\nand remains the final provider authorization gate before mutation. Buildchain\ndoes not claim that an IAM trust relationship passed before that transaction.\n\nExternally assembled admissions remain an optional compatibility path and must\nprovide the full admission, runner, control-plane, Gate aggregate, expected\nbindings, and nonce set. They are not required for the managed web-surface\nrelease-PR or trusted-manual paths.\n\n## Consumer qualification handoff\n\nFor managed release candidates, a consumer whose Gate can only be decided\nafter the exact candidate bytes exist may provide `publication-gate-command`.\nThe sealed authority downloads and recomputes the RC evidence first, checks out\nthe exact admitted consumer source without credentials, and runs that command\nwith read-only evidence paths. The command must write one complete qualifying\nShifu aggregate to `BUILDCHAIN_PUBLICATION_GATE_RESULT_PATH`. Buildchain then\nchecks the aggregate digest and source binding before assembling the admission;\nthe later consumer predicate and provider action still revalidate the same\ncomplete aggregate. A precomputed aggregate, the command, and an explicit\nno-Gate decision are mutually exclusive.\n\nConsumers may explicitly opt in to a final, consumer-owned qualification\npredicate. Buildchain then transports the complete Gate aggregate alongside the\nsealed capability instead of reducing it to a summary. The capability binds the\nauthority registry, consumer Gate registry and policy, exact source and runtime,\ncontroller, runner, control-plane, artifact, provider target, channel, version,\nfreshness window, nonce, and exact predicate command digest.\n\nThe predicate runs in a separate job with read-only source access, no inherited\nsecrets, no OIDC permission, and no provider write permission. It receives only\npaths to `capability.json` and `gate-aggregate.json` plus the exact predicate id\nand digest. The consumer writes a\n`kungfu-buildchain-consumer-publication-decision`; Buildchain seals that result\nas a deterministic\n`kungfu-buildchain-publication-qualification-receipt`. Buildchain does not parse\nproduct-specific Gate meanings.\n\nThe provider action revalidates the capability, full aggregate, receipt,\npredicate identity, freshness, nonce, source, version, channel, target, and all\nsealed digests immediately before the publish transaction. Missing, denied,\nstale, replayed, substituted, or drifted receipts fail before provider mutation.\nDirect calls to the provider action cannot bypass the receipt when\n`require-publication-qualification` is enabled. Consumers that do not opt in\nretain the existing publication contract.\n\n## API and CLI\n\nUse `@kungfu-tech/buildchain/publication-authority` or run:\n\n```bash\nbuildchain verify publication-admission admission.json \\\n  --registry-json publication-authority-registry.json \\\n  --runner-json runner.json \\\n  --control-plane-audit-json control-plane.json \\\n  --publication-evidence-json publication-evidence.json \\\n  --expected-json expected.json \\\n  --used-nonce previous-run-nonce \\\n  --json\n```\n\nThe read-only live collector defaults to npm trusted publishing. Other product\nproviders select an explicit adapter:\n\n```bash\nbuildchain audit publication-control-plane \\\n  --repository kungfu-systems/buildchain \\\n  --branch dev/v3/v3.0 \\\n  --source-sha <exact-merged-branch-sha> \\\n  --workflow .github/workflows/release-candidate-promote.yml \\\n  --workflow-ref <exact-buildchain-sha> \\\n  --publisher-workflow .github/workflows/buildchain-ref-promotion.yml \\\n  --job promote \\\n  --environment none\n\n# Optional stronger external evidence; generate the JSON outside the workflow.\nbuildchain audit publication-control-plane \\\n  --repository kungfu-systems/buildchain \\\n  --branch dev/v3/v3.0 \\\n  --workflow .github/workflows/release-candidate-promote.yml \\\n  --publisher-workflow .github/workflows/buildchain-ref-promotion.yml \\\n  --job promote \\\n  --environment none \\\n  --npm-trust-json sanitized-npm-trust.json\n\nbuildchain audit publication-control-plane \\\n  --repository kungfu-systems/buildchain \\\n  --branch release/v3/v3.0 \\\n  --workflow .github/workflows/.binary-release-assets.yml \\\n  --job publish \\\n  --environment buildchain-release-assets \\\n  --publisher-mode github-token\n\nbuildchain audit publication-control-plane \\\n  --repository OWNER/CONSUMER \\\n  --workflow-repository kungfu-systems/buildchain \\\n  --branch main \\\n  --workflow .github/workflows/.web-surface.yml \\\n  --job production-apply \\\n  --environment production \\\n  --publisher-mode oidc-role \\\n  --provider-audit-json sanitized-oidc-role-audit.json\n```\n\nThe authority workflow identifies the reusable implementation that performs the\npublication job. The publisher workflow identifies the caller filename bound by\nthe provider's trusted-publisher policy; these identities are deliberately\nseparate. `--environment none` is an explicit assertion that the job declares no\nGitHub Environment and the provider policy has no Environment restriction. A\nnamed Environment must exist, be protected, and be declared by the job. The\nBuildchain receipt alone is never sufficient authorization.\n\n## Publication lanes\n\n`Binary Distribution` is evidence-only. It builds platform archives and a\nrelease evidence bundle with read-only repository permissions. GitHub Release\nasset writes live in `Binary Release Assets`, which downloads an exact prior\nevidence run, verifies its bundle digest against the sealed capability, and is\nthe only binary job with `contents: write` in the protected\n`buildchain-release-assets` Environment.\n\nThe npm/promotion, paper, binary-release, and web-production lanes all depend on\nthe independent verifier. Preview, staging, build, source-check, controller,\nand failure-evidence lanes do not inherit product publication capability."
    },
    {
      "id": "manual:publish-transaction",
      "title": "Publish Transaction",
      "route": "/docs/publish-transaction",
      "category": "manual",
      "capabilityGroup": "release-passport-trust",
      "audience": [
        "release-operator"
      ],
      "maturity": "stable",
      "sourcePath": "docs/publish-transaction.md",
      "digest": "sha256:72466943bb459f6857f23ac6f92bcf4714dcd2f535c38a9f0e34864b36404e06",
      "headings": [
        {
          "level": 1,
          "title": "Publish Transaction",
          "anchor": "publish-transaction"
        },
        {
          "level": 2,
          "title": "Why This Exists",
          "anchor": "why-this-exists"
        },
        {
          "level": 2,
          "title": "Durable State",
          "anchor": "durable-state"
        },
        {
          "level": 2,
          "title": "Lifecycle",
          "anchor": "lifecycle"
        },
        {
          "level": 2,
          "title": "Post-Publish Requirements And Artifact Provenance",
          "anchor": "post-publish-requirements-and-artifact-provenance"
        },
        {
          "level": 2,
          "title": "Release Modes And Auth",
          "anchor": "release-modes-and-auth"
        },
        {
          "level": 2,
          "title": "Evidence",
          "anchor": "evidence"
        },
        {
          "level": 2,
          "title": "Registry Truth Contract",
          "anchor": "registry-truth-contract"
        },
        {
          "level": 2,
          "title": "States",
          "anchor": "states"
        },
        {
          "level": 2,
          "title": "Ref Ordering",
          "anchor": "ref-ordering"
        },
        {
          "level": 2,
          "title": "CLI Recovery",
          "anchor": "cli-recovery"
        },
        {
          "level": 2,
          "title": "Build-Images Follow-Up",
          "anchor": "build-images-follow-up"
        }
      ],
      "markdown": "---\nstatus: active\nperiod: ongoing\ntheme: buildchain-publish-transaction\ndoc_type: technical-reference\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-08-06\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-31\n  invisible_context: not asserted\n---\n\n# Publish Transaction\n\nBuildchain release promotion is not just tag movement. A release can also publish\nexternal artifacts: npm packages, Python wheels, OCI images, binary archives,\nmetadata manifests, or site deployment records. Those side effects are harder\nthan Git refs because most registries are append-only: a failed rerun must know\nwhich artifacts already exist, which are still missing, and whether any existing\nartifact conflicts with the release material.\n\nBuildchain v3 models that work as a release transaction.\n\n## Why This Exists\n\nThe old ABV workflow made Git refs the visible release authority. That was\nenough when \"release\" meant \"create a version commit, move tags, and let\ndownstream jobs react.\" It is not enough when a single publish run must also\nupload packages and images.\n\nThe failure mode to avoid is:\n\n1. publish an external artifact;\n2. fail before moving the exact release tag or floating channel refs;\n3. rerun from a new job id with no memory of the artifact;\n4. either republish something different or move refs without proving the\n   already-published artifact matches the release.\n\nThe transaction gives reruns a stable identity and a machine-readable state so\nBuildchain can resume safely. The identity is:\n\n```text\nrepository + version + source_sha + target_ref\n```\n\nIt is not the GitHub Actions run id.\n\n## Durable State\n\n`actions/promote-buildchain-ref` stores release transaction state in a\nmachine-managed Git branch:\n\n```text\nrefs/heads/buildchain/release-state/<version>\n```\n\nThe branch contains:\n\n```text\nstate.json\nevidence.json   # present after publish evidence exists\nsealed-bundle/<candidate-root>/files/**  # present for build-once publication\n```\n\nThe local `.buildchain/release-state/...` and\n`.buildchain/release-evidence/...` files are working copies. They are useful for\nlocal inspection and lifecycle commands, but they are not the durable truth for\nGitHub-hosted reruns. On action startup, Buildchain reads the durable state ref\nfirst, restores the local working copies, and only then decides whether to\npublish, repair, or finalize.\n\nEvery meaningful state transition is written to the durable ref before public\nrelease refs move. Release-state GitHub API reads and writes use retry/backoff\nfor transient service failures such as HTTP 5xx responses, connection resets,\ntimeouts, and \"other side closed\" socket failures. If the durable write still\ncannot be persisted after retries, the action fails closed.\n\nFor a sealed publication, `state.json` also carries the typed sealed-bundle\nmanifest, its candidate root, publication milestones, stable\n`publication_state`, and an exact resume command. The durable ref stores every\ndeclared bundle file as binary Git blobs before the publish lifecycle starts.\nA fresh runner restores those blobs into\n`.buildchain/recovered-publication/<version>/`, verifies every size and SHA-256\nagainst the manifest, and only then supplies the recovered paths to the publish\nlifecycle. A missing or changed tarball, PDF, source bundle, or manifest fails\nbefore registry publication.\n\nDurable release-state refs reserve their exact version even when the public exact\ntag was never created. If a later machine run sees a failed or repair-required\nstate for `vX.Y.Z-alpha.N` and cannot resume it with the same transaction\nidentity, alpha version selection must advance to the next prerelease instead\nof reusing or overwriting that failed transaction slot.\n\n`release-candidate-promote.yml` can establish or restore this state from an\nolder successful candidate run through the documented fresh-event recovery\ninputs. The recovery receipt and sealed bundle are verified before the action\nreads or creates transaction state. If `resume-transaction-id` is supplied,\nthe restored durable/local transaction must already exist with that exact id;\na missing or different id fails before provider mutation. An absent transaction\nis created only when no expected existing identity was requested. See\n[Release Candidate: Resume from an existing candidate run](release-candidate.md#resume-from-an-existing-candidate-run).\n\n## Lifecycle\n\nRepositories declare publish work in `.buildchain/buildchain.toml`:\n\n```toml\n[publish]\nmode = \"publish-final-version\"\nauth = \"trusted-publishing\"\ndist_tag = \"latest\"\npackage_set_order = \"platforms-first-main-last\"\nmain_package = \"@kungfu-tech/libnode\"\n\n[lifecycle.publish]\ncommands = [\n  \"python scripts/publish_wheels.py\",\n  \"node scripts/publish-images.mjs\",\n  \"node scripts/write-publish-evidence.mjs\",\n]\n```\n\n`actions/promote-buildchain-ref` runs `lifecycle.publish` only when\n`publish-transaction: \"true\"` is set or when a `publish-command` input is\nprovided. The action sets:\n\n```text\nBUILDCHAIN_VERSION\nBUILDCHAIN_CHANNEL\nBUILDCHAIN_SOURCE_SHA\nBUILDCHAIN_TARGET_REF\nBUILDCHAIN_RELEASE_STATE\nBUILDCHAIN_EVIDENCE_DIR\nBUILDCHAIN_RELEASE_SHA\nBUILDCHAIN_RELEASE_MATERIAL_SHA\nBUILDCHAIN_PUBLISH_TOOLING_SHA\nBUILDCHAIN_PUBLISH_EVIDENCE\nBUILDCHAIN_SEALED_BUNDLE_ROOT\nBUILDCHAIN_SEALED_NPM_TARBALL\nBUILDCHAIN_SEALED_NPM_INTEGRITY\nBUILDCHAIN_SEALED_NPM_SHA256\nBUILDCHAIN_REQUIRED_ARTIFACTS\nBUILDCHAIN_PUBLISH_MODE\nBUILDCHAIN_PUBLISH_AUTH\nBUILDCHAIN_NPM_DIST_TAG\nBUILDCHAIN_PACKAGE_SET_ORDER\nBUILDCHAIN_PACKAGE_SET_MAIN_PACKAGE\n```\n\nBuildchain itself uses this contract for npm publishing:\n\n```toml\n[lifecycle.publish]\ncommand = \"node scripts/npm-publish-transaction.mjs\"\n```\n\nThat script validates that `package.json` matches `BUILDCHAIN_VERSION`, runs\n`npm publish --access public --tag <BUILDCHAIN_NPM_DIST_TAG>` through npm Trusted\nPublishing, and writes npm artifact evidence before the promotion action moves\npublic refs. When the sealed npm variables are present, the script verifies and\npublishes that exact `.tgz` file. It does not run `npm pack` again.\n\n`BUILDCHAIN_RELEASE_MATERIAL_SHA` is the source material whose artifacts must\nmatch. `BUILDCHAIN_PUBLISH_TOOLING_SHA` identifies the publishing code. A repair\nrun may change tooling, but material drift fails closed.\n\n## Post-Publish Requirements And Artifact Provenance\n\n`publish-required-artifacts-json` is a pre-publish family declaration, not a\nrequest to guess registry digests. A descriptor must include `kind + name`; it\nmay omit `ref` and `digest`. The action resolves a missing `ref` to the exact\n`BUILDCHAIN_VERSION`. Registries whose exact refs add a stable prefix or suffix\nmay instead declare a `ref_template` containing exactly one `{version}`, such\nas `v{version}`. The template is expanded only after exact version selection,\nso a resumed alpha transaction receives the newly selected prerelease rather\nthan the checked-out version. Declaring both `ref` and `ref_template`, using\nanother placeholder, or leaving unmatched braces fails before\n`lifecycle.publish`. The action exports the normalized exact refs as\n`BUILDCHAIN_REQUIRED_ARTIFACTS`, runs `lifecycle.publish`, and then requires the\nfinal evidence to contain every exact member with a non-empty digest. Existing\ncallers may continue supplying exact refs and digests.\n\nOCI publishers can opt into strict per-artifact provenance by adding\n`action: built` or `action: reused`. Those artifacts carry two separate\ncoordinates:\n\n- `content`: the version, ref, source SHA, and material SHA that produced the\n  immutable content;\n- `release`: the exact current version/ref, target ref, source SHA, and release\n  material SHA that bind that content into this release.\n\nThis distinction permits truthful cross-version reuse without claiming that an\nold OCI config was rebuilt from current material. For an OCI artifact with an\naction, final evidence also requires `platform`, positive `contract_major`, and\n`verification` containing a public manifest result, exact ref and digest,\nplatform, contract major, optional parent digest, evidence location, and a\npassed named smoke policy. Buildchain cross-checks those values against the\nartifact and current transaction. Missing family members and ref, digest,\ncontent, release, or verification conflicts enter `repair_required` before\npublic refs move.\n\nExample reused OCI evidence entry (the pre-publish requirement may omit\n`ref`, `digest`, `release`, and the observed verification values):\n\n```json\n{\n  \"group\": \"image\",\n  \"kind\": \"oci\",\n  \"name\": \"ghcr.io/kungfu-systems/base-linux\",\n  \"ref\": \"1.2.0-alpha.3\",\n  \"digest\": \"sha256:...\",\n  \"action\": \"reused\",\n  \"platform\": \"linux/amd64\",\n  \"contract_major\": 1,\n  \"content\": {\n    \"version\": \"1.1.9\",\n    \"ref\": \"1.1.9\",\n    \"source_sha\": \"<source-sha>\",\n    \"material_sha\": \"<material-sha>\"\n  },\n  \"release\": {\n    \"version\": \"1.2.0-alpha.3\",\n    \"ref\": \"1.2.0-alpha.3\",\n    \"target_ref\": \"alpha/v1/v1.2\",\n    \"source_sha\": \"<current-source-sha>\",\n    \"material_sha\": \"<current-material-sha>\"\n  },\n  \"verification\": {\n    \"public_manifest\": true,\n    \"ref\": \"1.2.0-alpha.3\",\n    \"digest\": \"sha256:...\",\n    \"platform\": \"linux/amd64\",\n    \"contract_major\": 1,\n    \"evidence\": \"registry-inspect.json\",\n    \"smoke\": {\n      \"policy\": \"manifest-contract\",\n      \"passed\": true,\n      \"evidence\": \"smoke.json\"\n    }\n  }\n}\n```\n\n## Release Modes And Auth\n\nBuildchain distinguishes two npm release modes:\n\n| Mode | Use | Auth | npm operation |\n| --- | --- | --- | --- |\n| `publish-final-version` | normal alpha or stable publication | `trusted-publishing` | `npm publish --tag <alpha|vX.Y-alpha|latest>` |\n| `promote-existing-version` | same-version alpha-to-latest recovery | `npm-token` | `npm dist-tag add <pkg>@<version> latest` |\n\nThe normal libnode path is `publish-final-version`: publish an alpha package set\nsuch as `22.22.3-kf.3-alpha.0` with the `alpha` dist-tag, then publish a\ndistinct final package set such as `22.22.3-kf.3` with the `latest` dist-tag.\nGitHub-hosted npm Trusted Publishing can authorize those `npm publish` calls\nwhen the workflow grants `id-token: write`.\n\n`promote-existing-version` is deliberately separate. npm Trusted Publishing does\nnot authorize arbitrary registry-management operations such as `npm dist-tag\nadd`; it authorizes publish-time package provenance. Therefore same-version\npromotion must declare `auth = \"npm-token\"`. Buildchain runs an npm token\npreflight with `npm whoami` before it writes any release transaction state or\nmoves a dist-tag. Missing token auth fails early with a contract error instead\nof a late `E401` after publish evidence has started to move.\n\nFor package sets, `package_set_order = \"platforms-first-main-last\"` makes the\nmain package the visibility gate. Platform package side effects are planned or\nretried first, and the main package or main dist-tag move happens last.\n\nWhen the transaction reaches `complete`, `actions/promote-buildchain-ref`\ngenerates `.buildchain/release-passport/buildchain.release.json` and persists\nthe `release-passport/*` files into the durable `buildchain/release-state/...`\nref. The passport is the stable release artifact for agents and people: it\nlinks the package set, npm publish evidence, dist-tag evidence, build summary,\nplatform artifact manifests, trusted publishing metadata, release-state ref,\ndurable release-state SHA, and transaction result in one schema. Consumer\nrepositories can set `release-passport-product-name` so the passport names their\nproduct instead of the Buildchain default.\n\n## Evidence\n\nThe publish lifecycle must write JSON evidence. Buildchain validates common\nfields and required artifact identities before final refs move.\n\n```json\n{\n  \"schema\": 1,\n  \"version\": \"2.0.11\",\n  \"channel\": \"release\",\n  \"source_sha\": \"aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa\",\n  \"release_sha\": \"bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb\",\n  \"target_ref\": \"release/v3/v3.0\",\n  \"release_material_sha\": \"bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb\",\n  \"publish_tooling_sha\": \"bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb\",\n  \"artifacts\": [\n    {\n      \"group\": \"node\",\n      \"kind\": \"npm\",\n      \"name\": \"@kungfu-systems/example\",\n      \"ref\": \"2.0.11\",\n      \"digest\": \"sha256:...\"\n    },\n    {\n      \"group\": \"image\",\n      \"kind\": \"oci\",\n      \"name\": \"ghcr.io/kungfu-systems/example\",\n      \"ref\": \"2.0.11\",\n      \"digest\": \"sha256:...\"\n    }\n  ]\n}\n```\n\nThe generic contract is intentionally small:\n\n- `version`, `channel`, `source_sha`, `release_sha`, and `target_ref` must match\n  the promotion run;\n- dist-tag promotion evidence is written beside the publish evidence as\n  `dist-tag-evidence.json` and is referenced from the generated passport;\n- required artifacts must appear in evidence;\n- evidence used by a GitHub-hosted rerun must either be stored in the durable\n  state ref or be reconstructed by a machine-verifiable consumer command;\n- existing artifacts with the same identity and digest are accepted on rerun;\n- missing artifacts can be published by the next run;\n- an existing artifact with a different digest puts the transaction into\n  `repair_required`.\n\nArtifact identity is `group + kind + name + ref`. A required artifact that omits\n`group` matches any group with the same `kind + name + ref`.\n\n## Registry Truth Contract\n\nBuildchain owns transaction orchestration, finalization ordering, durable state,\nand generic evidence validation. It does not embed registry clients for npm,\nPyPI, GHCR/OCI, GitHub Releases, S3, Conan, CMake packaging, or project-specific\ndownload pages.\n\nConsumer `lifecycle.publish` commands own registry truth. A valid consumer stage\nmust be idempotent and machine-verifiable:\n\n- inspect the target registry before publishing;\n- accept an existing exact artifact only when version, identity, digest, and\n  release-source binding match;\n- publish missing required artifacts;\n- reject conflicting existing artifacts and write evidence that lets Buildchain\n  move the transaction to `repair_required`;\n- write `BUILDCHAIN_PUBLISH_EVIDENCE` after every successful inspect/publish\n  cycle;\n- leave floating aliases such as npm dist-tags, PyPI stable markers, OCI\n  floating tags, GitHub Release \"published\" status, or download-page stable\n  links to a finalization step after Buildchain evidence validation.\n\nThe first-class adapter surface is command-based. Projects may wrap npm, PyPI,\nGHCR/OCI, GitHub Release assets, archives, SBOMs, provenance, or checksums\nhowever they need, as long as they emit the common evidence contract.\n\n## States\n\nThe state machine is:\n\n```text\nprepared -> sealed -> publishing -> published -> finalizing -> complete\n                          |            |            |\n                          v            v            v\n                    publish_failed  repair_required failed_permanently\n                          |\n                          v\n                      abandoned\n```\n\nSupported states:\n\n| State                | Meaning                                                                                                  |\n| -------------------- | -------------------------------------------------------------------------------------------------------- |\n| `prepared`           | Transaction identity was created, but publish has not started.                                           |\n| `sealed`             | Exact candidate bytes and manifest are verified and durable; registry publication has not started.       |\n| `publishing`         | Publish lifecycle is running or may have been interrupted.                                               |\n| `publish_failed`     | Publish command failed before valid evidence was produced.                                               |\n| `published`          | Evidence is valid; refs have not necessarily finalized.                                                  |\n| `finalizing`         | Buildchain is moving exact/floating refs or needs a later run to do it.                                  |\n| `complete`           | Required evidence is valid and refs have finalized.                                                      |\n| `repair_required`    | Existing evidence or artifact state conflicts with expected release material.                            |\n| `abandoned`          | A human or controlled process abandoned this transaction, usually because a newer version supersedes it. |\n| `failed_permanently` | Recovery should not continue without explicit override.                                                  |\n\n`repair_required`, `abandoned`, and `failed_permanently` fail closed unless the\noperator passes an explicit override. That override is for controlled repair\nruns, not normal retry behavior.\n\n`publication_state` is a stable operator-facing projection over the detailed\ntransaction state. Its successful progression is\n`prepared -> sealed -> package-published -> alpha-complete` for Alpha or\n`release-complete` for stable release. If npm succeeds but GitHub Release work\nis interrupted, the durable record remains `package-published`; the next run\nreuses the exact npm evidence and sealed release assets instead of rebuilding\nor republishing them.\n\n## Ref Ordering\n\nWhen publish transactions are enabled, promotion order is:\n\n1. verify target source and governance;\n2. create or reuse the version-state release commit;\n3. acquire or resume the release transaction;\n4. for build-once publication, verify and persist the complete sealed bundle;\n5. run `lifecycle.publish` from the exact sealed tarball or accept already-valid\n   evidence;\n6. validate evidence and required artifacts;\n7. move exact release/prerelease tag;\n8. move floating tags and channel refs;\n9. mark the transaction `complete`;\n10. create or update the GitHub Release from restored sealed assets and record\n    the `github_release` milestone.\n\nWhen a protected channel requires a generated version-state pull request, the\nfirst run can stop at `finalizing` after registry publication. If the reviewed\nmerge commit later contains that exact transaction release material but the\nexact tag is still absent, a retry performs finalization only: it reloads the\nsame durable source, release material, tooling, evidence, version, and target\nbindings; creates the exact tag at the transaction source SHA; moves floating\nrefs to the transaction release SHA; and completes the passport from the\ntransaction source tree. It does not rerun the provider mutation and does not\nauthorize the newer composite channel tree\nas published material. A different source tree still requires a new version and\na fresh release candidate.\n\nDeferred binary dispatch, controller-evidence bundling, and any consumer\npublication commit are skipped while `finalization-needed=true`. They run only\nafter the exact public tag and complete release passport exist.\n\nConsumer products that expose a signed well-known channel can opt into one\nadditional, deliberately final step with `publication-commit-command`. Before\nthat command runs, Buildchain has already completed the transaction, created\nthe public GitHub Release, and uploaded every release-passport file plus the\nexplicit PR-stage payload files selected by\n`github-release-payload-patterns`. The command is therefore a commit point for\ndiscovery authority, not another artifact publisher.\n\nThe command receives the exact version, source SHA, release SHA, release tag,\nrelease passport path, and downloaded payload directory through\n`BUILDCHAIN_PUBLICATION_COMMIT_*`. Optional consumer-owned dispatch/API\ncredentials and private signing material are exposed separately as\n`BUILDCHAIN_PUBLICATION_COMMIT_TOKEN` and\n`BUILDCHAIN_PUBLICATION_COMMIT_SIGNING_KEY`; Buildchain never logs, persists,\nor interprets either value. The command must write\n`.buildchain/publication-commit/evidence.json` (or another declared path below\n`.buildchain/`) with this contract:\n\n```json\n{\n  \"schema\": \"kungfu-buildchain-publication-commit-evidence/v1\",\n  \"status\": \"passed\",\n  \"identity\": {\n    \"version\": \"4.0.0-alpha.2\",\n    \"sourceSha\": \"<source-sha>\",\n    \"releaseSha\": \"<release-sha>\",\n    \"releaseTag\": \"v4.0.0-alpha.2\"\n  },\n  \"publication\": {\n    \"url\": \"https://example.test/.well-known/product/alpha.json\",\n    \"payloadRoot\": \"sha256:<64-lowercase-hex>\"\n  },\n  \"readback\": {\n    \"status\": \"passed\",\n    \"url\": \"https://example.test/.well-known/product/alpha.json\",\n    \"payloadRoot\": \"sha256:<same-root>\"\n  },\n  \"recovery\": {\n    \"previousAuthority\": \"preserved\",\n    \"rollbackReference\": \"sha256:<previous-root>\"\n  }\n}\n```\n\nBuildchain rejects stale evidence, identity drift, non-public or mutable URLs,\nread-back root drift, and missing recovery evidence. It also rejects\n`standalone-binary-distribution=true` with a final commit command because that\nwould queue product mutations after the authority moved. On any command or\nread-back failure, the consumer must leave the previous well-known document\nauthoritative; Buildchain does not retry the command behind a successful\nreceipt.\n\nIf protected branch finalization is interrupted after publish evidence is\nvalid, the transaction can stop in `finalizing` and output\n`finalization-needed=true`. A later run resumes from the same transaction state\nand completes ref movement without republishing matching artifacts. New\nBuildchain-managed promotions first try to finish generated version-state\nbookkeeping with the promotion token directly. Before patching a protected\ngenerated bookkeeping ref, Buildchain emits every configured required check on\nthe exact generated version-state commit so branch protection can\nvalidate the automation path without a second build, then uses the generated\nref update token for the protected ref PATCH. If release finalization\nbookkeeping is still rejected, Buildchain creates or reuses a same-repository\n`buildchain/version-state/*` PR and leaves the transaction resumable with\n`finalization-needed=true`. Strict alpha uses the same protected PR fallback\nfor both its target channel and subsequent dev reconciliation. A later\nidempotent run continues only after the provider shows that the PR reached the\nprotected branch. The reusable wrapper binds that token to the run-scoped\n`github.token` and rejects user, team, or alternate App bypass actors.\n\nIf finalization fails after an exact Git tag, a channel branch, or dev/alpha\nsync ref has already moved, the next run reads the durable `finalizing` state\nand continues from the recorded transaction. The current workflow SHA may be a\ngenerated version-state commit, or a historical version-state merge commit, that\ncontains or corresponds to the transaction's `release_material_sha`; it does not\nhave to equal the original `source_sha` or the transaction `release_sha`. Exact\ntags are accepted when they already point at the transaction release/material\nSHA or the finalized channel head. Floating\nchannel tags and dev/alpha refs are then retried idempotently, and the\ntransaction is marked `complete` only after those public refs are consistent.\nWriting `complete` clears any stale `failure` value from earlier attempts, so\nthe durable `state.json` represents the successful final state instead of the\nlast transient error seen before a rerun.\nAn exact tag at an unrelated SHA is still a material conflict and blocks\nrecovery.\n\nFor anchored package versions, the package version and internal line tag are\nseparate transaction coordinates. A retry can correct a stale internal tag on\nan unfinished `published` or `finalizing` transaction only when its validated\nevidence and complete artifact set match the same package version, source,\nrelease material, and target. Buildchain additionally requires that the stale\ntag does not already point at the transaction and that the newly selected tag\nis unclaimed or already points at accepted release material. No registry publish\ncommand is rerun during this exact-tag rebind.\n\nGoverned retries distinguish unrelated channel advancement from advancement\nmade by their own durable transaction. An unrelated descendant remains an\nauditable `superseded-promotion` no-op. When the target ref is exactly the\nrecorded `release_sha` for the requested source, target, and expected version,\nBuildchain resumes finalization, restores publish evidence, and emits the\nrelease-passport paths needed by downstream controller receipts.\n\nPublication authority planning applies the same occupied-version rule as the\nlater mutation step. If a current alpha transaction already contains published\nmaterial and regenerating version state would create new release material, the\nplanner advances to the next alpha before sealing authority. It never seals the\nold published version and then lets the publisher discover a different version\ninside the mutation boundary.\n\nIf finalization fails after an exact Git tag is created, the next run reads the\ndurable `finalizing` state, verifies the exact tag points at the recorded\nsource SHA (while accepting legacy release/material targets for recovery), and\nretries the remaining floating refs. An exact tag at an unrelated SHA is a\nmaterial conflict and blocks recovery.\n\n## CLI Recovery\n\nLocal recovery commands operate on the same state/evidence files:\n\n```bash\nnode scripts/release-transaction.mjs inspect --version v3.0.2\nnode scripts/release-transaction.mjs recover --version v3.0.2\nnode scripts/release-transaction.mjs finalize --version v3.0.2\nnode scripts/release-transaction.mjs abort --version v3.0.2 --superseded-by v3.0.3\n```\n\nThe CLI is a diagnostic and local repair surface. It reports the durable\n`state_ref`, but remote durable-ref writes and public Git ref finalization are\nowned by `actions/promote-buildchain-ref`, because that action runs inside the\nsame governed GitHub permissions and branch-protection checks as release\npromotion. In other words, CLI `finalize` can mark the local transaction state\ncomplete after valid evidence; the machine-operated public finalization path is\nto rerun the promotion action.\n\nWhen no state file exists, creation commands also require:\n\n```bash\n--repository kungfu-systems/buildchain \\\n--source-sha <sha> \\\n--release-sha <sha> \\\n--target-ref release/v3/v3.0 \\\n--channel release\n```\n\n## Build-Images Follow-Up\n\n`build-images` should consume this contract rather than inventing a separate\nworkflow rule. The expected integration shape is:\n\n- image build writes OCI digests into publish evidence;\n- required image families are passed through `publish-required-artifacts-json`\n  before their final digests are known;\n- mixed built/reused evidence preserves content provenance separately from the\n  current release binding;\n- reruns check GHCR or the target registry and accept existing images only when\n  tag and digest match;\n- preview or alpha image tags remain non-stable until the transaction evidence\n  validates;\n- production image aliases move only after all required image artifacts are\n  present and the Buildchain exact release tag has finalized."
    },
    {
      "id": "manual:readme-badges",
      "title": "README Badge Blocks",
      "route": "/docs/readme-badges",
      "category": "manual",
      "capabilityGroup": "distribution-indexes",
      "audience": [
        "consumer",
        "site"
      ],
      "maturity": "stable",
      "sourcePath": "docs/readme-badges.md",
      "digest": "sha256:d032ddd27db62bdb21031cbd0673d9ae61af0250c12522fe6106e7aff835fb21",
      "headings": [
        {
          "level": 1,
          "title": "README Badge Blocks",
          "anchor": "readme-badge-blocks"
        },
        {
          "level": 2,
          "title": "Node API",
          "anchor": "node-api"
        },
        {
          "level": 2,
          "title": "CLI",
          "anchor": "cli"
        },
        {
          "level": 2,
          "title": "Configuration",
          "anchor": "configuration"
        },
        {
          "level": 2,
          "title": "KFD Badge Rules",
          "anchor": "kfd-badge-rules"
        },
        {
          "level": 2,
          "title": "CI Contract",
          "anchor": "ci-contract"
        }
      ],
      "markdown": "# README Badge Blocks\n\nBuildchain can generate a managed README badge block from repository-owned\nfacts. The README keeps only a projection; the source facts remain in\n`.buildchain/buildchain.toml`, package metadata, workflow files, KFD standards metadata,\nand the repository's own release passport.\n\nThe managed block is delimited by:\n\n```markdown\n<!-- buildchain:badges:start -->\n...\n<!-- buildchain:badges:end -->\n```\n\nBuildchain owns only that block. Everything outside the markers remains normal\nREADME content.\n\n## Node API\n\nUse the public package export:\n\n```js\nimport {\n  collectBadgeBundleFacts,\n  collectReadmeBadgeFacts,\n  createKfdBadgeSpecsFromStandards,\n  renderBadgeBundleBlock,\n  renderReadmeBadgeBlock,\n  checkBadgeBundleBlock,\n  checkReadmeBadgeBlock,\n  updateBadgeBundleBlock,\n  updateReadmeBadgeBlock,\n} from \"@kungfu-tech/buildchain/badges\";\n```\n\n`@kungfu-tech/buildchain/readme-badges` remains available for compatibility,\nbut new integrations should use `@kungfu-tech/buildchain/badges`.\n\n`collectReadmeBadgeFacts({ cwd })` returns a machine-readable object with\ncontract `kungfu-buildchain-readme-badge-facts`. It collects repository\nidentity, package name/version/license, configured platforms, configured\nworkflow status badges, the repository's own Buildchain Release Passport\nlocation and verification result, and KFD badge state. KFD badge labels,\nhuman-facing concept text, standard document links, schema IDs, and interface\ncontracts are read from\n`@kungfu-tech/kfd/standards.json` when the package is installed, or from an\nexplicit `kfd_standards` path/URL. When present, it also summarizes local KFD\nclaim registry and product-mechanism facts from the package-owned site bundle,\nso downstream agents can connect README badges back to Buildchain's\nKFD/source-of-truth surfaces.\n\n`renderReadmeBadgeBlock(facts)` renders deterministic Markdown from that facts\nobject. `checkReadmeBadgeBlock({ readmeText, facts })` compares the current\nREADME marker block against the expected block and reports missing or stale\ndrift. `updateReadmeBadgeBlock({ readmeText, facts })` inserts or replaces the\nmanaged block.\n\nThe Node API is the implementation source. The CLI delegates to it.\n\n`collectBadgeBundleFacts({ cwd, claims })` is the trust-badge bundle API. It\nuses the same repository facts, but returns contract\n`kungfu-buildchain-badge-bundle-facts` and only renders the Buildchain trust\nclaims: every active `kfd-*` standard discovered from KFD standards metadata,\nplus `release-passport`. KFD-1, KFD-2, KFD-3, KFD-4, and release passport are\nenabled by default with current KFD metadata. Callers can pass\n`claims: \"kfd-1,release-passport\"` or an array to narrow the bundle without\nhand-writing badge Markdown.\n\n## CLI\n\nGenerate facts as JSON:\n\n```bash\nbuildchain badges readme --json\n```\n\nFail closed when the README block is missing or stale:\n\n```bash\nbuildchain badges readme --check\n```\n\nInsert or replace the block:\n\n```bash\nbuildchain badges readme --write\n```\n\nGenerate only the Buildchain trust badge bundle:\n\n```bash\nbuildchain badges bundle --json\nbuildchain badges bundle --check\nbuildchain badges bundle --write\n```\n\nNarrow the bundle to specific claims:\n\n```bash\nbuildchain badges bundle --claims kfd-1,release-passport --write\n```\n\nAll commands accept `--cwd <dir>` and `--readme <path>`. Repositories can add\n`buildchain badges bundle --check` or `buildchain badges readme --check` to CI\nso badge drift is detected like any other generated release-facing surface.\n\n## Configuration\n\nThe optional `[badges]` table in `.buildchain/buildchain.toml` declares local facts that\ncannot be inferred safely:\n\n```toml\n[badges]\nrelease_passport = \"https://github.com/example/project/releases/latest/download/buildchain.release.json\"\nkfd_standards = \"node_modules/@kungfu-tech/kfd/standards.json\"\nkfd_1 = \"declared\"\nkfd_2 = \"planned\"\nkfd_3 = \"aligned\"\nkfd_4 = \"declared\"\nplatforms = [\"macOS\", \"Linux\", \"Windows\"]\nworkflows = [\"verify.yml\", \"build.yml\"]\n\n[badges.bundle]\nclaims = [\"kfd-1\", \"kfd-2\", \"kfd-3\", \"kfd-4\", \"release-passport\"]\n```\n\n`release_passport` may be a local path or URL. If omitted, Buildchain tries\n`buildchain.release.json`, then `.buildchain/release-passport/buildchain.release.json`,\nthen the repository's latest GitHub Release asset when the GitHub repository\ncan be discovered.\n\nThe generated `Buildchain Release Passport` badge is a repository capability\nbadge: it says whether the current repository has a Buildchain release passport\nthat can be verified. It does not report the upstream `kungfu-systems/buildchain`\nrepository status. Buildchain's own README dogfoods the same rule because its\nconfigured `release_passport` points at Buildchain's own release passport.\n\nBuildchain-owned badges use stable hosted image URLs by default:\n\n```text\nhttps://buildchain.libkungfu.dev/badges/v1/{badge}/{state}.svg\n```\n\nThe URL is part of the Buildchain badge contract. Consumers do not need to\nregenerate README files when Buildchain replaces the placeholder badge logo\nwith a formal logo; the hosted endpoint owns logo rendering. The package-owned\nsite bundle publishes `badge-endpoint-registry.json` plus Shields-compatible\nJSON payloads under `badges/v1/**` so the site repository can serve or render\nthe exact SVG endpoints without inventing badge facts.\n\nForks or private deployments can override the image host with:\n\n```toml\n[badges]\nbadge_endpoint_base_url = \"https://example.com/buildchain-badges/v1\"\n```\n\n`kfd_standards` is optional. If omitted, Buildchain tries the installed\n`@kungfu-tech/kfd/standards.json` package export. Use the explicit path or URL\nonly when a repository deliberately vendors KFD standards metadata or validates\nagainst a local KFD development checkout. The KFD standards metadata controls\nthe badge vocabulary; the release passport still controls whether a repository\nmay display a KFD state as `passed`.\n\n## KFD Badge Rules\n\nKFD passed is evidence-backed. A repository may display `KFD-N passed` only when\nits own release passport verifies successfully and the corresponding passport\nsection has `status: \"passed\"`. The KFD badge vocabulary comes from KFD\nstandards metadata, not Buildchain private strings: for example KFD-2 uses the\n`releaseTrustPassport` concept and KFD-4 uses the `observerPerspective` concept\nfrom `@kungfu-tech/kfd/standards.json`.\n\nWhen no release passport exists yet, or when the passport cannot be verified,\nBuildchain downgrades each KFD badge to the explicit local declaration such as\n`declared`, `aligned`, or `planned`. A local `passed` declaration is treated as\n`declared`; unknown local states are normalized to a non-passed fallback.\n\nBuildchain's own README may link to Buildchain's own release passport. Other\nrepositories must not claim Buildchain's KFD status as their own; their badge\nlinks must point to their own release passport or evidence page.\n\n## CI Contract\n\nRecommended CI gate:\n\n```bash\nbuildchain badges readme --check\n```\n\nor, when the repository only wants the Buildchain trust bundle:\n\n```bash\nbuildchain badges bundle --check\n```\n\nThe check fails when:\n\n- the marker block is missing;\n- generated Markdown differs from repository facts;\n- a previously hand-written KFD passed claim is not backed by the repository's\n  verified release passport facts.\n\nThe machine-readable facts object should be used by downstream site renderers\nor audit tools when Markdown badges are not enough."
    },
    {
      "id": "manual:release-activation-transaction",
      "title": "Release activation transaction",
      "route": "/docs/release-activation-transaction",
      "category": "manual",
      "capabilityGroup": "release-passport-trust",
      "audience": [
        "release-operator",
        "agent"
      ],
      "maturity": "preview",
      "sourcePath": "docs/release-activation-transaction.md",
      "digest": "sha256:c3de5838603d3e6dd3ea03c599e67aafa1d1fc184498fb779cb703f8796424cf",
      "headings": [
        {
          "level": 1,
          "title": "Release activation transaction",
          "anchor": "release-activation-transaction"
        }
      ],
      "markdown": "# Release activation transaction\n\nBuildchain exposes `release-activation-transaction` as the final cross-repository\ncontract between a qualified product release, its public web surface, and the\nproduct-owned released-evidence projection.\n\nThe canonical order is:\n\n1. `candidate-qualified`\n2. `artifacts-published`\n3. `passport-sealed`\n4. `site-published`\n5. `public-readback`\n6. `evidence-synthesized`\n\n`packages/core/release-activation-transaction.js` is the executable authority.\nEvery transaction binds an exact product source SHA, exact reviewed site source\nSHA, tag, channel, version, environment, artifact-set root, and the three\nrepository owners. A later phase cannot pass while an earlier phase is\nincomplete. Replaying a passed phase is idempotent only when its retained\nreceipt roots are unchanged.\n\nReleased evidence must be synthesized from a canonical receipt set containing\nexactly one artifact-publication, release-passport, site-publication,\npublic-readback, and product-qualification receipt. Every receipt repeats the\nsame binding root. Missing, duplicated, stale, or substituted roots fail\nclosed.\n\nShadow rehearsal uses `mode=shadow`, `environment=shadow`, and always emits\n`releasedUseClaim=false`. It is suitable for protected PR qualification and\nmust never be published as real release evidence. Activation mode requires the\nproduction environment; actual channel mutation remains the caller's protected\npublication responsibility.\n\nThe web-surface workflow accepts `production-source-sha` only for an explicitly\napproved `workflow_dispatch`. It checks out and plans the exact reviewed\nconsumer commit, while the production environment and normal publication\nauthority gates remain intact."
    },
    {
      "id": "manual:release-candidate",
      "title": "Release Candidate Passport",
      "route": "/docs/release-candidate",
      "category": "manual",
      "capabilityGroup": "reusable-build",
      "audience": [
        "release-operator",
        "consumer"
      ],
      "maturity": "stable",
      "sourcePath": "docs/release-candidate.md",
      "digest": "sha256:d76bbd75aab3c4dd94756c1c64562a125e74369c7c8b97342dbcacc5d7561602",
      "headings": [
        {
          "level": 1,
          "title": "Release Candidate Passport",
          "anchor": "release-candidate-passport"
        },
        {
          "level": 2,
          "title": "Initiative-family release evidence",
          "anchor": "initiative-family-release-evidence"
        },
        {
          "level": 2,
          "title": "Resume from an existing candidate run",
          "anchor": "resume-from-an-existing-candidate-run"
        }
      ],
      "markdown": "# Release Candidate Passport\n\nThe release-candidate passport is the pre-promotion evidence contract produced\nafter a reusable build matrix succeeds and before any publish-gate side effects\nrun. It is different from the release passport:\n\n- `release-candidate-passport.json` proves which source SHA, channel, runtime,\n  workflow run, and platform artifacts were verified before promotion.\n- `buildchain.release.json` is generated after publish finalization and remains\n  the durable audit entrypoint for the published release.\n\nEnable it on the reusable build workflow:\n\n```yaml\njobs:\n  build:\n    uses: kungfu-systems/buildchain/.github/workflows/.build.yml@v3\n    with:\n      artifact-name: libnode\n      release-candidate: true\n      publish-channel: alpha\n      publish-source-ref: publish-gate/alpha/v22/v22.22/22.22.3-kf.3-alpha.7\n```\n\nWhen the platform matrix and aggregate summaries complete, Buildchain uploads:\n\n```text\n<artifact-name>-release-candidate-<publish-source-sha>\n```\n\nThe passport contract is `kungfu-buildchain-release-candidate-passport`. It\ncontains:\n\n- repository and pull request context;\n- target channel, target ref, and product version or a non-publish\n  `source-<shortSha>` candidate label;\n- source head SHA, merge ref SHA, and the Git `HEAD^{tree}` SHA for PR merge\n  equivalence after the channel PR lands;\n- Buildchain runtime ref/SHA and workflow shell ref;\n- workflow run id/attempt/url;\n- normalized platform matrix and artifact summaries;\n- the hash of the aggregate `build-summary.json`.\n\n## Initiative-family release evidence\n\nA consumer may pass `release-candidate-family-evidence-json` to the reusable\nbuild. Buildchain normalizes that value as\n`kungfu-buildchain-initiative-family-release-evidence/v1`, binds it into the\ncandidate hash, and carries it unchanged into publication authority. The\nenvelope can identify one Initiative family root plus the exact Initiative and\nAssignment responsible for the release; continuation evidence can also bind\nthe previous family root.\n\nThis is an adapter-edge release contract, not a second Work Control authority.\nThe immutable native Family State v1 projection and the additive Family State\nv2 typed envelope remain owned by Kungfu. Buildchain only proves that the\nrelease candidate consumed the caller-supplied family evidence exactly.\n\nPromotion workflows that should not rebuild artifacts can enable:\n\n```yaml\n- uses: kungfu-systems/buildchain/actions/promote-buildchain-ref@v3\n  with:\n    token: ${{ secrets.BUILDCHAIN_PROMOTION_TOKEN }}\n    sha: ${{ needs.build.outputs.publish-source-sha }}\n    target-ref: alpha/v22/v22.22\n    promote-only-release-candidate: \"true\"\n    release-candidate-passport-path: .buildchain/artifacts/release-candidate-passport.json\n    release-candidate-build-summary-path: .buildchain/artifacts/build-summary.json\n    release-candidate-family-evidence-required: \"true\"\n    release-candidate-family-evidence-root: sha256:<initiative-family-root>\n    release-candidate-family-initiative-id: 2026-07-30-example-initiative\n    release-candidate-family-assignment-id: 2026-07-30-example-release\n```\n\nWith `promote-only-release-candidate: \"true\"`, promotion fails before\nversion-state, publish transaction, tag, or branch side effects when the\npassport does not match the repository, channel, source identity, platform\nmatrix, or build-summary hash. Source identity accepts the exact PR source SHA,\nthe PR merge ref SHA, or an exact Git tree match with the promoted channel HEAD;\nthis keeps post-merge channel commits strict without forcing a rebuild. The\nBuildchain-owned promotion workflow resolves the matching same-repository\nmerged channel PR and downloads its PR-stage RC passport automatically before\npromotion starts. The consumer wrapper defaults to a PR-stage workflow file\nnamed `build.yml` with display name `Build`, and filters the RC passport and\nbuild summary by the configured `artifact-name` before promotion. It also\ndownloads payload artifacts from the same PR-stage run, validates the required\npayload count, passes downloaded platform manifests into the release passport,\nand either forwards an explicit `publish-required-artifacts-json` value or\ngenerates one before calling `promote-buildchain-ref`. Before that call, the\nwrapper creates or updates `publish-gate/{alpha,release,major}` to the\npromotion channel commit and passes that ref, target SHA, and `locked=true` to\nthe promote action with `require-publish-source-lock: \"true\"`. Consumers using\nfloating `@v3` therefore get publish-side source-lock drift protection without\ncopying resolver or promote YAML. The default npm path\ngenerates that requirement list from the downloaded `.tgz` payloads themselves:\nBuildchain reads `package/package.json` inside each tarball for the real scoped\npackage name and version, computes npm-style `sha512-...` integrity over the\ntarball bytes, marks `publish-package-main` as `role: main`, and marks every\nother package as `role: platform`. Consumer workflows therefore stay\ndeclarative and do not need their own artifact download or publish-evidence\ngeneration scripts.\n\nWhen `release-candidate-family-evidence-required` is true, the promotion\nboundary additionally requires the exact family root and may require the\nInitiative and Assignment ids. Missing, mismatched, or source-drifted family\nevidence fails before version-state, release-state, tag, or branch mutation.\n\nBecause a channel merge can trigger promotion before its PR-stage matrix has\nfinished uploading evidence, the resolver waits up to ten minutes for the exact\nmerged PR's successful workflow run and paired artifacts. Polling remains bound\nto the PR/head identity; timeout or a sibling run still fails closed.\n\nThe public promotion router preserves the requested `vN` or `vN-alpha` ref as\naudit metadata, but binds the router to GitHub's selected reusable-workflow SHA\nand resolves each remaining floating shell/runtime ref exactly once. Every\nlater checkout and delegated promotion receives those immutable SHAs, so a\nchannel tag moving during the run cannot mix two Buildchain revisions.\n\n## Resume from an existing candidate run\n\nDo not rely on `gh run rerun` after a reusable-workflow startup or router\nfailure. GitHub documents two different rerun behaviors: a full rerun may use a\ncalled workflow from the currently specified ref, while a failed-job rerun uses\nthe same called-workflow commit as the original attempt. Neither operation is a\nsupported way to create a job graph that GitHub failed to resolve at startup.\nSee GitHub's [reusable workflow rerun behavior](https://docs.github.com/en/actions/reference/workflows-and-actions/reusing-workflow-configurations#behavior-of-reusable-workflows-when-re-running-jobs)\nand [workflow rerun identity rules](https://docs.github.com/en/actions/how-tos/manage-workflow-runs/re-run-workflows-and-jobs).\n\nThe supported recovery boundary is a new `workflow_dispatch` (or another new\ncaller event) that invokes `release-candidate-promote.yml` and supplies the old\ncandidate run explicitly:\n\n```yaml\nname: Resume release candidate\non:\n  workflow_dispatch:\n    inputs:\n      candidate-run-id: { required: true, type: string }\n      target-sha: { required: true, type: string }\n      expected-tree: { required: true, type: string }\n      candidate-runtime-sha: { required: true, type: string }\n      buildchain-runtime-sha: { required: true, type: string }\n\njobs:\n  resume:\n    uses: kungfu-systems/buildchain/.github/workflows/release-candidate-promote.yml@<exact-current-buildchain-sha>\n    permissions:\n      actions: write\n      checks: write\n      contents: write\n      id-token: write\n      pull-requests: write\n    secrets: inherit\n    with:\n      buildchain-ref: ${{ inputs.buildchain-runtime-sha }}\n      channel: alpha\n      target-ref: alpha/v3/v3.0\n      target-sha: ${{ inputs.target-sha }}\n      artifact-name: product\n      artifact-patterns: product-package-*\n      release-candidate-workflow-file: build.yml\n      release-candidate-workflow-name: Build\n      resume-candidate-repository: ${{ github.repository }}\n      resume-candidate-run-id: ${{ inputs.candidate-run-id }}\n      resume-expected-workflow-file: build.yml\n      resume-expected-workflow-name: Build\n      resume-expected-source-tree: ${{ inputs.expected-tree }}\n      resume-expected-candidate-runtime-sha: ${{ inputs.candidate-runtime-sha }}\n      resume-buildchain-runtime-sha: ${{ inputs.buildchain-runtime-sha }}\n      publish-transaction-override: true\n```\n\n`resume-expected-candidate-root` may replace `resume-expected-source-tree`, or\ncallers may provide both. `resume-transaction-id` is optional; when supplied it\nmust identify an already durable transaction before any provider mutation.\n\nRecovery downloads and checks the successful `pull_request` run, active\nworkflow file and name, same-repository merged PR, trusted repository\nassociation, target ancestry, promotion tree, Passport candidate root,\nbuild-summary root, controller receipts, platform matrix, artifact archive\nsize/digest, every manifest file, and every product payload byte. Tree equality\nalone is never admission. A different promotion commit is allowed only when all\nof those identities still agree.\n\nThe recovery path conditionally skips consumer dependency installation and all\nproduct `install`, `build`, `verify`, and platform-matrix jobs. It restores the\ndownloaded bytes as a content-addressed sealed bundle, so npm publication uses\nthe original `.tgz`. The explicit recovery entry binds the bundle identity to\nthe original candidate runtime recorded in the Passport; a newer recovery\ntooling SHA is recorded only in the recovery evidence and cannot perturb the\ndurable payload root. A transaction-only re-resolution remains a narrower\nfinalization path and is not a substitute for the candidate-run entry when the\noriginal complete artifact inventory must be reconstructed. Recovery may\nregenerate only Buildchain-owned receipts,\nattestations, signatures, Release Passport data, publication, and readback.\n\nSuccess emits `kungfu-buildchain-release-candidate-recovery/v1` with\n`action: reused`, the original run/source/tree, candidate and artifact roots,\nthe skipped stages, current tooling SHA, transaction identity/state, and an\nexact receipt root. The receipt is uploaded as an Actions artifact and staged\nwith immutable GitHub Release Passport assets.\n\nThe original candidate Passport is never rewritten when a reusable fixture or\nconsumer build records a product version different from the sealed publication\npackage. In that case the promote action validates the Passport without\ndiscarding its original target, then requires the immutable recovery receipt to\nbind the original candidate root and source/tree to the exact version read from\nthe sealed payload. Without that receipt, the existing direct Passport version\ncheck remains mandatory; receipt, candidate-root, target, or version drift fails\nbefore publication side effects.\n\nMissing or expired artifacts, archive or payload digest drift, tree/root,\nrepository/workflow/channel/target mismatch, untrusted run/PR provenance,\nincomplete controller evidence, and transaction conflict fail closed with an\nerror code and next action. Buildchain never converts recovery failure into a\nhidden full rebuild. A repository owner must choose a new candidate build\nexplicitly.\n\nWhen a durable transaction is absent, recovery seals one from the verified\ncandidate. Existing `sealed`, `publishing`, `package-published`, `finalizing`,\nand `complete` transactions use the normal idempotent state machine. Matching\nregistry and GitHub bytes are preserved, only missing publication work is\nperformed, and conflicting public digests enter `repair_required`.\n\nWhen the immutable recovery receipt proves that the transaction was already\n`complete` before the recovery run began, Buildchain verifies the existing\npublic Release Passport bundle in place and reports the GitHub Release action\nas `reused`. Buildchain-owned evidence regenerated by newer recovery tooling is\nkept in the new recovery artifact; it does not replace same-name evidence that\nwas sealed by the original completed publication. Every declared product\npayload is still compared byte-for-byte, a missing payload is uploaded from the\nrestored sealed bundle, and a conflicting payload digest fails closed. Ordinary\nduplicate publication without a complete recovery receipt retains the stricter\nsame-name/same-digest rule for all assets.\n\nAfter a transaction finalizes, the target branch can legitimately advance from\nthe original promotion SHA. Repeating explicit recovery accepts that movement\nonly when the caller supplies the exact durable transaction identity, the\ntransaction remains resumable, and GitHub proves the observed target head is a\ndescendant of the original transaction source. The recovery receipt records\nboth the immutable transaction SHA and the observed ref SHA. Missing identity,\nunrelated advancement, or a repair state fails closed.\n\nBy default, the wrapper forwards GitHub Release publication to the underlying\n`promote-buildchain-ref` semver model. Once the release transaction is complete,\nthe action creates or updates the public GitHub Release, applies\nprerelease/latest metadata from the authoritative publication channel (falling\nback to semver tag syntax only for ordinary callers without that intent), and\nuploads the publish evidence file together with the generated release passport\nassets. This keeps\nnpm/registry publication, Buildchain release passport persistence, and\n`release.published` propagation in one declarative reusable workflow. Consumers\nthat do not publish GitHub Releases can opt out with `github-release: false`.\nFor anchored/manual package releases, the public GitHub Release tag defaults to\n`v<publishedVersion>` while the internal transaction exact tag remains recorded\nin the release passport.\n\nStandalone binary publication is a separate consumer capability. The promotion\nwrapper does not assume that an npm-only repository provides\n`.github/workflows/binary-distribution.yml`. Repositories that own that workflow\nopt in with `standalone-binary-distribution: true`; Buildchain's self-promotion\ndoes so explicitly. Once enabled, a missing or invalid binary workflow remains a\nhard failure rather than being silently skipped.\n\nProducts that publish KFD release trust evidence can keep that path declarative\ntoo. Pass KFD-1 self contract witnesses, KFD-2 public claim files, and KFD-3\npre-build/artifact evidence into the wrapper:\n\n```yaml\njobs:\n  promote:\n    uses: kungfu-systems/buildchain/.github/workflows/release-candidate-promote.yml@v3\n    with:\n      buildchain-channel: auto\n      buildchain-alpha-contract-lock-path: .buildchain/alpha-contract-lock.json\n      buildchain-stable-contract-lock-path: .buildchain/contract-lock.json\n      channel: alpha\n      artifact-name: libnode\n      release-passport-kfd-1-witness-jsons: .buildchain/kfd/kfd-1/standard-contract.witness.json\n      release-passport-kfd-2-claim-jsons: .buildchain/kfd/kfd-2/release-claims.json\n      release-passport-kfd-3-prebuild-witness-jsons: .buildchain/kfd/kfd-3/collaboration-interface.prebuild.json\n      release-passport-kfd-3-artifact-verify-command: kungfu agent verify --json\n```\n\nBuildchain forwards those declarations into `promote-buildchain-ref`, verifies\nKFD-1 source/artifact contract surfaces, audits KFD-2 public release claims, and\ncompares KFD-3 declared shipped public surfaces with artifact-exposed public\nsurfaces. The release passport records the results under `kfd-1`, `kfd-2`, and\nthe KFD-provided `kfd-3` section.\n\nManaged consumers may also ask the promotion wrapper to assemble sealed\npublication evidence from the exact release candidate instead of producing\nshort-lived admission JSON in repository-specific workflow code:\n\n```yaml\n      publication-auto-admission: true\n      publication-auto-no-gate: true\n      publication-publisher-workflow-path: .github/workflows/buildchain-ref-promotion.yml\n      publication-product: Example Product\n      publication-target: npm:@example/product\n      publication-package-name: \"@example/product\"\n```\n\n`publication-auto-no-gate` is an explicit consumer decision, not a default. A\nconsumer with a Shifu Gate registry either supplies\n`publication-gate-aggregate-json`, or supplies a source-controlled\n`publication-gate-command` that writes the aggregate to\n`BUILDCHAIN_PUBLICATION_GATE_RESULT_PATH`. The command runs from the exact\nconsumer source in the credential-free sealed-authority job, after Buildchain\nhas downloaded the exact RC passport, summary, controller receipt, manifests,\nand payload bytes. It can read those inputs through\n`BUILDCHAIN_PUBLICATION_EVIDENCE_ROOT`; it receives no publication token, OIDC\npermission, or provider write permission. Buildchain validates the aggregate\ndigest and exact source binding before it seals a capability. Exactly one of\nthe supplied aggregate, consumer command, or explicit no-Gate decision is\nallowed. Buildchain still requires caller-owned RC evidence, an exact authority\nruntime and source SHA, a repository-local publisher workflow, matching npm\ntarget/package identity or exact caller-bound GitHub Release target, and a\nqualifying control-plane audit.\n\nPromotion resolves the complete PR-stage workflow, not only the first required\nstatus job that becomes green. `release-candidate-wait-seconds` bounds that\nwait and defaults to three hours so long native builds can finish controller,\npublication-tail, and retained-evidence jobs without racing a merged promotion.\nAn incomplete or failed workflow still fails closed; the longer bound does not\nturn a partial required-check result into candidate evidence.\n\nGitHub-Release-only consumers use the same managed admission without inventing\nan npm package identity:\n\n```yaml\n      publication-auto-admission: true\n      publication-auto-no-gate: true\n      publication-publisher-workflow-path: .github/workflows/buildchain-ref-promotion.yml\n      publication-product: Example Binary\n      publication-target: github-release:example/example-binary\n      publication-package-name: \"\"\n```\n\nThe target must exactly match the caller repository. Buildchain audits the\njob-scoped GitHub token, exact release-candidate payloads and manifests,\nprotected channel lineage, and public release transaction before allowing the\nGitHub Release mutation.\n\nA consumer that owns additional product qualification semantics can opt in to\nthe sealed handoff without teaching Buildchain those semantics:\n\n```yaml\n      publication-consumer-predicate-id: kungfu.release-admission/v1\n      publication-consumer-qualification-command: node scripts/qualify-release.mjs\n```\n\nThe command reads `BUILDCHAIN_PUBLICATION_CAPABILITY_PATH` and\n`BUILDCHAIN_PUBLICATION_GATE_AGGREGATE_PATH`, evaluates the complete aggregate,\nand writes a decision JSON document to\n`BUILDCHAIN_PUBLICATION_QUALIFICATION_RESULT_PATH`. It also receives\n`BUILDCHAIN_PUBLICATION_PREDICATE_ID` and\n`BUILDCHAIN_PUBLICATION_PREDICATE_DIGEST`. The separate qualification job has\nno write or OIDC permission and does not inherit publication secrets. A\nsuccessful deterministic receipt is rechecked by the provider action\nimmediately before mutation. Omitting both inputs preserves the existing\nconsumer contract; supplying only one fails closed."
    },
    {
      "id": "manual:release-flow",
      "title": "Release Flow Diagrams",
      "route": "/docs/release-flow",
      "category": "manual",
      "capabilityGroup": "governance-versioning",
      "audience": [
        "release-operator",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "docs/release-flow.md",
      "digest": "sha256:f2086d06a64f9321d7c1d62f93b37a169f781ba5bed4b714b5a8cb6509953c6e",
      "headings": [
        {
          "level": 1,
          "title": "Release Flow Diagrams",
          "anchor": "release-flow-diagrams"
        },
        {
          "level": 2,
          "title": "Architecture",
          "anchor": "architecture"
        },
        {
          "level": 2,
          "title": "Ref State",
          "anchor": "ref-state"
        },
        {
          "level": 2,
          "title": "Ref Protection Contract",
          "anchor": "ref-protection-contract"
        },
        {
          "level": 2,
          "title": "Opening a Minor Line",
          "anchor": "opening-a-minor-line"
        },
        {
          "level": 2,
          "title": "Alpha Promotion",
          "anchor": "alpha-promotion"
        },
        {
          "level": 2,
          "title": "Release Promotion",
          "anchor": "release-promotion"
        },
        {
          "level": 2,
          "title": "State Machine",
          "anchor": "state-machine"
        },
        {
          "level": 2,
          "title": "Version Examples",
          "anchor": "version-examples"
        },
        {
          "level": 2,
          "title": "Major Gate Promotion",
          "anchor": "major-gate-promotion"
        },
        {
          "level": 2,
          "title": "Failure Boundaries",
          "anchor": "failure-boundaries"
        }
      ],
      "markdown": "---\nstatus: active\nperiod: ongoing\ntheme: buildchain-release-flow\ndoc_type: technical-reference\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-07-31\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-31\n  invisible_context: not asserted\n---\n\n# Release Flow Diagrams\n\nThis document describes the Buildchain v4 branch, tag, and version-state flow.\nSee [Release governance](release-governance.md) for the design rationale.\n\n## Architecture\n\n```mermaid\nflowchart TD\n  Maintainer[\"Maintainer opens channel PR\"]\n  Verify[\"Release - Verify\"]\n  Review[\"Protected branch review\"]\n  Merge[\"Merge PR into alpha or release\"]\n  Promotion[\"Buildchain Ref Promotion\"]\n  StableDecision{\"Release channel?\"}\n  StableGate[\"Stable only: exact-alpha canaries + soak + cooldown\"]\n  Action[\"promote-buildchain-ref action\"]\n  VersionState[\"Version-state commit\"]\n  ExactTag[\"Exact tag\"]\n  FloatingRefs[\"Floating tags and channel branches\"]\n  Consumers[\"Consumers pin stable or exact refs\"]\n\n  Maintainer --> Verify\n  Verify --> Review\n  Review --> Merge\n  Merge --> Promotion\n  Promotion --> StableDecision\n  StableDecision -->|yes| StableGate\n  StableDecision -->|no: alpha| Action\n  StableGate --> Action\n  Action --> VersionState\n  Action --> ExactTag\n  Action --> FloatingRefs\n  ExactTag --> Consumers\n  FloatingRefs --> Consumers\n```\n\nBuildchain treats the PR merge as release intent and the promotion action as the\nonly component allowed to turn that intent into release refs.\n\n`StableGate` applies only to Buildchain's release channel. Alpha and train\niteration bypass it. See [Stable Release Throttle And Canary Gate](release-governance.md#stable-release-throttle-and-canary-gate)\nfor the versioned policy and evidence contract.\n\n## Ref State\n\n| Ref kind | Example | Mutability | Purpose |\n| --- | --- | --- | --- |\n| Development branch | `dev/v4/v4.0` | moves | next source state for a minor line |\n| Alpha branch | `alpha/v4/v4.0` | moves | latest test state for a minor line |\n| Release branch | `release/v4/v4.0` | moves | latest production state for a minor line |\n| Major gate branch | `publish-gate/major` | moves | reviewed administrator gate for publishing the next major |\n| Exact alpha tag | `v4.0.3-alpha.0` | immutable | audit ref for one tested prerelease |\n| Exact release tag | `v4.0.2` | immutable | audit ref for one production release |\n| Floating alpha tag | `v4.0-alpha` | moves | latest test channel for a minor line |\n| Floating major alpha tag | `v4-alpha` | moves | latest test channel on the highest published alpha minor for a major line |\n| Floating minor tag | `v4.0` | moves | latest production patch on a minor line |\n| Floating major tag | `v4` | moves | selected stable major entrypoint |\n\n## Ref Protection Contract\n\nRepository rulesets must distinguish immutable evidence refs from mutable\nchannel refs.\n\nProtect exact release and alpha tags as immutable evidence:\n\n```text\nrefs/tags/v*.*.*\n```\n\nDo not apply immutable-tag rulesets to every `refs/tags/v*` ref. Buildchain\nmust be able to update floating channel tags such as `v4`, `v4.0`, `v4.0-alpha`,\nand `v4-alpha` after the exact tag and publish evidence are valid. A ruleset that\nmatches all `v*` tags also matches floating tags, so release finalization can\nfail with GitHub protected-ref errors even though the exact release tag and\npublished artifacts are already durable.\n\nThe intended governance split is:\n\n- exact tags such as `v4.0.2` and `v4.0.3-alpha.0` are immutable audit refs;\n- for publish transactions, the exact tag points to the transaction\n  `source_sha`, matching package-registry source metadata such as npm\n  `gitHead`; generated version-state commits remain on protected branches and\n  floating channel refs;\n- floating tags such as `v4`, `v4.0`, `v4.0-alpha`, and `v4-alpha` are mutable channel refs\n  owned by the Buildchain promotion token;\n- protected branches still require reviewed channel PRs before Buildchain can\n  move any exact or floating release refs.\n\n## Opening a Minor Line\n\nNew minor lines should be opened through Buildchain instead of hand-created\nbranches. The reusable entrypoint is the `Release Line Bootstrap` workflow. It\ndefaults to dry-run so maintainers can inspect the planned refs, protection\ncontract, initial version, and first alpha PR before any mutation.\n\nThe workflow is backed by the CLI command:\n\n```bash\nbuildchain release line open \\\n  --major 4 \\\n  --minor 1 \\\n  --source-ref release/v4/v4.0 \\\n  --json\n```\n\nWhen the workflow is run with `apply=true`, Buildchain:\n\n- writes the initial version-state commit, such as `4.1.0-alpha.0`;\n- creates `dev/v4/v4.1` from that commit;\n- creates `alpha/v4/v4.1` and `release/v4/v4.1` from the selected source ref;\n- applies branch protection with one approving review and the configured\n  required status check; dev starts strict, while alpha and release also require\n  the pair-specific `verify` aggregate without a source-up-to-date ancestry loop;\n- reconciles the new dev branch's explicitly declared merge queue, or inherits\n  the exact queue parameters and bypass actors from the current default dev\n  branch when the policy is `inherit` or absent;\n- switches the repository default branch to the new dev line when requested;\n- opens the first `dev/v4/v4.1 -> alpha/v4/v4.1` channel PR when requested.\n\nThis makes minor-line creation a single audited operation. The channel PR still\ngoes through the normal verify/review/promotion path before an alpha is\npublished. Queue reconciliation runs after branch protection and before the\ndefault-branch switch, so a failed governance apply leaves the old active line\nin place and the idempotently created new refs can be retried.\n\n## Alpha Promotion\n\n```mermaid\nsequenceDiagram\n  participant Dev as dev/vX/vX.Y\n  participant PR as PR dev -> alpha\n  participant Verify as Release - Verify\n  participant Alpha as alpha/vX/vX.Y\n  participant Promote as Buildchain Ref Promotion\n  participant Tags as Tags\n\n  Dev->>PR: open channel PR\n  PR->>Verify: run verification checks\n  Verify-->>PR: check succeeds\n  PR->>Alpha: reviewed merge\n  Alpha->>Promote: Verify workflow_run completed\n  Promote->>Promote: validate same-repo merged PR\n  Promote->>Promote: compute next vX.Y.Z-alpha.N\n  Promote->>Promote: write and verify version state\n  Promote->>Tags: create or reuse vX.Y.Z-alpha.N\n  Promote->>Tags: move vX.Y-alpha\n  Promote->>Tags: move vX-alpha when X.Y is the highest published alpha minor\n  Promote->>Alpha: move alpha/vX/vX.Y\n  Promote->>Dev: move dev/vX/vX.Y\n```\n\nResult:\n\n```text\nvX.Y.Z-alpha.N\nvX.Y-alpha\nvX-alpha when X.Y is the highest published alpha minor\nalpha/vX/vX.Y\ndev/vX/vX.Y\n```\n\nall point at the generated alpha version-state commit.\n\n## Release Promotion\n\n```mermaid\nsequenceDiagram\n  participant Alpha as alpha/vX/vX.Y\n  participant PR as PR alpha -> release\n  participant Verify as Release - Verify\n  participant Release as release/vX/vX.Y\n  participant Promote as Buildchain Ref Promotion\n  participant Tags as Tags\n  participant Dev as dev/vX/vX.Y\n\n  Alpha->>PR: open channel PR\n  PR->>Verify: run verification checks\n  Verify-->>PR: check succeeds\n  PR->>Release: reviewed merge\n  Release->>Promote: Verify workflow_run completed\n  Promote->>Promote: validate same-repo merged PR\n  Promote->>Promote: find same-patch alpha tag\n  Promote->>Promote: compare release tree with tested alpha tree\n  Promote->>Promote: write final version state or verify anchored material\n  Promote->>Tags: create or reuse vX.Y.Z\n  Promote->>Tags: move vX.Y\n  Promote->>Tags: move vX when eligible\n  Promote->>Release: move release/vX/vX.Y\n  Promote->>Promote: prepare vX.Y.(Z+1)-alpha.0\n  Promote->>Tags: create or reuse vX.Y.(Z+1)-alpha.0\n  Promote->>Tags: move vX.Y-alpha\n  Promote->>Tags: move vX-alpha when X.Y is the highest published alpha minor\n  Promote->>Alpha: move alpha/vX/vX.Y\n  Promote->>Dev: move dev/vX/vX.Y\n```\n\nResult:\n\n```text\nvX.Y.Z\nvX.Y\nvX\nrelease/vX/vX.Y\n```\n\npoint at the production version-state commit, while:\n\n```text\nvX.Y.(Z+1)-alpha.0\nvX.Y-alpha\nvX-alpha when X.Y is the highest published alpha minor\nalpha/vX/vX.Y\ndev/vX/vX.Y\n```\n\npoint at the next alpha version-state commit.\n\n## State Machine\n\n```mermaid\nstateDiagram-v2\n  [*] --> Development: work lands on dev/vX/vX.Y\n  Development --> AlphaCandidate: PR dev -> alpha\n  AlphaCandidate --> AlphaPublished: Verify + review + merge + promotion\n  AlphaPublished --> ReleaseCandidate: PR alpha -> release\n  ReleaseCandidate --> ProductionPublished: Verify + review + merge + promotion\n  ProductionPublished --> NextAlphaPrepared: prepare vX.Y.(Z+1)-alpha.0\n  NextAlphaPrepared --> Development: dev and alpha refs move to next alpha\n```\n\nThe same minor line can loop through this state machine many times.\n\n## Version Examples\n\nAssume `v4.0.2-alpha.1` has been tested and a maintainer merges\n`alpha/v4/v4.0 -> release/v4/v4.0`.\n\nBuildchain should produce:\n\n```text\nv4.0.2                  exact production tag\nv4.0                    floating minor tag\nv4                      floating major tag when v4.0 is the selected major line\nrelease/v4/v4.0         production channel branch\n```\n\nIt should also prepare:\n\n```text\nv4.0.3-alpha.0          exact next alpha tag\nv4.0-alpha              floating alpha tag\nv4-alpha                floating major alpha tag when v4.0 is the highest published alpha minor\nalpha/v4/v4.0           alpha channel branch\ndev/v4/v4.0             development channel branch\n```\n\nThis is expected behavior. A production release closes one patch and opens the\nnext test patch on the same minor line.\n\n## Major Gate Promotion\n\n```mermaid\nsequenceDiagram\n  participant Release as release/vX/vX.Y\n  participant PR as PR release -> publish-gate/major\n  participant Verify as Release - Verify\n  participant Gate as publish-gate/major\n  participant Promote as Buildchain Ref Promotion\n  participant Tags as Tags\n  participant Next as dev/alpha/release v(X+1).0\n\n  Release->>PR: open administrator PR\n  PR->>Verify: run verification checks\n  Verify-->>PR: check succeeds\n  PR->>Gate: reviewed merge\n  Gate->>Promote: Verify workflow_run completed\n  Promote->>Promote: validate same-repo release -> publish-gate/major PR\n  Promote->>Promote: write v(X+1).0.0 version state\n  Promote->>Tags: create v(X+1).0.0\n  Promote->>Tags: move v(X+1).0 and v(X+1)\n  Promote->>Gate: move publish-gate/major to v(X+1).0.0\n  Promote->>Next: move release/v(X+1)/v(X+1).0 to v(X+1).0.0\n  Promote->>Promote: prepare v(X+1).0.1-alpha.0\n  Promote->>Next: move alpha/dev v(X+1).0 to next alpha\n```\n\n`publish-gate/major` is intentionally not an active source branch. It is the PR\ntarget for the administrator's \"publish the next major\" decision. The older\n`major-gate` name is a compatibility alias only.\n\n## Failure Boundaries\n\nPromotion should stop before moving refs when:\n\n- the run is a non-dry-run manual dispatch;\n- the expected same-repository PR cannot be found;\n- the PR was not merged;\n- the branch pair is not a valid channel path;\n- the required status check did not pass;\n- a release tree does not match the same-patch alpha tag tree, except for the\n  declared anchored/manual version files and anchor manifest that\n  `lifecycle.verify` or `verification-command` validates;\n- version-state verification fails;\n- a required exact tag already exists at a commit unrelated to the active\n  transaction or finalized channel head.\n\nThese failures are intentional. They protect consumers from refs that look\nreleased but do not have a complete evidence chain.\n\nDuring transaction finalization recovery, the current channel head may be a\ngenerated version-state merge commit. Buildchain validates that the durable\ntransaction version, exact tag, evidence, and release material match, and that\nthe current target ref contains or corresponds to the recorded\n`release_material_sha`. It must then tolerate exact tags, dev refs, or alpha\nrefs that have already moved and continue filling any missing floating tags\nbefore writing the transaction state as `complete`."
    },
    {
      "id": "manual:release-governance",
      "title": "Release Governance",
      "route": "/docs/release-governance",
      "category": "manual",
      "capabilityGroup": "governance-versioning",
      "audience": [
        "maintainer",
        "release-operator"
      ],
      "maturity": "stable",
      "sourcePath": "docs/release-governance.md",
      "digest": "sha256:6dfe8a9b974040fc1465b0da696519b4e97b0b901e30d852ffacda0d193810af",
      "headings": [
        {
          "level": 1,
          "title": "Release Governance",
          "anchor": "release-governance"
        },
        {
          "level": 2,
          "title": "Design Problem",
          "anchor": "design-problem"
        },
        {
          "level": 2,
          "title": "What ABV Contributed",
          "anchor": "what-abv-contributed"
        },
        {
          "level": 2,
          "title": "Buildchain Implementation",
          "anchor": "buildchain-implementation"
        },
        {
          "level": 2,
          "title": "Reconciling a protected line without rebuilding",
          "anchor": "reconciling-a-protected-line-without-rebuilding"
        },
        {
          "level": 2,
          "title": "Version Lines",
          "anchor": "version-lines"
        },
        {
          "level": 2,
          "title": "Alpha Semantics",
          "anchor": "alpha-semantics"
        },
        {
          "level": 3,
          "title": "Buildchain Alpha Self-Dogfood",
          "anchor": "buildchain-alpha-self-dogfood"
        },
        {
          "level": 2,
          "title": "Release Semantics",
          "anchor": "release-semantics"
        },
        {
          "level": 3,
          "title": "Stable Release Throttle And Canary Gate",
          "anchor": "stable-release-throttle-and-canary-gate"
        },
        {
          "level": 2,
          "title": "Major Gate Semantics",
          "anchor": "major-gate-semantics"
        },
        {
          "level": 2,
          "title": "Protected Dev Branches",
          "anchor": "protected-dev-branches"
        },
        {
          "level": 2,
          "title": "Buildchain Patrol",
          "anchor": "buildchain-patrol"
        },
        {
          "level": 2,
          "title": "Package-Manager Adapters",
          "anchor": "package-manager-adapters"
        },
        {
          "level": 2,
          "title": "Lifecycle Configuration",
          "anchor": "lifecycle-configuration"
        },
        {
          "level": 2,
          "title": "What This Guarantees",
          "anchor": "what-this-guarantees"
        },
        {
          "level": 2,
          "title": "What This Does Not Do",
          "anchor": "what-this-does-not-do"
        },
        {
          "level": 2,
          "title": "Operational Reading Order",
          "anchor": "operational-reading-order"
        }
      ],
      "markdown": "---\nstatus: draft\nperiod: ongoing\ntheme: buildchain-release-governance\ndoc_type: technical-reference\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-07-31\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-27\n  invisible_context: not asserted\n---\n\n# Release Governance\n\nBuildchain v3 preserves the release semantics of the older ABV workflow while\nmoving the implementation into one modern repository.\n\nThe central idea is simple: a reviewed merge into a release channel is the\nrelease intent. Automation must then create the version-state commit, exact tag,\nfloating tag, and next alpha state that make that intent true in Git.\n\n## Design Problem\n\nKungfu release automation has to keep four facts aligned:\n\n1. The source tree that was reviewed.\n2. The package version recorded in manifests such as `package.json` or\n   `lerna.json`.\n3. The exact immutable release or prerelease tag.\n4. The floating channel refs that consumers actually use.\n\nIf any one of these facts is updated by hand, the system can split:\n\n- a consumer can fetch `v3.0` and receive a tree whose package version still\n  says the previous release;\n- a maintainer can move `v3` without producing an exact `v3.0.N` audit tag;\n- an alpha can be promoted to production even though the release tree is not the\n  same tree that was tested;\n- a protected branch merge can succeed while the follow-up version commit is\n  missing, or a flow-internal generated `dev`/`alpha`/`release` ref update can\n  fail after publish because the automation identity was not declared in the\n  branch-protection review bypass allowance.\n\nThe older ABV workflow addressed this by letting GitHub PRs drive release\nstate. Buildchain keeps that choice because it makes release intent reviewable,\nobservable, and recoverable from Git history.\n\n## What ABV Contributed\n\nThe old ABV model was not just \"bump a version number.\" It encoded a governance\nloop:\n\n- release branches are named as channels: `dev`, `alpha`, `release`, and the\n  administrative `publish-gate/major`;\n- a PR from one channel to the next is the release request;\n- verify jobs check that the branch pair is valid before merge;\n- a maintainer review is required before the branch moves;\n- after merge, automation writes the version change and moves tags;\n- exact tags and floating refs are aligned with the resulting commit;\n- the next development channel is prepared automatically.\n\nABV also kept the version-state mutation in the repository. For JavaScript\nrepositories that usually meant changing `lerna.json` and/or `package.json`.\nThat commit is important because the tag alone is not enough evidence: the\nsource tree should also declare the version that the tag advertises.\n\nBuildchain v3 treats that as a hard semantic requirement for its own release\nline.\n\n## Buildchain Implementation\n\nBuildchain implements the same governance loop with:\n\n- `.github/workflows/release-verify.yml` for PR verification;\n- `.github/workflows/buildchain-ref-promotion.yml` for post-verify ref\n  promotion; this workflow dogfoods the declarative\n  `release-candidate-promote.yml` wrapper and does not hand-wire resolver,\n  artifact download, publish-gate, or promote action steps;\n- Buildchain self promotion enables `release-passport-buildchain-self-kfd`, so\n  the promote action generates KFD-1 witnesses, KFD-2 public claim JSON, and\n  KFD-3 collaboration-interface witnesses from the final version-state workspace\n  before release passport finalization. The witness hashes therefore bind to the\n  exact published package and site facts from\n  `packages/core/buildchain-kfd-claims.js` instead of relying on prose release\n  notes;\n- `actions/promote-buildchain-ref` for branch, tag, version-state, and\n  governance checks;\n- package-manager adapters that can update version state for pnpm, npm, and\n  yarn style repositories;\n- `buildchain.toml` lifecycle configuration for repositories whose version\n  state or verification commands are not Node package-manager defaults.\n\nThe implementation is intentionally stricter than a local release script:\n\n- manual workflow dispatch can only do dry-run promotion;\n- non-dry-run promotion must be driven by a completed `Verify` workflow;\n- target branch protection details must be readable, and branch protection must\n  apply to administrators as well as regular contributors;\n- `alpha/vX/vX.Y` and `release/vX/vX.Y` branch protection must require both the\n  general `check` context and the Release Verify aggregate `verify` context, so\n  an invalid channel pair cannot merge even when repository checks pass;\n- release targets keep those checks non-strict with respect to source-branch\n  ancestry: generated channel bookkeeping intentionally makes the source and\n  target histories diverge, while the pair-specific `verify` context validates\n  the legal channel transition;\n- alpha promotion must come from a merged same-repository PR from\n  `dev/vX/vX.Y` to `alpha/vX/vX.Y`;\n- release promotion must come from a merged same-repository PR from\n  `alpha/vX/vX.Y` to `release/vX/vX.Y`;\n- major promotion must come from a merged same-repository PR from\n  `release/vX/vX.Y` to `publish-gate/major`;\n- release promotion requires an existing same-patch alpha tag and checks the\n  release source tree against that tested alpha tree;\n- generated version-state commits are verified before refs move.\n\n## Reconciling a protected line without rebuilding\n\nThe public `build.yml` channel router ends with a top-level job named\n`Summarize build contract`. Keeping this aggregate at the public router boundary\nprevents its required check context from changing when the internal reusable\nbuild workflow gains another nesting layer.\n\nFor an already-tested pull request whose protected target still requires an\nolder Buildchain aggregate context, inspect the exact candidate SHA first:\n\n```bash\nGH_TOKEN=\"$(gh auth token)\" npx @kungfu-tech/buildchain@latest \\\n  release-governance reconcile \\\n  --repository kungfu-systems/example \\\n  --branch release/v3/v3.0 \\\n  --candidate-sha <tested-pr-head-sha> \\\n  --json\n```\n\nThe dry run reads the successful checks emitted for that SHA and reports the\nexact expected/actual context pair. It chooses the shallowest successful\n`Summarize build contract` context, so a new top-level router aggregate wins\nover the nested internal build summary. To apply the plan, rerun the same\ncommand with `--apply` using a token that can update branch protection.\n\nReconciliation changes only the required-status-check subresource. It replaces\nstale Buildchain aggregate contexts, preserves unrelated checks and strictness,\nand does not modify review requirements, administrator enforcement,\nconversation resolution, force-push policy, or deletion policy. The candidate\nmust still be the head of a pull request targeting the named managed branch;\nthe command fails closed otherwise. This lets a previously successful candidate\ncontinue from the same SHA without another native build or an administrator\nmerge bypass.\n\nRepositories may also expose a small caller workflow around\n`.github/workflows/release-governance-reconcile.yml@v3`. Pass `branch`,\n`candidate-sha`, and `apply`, and provide `governance-token` through the caller's\nsecrets. The reusable workflow uploads the JSON reconciliation receipt.\n\nExact publication planning installs the checked-out promotion source's declared\ndependencies before version-state verification. This keeps the pre-authority\nversion plan on the same package-manager boundary as the later promotion job,\nincluding repositories whose verification commands import production packages.\nThe planning pass may materialize and verify declared derived files locally,\nbut dry-run never creates Git blobs, trees, commits, refs, or tags.\n\nPromotion intents are serialized globally per caller repository with\n`cancel-in-progress: false`. A queued intent re-reads its protected target ref\nbefore checkout, dependency installation, release-candidate resolution, or any\npublish-gate/ref mutation. If the ref already points at a newer SHA, that older\nintent is no longer release authority: the workflow records the requested and\ncurrent SHAs, proves that the current target is ahead of the requested commit,\nand completes as a `target-ref-advanced` superseded no-op. Diverged or behind\ncomparisons are not superseded transactions and still fail closed.\nMissing refs, unreadable repository state, invalid channels, governance\nfailures, and artifact mismatches still fail closed. The promote action repeats\nthe target check at the mutation boundary, so a ref that advances after the\nworkflow preflight cannot receive a second set of publication side effects.\n\n## Version Lines\n\nKungfu uses Python-like version lines where a minor line can represent a\nlong-lived product train. A line such as `v3.0` can produce many production\npatch releases:\n\n```text\nv3.0.0\nv3.0.1\nv3.0.2\n...\nv3.0.1234\n```\n\nThis is why Buildchain maintains both exact and floating refs:\n\n- `v3.0.2` is immutable release evidence;\n- `v3.0` is the latest production release on the `3.0` line;\n- `v3` is the selected stable major-line entrypoint;\n- `v3.0.3-alpha.0` is immutable alpha evidence;\n- `v3.0-alpha` is the latest test channel for the `3.0` line.\n- `v3-alpha` is the latest test channel on the highest published alpha minor in major `3`.\n\nA release does not mean \"minor is complete.\" It means \"this patch on this minor\nline is now production.\"\n\nGitHub repository rules must preserve that distinction. Exact tags such as\n`v3.0.2` and `v3.0.3-alpha.0` should be immutable. Floating channel tags such as\n`v3`, `v3.0`, `v3.0-alpha`, and `v3-alpha` must remain movable by the Buildchain promotion\ntoken after governance checks and publish evidence pass. A tag ruleset that\nprotects every `refs/tags/v*` ref is too broad because it also locks the\nfloating channel tags that Buildchain is required to update. Prefer exact-tag\npatterns such as `refs/tags/v*.*.*` for immutable release evidence, while\nleaving floating channel tags under Buildchain automation control.\n\n## Alpha Semantics\n\nAn alpha merge is:\n\n```text\ndev/vX/vX.Y -> alpha/vX/vX.Y\n```\n\nBuildchain then:\n\n1. Computes the next prerelease for the minor line.\n2. Writes version state such as `vX.Y.Z-alpha.N`.\n3. Verifies the generated version-state tree.\n4. Creates or reuses the exact alpha tag.\n5. Moves `alpha/vX/vX.Y` to the generated alpha commit.\n6. Moves `dev/vX/vX.Y` to the same generated alpha commit when this is a\n   fast-forward update.\n7. Moves `vX.Y-alpha` to the same generated alpha commit.\n8. Moves `vX-alpha` only when `X.Y` is the highest minor in major `X` with a published alpha; older minor alpha work records a skip and cannot move the major channel backwards.\n\nThe npm channel follows the same ownership rule. The highest alpha minor publishes\nwith dist-tag `alpha`; maintenance alphas on an older minor publish with the\nline-specific dist-tag `vX.Y-alpha` so they cannot roll the global `alpha`\nchannel backward. Exact prerelease versions remain installable directly.\n\nThis keeps the test channel self-describing. If a consumer checks out\n`v3.0-alpha` or `v3-alpha`, the manifests and exact alpha tag agree. The major\nalpha ref removes routine consumer edits when Buildchain opens a newer minor,\nwhile exact tags and SHAs remain the reproducible audit choice.\n\n### Buildchain Alpha Self-Dogfood\n\nBuildchain continuously consumes its own current major alpha through\n`.github/workflows/buildchain-alpha-self-dogfood.yml`. Both lanes call the\nreleased channel router at `build.yml@v3-alpha`. The auto lane must resolve\n`v3-alpha`; the explicit stable lane must resolve `v3`. Both execute the same\ndeclared install, build, and verify fixture, proving that a single consumer\nsurface routes to distinct released runtimes without duplicating lifecycle\nconfiguration in the consumer.\n\nBuildchain's generic artifact-signing contract seals source-, tree-, runtime-,\nplatform-, and digest-bound requests from ordinary credential-free build jobs.\nProvider-specific authority jobs consume only those sealed payloads. Apple\nDeveloper ID, Windows Authenticode, and detached cryptographic signatures share\nthe request/receipt model, while each profile retains its honest platform\nsemantics and fail-closed verification requirements.\n\nThe authority verifies the complete result set on GitHub-hosted infrastructure\nbefore delivery. The consumer controller also performs final result verification,\nexact-byte import, manifest recomputation, and deterministic-artifact replacement\non a GitHub-hosted lane. Self-hosted build runners do not download authority\nresult payloads, and aggregate/release evidence fails closed until this\nfinalization succeeds.\n\nThe central `buildchain-artifact-signing` environment reuses the established\nmacOS Credential Island names (`BUILDCHAIN_MACOS_CERTIFICATE_*`,\n`BUILDCHAIN_MACOS_NOTARY_API_*`, and\n`BUILDCHAIN_MACOS_EXPECTED_TEAM_ID`). Those authority-only values are never\ndeclared by or forwarded through a consumer repository. Windows and detached\nproviders follow the same central-environment boundary.\n\nThe reusable build trust gate reads `job.workflow_ref`, which identifies the\ncalled workflow and its selected ref. It does not infer the runtime from\n`github.workflow_ref`, because GitHub defines that context as the caller\nworkflow identity during a reusable call.\n\nThe router selects `.buildchain/alpha-contract-lock.json` for alpha and\n`.buildchain/contract-lock.json` for stable. The alpha lock records the exact\nreviewed alpha SHA and compatibility digest; it does not replace the stable\nconsumer lock. A later alpha with only compatible additive drift continues,\nwhile a changed breaking digest fails until the new alpha contract is reviewed.\n\nThe evidence job resolves `v3-alpha` and `v3` through the GitHub refs API,\ncompares those immutable SHAs with the reusable workflow outputs, verifies the\n`alpha` and `stable` classifications, and uploads a JSON evidence artifact.\nThe canary runs after successful Buildchain ref promotion, on a daily fallback\nschedule, and on manual dispatch. It shares the release-promotion concurrency\ngroup, so another promotion cannot move the floating refs between runtime\nresolution and evidence comparison.\n\nThis is a post-publication consumer canary, not a release bootstrap. Source\nverification still runs the current commit, and\n`buildchain-ref-promotion.yml` still passes the verified exact SHA into the\npromotion workflow. Patrol, dev-merge, repair, and promotion defaults remain on\nstable or exact refs so a broken alpha cannot prevent Buildchain from publishing\nits fix. When Buildchain opens a new major, inventory validation requires this\nworkflow's fixed GitHub `uses` refs to move from `vN`/`vN-alpha` to the new\nmajor; GitHub does not allow expressions in a reusable-workflow `uses` ref.\n\nIf `dev/vX/vX.Y` has already advanced before generated alpha version-state\nbookkeeping can sync back, Buildchain records `skipped-non-fast-forward` for the\ndev sync and still completes the exact and floating alpha tags for the reviewed\nalpha commit. Later dev changes must go through their own dev-to-alpha\npromotion instead of rewinding dev. The normal path is direct: after alpha\nmerges, Buildchain applies the generated version-state commit to alpha and then\nfast-forwards dev to the same commit without a human version-state PR.\n\nIf alpha finalization is resumed after generated version-state bookkeeping was\npartially applied, Buildchain accepts the current alpha head as the generated\ncommit, or as a historical merge commit that contains the recorded release\nmaterial. An already-created exact alpha tag may point at the transaction\nrelease/material SHA or at the finalized alpha head; missing floating alpha\ntags are retried before the transaction becomes `complete`.\n\n## Release Semantics\n\nA release merge is:\n\n```text\nalpha/vX/vX.Y -> release/vX/vX.Y\n```\n\nBuildchain then:\n\n1. Finds the same-patch alpha tag that was tested.\n2. Checks that the release source tree matches that alpha tag tree, excluding\n   only generated version-state differences.\n3. Writes final release version state such as `vX.Y.Z`.\n4. Verifies the generated release tree.\n5. Creates or reuses the exact release tag `vX.Y.Z`.\n6. Moves `release/vX/vX.Y` to the exact release commit.\n7. Moves `vX.Y` to the exact release commit.\n8. Moves `vX` when this minor line should be the stable major entrypoint.\n9. Prepares the next alpha version-state commit, such as\n   `vX.Y.(Z+1)-alpha.0`.\n10. Moves `alpha/vX/vX.Y`, `dev/vX/vX.Y`, and `vX.Y-alpha` to that next alpha\n    commit.\n11. Moves `vX-alpha` to that next alpha only when this remains the highest published alpha minor.\n\nThe historical alpha tree comparison remains the default stable source gate.\nA promote-only stable run may accept a broader reviewed release PR only when\nthe downloaded RC passport proves that the PR's exact target tree is the tree\nthat completed the PR-stage build. Buildchain also requires the target commit\nto belong to a merged same-repository PR into the selected release branch and\nrecords the accepted commit, tree, RC source, alpha source, and PR as promotion\nevidence. A stale passport, a different target tree, a generated final release\ncommit, or an unreviewed target commit still falls through to the normal\nalpha-tree and declared version-state checks.\n\nThe production channel and the test channel therefore intentionally diverge\nafter release: production stays on the release commit, while alpha/dev continue\nat the next prerelease commit.\n\n### Stable Release Throttle And Canary Gate\n\nBuildchain's own stable channel has an additional pre-publication gate. It is\nevaluated after the PR-stage release candidate has been resolved and before the\npublish-gate ref, package registry, exact stable tag, or floating stable refs\nare mutated. Train refs and alpha promotion do not execute this gate.\n\nAll alpha and release promotions first run a metadata-only release-candidate\npreflight after queued-intent revalidation. The preflight uses the same resolver\nand exact target SHA as the publication job, but does not download payloads or\ninstall the candidate repository dependencies. Missing channel PRs, stale\nworkflow runs, expired passport pairs, and insufficient payload artifact sets\ntherefore fail before the full promotion job starts. The publication job still\ndownloads and validates the exact evidence again at the trust boundary; the\npreflight moves failure earlier without weakening the final check.\n\nThe policy is versioned in `.buildchain/stable-release-policy.json`. A stable\ncandidate is allowed only when all of these facts are true:\n\n- the candidate resolves to an immutable exact alpha tag and its GitHub\n  prerelease timestamp;\n- at least 24 hours have passed since the preceding stable patch on the same\n  minor line;\n- the preceding stable-to-alpha comparison contains a product or public\n  contract path, not only version, test, evidence, or retrospective changes;\n- the version-bound impact record has a non-empty summary and at least one\n  surface impact;\n- the `Build Surface Fixture` release-candidate run succeeded;\n- `site-libkungfu-dev` completed its no-apply `Buildchain Stable Canary` and an allowed\n  maintainer attested that successful run on the exact alpha SHA through the\n  `buildchain-canary/site-libkungfu-dev` commit-status context;\n- the canary runtime input is exactly the candidate alpha tag or the 40-character\n  commit SHA resolved from that tag; a successful status pointing at another\n  workflow, repository, tag, floating ref, or SHA is rejected as mismatched;\n- at least one hour has elapsed after the last required canary completed.\n\nThe machine report is written to\n`.buildchain/release-passport/stable-release-gate.json`. A passing report is\nuploaded with the stable release passport. A blocked run writes the same report\nbefore failing, so the missing or stale condition is inspectable without\nopening a publication transaction.\n\nGitHub's Actions run REST object does not expose `workflow_dispatch` inputs.\nBuildchain therefore verifies the run's `workflow_id` against the authoritative\nworkflow metadata, then reads the exact runtime from the workflow-owned\n`<workflow name> / <runtime ref>` run-name when no input field is available.\nAn explicit API input, when present, remains authoritative and cannot be\noverridden by the display name.\n\nThe cooldown is a minimum interval, not an instruction to release every day.\nCompatible work should still be batched until a stable release has a concrete\nconsumer need. Changing the interval, canary set, attestors, product path\nboundary, or soak time is a reviewed policy change.\n\nRepositories that want a predictable scheduled stable window can use\n[`Stable Candidate Patrol`](stable-candidate-patrol.md). It persists each exact\nalpha independently, qualifies it after repository-declared checks and soak,\nand selects the newest qualified non-revoked candidate. A newer soaking alpha\ndoes not invalidate an older qualified candidate. The selected tree enters the\nexisting strict `publish-gate/release/<line>/<version> -> release/<line>` PR\npath, so scheduled selection changes release intent timing without weakening\nsource locks, review, verification, publish transactions, or passports.\n\nIf release finalization is resumed after generated version-state bookkeeping was\npartially applied, Buildchain applies the same recovery rule: the current\nrelease head may be the generated commit, or a historical merge commit that\ncontains the recorded release material, existing exact tags and alpha/dev refs\nare accepted when they match the transaction, and missing floating `vX.Y` or\n`vX` tags are retried idempotently before completion.\n\nOnce the durable release transaction is `complete` and the exact/floating\nstable refs have moved, next-alpha preparation is post-release bookkeeping. A\nfailure there records `deferred-post-release-bookkeeping` and\n`next-anchor-required` instead of retroactively reporting the stable release as\nfailed. Generated next-alpha merges use the current dev tree as their base and\noverlay only declared version-state paths, preserving concurrent dev changes.\n\n## Major Gate Semantics\n\nA major gate merge is:\n\n```text\nrelease/vX/vX.Y -> publish-gate/major\n```\n\n`publish-gate/major` is the explicit replacement for the older ABV `main`\nchannel. The name is intentionally operational: it is a gate for a rare\nadministrator decision, not the active trunk. Keeping this decision in the same\nPR UI as alpha and release promotion keeps the human workflow simple while\navoiding the misleading meaning of `main`. The older `major-gate` branch name is\na compatibility alias only.\n\nBuildchain then:\n\n1. Verifies the source is a merged same-repository PR from a protected release\n   line into `publish-gate/major`.\n2. Writes the next major production version state, such as `v(X+1).0.0`.\n3. Creates or reuses the exact release tag `v(X+1).0.0`.\n4. Moves `publish-gate/major` and `release/v(X+1)/v(X+1).0` to that release commit.\n5. Moves `v(X+1).0` and `v(X+1)` to that release commit.\n6. Prepares the next alpha version-state commit, such as\n   `v(X+1).0.1-alpha.0`.\n7. Moves `alpha/v(X+1)/v(X+1).0`, `dev/v(X+1)/v(X+1).0`, and\n   `v(X+1).0-alpha` to that next alpha commit.\n\nChecking out `publish-gate/major` should therefore look like a frozen release\nstate, not like a branch where day-to-day source work continues. Day-to-day\nsource work continues on `dev/vX/vX.Y`.\n\n## Protected Dev Branches\n\n`dev/vX/vX.Y` is a protected development channel, not a scratch branch. Normal\nsource changes should be made on work branches such as `feature/*`, `fix/*`,\n`chore/*`, `docs/*`, `ci/*`, or `refactor/*`, then reviewed through a pull\nrequest into the target dev line.\n\nThis keeps the earliest development channel audit-friendly:\n\n- the version line being changed is visible in the PR base branch;\n- CI and required checks run before the channel moves;\n- branch protection can prevent direct pushes and stale merges;\n- later `dev -> alpha -> release` promotion inherits a reviewable source\n  lineage instead of trying to reconstruct how the dev branch changed.\n\nWhen required checks take longer than the normal dev-channel commit interval,\nclassic strict up-to-date protection can become a non-converging retry loop:\neach base update invalidates a completed check set and rebasing restarts the\nsame slow checks. Buildchain supports GitHub merge queues for that channel\nshape. The queue validates the projected merged result and serializes the final\nref update, so concurrent channel movement no longer invalidates the candidate.\n\nGitHub Merge Queue does not by itself decide which candidate may spend a long\nnative proof before enqueue. Repositories with that workload use the\n[Dev Delivery Warrant Queue](dev-delivery-warrant.md) as the durable,\nFIFO-aging scheduling and fencing authority before native queue admission. A\nselected Warrant owns one complete delivery attempt and later candidates remain\nvisibly queued; GitHub still owns the exact `merge_group` proof and final ref\nmutation. Workflow concurrency remains only a process critical section and is\nnot fairness or ownership authority.\n\nEvery required workflow must handle both `pull_request` and `merge_group`\nbefore the queue is enabled. Queue runs do not provide\n`github.event.pull_request`; required workflows must use the checked-out\n`github.sha` or event-neutral source facts. The governance command is dry-run by\ndefault and refuses to enable a queue when a declared required workflow lacks\neither trigger or still reads the pull-request-only payload directly:\n\n```bash\nbuildchain dev merge-queue \\\n  --repository owner/repository \\\n  --branch dev/v4/v4.0 \\\n  --workflow .github/workflows/source-acceptance.yml \\\n  --workflow .github/workflows/affected-native-pr.yml \\\n  --bypass-app dedicated-release-app\n```\n\nAfter reviewing the plan, repeat with `--apply`. Buildchain creates or updates\nan exact-branch `merge_queue` ruleset first, then changes only the classic\nrequired-status-check policy from strict to loose. Reviews, administrator\nenforcement, conversation resolution, required check identities, force-push\nprotection, and deletion protection remain owned by the existing branch\nprotection. The ruleset uses the first merge method that the repository itself\nallows, and fails closed when the repository has no enabled merge method.\nRe-running the command is idempotent.\n\nThe repository policy can be declared once instead of repeated as CLI flags:\n\n```toml\n[governance.dev.merge_queue]\nmode = \"inherit\"\nrequired_workflows = [\".github/workflows/verify.yml\"]\n```\n\n`enabled` explicitly requires Buildchain to create or update an exact-branch\nqueue; `inherit` copies queue parameters and bypass actors from the repository's\ncurrent default dev branch; `disabled` prevents automatic queue creation. An\nabsent declaration behaves as `inherit` during release-line bootstrap so a new\nmajor or minor line does not silently lose governance already active on the\nprevious line. Required status-check identities still come from the new\nbranch's own classic protection rather than being copied from the old branch.\n\nMerge-queue rules also reject generated post-publish version-state ref updates.\nWhen the sealed promotion workflow uses a dedicated GitHub App, user, or team\nalready declared by release governance, repeat `--bypass-app`, `--bypass-user`,\nor `--bypass-team` to project that exact actor into the ruleset. Bypass actors\nare never inferred and broad repository or organization roles are not accepted.\nThis keeps ordinary feature PRs on the predecessor-aligned queue path while the\nsealed publication authority can finish its machine-verified bookkeeping. The\ndry-run receipt exposes the exact actor IDs before `--apply` changes GitHub.\n\nBuildchain provides the reusable\n`.github/workflows/dev-pr-auto-merge.yml` workflow for repositories that want a\nscheduled or manual \"merge ready dev PRs\" pass. The consumer repository owns\nthe trigger schedule, but the merge decision is declared through workflow\ninputs: target dev branch, required status/check names, ready and block labels,\nallowed work-branch prefixes, review requirements, maximum merges per run,\nmerge method, and dry-run mode.\n\nAgent delivery uses the targeted Buildchain command instead of relying on a\nscheduled scan:\n\n```sh\nbuildchain dev pr-admit \\\n  --repository kungfu-systems/example \\\n  --branch dev/v3/v3.0 \\\n  --pull-request 123 \\\n  --expected-head 0123456789abcdef0123456789abcdef01234567\n```\n\nThe default is a mutation-free plan. After reviewing it, add `--execute` to\nestablish the configured readiness label for only that PR and exact head, read\nthe state back, and attempt native queue admission. Repeating execute is\nidempotent: an exact matching queue entry is adopted, not submitted again. A\nstale head or base, fork, draft, block label, missing approval, failed check,\nactive predecessor, or rejected enqueue exits nonzero. Execute mode also\ncreates or updates an exact-head PR comment and named commit status containing\nthe current state, reason, receipt root, and copyable next action. The JSON\nreceipt remains the complete content-addressed evidence.\n\nGitHub auto-merge is observed but is never readiness or admission authority.\nApproval plus green checks plus auto-merge enabled does not qualify a PR that\nlacks explicit Buildchain delivery intent. The targeted workflow interface\nexposes the same contract through `expected-pr-number` and\n`expected-head-sha`; cadence patrol runs leave those inputs empty.\n\nThe workflow defaults are conservative. A PR is skipped unless it targets the\nconfigured dev line, is not a draft, has the ready label, has no block label,\ncomes from the same repository, uses an allowed work-branch prefix, has a\ncurrent approval, is mergeable, and has the configured required checks passing.\n`landing-mode: auto` reads the target branch's native merge-queue state. When a\nqueue exists, Buildchain never calls the direct merge endpoint: it admits at\nmost one PR against the observed target-branch SHA and immutable PR head, then\ncalls GraphQL `enqueuePullRequest` with `expectedHeadOid`. GitHub's\n`merge_group` checks remain the final authority for the projected merge.\n\nThe admission receipt records the expected and observed base/head SHAs, policy\nchecks, decision, reason, and active predecessor. Buildchain re-reads the base,\nhead, mergeability, and native queue immediately before enqueueing. Base or\nhead drift fails closed, an active queue entry blocks admission, and a rejected\nready predecessor leaves its PR open while later PRs receive\n`blocked-by-predecessor`. Workflow concurrency serializes Buildchain-owned\nadmission runs; GitHub still owns the atomic queue and protected-ref update.\nRepositories may explicitly select `landing-mode: direct` only when the target\nbranch has no native queue. Queue presence always disables the direct path.\n\nFor slow candidates on a frequently advancing dev line, the optional\n[Dev Delivery Warrant Queue](dev-delivery-warrant.md) adds durable FIFO plus\naging scheduling before native queue admission. It separates reusable source\nqualification from exact merge-group integration, uses expected-old Git-ref\nupdates and fenced leases, and keeps the PR head unchanged when only dev moves.\nThe reusable caller supports `off`, read-only `shadow`, and fail-closed\n`required` rollout modes. GitHub Merge Queue remains the final protected-ref\nauthority in every mode.\n\nThe canonical consumer required check context is `check / check`, matching the\nreusable workflow call plus its `check` job. Buildchain's own `Verify` workflow\nemits the repository-local context `check`, so Buildchain self-promotion,\nrelease-line bootstrap, and dogfood patrol wrappers pass `check` explicitly.\nRelease governance preserves the exact context emitted by the repository and\nrecords branch-protection policy before/after facts; it does not rewrite one\ncontext shape into the other. Consumer repositories can keep their context\nstable while changing the actual verification command declaratively in\n`buildchain.toml`:\n\nBefore a release caller is merged, consumers should also verify its exact\nreusable-workflow call contract. The checker reads the caller and an already\nchecked-out exact Buildchain commit; it never resolves a floating ref or starts\na release. It rejects unknown or missing inputs and secrets, literal type\ndrift, insufficient permissions, untrusted event classes, and a caller pin that\ndoes not equal the checked callee commit. Defaults, workflow bytes, and the\ncomplete interface are bound into `contractRoot`; the receipt additionally\nbinds the caller commit/tree and both workflow digests.\n\n```sh\nnode .buildchain/workflow-contract-runtime/scripts/workflow-call-contract.mjs check \\\n  --caller-root . \\\n  --caller-workflow .github/workflows/release-new-version.yml \\\n  --caller-repository kungfu-systems/example \\\n  --job promote \\\n  --callee-root .buildchain/workflow-contract-runtime \\\n  --callee-workflow .github/workflows/release-candidate-promote.yml \\\n  --callee-repository kungfu-systems/buildchain \\\n  --trusted-event workflow_dispatch \\\n  --trusted-event pull_request:closed \\\n  --expected-contract-root \"$(cat .buildchain/release-call-contract-root)\" \\\n  --output .buildchain/workflow-call-receipts/release-new-version.json\n```\n\nThe checkout at `.buildchain/workflow-contract-runtime` must use the same\n40-character SHA written in the caller's `uses:` edge. To accept an intentional\ncontract change, first run without `--expected-contract-root`, review the full\ndiagnostic and exact coordinates, then replace only the committed root. The\nordinary PR check runs this command before any candidate or promotion dispatch.\nLocal pre-commit rehearsal may add `--allow-dirty`; that result is marked\n`receiptReusable: false` and cannot replace the clean exact-source receipt.\n\n```toml\n[lifecycle.install]\ncommand = \"cargo fetch --locked\"\n\n[lifecycle.verify]\ncommand = \"cargo test --workspace --locked\"\n```\n\nConsumers that want Buildchain to own the check wrapper can call\n`.github/workflows/check.yml@v3`. The wrapper runs the declared\n`lifecycle.install` and `lifecycle.verify` stages and fails the `check` job when\neither declaration is missing or the command exits non-zero.\n\nDevelopment pull requests that need source acceptance without product build or\nartifact verification can opt into `mode: source`. That mode runs only\n`lifecycle.install` and `lifecycle.check` on GitHub-hosted `ubuntu-24.04` while\npreserving the stable `check / check` required-check context. Existing callers\nremain on `mode: verify` by default, and callers may set\n`upload-artifacts: false` without weakening the job conclusion.\n\nTypical consumer wrapper:\n\n```yaml\nname: Merge Ready Dev PRs\n\non:\n  schedule:\n    - cron: \"17 * * * *\"\n  workflow_dispatch:\n    inputs:\n      dry-run:\n        type: boolean\n        default: true\n\njobs:\n  merge-dev:\n    uses: kungfu-systems/buildchain/.github/workflows/dev-pr-auto-merge.yml@v3\n    permissions:\n      contents: write\n      pull-requests: write\n      checks: read\n      statuses: write\n    with:\n      target-branch: dev/v3/v3.0\n      required-status-checks: check / check\n      queue-admission-context: Queue admission lease\n      ready-label: ready\n      block-labels: blocked,do-not-merge\n      max-merges: 1\n      landing-mode: auto\n      dry-run: ${{ inputs.dry-run || false }}\n```\n\nWhen the protected branch requires a merge-group-only queue lease, the wrapper\nposts that configured context as a temporary success status on the exact PR\nhead only after the ready, review, and required-check gates pass. It then\nenqueues with `expectedHeadOid`; a rejected enqueue rewrites the temporary\nstatus to failure, while the merge group must still produce its own final check.\n\n## Buildchain Patrol\n\n`dev-pr-auto-merge.yml` remains the focused merge primitive. For repositories\nthat want a stable day-to-day operations contract, Buildchain also exposes a\npatrol workflow family:\n\n| Workflow | Intended cadence | Default intent |\n| --- | --- | --- |\n| `.github/workflows/patrol-daily.yml` | daily | lightweight inspection plus ready dev PR maintenance |\n| `.github/workflows/patrol-weekly.yml` | weekly | release-state, passport, gate, and stale-state health checks as they are added |\n| `.github/workflows/patrol-monthly.yml` | monthly | governance, permission, branch-protection, and workflow drift checks as they are added |\n| `.github/workflows/patrol-observed-evidence.yml` | caller-selected schedule | validated immutable observation plus atomic last-known-good publication; no per-refresh PR |\n| `.github/workflows/stable-candidate-patrol.yml` | repository-selected release window | qualify immutable alpha candidates and open the exact source-lock stable PR |\n\nThe cadence names describe patrol intensity, not release cadence:\n\n- daily patrol can run every day without implying a daily release;\n- weekly patrol is for medium-cost maintenance and audit checks;\n- monthly patrol is for structural drift checks that should not block ordinary\n  development velocity.\n\nEvery cadence result is typed `runKind: cadence-patrol` with\n`qualification: false`. A run with no open candidates reports\n`no-op-no-candidates`; a run where every candidate is skipped reports\n`no-op-all-skipped`. Either no-op can keep maintenance green, but neither is a\ndelivery qualification, a targeted admission receipt, or evidence that an\nexpected PR entered the merge queue.\n\nStable Candidate Patrol is separate from those maintenance cadences because its\ncaller-owned cron is a release-intent window. Its candidate ledger and selection\nremain generic; registry-specific side effects still run through the normal\nrepository `lifecycle.publish` transaction. See\n[`stable-candidate-patrol.md`](stable-candidate-patrol.md).\n\nObserved data that is mechanically regenerated and path-scoped uses the\nseparate [`Observed Evidence Patrol`](observed-evidence-patrol.md) contract.\nIts one-time mechanism changes remain reviewed, while steady-state snapshot\nrefreshes publish directly from trusted default-branch schedule/manual callers.\n\nConsumers should schedule thin callers and keep their YAML declarative. For\nexample:\n\n```yaml\nname: Buildchain Daily Patrol\n\non:\n  schedule:\n    - cron: \"17 2 * * *\"\n  workflow_dispatch:\n\njobs:\n  patrol:\n    uses: kungfu-systems/buildchain/.github/workflows/patrol-daily.yml@v3\n    with:\n      dry-run: false\n      max-actions: 1\n```\n\nWeekly and monthly callers use the matching wrapper:\n\n```yaml\njobs:\n  patrol:\n    uses: kungfu-systems/buildchain/.github/workflows/patrol-weekly.yml@v3\n    with:\n      dry-run: true\n```\n\nAll three wrappers default to the `v3` floating Buildchain runtime. When\n`target-branch` is omitted, the caller's current/default branch selects the\nactive semver dev line, so consumers do not pin patrol to a stale minor branch.\nThe separate workflow names keep consumer schedules readable and stable while\nBuildchain adds new checks behind the cadence wrappers.\n\nBranch and pull-request residue uses the separate\n[`Engineering Housekeeper`](engineering-housekeeper.md) contract. Its reusable\nsurface remains report-first, while Buildchain's committed daily, weekly, and\nmonthly callers run unattended apply across all discovered protected mainlines.\nOnly the positive temporary-development allowlist is mutable; unknown branch\nfamilies remain report-only. Every apply still requires the caller's explicit\ntwo-part policy inputs, exact provider-state revalidation, scoped job\npermissions, and rooted plan/report/receipt evidence.\n\n## Package-Manager Adapters\n\nOld ABV assumed JavaScript repositories with root version state and often\nLerna. Buildchain keeps the version-state contract but does not assume every\nrepository is yarn/Lerna.\n\nThe promotion action discovers and updates:\n\n- root `package.json`;\n- `lerna.json`;\n- package manifests from `package.json` workspaces;\n- package manifests from `lerna.json` packages;\n- package manifests from `pnpm-workspace.yaml`.\n\nIt then runs the repository's detected package manager semantics where needed:\n\n- pnpm repositories use pnpm-oriented workspace discovery;\n- npm repositories use npm/package-lock semantics where present;\n- yarn repositories use yarn-style metadata where present.\n\nFor Buildchain itself, version state is required. For a consumer repository that\nhas no package manifest, the same action can degrade to ref-only behavior only\nwhen that is explicitly allowed by the caller.\n\n## Lifecycle Configuration\n\n`.buildchain/buildchain.toml` is the v3 user configuration format. It lets a repository\ndeclare version-state files and lifecycle commands without pretending every\nproject is a Node workspace. Supported version files include JSON, TOML, and\nregex-based files such as `CMakeLists.txt` or `conanfile.py`.\n\nThe promotion action consumes `version.files`, optional anchored/manual\n`version.derived_files`, and `lifecycle.verify`.\nThe verify stage runs after generated version-state changes are applied locally\nand before any release refs move. If `verification-command` is passed directly\nto the action, that explicit command overrides `lifecycle.verify`.\n\nAnchored/manual repositories may use `version.derived_files` for committed\nversion witnesses that are regenerated by `lifecycle.version-state`. The\nrelease-candidate build verifies those witnesses before heavy builds and records\ntheir digests with the exact alpha and release tree identities. Promotion then\naccepts only declared version files, the anchor manifest, and those derived\nfiles as differences from the tested alpha tree; release passports preserve the\nsame material binding.\n\nProtected release-line branches keep their normal human review gate. Managed\n`dev/vN/vN.M`, `alpha/vN/vN.M`, and `release/vN/vN.M` branches are configured\nwith one required approving review, required GitHub Actions checks, administrator\nenforcement, conversation resolution, no force pushes, and no deletions. Each\ntarget uses the exact check set, GitHub App identity, and strictness declared by\nthe governance authority descriptor. The\nreusable `release-candidate-promote.yml` wrapper defaults\n`branch-protection-bypass-apps` to `github-actions`, which lets the workflow's\nautomation identity apply generated version-state or post-publish channel\nbookkeeping after the reviewed channel PR has merged. Direct\n`promote-buildchain-ref` callers may opt into that one controlled bypass with\n`branch-protection-bypass-apps: github-actions`; every other App slug and all\nuser or team bypass actors are rejected. Before\npatching a protected generated bookkeeping ref, the action creates the\nfull configured required-check set on the exact generated version-state commit, so strict\nstatus checks are satisfied by machine-verifiable Buildchain evidence rather\nthan a human PR. The protected ref PATCH itself uses the generated ref update\ntoken; the reusable wrapper binds it to the run-scoped `github.token`. If direct generated\nrelease finalization bookkeeping is still rejected, Buildchain creates or\nreuses a same-repository `buildchain/version-state/*` PR and records\n`finalization-needed=true` in the durable transaction output. Strict alpha\nfollows the same provider-enforced PR path for its alpha and dev bookkeeping.\nThe PR remains subject to the declared review, required checks, and merge-queue\npolicy; publication resumes idempotently after that protected transaction\nlands.\n\nFor a stable release, the wrapper also checks out the exact current development\nchannel into `.buildchain/reconciliation/dev`. When the prepared next-alpha\ncommit cannot fast-forward dev because reviewed work landed concurrently, the\npromotion action applies the next version to that checkout, regenerates every\ndeclared derived version-state file, reruns the verification lifecycle, and\nonly then creates the two-parent reconciliation commit. A checkout/current-ref\nSHA mismatch blocks reconciliation instead of committing stale projections.\nBuildchain's own promotion workflow accepts only\n`BUILDCHAIN_PROMOTION_BYPASS_APPS=github-actions`, defaulting to that exact App\nwhen the variable is absent. Buildchain's release-line bootstrap uses the\nadministrator-scoped promotion token only to configure protection; branch\ncreation and generated ref updates use the run-scoped token. New channel\nprotection binds required checks to GitHub Actions App id `15368`, enables Code\nOwner, stale-review, and latest-push review gates, and admits no user or team\nbypass actor.\n\n## What This Guarantees\n\nWhen the loop succeeds, maintainers and consumers can rely on these facts:\n\n- every production release has an exact tag such as `v3.0.2`;\n- every production minor line has a floating tag such as `v3.0`;\n- every selected stable major has a floating tag such as `v3`;\n- every next-major release is driven by a reviewed `release -> publish-gate/major` PR,\n  not a hidden manual button;\n- every test channel has an exact alpha tag such as `v3.0.3-alpha.0`;\n- every alpha minor line has a floating tag such as `v3.0-alpha`;\n- every major with a published alpha has a cross-minor floating tag such as `v3-alpha`, owned by its highest published alpha minor;\n- version manifests match the tag visible from the same commit;\n- production releases are derived from the alpha tree that was tested;\n- manual non-dry-run promotion cannot bypass PR review and verification;\n- flow-internal automation bypasses apply only to declared GitHub Apps, users,\n  or teams on Buildchain-managed channel branch protection, while one-review\n  protection remains enforced for humans;\n- admin users cannot make a channel promotion valid by temporarily bypassing\n  branch protection.\n\nThis is the practical meaning of \"governance closed loop\" in Buildchain: the\ndecision, code, version state, and Git refs close over the same evidence chain.\n\n## What This Does Not Do\n\nBuildchain release promotion does not embed registry clients or product-specific\npublish logic. When publish transactions are enabled, `promote-buildchain-ref`\ncan run the consumer's `lifecycle.publish` command and own the transaction,\nevidence validation, durable recovery state, and ref finalization order. The\nconsumer repository still owns registry truth: npm, PyPI, OCI, S3, Conan, CMake\npackaging, download pages, dist-tags, and similar side effects must be\nimplemented by project lifecycle commands that emit Buildchain publish evidence.\n\nDurable transaction recovery is also bound to the exact publication version\nplanned for the current run. An unfinished transaction may be resumed from the\ncurrent source or its history only when its recorded version matches that plan;\nan older failed transaction that happens to be an ancestor cannot reserve its\nold exact tag for a newer package publication.\n\nThe exact tag is also part of the durable transaction identity. If an anchored\npackage publication completed registry side effects under a stale internal tag\nselection, a retry may rebind the unfinished `published` or `finalizing`\ntransaction to the newly planned internal tag only when the package version,\nsource, release material, target, complete artifact set, and evidence all still\nmatch; the stale tag must not point at the transaction, and the requested tag\nmust be absent or already point at accepted release material. This preserves an\nimmutable tag that represents a completed transaction while allowing a tag\ncollision discovered after registry publication to recover without republishing.\n\nFor package publish transactions, the immutable public version tag points to\nthe transaction `source_sha`, so registry source metadata such as npm `gitHead`\nand the Git tag identify the same source commit. Protected branches and mutable\nchannel tags continue to point to the generated `release_sha`. Recovery accepts\nolder completed transactions whose exact tags already point to recorded release\nor release-material SHAs, but new tags are source-bound.\n\nEvery Buildchain publish model that can run registry side effects must bind the\npublish entrypoint to an immutable `publish-gate/*` source lock. The reusable\n`release-candidate-promote.yml@v3` wrapper creates or updates that gate ref and\npasses `require-publish-source-lock`, `publish-source-ref`,\n`publish-source-sha`, and `publish-source-locked` to\n`promote-buildchain-ref`. Direct action callers must pass the same four inputs\nfrom the reusable build outputs. Workflows that only collect passports or run\ndry-run package checks do not move publish refs and are not publish-gate\npublication models. A dry-run of `release-candidate-promote.yml` computes and\nreports the exact `publish-gate/*` source lock that a real promotion would use,\nbut does not read, create, or move that ref.\n\nSemver GitHub Release publication is owned by `promote-buildchain-ref`, not by\nconsumer shell glue. Consumers normally use the `release-candidate-promote.yml`\ngenerated channel router, where GitHub Release publication is enabled by default and can be\ndisabled with `github-release: false`; the wrapper passes that declaration to\nthe action. After the publish transaction reaches `complete`, Buildchain creates\nor updates the public GitHub Release and uploads the generated\n`buildchain.release.json`, release-passport assets, and publish evidence. The\nauthoritative publication channel controls GitHub metadata: alpha is marked\n`prerelease=true` and `make_latest=false`; release/stable/major is marked latest.\nSemver tag syntax remains the fallback for ordinary callers without explicit\npublication intent. For anchored/manual package releases, the public\nrelease tag defaults to `v<publishedVersion>` while the internal exact\ntransaction tag remains in the release passport and release-state ref. This is\nthe supported path for downstream\n`release.published` propagation across semver, major, and promote-only release\ncandidate publication models.\n\nPublished GitHub Release assets are immutable evidence. A repeated promotion\npreserves an existing asset when its SHA-256 digest matches the regenerated\nbytes, uploads only missing assets, and fails with an immutable-release\ncollision when a same-name asset has different bytes. It never deletes and\nreplaces an existing asset during retry or duplicate workflow delivery.\nAn explicit candidate recovery whose validated receipt records an already\ncomplete transaction instead verifies the existing public Release Passport\nbundle and preserves its Buildchain-owned evidence generation. Product payload\nbytes remain digest-bound to the restored candidate, and missing product assets\nalone may be filled from that sealed bundle. This exception is unavailable to\nordinary reruns or receipts from earlier transaction states.\n\nProduct payloads are included only through the explicit\n`github-release-payload-patterns` input. Patterns match basenames inside the\ndownloaded PR-stage RC payload bundle; zero matches or duplicate public\nbasenames fail closed. This preserves the exact PR-built bytes instead of\nrebuilding archives during promotion.\n\nConsumers with a signed well-known discovery document can additionally provide\n`publication-commit-command`. The advanced promotion workflow validates its\ntopology before any publish-gate or release mutation, then runs it only after\nthe GitHub Release and its immutable payload/passport assets exist. The command\nmust publicly read back the exact new payload root and emit\n`kungfu-buildchain-publication-commit-evidence/v1`; that evidence is copied\ninto the controller artifact and exposed as workflow outputs. The previous\nauthority must remain valid on every failure. Deferred standalone binary\ndistribution is incompatible with this mode because the discovery authority\nmust be the final product mutation.\n\nBuildchain also does not maintain bare exact tags such as `1.0.0`. The supported\nexact release and alpha refs are v-prefixed:\n\n```text\nv3.0.0\nv3.0.1-alpha.0\n```\n\n## Operational Reading Order\n\nWhen debugging or extending release behavior, read in this order:\n\n1. `docs/release-flow.md`\n2. `.github/workflows/release-verify.yml`\n3. `.github/workflows/buildchain-ref-promotion.yml`\n4. `.github/workflows/release-candidate-promote.yml`\n5. `.github/workflows/.release-candidate-promote.yml`\n6. `actions/promote-buildchain-ref/README.md`\n7. `actions/promote-buildchain-ref/src/`\n8. `docs/migration-inventory.md`\n\nThat path gives the policy first, the workflow trigger second, and the action\nimplementation last."
    },
    {
      "id": "manual:release-passport",
      "title": "Release Passport",
      "route": "/docs/release-passport",
      "category": "manual",
      "capabilityGroup": "release-passport-trust",
      "audience": [
        "release-operator",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "docs/release-passport.md",
      "digest": "sha256:4ce3c2edb095d7a103b3b1d22033b4ac3709ce709f8990b21995d491898bd051",
      "headings": [
        {
          "level": 1,
          "title": "Release Passport",
          "anchor": "release-passport"
        },
        {
          "level": 2,
          "title": "Contract",
          "anchor": "contract"
        },
        {
          "level": 2,
          "title": "Runner Policy",
          "anchor": "runner-policy"
        },
        {
          "level": 2,
          "title": "CLI",
          "anchor": "cli"
        },
        {
          "level": 3,
          "title": "KFD-1 contract-world release gate",
          "anchor": "kfd-1-contract-world-release-gate"
        },
        {
          "level": 3,
          "title": "KFD-2 release trust passport audit",
          "anchor": "kfd-2-release-trust-passport-audit"
        },
        {
          "level": 3,
          "title": "KFD-3 collaboration-interface release gate",
          "anchor": "kfd-3-collaboration-interface-release-gate"
        },
        {
          "level": 3,
          "title": "KFD support projection",
          "anchor": "kfd-support-projection"
        },
        {
          "level": 3,
          "title": "Floating Buildchain contract lock",
          "anchor": "floating-buildchain-contract-lock"
        },
        {
          "level": 2,
          "title": "Binary Distribution",
          "anchor": "binary-distribution"
        }
      ],
      "markdown": "# Release Passport\n\nBuildchain Release Passport is the core product mechanism: a mature product\nrelease record for artifacts that users or agents depend on.\n\nThe protocol is GitHub-native because it uses protected refs, reviewed\npromotion PRs, exact tags, GitHub Releases, npm Trusted Publishing, and\nmachine-readable evidence. A project can keep its existing build system and use\nBuildchain to make the release record auditable.\n\nLinux release artifacts can additionally carry a GitHub keyless attestation\npolicy in `githubArtifactAttestations[]`. The policy binds the exact subject,\nconsumer source, original Linux build evidence, immutable Buildchain signer\nworkflow, and minimum permissions before the provider attestation exists. The\ncompleted provider bundle and attestation identifier remain separate evidence,\navoiding a Passport hash cycle. See\n[`github-artifact-attestation.md`](github-artifact-attestation.md).\n\nRelease-candidate and final passports may also include compact\n`controllerReceipts[]` references. These bind a real reusable-workflow receipt\nto its plan digest, consumer source SHA, and exact Buildchain runtime SHA; they\ndo not infer execution evidence from a green job. See\n[`controller-evidence.md`](controller-evidence.md).\n\n## Contract\n\nThe release passport surface is a welded contract. Additive fields are allowed;\nbreaking semantic changes require a new major line.\n\nIndependent verifiers can pin two package-owned, standalone files without\nscraping this implementation:\n\n- `dist/site/schemas/release-passport-v1.schema.json` is the self-contained\n  JSON Schema for the Buildchain-owned envelope;\n- `dist/site/release-passport-check-manifest.json` names the normative checker,\n  required and conditional sibling evidence, local-resolution rules,\n  Buildchain aggregation fields, canonical KFD subsection schema authorities,\n  and forward-compatibility policy.\n\nThe same files are exported as\n`@kungfu-tech/buildchain/site/schemas/release-passport-v1.schema.json` and\n`@kungfu-tech/buildchain/site/release-passport-check-manifest.json`. The schema\nchecks the envelope shape. `buildchain verify release-passport` remains the\nnormative semantic checker: it resolves sibling evidence relative to the\npassport and fails closed on missing evidence, digest drift, or inconsistent\nrelease facts. Buildchain owns envelope aggregation; KFD retains schema and\ncompatibility authority for the `kfd-1`, `kfd-2`, and `kfd-3` subsections.\n\nP0 protocol artifacts:\n\n- `product-mechanism.json`\n- `buildchain.release.json`\n- `artifact-evidence.json`\n- `impact.json`\n- `agent-index.json`\n- `check-report.json`\n- `llms.txt`\n- `buildchain-release-bundle.json`\n- `buildchain-release-bundle.tar.gz`\n\n`buildchain.release.json` is the first file an agent should read. It points to\nartifact evidence, impact, recovery, product mechanism, and agent index facts.\nIt is also the unified release responsibility summary: when publish\ntransactions are used, the same passport records the package set, npm dist-tags,\nrelease source refs, release-state ref, anchor manifest, registry artifact\ndigests, trusted publishing evidence, and transaction result.\n\nAdditive passport sections:\n\n- `release`: public release tag, internal transaction tag, line, channel,\n  source SHA, target ref, release SHA, release material SHA, publish tooling\n  SHA, and durable release-state ref. Anchored/manual package releases use the\n  published package version for the public tag while preserving the internal\n  exact transaction tag for Buildchain recovery.\n- `versionImpact`: final patch/minor/major classification, source, and\n  rationale.\n- `surfaceImpacts`: per registered surface classification. The final impact is\n  the highest entry in this list.\n- `packageSet`: main package, platform packages, package-set order, registry,\n  versions, dist-tags, and package digests.\n- `anchorManifest`: anchored/manual version manifest path, digest, and fields.\n- `trustedPublishing`: provider, auth mode, workflow run evidence, and whether\n  trusted publishing was enabled.\n- `transaction`: durable Buildchain release transaction id, state, exact tag,\n  release SHA, state ref, and state SHA.\n- `surfaceTimestampPolicy`: the common Buildchain surface manifest timestamp\n  policy. It records real CI/release generation and publication times,\n  reproducibility inputs, source revision or source-date-epoch, and whether\n  timestamp fields participate in the release artifact digest.\n- `buildFacts`: module/product build facts that bind Git source digests,\n  version sources, lifecycle invocations, platforms, outputs, product\n  artifacts, and verification results to the release.\n- `artifacts`: release assets and registry artifacts in one list, each pointing\n  back to the evidence file that proves its digest. Registry artifacts retain\n  optional built/reused action, content and current-release coordinates,\n  platform/contract/parent metadata, and fail-closed verification evidence.\n- `invariantPassports`: product-owned invariant verification results admitted\n  by Buildchain. Each entry binds the product contract and registry roots,\n  semantic Passport root, exact clean source revision, complete platform\n  coverage, verdict, and residual risk. Buildchain owns release admission, not\n  the meaning of the product invariants.\n- `releaseEvidence`: typed references to product-owned JSON evidence copied\n  beside the Passport. Buildchain does not interpret product or legal meaning;\n  it binds each document's canonical JSON digest and exact source SHA, tag, and\n  channel, then independently re-verifies the sibling document.\n- `githubArtifactAttestations`: expected GitHub keyless attestation identities\n  for Linux release artifacts, including subject, caller source, original build\n  evidence, exact Buildchain signer workflow digest, and least-privilege\n  permissions. Dynamic provider evidence is stored beside the Passport.\n\nBuildchain's own binary lane also publishes observability artifacts generated by\nthe Buildchain logging API and CLI:\n\n- `buildchain-log-events-<platform>.jsonl`\n- `buildchain-log-summary-<platform>.json`\n- `buildchain-log-events-passport.jsonl`\n- `buildchain-log-summary-passport.json`\n\n`buildchain-release-bundle.tar.gz` is the single evidence bundle for consumers\nthat want one file for offline inspection, mirroring, or site ingestion.\n`buildchain-release-bundle.json` records its digest and the digest of every\nincluded file.\n\n## Runner Policy\n\nProduction binary distribution should use GitHub-hosted runners by default:\n\n- `ubuntu-24.04`\n- `macos-latest`\n- `windows-2022`\n\nThis keeps the public release path easy for other projects to reproduce.\nSelf-hosted runners remain compatibility fixtures: they prove that the protocol\ndoes not depend on GitHub-hosted images, but they are not the default public\ndistribution lane.\n\nThe protocol records runner facts in `artifact-evidence.json`; it does not\nrequire a specific runner class.\n\n## CLI\n\nGenerate a local release passport bundle from release assets:\n\n```bash\nbuildchain collect github-release \\\n  --tag v3.0.0 \\\n  --repository kungfu-systems/buildchain \\\n  --assets-dir dist \\\n  --publish-evidence-json .buildchain/release-evidence/v3.0.0/evidence.json \\\n  --transaction-json .buildchain/release-state/v3.0.0/state.json \\\n  --package-set-json package-set.json \\\n  --anchor-manifest-json libnode.release.json \\\n  --build-summary-json .buildchain/artifacts/build-summary.json \\\n  --build-facts-json .buildchain/facts/native-core.json \\\n  --build-facts-json .buildchain/facts/product.json \\\n  --platform-manifest-json .buildchain/artifacts/linux-x64/manifest.json \\\n  --platform-manifest-json .buildchain/artifacts/darwin-arm64/manifest.json \\\n  --platform-manifest-json .buildchain/artifacts/win32-x64/manifest.json \\\n  --dist-tag-evidence-json .buildchain/release-evidence/v3.0.0/dist-tag-evidence.json \\\n  --kfd-1-witness-json .buildchain/kfd/kfd-1/contract-world.witness.json \\\n  --kfd-2-claim-json .buildchain/kfd/kfd-2/release-claims.json \\\n  --invariant-passport-json product/release/qualification/invariant-passport.json \\\n  --github-artifact-attestation-policy-json .buildchain/github-artifact-attestation/policy.json \\\n  --output-dir .buildchain/release-passport\n```\n\nFor a promotion workflow, consumers can instead use\n`release-passport-invariant-passport-command`. The command must emit exactly one\ncanonical JSON object on stdout; for example:\n\n```yaml\nrelease-passport-invariant-passport-command: >-\n  node scripts/kungfu-invariant.mjs --collect-evidence .\n  --passport product/release/qualification/invariant-passport.json --json\n```\n\nSupplying the input makes the invariant gate mandatory. Command failure,\nmissing output, semantic-root drift, a non-`verified` verdict, incomplete\ncoverage, dirty source state, or a source revision unrelated to the release\nfails closed before release publication.\n\n`packageSet` records the ordered main-plus-platform package set.\n`publish.packages[]` summarizes each published npm package with its version,\ndist-tag, registry, role, platform, and digest, so agents do not need to stitch\nnpm facts back together from the lower-level evidence files.\n`buildSummary`, `platformArtifactManifests`, and `distTagPromotion` preserve the\nbuild and npm dist-tag evidence chain in the same passport. `buildFacts[]`\nrecords first-class module/product build facts, while\n`evidence.buildFacts[]` gives agents compact paths, SHA-256 hashes, contracts,\nids, and digests for quick audit traversal. See\n[`build-facts.md`](build-facts.md) for the fact collection and verification\ncontract.\n\n### KFD-1 contract-world release gate\n\nBuildchain can gate release artifacts with KFD-1 contract-world witnesses. This\nis a structured evidence protocol, not a request for consumers to shell out to\nthe Kungfu SDK. The authority chain is:\n\n1. KFD owns the standard metadata and schema ids in `@kungfu-tech/kfd`.\n2. Buildchain imports that metadata, owns the JSON formatting policy, freezes\n   the pre-build witness, and independently verifies post-build artifact bytes.\n3. Consumers only pass declarative witness JSON plus the artifact payloads their\n   build already produced.\n\nThis gives agents a concrete answer to \"what changed and can I trust it?\" A\nrelease can include both normal release passport evidence and KFD-1 evidence:\nthe passport proves the release transaction and artifacts are complete, while\nKFD-1 proves selected contract-world surfaces inside those artifacts are the\nbyte-for-byte surfaces the release intended to ship.\n\nThe witness JSON names the contract world, the canonical serialization policy,\nand the release surfaces that must be byte-for-byte verified:\n\n```json\n{\n  \"id\": \"kungfu-config\",\n  \"standard\": \"kfd-1\",\n  \"source\": \"kfd\",\n  \"contractWorld\": {\n    \"id\": \"kungfu-config\",\n    \"kind\": \"schema\",\n    \"name\": \"Kungfu config schema\"\n  },\n  \"canonicalPolicy\": {\n    \"format\": \"json\",\n    \"encoding\": \"utf-8\",\n    \"indent\": 2,\n    \"trailingNewline\": true\n  },\n  \"surfaces\": [\n    {\n      \"id\": \"kungfu-config-schema\",\n      \"artifactPath\": \"Contents/Resources/core/config.schema.json\",\n      \"expectedSha256\": \"...\"\n    }\n  ]\n}\n```\n\n`collect github-release` writes the result under the KFD-provided top-level key\ncurrently named `kfd-1`. Each contract world records the frozen witness digest,\nthe KFD package version, KFD schema ids, the Buildchain formatting policy, and\nthe actual artifact digest observed after the build. Verification fails closed\nwhen the witness is missing required facts, an artifact cannot be found, or a\npost-build digest does not match the frozen witness.\n\nFor the KFD repository itself, the KFD-1 witness can be a self-hosted standard\ncontract witness. In that mode KFD owns the standard-contract facts and\nBuildchain verifies declared source standard metadata, schemas, package\nexports, and site-consumption entrypoints against the packaged artifact. The\npassport records source and artifact hash summaries, schema ids, the\nself-hosting boundary, result, residual risk, and responsibility state for\nsource ownership, artifact verification, and release-passport proof ownership.\n\nGood KFD-1 witnesses should point at release payload surfaces, not at private\nbuild-machine state. For Buildchain itself, the natural witness set is the\nrelease passport schema and implementation, KFD-1 gate implementation,\n`dist/site/buildchain-contract.json`, and the npm package payload files that\nexpose the public CLI, reusable workflow/action contracts, and site facts.\nThe final `buildchain.release.json` file should not be used as an ordinary\nbyte-for-byte KFD surface because it contains KFD evidence; instead, the\npassport is audited through release-state SHA, `check-report.json`, and the\ncontract files that generate and verify it.\n\n### KFD-2 release trust passport audit\n\nBuildchain can write a KFD-2 release trust passport audit under the top-level\n`kfd-2` section. The section is generated automatically from KFD-1 and KFD-3\nrelease-gate evidence, and callers may add explicit public release claims with\n`--kfd-2-claim-json`.\n\nEvery public claim must bind:\n\n- declared sources;\n- machine-readable evidence;\n- source/evidence/artifact hashes;\n- artifact coordinates;\n- verification results;\n- audit boundary;\n- responsibility state;\n- residual risk, even when the array is empty.\n\nUnbound public claims fail release passport verification. Claims that are\nmachine-bound but only supported by prose downgrade the KFD-2 audit and produce\na warning, so agents can distinguish \"verified\", \"needs review\", and \"not\nbound to evidence\" without reading release notes.\n\nFor Buildchain's own releases, public release claims are not authored in prose\ninside the workflow. The source registry is\n`packages/core/buildchain-kfd-claims.js`, published as\n`dist/site/kfd-claims.json` and exported as\n`@kungfu-tech/buildchain/buildchain-kfd-claims`. That registry is the\nversion-invariant source of public claims and collaboration surfaces: it does\nnot store the exact release version, promotion SHA, or exact runtime contract\ndigest. Those run-specific facts belong in the release passport and generated\nwitnesses. During Buildchain promotion,\n`scripts/generate-buildchain-kfd-witnesses.mjs` binds the source registry to the\ncurrent source/artifact hashes and generates:\n\n- a KFD-1 self contract-world witness for the packaged docs, schemas, workflows,\n  actions, Node exports, and site-consumption facts;\n- one KFD-2 claim JSON per public Buildchain release claim;\n- KFD-3 pre-build and artifact witnesses for the same public collaboration\n  surfaces.\n\nThe generated claim set covers Buildchain's KFD release passport support,\nagent-first single source of truth, floating `@v3` contract drift protection,\nsemver GitHub Release evidence publication, channel-preserving release\npropagation, and npm publish evidence/finalization. Buildchain self promotion\npasses those files into `promote-buildchain-ref`; `verifyReleasePassport()` then\nfails closed if any claim is missing source bindings, machine evidence, hashes,\nartifact coordinates, verification result, audit boundary, responsibility, or\nresidual risk.\n\n### KFD-3 collaboration-interface release gate\n\nKFD-3 asks a different release question than KFD-1. KFD-1 proves that named\npayload bytes match one contract world. KFD-3 proves that a product's shipped\nparticipant-facing collaboration/control surface is closed over its declared\ninterface.\n\nFor Buildchain itself, the declared interface starts in\n`packages/core/buildchain-kfd-claims.js`, not in this Markdown file. The\nregistry enumerates public human/agent surfaces across manuals, schema and\nstandard metadata, package exports, site-consumption contracts, workflows, and\nactions. `dist/site/kfd-claims.json` is the packaged machine-readable form used\nby downstream sites and by Buildchain's own release passport. Exact release\nversion/SHA binding is deliberately deferred to the promotion witness, so the\nsource registry can remain stable across semver version-state bumps.\n\nBuildchain also performs a reverse audit before that witness is used. The\ngenerated `dist/site/public-surface-audit.json` enumerates real CLI commands\nfrom `bin/buildchain.mjs`, workflow inputs, action inputs, site pages, and docs\ncommand references, then compares them with the generated registries. Buildchain\nself KFD witnesses include that audit result and classify the collaboration\ninterface as closed-world only when the reverse audit passes. If a public\ncommand, workflow input, action input, or site page is exposed without a\nregistry entry, `pnpm run check` fails before release promotion can produce a\npassport.\n\nThe product remains the fact source. Before build/publish, the product writes a\npre-build witness:\n\n```bash\nkungfu sdk collaboration-interface witness --json \\\n  > .buildchain/kfd/kfd-3/collaboration-interface.prebuild.json\n```\n\nThat witness must contain, or point to, the product-owned KFD-3 collaboration\ninterface, registry digest, participants, and declared public shipped surfaces.\nKFD repository self-verification can declare the same facts as grouped machine\nsurfaces: docs, schemas, standards metadata, package exports, and\nsite-consumption contracts.\nAfter the artifact is built, the product also provides artifact-side evidence,\neither as a JSON file or a command:\n\n```bash\nbuildchain collect github-release \\\n  --kfd-3-prebuild-witness-json .buildchain/kfd/kfd-3/collaboration-interface.prebuild.json \\\n  --kfd-3-artifact-verify-cmd \"kungfu agent verify --json\"\n```\n\nBuildchain imports the KFD-3 metadata from `@kungfu-tech/kfd`, freezes the\npre-build witness digest, ingests the artifact witness, and compares the two\nsets:\n\n- every declared `shipped` public participant-facing surface must appear in the\n  artifact witness;\n- every artifact-exposed public participant-facing surface must be declared by\n  the pre-build witness;\n- if both witnesses record `collaborationInterface.digest`, the digests must\n  match;\n- contradictory, missing, stale, or schema-incomplete evidence fails closed.\n\nThe generated release passport records the result under the KFD-provided\ntop-level key currently named `kfd-3`. The section includes the KFD package\nversion, schema ids/paths, pre-build witness digest, artifact witness digest,\ndeclared/exposed surface counts, missing declared shipped surfaces, and\nunclassified artifact public surfaces. Buildchain also projects the same\ncollaboration-interface evidence into the top-level `kfd-2` audit as a\nmachine-readable `trustProof` object on the generated `kfd-3:*` public claim.\nThat proof carries `releaseStatus`, witness file hashes and canonical hashes,\ndeclared capability verification, reverse audit result and boundary, residual\nrisk, and responsibility state.\n\nThe trust proof makes the strongest claim only when the witnesses justify it:\n`No unclassified reachable surface within the declared audit boundary.` If the\nproduct declares non-exhaustive surfaces, Buildchain keeps the passport\nverifiable but marks the interface `audited` instead of `enforced` and records\nthe residual risk explicitly. Draft or partial KFD-3 declarations are\ndowngraded; missing declared capabilities, undeclared public artifact surfaces,\nor stale collaboration-interface digests fail the proof.\n\nThis makes KFD-3 support usable by readers and agents immediately: they can\ninspect `buildchain.release.json` and know whether the released package\nactually exposes no more and no less than the declared collaboration interface,\ninstead of trusting docs or release notes.\n\n### KFD support projection\n\nPass the standard full-cut declaration with `--kfd-adopter-manifest-json`\ntogether with three `--kfd-product-gate-json` arguments for KFD-4, KFD-5, and\nKFD-7. The collector invokes the verifier from the exact installed\n`@kungfu-tech/kfd` package, binds the package artifact, registry and verifier\nroots, the exact Buildchain source, the manifest/report/bundle witness roots,\nand the existing product-gate roots. It emits `kfd-adopter-manifest.json`,\n`kfd-adopter-manifest-gate.json`, and a legacy `kfd-support.json` projection.\nThe release passport and `artifact-evidence.json` carry the same rooted\n`kfdAdopter` binding.\n\nThe adopter manifest is the sole declaration authority. The old\n`--kfd-support-matrix-json` input is retained only as a compatibility check: if\nsupplied with the manifest, it must exactly equal the generated legacy\nprojection. Release verification fails closed when any sibling, package root,\nsource root, witness root, gate root, passport binding, or artifact-evidence\nbinding differs. A passed binding is release evidence only; product\nqualification, activation, certification, and support ownership remain outside\nBuildchain.\n\n### Floating Buildchain contract lock\n\nKFD-1 protects release payload surfaces. Floating ref contract locks protect the\nconsumer's relationship to Buildchain itself. A consumer can keep\n`.buildchain/contract-lock.json` with the Buildchain floating ref it accepted,\nthe resolved SHA, the contract digest, and the compatibility policy. Each\nBuildchain run reads the actual contract from the checked-out Buildchain ref\nand compares it before heavy build or publish work begins.\n\nCompatible drift, such as optional inputs or extra diagnostics, continues and\ncreates a consumer-local issue for review. Breaking drift fails fast. This means\nconsumers can use `@v3` without silently accepting incompatible changes, while\nBuildchain maintainers can still ship compatible improvements under the same\nmajor floating tag.\n\n`impact.json` can be supplied with `--impact-json`. Production release\npassports (`release/*`) and major publish-gate passports require\n`surfaceImpacts[]`; alpha, local, and legacy passport contexts keep the field\noptional. When `surfaceImpacts[]` is required or supplied, verification fails\nclosed unless each entry has an id, impact, and rationale, and\n`versionImpact.final` matches the highest surface impact. For example, KFD-2\ncontent can remain patch while an additive `registry.kind` field on the\nmachine-consumed KFD registry schema records a minor `kfd-registry-schema`\nsurface impact.\n\nPromote-only stable publication may omit an explicit impact ledger only when\nthe downloaded PR-stage release-candidate passport proves exact tree\nequivalence. Buildchain then records a patch-level release-governance impact\nbound to that candidate. Missing, stale, or non-equivalent candidate evidence\ndoes not receive this fallback and remains fail-closed.\n\nVerify a release passport:\n\n```bash\nbuildchain verify release-passport .buildchain/release-passport/buildchain.release.json\n```\n\nVerify a specific artifact by discovering its detached passport:\n\n```bash\nbuildchain verify artifact ./Kungfu-2.8.0-windows-x64.exe\n```\n\nArtifact verification is subject-centric. Buildchain identifies the subject,\ncomputes or obtains its digest, discovers a detached `buildchain.release.json`,\nverifies that release passport and its evidence, then proves the subject digest\nappears in the passport's artifacts, package set, publish evidence, or artifact\nevidence. The command returns `pass`, `fail`, or `unverifiable`; missing\npassports and digest mismatches fail closed.\n\nFor npm subjects, Buildchain treats the registry as the package digest source:\n`npm:<name>@<version>` resolves `dist.integrity` and matches it against\n`packageSet.main.digest`, `packageSet.platforms[].digest`, and publish evidence.\nUse `--npm-registry <url>` when the package comes from a non-default registry.\n\nDiscovery is ordered and auditable:\n\n1. explicit `--passport`;\n2. sidecar pointer;\n3. embedded/package pointer;\n4. local config or org index;\n5. GitHub Release default from artifact naming/repository/tag hints;\n6. custom locator;\n7. unverifiable with retry guidance.\n\nFor Buildchain-managed GitHub Release lanes, release passport files are\npublished as release assets by default when the upload backend is enabled, so a\nGitHub Release asset URL can discover the sibling `buildchain.release.json`\nwithout a consumer copying YAML resolver logic.\n\nExplain a release to an agent:\n\n```bash\nbuildchain explain release \\\n  --passport .buildchain/release-passport/buildchain.release.json \\\n  --for agent \\\n  --json\n```\n\nThe verifier fails closed when a passport omits artifacts, omits evidence, has\ndigest mismatches, or misses required protocol files.\n\n## Binary Distribution\n\nInitial binary distribution stays lightweight:\n\n- GitHub Release assets.\n- `checksums.txt`.\n- release passport artifacts.\n- a single release evidence bundle.\n- install scripts and Homebrew tap fixtures after the passport path is reliable.\n\nBuildchain publishes platform-specific archives, not loose top-level\nexecutables:\n\n- `buildchain-x86_64-unknown-linux-gnu.tar.gz`\n- `buildchain-aarch64-apple-darwin.tar.gz`\n- `buildchain-x86_64-pc-windows-msvc.zip`\n\nThe executable name inside each archive stays natural for the platform\n(`buildchain` or `buildchain.exe`). Top-level loose executable assets are not\nuploaded, because Linux and macOS would otherwise collide when GitHub Actions\nmatrix artifacts are merged.\n\nHeavy package manager channels such as apt, yum, winget, choco, Scoop, mise, or\nasdf are out of the P0/P1 scope until there is real external demand.\n\nStandalone binaries are a distribution shape, not a second implementation. The\nsource of truth remains the Node/ESM CLI and core library.\n\nThe standalone binary builder imports `@kungfu-tech/buildchain/logging` directly\nand records setup, SEA blob generation, injection, signing, archiving, manifest,\nand evidence phases. The GitHub workflow wraps the same build and passport\nsteps with `buildchain mark`, `buildchain span`,\n`buildchain verify observability-log`, and `buildchain log summary`. Logging is\na hard release gate: missing events, error events, or missing required phases\nfail the job before assets are uploaded. The verified logs are release assets\nand are covered by the release passport digest checks.\n\nSee also [`binary-distribution.md`](binary-distribution.md) for asset naming and\nbundle details, and [`install.md`](install.md) for consumer commands."
    },
    {
      "id": "manual:release-propagation",
      "title": "Release Propagation",
      "route": "/docs/release-propagation",
      "category": "manual",
      "capabilityGroup": "site-and-propagation",
      "audience": [
        "release-operator",
        "agent"
      ],
      "maturity": "preview",
      "sourcePath": "docs/release-propagation.md",
      "digest": "sha256:6e8417ff70db290ee6197f064ed9b7a7da3770738509fac06161dad05b3fca7f",
      "headings": [
        {
          "level": 1,
          "title": "Release Propagation",
          "anchor": "release-propagation"
        },
        {
          "level": 2,
          "title": "Contract",
          "anchor": "contract"
        },
        {
          "level": 2,
          "title": "Upstream Release Envelope",
          "anchor": "upstream-release-envelope"
        },
        {
          "level": 2,
          "title": "CLI",
          "anchor": "cli"
        },
        {
          "level": 2,
          "title": "Unified Site agent entry",
          "anchor": "unified-site-agent-entry"
        },
        {
          "level": 2,
          "title": "Agent-native work envelope",
          "anchor": "agent-native-work-envelope"
        },
        {
          "level": 2,
          "title": "Reusable Workflow",
          "anchor": "reusable-workflow"
        },
        {
          "level": 2,
          "title": "kfd to site-libkungfu-dev",
          "anchor": "kfd-to-site-libkungfu-dev"
        }
      ],
      "markdown": "---\nstatus: active\nperiod: ongoing\ntheme: buildchain-release-propagation\ndoc_type: technical-reference\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-08-03\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-08-03\n  invisible_context: not asserted\n---\n\n# Release Propagation\n\nRelease propagation lets a finalized upstream release open a downstream update\nPR using the upstream release passport as the audit source. It is for product\nchains such as:\n\n```text\nkfd -> site-libkungfu-dev\nA -> B -> C\n```\n\nThe downstream repository receives an exact lock, not a floating dist-tag. A\nsite or app can then consume the upstream package, site bundle, or release\npassport as its single source of truth without hand-copying release facts.\n\n## Contract\n\nThe propagation graph is declarative JSON:\n\n```json\n{\n  \"schemaVersion\": 1,\n  \"contract\": \"kungfu-buildchain-release-propagation-graph\",\n  \"nodes\": [\n    {\n      \"id\": \"kfd\",\n      \"repository\": \"kungfu-systems/kfd\",\n      \"package\": \"@kungfu-tech/kfd\"\n    },\n    {\n      \"id\": \"site-libkungfu-dev\",\n      \"repository\": \"kungfu-systems/site-libkungfu-dev\",\n      \"lockPath\": \"buildchain.upstreams/kfd.release.json\",\n      \"baseRef\": \"dev/v2/v2.7\"\n    }\n  ],\n  \"edges\": [\n    {\n      \"id\": \"kfd-to-site\",\n      \"from\": \"kfd\",\n      \"to\": \"site-libkungfu-dev\",\n      \"channelPolicy\": \"preserve\"\n    }\n  ]\n}\n```\n\n`channelPolicy: \"preserve\"` is the default and maps:\n\n```text\nalpha   -> alpha\nrelease -> release\n```\n\nCross-channel mapping is allowed only when an edge declares\n`channelPolicy: \"explicit\"` and a `channelMap`. Buildchain rejects cycles so a\nchain can fan out or continue as `A -> B -> C`, but cannot loop back into an\nalready visited release line.\n\n## Upstream Release Envelope\n\nThe upstream release envelope is the post-finalization fact set:\n\n```json\n{\n  \"repository\": \"kungfu-systems/kfd\",\n  \"channel\": \"alpha\",\n  \"tag\": \"v1.4.0-alpha.3\",\n  \"sourceSha\": \"1111111111111111111111111111111111111111\",\n  \"tagTargetSha\": \"1111111111111111111111111111111111111111\",\n  \"package\": {\n    \"name\": \"@kungfu-tech/kfd\",\n    \"version\": \"1.4.0-alpha.3\",\n    \"integrity\": \"sha512-...\",\n    \"gitHead\": \"1111111111111111111111111111111111111111\"\n  },\n  \"releasePassport\": {\n    \"url\": \"https://github.com/kungfu-systems/kfd/releases/download/v1.4.0-alpha.3/buildchain.release.json\",\n    \"sha256\": \"2222222222222222222222222222222222222222222222222222222222222222\"\n  },\n  \"siteBundle\": {\n    \"manifestSha256\": \"3333333333333333333333333333333333333333333333333333333333333333\"\n  }\n}\n```\n\nThe package version, integrity, and npm `gitHead` must be exact. The exact tag\nmust be `v<version>`, and `gitHead`, tag target, and `sourceSha` must describe\nthe same source commit before propagation is admitted. Downstream build logic\ninstalls that version directly and never resolves `alpha` or `latest` again.\n\nPublication repositories can propagate immutable publication archive evidence\nwithout npm package facts. The upstream envelope then includes\n`publicationArtifact`:\n\n```json\n{\n  \"repository\": \"kungfu-systems/paper-observer-declared-timelines\",\n  \"channel\": \"alpha\",\n  \"tag\": \"v0.1.0-alpha.1\",\n  \"sourceSha\": \"4444444444444444444444444444444444444444\",\n  \"tagTargetSha\": \"4444444444444444444444444444444444444444\",\n  \"releasePassport\": {\n    \"url\": \"https://github.com/kungfu-systems/paper-observer-declared-timelines/releases/download/v0.1.0-alpha.1/buildchain.release.json\",\n    \"sha256\": \"5555555555555555555555555555555555555555555555555555555555555555\"\n  },\n  \"publicationArtifact\": {\n    \"id\": \"observer-declared-timelines\",\n    \"kind\": \"paper\",\n    \"version\": \"0.1.0-alpha.1\",\n    \"canonicalUrl\": \"https://papers.libkungfu.dev/observer-declared-timelines/\",\n    \"latestUrl\": \"https://papers.libkungfu.dev/observer-declared-timelines/latest/\",\n    \"latestEvidenceUrl\": \"https://papers.libkungfu.dev/observer-declared-timelines/latest/buildchain.release.json\",\n    \"immutableVersionUrl\": \"https://papers.libkungfu.dev/archive/observer-declared-timelines/v0.1.0-alpha.1/\",\n    \"registry\": {\n      \"url\": \"https://github.com/kungfu-systems/paper-observer-declared-timelines/releases/download/v0.1.0-alpha.1/publication-registry.json\",\n      \"sha256\": \"6666666666666666666666666666666666666666666666666666666666666666\"\n    },\n    \"manifest\": {\n      \"url\": \"https://github.com/kungfu-systems/paper-observer-declared-timelines/releases/download/v0.1.0-alpha.1/publication-artifact.json\",\n      \"sha256\": \"7777777777777777777777777777777777777777777777777777777777777777\"\n    },\n    \"passport\": {\n      \"url\": \"https://github.com/kungfu-systems/paper-observer-declared-timelines/releases/download/v0.1.0-alpha.1/publication-artifact-passport.json\",\n      \"sha256\": \"8888888888888888888888888888888888888888888888888888888888888888\"\n    },\n    \"primaryArtifact\": {\n      \"path\": \"_build/main.pdf\",\n      \"url\": \"https://papers.libkungfu.dev/archive/observer-declared-timelines/v0.1.0-alpha.1/main.pdf\",\n      \"sha256\": \"9999999999999999999999999999999999999999999999999999999999999999\"\n    }\n  }\n}\n```\n\nThis lets a site repository render the latest reader page and historical\nversion index from release facts while keeping old PDFs, source bundles,\nmanifests, and passports immutable.\n\nWhen the downstream consumer is expected to update an exact npm paper pin, the\nupstream envelope must carry both `package` and `publicationArtifact`. The\nconsumer can then prove that package name, version, sha512 integrity,\npublication URLs, and immutable artifact digests all describe the same release.\n`publicationArtifact` without `package` remains valid for evidence-only\npropagation, but it cannot qualify a package-pin fast path.\n\n## CLI\n\nGenerate a propagation plan:\n\n```bash\nbuildchain release-propagation plan \\\n  --graph buildchain.release-propagation.json \\\n  --upstream-release .buildchain/upstream-release.json \\\n  --output .buildchain/release-propagation-plan.json \\\n  --json\n```\n\nWrite the downstream lock:\n\n```bash\nbuildchain release-propagation write-lock \\\n  --plan .buildchain/release-propagation-plan.json \\\n  --target site-libkungfu-dev \\\n  --cwd downstream-checkout \\\n  --json\n```\n\nThe written lock has contract\n`kungfu-buildchain-release-propagation-lock` and records:\n\n- upstream repository, channel, exact tag, source SHA;\n- optional npm package name, exact version, and sha512 integrity;\n- optional publication artifact canonical/latest/immutable URLs, registry,\n  manifest, passport, source bundle, and primary artifact digests;\n- release passport URL and SHA-256;\n- optional site bundle manifest SHA-256;\n- downstream repository, channel, base ref, lock path;\n- edge id and channel policy;\n- a deterministic propagation key and branch derived from the exact upstream\n  repository/version/channel plus downstream repository.\n\nRepeated runs for the same release identity reuse that branch and lock. A\ndifferent release version or channel receives a different branch, so concurrent\nreleases cannot collapse into one mutable propagation PR.\n\nCreate the exact propagation receipt after the lock/PR outcome is known:\n\n```bash\nbuildchain release-propagation receipt \\\n  --plan .buildchain/release-propagation-plan.json \\\n  --lock-result .buildchain/release-propagation-write-lock.json \\\n  --pr-outcome .buildchain/release-propagation-pr-outcome.json \\\n  --target site-libkungfu-dev \\\n  --output .buildchain/release-propagation-receipt.json \\\n  --json\n```\n\nThe receipt keeps four machine states separate:\n\n- `package-published`: exact npm name/version/integrity exists;\n- `alpha-complete`: the upstream alpha passport/tag is complete;\n- `staging-visible`: the downstream staging surface is actually visible;\n- `production-visible`: the production surface is actually visible.\n\nPackage publication or alpha completion never implies either visibility state.\n\n## Unified Site agent entry\n\nAn Agent begins every Site upstream update through one policy-reporting entry:\n\n```bash\nbuildchain release-propagation entry plan \\\n  --source-id <paper|kfd|buildchain|kungfu-core> \\\n  --channel <alpha|release> \\\n  --json\n```\n\nThe entry does not blur content and code release policies:\n\n| Upstream    | Trigger policy            | Entry result                                       |\n| ----------- | ------------------------- | -------------------------------------------------- |\n| Paper       | automatic release handoff | requires or resumes the exact captured Work        |\n| KFD         | automatic release handoff | requires or resumes the exact captured Work        |\n| Buildchain  | explicit Site intent      | resolves an exact published package before capture |\n| Kungfu Core | explicit Site intent      | resolves an exact published package before capture |\n\nPaper and KFD releases keep automatic capture-only handoff. Buildchain and\nKungfu Core releases remain inert until a downstream Agent receives explicit\nSite-update intent. In all four cases, the entry reports the selected policy,\nexact release coordinate when one has been admitted, Work root and recovery\ncursor when one exists, and one machine-readable next action. A GitHub PR is a\ndelivery stage inside that Work; it is not the handoff unit.\n\nFor an automatic handoff, bind the exact artifact rather than resolving a\nfloating tag again:\n\n```bash\nbuildchain release-propagation entry plan \\\n  --source-id kfd \\\n  --handoff-work work.json \\\n  --json\n```\n\nThe deterministic recovery table is available without repository mutation:\n\n```bash\nbuildchain release-propagation entry fault-matrix --json\n```\n\nIt classifies current and duplicate Work as successful no-ops, supersession as\nan explicit decision boundary, stale base/expected-old and operational failures\nas retryable, and package/schema disagreement as a hard safety gate.\n\n## Agent-native work envelope\n\nSetting `agent-work-mode: capture-only` makes a finalized release emit a\nresumable delivery handoff without mutating the downstream repository. Passing\nan exact `agent-work-context-json` instead emits an already-authorized unit.\nBuildchain emits one\n`kungfu-buildchain-release-propagation-work` v1 envelope per exact release and\ndownstream target. This is a Buildchain domain execution contract, not another\nWork Control database or authority.\n\nThe envelope binds:\n\n- the exact normalized upstream release and release-lock roots;\n- the downstream repository, channel, base ref, expected base SHA, managed\n  branch, lock path, and propagation key;\n- exact parent and child `kungfu.assignment-graph.work-ref/v1` values derived\n  from the immutable release and downstream plan;\n- either a pending Family binding or one exact\n  `kungfu.work-control.initiative-family-state/v2` coordinate;\n- capture-only or end-to-end execution authority, including an active typed\n  execution-Warrant reference for execution;\n- explicit publish-to-production intent, deterministic commands, canonical\n  ordered stages, a recovery cursor, stage receipts, supersession policy, and\n  a content root.\n\nThe ordered stages are:\n\n```text\nmaterialize -> verify-release -> push-branch -> pull-request -> preview\n-> independent-review -> protected-merge -> staging -> production-release\n-> production-deploy -> online-readback -> complete\n```\n\n`pull-request` and `protected-merge` are intermediate states. Only exact online\nreadback followed by an accepted Work Control Decision can record `complete`.\nEvery state transition uses expected-old fencing against the current work\ncontent root. An identical initial envelope has the same work id and root;\nnewer releases receive distinct propagation keys and must name an explicit\nsuperseded work root when they replace unfinished work.\n\nThe context has this shape (roots abbreviated here only for readability):\n\n```json\n{\n  \"parentWorkRef\": {\n    \"schema\": \"kungfu.assignment-graph.work-ref/v1\",\n    \"workspace_identity_root\": \"sha256:<64 hex>\",\n    \"object_kind\": \"initiative\",\n    \"subject\": \"paper-publication\",\n    \"version_root\": \"sha256:<64 hex>\",\n    \"cut_root\": \"sha256:<64 hex>\"\n  },\n  \"childWorkRef\": {\n    \"schema\": \"kungfu.assignment-graph.work-ref/v1\",\n    \"workspace_identity_root\": \"sha256:<64 hex>\",\n    \"object_kind\": \"assignment\",\n    \"subject\": \"site-propagation\",\n    \"version_root\": \"sha256:<64 hex>\",\n    \"cut_root\": \"sha256:<64 hex>\"\n  },\n  \"familyState\": {\n    \"schema\": \"kungfu.work-control.initiative-family-state/v2\",\n    \"stateRoot\": \"sha256:<64 hex>\",\n    \"v1ProjectionRoot\": \"sha256:<64 hex>\",\n    \"typedBindingRoot\": \"sha256:<64 hex>\",\n    \"factWorld\": \"<owning fact world>\",\n    \"cutRoot\": \"sha256:<64 hex>\"\n  },\n  \"authority\": {\n    \"mode\": \"capture-only\",\n    \"publishToProduction\": false,\n    \"allowedActions\": [],\n    \"executionPrincipal\": null,\n    \"sourceControlPrincipal\": null,\n    \"executionWarrant\": null\n  },\n  \"supersedesWorkRoot\": \"\"\n}\n```\n\nAutomatic capture emits deterministic Buildchain-owned release and propagation\nWorkRefs, leaves `workControl.bindingState` as `pending`, emits no Family State\nor Warrant, and performs no downstream write. Claiming that unit supplies the\nexact Family State v2 coordinate and active Warrant while preserving the work\nidentity. An executing input must carry an active Warrant at the same Family\nState fact world and cut, explicit production intent, and the complete supported\naction set. It also binds the acting Agent principal and the source-control\nprincipal that authors the PR. Buildchain never invents external Work Control\nauthority.\n\nA managed Paper opts into automatic capture with a thin, source-controlled\n`.buildchain/release-propagation.json`. The sealed release workflow reads that\nexact file from the released Paper SHA only after npm, tag, Passport, and\npublication evidence agree. It emits one paused work artifact per declared\ntarget; publication itself does not open a Site PR.\n\n```json\n{\n  \"schemaVersion\": 1,\n  \"contract\": \"kungfu-buildchain-paper-release-propagation\",\n  \"sourceNode\": \"paper-example\",\n  \"graph\": {\n    \"schemaVersion\": 1,\n    \"contract\": \"kungfu-buildchain-release-propagation-graph\",\n    \"nodes\": [],\n    \"edges\": []\n  },\n  \"targets\": [\"site-libkungfu-dev\"]\n}\n```\n\nA managed npm package uses the parallel generic contract and passes its path to\nthe release-candidate promotion workflow:\n\n```json\n{\n  \"schemaVersion\": 1,\n  \"contract\": \"kungfu-buildchain-package-release-propagation\",\n  \"sourceNode\": \"kfd\",\n  \"graph\": {\n    \"schemaVersion\": 1,\n    \"contract\": \"kungfu-buildchain-release-propagation-graph\",\n    \"nodes\": [],\n    \"edges\": []\n  },\n  \"targets\": [\"site-libkungfu-dev\"]\n}\n```\n\n```yaml\nwith:\n  release-propagation-config-path: .buildchain/release-propagation.json\n```\n\nThe config is read with `git show` from the exact finalized release SHA. Its\nroot fields, graph fields, nodes, edges, targets, and execution profiles reject\nunknown fields. After npm publication and the public GitHub Release are\ncomplete, Buildchain independently reads npm `version`, `dist.integrity`, and\n`gitHead`, resolves annotated Git tags to their commit, downloads the public\n`buildchain.release.json` asset, and compares its bytes with the finalized\nPassport. Only an exact source SHA, tag target, npm `gitHead`, package version,\nintegrity, and Passport digest can produce the capture artifact. The promotion\noutput `release-propagation-work-artifact` names the restart-safe artifact set.\nNo downstream checkout, branch, or pull request is created by this step.\n\nEach graph target owns an exact GitHub web-surface execution profile: workflow,\nbase and managed branch, lock path, consumer commands, production status URL,\nand production artifact readback URLs. The sealed workflow rejects extra config\nfields, unknown targets, or a target whose base revision cannot be resolved.\n\nThe reusable workflow keeps its prior behavior when `agent-work-mode` is\n`legacy` (the default). Managed Paper callers set `capture-only`; an Agent later\nclaims the emitted artifact and resumes from its machine-readable `next_action`.\n\nAgent entrypoints are machine-readable and restart-safe:\n\n```bash\nbuildchain release-propagation work create ... --output work.json --json\nbuildchain release-propagation work status --work work.json --json\nbuildchain release-propagation work resume --work work.json --json\nbuildchain release-propagation work claim ... --output successor.json --json\nbuildchain release-propagation work receipt ... --output receipt.json --json\nbuildchain release-propagation work record ... --output successor.json --json\nbuildchain release-propagation work repair ... --output successor.json --json\nbuildchain release-propagation work complete ... --output successor.json --json\n```\n\nThe `push-branch` stage has an executable, fail-closed entrypoint:\n\n```bash\nbuildchain release-propagation work push-plan \\\n  --work work.json \\\n  --expected-work-root sha256:<64-hex> \\\n  --cwd downstream-worktree \\\n  --remote origin \\\n  --json\n\nbuildchain release-propagation work push-branch \\\n  --work work.json \\\n  --expected-work-root sha256:<64-hex> \\\n  --cwd downstream-worktree \\\n  --remote origin \\\n  --execute \\\n  --json\n```\n\nThe executor checks the exact GitHub repository, current managed branch,\ncaptured downstream base, and expected-old Work root. It pushes only the current\ncommit with `HEAD:refs/heads/<managed-branch>`, never a bare branch or wildcard,\nnever a force option, then reads that exact remote ref back. Its typed branch\nreconciliation evidence records the argv, source SHA, destination ref, prior\nremote SHA, observed remote SHA, and whether a mutation occurred. A wrong\nrepository, unrelated branch, stale base, concurrent writer, or non-fast-forward\ntarget fails closed without mutating another branch.\n\nKnown operational races (`stale-branch`, `expected-old-mismatch`,\n`lockfile-drift`, `failed-check`, `interrupted-execution`, and `ci-delay`) return\na retryable repair action. Semantic ambiguity, missing credentials, policy\nexpansion, and unknown failures stop at `needs-decision`. Release-contract\nmismatch, immutable-artifact conflict, and destructive recovery stop at a hard\nsafety gate. Evidence locators containing signed or credential parameters are\nrejected.\n\nSuccessful stage receipts are typed, not generic progress notes. In particular,\nthe pushed-branch receipt hashes the full expected-old branch reconciliation;\nreview binds an approved GitHub review and must come from an identity distinct\nfrom both the acting Agent and PR author; production deployment carries release,\nlock, deployed artifact, expected readback digest, and rollback coordinates; and\nonline readback must cover the exact execution-profile URLs with HTTP 200,\nobserved non-zero bytes, exact deployed Git revision, and matching release and\nartifact digests. The final receipt binds the accepted Work Control Decision\nroot.\n\n## Reusable Workflow\n\nUpstream repositories can call\n`.github/workflows/release-propagation.yml@v3` after release finalization:\n\n```yaml\njobs:\n  propagate-site:\n    uses: kungfu-systems/buildchain/.github/workflows/release-propagation.yml@v3\n    with:\n      buildchain-ref: v3\n      graph-json: ${{ needs.release.outputs.propagation-graph-json }}\n      upstream-release-json: ${{ needs.release.outputs.upstream-release-json }}\n      downstream-target: site-libkungfu-dev\n      downstream-repository: kungfu-systems/site-libkungfu-dev\n      downstream-base-ref: dev/v2/v2.7\n      downstream-update-command: >-\n        node scripts/paper-propagation.cjs consume\n        --lock \"$BUILDCHAIN_PROPAGATION_LOCK_PATH\"\n        && corepack pnpm install --lockfile-only --ignore-scripts\n      downstream-prepare-command: pnpm install --frozen-lockfile --ignore-scripts\n      downstream-verify-command: pnpm run check\n      dry-run: false\n    secrets:\n      propagation-token: ${{ secrets.BUILDCHAIN_PROMOTION_TOKEN }}\n```\n\nThe downstream branch name may be reused across upstream releases. Before\nreplacing an existing managed branch, the workflow reads its exact remote SHA\nand pushes with an explicit `--force-with-lease=<ref>:<sha>`. A surviving branch\nfrom a merged PR is therefore reconciled without manual deletion, while a\nconcurrent writer makes the lease fail closed. The controller receipt includes a\n`propagation-branch-reconciliation` evidence file recording the branch, observed\nremote SHA, pushed SHA, lease mode, and the deterministically created or updated\nopen PR.\n\nThe workflow checks out the Buildchain runtime selected by\n`buildchain-repository` and `buildchain-ref` into `.buildchain/runtime`, invokes\nthat runtime for the propagation plan and lock write, then checks out the\ndownstream repository and writes the exact lock. If\n`downstream-update-command` is set, Buildchain runs that consumer-owned command\nafter writing the lock and exposes the exact lock path, lock SHA-256,\npropagation key, branch, and upstream release JSON as\n`BUILDCHAIN_PROPAGATION_*` environment variables. The command is part of the\ndownstream PR diff; it is not a deployment hook.\n\nA consumer that must perform further deterministic preparation can declare\n`downstream-prepare-command`. The command receives\n`BUILDCHAIN_UPSTREAM_PACKAGE_NAME`, `BUILDCHAIN_UPSTREAM_PACKAGE_VERSION`, and\n`BUILDCHAIN_UPSTREAM_RELEASE_LOCK`. After preparation, Buildchain refreshes an\nexisting `<!-- buildchain:badges:start -->` README block by default. Consumers\ncan disable that step with `refresh-managed-readme-badges: false`.\n\n`downstream-verify-command` runs against the final tree before any commit or\npush, so consumers can use the same check as their PR workflow. Update,\npreparation, badge refresh, and verification failures all fail closed. The\nworkflow stages the complete deterministic result, signs the propagation\ncommit with DCO, and then opens or updates the PR. With no agent work context,\nthe reusable workflow retains this backward-compatible PR boundary. With an\nexecuting work context, it records materialization, verification, branch, and\nPR receipts and returns `preview` as the next action; the authorized Agent then\ncontinues through the downstream repository's normal protected review,\npublication, deployment, and readback entrypoints. A byte-identical rerun is an\nexplicit successful no-op, never a synthetic completion.\n\nFor unreleased runtime validation, keep the caller's reusable workflow reference\non `@v3` and pass a temporary train ref through `buildchain-ref`.\n\n## kfd to site-libkungfu-dev\n\nFor `kfd -> site-libkungfu-dev`, the graph should preserve channels:\n\n- a `kfd` alpha release produces a downstream alpha lock and downstream alpha\n  publication consumes the exact `@kungfu-tech/kfd@...-alpha.N` package;\n- a `kfd` stable release produces a downstream release lock and downstream\n  stable publication consumes the exact stable package.\n\nThis keeps the site synchronized to the package truth without allowing the site\nto drift onto a floating npm dist-tag."
    },
    {
      "id": "manual:release-tail-contract",
      "title": "Declarative release-tail contract",
      "route": "/docs/release-tail-contract",
      "category": "manual",
      "capabilityGroup": "release-passport-trust",
      "audience": [
        "release-operator",
        "agent",
        "maintainer"
      ],
      "maturity": "draft",
      "sourcePath": "docs/release-tail-contract.md",
      "digest": "sha256:db5d38df0af0f7ce76ff93cc78a0d96a0738a40f6f40f7c1a0cfd78ca9f4f22a",
      "headings": [
        {
          "level": 1,
          "title": "Declarative release-tail contract",
          "anchor": "declarative-release-tail-contract"
        },
        {
          "level": 2,
          "title": "Current executable surfaces",
          "anchor": "current-executable-surfaces"
        },
        {
          "level": 2,
          "title": "Capability declaration",
          "anchor": "capability-declaration"
        },
        {
          "level": 2,
          "title": "One release transaction",
          "anchor": "one-release-transaction"
        },
        {
          "level": 2,
          "title": "Compatibility and migration",
          "anchor": "compatibility-and-migration"
        },
        {
          "level": 2,
          "title": "Failure rules",
          "anchor": "failure-rules"
        }
      ],
      "markdown": "---\nstatus: draft\nperiod: 2026-08-07\ntheme: buildchain-release-tail-contract\ndoc_type: architecture\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: self-reviewed\nlast_reviewed: 2026-08-13\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-08-07\n  visible_context: Buildchain dev/v3/v3.0 release workflows, the v4 capability manifest and architecture constitution, promotion Action, transaction and activation code, local exact-head managed-consumer callers, and the Kungfu alpha release-tail implementation.\n  invisible_context_boundary: Did not read credentials, private logs, signed URLs, provider state, or unpublished release assets.\n---\n\n# Declarative release-tail contract\n\nBuildchain's v3 compatibility line lets a consumer repository provide shell\ncommands at several points around publication. Those hooks made early adoption\npossible, but they also let a consumer redefine the final release transaction. The\nmachine authority for the current inventory is\n[`architecture/release-tail-contract-inventory.json`](../architecture/release-tail-contract-inventory.json).\nThe declaration schema is\n[`contracts/release-tail-capabilities-v1.schema.json`](../contracts/release-tail-capabilities-v1.schema.json).\n\nThis contract freezes the replacement boundary. The Buildchain-owned provider\nimplementation is documented in\n[`release-tail-provider-plane.md`](./release-tail-provider-plane.md). Adding the\nprovider plane does not itself cut over a consumer, run a release, or\nreinterpret an already published release.\n\nThe v4 line carries this contract as its production release-tail boundary. The\nv4 capability manifest names `typescript-v4` as the sole writer and marks the\nlegacy v3 writer retired. Deterministic v4 journal, activation, stable-fence,\nrecovery, provider readback, rollback, and N-1 qualification contracts gate\nevery provider mutation; the retained v3 release ref is rollback evidence, not\nan active fallback writer.\n\n## Current executable surfaces\n\nThe reverse scan classifies 27 workflow, Action, config, and CLI coordinates\ninto seven owned surface groups:\n\n| Surface                                                                  | Current role                                              | Replacement                                                 |\n| ------------------------------------------------------------------------ | --------------------------------------------------------- | ----------------------------------------------------------- |\n| `publication-gate-command`, `publication-consumer-qualification-command` | Consumer-owned admission and predicate logic              | Buildchain-evaluated declarative predicates                 |\n| `publish-command`, `lifecycle.publish`                                   | Artifact/package materialization and provider publication | `artifact.publish`                                          |\n| KFD-3, invariant Passport, and attachment commands                       | Product-specific evidence generation                      | Typed evidence requirements and Buildchain-owned projectors |\n| `publication-commit-command`                                             | Final signed or well-known channel authority move         | `signed-channel.commit`                                     |\n| `release-activation-command`                                             | Site activation and production readback                   | `release.activate`                                          |\n| reusable-workflow `release-passport-evidence-command`                    | Receipt-only released-evidence synthesis                  | `released-evidence.synthesize`                              |\n| Action `verification-command`                                            | Version-state verification before release-tail execution  | Separate version-state contract; not part of release tail   |\n\nOne name is already ambiguous. In the reusable promotion workflow,\n`release-passport-evidence-command` means post-activation released-evidence\nsynthesis. In the lower-level promotion Action, the same name is a deprecated\nalias for `release-passport-attachment-command`. New declarations reject that\ncross-layer alias collision instead of preserving it as a permanent escape\nhatch.\n\nThe current v3 managed-caller snapshot covers Buildchain self-bootstrap, both\nBuildchain paper release paths, Kungfu, Libnode, KFD, and the Kungfu product\nwhite paper. The inventory binds every snapshot to an exact commit, tree,\nworkflow path, runtime ref, and the executable surface groups it uses. The\nlegacy `agent-hub-demo@v2` caller is recorded but excluded from the v3 contract.\n\n## Capability declaration\n\nA declaration contains data, never repository shell. Four capability ids cover\nthe current Kungfu alpha tail:\n\n1. `artifact.publish` publishes exact artifact roles to a declared destination.\n2. `signed-channel.commit` moves a signed channel authority only after artifact\n   and Passport prerequisites are durable.\n3. `release.activate` applies the production activation policy and evaluates\n   declared public readback predicates.\n4. `released-evidence.synthesize` consumes the validated activation receipt set\n   and deterministically projects released evidence.\n\nEvery capability declares:\n\n- artifact roles and content roots;\n- destination, channel/tag, activation, and readback policy;\n- standardized effect, observation, and receipt schemas;\n- stable transaction, subject, target, capability, and attempt identity;\n- idempotency behavior and a bounded local retry class;\n- exact evidence requirements.\n\nKeys named `command`, `cmd`, `script`, `shell`, or `run` are forbidden anywhere\nin the declaration. Provider adapters may translate a rooted effect into API\ncalls, read providers, and return observations. They may not select state\ntransitions, change identity, synthesize success, or execute repository-owned\nshell.\n\nThe checked fixture\n[`kungfu-alpha.json`](../contracts/fixtures/release-tail-capabilities-v1/kungfu-alpha.json)\nrepresents the current Kungfu flow: public release assets, the Ed25519-signed\nAlpha channel document, production status/acquisition/product readback, and\nreleased-evidence synthesis from five canonical activation receipts.\n\n## One release transaction\n\n`buildchain.release-tail/v1` is the only owner of the tail lifecycle:\n\n```text\nprepare\n  -> publish artifacts\n  -> commit signed channel authority\n  -> activate\n  -> read back every declared predicate\n  -> settle receipts and released evidence\n  -> complete | blocked | repair-required | terminal-failure\n```\n\nEach effect uses one stable operation identity. A duplicate attempt performs\nreadback before any retry. `never`, `readback`, and `provider-transient` are the\nonly retry classes, and no local executor may exceed three attempts. Provider\nconflict, identity drift, missing readback, and exhausted retry remain explicit\nterminal classifications; an adapter cannot convert them into success.\n\n## Compatibility and migration\n\nThe compatibility window begins when\n`train/v3/v3.0/release-tail-contract` is published. It closes at the earlier of\n90 days or the first v3.2 stable release, and spans at most two minor lines.\n\nDuring that window:\n\n- previously published tags, assets, packages, signed channel documents,\n  Passports, and receipts remain immutable;\n- only the exact enumerated callers may use the legacy adapter;\n- every exception has an owner, the common expiry, and a removal test;\n- migrated declarations create new transactions and never reinterpret settled\n  history;\n- no new arbitrary command input or generic plugin is accepted.\n\nCutover order is the Buildchain paper callers plus a self-bootstrap no-command\nregression, Kungfu's complete Alpha tail, Libnode evidence generation,\nKFD/white-paper no-command regression, then deletion of the Action alias and\nall remaining command inputs. This card\ndefines that order only; consumer migrations are separate changes.\n\n## Failure rules\n\nThe contract fails closed when:\n\n- a reverse scan discovers an unregistered command-bearing release-tail input;\n- one name maps to multiple capabilities;\n- an effect lacks stable operation identity;\n- a mutation lacks readback and receipt contracts;\n- local retry is unbounded;\n- an exception lacks an owner, expiry, or executable removal test.\n\nRun the contract check with:\n\n```bash\nnode scripts/check-release-tail-contract.mjs\nnode --test tests/release-tail-contract.test.mjs\n```\n\nThe tests mutate the inventory and declaration fixtures to prove that orphaned\nhooks, ambiguous ownership, embedded commands, missing identity/readback,\nunbounded retry, and permanent escape hatches are rejected."
    },
    {
      "id": "manual:release-tail-provider-plane",
      "title": "Declarative release-tail provider plane",
      "route": "/docs/release-tail-provider-plane",
      "category": "manual",
      "capabilityGroup": "release-passport-trust",
      "audience": [
        "release-operator",
        "agent",
        "maintainer"
      ],
      "maturity": "preview",
      "sourcePath": "docs/release-tail-provider-plane.md",
      "digest": "sha256:80b39ba4f0a8ed723e2a03e7efff0fee1e891245f7d1bf343edc75011aded801",
      "headings": [
        {
          "level": 1,
          "title": "Declarative release-tail provider plane",
          "anchor": "declarative-release-tail-provider-plane"
        },
        {
          "level": 2,
          "title": "Public entry points",
          "anchor": "public-entry-points"
        },
        {
          "level": 2,
          "title": "Inputs and secrets",
          "anchor": "inputs-and-secrets"
        },
        {
          "level": 2,
          "title": "Transaction semantics",
          "anchor": "transaction-semantics"
        },
        {
          "level": 2,
          "title": "Local verification",
          "anchor": "local-verification"
        },
        {
          "level": 2,
          "title": "Buildchain self-dogfood route",
          "anchor": "buildchain-self-dogfood-route"
        },
        {
          "level": 2,
          "title": "v3 compatibility boundary",
          "anchor": "v3-compatibility-boundary"
        }
      ],
      "markdown": "---\nstatus: draft\nperiod: 2026-08-07\ntheme: buildchain-release-tail-provider-plane\ndoc_type: architecture\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-08-07\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-08-07\n  visible_context: Buildchain release-tail declaration, provider adapters, durable transaction implementation, CLI, Action, reusable workflow, tests, and frozen consumer inventory.\n  invisible_context_boundary: Did not read credentials, private provider state, signed URLs, unpublished release assets, or production receipts.\n---\n\n# Declarative release-tail provider plane\n\nBuildchain owns the final release tail as one versioned transaction. A consumer\nsupplies a sealed capability declaration and data-only provider bindings; it\ndoes not supply shell, JavaScript, executable paths, callbacks, or plugins.\nThe frozen boundary and migration inventory remain in\n[`release-tail-contract.md`](./release-tail-contract.md).\n\n## Public entry points\n\n- Node: `@kungfu-tech/buildchain/release-tail-provider-plane`,\n  `release-tail-provider-adapters`, and `release-tail-compatibility`.\n- CLI: `buildchain release-tail plan|init|status|verify|compat`.\n- Action: `kungfu-systems/buildchain/actions/release-tail@<exact-ref>`.\n- reusable workflow: `kungfu-systems/buildchain/.github/workflows/release-tail.yml@<exact-ref>`.\n\nThe Action is the provider-executing entry point. The CLI compiles, initializes,\ninspects, verifies, and diagnoses bounded v3 compatibility using the same core\ntransaction format. The reusable workflow checks out an exact Buildchain ref\nand invokes the packaged Action; callers cannot inject an execution command.\n\n## Inputs and secrets\n\nThe declaration follows\n[`release-tail-capabilities-v1.schema.json`](../contracts/release-tail-capabilities-v1.schema.json).\nProvider file and endpoint bindings follow\n[`release-tail-provider-bindings-v1.schema.json`](../contracts/release-tail-provider-bindings-v1.schema.json).\nBindings contain paths, asset names, HTTP methods, and evidence input paths.\nGitHub and HTTP bearer tokens are separate secret inputs and never enter the\neffect plan, checkpoint, observation, receipt, or output.\n\n## Transaction semantics\n\nDeclaration parsing rejects unknown fields, identity drift, unsupported\ncapability/adapter pairs, unbounded retries, and executable keys recursively.\nCompilation produces deterministic effect and plan roots. Execution persists\none atomic checkpoint containing ordered operations, rooted observations, and\nrooted receipts.\n\nFor each effect Buildchain performs readback before mutation, applies at most\nthe declared bounded local attempts, then performs readback again. Buildchain\ncore alone compares the declared subject and target roots and chooses\n`complete`, `blocked`, `repair-required`, or `terminal-failure`. An adapter can\nreport observed, absent, transient, or conflict; it cannot declare success.\n\nThe built-in adapters are:\n\n- `github-release-assets`: exact GitHub Release tag and immutable named assets;\n- `signed-static-channel`: rooted HTTPS JSON channel commit with optional CAS;\n- `site-release-activation`: rooted HTTPS activation and public readback;\n- `activation-receipt-projector`: deterministic released-evidence synthesis.\n\nDuplicate execution is a readback no-op. A lost mutation response is recovered\nby the next local readback. A stale rooted object requires repair, immutable\nprovider collision is terminal, and credential/network uncertainty remains a\nbounded blocked result rather than synthesized success.\n\n## Local verification\n\n```bash\nbuildchain release-tail plan --declaration release-tail.json\nbuildchain release-tail init --declaration release-tail.json --state .buildchain/release-tail/state.json\nbuildchain release-tail verify --state .buildchain/release-tail/state.json\n```\n\nProvider execution belongs in the Action or reusable workflow so token handling\nand provider permissions remain explicit. Retain the state artifact: it is the\nresume boundary and evidence source, not a disposable log.\n\n## Buildchain self-dogfood route\n\nBuildchain self-release calls the same public reusable workflow coordinate as a\nconsumer:\n\n```text\nkungfu-systems/buildchain/.github/workflows/release-candidate-promote.yml@train/v3/v3.0/consumer-equivalent-self-dogfood\n```\n\nThe public router resolves the workflow shell and runtime to exact SHAs. For\nalpha self-release, the promotion Action materializes the sealed GitHub Release\nasset declaration, executes it through this provider plane, and retains the\ndeclaration root, transaction root, state root, receipt roots, controller\nreceipt, and route-parity evidence. The legacy GitHub Release helper is not a\nfallback when `declarative-release-tail` is enabled; a provider or readback\nfailure fails the authoritative run.\n\nStable routing remains on the existing `v3` shell and does not receive the new\nalpha-train input. Stable cutover is a separate gate after prerelease dogfood.\n\n## v3 compatibility boundary\n\n`release-tail compat --hooks-json <json-or-path>` recognizes only the frozen v3\nhook names. It emits diagnostics for enumerated legacy callers and rejects any\nnew command-bearing release-tail field. Compatibility never converts legacy\nshell into a new provider plugin and never reinterprets settled release history."
    },
    {
      "id": "manual:release-train",
      "title": "Release Train and Release Cut",
      "route": "/docs/release-train",
      "category": "manual",
      "capabilityGroup": "governance-versioning",
      "audience": [
        "release-operator",
        "consumer",
        "agent"
      ],
      "maturity": "preview",
      "sourcePath": "docs/release-train.md",
      "digest": "sha256:6989ada03d381e68fdec55b26b76b2070fb37969826eadc0a989844a732ba557",
      "headings": [
        {
          "level": 1,
          "title": "Release Train and Release Cut",
          "anchor": "release-train-and-release-cut"
        },
        {
          "level": 2,
          "title": "Frozen Release Cut",
          "anchor": "frozen-release-cut"
        },
        {
          "level": 2,
          "title": "Release Train state",
          "anchor": "release-train-state"
        },
        {
          "level": 2,
          "title": "Rooted release-blocker repair",
          "anchor": "rooted-release-blocker-repair"
        },
        {
          "level": 2,
          "title": "Buildchain self-dogfood campaign",
          "anchor": "buildchain-self-dogfood-campaign"
        },
        {
          "level": 2,
          "title": "Readback and legacy state",
          "anchor": "readback-and-legacy-state"
        },
        {
          "level": 2,
          "title": "Public API and schemas",
          "anchor": "public-api-and-schemas"
        }
      ],
      "markdown": "---\nstatus: preview\nperiod: ongoing\ntheme: buildchain-release-train\ndoc_type: architecture-and-usage\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: self-reviewed\nlast_reviewed: 2026-08-11\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-08-11\n  visible_context: Buildchain v4 parity of the v3 release candidate, recovery, Dev to Alpha Candidate Patrol, rooted blocker repair, Warrant, publication transaction, and release governance sources.\n  invisible_context_boundary: Live provider state and credentials were not read.\n---\n\n# Release Train and Release Cut\n\nBuildchain v4 exposes the same pure, provider-neutral Release Train contract proven on v3 for\nretaining one authorized Alpha candidate while the development branch keeps\nmoving. The contract does not select a candidate, write a Git ref, open a pull\nrequest, publish a package, or replace any existing provider gate. Controllers\nown those effects and persist the rooted contract in their declared store.\n\n## Frozen Release Cut\n\n`createReleaseCut()` records one exact candidate generation. It binds:\n\n- repository, source branch, and target branch;\n- the development head from which the cut was authorized;\n- candidate commit and tree;\n- exact Alpha base and Buildchain runtime commits;\n- a positive generation;\n- sorted, duplicate-free authority roots; and\n- a canonical creation timestamp.\n\nThe resulting `cutRoot` covers all of those fields. A generation greater than\none must name the prior cut root and one of five supersession causes:\n\n- `release-blocker-repair` (reserved for the rooted repair contract below);\n- `incompatible-semantics`;\n- `alpha-base-incompatibility`;\n- `invalid-authority`; or\n- `severe-security`.\n\nLatest-development movement is deliberately absent from that list. Merely\nobserving a newer development head therefore cannot replace the candidate or\nincrement its generation.\n\n## Release Train state\n\n`createReleaseTrain()` wraps the frozen cut in\n`kungfu-buildchain-release-train/v1`. The train identity root covers only the\nimmutable Release Cut. Its state chain can move through:\n\n```text\npreparing -> building -> publication-blocked -> publishable -> terminal\n                   \\-> repair-required --------^          \\-> superseded\n```\n\nThe complete transition table is enforced by the Node API. `superseded` and\n`terminal` are terminal states. A superseded transition must bind its explicit\ncause, replacement cut root, and replacement candidate commit.\n\nEvery transition uses compare-and-swap against the exact current `stateRoot`,\nbinds non-empty authority roots, and produces deterministic request,\ntransition, and next-state roots. Replaying the exact same request after it has\nalready landed returns the existing train unchanged. A stale expected state or\nan invalid transition fails closed.\n\n`observeReleaseTrain()` appends a rooted development-head observation without\nchanging `trainRoot`, `cutRoot`, candidate identity, generation, or state. The\nsame exact observation is idempotent.\n\n## Rooted release-blocker repair\n\n`createReleaseBlockerRepair()` starts only from the active train's exact\n`repair-required` state root. It creates generation N+1 from the frozen cut,\nchanging only the candidate commit and tree while preserving the original Dev\ncut, Alpha base, runtime, route, and prior cut root. The prior train receives an\nexplicit `release-blocker-repair` supersession transition; later Dev movement\nalone still cannot advance a generation.\n\nThe repair binds one semantic patch root to a cut landing and a Dev\nforward-port. A successful cut landing makes the successor candidate buildable\neven while the Dev forward-port is in conflict. Publication remains blocked\nuntil `settleReleaseBlockerDevLanding()` compare-and-swap checks the repair root\nand records a Dev landing with the same patch root. A landed but different Dev\npatch produces a rooted `cut-dev-patch-root-mismatch` gate rather than\npublication authority.\n\nBuildchain v4 Candidate Patrol resolves the open managed candidate's persisted\ntrain before it considers a new qualified development head. It reads back the\ncandidate ref and tree, Alpha base, and exact Buildchain runtime. Matching\ncoordinates resume the frozen candidate; a newer development head becomes a\nsingle rooted observation. Candidate, tree, base, runtime, or route drift emits\na rooted hold and stops settlement. Only a validated train already carrying an\nenumerated `superseded` transition is reported as superseded.\n\n## Buildchain self-dogfood campaign\n\nBuildchain qualifies the complete v4 parity mechanism with\n`scripts/release-train-self-dogfood.mjs`. The campaign composes one frozen\nRelease Cut, moving-dev observation, deterministic failed build, successor\nrepair, cut/dev patch-root settlement, publication gate, and bounded Delivery\nWarrant priority. It also proves that an active Warrant is not preempted and\nthat duplicate events, invalid authority, and unrelated priority claims fail\nclosed.\n\nThe command accepts an exact evidence input and emits a replayable rooted\nreport:\n\n```sh\nnode scripts/release-train-self-dogfood.mjs \\\n  --input /path/to/exact-protected-delivery.json \\\n  --output /tmp/buildchain-release-train-self-dogfood.json\n```\n\nA passing report requires a merged protected PR, exact-head approval,\nmerge-group CI success, tree-equivalent merge readback, artifact evidence, and\ninstalled-product evidence. Synthetic or unit-only evidence is useful for\nnegative tests but is not sufficient for release qualification.\n\n## Readback and legacy state\n\n`validateReleaseCut()` checks the standalone immutable cut and its canonical\nroot. `validateReleaseTrain()` replays the complete transition and observation\nchain from that frozen cut and rejects root drift, stale compare-and-swap\nedges, duplicate observations, or an invalid lifecycle path.\n\n`readReleaseTrain()` also recognizes the existing\n`kungfu-buildchain-dev-alpha-candidate-state/v1` patrol marker. That path is a\nread-only compatibility projection with `authoritative: false` and `train:\nnull`. It exposes the legacy generation and candidate SHA when present, but it\nnever invents a Release Cut, authority root, runtime binding, Alpha base, or\ncandidate tree retroactively. A controller must create a new, fully witnessed\nRelease Cut before it can claim Release Train authority.\n\n## Public API and schemas\n\nImport the contract from `@kungfu-tech/buildchain/release-train`. Machine\nschemas are published with the package:\n\n- `contracts/release-cut-v1.schema.json`;\n- `contracts/release-train-v1.schema.json`; and\n- `contracts/release-train-transition-v1.schema.json`.\n\nThe schemas check structure. The Node validator remains authoritative for\ncanonical roots, state-chain replay, idempotence, and cross-field semantics."
    },
    {
      "id": "manual:reusable-build-surface",
      "title": "Reusable Build Surface",
      "route": "/docs/reusable-build-surface",
      "category": "manual",
      "capabilityGroup": "reusable-build",
      "audience": [
        "consumer",
        "release-operator"
      ],
      "maturity": "stable",
      "sourcePath": "docs/reusable-build-surface.md",
      "digest": "sha256:54cadd6e2f168ca40d9ed66d2f9848d5d56c9d05759bf0454f5027b1df274796",
      "headings": [
        {
          "level": 1,
          "title": "Reusable Build Surface",
          "anchor": "reusable-build-surface"
        },
        {
          "level": 2,
          "title": "Automatic Channel Router",
          "anchor": "automatic-channel-router"
        },
        {
          "level": 2,
          "title": "Advanced Workflow",
          "anchor": "advanced-workflow"
        },
        {
          "level": 2,
          "title": "Linux Job Containers",
          "anchor": "linux-job-containers"
        },
        {
          "level": 2,
          "title": "Native Rust Toolchains",
          "anchor": "native-rust-toolchains"
        },
        {
          "level": 2,
          "title": "Buildchain Runtime Override",
          "anchor": "buildchain-runtime-override"
        },
        {
          "level": 2,
          "title": "Floating Ref Contract Lock",
          "anchor": "floating-ref-contract-lock"
        },
        {
          "level": 2,
          "title": "Shifu Cache Profile Passthrough",
          "anchor": "shifu-cache-profile-passthrough"
        },
        {
          "level": 2,
          "title": "Locked Source Checkout Cache",
          "anchor": "locked-source-checkout-cache"
        },
        {
          "level": 2,
          "title": "Auditable Compiler Cache",
          "anchor": "auditable-compiler-cache"
        },
        {
          "level": 2,
          "title": "Workflow Outputs",
          "anchor": "workflow-outputs"
        },
        {
          "level": 2,
          "title": "Artifact Signing Authority",
          "anchor": "artifact-signing-authority"
        },
        {
          "level": 2,
          "title": "Artifact Transfer Relay",
          "anchor": "artifact-transfer-relay"
        },
        {
          "level": 2,
          "title": "Publish Gate",
          "anchor": "publish-gate"
        },
        {
          "level": 2,
          "title": "Publish Source Lock",
          "anchor": "publish-source-lock"
        },
        {
          "level": 2,
          "title": "Release Candidate Promote-Only",
          "anchor": "release-candidate-promote-only"
        },
        {
          "level": 2,
          "title": "Package-Set Publish Plan",
          "anchor": "package-set-publish-plan"
        },
        {
          "level": 2,
          "title": "Command Sources",
          "anchor": "command-sources"
        },
        {
          "level": 2,
          "title": "Artifact Contract",
          "anchor": "artifact-contract"
        },
        {
          "level": 2,
          "title": "Trusted Event Gate",
          "anchor": "trusted-event-gate"
        },
        {
          "level": 2,
          "title": "Fixture",
          "anchor": "fixture"
        }
      ],
      "markdown": "---\nstatus: draft\nperiod: ongoing\ntheme: buildchain-reusable-build\ndoc_type: technical-reference\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-08-03\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-08-03\n  invisible_context: not asserted\n---\n\n# Reusable Build Surface\n\nBuildchain v3 provides a reusable build workflow for repositories that need\nBuildchain's release semantics but cannot be described as a simple Node package.\nThe first target shape is `libnode`: expensive native builds, multiple operating\nsystems, self-hosted runner labels, and release artifacts that must be auditable.\n\nFor Linux release artifacts, the build workflow can hand the sealed artifact,\nplatform manifest, and Release Passport to the separate GitHub-hosted keyless\nattester. The compiler runner remains the recorded build identity; the attester\nonly signs and verifies immutable data. See\n[`github-artifact-attestation.md`](github-artifact-attestation.md).\n\n## Automatic Channel Router\n\nThe preferred consumer surface is one reusable workflow call. Consumers keep\nthis configuration for both alpha development and stable release work:\n\n```yaml\njobs:\n  build:\n    uses: kungfu-systems/buildchain/.github/workflows/build.yml@v3\n    permissions:\n      contents: read\n      issues: write\n      id-token: write\n    with:\n      working-directory: .\n      artifact-name: libnode\n      runner-preset: kungfu-v4-self-hosted\n      publish-channel: none\n    secrets: inherit\n```\n\n`buildchain-channel` defaults to `auto`. Selection uses this precedence:\n\n1. an explicit `buildchain-ref` protected authority, train, SHA, or official channel;\n2. an explicit `buildchain-channel: alpha|stable`;\n3. `publish-channel: alpha|release|major`;\n4. GitHub release prerelease metadata;\n5. a canonical semver tag;\n6. non-release PR, push, dispatch, schedule, and workflow-run events default to\n   alpha.\n\nThe resolved runtime is `vN-alpha` for development and prerelease intent and\n`vN` for stable release intent. Unknown custom publish channels, malformed\nrelease events, and non-semver release-like tags fail before the build matrix;\nthey never guess alpha for a stable release.\n\nThe router automatically selects `.buildchain/alpha-contract-lock.json` for\nalpha and `.buildchain/contract-lock.json` for stable. The generated workflow\nuses two static advanced-workflow calls: `@vN-alpha` for alpha and `@vN` for\nstable. A repository can override the common path with\n`buildchain-contract-lock-path`, or override one channel with\n`buildchain-alpha-contract-lock-path` / `buildchain-stable-contract-lock-path`,\nbut the path is never channel authority. The selected file's\n`buildchain.ref` must prove the same channel and major as the workflow shell and\nruntime.\n\nChannel binding is independent of the current Buildchain major. Every\nchannel-bound run validates the complete triad before compatibility drift:\n\n- stable = shell `vN` + runtime `vN` + a lock whose ref is stable `vN`;\n- alpha = shell `vN-alpha` + runtime `vN-alpha` + a lock whose ref is alpha\n  `vN-alpha`.\n\nExact release refs are classified the same way. A missing lock, an ambiguous\nidentity, a major mismatch, or any stable/alpha mixture fails even when the\ncontract digest is unchanged or the drift would otherwise be additive.\n\nOnly repositories changing the default policy need extra routing input:\n\n```yaml\nwith:\n  buildchain-channel: stable\n```\n\nDuring v3 prerelease evaluation windows, canaries use `build.yml@v3-alpha`.\nThe same router then selects `v3-alpha` or stable `v3` as the runtime.\nProduction consumers use `build.yml@v3`; this keeps the routing shell itself on\na stable ref.\n\nThe router is generated from `.build.yml`'s input/output surface. Run\n`node scripts/generate-channel-build-workflow.mjs` after changing the advanced\nbuild workflow; inventory and unit tests reject a stale generated router.\n\n## Advanced Workflow\n\nConsumers that need direct workflow-shell or runtime control call the advanced\nsurface:\n\n```yaml\njobs:\n  build:\n    uses: kungfu-systems/buildchain/.github/workflows/.build.yml@v3\n    with:\n      working-directory: .\n      artifact-name: libnode\n      runner-preset: kungfu-v4-self-hosted\n      linux-container-preset: kungfu-verify\n      artifact-name-template: \"{artifact}-{platform}-{sha}\"\n      artifact-paths: |\n        dist\n        build/stage\n      pre-upload-transport-smoke-scenario-path: .buildchain/auditable-demo.json\n      pre-upload-transport-smoke-artifact-root: .\n      expected-artifacts-json: >-\n        {\"minFiles\":2,\"requiredPaths\":[\"dist/libnode.tar.gz\",\"dist/checksums.txt\"]}\n      process-summary-path: .buildchain/diagnostics/process-summary.json\n      release-candidate: true\n      publish-channel: release\n      publish-source-ref: publish-gate/release/v22/v22.22/22.22.3-kf.0\n```\n\nFor a standalone Linux binary demo, the optional pre-upload transport smoke\nuses the same declarative scenario as the later capture workflow. Buildchain\ncopies the distribution containing the scenario metadata, strips file execute\nbits to model GitHub Artifact transport, restores only the declared\ndigest-bound executable closure, and runs `transportSmoke` before either the\nGitHub Artifact or S3 relay upload step. The smoke must be non-interactive and\nis hard-capped at 60 seconds. Omitting the input preserves the ordinary build\nsurface; enabling it requires a scenario with `transportSmoke`.\n\n`runner-preset` is the stable first-class surface for known runner fleets:\n\n| Preset                  | Platforms                                                                                                      |\n| ----------------------- | -------------------------------------------------------------------------------------------------------------- |\n| `github-hosted`         | `ubuntu-24.04`, `macos-latest`, `windows-2022`                                                                 |\n| `kungfu-v4-self-hosted` | Kungfu Linux x64, macOS ARM64, and Windows x64 self-hosted runner labels                                       |\n| `kungfu-v4-native`      | Kungfu Linux x64, Linux ARM64, macOS ARM64, and Windows x64; Linux ARM64 uses GitHub-hosted `ubuntu-24.04-arm` |\n| `custom`                | Requires `platforms-json`                                                                                      |\n\nSet `self-hosted-offline-fallback: true` to inspect every exact-label\nself-hosted lane from the trusted Buildchain workflow shell before the matrix\nstarts. A lane with no matching online runner is replaced independently by its\nsupported GitHub-hosted runner: Kungfu Linux x64 uses `ubuntu-24.04`, macOS ARM64\nuses `macos-15`, and Windows x64 uses `windows-2022`. Online-but-busy runners\nremain online and keep their declared self-hosted route. Organization-owned\nrepositories inspect organization runner inventory so selected-repository runner\ngroups are not mistaken for an empty repository runner inventory. If the\ninventory token, permission, or API is unavailable, Buildchain preserves the\noriginal matrix instead of guessing that the fleet is offline. The public\nworkflow output `runner-routing-json` records only de-identified counts,\ninventory scope, and routing decisions.\n\n```yaml\nwith:\n  runner-preset: kungfu-v4-native\n  self-hosted-offline-fallback: true\nsecrets:\n  BUILDCHAIN_PROMOTION_TOKEN: ${{ secrets.KUNGFU_GITHUB_TOKEN }}\n```\n\nCallers can still provide a custom matrix with `platforms-json`. Each platform\nobject has:\n\n| Field    | Meaning                                           |\n| -------- | ------------------------------------------------- |\n| `id`     | Stable artifact/platform key, such as `linux-x64` |\n| `name`   | Human-readable job name                           |\n| `runner` | JSON string passed to `runs-on` after `fromJSON`  |\n\nThe runner field is intentionally a JSON string so callers can pass either\nGitHub-hosted runners or multi-label self-hosted runners without Buildchain\nguessing the labels.\n\nOnly include platforms that should run. GitHub schedules matrix jobs before\nsteps execute, so a disabled entry with unavailable runner labels can still\nblock the workflow queue.\n\n`fail-fast` defaults to `false`, preserving the diagnostic behavior that\ncollects every platform result. Required promotion callers can set it to `true`\nto cancel sibling native, container, and relay matrix lanes after the first\nfailure. This input changes scheduling only: it does not reduce the declared\nplatform matrix, turn cancellation into a pass, or alter artifact and release\nadmission.\n\n## Linux Job Containers\n\nLinux build platforms can run inside a digest-pinned job container while macOS\nand Windows keep using native runners. This is the recommended way to remove\nmoving Linux runner prerequisites from Buildchain consumers: the Linux host only\nneeds a GitHub Actions runner, Docker, and network access; common verification\ntools come from the image contract.\n\nUse the Kungfu verification image for lifecycle stages that need Git, jq,\nPython, uv, and fnm, but do not need native compilation:\n\n```yaml\njobs:\n  build:\n    uses: kungfu-systems/buildchain/.github/workflows/.build.yml@v3\n    with:\n      runner-preset: kungfu-v4-self-hosted\n      linux-container-preset: kungfu-verify\n```\n\n`kungfu-verify` resolves to:\n\n```text\nghcr.io/kungfu-systems/build-images/kungfu-verify@sha256:11f0ba64267ce88174a4f73a9bf833ff4e9c59cd16ec3d08a6432a06c2be6fb1\n```\n\nCallers that own a different Linux image can pass it explicitly:\n\n```yaml\nwith:\n  linux-container-preset: custom\n  linux-container-image: ghcr.io/example/project-build@sha256:<digest>\n```\n\n`linux-container-image` should be pinned by digest. A floating tag makes the\nrunner surface mutable and weakens Buildchain's release evidence.\n\nThe workflow splits the matrix into two build jobs:\n\n- Linux platforms go to `build-linux-container` when a Linux container is\n  configured.\n- All other platforms go to `build-native`.\n\nArtifact names, manifest paths, expected artifact checks, publish-source locks,\nand aggregate summaries are the same in both jobs. The split is an execution\ndetail, not a different artifact contract.\n\n## Native Rust Toolchains\n\nNative lifecycle jobs can request an isolated Rust installation instead of\ndepending on a self-hosted runner user's PATH:\n\n```yaml\nwith:\n  setup-rust: true\n  rust-toolchain: \"1.96.0\"\n  rustup-dist-server: \"https://rsproxy.cn\"\n  rustup-update-root: \"https://rsproxy.cn/rustup\"\n  cargo-registry-index: ${{ vars.BUILDCHAIN_CARGO_REGISTRY_INDEX }}\n```\n\n`setup-rust` defaults to `false`, so existing consumers are unchanged. When it\nis enabled, Buildchain installs `rust-toolchain` before the install, build, and\nverify lifecycle stages on every native matrix platform. Windows uses the\nofficial rustup bootstrap through `cmd.exe` and `curl.exe` into runner-temporary\nCargo and rustup homes, so it works under a restrictive PowerShell execution\npolicy and the service account does not depend on another user's PATH or mutate\nhost toolchain state. Pin an exact toolchain for release builds. Linux container jobs continue\nto obtain Rust from their digest-pinned image contract; Buildchain does not\nmutate that container surface.\n\nThe rustup server inputs are optional and default to Rust's official servers.\nConsumers behind a slow cross-border link may select a trusted transport mirror;\nrustup still verifies the selected toolchain's distribution metadata and\ncomponent checksums.\n\n`cargo-registry-index` is also optional. When set, Buildchain exposes it to\nCargo as `CARGO_REGISTRIES_CRATES_IO_INDEX` for every native lifecycle stage,\nso a self-hosted runner can use a repository or organization variable without\ncommitting private LAN topology to public workflow YAML. The endpoint must be a\ncrates.io-compatible index whose `config.json` download contract serves the\nmatching checksum-verified crate archives. An empty value preserves Cargo's\nnormal crates.io behavior.\n\nThe container image provides `fnm` but does not preinstall Node. Buildchain uses\n`fnm` inside the container to install the requested `node-version` before it\nruns Buildchain runtime scripts or lifecycle actions.\n\nDo not use `kungfu-verify` for stages that need CMake, Ninja, ccache, Conan, or\nDocker image publishing. Those should use a heavier native-build image or remain\non a host runner until their image contract is explicit.\n\n## Buildchain Runtime Override\n\nStable consumers should keep the reusable workflow pinned to stable refs such as\n`@v3`. The optional `buildchain-ref` input is empty by default; empty means\nBuildchain resolves and executes the stable runtime selected by the workflow\nshell. The full train validation protocol is documented in\n[`runtime-train-validation.md`](runtime-train-validation.md).\n\nFor one-off manual validation, a trusted maintainer can run the caller workflow\nwith a temporary runtime override. The override inherits the caller's declared\nalpha or stable lane; trust authorizes the opaque ref, not cross-channel use:\n\n```yaml\non:\n  workflow_dispatch:\n    inputs:\n      buildchain-ref:\n        description: \"Temporary Buildchain runtime ref for trusted manual validation\"\n        required: false\n        default: \"\"\n\njobs:\n  build:\n    uses: kungfu-systems/buildchain/.github/workflows/.build.yml@v3\n    with:\n      buildchain-ref: ${{ inputs.buildchain-ref || '' }}\n```\n\nAllowed override refs are deliberately narrow:\n\n| Ref form                                | Meaning                                                |\n| --------------------------------------- | ------------------------------------------------------ |\n| `train/v3/v3.0/<capability>`            | Temporary capability train under the active minor line |\n| `refs/heads/train/v3/v3.0/<capability>` | Explicit branch ref for the same train                 |\n| `<40-character SHA>`                    | Exact immutable Buildchain runtime commit              |\n\nOverride requests fail closed unless the event is `workflow_dispatch` and the\nactor has write, maintain, or admin permission on the caller repository. One\nnon-override exact-pin case is also admitted: when the reusable workflow itself\nis invoked from an exact Buildchain SHA and `buildchain-ref` names that identical\nSHA, the run records `pinned-self`. The input cannot select code other than the\nalready-running workflow shell, so protected push and pull-request publication\njobs can retain one immutable runtime root. Different SHA and train requests\nstill fail closed outside trusted manual dispatch.\n\nPull requests, including same-repository pull requests and fork-originated pull\nrequests, cannot select an independent `buildchain-ref` override. This keeps\nautomated PR builds on the stable or exact pinned-self runtime surface.\n\nEvery run resolves the runtime ref to an immutable SHA before checkout. The job\nsummary and aggregate build summary record the workflow shell ref, requested\nruntime ref, resolved runtime ref, runtime SHA, stability class, trust decision,\nand rollback ref. Train refs are development validation refs: they do not move\n`v3`, `vX.Y`, `vX.Y-alpha`, npm dist-tags, or production release refs, and they\nmust not be pinned as long-term production dependencies.\n\nRuntime override validates Buildchain runtime scripts, CLI code, local actions,\nconfig parsing, and lifecycle behavior. It cannot validate changes that require\nthe outer reusable workflow YAML itself to change, such as new jobs,\npermissions, workflow outputs, or matrix topology. Those changes need a canary\nworkflow path or a temporary explicit workflow ref.\n\n## Floating Ref Contract Lock\n\nStable consumers should use floating major refs such as `@v3`, but a floating\nref is not blind trust. Each released Buildchain ref carries a package-owned\nruntime contract world in `dist/site/buildchain-contract.json`. Consumers may\nkeep a small lock file, `.buildchain/contract-lock.json`, recording the\nBuildchain ref, resolved SHA, contract digest, compatibility digest, accepted\nmajor line, and compatibility policy they reviewed.\n\nThe reusable build trust gate checks this lock before any heavy matrix job:\n\n1. resolve the Buildchain runtime ref, for example `v3`, to an immutable SHA;\n2. read `dist/site/buildchain-contract.json` from that checked-out Buildchain\n   ref;\n3. read the consumer's `.buildchain/contract-lock.json`;\n4. compare the accepted contract with the current contract.\n\nSHA drift alone is not a failure. `v3` is expected to advance. Buildchain only\nfails fast when the accepted contract is no longer compatible, for example a\nrequired input is removed, a required output disappears, a protected behavior\npromise changes, or the major line changes. Additive changes such as optional\ninputs, optional outputs, diagnostics, or documentation updates continue under\nthe default `major-compatible` policy.\n\n```yaml\njobs:\n  build:\n    uses: kungfu-systems/buildchain/.github/workflows/.build.yml@v3\n    permissions:\n      contents: read\n      issues: write\n      id-token: write\n    with:\n      buildchain-contract-lock-path: .buildchain/contract-lock.json\n      buildchain-contract-compatibility-policy: major-compatible\n      buildchain-contract-drift-issue-mode: compatible-and-breaking\n```\n\nWhen compatible drift is detected, the build continues and Buildchain opens or\nupdates a low-priority issue in the consumer repository. The issue records the\nold SHA/digest, new SHA/digest, compatibility result, workflow run, and the next\naction: review the Buildchain release notes and update the lock. When breaking\ndrift is detected, the same issue path is used, but the trust gate fails before\nmatrix build or publish work starts. If the workflow token cannot write issues,\nBuildchain writes a copyable issue body into the job summary.\n\nThe lock is intentionally small. It does not copy the full contract. The full\ncontract remains in the Buildchain ref and package; the consumer records only\nwhat it accepted and the policy used to compare future floating-ref movement.\n\nAdvanced alpha-channel consumers select the matching workflow shell:\n\n```yaml\njobs:\n  build:\n    uses: kungfu-systems/buildchain/.github/workflows/.build.yml@v3-alpha\n    with:\n      buildchain-contract-lock-path: .buildchain/contract-lock.json\n```\n\nThe runtime follows the called workflow through `job.workflow_ref`. Callers may\nalso pass `buildchain-ref: v3-alpha` explicitly; official floating refs are\nordinary channel selections and are allowed on pull requests and pushes. Train\nrefs and exact SHAs remain trusted manual overrides.\n\n## Shifu Cache Profile Passthrough\n\nBuildchain can carry one trusted Shifu cache-profile reference and its exact\ndigest into lifecycle execution. Its contract is an opaque reference and digest\nonly. This surface is deliberately opaque:\nBuildchain does not fetch the profile, parse JSON, select cache services,\nrewrite bindings, decide fallback, or emit Shifu resolution evidence. Those\nsemantics remain owned by the consumer's pinned Shifu implementation.\n\n```yaml\njobs:\n  build:\n    uses: kungfu-systems/buildchain/.github/workflows/build.yml@v3\n    with:\n      shifu-cache-profile-ref: ${{ vars.SHIFU_CACHE_PROFILE_REF }}\n      shifu-cache-profile-digest: ${{ vars.SHIFU_CACHE_PROFILE_DIGEST }}\n```\n\nThe reusable workflow passes the pair as `SHIFU_CACHE_PROFILE_REF` and\n`SHIFU_CACHE_PROFILE_DIGEST` to install, build, and verify lifecycle commands.\nThe consumer must invoke its Shifu cache-aware execution surface. An empty pair\npreserves existing behavior; a consumer Shifu should fail closed when exactly\none value is present or the resolved bytes do not match the expected digest.\n\nUse trusted repository or organization variables rather than PR-controlled\nfiles for private/LAN references. The variables must remain secret-free; any\ncredentials use a separate provider-approved secret surface and must not be\nembedded in the profile reference. This passthrough is separate from\nBuildchain's locked source checkout cache below: Buildchain owns checkout\ntransport and source identity, while Shifu owns post-checkout execution cache\nbindings and receipts.\n\n## Locked Source Checkout Cache\n\nSelf-hosted runners that build large repositories can opt into a locked checkout\ncache for both the consumer source and the Buildchain runtime. This changes only\nthe Git object transport. Buildchain still resolves `publish-source-sha` and the\nruntime SHA before any build runner starts, checks out those exact commits, and\nverifies each final `HEAD` plus the resolved consumer source tree SHA before\nlifecycle commands run.\n\n```yaml\njobs:\n  build:\n    uses: kungfu-systems/buildchain/.github/workflows/.build.yml@v3\n    with:\n      runner-preset: kungfu-v4-self-hosted\n      checkout-cache-mode: auto\n      checkout-cache-mirror-url-template: ${{ vars.BUILDCHAIN_CHECKOUT_CACHE_MIRROR_URL_TEMPLATE }}\n      checkout-cache-reference-repository-template: ${{ vars.BUILDCHAIN_CHECKOUT_CACHE_REFERENCE_REPOSITORY_TEMPLATE }}\n      checkout-cache-fallback: github\n      checkout-cache-timeout-seconds: 60\n      checkout-cache-github-timeout-seconds: 600\n      checkout-cache-fetch-attempts: 3\n      checkout-history-mode: shallow\n```\n\n`checkout-cache-mode` accepts:\n\n| Mode      | Behavior                                                                                                    |\n| --------- | ----------------------------------------------------------------------------------------------------------- |\n| `off`     | Default. Buildchain fetches the locked commit from GitHub.                                                  |\n| `auto`    | Try the trusted cache first; on miss, record the miss and fall back according to `checkout-cache-fallback`. |\n| `require` | Require the cache to provide the locked commit and fail before lifecycle work if unavailable.               |\n\n`checkout-history-mode` defaults to `shallow`, preserving the bounded single-\ncommit transport used by ordinary builds. Set it to `full` only when a\nconsumer gate must inspect source ancestry, for example when an Alpha pull\nrequest qualifies GitHub's synthetic merge ref while retained evidence is\nbound to an ancestor of the source-lock head. Full mode still verifies the\nresolved immutable `HEAD` and tree; it changes only whether the advertised\nsource ref is fetched with depth one or with its reachable history.\n\nThe cache can be a local/LAN mirror URL template or a runner-local bare\nreference repository template. Templates support `{owner}`, `{repo}`,\n`{repository}`, `{repositorySlug}`, and `{sha}`. The workflow also reads\nrepository or organization variables named\n`BUILDCHAIN_CHECKOUT_CACHE_MIRROR_URL_TEMPLATE` and\n`BUILDCHAIN_CHECKOUT_CACHE_REFERENCE_REPOSITORY_TEMPLATE`, so consumers can keep\nprivate LAN topology out of repository YAML.\n\nThe GitHub-hosted trust gate resolves the reusable workflow shell to an exact\ncommit and uploads that shell's small checkout bootstrap script. Native and\nLinux-container build jobs download the bootstrap, then use the same cache\npolicy to obtain both the selected Buildchain runtime and consumer source at\ntheir already resolved immutable SHAs. Keeping the bootstrap owned by the\nworkflow shell is important when `@vN-alpha` routes a stable release to an older\n`vN` runtime: the stable runtime does not need to already contain the newest\ncheckout transport implementation. This also prevents a large direct\n`actions/checkout` runtime clone from becoming a separate timeout path on\nconstrained self-hosted uplinks. The bootstrap artifact does not contain the\nruntime repository and cannot move either selected ref.\n\nDo not read cache URLs or reference paths from PR-controlled files such as\n`.buildchain/buildchain.toml`. These values are trusted workflow inputs or repo/org\nvariables. Buildchain does not pass GitHub credentials to cache mirrors or\nreference repositories. If it must fall back to GitHub, the workflow token is\nused only for the GitHub fetch path. Cache attempts use\n`checkout-cache-timeout-seconds`; the potentially larger GitHub fallback uses\nthe independent `checkout-cache-github-timeout-seconds` budget (600 seconds by\ndefault). Buildchain fetches the advertised source ref before trying an exact\nSHA, so a cache hit or stale-cache seed can contribute objects and the fallback\ndoes not first waste a full timeout on an unadvertised SHA. Retryable timeout\nand transient network failures use the bounded `checkout-cache-fetch-attempts`\nbudget; permanent failures stop immediately. Diagnostics record both timeout\nbudgets and the actual GitHub fetch attempts before exact HEAD/tree\nverification.\n\nEach platform diagnostics artifact includes `source-checkout.json` and embeds a\ncompact `sourceCheckout` summary in `diagnostics.json`: mode, transport,\nhit/miss, fallback reason, duration, final HEAD verification, and tree\nverification. Remote URLs are sanitized and local reference paths are represented\nby a short display name plus fingerprint, not by secret-bearing credentials.\nRuntime checkout evidence is uploaded separately as `runtime-checkout.json`,\nincluding cache transport, fallback attempts, and exact runtime `HEAD`\nverification, even when a later lifecycle step fails.\n\n## Auditable Compiler Cache\n\nConsumers can prepare `sccache` on selected platforms after the install\nlifecycle and before compilation:\n\n```yaml\nwith:\n  compiler-cache-provider: sccache\n  compiler-cache-platforms-json: '[\"windows-x64\"]'\n  compiler-cache-required: true\n```\n\nThe consumer remains responsible for installing and pinning the tool before\nthe preparation step. Buildchain probes its version, runs `sccache\n--zero-stats`, and writes\n`compiler-cache-preparation.json`. The receipt binds the source commit/tree,\nBuildchain runtime, platform, cache profile, and any declared dependency,\ntoolchain, or policy roots. It resets counters only; it does not delete cached\ncompiler outputs. The same preparation exports `RUSTC_WRAPPER`,\n`CMAKE_C_COMPILER_LAUNCHER`, and `CMAKE_CXX_COMPILER_LAUNCHER` so Cargo and\nCMake/Ninja compilation actually passes through the audited tool.\n\nAfter the build lifecycle, Buildchain probes the reset counter set again. When\n`compiler-cache-required` is true, the build fails closed if sccache observed\nzero compiler requests or zero cacheable requests. This prevents an installed\nbut unbound sccache binary from being reported as an active compiler cache.\n\nFinal diagnostics admit sccache hit/miss outcomes as current-run evidence only\nwhen that preparation receipt is present and valid. A bare `sccache\n--show-stats` result without the reset receipt remains cumulative and is\nreported as unavailable for the current run. The preparation receipt is copied\ninto the small diagnostics artifact and sealed by\n`diagnostics-manifest.json`.\n\nWhen a Buildchain maintainer asks for downstream validation, the expected\nrequest is:\n\n```text\nBuildchain train ready: buildchain-ref=train/v3/v3.0/<capability>.\nKeep uses: ...@v3; run workflow_dispatch with that buildchain-ref and report the runtime evidence summary.\n```\n\nAfter validation succeeds, the Buildchain change should continue through the\nnormal mainline and release path. Do not treat the train as a pending merge\nitem; it is only a temporary fast-use, diagnostic, and rollback channel. It may\nremain for a retention window after release, with old trains handled by a\nseparate periodic cleanup task.\n\n## Workflow Outputs\n\nThe reusable workflow exposes the resolved contract:\n\n| Output                                | Meaning                                                                                                                                      |\n| ------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------- |\n| `runner-preset`                       | Resolved preset, or `custom` when `platforms-json` was provided                                                                              |\n| `platforms-json`                      | Exact matrix JSON used by the build job                                                                                                      |\n| `platform-count`                      | Number of matrix platforms                                                                                                                   |\n| `linux-container-enabled`             | `true` when Linux platforms are routed through a job container                                                                               |\n| `linux-container-image`               | Resolved digest-pinned Linux job container image                                                                                             |\n| `build-summary-artifact`              | Uploaded aggregate summary artifact name                                                                                                     |\n| `build-diagnostics-summary-artifact`  | Uploaded aggregate diagnostics summary artifact name                                                                                         |\n| `release-candidate-passport-artifact` | Uploaded PR-stage release-candidate passport artifact name when `release-candidate` is enabled                                               |\n| `release-candidate-passport-json`     | Compact release-candidate passport JSON when `release-candidate` is enabled                                                                  |\n| `build-summary-json`                  | Compact aggregate JSON with platform count, file count, and byte total                                                                       |\n| `build-diagnostics-summary-json`      | Compact aggregate diagnostics JSON with platform, lifecycle warning/error, diagnostics contract warning, and sidecar manifest warning totals |\n| `trusted-event`                       | `true` when the event is trusted enough to reach build runners                                                                               |\n| `buildchain-runtime-ref`              | Runtime ref selected after applying the empty-default or override policy                                                                     |\n| `buildchain-runtime-sha`              | Immutable Buildchain runtime commit used by all runtime checkouts                                                                            |\n| `buildchain-runtime-class`            | `stable`, `alpha`, `authority`, `train`, `exact-sha`, or `development`                                                                       |\n| `buildchain-runtime-override`         | `true` when an authority, train, or exact-SHA `buildchain-ref` override was accepted                                                         |\n| `buildchain-runtime-trust-decision`   | Runtime override trust decision                                                                                                              |\n| `buildchain-contract-lock-status`     | `unchanged`, `compatible-drift`, `breaking-drift`, `missing-lock`, `non-floating-runtime`, or first-release `runtime-contract-unavailable`   |\n| `buildchain-contract-lock-drift`      | `true` when the floating runtime SHA or contract digest changed                                                                              |\n| `buildchain-contract-digest`          | Current Buildchain runtime contract digest                                                                                                   |\n| `publish-channel`                     | Resolved publish channel requested by the caller                                                                                             |\n| `publish-allowed`                     | `true` only when this event/ref may publish after verification                                                                               |\n| `publish-reason`                      | Human-readable reason for the publish gate decision                                                                                          |\n| `publish-source-ref`                  | Gate source ref that was resolved before checkout                                                                                            |\n| `publish-source-sha`                  | Exact source commit used by checkout, build, verify, and artifacts                                                                           |\n| `publish-source-locked`               | `true` when a `publish-gate/*` source ref was explicitly locked                                                                              |\n| `publish-source-channel`              | `alpha`, `release`, `anchor`, or `major` parsed from the source ref                                                                          |\n| `publish-source-line`                 | Product line parsed from source refs such as `v22/v22.22`                                                                                    |\n| `publish-source-consumer-version`     | Consumer package version parsed from source refs                                                                                             |\n| `release-manifest-json`               | Resolved release manifest including source lock, version state, and anchor data                                                              |\n\nThe aggregate summaries are intentionally artifacts as well as outputs. GitHub\nActions matrix outputs are not a reliable place to carry every platform's full\nmanifest, so Buildchain uploads each platform manifest and then emits one\naggregate build summary artifact after the matrix completes. Buildchain uploads\n`diagnostics-summary.json` as a separate aggregate diagnostics summary artifact,\na compact rollup of each platform's small diagnostics upload. The rollup keeps\nper-platform runner facts, checked tool versions/missing tools, package\nmanager/cache directory details, compiler-cache availability, lifecycle timing,\nprocess sampler context, and links back to the exact platform artifacts. Each\nplatform diagnostics upload includes `diagnostics.json`,\n`diagnostics-manifest.json`, the lifecycle `events.jsonl`, and process sampler\nsidecars when enabled, so slow-build diagnosis does not require downloading the\nbinary platform artifact or the aggregate build summary. The sidecar manifest\nrecords the uploaded diagnostics files with bytes and sha256 hashes. Each\n`diagnostics.json` also records the related binary artifact name, manifest\nartifact name, diagnostics artifact name, diagnostics sidecar manifest path, and\nplatform id in `links`, so a reviewer can navigate from the small diagnostics\nartifact back to the exact platform outputs when deeper inspection is needed.\nThe workflow output `build-diagnostics-summary-json` includes\n`diagnosticsContractWarningCount` and `diagnosticsManifestWarningCount` so\nrelease jobs can detect drifting diagnostics JSON contracts and missing or\ndrifting diagnostics sidecar manifests without downloading the per-platform\ndiagnostics artifacts first.\n\n## Artifact Signing Authority\n\nArtifact signing is a Buildchain capability, not a macOS application workflow.\nConsumers declare desired signature state next to their artifact facts; they do\nnot configure certificates, Team IDs, notary credentials, protected\nenvironments, authority roles, or signing jobs:\n\n```toml\n[[signing.artifacts]]\nid = \"native-engine\"\npath = \"dist/kungfu-engine\"\nprofile = \"auto\"\nkind = \"mach-o\"\nplatforms = [\"macos-arm64\", \"macos-x64\"]\n```\n\nEvery native and container build lane reads this declaration after the build\nlifecycle and before verification. Buildchain binds the exact artifact bytes or directory tree to\nthe caller repository, source commit, source tree, immutable runtime, platform,\nand requested signature semantics, then publishes a deterministic\n`<artifact>-signing-request-<platform>-<source-sha>-<run-id>-<run-attempt>`\nrequest. No consumer\nworkflow step is required. The lifecycle runner automatically adds declarations\nselected for the current platform to the `build` manifest scan, including\nsubjects outside the caller's ordinary `artifact-paths`; this extends the\nevidence preimage without silently adding those subjects to the ordinary\nartifact upload.\n\nThe request root is a Buildchain-owned generated output. After the declaration,\nlifecycle manifest, and source paths pass validation, sealing replaces that root\nbefore materializing the current request set. This keeps repeated jobs on a\nself-hosted runner idempotent and prevents stale requests from an earlier run\nfrom entering the uploaded request artifact. An output root that contains the\nworkspace, working directory, lifecycle manifest, or any declared subject is\nrejected before cleanup.\n\nSelf-hosted runners whose network requires different routes for Artifact upload\nand download can scope an upload-only proxy bypass to the sealed signing request:\n\n```yaml\nwith:\n  artifact-signing-request-upload-no-proxy: \".blob.core.windows.net\"\n```\n\nThe caller repository variable\n`BUILDCHAIN_ARTIFACT_SIGNING_REQUEST_UPLOAD_NO_PROXY` provides the same value\nwithout changing a consumer workflow; an explicit workflow input takes\nprecedence. When neither is set, Buildchain preserves the runner's existing\n`NO_PROXY` and `no_proxy` values. The resolved value applies only to the\nBuildchain-owned signing-request upload. Authority dispatch and immutable\nsigned-result download keep the runner's original proxy route. This is a\ntransport control only: it does not change request bytes, signing authority,\nartifact identity, or verification policy.\n\n`profile = \"auto\"` resolves signable Apple artifacts such as Mach-O files,\n`.dylib`, `.framework`, `.app`, `.xpc`, `.plugin`, `.pkg`, `.dmg`, and macOS\narchives containing native code to the native `apple-developer-id` provider.\nFor a declared macOS `archive`, the authority safely extracts the sealed\ncontainer, signs and verifies every Mach-O payload, signs Mach-O payloads inside\nembedded Python wheels, rebuilds each affected wheel's PEP 427 `RECORD`, and\nrecreates the original zip or tar.gz before returning the exact final bytes.\nWindows `pe` and `binary` artifacts\nresolve to timestamped native `windows-authenticode`; Windows PE never falls\nback to a detached signature. Linux and other non-native binary files,\narchives, blobs, and directories resolve to `detached-signature-v1`. Buildchain records that as a\ndetached cryptographic signature and never misrepresents it as an operating\nsystem code signature. Explicit incompatible provider/kind/platform\ncombinations fail closed.\n\nThe request schema rejects credential and authority-infrastructure fields. The\nBuildchain-owned signing authority is responsible for credential selection,\nnative signing, notarization where applicable, immutable result delivery, and a\nreceipt bound to the request digest, runtime SHA, output digest, and signature\nevidence. Consumer repositories neither receive nor duplicate credential-island\nmaterial. Each platform lane seals and uploads the unsigned request plus a\nrun-attempt-bound control request, completes functional verification, and exits.\nIt does not dispatch or poll the authority. A separate `ubuntu-24.04` controller\nstarts only after the build matrices complete, validates the exact source,\ntree, runtime, request-set root, platform, run attempt, and correlation, then\ndispatches and awaits the protected authority workflow. Its retained receipt\nrecords two independent immutable identities: the consumer Buildchain runtime\nSHA carried by the control request and the exact authority-ref commit resolved\nimmediately before dispatch. The former validates the request-producing\nruntime; the latter must equal the authority workflow run's `head_sha` and is\nretained with the exact authority run and result artifact. If the protected ref\nmoves between resolution and dispatch, settlement fails closed. Failure, timeout, or\ncancellation produces a non-qualifying receipt and no finalization delegation.\n\nA second GitHub-hosted finalization lane downloads the original control request,\ncontroller receipt, and delegation, verifies their roots and coordinates agree,\nthen verifies the authority result against the sealed request, imports the exact\nsigned bytes, and recomputes the final manifest before replacing the\ndeterministic artifact. The signing result is never downloaded back to a\nself-hosted native runner, so a macOS caller is released before credential-island\nsigning and notarization complete.\nPlatform manifests, KFD evidence, checksums, and Release Passport inputs\ntherefore observe the final signed artifact rather than the pre-signing build\noutput.\n\nFor a standalone Mach-O request, the authority requires strict Developer ID\nverification, the declared Team ID, hardened runtime, and an `Accepted`\n`notarytool` result for the exact submission. Apple creates the notarization\nticket for that binary and publishes it online, but\n[standalone binaries do not support stapling](https://developer.apple.com/documentation/security/customizing-the-notarization-workflow).\nBuildchain therefore records\n`standalone-notary-ticket-online` and does not misapply app-bundle\n`spctl --assess --type execute` semantics to the raw executable.\n\nFor a compound archive request, the authority notarizes the complete extracted\nsigned product tree and records `compound-notary-ticket-online`. A generic\narchive container cannot carry a stapled ticket and is not itself a Gatekeeper\nexecution target; Gatekeeper evaluates the extracted signed code. Archive path\nand symlink validation fail closed before any payload is signed.\n\nFor a declared `app-bundle`, the same protected authority extracts the sealed\napplication, derives and verifies its bundle identity, signs nested native code,\nsubmits both the application and disk image for notarization, staples and\nGatekeeper-assesses both deliverables, and returns a ZIP, DMG, evidence document,\nand source-bound manifest. The reusable workflow verifies those returned bytes\non GitHub-hosted infrastructure, adds them to the normal macOS platform payload,\nand publishes a separate `<artifact>-macos-credential-<source-sha>` projection\nfor release pipelines that consume the credential-island evidence contract.\nConsumers declare the `.app` under `[[signing.artifacts]]`; they do not configure\nan environment, certificate, notary credential, or authority workflow.\n\nThe durable v3 authority runtime is\n`authority/v3/v3.0/artifact-signing`. It is channel-neutral: alpha and stable\nrelease work use the same protected `buildchain-artifact-signing` environment\nand provider identities. The authority ref is protected independently from\nrelease channels and can advance only through reviewed, checked changes; the\ntemporary `train/v3/v3.0/artifact-signing-authority` ref is retained only as a\nbounded migration rollback.\n\nThe older `credential-island-macos-*` reusable-workflow inputs remain a\ncompatibility surface while existing callers migrate. They are not the target\nconsumer contract and must not be used to design new integrations.\n\n## Artifact Transfer Relay\n\nBy default, platform jobs upload payloads, manifests, and diagnostics directly\nto GitHub artifacts:\n\n```yaml\nwith:\n  artifact-transfer-mode: github-artifacts\n  artifact-compression-level: 0\n```\n\nDirect GitHub Artifact payloads default to compression level `0`. Buildchain\nartifacts are commonly already-compressed archives; storing them without a\nsecond compression pass shortens the upload window while preserving the same\nartifact name, run/id/digest binding, retention, and no-overwrite behavior.\nDirect build and signed-finalization payload uploads include hidden files under\nthe caller-declared artifact paths, matching the relay path so manifest-bound\ndotfiles are not silently removed in transit.\nCallers may select `1` through `9` for payloads that materially benefit from\ncompression. Manifests and diagnostics retain their existing small-artifact\nbehavior.\n\nLarge self-hosted native builds can opt into the first-class S3 relay path:\n\n```yaml\njobs:\n  build:\n    uses: kungfu-systems/buildchain/.github/workflows/.build.yml@v3\n    with:\n      runner-preset: kungfu-v4-self-hosted\n      artifact-transfer-mode: s3-to-github-artifacts\n      artifact-relay-s3-bucket: ${{ vars.BUILDCHAIN_ARTIFACT_RELAY_S3_BUCKET }}\n      artifact-relay-s3-region: ${{ vars.BUILDCHAIN_ARTIFACT_RELAY_S3_REGION }}\n      artifact-relay-s3-prefix: ${{ vars.BUILDCHAIN_ARTIFACT_RELAY_S3_PREFIX }}\n```\n\nThe mode is a policy for platforms that run outside GitHub. GitHub-hosted\nplatforms always upload directly with `actions/upload-artifact`, even when a\nmixed matrix requests `s3-to-github-artifacts`; they never send their payloads\nthrough S3 or the replay job. Buildchain recognizes its hosted presets and the\nstandard hosted runner labels. Custom matrices with non-standard hosted labels\nmust declare `\"githubHosted\": true` on those platform rows.\n\nFor remaining relay-mode platforms, each job uploads the heavy payload files to\nS3 and uploads only a small `relay-manifest.json` to GitHub. A GitHub-hosted\n`relay-artifacts` job then assumes the configured download role, downloads the\npayloads from S3, verifies every file by SHA256, and re-uploads the normal\nGitHub artifacts under the same artifact names that direct mode uses. Downstream\nsummary, release-candidate, and promote-only workflows therefore continue to\nconsume GitHub artifacts and do not need custom S3 logic.\nThe relay implementation uses Node.js plus the standard AWS environment\ncredentials from GitHub OIDC; runner images and build containers do not need the\nAWS CLI installed.\n\nAfter the GitHub artifact uploads succeed, Buildchain deletes the S3 objects\nlisted in the relay manifest for that platform. If any download, verification,\nor GitHub artifact upload fails, cleanup is skipped so maintainers can inspect\nthe retained S3 payload. Configure a short bucket lifecycle expiration as a\ncost and cleanup backstop.\n\nThe relay configuration is intentionally generic. Buildchain does not hard-code\norganization buckets, regions, or role ARNs. Callers may pass explicit inputs,\nor set repository/organization variables and secrets using these names:\n\n| Variable or secret                               | Meaning                                                 |\n| ------------------------------------------------ | ------------------------------------------------------- |\n| `BUILDCHAIN_ARTIFACT_RELAY_S3_BUCKET`            | Relay bucket name                                       |\n| `BUILDCHAIN_ARTIFACT_RELAY_S3_REGION`            | Relay bucket region                                     |\n| `BUILDCHAIN_ARTIFACT_RELAY_S3_PREFIX`            | Relay object prefix; defaults to `buildchain-artifacts` |\n| `BUILDCHAIN_ARTIFACT_RELAY_S3_ROLE_ARN`          | Shared OIDC role ARN for upload and download            |\n| `BUILDCHAIN_ARTIFACT_RELAY_S3_UPLOAD_ROLE_ARN`   | Upload OIDC role ARN for self-hosted build jobs         |\n| `BUILDCHAIN_ARTIFACT_RELAY_S3_DOWNLOAD_ROLE_ARN` | Download OIDC role ARN for the GitHub-hosted relay job  |\n| `BUILDCHAIN_ARTIFACT_RELAY_S3_OIDC_AUDIENCE`     | Optional OIDC audience override                         |\n\nFor AWS China regions, Buildchain defaults the OIDC audience to\n`sts.amazonaws.com.cn`; other regions default to `sts.amazonaws.com`. The caller\nworkflow must allow `id-token: write`, and the target role trust policy should\nrestrict GitHub OIDC claims to the expected organization, repository, workflow,\nand branch/ref. The S3 permissions should be scoped to the relay bucket/prefix\nused by the repository.\nUpload roles need write/delete access under the relay prefix; download roles\nneed read access plus delete access for successful cleanup.\n\nRelay mode is opt-in and does not affect forks or open-source users that do not\nconfigure S3. Missing bucket, region, upload role, or download role values fail\nbefore the heavy build matrix is scheduled. Buildchain treats S3 as a transport\ncache, not as the final release evidence store; the final audit entry remains\nthe GitHub artifact set plus the Buildchain build summary and release-candidate\npassport.\n\nSet `release-candidate: true` when the successful reusable build is meant to be\nthe artifact source promoted later. Buildchain then uploads\n`release-candidate-passport.json` under the\n`<artifact-name>-release-candidate-<publish-source-sha>` artifact name. Promotion\njobs can pass that passport to `promote-buildchain-ref` with\n`promote-only-release-candidate: \"true\"` so source, channel, platforms, and the\naggregate build-summary hash are checked before publish-gate side effects. The\npassport records the locked commit's Git tree SHA, so a post-merge channel HEAD\ncan be accepted only when it is tree-equivalent to the PR-stage build evidence.\n\n## Publish Gate\n\nBuildchain separates \"may build/verify\" from \"may publish.\" A same-repository\npull request may be trusted enough to run the build matrix, but it still must\nnot publish packages, S3 objects, release pages, or preview aliases. Publishing\nis allowed only when the caller explicitly requests a channel and the current\nevent/ref matches that channel.\n\nUse `publish-channel` to request a channel:\n\n```yaml\njobs:\n  build:\n    uses: kungfu-systems/buildchain/.github/workflows/.build.yml@v3\n    with:\n      publish-channel: release\n\n  publish:\n    needs: build\n    if: ${{ needs.build.outputs.publish-allowed == 'true' }}\n    runs-on: ubuntu-24.04\n    steps:\n      - run: ./scripts/publish.sh\n```\n\nDefault channels are:\n\n| Channel   | Allowed refs                                                                                         |\n| --------- | ---------------------------------------------------------------------------------------------------- |\n| `none`    | Never publishes; this is the default                                                                 |\n| `alpha`   | `alpha/vN/vN.M` branches or exact `vN.M.P-alpha.K` tags                                              |\n| `release` | `release/vN/vN.M` branches or release tags such as `vN.M.P`, `vN.M`, `vN`                            |\n| `major`   | `publish-gate/major`, legacy `major-gate`, or next-major release tags such as `vN.0.0`, `vN.0`, `vN` |\n\nPull request events always produce `publish-allowed=false`, even when the PR is\nfrom the same repository. Untrusted fork events also produce\n`publish-allowed=false`; with the default `untrusted-policy: fail`, the workflow\nthen fails before any build runner starts.\n\nProjects with their own channel names can pass `publish-refs-json`:\n\n```yaml\nwith:\n  publish-channel: nightly\n  publish-refs-json: >-\n    {\"nightly\":[\"^refs/heads/nightly/v\\\\d+$\"]}\n```\n\nThe aggregate build summary includes the same publish gate decision under\n`publishGate`, so a downloaded artifact summary explains both what was built and\nwhy it was or was not eligible to publish.\n\n## Publish Source Lock\n\n`publish-channel` answers \"may this event publish?\" Source lock answers \"which\nsource tree is the publish decision about?\" A caller can pass `publish-source-ref`\nto bind a publish run to a reviewed gate branch before any checkout happens:\n\n| Ref                                              | Meaning                                                                     |\n| ------------------------------------------------ | --------------------------------------------------------------------------- |\n| `publish-gate/alpha/<line>/<consumer-version>`   | Build and publish an alpha candidate for a consumer line                    |\n| `publish-gate/release/<line>/<consumer-version>` | Build and publish a production candidate for a consumer line                |\n| `publish-gate/anchor`                            | Resolve an explicit anchor request; it does not publish artifacts by itself |\n| `publish-gate/major`                             | Gate the next major source state                                            |\n| `major-gate`                                     | Legacy compatibility alias for the major gate                               |\n\nFor alpha and release refs, `<line>` is intentionally allowed to contain `/`, so\nKungfu-style lines such as `v22/v22.22` stay readable. The final path segment is\nthe consumer-visible version, for example `22.22.3-kf.0`.\n\nThe reusable workflow resolves the branch tip to `publish-source-sha`, checks out\nthat SHA in every build job, and uses the same SHA in artifact names, manifests,\nand aggregate summaries. Reruns therefore rebuild the same source tree even if a\ngate branch moves later.\n\nBefore any heavy build matrix is scheduled, the workflow also verifies that the\ntarget channel ref implied by the source lock already points at\n`publish-source-sha` and that the target channel HEAD came from the required\nmerged same-repository channel PR. `publish-gate/alpha/<line>/<version>` must\nmatch `alpha/<line>` and have PR lineage `dev/<line> -> alpha/<line>`;\n`publish-gate/release/<line>/<version>` must match `release/<line>` and have PR\nlineage `alpha/<line> -> release/<line>`. If either check fails, the run fails\nfast with a diagnostic telling maintainers to merge the source commit through\nthe channel PR first. This keeps verify from spending runner time on a source\ntree that cannot legally enter the requested publish channel.\n\nThe resolved release manifest is uploaded as an artifact and emitted as\n`release-manifest-json`. It records:\n\n- source ref, source SHA, channel, line, and consumer version;\n- configured version strategy and configured version-state files;\n- each version file's value, with release gates failing closed if the configured\n  files do not equal the consumer version;\n- anchor manifest summary for anchored/manual projects;\n- explicit anchor request JSON for `publish-gate/anchor`;\n- publish registry, dist-tag, and gate visibility metadata.\n\nPublish side-effect jobs should verify the lock immediately before publishing:\n\n```yaml\n- name: Verify publish gate did not move\n  run: node .buildchain/runtime/scripts/verify-publish-source-lock.mjs\n  env:\n    BUILDCHAIN_PUBLISH_SOURCE_REF: ${{ needs.build.outputs.publish-source-ref }}\n    BUILDCHAIN_PUBLISH_SOURCE_SHA: ${{ needs.build.outputs.publish-source-sha }}\n    BUILDCHAIN_SOURCE_REPOSITORY: ${{ github.repository }}\n    GITHUB_TOKEN: ${{ github.token }}\n```\n\nIf the branch tip no longer matches the manifest SHA, the publish job must fail\nclosed. Moving a gate branch creates a new publish decision and should produce a\nnew build run.\n\n## Release Candidate Promote-Only\n\nFor native package sets, the PR build is the only heavy build. When a PR targets\n`alpha/<line>` or `release/<line>`, `.build.yml` uploads a release-candidate\nbundle next to the platform artifacts. The bundle contains:\n\n- `release-candidate.passport.json`;\n- the aggregate `build-summary.json`;\n- copied platform manifest evidence for the built platforms.\n\nThe passport records two separate source identities:\n\n- `builtSourceSha` / `builtSourceTreeSha`: the PR-stage source that produced the\n  artifacts, usually the PR merge ref;\n- `promotionChannelSha` / `promotionChannelTreeSha`: the post-merge channel\n  commit used for publish authority.\n\nThe reusable promote wrapper resolves the merged PR, finds exactly one matching\nPR-stage release-candidate artifact, downloads it with the build summary and\npayload artifacts from the same PR-stage run, validates the payload count,\ncompares the built tree with the promotion channel tree, locks\n`publish-gate/{alpha,release,major}` to the promotion channel commit, and then\ncalls `actions/promote-buildchain-ref` with\n`promote-only-release-candidate: \"true\"` and\n`require-publish-source-lock: \"true\"`. The wrapper passes the created\n`publish-gate/*` ref, target SHA, and `locked=true` into the promote action, so\nfloating `@v3` consumers receive publish-side source-lock drift protection by\ndefault. It also defaults `branch-protection-bypass-apps` to `github-actions`\nso the workflow automation can apply generated version-state and channel\nbookkeeping on protected `dev`/`alpha`/`release` branches after the reviewed\nchannel PR has merged. Other App slugs and all user or team bypass actors are\nrejected. The wrapper uses the run-scoped `github.token` as the generated ref\nupdate token for protected bookkeeping PATCH calls, so the exact GitHub Actions\nApp authority can sync dev immediately after alpha/release publish without a\npost-publish PR.\nIt does not call `.build.yml`, does not create a matrix, and must fail before\npublish if the RC evidence, payload set, or source-lock ref is missing or\nambiguous.\n\nThe public `release-candidate-promote.yml` is a generated channel router. It\nderives the publication lane from `target-ref`, then selects the matching\nadvanced workflow shell, runtime, and consumer lock before the advanced\npromotion starts:\n\n- alpha targets use `.release-candidate-promote.yml@vN-alpha`, runtime\n  `vN-alpha`, and `buildchain-alpha-contract-lock-path`;\n- release and major targets use `.release-candidate-promote.yml@vN`, runtime\n  `vN`, and `buildchain-stable-contract-lock-path`.\n\nThe generated router also owns the stable-shell layout transition through\n`.buildchain/promotion-shell-routing.json`. The v3 stable and alpha lanes call\nthe hidden advanced workflow at the exact immutable SHA behind their selected\nv3 channel state and forward the complete internal promotion identity surface.\nThe logical shell identity remains `vN`, and the router retains it in the public\naudit outputs. The internal advanced-shell call receives the exact call ref\nselected by the routing configuration, so its called-workflow ref check and\ncheckout SHA both bind to the same immutable identity. Updating a routing pin\nafter a release does not require any consumer declaration change.\n\nThe router resolves immutable SHAs and the selected lock digest before candidate\ndownload. The advanced shell verifies the same router, shell, runtime, lock,\nchannel, and target binding again. Train and exact-SHA runtime overrides remain\nrestricted to trusted `workflow_dispatch` actors with write, maintain, or admin\npermission. Promotion controller evidence, the promotion copy of the release\ncandidate passport, and the final release passport record these identities.\n\n```yaml\njobs:\n  promote:\n    uses: kungfu-systems/buildchain/.github/workflows/release-candidate-promote.yml@v3\n    secrets:\n      buildchain-issue-app-id: ${{ secrets.BUILDCHAIN_ISSUE_APP_ID }}\n      buildchain-issue-app-private-key: ${{ secrets.BUILDCHAIN_ISSUE_APP_PRIVATE_KEY }}\n    with:\n      buildchain-channel: auto\n      buildchain-alpha-contract-lock-path: .buildchain/alpha-contract-lock.json\n      buildchain-stable-contract-lock-path: .buildchain/contract-lock.json\n      channel: alpha\n      target-ref: alpha/v22/v22.22\n      artifact-name: libnode\n      # Defaults to build.yml / Build. Override only when the PR-stage build\n      # workflow uses a different file or display name.\n      release-candidate-workflow-file: build.yml\n      release-candidate-workflow-name: Build\n      package-manager: npm\n      publish-target: npm\n      runner-preset: github-hosted\n      trusted-publishing: true\n      github-release: true\n      required-status-check: check / check\n      required-artifact-count: 3\n      publish-dist-tag: alpha\n      publish-package-set-order: platforms-first-main-last\n      publish-package-main: \"@kungfu-tech/libnode\"\n      release-passport-product-name: Libnode\n      buildchain-contract-drift-issue-mode: compatible-and-breaking\n```\n\nExisting callers may keep `buildchain-contract-lock-path`; a non-empty explicit\npath overrides channel-specific path selection only. Its lock content must\nstill prove the selected channel and major. Migration only requires adding the\ntwo channel lock inputs and may retain the remaining common promotion\ndeclaration unchanged. Consumers must not call the dot-prefixed advanced\nworkflow directly.\n\n`buildchain-issue-app-id` and `buildchain-issue-app-private-key` are optional\nbut recommended for cross-repository consumers. They should identify a GitHub\nApp installation with `issues: write` on `kungfu-systems/buildchain`; the\nwrapper mints the installation token before calling\n`actions/report-buildchain-issue`. Consumers can also pass a pre-minted\n`buildchain-issue-token`. If both are omitted, the wrapper falls back to\n`BUILDCHAIN_ISSUE_TOKEN`, `BUILDCHAIN_PROMOTION_TOKEN`, and then the consumer\nworkflow's `github.token`; the last fallback can only report issues when it has\nwrite access to the target Buildchain repository.\n\n`publish-required-artifacts-json` can still be passed explicitly for custom\npublish targets. Custom OCI requirements may omit pre-publish refs and digests;\nthe action resolves the exact version ref and validates final digests and any\nbuilt/reused provenance after `lifecycle.publish`. For the default\n`publish-artifact-kind: npm` path, consumers do\nnot download artifacts or run repository scripts to build publish evidence. The\nwrapper downloads the PR-stage payload artifacts, finds the downloaded `.tgz`\npackages, reads each tarball's `package/package.json` for the real scoped\npackage name and version, computes the npm `sha512-...` integrity from the\ntarball bytes, marks the package matching `publish-package-main` as `role:\nmain`, marks the rest as `role: platform`, and passes the generated\n`publish-required-artifacts-json` to `promote-buildchain-ref` before any publish\nside effect. Downloaded platform manifests are still passed into the release\npassport unless `release-passport-platform-manifest-paths` is set explicitly.\nThe same Buildchain contract lock check runs before release-candidate\nresolution and before publish. A compatible `v3` drift leaves an issue in the\nconsumer repository but does not trigger a second heavy build; an incompatible\ndrift fails before publish side effects.\n\nThe wrapper publishes the public release tag as a GitHub Release by default.\nAfter `promote-buildchain-ref` reports a complete release transaction, the\nwrapper creates or updates the public release, marks semver prerelease tags\nsuch as `v1.2.3-alpha.0`, `v1.2.3-rc.1`, or `v22.22.3-kf.3-alpha.7` as\n`prerelease=true` and `make_latest=false`, marks stable semver tags as latest,\nand uploads the publish evidence file plus every file in the generated release\npassport directory, including `buildchain.release.json` and `check-report.json`.\nFor anchored/manual package releases, the public release tag is derived from the\npublished package version and the internal exact transaction tag remains\navailable in the release passport.\nConsumers do not need to hand-write `gh release` logic to trigger\n`release.published` propagation. Set `github-release: false` only for\nrepositories that intentionally do not maintain GitHub Releases.\nIf the transaction still needs protected-ref finalization, the wrapper defers\nGitHub Release creation until the later run that reaches `state=complete`.\n\nCustom publish jobs can also repeat the channel-ref preflight:\n\n```yaml\n- name: Verify publish channel ref still matches\n  run: node .buildchain/runtime/scripts/verify-publish-channel-ref.mjs\n  env:\n    BUILDCHAIN_PUBLISH_SOURCE_REF: ${{ needs.build.outputs.publish-source-ref }}\n    BUILDCHAIN_PUBLISH_SOURCE_SHA: ${{ needs.build.outputs.publish-source-sha }}\n    BUILDCHAIN_SOURCE_REPOSITORY: ${{ github.repository }}\n    GITHUB_TOKEN: ${{ github.token }}\n```\n\nAnchored/manual package release jobs should also make the Buildchain promotion\naction validate that publication is entering through the same\n`publish-gate/{alpha,release,major}` source-lock contract before any package\npublish side effect:\n\n```yaml\n- name: Promote release ref and publish npm package set\n  uses: kungfu-systems/buildchain/actions/promote-buildchain-ref@v3\n  with:\n    sha: ${{ needs.build.outputs.publish-source-sha }}\n    target-ref: release/v22/v22.22\n    require-publish-source-lock: \"true\"\n    publish-source-ref: ${{ needs.build.outputs.publish-source-ref }}\n    publish-source-sha: ${{ needs.build.outputs.publish-source-sha }}\n    publish-source-locked: ${{ needs.build.outputs.publish-source-locked }}\n```\n\n`target-ref` stays the Buildchain channel promotion target, such as\n`alpha/v22/v22.22`, `release/v22/v22.22`, or `publish-gate/major`.\n`publish-source-ref` is the reviewed source-lock branch that authorized this\nspecific package publication. For alpha and release package publications, the\nsource-lock branch must point at the exact channel-line commit that promotion is\nvalidating; it is not a replacement for `target-ref`.\n\nThis keeps the version bump commit, publish authorization, and auditable publish\nentrypoint on the Buildchain source-lock protocol. The CLI form\n`buildchain publish-source validate-anchored-release --json` is still useful for\ncustom publish scripts, but the preferred GitHub Actions gate is the promotion\naction input above. A publish job that still runs directly from `alpha/*` or\n`release/*` channel branches fails this check because those refs are channel\nstate, not publish-gate decisions.\n\n## Package-Set Publish Plan\n\nProjects that publish multiple packages should treat package publication as a\npackage-set operation. Buildchain's package-set planner uses these rules:\n\n- platform packages publish first;\n- the main package publishes last;\n- the dist-tag move happens only after the full package set is present;\n- reruns accept already-published packages only when package name, version, and\n  integrity match;\n- an existing package with different integrity is a hard failure.\n\nThis keeps a consumer from observing a floating dist-tag that points to a main\npackage before all platform artifacts for the same source SHA are available.\n\n## Command Sources\n\nThe workflow runs `.buildchain/buildchain.toml` lifecycle stages by default:\n\n```toml\n[lifecycle.install]\ncommand = \"corepack yarn install --immutable\"\n\n[lifecycle.build]\ncommands = [\n  \"corepack yarn make\",\n  \"corepack yarn build\",\n]\n\n[lifecycle.verify]\ncommand = \"corepack yarn test\"\n```\n\nCallers can override any stage for one invocation:\n\n```yaml\nwith:\n  build-command: cmake --build build --config Release\n  verify-command: ctest --test-dir build --output-on-failure\n```\n\nEvery native and container matrix job is bounded by\n`lifecycle-timeout-minutes`, which defaults to 120 minutes. The same input is\nthe fallback deadline for each install, build, and verify action, so a hung\ncommand fails with the lifecycle name and matrix platform before it can occupy\na self-hosted runner indefinitely. A stage-level `timeout_minutes` in\n`buildchain.toml` remains the more specific override for that stage.\n\n```yaml\nwith:\n  lifecycle-timeout-minutes: 90\n```\n\nThe reusable build workflow samples the build lifecycle by default and carries\nthe generated summary into the final verify diagnostics. Callers can override\nthe sidecar path or disable sampling:\n\n```yaml\nwith:\n  sample-process-tree: true\n  process-summary-path: .buildchain/diagnostics/process-summary.json\n  process-sample-interval-ms: 15000\n  requested-parallelism: 20\n```\n\nWhen `sample-process-tree` is true, Buildchain wraps either `build-command` or\nthe configured `lifecycle.build` stage with `buildchain sample process-tree`.\nThe path is relative to the checked-out workspace and is read again during the\nfinal verify lifecycle. Custom workflows can still write their own sampler\nsummary and pass `process-summary-path`; Buildchain reads the file after the\nlifecycle command finishes, so it may be produced during the same invocation.\nWhen the build stage is optional, the reusable workflow treats the default\nsampler path as optional during verify; an explicitly supplied\n`process-summary-path` remains required.\n\nFor custom workflows, use the action directly:\n\n```yaml\n- uses: kungfu-systems/buildchain/actions/run-lifecycle@v3\n  with:\n    stage: build\n    required: \"true\"\n    timeout-minutes: \"90\"\n    artifact-name: libnode-linux-x64-${{ github.sha }}\n    artifact-paths: |\n      dist\n      build/stage\n```\n\n## Artifact Contract\n\nEach platform upload uses `artifact-name-template`. The default is:\n\n```text\n{artifact}-{platform}-{sha}\n```\n\nSupported placeholders are `{artifact}`, `{artifactName}`, `{platform}`,\n`{platformId}`, `{platformName}`, `{sha}`, `{shortSha}`, `{ref}`, `{runId}`,\nand `{runAttempt}`. Invalid GitHub artifact name characters are normalized to\n`-`, so `{ref}` remains deterministic even for refs such as\n`refs/heads/dev/v3/v3.0`.\n\nEach platform also writes and uploads:\n\n```text\n.buildchain/artifacts/<platform-id>/manifest.json\n.buildchain/artifacts/<platform-id>/summary.json\n```\n\nThe manifest schema is:\n\n```json\n{\n  \"schemaVersion\": 1,\n  \"contract\": \"kungfu-buildchain-artifact\",\n  \"artifactName\": \"libnode-linux-x64-<sha>\",\n  \"platform\": {\n    \"id\": \"linux-x64\",\n    \"name\": \"Linux x64\",\n    \"os\": \"Linux\",\n    \"arch\": \"X64\"\n  },\n  \"git\": {\n    \"repository\": \"kungfu-systems/libnode\",\n    \"sha\": \"<sha>\",\n    \"ref\": \"<ref>\",\n    \"runId\": \"<run id>\",\n    \"runAttempt\": \"<attempt>\"\n  },\n  \"lifecycle\": {\n    \"stage\": \"verify\",\n    \"commandSource\": \"buildchain.toml\",\n    \"executed\": true\n  },\n  \"summary\": {\n    \"contract\": \"kungfu-buildchain-artifact-summary\",\n    \"artifactName\": \"libnode-linux-x64-<sha>\",\n    \"fileCount\": 1,\n    \"totalBytes\": 1234,\n    \"digest\": \"<hex>\"\n  },\n  \"expectedArtifacts\": {\n    \"ok\": true,\n    \"source\": \"expected-artifacts-json\",\n    \"checks\": []\n  },\n  \"files\": [\n    {\n      \"path\": \"dist/example.zip\",\n      \"size\": 1234,\n      \"sha256\": \"<hex>\"\n    }\n  ]\n}\n```\n\nArtifact names do not include actor names, timestamps, or retry counters. Reruns\nproduce a new GitHub Actions run but keep the same source SHA/platform contract.\n\n`expected-artifacts-json` fails the build before upload when the artifact does\nnot match the caller's declared contract. Supported checks are:\n\n| Field           | Meaning                              |\n| --------------- | ------------------------------------ |\n| `minFiles`      | Minimum number of manifest files     |\n| `maxFiles`      | Maximum number of manifest files     |\n| `minTotalBytes` | Minimum total byte count             |\n| `requiredPaths` | Exact manifest paths that must exist |\n\n## Trusted Event Gate\n\nThe workflow has an explicit `trust-gate` job. By default, pull requests from\nforks fail before any build job can reach self-hosted runners, secrets,\npublishing credentials, or heavyweight build commands. Same-repository PRs,\nworkflow dispatches, and protected branch events can proceed.\n\nIf a repository wants fork PRs to skip rather than fail, it can set:\n\n```yaml\nwith:\n  untrusted-policy: skip\n```\n\nDo not set `require-trusted-event: false` for workflows that use self-hosted\nrunners or secrets.\n\nThe build matrix and the workflow control plane are routed independently. The\nmatrix continues to use `runner-preset` and `platforms-json`. Consumers with a\ngoverned runner may also move channel resolution, trust evaluation, contract\nresolution, controller evidence, artifact transfer, and aggregation off the\ndefault GitHub-hosted runner:\n\n```yaml\nwith:\n  control-runner-json: '[\"self-hosted\",\"agent-120\"]'\n  runner-preset: custom\n  platforms-json: '[{\"id\":\"linux-x64\",\"name\":\"Linux x64\",\"runner\":\"[\\\"self-hosted\\\",\\\"agent-120\\\"]\"}]'\n```\n\n`control-runner-json` is additive and defaults to `[\"ubuntu-24.04\"]`. Keep\n`require-trusted-event: true` whenever either runner input selects\n`self-hosted`; a self-hosted control plane must not be exposed to untrusted fork\nevents or arbitrary caller-controlled workflow code.\n\nConsumers that must verify platform-native properties of the final bytes can\nset `artifact-finalization-command` and `artifact-finalization-on-platform:\ntrue`. Buildchain then imports any signed result (or preserves the declared\nunsigned artifact), runs the command on the matching GitHub-hosted platform,\nand reseals the manifest before publishing the final deterministic artifact.\nPlatform-native finalization fails closed for self-hosted runners so signing\nauthority credentials and final bytes stay inside the trusted hosted boundary.\n\n`require-trusted-event` controls access to build runners. It does not override\nthe publish gate: pull requests remain non-publishing events.\n\n## Fixture\n\n`fixtures/libnode-shaped` is the contract fixture. It has:\n\n- `package.json` version state;\n- `.buildchain/buildchain.toml` with `install`, `build`, `verify`, and `publish`;\n- cross-platform Node scripts that create small `dist/` outputs;\n- `Build Surface Fixture` workflow coverage.\n\nThe fixture proves the reusable surface without running the real libnode native\nbuild."
    },
    {
      "id": "manual:runtime-train-validation",
      "title": "Runtime Train Validation",
      "route": "/docs/runtime-train-validation",
      "category": "manual",
      "capabilityGroup": "governance-versioning",
      "audience": [
        "maintainer",
        "consumer"
      ],
      "maturity": "stable",
      "sourcePath": "docs/runtime-train-validation.md",
      "digest": "sha256:f0a1cdb7fe5f72fc2ed921f1aeadbd16184dda16be3727e4193fa2af250325db",
      "headings": [
        {
          "level": 1,
          "title": "Runtime Train Validation",
          "anchor": "runtime-train-validation"
        },
        {
          "level": 2,
          "title": "Train refs",
          "anchor": "train-refs"
        },
        {
          "level": 2,
          "title": "Buildchain contributor requirement",
          "anchor": "buildchain-contributor-requirement"
        },
        {
          "level": 2,
          "title": "Formal artifact-signing authority ref",
          "anchor": "formal-artifact-signing-authority-ref"
        },
        {
          "level": 2,
          "title": "Consumer workflow requirement",
          "anchor": "consumer-workflow-requirement"
        },
        {
          "level": 2,
          "title": "Validation request",
          "anchor": "validation-request"
        },
        {
          "level": 2,
          "title": "Trust and limitation",
          "anchor": "trust-and-limitation"
        }
      ],
      "markdown": "---\nstatus: active\nperiod: ongoing\ntheme: buildchain-runtime-train-validation\ndoc_type: technical-reference\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-07-31\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-31\n  invisible_context: not asserted\n---\n\n# Runtime Train Validation\n\nBuildchain consumers should keep stable workflow refs such as `@v3` in\ncommitted workflow YAML. Runtime trains provide a temporary validation pointer\nfor Buildchain changes that are ready for downstream testing but not yet\npromoted through the normal `dev -> alpha -> release` chain.\n\nOfficial floating channels are not runtime overrides. A consumer that\ndeliberately follows `@v3-alpha` gets the matching runtime on pull requests and\npushes because the reusable workflow reads the called workflow identity from\n`job.workflow_ref`. Passing `buildchain-ref: v3-alpha` explicitly is also\naccepted when the caller wants the channel binding visible in its input set.\nThe caller's `github.workflow_ref` is not used for this inference because it\nidentifies the caller workflow during reusable calls.\n\n## Train refs\n\nA train ref is a branch in the Buildchain repository:\n\n```text\ntrain/v3/v3.0/<capability>\n```\n\nIt is a validation pointer, not a release channel:\n\n- it does not move `v3`, `vX.Y`, `vX.Y-alpha`, exact tags, npm dist-tags, or\n  production refs;\n- it must not be pinned as a long-term production dependency;\n- it should point at the Buildchain commit that downstream maintainers are\n  expected to validate;\n- it is not a pending merge target or a delivery state;\n- the final durable path is still a pull request into the active `dev/*`\n  channel, followed by the requested alpha or release promotion.\n- it may remain for a retention window after release so initiating repositories\n  have a stable fast-use and rollback channel while stable refs, caches, or\n  rollout windows settle.\n\n## Buildchain contributor requirement\n\nWhen a Buildchain change needs downstream validation before stable refs move,\npublish a train ref before asking consumers to test it:\n\n```sh\ngit push origin HEAD:refs/heads/train/v3/v3.0/<capability>\n```\n\nUse a capability slug that names the behavior being validated, for example:\n\n```text\ntrain/v3/v3.0/runtime-loader\ntrain/v3/v3.0/toolkit-diagnostics\ntrain/v3/v3.0/site-source-of-truth\n```\n\nThe pull request or validation request should include the train ref, the exact\ncommit SHA it points to, and the downstream evidence expected from consumers.\nIf the train is refreshed, state the new SHA in the validation thread.\n\nAfter downstream validation succeeds, close out through the normal release\npath. Merge the Buildchain pull request into the active `dev/*` mainline, run\nthe requested alpha or release promotion, and record the final mainline commit\nplus release ref or tag in the delivery thread. Do not leave the train as the\nitem that still needs to be merged; it is only a temporary fast-use,\ndiagnostic, and rollback channel for initiating repositories. Retained trains\nare cleaned up by a separate periodic Buildchain cleanup task.\n\n## Formal artifact-signing authority ref\n\nArtifact signing uses a durable, channel-neutral authority ref after its\nruntime has passed downstream validation:\n\n```text\nauthority/v3/v3.0/artifact-signing\n```\n\nUnlike a train, this ref is a protected execution boundary. Alpha and stable\nrelease intent use the same authority ref and the same\n`buildchain-artifact-signing` environment; channel promotion never selects a\ndifferent certificate environment. Updates to the authority ref require a\nreviewed pull request, the normal `check` and `verify` status contexts, and a\nfast-forward-safe protected branch policy. Deletion and non-fast-forward\nupdates are forbidden.\n\nThe temporary `train/v3/v3.0/artifact-signing-authority` ref remains a bounded\nrollback and diagnostic pointer during migration. It is not the production\nidentity and must not regain credential ownership.\n\n## Consumer workflow requirement\n\nConsumers keep their reusable workflow pinned to the stable shell:\n\n```yaml\njobs:\n  build:\n    uses: kungfu-systems/buildchain/.github/workflows/.build.yml@v3\n```\n\nTo validate a train without committing temporary workflow refs, expose a\ntrusted manual pass-through once:\n\n```yaml\non:\n  workflow_dispatch:\n    inputs:\n      buildchain-ref:\n        description: \"Temporary Buildchain runtime ref for trusted manual validation\"\n        required: false\n        default: \"\"\n\njobs:\n  build:\n    uses: kungfu-systems/buildchain/.github/workflows/.build.yml@v3\n    with:\n      buildchain-ref: ${{ inputs.buildchain-ref || '' }}\n```\n\nBuildchain initializes new package workflows with this pass-through. Existing\nconsumers that do not have it should add it once before validating a train.\n\n## Validation request\n\nUse this short request when a train is ready:\n\n```text\nBuildchain train ready: buildchain-ref=train/v3/v3.0/<capability>.\nKeep uses: ...@v3; run workflow_dispatch with that buildchain-ref and report the runtime evidence summary.\n```\n\nThe consumer should run a trusted `workflow_dispatch`, paste the train ref into\n`buildchain-ref`, and report the workflow summary or aggregate Buildchain\nsummary. The evidence should include:\n\n- workflow shell ref;\n- requested runtime ref;\n- resolved runtime ref;\n- resolved runtime SHA;\n- stability class;\n- trust decision;\n- rollback ref.\n\n## Trust and limitation\n\nOfficial floating channel refs such as `v3` and `v3-alpha` may be selected on\npull requests and pushes. Train refs and arbitrary exact-SHA overrides still\nfail closed unless the event is `workflow_dispatch` and the actor has write,\nmaintain, or admin permission on the caller repository. Pull requests,\nincluding fork-originated pull requests, cannot use train or exact-SHA\noverrides.\n\nThat permission does not create a third channel. A train, authority ref, or\nexact SHA must be bound to an alpha or stable shell lane, and the consumer lock\nmust prove that same lane and major. Trusted overrides can replace the runtime\ncoordinate for validation; they cannot combine a stable shell or lock with an\nalpha runtime, or the reverse.\n\nRuntime train validation covers Buildchain runtime scripts, CLI code, local\nactions, configuration parsing, and lifecycle behavior. It cannot validate\nchanges that require the outer reusable workflow YAML itself to change, such as\nnew jobs, permissions, workflow outputs, or matrix topology. Those changes need\na canary workflow path or a temporary explicit workflow ref."
    },
    {
      "id": "manual:shifu-gate-profiles",
      "title": "Shifu Gate profile orchestration",
      "route": "/docs/shifu-gate-profiles",
      "category": "manual",
      "capabilityGroup": "getting-started",
      "audience": [
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "docs/shifu-gate-profiles.md",
      "digest": "sha256:eaee9c4fe10538f2de5c0c55b36ce948fc833f26e18c62493fc49e89789fb0fc",
      "headings": [
        {
          "level": 1,
          "title": "Shifu Gate profile orchestration",
          "anchor": "shifu-gate-profile-orchestration"
        },
        {
          "level": 2,
          "title": "Ownership boundary",
          "anchor": "ownership-boundary"
        },
        {
          "level": 2,
          "title": "Runner matrix",
          "anchor": "runner-matrix"
        },
        {
          "level": 2,
          "title": "Execution and receipts",
          "anchor": "execution-and-receipts"
        },
        {
          "level": 2,
          "title": "Consumer workflow",
          "anchor": "consumer-workflow"
        },
        {
          "level": 2,
          "title": "Failure diagnosis and rollback",
          "anchor": "failure-diagnosis-and-rollback"
        },
        {
          "level": 2,
          "title": "Validation boundary",
          "anchor": "validation-boundary"
        }
      ],
      "markdown": "---\nstatus: draft\nperiod: ongoing\ntheme: buildchain-shifu-gate-orchestration\ndoc_type: technical-manual\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: B\nreview_state: self-reviewed\nlast_reviewed: 2026-07-29\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-13\n  invisible_context_boundary: No private runner configuration, credentials, or unpublished Shifu implementation state was used.\n---\n\n# Shifu Gate profile orchestration\n\nBuildchain can schedule and aggregate a project-owned Shifu Gate profile without\nowning that project's gate ids, commands, dependencies, or dev/alpha/release\npolicy. The reusable workflow is\n`.github/workflows/.gate-profile.yml`.\n\n## Ownership boundary\n\n| Concern                                                                             | Owner                                 | Enforced surface                                                             |\n| ----------------------------------------------------------------------------------- | ------------------------------------- | ---------------------------------------------------------------------------- |\n| Gate schema, profile planning, execution, receipt qualification                     | Shifu                                 | `shifu gate plan`, `shifu gate run --profile`, `shifu gate receipt validate` |\n| Concrete gate catalog and profile decisions                                         | Consumer project                      | project Gate registry and detailed Gate docs                                 |\n| Runner labels and declared capabilities                                             | Consumer workflow / Buildchain preset | `runner-preset` or `platforms-json`                                          |\n| Deterministic runner matrix, immutable checkout, receipt transport, aggregate check | Buildchain                            | `.gate-profile.yml` and `shifu-gate-profile.mjs`                             |\n| Whether a profile aggregate is required for dev, alpha, or release                  | Consumer project                      | protected-branch required-check policy and caller workflow                   |\n\nBuildchain treats the Shifu plan and receipt as versioned input contracts. It\ndoes not reimplement policy selection, execute raw shell strings, convert an\nexplicit diagnostic gate run into qualification, or mint missing evidence.\n\n## Runner matrix\n\nThe plan job asks the consumer's Shifu entrypoint for one plan per configured\nplatform. A platform is dispatchable only when:\n\n- the Shifu plan is qualifying;\n- every required selection is supported on that platform;\n- the runner declares every capability requested by the selected gates; and\n- all platform plans carry the same project id and registry digest.\n\nConfigured platforms are required by default. A required platform that cannot\nhost the profile fails before runner dispatch. A platform with\n`\"required\": false` may be omitted, but the omission and reasons remain in the\nmatrix and aggregate. Matrix entries retain the Shifu plan digest, ordered gate\ngroups, required/advisory modes, action ids, definition digests, skips, and\nunsupported selections.\n\nEach matrix job timeout reserves the sum of the selected Gate action budgets\nplus 30 minutes for Buildchain-owned checkout, toolchain setup, plan download,\nreceipt validation, and artifact upload. The total remains capped at GitHub's\nsix-hour job limit. This control-plane allowance does not enlarge any Shifu\nGate's own declared action budget or change its definition digest.\n\n`github-hosted` declares only the inherent `node` capability. Projects that\nneed a native compiler, product artifacts, devices, or other facilities must\nuse a suitable preset or declare a custom matrix. Capabilities are scheduling\nclaims, not installation instructions.\n\n```json\n[\n  {\n    \"id\": \"linux-native\",\n    \"name\": \"Linux native\",\n    \"platform\": \"linux\",\n    \"runner\": \"[\\\"self-hosted\\\",\\\"Linux\\\",\\\"X64\\\",\\\"product-build\\\"]\",\n    \"capabilities\": [\"node\", \"native-toolchain\", \"product-artifacts\"]\n  }\n]\n```\n\n## Execution and receipts\n\nEvery matrix job checks out the exact source SHA planned by Buildchain, invokes\n`shifu gate run --profile`, writes the receipt outside the source checkout, and\nthen invokes `shifu gate receipt validate`. Buildchain uploads the original\nreceipt and validation result even when the run fails.\n\nBefore invoking the project-owned command, the workflow adds the runner\naccount's `~/.local/bin` directory to `PATH` on Windows, Linux, and macOS. This\nkeeps user-scoped tools such as `uv` available to strict Shifu cache profiles\nwithout assuming an administrator-managed system installation. The consumer or\nrunner owner remains responsible for provisioning the declared tools.\n\nThe fixed `Gate profile / aggregate` job fails closed for missing receipts,\ninvalid or stale Shifu validation, dirty or mismatched source SHA, registry or\nplan drift, missing required results, required failures/skips, or gate action\nand definition digest drift. Advisory failures remain visible but do not turn a\nShifu-qualifying receipt into a required failure. Buildchain's aggregate is\n`buildchain.shifu-gate-aggregate/v1`; its digest covers the matrix, receipts,\nper-gate evidence pointers, omissions, and issues.\n\n## Consumer workflow\n\n```yaml\njobs:\n  gates:\n    uses: kungfu-systems/buildchain/.github/workflows/.gate-profile.yml@v3\n    with:\n      gate-profile: alpha-pr\n      runner-preset: kungfu-v4-self-hosted\n      include-advisory: true\n\n  build:\n    needs: gates\n    uses: kungfu-systems/buildchain/.github/workflows/build.yml@v3\n    with:\n      release-candidate: true\n      gate-profile-aggregate-json: ${{ needs.gates.outputs.gate-aggregate-json }}\n```\n\nThe command input is an argv map, not a shell string. The default supports the\nordinary Shifu launcher names on all three platforms. A project with a\ndifferent launcher can override it without teaching Buildchain project tasks:\n\n```yaml\ngate-command-json: >-\n  {\"linux\":[\"./tools/shifu\"],\"macos\":[\"./tools/shifu\"],\"windows\":[\"./tools/shifu.cmd\"]}\n```\n\n`gate-command-json` is the execution command. If execution needs a cache,\ncontainer, or other project-owned wrapper that should not make the read-only\nplan depend on that service, pass a separate lightweight argv map through\n`gate-plan-command-json`. It defaults to the execution command for backward\ncompatibility; Buildchain still treats both inputs as argv and never evaluates\na shell string.\n\nProjects may also pass non-sensitive scalar environment through\n`gate-environment-json`; Buildchain validates the JSON shape and forwards it\nwithout interpreting names or values. A custom `platforms-json` entry may add\nan `environment` object when a value is platform-specific; those scalars\noverride the shared environment only for that matrix job. For example, a\nGitHub-hosted Linux lane can select an installed compiler without leaking the\nsame setting into macOS or Windows:\n\n```yaml\nplatforms-json: >-\n  [{\"id\":\"linux-x64\",\"name\":\"Linux x64\",\"platform\":\"linux\",\"runner\":\"[\\\"ubuntu-24.04\\\"]\",\"capabilities\":[\"node\",\"native-toolchain\"],\"environment\":{\"CC\":\"gcc-14\",\"CXX\":\"g++-14\"}}]\n```\n\nCache profile references use the same\nopaque `shifu-cache-profile-ref` and `shifu-cache-profile-digest` inputs as the\nreusable build. Do not place tokens, credentials, or other secrets in workflow\ninputs or Gate receipts.\n\nWhen a qualifying aggregate is passed to the build workflow, the\nrelease-candidate passport binds its profile, source SHA, registry digest,\nmatrix digest, aggregate digest, receipt count, and result count. A failed,\nnon-qualifying, or source-mismatched aggregate cannot produce a valid passport.\nPromote-only release validation preserves that same Gate evidence summary in\nthe final Release Passport release identity, so promotion cannot silently drop\nthe qualified profile provenance.\n\n## Failure diagnosis and rollback\n\nStart with the aggregate artifact, then the platform receipt named in its\nissues. Reproduce the exact project decision with Shifu, for example:\n\n```bash\n./shifu gate explain <gate-id> --profile <profile>\n./shifu gate plan <profile> --platform <platform> --json\n./shifu gate receipt validate <receipt.json> --json\n```\n\nThe existing reusable build workflow remains usable without Gate inputs. To\nroll back Gate orchestration, remove the caller's `gates` job and\n`gate-profile-aggregate-json` handoff; this does not alter the consumer's Shifu\nregistry or its direct diagnostic commands.\n\n## Validation boundary\n\nUnit fixtures prove deterministic matrix generation and required/advisory,\ncapability, unsupported, missing, stale, failure, and definition-drift\npropagation. Because a train ref changes runtime scripts but not the outer\nreusable workflow topology, an unreleased `.gate-profile.yml` must also be\nvalidated through a trusted `workflow_dispatch` canary that references the\ntemporary workflow ref or exact SHA. See\n[`runtime-train-validation.md`](runtime-train-validation.md)."
    },
    {
      "id": "manual:site-bundle-contract",
      "title": "Site Bundle Contract",
      "route": "/docs/site-bundle-contract",
      "category": "manual",
      "capabilityGroup": "site-and-propagation",
      "audience": [
        "site",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "docs/site-bundle-contract.md",
      "digest": "sha256:36a4e60e91f500ea1dcdbef97cd0250a2c26562b98d8d3622e8e0f9df2aad23b",
      "headings": [
        {
          "level": 1,
          "title": "Site Bundle Contract",
          "anchor": "site-bundle-contract"
        },
        {
          "level": 2,
          "title": "Files",
          "anchor": "files"
        },
        {
          "level": 2,
          "title": "Timestamp and Reproducibility Policy",
          "anchor": "timestamp-and-reproducibility-policy"
        },
        {
          "level": 2,
          "title": "npm Consumption",
          "anchor": "npm-consumption"
        },
        {
          "level": 2,
          "title": "Generation",
          "anchor": "generation"
        },
        {
          "level": 2,
          "title": "Scope",
          "anchor": "scope"
        },
        {
          "level": 2,
          "title": "Rendering Boundary",
          "anchor": "rendering-boundary"
        }
      ],
      "markdown": "# Site Bundle Contract\n\n`@kungfu-tech/buildchain` publishes `dist/site/` as the package-owned fact\nsource for `buildchain.libkungfu.dev` and other documentation surfaces.\n\nThe website may design navigation, visual hierarchy, examples, and explanatory\ncopy around these facts. It should not hand-write the current Buildchain\nrelease mechanics, command registry, workflow registry, or artifact schema.\n\n## Files\n\n```text\ndist/site/\n  buildchain-site.json\n  site-manifest.json\n  publication-registry.json\n  capability-registry.json\n  cli-registry.json\n  manual-registry.json\n  node-api-registry.json\n  workflow-registry.json\n  public-surface-audit.json\n  release-model.json\n  artifact-schemas.json\n  buildchain-contract.json\n  kfd-claims.json\n  product-mechanism.json\n  release-provenance.json\n  agent-index.json\n```\n\n`buildchain-site.json` is the top-level bundle entrypoint.\nIt includes a `homepage` object generated from `README.md`, including\n`homepage.sections`, `homepage.displayPlan`, and a\n`homepage.rendererContract` that is implementation metadata rather than\nordinary homepage copy. Site repositories should consume those fields instead\nof parsing `README.md` themselves.\nWhen the README intro starts with the managed Buildchain badge block,\n`homepage.lead` contains that complete marker-delimited block and\n`homepage.mechanismSummary` starts with prose after the block. A renderer must\nnot repair or recombine split badge fragments.\nIt also includes a `pages` collection that mirrors `page-registry.json`, so a\nsite repository can build the full Buildchain public documentation surface from\nthe npm package without scanning the source checkout.\n`capability-registry.json` is the navigation spine for that page surface. It\ngroups manuals, pages, CLI commands, workflows, actions, Node API exports, and\nKFD claim facts into stable product capability groups. Site repositories should\nrender navigation from this registry first, then use `page-registry.json`,\n`manual-registry.json`, `cli-registry.json`, `node-api-registry.json`, and\n`workflow-registry.json` for the concrete entries inside each group.\n`page-registry.json` is the complete page fact source: README homepage content,\nall packaged `docs/*.md` manuals, action README files, the Node API package\noverview, and fixture guides.\n`buildchain-contract.json` is the machine-readable Buildchain runtime contract\nworld used by floating-ref contract locks. It records public workflow/action/CLI\nsurfaces, compatibility digests, and audit digests for the files that implement\nthose surfaces.\n`manual-registry.json` enumerates the packaged Markdown manuals with source\ndigests so an agent can find complete operating documentation from the npm\nartifact. `node-api-registry.json` enumerates public Node import surfaces from\n`package.json#exports` and closes each JavaScript subpath over its exact exported\nsymbols. Each symbol includes its source-derived signature and parameters,\nconservative return/error contract, detected side effects, maturity, example\nimport, and source location, so agents do not have to infer supported APIs from\ninternal paths. `cli-registry.json` similarly retains every governed command\npath, syntax, option, alias, and side-effect-free help command projected from\nthe runtime registry and usage authority.\n`kfd-claims.json` is the Buildchain-owned KFD claim registry. It is generated\nfrom `packages/core/buildchain-kfd-claims.js` and enumerates the public release\nclaims plus the KFD-3 collaboration surfaces that Buildchain self-verifies\nduring release promotion.\n`public-surface-audit.json` is the reverse enumeration report for those\nsurfaces. It enumerates real CLI commands from `bin/buildchain.mjs`, workflow\ninputs, action inputs, site pages, and documentation command references, then\ncompares those sets with `cli-registry.json`, `workflow-registry.json`, and\n`page-registry.json`. Buildchain's self-check fails closed when an enumerable\npublic surface is missing from the generated registries.\n`publication-registry.json` is the package-owned publication archive registry\nfor downstream papers surfaces. Site repositories can render latest reader\nroutes, immutable version artifact routes, source bundles, and publication\npassport links from this file instead of keeping their own fixture registry.\n\n## Timestamp and Reproducibility Policy\n\nEvery Buildchain-owned surface manifest uses the same timestamp policy fields:\n\n- `generatedAt`: when the manifest JSON was generated.\n- `publishedAt`: when the surface was published, when known.\n- `reproducible`: whether the manifest declares its reproducibility inputs.\n- `timestampPolicy`: `ci-injected` for release/workflow-generated public\n  artifacts, or `source-date-epoch` for local deterministic source checks.\n- `deterministicInputs`: the source files, revisions, package metadata, and\n  declared Buildchain contracts that determine the manifest bytes.\n- `sourceDateEpoch` / `sourceRevision`: the deterministic time input or source\n  revision used to reproduce the manifest.\n- `timestampPolicyDetails.timestampFieldsParticipateInArtifactDigest`: whether\n  timestamp fields are included in the artifact digest being audited.\n\nThe policy is defined by `@kungfu-tech/buildchain/surface-manifest` and applies\nto the root site bundle, `site-manifest.json`, and web-surface deployment\nmanifests for named surfaces such as KFD, Buildchain, and Core. Site\nrepositories should render these fields; they should not invent their own\nmanifest time semantics.\n\nSource checkouts may use `SOURCE_DATE_EPOCH` for deterministic local checks.\nPublished CI/release artifacts should inject real timestamps with\n`BUILDCHAIN_SITE_GENERATED_AT` / `BUILDCHAIN_SITE_PUBLISHED_AT` or the matching\n`BUILDCHAIN_SURFACE_*` variables, so public manifests do not expose epoch time\nas if it were a real metadata time.\n\nVersion-state branches may already contain a generated manifest for the current\npackage version with `timestampPolicy: ci-injected`. In that case\n`generate-site-bundle.mjs --check` preserves the existing timestamp policy as\nthe deterministic input instead of rewriting public release metadata back to\nepoch time.\n\n## npm Consumption\n\n```bash\nnpm install @kungfu-tech/buildchain\n```\n\nThen read files from:\n\n```text\nnode_modules/@kungfu-tech/buildchain/dist/site/\n```\n\nPackage exports are also provided for direct JSON-aware consumers:\n\n```js\nimport siteManifest from \"@kungfu-tech/buildchain/site/site-manifest.json\" with { type: \"json\" };\n```\n\n## Generation\n\n```bash\npnpm run generate:reference\npnpm run generate:site\npnpm run check:site\n```\n\n`check:site` fails when generated files are stale. `pnpm run check` includes\nthis gate, so release candidates cannot publish an out-of-date site bundle.\n\n## Scope\n\nThe P0 bundle includes:\n\n- README-derived homepage fields and display plan;\n- capability-grouped navigation facts for docs, CLI, Node API, workflows,\n  actions, and KFD claims;\n- complete markdown page registry for public Buildchain docs, action manuals,\n  Node API overview, and fixtures;\n- site manifest;\n- publication archive registry for downstream papers surfaces;\n- CLI command registry plus full-path generated human reference;\n- manual registry for packaged agent-facing documentation;\n- Node API registry plus per-symbol generated human reference for public package exports;\n- workflow/action registry;\n- release model facts;\n- artifact and evidence schema index;\n- Buildchain runtime contract world for `@v3` floating-ref compatibility checks,\n  KFD-1/KFD-2/KFD-3 release gates, GitHub Release evidence publication, and\n  site-consumption contracts;\n- Buildchain KFD claim registry for release-passport self verification and\n  agent-first public claim discovery;\n- product mechanism manifest;\n- release provenance;\n- agent read order.\n\nFuture minor lines can add examples, recipes, fixture indexes, and richer\nschema metadata without breaking existing consumers.\n\n`release-propagation.md` describes the package-to-package or package-to-site\nrelease chain model. The site bundle exposes that document and the\n`release-propagation` CLI entry so downstream sites can render the current\nBuildchain-owned propagation contract instead of hand-writing it.\n`publication-registry.json` is the static site-consumption entrypoint for\npublication archive pages. It uses the\n`kungfu-buildchain-publication-release-registry` contract and declares the\nmutable latest/canonical routes separately from append-only immutable version\nprefixes.\n\n## Rendering Boundary\n\nBuildchain owns the homepage wording, section ordering intent, complete\nmarkdown page registry, release model facts, workflow/action registry, CLI\nregistry, manual registry, Node API registry, KFD claim registry, and\nrelease-passport evidence vocabulary. The site owns HTML, CSS, responsive\nlayout, navigation, visual assets, decorative media, markdown-to-HTML rendering,\nand progressive disclosure within the Buildchain-provided\n`homepage.displayPlan` and page metadata.\n\nThe page registry is also part of Buildchain's KFD-3 collaboration-interface\nsurface. Releases declare it as a site-consumption contract, and Buildchain's\nKFD-3 witness generation includes the underlying markdown sources as public\ndocumentation surfaces. If a page is public enough for the site to render, it\nmust be declared and hash-bound in the package-owned site bundle."
    },
    {
      "id": "manual:stable-candidate-patrol",
      "title": "Stable Candidate Patrol",
      "route": "/docs/stable-candidate-patrol",
      "category": "manual",
      "capabilityGroup": "governance-versioning",
      "audience": [
        "release-operator",
        "consumer"
      ],
      "maturity": "preview",
      "sourcePath": "docs/stable-candidate-patrol.md",
      "digest": "sha256:fdbea5b242fb2cc91497f45d960c446c3984e92bfd0d5201e6d1d4445dd1b31d",
      "headings": [
        {
          "level": 1,
          "title": "Stable Candidate Patrol",
          "anchor": "stable-candidate-patrol"
        },
        {
          "level": 2,
          "title": "Candidate lifecycle",
          "anchor": "candidate-lifecycle"
        },
        {
          "level": 2,
          "title": "Repository policy",
          "anchor": "repository-policy"
        },
        {
          "level": 2,
          "title": "Exact-source stable promotion",
          "anchor": "exact-source-stable-promotion"
        },
        {
          "level": 2,
          "title": "Hold, revoke, and immediate release",
          "anchor": "hold-revoke-and-immediate-release"
        },
        {
          "level": 2,
          "title": "Durable recovery",
          "anchor": "durable-recovery"
        }
      ],
      "markdown": "---\nstatus: preview\nperiod: ongoing\ntheme: stable-candidate-patrol\ndoc_type: architecture-and-usage\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: self-reviewed\nlast_reviewed: 2026-08-03\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-11\n  visible_context: Buildchain candidate passport, stable gate, Patrol, publish transaction, exact source-lock PR contracts, tests, and user consensus.\n  invisible_context_boundary: No credentials, private logs, or unpublished consumer content were used.\n---\n\n# Stable Candidate Patrol\n\nBuildchain can treat every exact alpha as an independent stable candidate. A\nnew alpha creates a new candidate; it does not silently revoke an older alpha\nthat already completed its checks and soak interval.\n\n## Candidate lifecycle\n\nThe durable ledger contract is `kungfu-buildchain-stable-candidate-ledger`:\n\n```text\nregistered -> soaking -> qualified -> promoted\n                       \\-> revoked\n```\n\nEach entry binds an exact alpha version to one immutable commit SHA. Registering\nthe same version at another SHA fails closed. Qualification records the required\nchecks, their completion times, the derived soak start, and elapsed time.\n\nScheduled selection chooses the newest `qualified` candidate that is neither\n`revoked` nor already `promoted`. A newer alpha that is still `soaking` does not\nhide an older qualified candidate. Once a stable version is promoted, remaining\nalphas for that exact stable version are closed because that immutable stable\nversion has been consumed; their later product changes continue through the\nnext patch alpha prepared by the normal release transaction.\n\nFor Buildchain's own release line, successful Alpha Self-Dogfood starts an\nidempotent qualification producer for the exact alpha SHA. It dispatches the\nexisting `Build Surface Fixture` at the immutable exact tag, runs the existing\n`site-libkungfu-dev` no-apply canary with the exact SHA, and writes the declared\ncommit-status attestation only after that authoritative canary succeeds. The\nproducer creates evidence only: Patrol still owns qualification and selection,\nand the normal source-lock PR, stable gate, transaction, and branch protections\nremain mandatory.\n\nCross-repository dispatch and repository-local attestation use separate tokens.\nThe promotion token can start the no-apply consumer workflow, while the\nrepository-scoped Actions token writes the status as `github-actions[bot]` only\nafter the producer has observed the successful authoritative workflow run. The\nstable gate still verifies the workflow identity, exact runtime SHA, target URL,\nand allowed attestor before accepting that status.\n\nWhen a candidate changes the outer reusable-workflow YAML itself, the stable\nshell cannot exercise that change through a runtime override. A maintainer may\nmanually qualify it with `canary-ref` set to a dispatchable consumer branch or\ntag and `canary-sha` set to the exact 40-character commit that ref must resolve\nto. That consumer workflow pins the candidate's exact Buildchain SHA. The\nqualification producer verifies the ref binding before dispatch, accepts only a\nrun whose source SHA matches, and writes the normal candidate-bound status only\nafter success. The automatic path continues to use the consumer default branch.\n\n## Repository policy\n\nDeclare the default once in `.buildchain/buildchain.toml`:\n\n```toml\n[release.stable]\nstrategy = \"latest-qualified-alpha\"\ntimezone = \"Asia/Shanghai\"\npublish_at = \"03:00\"\nminimum_soak_seconds = 3600\nrequired_checks = [\n  \"alpha-release\",\n  \"workflow:Build\",\n  \"status:buildchain-canary/consumer\",\n]\nauto_promote = true\nauto_merge = true\n```\n\nCheck identifiers use these forms:\n\n- `alpha-release`: the exact GitHub prerelease publication fact;\n- `workflow:<name>`: a successful Actions workflow run on the exact candidate SHA;\n- `status:<context>`: a successful commit status on the exact candidate SHA;\n- an unprefixed value: an exact status context or check-run name.\n\nCandidate discovery uses immutable exact alpha Git tags. When a repository also\npublishes GitHub prereleases, `alpha-release` binds qualification to that public\nrelease fact. Repositories that intentionally disable GitHub Releases omit\n`alpha-release` and declare their own exact-SHA workflow/status evidence; tag\ncommit time remains the earliest possible soak start.\n\n`publish_at` and `timezone` are the auditable policy declaration. GitHub only\nstarts scheduled workflows from caller-owned cron, so the thin caller keeps the\nmatching UTC trigger:\n\n```yaml\nname: Stable Candidate Patrol\n\non:\n  schedule:\n    - cron: \"0 19 * * *\" # 03:00 Asia/Shanghai\n  workflow_dispatch:\n    inputs:\n      release-now:\n        description: Exact alpha selected by explicit human authority\n        required: false\n        default: \"\"\n\npermissions:\n  contents: write\n  pull-requests: write\n  checks: read\n  statuses: read\n\njobs:\n  stable:\n    uses: kungfu-systems/buildchain/.github/workflows/stable-candidate-patrol.yml@v4\n    with:\n      release-now: ${{ inputs.release-now }}\n      dry-run: false\n    secrets:\n      promotion-token: ${{ secrets.BUILDCHAIN_PROMOTION_TOKEN }}\n      approval-token: ${{ secrets.BUILDCHAIN_APPROVAL_TOKEN }}\n```\n\nThe promotion token must be repository-owned and capable of creating the\nmachine ledger branch, exact source-lock branch, and pull request. Repositories\nthat require an approving review can pass an independent repository-owned App,\nbot, or human service-account token as `approval-token`. The approval identity\nmust differ from the promotion token identity that opens the PR. When no\n`approval-token` is passed, `auto-approve: true` falls back to the caller\n`github.token` and therefore requires GitHub Actions approval permission. The\ngenerated PR may use auto-merge, but it never bypasses the target branch\nchecks. Callers can select `merge-method: merge`, `squash`, or `rebase`; the\ndefault is `merge` for compatibility. Unsupported values fail closed before\nGitHub is called.\n\nBefore enabling `auto-approve` and `auto-merge`, the caller repository must\nprovide one approval path and enable auto-merge:\n\n- pass an independent `approval-token`; or enable **Actions > General >\n  Workflow permissions > Allow GitHub Actions to create and approve pull\n  requests**, so the caller `github.token` can approve independently from the\n  promotion token that opened the PR;\n- **General > Pull Requests > Allow auto-merge**, so Patrol can arm the\n  protected merge while required reviews and checks are still pending.\n\nGitHub rejects approval from the same identity that opened the pull request;\nPatrol propagates that review failure instead of reporting success.\n\nPatrol treats a GraphQL refusal to enable auto-merge as a hard failure. A run\nmust not report publication authority when GitHub accepted the HTTP request but\nreturned a GraphQL error in the response body.\n\n## Exact-source stable promotion\n\nFor a selected `4.0.2-alpha.4`, Patrol creates the immutable source branch:\n\n```text\npublish-gate/release/v4/v4.0/4.0.2-alpha.4\n```\n\nand opens it against `release/v4/v4.0`. This is an existing strict Buildchain\ngovernance path. The PR freezes the qualified candidate even if `v4.0-alpha`\nor `alpha/v4/v4.0` has already moved to alpha.5. Normal Verify,\nrelease-candidate resolution, source-tree equivalence, publish transaction,\npassport, registry, tag, and floating-ref checks still run.\n\n## Hold, revoke, and immediate release\n\nPersistent repository controls can be supplied as reusable-workflow inputs or\nrepository variables:\n\n```text\nBUILDCHAIN_STABLE_HOLD=true\nBUILDCHAIN_STABLE_HOLD_REASON=release freeze\nBUILDCHAIN_STABLE_REVOKED_ALPHA_VERSIONS=2.12.0-alpha.5,2.12.0-alpha.7\nBUILDCHAIN_STABLE_REVOKE_REASON=consumer regression\n```\n\nRevocation is explicit evidence; publishing a newer alpha alone is not\nrevocation. A manual `workflow_dispatch` `release-now` chooses one exact,\nnon-revoked candidate immediately. It may bypass the scheduled soak decision,\nbut cannot change candidate SHA, reuse a consumed stable version, or bypass the\nsource-lock PR and publish transaction.\n\nFor Buildchain's own stable gate, Patrol automatically projects that explicit\nhuman decision into the exact-candidate `BUILDCHAIN_STABLE_RELEASE_NOW` and\nreason variables. A later Patrol run removes them after it observes the public\nstable release. This is an internal compatibility projection, not a manual user\nstep; the durable authority record remains the candidate ledger entry and PR.\n\n## Durable recovery\n\nThe default ledger ref is derived from the release line, for example:\n\n```text\nbuildchain/candidate-ledger/v4/v4.0\n```\n\nIt stores `.buildchain/stable-candidate-ledger.json`. Patrol runs are serialized\nper repository and release line. Repeated runs reuse the same exact source-lock\nbranch and PR, while later runs observe the public stable release and mark the\ncandidate `promoted`.\n\nWhen Patrol is enabled after a stable version already exists, it reconstructs\nthat consumed patch from GitHub Release truth and closes historical alpha\ncandidates for the same stable version. It never attempts to republish an\nalready claimed exact stable version."
    },
    {
      "id": "manual:toolkit-observability",
      "title": "Toolkit Observability",
      "route": "/docs/toolkit-observability",
      "category": "manual",
      "capabilityGroup": "observability-diagnostics",
      "audience": [
        "developer",
        "maintainer"
      ],
      "maturity": "stable",
      "sourcePath": "docs/toolkit-observability.md",
      "digest": "sha256:1a08331cdca2b48e622ecbb799a7465a59cc4a779dd73d36f559f9bc1b98578c",
      "headings": [
        {
          "level": 1,
          "title": "Toolkit Observability",
          "anchor": "toolkit-observability"
        },
        {
          "level": 2,
          "title": "Choose API or CLI",
          "anchor": "choose-api-or-cli"
        },
        {
          "level": 2,
          "title": "Library API",
          "anchor": "library-api"
        },
        {
          "level": 2,
          "title": "Candidate timelines and critical-path-safe timing",
          "anchor": "candidate-timelines-and-critical-path-safe-timing"
        },
        {
          "level": 2,
          "title": "Diagnostics API",
          "anchor": "diagnostics-api"
        },
        {
          "level": 2,
          "title": "CLI Logging",
          "anchor": "cli-logging"
        },
        {
          "level": 2,
          "title": "Release Gate",
          "anchor": "release-gate"
        }
      ],
      "markdown": "---\nstatus: draft\nperiod: ongoing\ntheme: buildchain-observability\ndoc_type: technical-reference\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-07-31\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-31\n  invisible_context: not asserted\n---\n\n# Toolkit Observability\n\nBuildchain ships a small logging toolkit for repository workflows and project\nscripts. The goal is to separate time spent in Buildchain's framework from time\nspent in the consumer's own build, test, packaging, and publish steps.\n\n## Choose API or CLI\n\n`@kungfu-tech/buildchain` is not only a CLI package. It exports ESM toolkit APIs\nthat project scripts can import directly:\n\n```js\nimport { createBuildchainLogger } from \"@kungfu-tech/buildchain/logging\";\n```\n\nUse the API inside JavaScript or TypeScript build code. Do not spawn\n`buildchain`, download the standalone binary, or shell out through `npx` from\ncode that can import the package. The CLI is for GitHub Actions steps, shell\nscripts, and non-JavaScript tools.\n\nWhen a script runs inside `buildchain lifecycle run`, the lifecycle runner sets\n`BUILDCHAIN_LOG_PATH` and `BUILDCHAIN_LOG_RUN_ID`. Imported loggers pick up those\nenvironment variables automatically, so events emitted deep inside the build are\ngrouped into the same lifecycle summary.\n\nOutside a Buildchain lifecycle or GitHub Actions run, the logger defaults to\nconsole output unless a path is provided. Pass `path` when local scripts should\nwrite a reusable JSONL log:\n\n```js\nconst logger = createBuildchainLogger({\n  path: \".buildchain/logs/native-build.jsonl\",\n  source: \"user\",\n  component: \"native-build\",\n});\n```\n\n## Library API\n\n```js\nimport {\n  createBuildchainLogger,\n  verifyBuildchainLogEvents,\n} from \"@kungfu-tech/buildchain/logging\";\n\nconst logger = createBuildchainLogger({\n  source: \"user\",\n  component: \"native-build\",\n});\n\nlogger.mark(\"configure.ready\", {\n  phase: \"configure\",\n  attributes: { preset: \"release\" },\n});\n\nawait logger.span(\"native.compile\", {\n  phase: \"build\",\n  attributes: { target: \"release\" },\n}, async () => {\n  await compile();\n});\n\nlogger.spanSync(\"native.archive\", {\n  phase: \"build\",\n  attributes: { tool: \"libtool\" },\n}, () => {\n  archiveStaticLibraries();\n});\n\nlogger.spawnSync(\"native.build\", \"make\", [\"-j20\"], {\n  stdio: \"inherit\",\n}, {\n  phase: \"build\",\n  attributes: { requestedJobs: 20 },\n});\n\nconst report = verifyBuildchainLogEvents({\n  path: logger.path,\n  minEvents: 3,\n  requirePhases: [\"configure\", \"build\"],\n  requireEvents: [\n    \"configure.ready\",\n    \"native.compile.start\",\n    \"native.compile.end\",\n  ],\n});\n\nif (!report.ok) {\n  throw new Error(\"Buildchain observability verification failed\");\n}\n```\n\nUse the API when a build script has internal stages that are invisible to the\nouter workflow. Keep secret values out of attributes; known sensitive keys are\nredacted, but callers should still avoid logging private material.\n\n## Candidate timelines and critical-path-safe timing\n\nLifecycle diagnostics retain their existing summed-duration tables for\ncompatibility. Do not interpret those tables as elapsed time when spans are\nnested or jobs run in parallel. Use the candidate timeline contract when a\nchange must be followed from pull-request admission through Merge Queue attempts\nto its final merge:\n\n```js\nimport {\n  createCandidateTimeline,\n  formatCandidateTimelineReport,\n} from \"@kungfu-tech/buildchain/candidate-timeline\";\n\nconst timeline = createCandidateTimeline({\n  candidate: {\n    repository: \"owner/repository\",\n    baseBranch: \"dev/v4/v4.0\",\n    sourceSha,\n    pullRequest: 123,\n  },\n  events,\n});\n\nconsole.log(formatCandidateTimelineReport(timeline));\n```\n\nEach event binds a stable event id to one attempt id and may also bind a Gate\nid, merge-group SHA, workflow run, platform, partition, cache outcome, execution\nboundary, and parent span. Terminal execution states (`success`, `failure`, and\n`cancelled`) require start and completion timestamps. Non-executed states use\n`skipped`, `dependency-blocked`, or `not-required` without invented timings.\nRecord the clock and timestamp precision explicitly: GitHub Actions timestamps\nare normally provider wall-clock observations with one-second precision, while\nan in-process span may also carry a monotonic duration with millisecond or\nbetter precision.\n\nThe `buildchain.candidate-timeline/v1` artifact reports an independent critical\npath for every attempt. Its critical-path duration is the attempt's observed\nwall-clock envelope; its active duration and per-phase durations are interval\nunions. This prevents nested or parallel spans from being added twice, and it\ndoes not combine a failed or dequeued attempt with a later retry. Missing\nrequired measurements make that attempt `incomplete` instead of producing fake\nprecision.\n\nEach attempt also reports measured execution lanes, lane skew, cache outcome\ncounts, the ten longest actionable spans, and one falsifiable next optimization\ntarget. Queue residence, whole-workflow envelopes, and job parents are excluded\nfrom the actionable ranking so they cannot hide the build or qualification\nstage that can actually be changed. The target is an observation, not a causal\nclaim: repeat the same source-bound cohort and disprove it by reducing that span\nbelow the next measured span without increasing attempt elapsed time or\nfailures.\n\nShell and workflow consumers can generate the same machine artifact plus a\ncompact report:\n\n```sh\nbuildchain candidate timeline \\\n  --input .buildchain/candidate-timeline-input.json \\\n  --output .buildchain/candidate-timeline.json\n```\n\nThe input and output should contain only bounded correlation facts and timing\nreceipts. Do not include tokens, environment dumps, full commands, raw process\ndumps, or private absolute paths.\n\nCommonJS scripts should import Buildchain's ESM surfaces dynamically:\n\n```js\nconst { createBuildchainLogger } = await import(\"@kungfu-tech/buildchain/logging\");\nconst { collectRunnerDiagnostics } = await import(\"@kungfu-tech/buildchain/diagnostics\");\n```\n\n## Diagnostics API\n\nThe diagnostics surface collects local, non-telemetry build facts that are\nuseful when a native build is slow or flaky:\n\n```js\nimport {\n  collectBuildchainDiagnostics,\n  collectCacheDiagnostics,\n  collectCompilerCacheDiagnostics,\n  collectRunnerDiagnostics,\n  collectToolDiagnostics,\n  detectRequestedParallelism,\n  startProcessSampler,\n  summarizeDiagnosticsArtifacts,\n  summarizeLifecycleObservability,\n  summarizeProcessSamples,\n  validateAnchoredPackageRelease,\n  writeDiagnosticsArtifact,\n} from \"@kungfu-tech/buildchain/diagnostics\";\n\nconst lifecycleObservability = summarizeLifecycleObservability({\n  logPath: \".buildchain/logs/events.jsonl\",\n});\nconst buildCommand = \"make\";\nconst buildArgs = [\"-j20\"];\nconst requestedParallelism = detectRequestedParallelism({\n  command: buildCommand,\n  args: buildArgs,\n});\nconst processSampler = startProcessSampler({\n  intervalMs: 15000,\n  label: \"native-build\",\n  command: buildCommand,\n  args: buildArgs,\n});\n// Run the long native build while the sampler is active.\nconst processSummary = summarizeProcessSamples({\n  requestedParallelism: requestedParallelism.value,\n  samples: processSampler.stop(),\n});\nconst cacheDiagnostics = collectCacheDiagnostics({ cwd: process.cwd() });\n\nwriteDiagnosticsArtifact(\".buildchain/artifacts/diagnostics.json\", {\n  contract: \"consumer-build-diagnostics\",\n  buildchain: collectBuildchainDiagnostics({ cwd: process.cwd() }),\n  runner: collectRunnerDiagnostics(),\n  tools: collectToolDiagnostics({ cwd: process.cwd() }),\n  cache: cacheDiagnostics,\n  lifecycleObservability,\n  process: processSummary,\n});\n```\n\n`collectCacheDiagnostics()` includes package-manager/workspace context, selected\ncache directory stats, and compiler-cache stats from `ccache --show-stats\n--json` plus `sccache --show-stats --stats-format json` when those tools are\npresent. If a ccache build does not support JSON stats, Buildchain falls back to\nplain `ccache --show-stats` and parses the text counters. Missing cache tools\nare recorded as unavailable instead of failing the diagnostics artifact. Call\n`collectCompilerCacheDiagnostics()` directly when a consumer script only needs\ncompiler cache data. Native diagnostics also expose `compilerCaches` and\n`nativeCacheDirs` as top-level fields in each diagnostics artifact and aggregate\nsummary, so reviewers do not have to dig through nested cache sections first.\nFor reusable builds, sccache outcomes enter structured current-run evidence only\nwhen a sibling `compiler-cache-preparation.json` proves the counters were reset\nafter install and before build; cumulative stats without that receipt remain\nexplicitly unavailable.\n\nProcess samples are intentionally summarized before they become long-lived\nartifacts. The summary records requested parallelism, the source of that value\n(`command`, `process-tree`, `env:MAKEFLAGS`,\n`env:CMAKE_BUILD_PARALLEL_LEVEL`, or `explicit`), observed active process\nconcurrency, elapsed sample time, total sampled CPU, and conservative command\ncategories such as `compiler`, `archive`, `linker`, `build-tool`, and `cache`.\nThe sampler detects common `make -j N`, `ninja -j N`, CMake/MSBuild/Xcode job\nflags, and MAKEFLAGS. This lets native projects distinguish \"we asked for\n`make -j20`\" from \"the build graph only kept two active compiler or archive\nchildren busy during the sampled window\" without storing environment dumps.\n\nNative repositories can opt into a reusable diagnostics profile in\n`buildchain.toml`:\n\n```toml\n[diagnostics.native]\nenabled = true\nsample_process_tree = true\ncompiler_cache = \"auto\"\nexpected_tools = [\"ccache\", \"sccache\", \"clang\", \"cl\", \"cmake\", \"ninja\"]\nartifact_dirs = [\"build\", \"dist\", \"build/Release\"]\ncache_dirs = [\".ccache\", \".sccache\"]\n```\n\nWhen enabled, diagnostics artifacts include the normalized profile, selected\ntool versions, compiler-cache stats, and configured artifact/cache directory\nstats. The profile is data-driven: Buildchain does not assume a specific\nproject such as libnode. The reusable build workflow also exposes\n`sample-process-tree`, which wraps the build lifecycle with the process sampler\nand carries the generated summary into the final diagnostics artifact. Custom\nworkflows can call `buildchain sample process-tree` directly when they need a\ndifferent command boundary.\n\nAnchored/manual package projects can also run one higher-level release-shape\ncheck instead of assembling lower-level config calls:\n\n```js\nconst anchoredReport = validateAnchoredPackageRelease({\n  cwd: process.cwd(),\n  requireManifest: true,\n  requirePackageSetOrder: \"platforms-first-main-last\",\n  requireTrustedPublishing: true,\n});\n\nif (!anchoredReport.ok) {\n  throw new Error(\"Anchored package release contract failed\");\n}\n```\n\nIn an actual publish job, make that check source-lock aware:\n\n```js\nconst publishReady = validateAnchoredPackageRelease({\n  cwd: process.cwd(),\n  requirePublishGateSourceLock: true,\n});\n```\n\nThe source-lock inputs are read from `BUILDCHAIN_PUBLISH_SOURCE_REF`,\n`BUILDCHAIN_PUBLISH_SOURCE_SHA`, and `BUILDCHAIN_PUBLISH_SOURCE_LOCKED`, which\nthe reusable build workflow emits after resolving `publish-source-ref`. That\nturns direct channel-branch publication from `alpha/*` or `release/*` into a\nhard failure, while `publish-gate/alpha/<line>/<version>` and\n`publish-gate/release/<line>/<version>` also validate the requested consumer\nversion against configured version files and the anchor manifest.\n\n`buildchain lifecycle run` writes this small diagnostics artifact next to the\nplatform manifest by default. The per-platform diagnostics upload includes the\ncompact `diagnostics.json`, `diagnostics-manifest.json`, lifecycle\n`events.jsonl`, and, when process sampling is enabled, copied\n`process-summary.json` and `process-samples.jsonl` sidecars. The sidecar\nmanifest records each uploaded diagnostics file with its relative path, byte\ncount, and sha256 hash. It is intended to stay small enough to download without\nfetching large binary packages, and it should not include full environment dumps\nor secret-looking values.\n\nUse `summarizeDiagnosticsArtifacts()` when a matrix build uploads one\ndiagnostics artifact per platform. The summary keeps each platform's lifecycle\nstage table, adds a lifecycle total duration, carries the top slow spans, and\naggregates warning/error counts plus the slowest platforms. Per-platform rows\nalso include compact runner facts, checked tool versions/missing tools, package\nmanager/cache directory details, compiler cache availability, and a compact\nprocess sampler view with requested parallelism, observed max active processes,\nthe ratio between them, sample count, process categories, and top sampled\ncommand basenames. That gives release reviewers a small cross-platform timing,\nrunner, tool, cache, and concurrency view without downloading full build outputs\nor process sidecars.\n\nThe reusable build workflow writes that rollup as `diagnostics-summary.json` and\nuploads it in a separate aggregate diagnostics summary artifact. Consumers can\nread the `build-diagnostics-summary-artifact` output when they need only timing,\nwarning/error, runner, cache, and process-sampler context instead of the build\nsummary or binary artifacts. Per-platform rows keep the diagnostics `links`\nobject, including the binary artifact name, manifest artifact name, diagnostics\nartifact name, platform id, diagnostics sidecar manifest path, manifest path,\nsummary path, and process sidecar paths when present. They also keep compact\nrunner/tool/cache summaries so reviewers can tell whether a slow row ran on the\nexpected runner, missed an expected tool, or lacked useful compiler-cache stats.\nWhen the downloaded platform diagnostics include a sibling\n`diagnostics-manifest.json`, `summarizeDiagnosticsArtifacts()` carries a compact\n`diagnosticsManifest` section for that platform and verifies the manifest's\n`diagnostics.json` byte count and sha256. Missing or mismatched sidecar manifests\nincrement `diagnosticsManifestWarningCount`, so reviewers can distinguish\ndiagnostics sidecar drift from lifecycle warnings or build failures.\nThe same summary carries `diagnosticsContract` per platform and aggregates\n`diagnosticsContractWarningCount` when a downloaded `diagnostics.json` does not\nmatch `BUILDCHAIN_DIAGNOSTICS_CONTRACT`.\n\nThe diagnostics SDK also exports stable contract constants such as\n`BUILDCHAIN_DIAGNOSTICS_SUMMARY_CONTRACT`,\n`BUILDCHAIN_DIAGNOSTICS_MANIFEST_CONTRACT`,\n`BUILDCHAIN_PROCESS_SAMPLE_REPORT_CONTRACT`,\n`BUILDCHAIN_PROCESS_SAMPLE_SUMMARY_CONTRACT`, and\n`BUILDCHAIN_ANCHORED_PACKAGE_RELEASE_VALIDATION_CONTRACT` from\n`@kungfu-tech/buildchain/diagnostics`; consumers should compare against those\nconstants instead of hardcoding contract strings.\n\nThe CLI exposes the same aggregation for shell and workflow steps:\n\n```bash\nbuildchain diagnostics summary \\\n  .buildchain/artifacts/linux-x64/diagnostics.json \\\n  .buildchain/artifacts/macos-arm64/diagnostics.json \\\n  --output .buildchain/artifacts/diagnostics-summary.json \\\n  --json\n```\n\nOmit `--json` when the workflow log should show a compact platform table with\nlifecycle stages, artifact scan/upload time, total time, requested jobs,\nobserved active processes, warnings, and errors.\n\nFor long native build commands, the CLI can also sample the child process tree\nwhile preserving the wrapped command's exit code:\n\n```bash\nbuildchain sample process-tree \\\n  --label native-build \\\n  --interval-ms 15000 \\\n  --output .buildchain/diagnostics/process-samples.jsonl \\\n  --summary-output .buildchain/diagnostics/process-summary.json \\\n  -- \\\n  make -j20\n```\n\nThe JSONL sample file stores timestamped process-tree snapshots with full\nredacted command lines, command basenames, CPU percentages when available,\nelapsed time, and requested parallelism context. Unix and macOS snapshots read\nthe full `ps args` field instead of truncated `comm` names. Windows snapshots\nread `Win32_Process` command lines through PowerShell so the sampler no longer\nreturns an empty process set on Windows runners. The summary file records\nobserved concurrency, total sampled CPU, command categories, and top command\nbasenames. This is intended for diagnosing low-utilization tails such as\narchive/link phases without logging full environment dumps.\n\nThe lifecycle observability summary is stage-wide, not just final-step timing:\nwhen install and build write to the same Buildchain log, the final platform\nmanifest can show both stages and the slowest spans.\n\n## CLI Logging\n\n```bash\nbuildchain mark \\\n  --event native.configure \\\n  --phase configure \\\n  --component cmake \\\n  --attribute preset=release\n\nbuildchain span \\\n  --event native.build \\\n  --phase build \\\n  --component cmake \\\n  -- cmake --build build --config Release\n\nbuildchain log summary --json\nbuildchain verify observability-log .buildchain/logs/events.jsonl --min-events 4\n```\n\nEvery event records a timestamp. `span` records duration and preserves the\nwrapped command's exit code.\n\nBuildchain also records local control-plane outcome events for workflow-friction\nincident handling and production release-intent PR handling. `log summary`\nreports the observed incident reuse rate, release-intent suppression rate, and\nsuppression reasons. A reused incident means an equivalent occurrence found the\nsame fingerprint and was commented, cooled down, or otherwise reused; a\nsuppressed release intent means Buildchain proved that the source commit already\nhad a qualifying merged release PR. These are operational facts, not release\npolicy inputs, and logging failure remains non-fatal by default.\n\nThe reusable promotion workflow uploads `.buildchain/logs/events.jsonl` when a\nfriction report is produced. The web-surface production release PR handoff\nartifact includes the same path, so a real run can falsify the P0 claim instead\nof relying only on unit tests.\n\n## Release Gate\n\nBuildchain's own binary distribution lane verifies required log events before\nuploading release assets. Consumers can apply the same pattern:\n\n```bash\nbuildchain verify observability-log .buildchain/logs/events.jsonl \\\n  --require-phase build \\\n  --require-phase package \\\n  --require-component workflow \\\n  --require-event native.build.start \\\n  --require-event native.build.end\n```\n\nThis makes missing instrumentation a release failure instead of a dashboard\nafterthought."
    },
    {
      "id": "manual:v4-canonical-contracts",
      "title": "Buildchain v4 canonical contracts",
      "route": "/docs/v4-canonical-contracts",
      "category": "manual",
      "capabilityGroup": "governance-versioning",
      "audience": [
        "developer",
        "maintainer",
        "agent"
      ],
      "maturity": "preview",
      "sourcePath": "docs/v4-canonical-contracts.md",
      "digest": "sha256:e84222cd5a7c9bbea798d9a0e9e0888a70c3d449dfec4de9a894c95fc6a32bbf",
      "headings": [
        {
          "level": 1,
          "title": "Buildchain v4 canonical contracts",
          "anchor": "buildchain-v4-canonical-contracts"
        },
        {
          "level": 2,
          "title": "Canonical JSON v1",
          "anchor": "canonical-json-v1"
        },
        {
          "level": 2,
          "title": "Explicit clocks and closed envelopes",
          "anchor": "explicit-clocks-and-closed-envelopes"
        },
        {
          "level": 2,
          "title": "Implementations and proof",
          "anchor": "implementations-and-proof"
        },
        {
          "level": 2,
          "title": "Shared Delivery Warrant fixture runner",
          "anchor": "shared-delivery-warrant-fixture-runner"
        },
        {
          "level": 2,
          "title": "TypeScript shadow adapter",
          "anchor": "typescript-shadow-adapter"
        },
        {
          "level": 2,
          "title": "Pure Rust Delivery Warrant domain",
          "anchor": "pure-rust-delivery-warrant-domain"
        },
        {
          "level": 2,
          "title": "Read-only state projection",
          "anchor": "read-only-state-projection"
        }
      ],
      "markdown": "---\nstatus: draft\nperiod: 2026-08-07\ntheme: buildchain-v4-canonical-contracts\ndoc_type: technical-reference\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-08-07\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-08-07\n  visible_context: Protected Buildchain v4 architecture, canonical contract implementations, schemas, and cross-language fixtures.\n  invisible_context_boundary: Did not inspect credentials, private logs, hidden model state, or unobserved production behavior.\n---\n\n# Buildchain v4 canonical contracts\n\nBuildchain v4 uses one provider-free contract layer for deterministic state-machine bytes and roots. TypeScript v3 remains the sole production writer. These contracts introduce no Git ref writer, network or filesystem effect, daemon, database, credential owner, or ambient clock.\n\n## Canonical JSON v1\n\n`buildchain-canonical-json/v1` accepts only JSON values. Object keys must be non-empty printable ASCII and are ordered by ascending ASCII code point. Arrays retain input order. Numbers are base-10 integers in the inclusive JavaScript-safe range `-9007199254740991..9007199254740991`; fractions, negative zero, non-finite numbers, and wider integers are rejected. Strings use JSON escaping and UTF-8. The exact output ends with one LF byte.\n\nContent roots hash these exact bytes with an explicit domain separator:\n\n```text\nsha256(ASCII(domain) + NUL + canonical-json-bytes)\n```\n\nThe only v1 domains are `queue-state`, `candidate-identity`, `fencing-token`, `transition-receipt`, `observation`, `semantic-diff`, and `bootstrap-evidence`. A queue-state root is computed from a value that omits its own `stateRoot` field.\n\n## Explicit clocks and closed envelopes\n\nPure contract code accepts time only as `YYYY-MM-DDTHH:mm:ss.SSSZ`. An adapter samples once and passes the value as data. Missing clocks, offsets, invalid calendar instants, or other precision are rejected.\n\nEvent, receipt, and typed-fault objects use closed versioned shapes in [`contracts/v4-canonical-contracts-v1.schema.json`](../contracts/v4-canonical-contracts-v1.schema.json). Unknown fields fail. Only a rejected receipt carries a typed fault; accepted and no-op receipts carry `null`.\n\n## Implementations and proof\n\n- JavaScript: [`packages/core/v4-canonical-contracts.js`](../packages/core/v4-canonical-contracts.js)\n- Rust: [`crates/buildchain-v4-contracts`](../crates/buildchain-v4-contracts)\n- Shared golden and adversarial cases: [`architecture/v4-canonical-contract-fixtures.json`](../architecture/v4-canonical-contract-fixtures.json)\n\nRun the focused proof with:\n\n```sh\npnpm run check:v4-contracts\n```\n\nThe check validates both implementations, compares exact UTF-8 bytes and SHA-256 roots, exercises invalid numbers, keys, clocks, domains, and envelope shapes, and scans the pure libraries for ambient clock or provider imports. Delivery Warrant decide/fold, shadow invocation, provider effects, and production authority remain outside this contract slice.\n\n## Shared Delivery Warrant fixture runner\n\nThe versioned trace contract in [`contracts/v4-delivery-warrant-trace-v1.schema.json`](../contracts/v4-delivery-warrant-trace-v1.schema.json) is the language-neutral boundary for retained Delivery Warrant fixtures. The JavaScript runner in [`packages/core/v4-delivery-warrant-fixture-runner.js`](../packages/core/v4-delivery-warrant-fixture-runner.js) and the Rust runner in [`crates/buildchain-v4-contracts`](../crates/buildchain-v4-contracts) consume the same UTF-8 fixture bytes and emit the same deterministic semantic projection.\n\nEach trace is closed and ordered. It binds the exact prior root, event, action or typed fault, canonical successor bytes and root, generation, fencing counter, ordered declarative effects, provider-neutral observations, and rooted receipt. The runner verifies the full root chain before returning a projection. Malformed JSON, missing or unknown fields, reordered sequences, stale roots, and unsupported contract versions fail closed.\n\nThe retained public-safe fixtures are:\n\n- [`golden.json`](../contracts/fixtures/v4-delivery-warrant-trace-v1/golden.json) for accepted submit/select transitions and ordered effects;\n- [`replay.json`](../contracts/fixtures/v4-delivery-warrant-trace-v1/replay.json) for a stale-fence typed fault and response-loss readback.\n\nThe runner is not a state-machine implementation and does not sample time, execute effects, access Git/GitHub, or move production authority. TypeScript v3 remains the sole production writer. Later Rust decide/fold and TypeScript shadow adapters supply or consume this contract instead of defining another projection shape.\n\n## TypeScript shadow adapter\n\nThe adapter in [`packages/core/v4-delivery-warrant-shadow-adapter.js`](../packages/core/v4-delivery-warrant-shadow-adapter.js) runs the existing TypeScript v3 fixture projection first and preserves that exact result as the only authoritative output. When explicitly enabled, it sends the same canonical input bytes to the replaceable Rust host command, requires the effect-disabled host capability, and captures the returned semantic projection only as a non-authoritative observation. Rust never receives effect authority, and success, failure, timeout, cancellation, malformed output, or an unsupported host cannot change the v3 result.\n\nShadow retention accepts only checked-in fixtures or captured replays explicitly marked public-safe. Each returned observation binds the input root, exact TypeScript and Rust source revisions, validator version, capture time, fixed retention deadline, both projections, and sanitized diagnostics. It contains no comparison verdict or cutover signal. The adapter is disabled unless the caller opts in or sets `BUILDCHAIN_V4_WARRANT_SHADOW=enabled`; even then, invalid source bindings or an unsafe retention class skip Rust invocation.\n\n## Pure Rust Delivery Warrant domain\n\nThe `warrant` module in [`crates/buildchain-v4-contracts`](../crates/buildchain-v4-contracts) implements the protected Delivery Warrant manifest as provider-free typed state, seven event decisions, and a separate fold. It freezes all nine candidate states and all nine primitives from the shadow bootstrap plan. Every decision binds the event's exact `subjectRoot`, takes time only from the validated event envelope, and returns a typed action or fault. Fold produces a canonical successor; the combined transition produces only ordered `persist-successor` and `request-admission` intents plus a rooted receipt. It never executes either intent.\n\nDuplicate submission deliberately retains the legacy generation/root mutation for shadow comparability. Manifest aliases remain explicit, waiting and blocked remain valid states without invented public transitions, and response-loss reconciliation is symmetric for every declarative effect. Stale expected-old roots and fences, lease expiry, terminal duplicates, cancellation, response loss, provider conflict, and retry exhaustion are closed typed outcomes. The retry policy permits at most one reread/redecision and then stops.\n\nThe domain consumes the same retained golden and replay bytes as the shared runner. Focused tests cover deterministic replay, bounded property sequences, duplicate behavior, stale compare-and-set and fencing, lease recovery/reselection, settlement and cancellation idempotence, response loss, provider conflict, and calendar-boundary clock arithmetic. Repository-level architecture tests reject provider and I/O imports, ambient clocks, process execution, hidden writers, and unbounded retry loops. The manifest still names `typescript-v3` as the sole authoritative writer with a zero second-writer budget; this slice adds no shadow routing, effect adapter, read/write cutover, or production authority.\n\n## Read-only state projection\n\nThe Rust host also accepts `delivery-warrant.state-project` with the dedicated\n`delivery-warrant-state-projection-v1` capability. It decodes and validates the\nclosed v4 state, then returns the same state and its canonical `queue-state`\nroot. The command has no effect adapter, provider import, store access, or write\nauthority. The TypeScript read-candidate adapter binds this projection to a\npreviously qualified semantic-diff report and retains parity evidence before\nreturning the unchanged v3 observation schema. See\n[`v4-delivery-warrant-read-candidate.md`](v4-delivery-warrant-read-candidate.md)."
    },
    {
      "id": "manual:v4-delivery-warrant-read-candidate",
      "title": "Delivery Warrant v4 read candidate",
      "route": "/docs/v4-delivery-warrant-read-candidate",
      "category": "manual",
      "capabilityGroup": "getting-started",
      "audience": [
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "docs/v4-delivery-warrant-read-candidate.md",
      "digest": "sha256:7e19141b72a0454f27c0c2429b8df3b9605013bf8a6c2f765502fd3ab085ad03",
      "headings": [
        {
          "level": 1,
          "title": "Delivery Warrant v4 read candidate",
          "anchor": "delivery-warrant-v4-read-candidate"
        },
        {
          "level": 2,
          "title": "Source-checkout invocation",
          "anchor": "source-checkout-invocation"
        }
      ],
      "markdown": "---\nstatus: draft\nperiod: ongoing\ntheme: buildchain-v4-delivery-warrant\ndoc_type: contract-guide\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-08-08\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-08-08\n  invisible_context: not asserted\n---\n\n# Delivery Warrant v4 read candidate\n\nThe v4 read candidate is an explicit, reversible observation path. TypeScript\nv3 remains the sole production writer, queue store owner, rollback authority,\nand provider adapter. Rust receives canonical state bytes, validates the pure v4\nstate contract, and returns a read-only projection with effects disabled.\n\nThe normal `observe` path defaults to `--read-mode v3`. No mutation command\nconsults the read switch. A caller may select v4 only by supplying all of the\nfollowing:\n\n- a retained, self-root-verifying semantic-diff report;\n- the exact expected report root;\n- the report's exact TypeScript revision, Rust revision, and validator version;\n- a caller-owned evidence output.\n\nThe candidate fails closed on a blocked, expired, missing, or drifted\nqualification; source mismatch; unsupported host capability; crash; timeout;\ncancellation; malformed response; state/root disagreement; or evidence\nretention failure. It never silently falls back inside a v4 request. Rollback\nis the explicit caller change back to `--read-mode v3`, which avoids dual read\nauthority and leaves the v3 queue untouched.\n\n## Source-checkout invocation\n\nThe preview candidate runs against the checked-out Rust contract host:\n\n```sh\nbuildchain dev warrant observe \\\n  --repository owner/repository --branch dev/v4/v4.0 \\\n  --read-mode v4 \\\n  --read-qualification semantic-diff-report.json \\\n  --read-qualification-root sha256:<root> \\\n  --read-typescript-revision <sha> \\\n  --read-rust-revision <sha> \\\n  --read-validator-version semantic-diff-gate-v1 \\\n  --read-evidence-output .buildchain/dev-delivery/v4-read-evidence.json\n```\n\nThe returned command result keeps the existing v3 observation schema for\ncaller compatibility and adds `readCandidate` evidence that fixes\n`writerAuthority=typescript-v3`, `rustAuthority=read-only`,\n`rustEffects=disabled`, `rollbackMode=v3`, both state roots, the qualification\nroot, and the retained evidence receipt root.\n\nFocused verification:\n\n```sh\nnode --test tests/v4-delivery-warrant-read-candidate.test.mjs\npnpm run check:v4-contracts\n```\n\nThis candidate does not authorize a v4 write cutover. Protected-window parity,\nindependent review, and the rollback drill remain required exit evidence for\nthe read stage."
    },
    {
      "id": "manual:v4-delivery-warrant-semantic-diff",
      "title": "Delivery Warrant v4 semantic diff gate",
      "route": "/docs/v4-delivery-warrant-semantic-diff",
      "category": "manual",
      "capabilityGroup": "getting-started",
      "audience": [
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "docs/v4-delivery-warrant-semantic-diff.md",
      "digest": "sha256:27c93e52c7ebd76fd835cf91df75bf72b183d2484e4d8500d260e810be9e8fdb",
      "headings": [
        {
          "level": 1,
          "title": "Delivery Warrant v4 semantic diff gate",
          "anchor": "delivery-warrant-v4-semantic-diff-gate"
        },
        {
          "level": 2,
          "title": "Qualification contract",
          "anchor": "qualification-contract"
        },
        {
          "level": 2,
          "title": "Run the gate",
          "anchor": "run-the-gate"
        }
      ],
      "markdown": "---\nstatus: draft\nperiod: ongoing\ntheme: buildchain-v4-delivery-warrant\ndoc_type: contract-guide\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-08-08\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-08-08\n  invisible_context: not asserted\n---\n\n# Delivery Warrant v4 semantic diff gate\n\nThe semantic diff gate qualifies paired TypeScript and Rust shadow projections\nwithout moving production authority. TypeScript v3 remains the sole writer,\nthe Rust host remains effect-disabled, and every report fixes\n`v4WriteAuthorized` to `false`.\n\n## Qualification contract\n\nEvery case supplies identical public-safe retained bytes to the JavaScript\nfixture runner and Rust shadow host. The report binds:\n\n- exact TypeScript and Rust source revisions;\n- trace schema, report schema, runner, and validator identities;\n- input, JavaScript projection, Rust projection, difference, evidence, and\n  retention roots, including a root over each retained full shadow observation;\n- golden, bounded property, lease/fence, CAS, duplicate, cancellation,\n  response-loss, provider-conflict, and captured-replay coverage;\n- bounded fault-probe receipts proving that changes to decisions, successor\n  roots, generation, fencing, effects, observations, or receipts are detected.\n\nAn unexplained difference, missing observation, incomplete coverage,\nundetected fault probe, source-binding mismatch, or retention failure blocks\nthe gate with a zero retry budget. A compatibility exclusion is accepted only\nwhen its exact difference root, reason code, independent review root, and\ndisposition root all verify.\n\nThe gate requires every full public-safe shadow observation and the final\nqualification report to be retained for 90 days. Missing either retention\nreceipt blocks qualification. It does not accept private payloads, invoke\nprovider effects, modify v3 authority, or provide a v4 write cutover receipt.\n\n## Run the gate\n\nCall `runV4DeliveryWarrantSemanticDiffGate` with exact source revisions,\nexplicit observation time, schema and runner roots, public-safe retained cases,\nbounded fault probes, an observation retention sink, and a report retention\nsink. The returned report is canonical JSON data suitable for a caller-owned\nretained evidence file.\n\nThe checked-in focused suite exercises that API against the real Rust host:\n\n```sh\nnode --test tests/v4-delivery-warrant-fixture-runner.test.mjs\n```\n\nA qualified report makes only the next\nread-candidate stage eligible; it never authorizes v4 writes.\nThe reversible caller contract and its fail-closed qualification binding are\ndocumented in\n[`v4-delivery-warrant-read-candidate.md`](v4-delivery-warrant-read-candidate.md).\n\nFocused verification:\n\n```sh\npnpm run check:v4-contracts\n```"
    },
    {
      "id": "manual:v4-production-release",
      "title": "Buildchain v4 production release",
      "route": "/docs/v4-production-release",
      "category": "manual",
      "capabilityGroup": "getting-started",
      "audience": [
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "docs/v4-production-release.md",
      "digest": "sha256:525da04bc698e4834d5a380435e51ee566bb8a898e300897435ce1c75c119aad",
      "headings": [
        {
          "level": 1,
          "title": "Buildchain v4 production release",
          "anchor": "buildchain-v4-production-release"
        },
        {
          "level": 2,
          "title": "Provider readback",
          "anchor": "provider-readback"
        },
        {
          "level": 2,
          "title": "Non-destructive rollback",
          "anchor": "non-destructive-rollback"
        }
      ],
      "markdown": "---\nstatus: active\nperiod: ongoing\ntheme: buildchain-v4-production-release\ndoc_type: runbook\nsource_level: repository-contracts + protected-provider-readback\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: self-reviewed\nlast_reviewed: 2026-08-13\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-08-13\n  invisible_context: Provider credentials and private provider state were not read.\n---\n\n# Buildchain v4 production release\n\nBuildchain v4 is the production release authority for the `v4.0` line. The\nprotected source path is:\n\n```text\ndev/v4/v4.0 -> alpha/v4/v4.0 -> release/v4/v4.0\n```\n\nPublic consumers use `v4-alpha` for the current prerelease channel and `v4`\nfor stable. Reproducible consumers may pin an exact 40-character commit or an\nexact immutable release tag such as `v4.0.0`.\n\nThe release transaction is fail-closed. The v4 provider-operation journal,\nactivation plan, stable publication fence, and partial-mutation recovery plan\nbind the exact source, qualification, policy, provider readback, protected\nancestry, and target roots. Confirmed operations are never replayed; uncertain\noperations require provider readback before retry; stable publication requires\nan N-1 or independently sealed qualification.\n\n## Provider readback\n\nA stable release is complete only when all of these coordinates agree:\n\n- `release/v4/v4.0`, `v4`, `v4.0`, and the exact `v4.0.x` tag;\n- the GitHub Release tag and attached Release Passport evidence;\n- npm `@kungfu-tech/buildchain@4.0.x`, its `gitHead`, and the `latest` tag;\n- the protected source and release transaction roots.\n\nThe alpha channel applies the same rule to `alpha/v4/v4.0`, `v4-alpha`, the\nexact alpha tag, and npm's `alpha` tag.\n\n## Non-destructive rollback\n\nRollback never rewrites an exact tag, release, package version, Passport, or\nprovider journal. Stop forward promotion, pin consumers to the last verified\nexact v4 SHA or exact stable tag, and use the retained `release/v3/v3.0`\ncoordinate only as an explicit compatibility rollback reference. Restoring v3\nas production authority requires a new reviewed cutover; it is not an implicit\nfallback.\n\nBefore any retry, compare the current provider state with the retained\ntransaction and operation roots. Resume only missing eligible operations.\nConflicting state remains `repair-required` or terminal and must not be\nconverted into success by moving a floating ref."
    },
    {
      "id": "manual:v4-stage-capsule",
      "title": "Buildchain v4 Stage Capsule",
      "route": "/docs/v4-stage-capsule",
      "category": "manual",
      "capabilityGroup": "getting-started",
      "audience": [
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "docs/v4-stage-capsule.md",
      "digest": "sha256:6ad1e58b455e6bf80b34088151e095ed775880bc806e0c196d2569a65ac0b8e3",
      "headings": [
        {
          "level": 1,
          "title": "Buildchain v4 Stage Capsule",
          "anchor": "buildchain-v4-stage-capsule"
        },
        {
          "level": 2,
          "title": "Platform checkpoint projection",
          "anchor": "platform-checkpoint-projection"
        },
        {
          "level": 2,
          "title": "Three separate roots",
          "anchor": "three-separate-roots"
        },
        {
          "level": 2,
          "title": "Retention and reuse",
          "anchor": "retention-and-reuse"
        },
        {
          "level": 2,
          "title": "Content-addressed reference store",
          "anchor": "content-addressed-reference-store"
        },
        {
          "level": 2,
          "title": "Deterministic resume planning",
          "anchor": "deterministic-resume-planning"
        },
        {
          "level": 2,
          "title": "Three-platform qualification and Wave reconciliation",
          "anchor": "three-platform-qualification-and-wave-reconciliation"
        }
      ],
      "markdown": "---\nstatus: draft\nperiod: ongoing\ntheme: buildchain-v4-stage-capsule\ndoc_type: contract-guide\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-08-10\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-08-10\n  invisible_context: not asserted\n---\n\n# Buildchain v4 Stage Capsule\n\n## Platform checkpoint projection\n\n`architecture/v4-platform-stage-checkpoints.json` is the single declaration\nfor the macOS arm64, Linux x64, and Windows x64 shadow checkpoint lanes. It\ndefines the allowed platform/stage pairs and the exact declared inputs,\noutputs, environment names, toolchains, and portable restore paths.\n\nThe protected `Verify` workflow runs each platform on its real hosted runner.\nAfter a declared successful stage, the TypeScript v3 writer emits the canonical\nCapsule and immutable local-store receipt. A separate Node process restores the\ndeclared output layout into an empty directory and verifies every blob and\nmanifest root. A failed stage emits no Capsule; a later failure does not remove\nearlier successful stage Capsules.\n\nThis is shadow evidence only. It records per-platform/stage overhead and asserts\nthat production bytes did not change. It does not skip production stages, read\nambient runner state, include provider credentials, perform signing or\npublication, or grant provider/cache presence qualification authority. The\ngenerated consumer workflow and Agent guidance point back to the same\ndeclaration; undeclared fields fail closed.\n\nA Stage Capsule is the immutable, per-platform evidence contract for one build\nstage. It does not store artifacts, plan resume, publish provider state, or move\nproduction write authority. TypeScript v3 remains the sole writer; Rust is a\npure validation and root-projection implementation.\n\n## Three separate roots\n\nThe contract deliberately keeps three facts separate:\n\n1. `identityRoot` binds source, platform, stage, toolchain, runtime, policy,\n   declared inputs, transformation, output manifest, qualification, and any\n   explicitly declared rooted observations.\n2. `capsuleRoot` binds that immutable identity and the retention promise.\n3. `availabilityRoot` binds a caller-supplied observation of current\n   availability, content, qualification, and rooted transport locators.\n\nChanging platform, stage, policy, transformation, or a declared input changes\nthe identity root. Changing an observation time or transport locator changes\nonly the availability root. A provider run ID, provider artifact ID, runner\npath, credential, ambient clock, raw network observation, mutable tag, or cache\nhit is not a schema field and therefore cannot silently become identity.\nProvider evidence participates only as an explicitly named observation root.\n\n## Retention and reuse\n\nA retention promise is not proof that bytes currently exist. Reuse is a pure\ndecision over an explicit evaluation clock and a current availability\nobservation. It is eligible only when the capsule, output-manifest, and\nqualification roots all match, the observation is `available`, and the\nretention promise has not expired. `missing`, `expired`, `corrupt`, and\n`root-mismatch` always fail closed. Transport locators are rooted observations,\nnot artifact authority.\n\nThe sole schema authority is\n[`v4-stage-capsule-v1.schema.json`](../contracts/v4-stage-capsule-v1.schema.json).\nThe shared fixture is consumed by both implementations. The next Wave 2 cards\nmay add checkpoints, resume planning, and reconciliation, but must not weaken\nor duplicate this contract.\n\n## Content-addressed reference store\n\nThe storage successor adds one closed output-manifest and store contract suite\nwithout changing Capsule identity. Raw blob bytes use lowercase SHA-256 roots;\nthe canonical output manifest binds byte roots, sizes, and sorted names, and its\n`manifestRoot` must equal the Capsule `outputManifestRoot`. The local reference\nstore writes immutable `blobs`, `capsules`, `manifests`, and `records` families\nunder exact roots. A fresh process can restore by `capsuleRoot`, then re-verifies\nthe Capsule, manifest, every byte root, retention state, availability, transport\nobservation, and qualification root before returning bytes.\n\nRepeated put and restore are idempotent. A different physical store directory\ndoes not change Capsule or manifest identity. `missing`, `expired`, `partial`,\n`corrupt`, `quarantined`, and `root-mismatch` are deterministic fail-closed\nclassifications; there is no cache fallback. Retention promise, evaluated\nretention state, current availability, rooted transport locator, qualification,\nand operation receipt are different roots with caller-supplied clocks.\n\nGitHub Artifact and S3-compatible adapters expose only `effect-disabled` and\n`fixture-backed` modes in this slice. They accept rooted locators, never raw\ncredentials or signed URLs, and cannot perform a provider upload or restore.\nThe executable architecture ceiling is\n[`v4-stage-capsule-store-contract.json`](../architecture/v4-stage-capsule-store-contract.json),\nand the shared Rust/JavaScript fixture is\n[`shared.json`](../contracts/fixtures/v4-stage-capsule-store-v1/shared.json).\n\nFocused verification:\n\n```sh\npnpm run check:v4-contracts\n```\n\n## Deterministic resume planning\n\n`architecture/v4-stage-capsule-resume-planner.json` closes the Wave 2 resume\nplanner. Its request is an explicit topological stage graph with targets,\nexpected Capsule identity and retention, current Capsule/availability\nobservations, an evaluation clock, and separately declared provider or\nrelease-tail effects. The Rust domain core and TypeScript projection consume\nthe same request without filesystem, network, environment, or ambient-clock\naccess and produce the same ordered decisions and `planRoot`.\n\nAn eligible completed dependency becomes an exact-root restore; a missing or\ninvalid target becomes a rebuild, and only that target's dependency closure is\nscheduled. Source, platform, toolchain, runtime, policy, declared-input,\ntransformation, output-manifest, and retention changes carry rooted causal\ninvalidation fields. Cross-platform reuse, corrupt or partial content, root\nmismatch, and insufficient qualification reject reuse fail closed.\n\nEffects never participate in Capsule reuse. They remain ordered declarations\nwith required provider readback and planner mutation disabled. This planner is\nshadow-only: it does not skip a v3 production stage or move v3 authority.\n\n## Three-platform qualification and Wave reconciliation\n\n`architecture/v4-stage-capsule-qualification.json` closes the Wave 2\nqualification boundary. Buildchain and external repositories use the same\nBuildchain-owned public reusable workflow,\n`.github/workflows/v4-stage-capsule-canary.yml`. Buildchain's caller is the thin\n`.github/workflows/v4-public-consumer-dogfood.yml`; it has no steps, copied\norchestration, local action, direct qualification invocation, or private\nconsumer profile. Candidate recursion is resolved only by publishing the exact\ncandidate at `train/v4/v4.0/<capability>` and calling that fully qualified\npublic ref. After successful qualification and protected merge, the caller can\nbe pinned to the exact protected commit. An internal exception is never a\npermitted recursion mechanism.\n\nThe called workflow checks out that same commit as its runtime, reads the consumer's\ntracked `.buildchain/buildchain.toml`, and executes only `install`, `build`,\nand `verify` on GitHub-hosted Linux x64, macOS arm64, and Windows x64 runners.\nEach stage binds its declared command, dependency edge, exact consumer source,\nplatform, lifecycle manifest, summary, and real output roots into the campaign\nprofile. `publish` is explicitly classified as a provider mutation and is not\nexecuted. The caller supplies only its stable consumer name and the real output\npaths; it does not copy the campaign orchestration.\n\nThe external seed retains `install` and `build` before an intentional late\n`verify` failure. A clean process reads the retained store, restores only the\nexact `build` root, rebuilds `verify`, and compares the result with the fresh\nthree-stage aggregate. Runtime-ref, source, command/profile, manifest, summary,\noutput, platform, and Capsule-root drift all stop with typed diagnostics.\n\nQualification compares the declared artifact-manifest and aggregate content\nroots from a fresh full build with the roots assembled from retained and rebuilt\nCapsules. It fails closed on missing, expired, corrupt, partial, cross-platform,\ncross-stage, source/toolchain/policy drift, stale-writer, and root-mismatch\ncampaigns. The rooted report records retained bytes, restore overhead, planner\naccuracy, false reuse, and false rebuild counts. Every invocation declares one\nexact public consumer identity and requires its Linux, macOS, and Windows\nreports before emitting a qualification root. Buildchain declares `buildchain`\nand receives no additional profile or authority.\n\nThe post-merge reconciliation interface accepts that qualification root only\nwith all five Wave 2 children in native terminal state, exact source and\nprotected merge revisions, independent review roots, Delivery Warrant roots,\nnative gate roots, and an empty protected-delivery queue. It emits evidence; it\ndoes not rewrite child authority. `--stage-capsule-mode v3` is the explicit\nnon-destructive rollback switch. No migration, retained-state deletion,\nproduction reuse, provider effect, release effect, or v3 behavior change is\nauthorized by this qualification.\n\nFocused local rehearsal:\n\n```sh\nnode scripts/v4-stage-capsule-qualification.mjs campaign \\\n  --work-root /tmp/buildchain-v4-stage-qualification \\\n  --platform linux-x64 \\\n  --consumer buildchain \\\n  --runtime-ref <exact-buildchain-commit> \\\n  --consumer-source-revision <exact-consumer-commit> \\\n  --consumer-root . \\\n  --lifecycle-evidence-root .buildchain/artifacts/v4-stage-capsule-canary\n```"
    },
    {
      "id": "manual:versioning",
      "title": "Buildchain Versioning",
      "route": "/docs/versioning",
      "category": "manual",
      "capabilityGroup": "governance-versioning",
      "audience": [
        "maintainer"
      ],
      "maturity": "stable",
      "sourcePath": "docs/versioning.md",
      "digest": "sha256:7f6e377abf976e9eb9c5f0fd2baec96922ca44d9ab7dd08178608657fa858978",
      "headings": [
        {
          "level": 1,
          "title": "Buildchain Versioning",
          "anchor": "buildchain-versioning"
        },
        {
          "level": 2,
          "title": "Lines",
          "anchor": "lines"
        },
        {
          "level": 2,
          "title": "Welded Surfaces",
          "anchor": "welded-surfaces"
        },
        {
          "level": 2,
          "title": "Decision Log",
          "anchor": "decision-log"
        },
        {
          "level": 2,
          "title": "Runner Policy",
          "anchor": "runner-policy"
        }
      ],
      "markdown": "---\nstatus: draft\nperiod: ongoing\ntheme: buildchain-versioning\ndoc_type: policy\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-08-01\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-30\n  invisible_context_boundary: Live release and provider state must be verified independently.\n---\n\n# Buildchain Versioning\n\nBuildchain uses semantic version lines to describe public contracts, not only\ncode size. A release can be small in diff size and still open a new minor line\nwhen it adds a durable surface that consumers, workflows, or agents can depend\non.\n\n## Lines\n\n| Line  | Meaning                                                                                                                                                                      |\n| ----- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| Patch | Compatible fix, hardening, documentation correction, or implementation repair inside an existing surface.                                                                    |\n| Minor | New compatible welded surface: reusable workflow output, CLI command family, config protocol, published subpath, evidence file, runner contract, or agent-readable artifact. |\n| Major | Breaking semantic change, removed stable surface, changed branch/tag governance, or incompatible protocol rewrite.                                                           |\n\nKungfu minor lines are long-lived trains. `v3.0`, `v3.1`, and `v3.2` can each\nreceive many patch releases. The major ref, such as `v3`, points at the\nselected stable major entrypoint; the minor ref, such as `v3.2`, points at the\nlatest stable production patch for that minor line.\n\n## Welded Surfaces\n\nThese surfaces are classified independently; the final release impact is the\nhighest impact across the affected registered surfaces:\n\n- reusable workflow inputs, outputs, and artifact contracts;\n- public CLI command families and their machine-readable JSON shapes;\n- public npm exports such as `@kungfu-tech/buildchain/logging`;\n- config protocols such as `buildchain.toml`;\n- release governance state machines and protected ref semantics;\n- release evidence contracts such as passport, artifact evidence, impact\n  ledger, and agent index files;\n- binary distribution shapes that users can install or automate against.\n\nFor each surface:\n\n- content, documentation, or implementation-only work that does not touch a\n  registered surface is patch;\n- additive fields, new commands, new exports, new evidence sections, or new\n  registered surfaces are minor;\n- removals, incompatible renames, changed meanings, newly required fields,\n  weakened trust gates, or changed ref flow are major.\n\nThe release passport records this as `surfaceImpacts[]` plus\n`versionImpact.final`. The final impact must equal the highest surface impact,\nso an agent cannot silently label a release patch when one machine surface needs\nminor review.\n\n`surfaceImpacts[]` is mandatory for production release passports (`release/*`)\nand major publish-gate passports. Alpha, local, and legacy passport contexts\nkeep the field optional so temporary validation can proceed without pretending\nto be a production release decision.\n\nExample: a KFD document such as KFD-2 is content and remains patch, but adding a\n`kind` field to the machine-consumed KFD `registry.json` is an additive change\nto the `kfd-registry-schema` surface and therefore requires minor-impact\nreview. This avoids both false shortcuts: \"new KFD means minor\" and \"all KFD\nrepository changes are patch\".\n\n## Decision Log\n\n| Date       | Action       | Line    | Faces                                                                                                                                                                        | Class    | Rationale                                                                                                                                                                                                                                                                                                                              | PR    |\n| ---------- | ------------ | ------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----- |\n| 2026-08-11 | extend-minor | `v4.0`  | release-blocker-repair-contract, release-blocker-priority-claim, release-train-node-export, dev-delivery-warrant-node-export                                                 | additive | Forward-port rooted successor candidate generations, exact semantic patch identity across cut and Dev landings, publication blocking through conflict or mismatch, and the narrow non-preemptive Warrant blocker lane already protected and self-dogfood-proven on v3.                                                               |       |\n| 2026-08-10 | extend-minor | `v4.0`  | release-cut-contract, release-train-state-machine, release-train-node-export                                                                                                | additive | Forward-port the provider-neutral rooted Release Cut and idempotent Release Train state contract already proven on v3; candidate, tree, Alpha base, runtime, generation, and authority stay frozen while later Dev movement remains an observation rather than implicit supersession.                                                   |       |\n| 2026-08-08 | extend-minor | `v4.0`  | dev-delivery-warrant-read-candidate, rust-state-projection, dev-delivery-cli                                                                                                 | additive | Add an opt-in, qualification-bound read projection behind `observe --read-mode v4`; v3 remains the sole writer and default reader, mutation commands ignore the switch, failures stop, and rollback is the explicit caller change back to v3.                                                                                          |       |\n| 2026-08-05 | extend-minor | `v3.0`  | auditable-demo-scenario, auditable-demo-capture, auditable-demo-adapter                                                                                                      | additive | Add an opt-in deterministic readable-playback declaration that preserves captured terminal payloads and order while normalizing only presentation timing; omitted playback continues to use observed PTY timestamps, and existing composition modes remain unchanged.                                                                  |       |\n| 2026-08-04 | extend-minor | `v3.0`  | dev-delivery-warrant-queue, source-qualification-proof, integration-delivery-proof, dev-delivery-cli, reusable-dev-delivery-workflows                                        | additive | Add durable fair and fenced protected-dev scheduling plus split source/integration proof contracts. Existing PR admission remains available through explicit `off` and `shadow` rollout modes; no existing command, export, or release flow is removed.                                                                                |       |\n| 2026-08-01 | extend-minor | `v3.0`  | cli-reference-registry, node-api-symbol-registry, golden-path-manual                                                                                                         | additive | Add generated, drift-checked CLI and Node API reference registries to the public site bundle, plus a package-tested first-user Golden Path; existing command execution and import semantics remain unchanged.                                                                                                                          |       |\n| 2026-07-31 | extend-minor | `v3.0`  | auditable-demo-workflow, auditable-demo-media-profile, auditable-demo-media-receipt                                                                                          | additive | Add an opt-in responsive profile that binds source-resolution and exact 1280x720 MP4/WebM/GIF renditions to one Gate and receipt while rejecting upscales, aspect-ratio drift, and profile changes between Gate-only and full-render paths.                                                                                            |       |\n| 2026-07-31 | extend-minor | `v3.0`  | release-candidate-family-evidence, release-passport-evidence-attachment, promotion-action, release-passport-cli                                                              | additive | Restore all-ref v2 parity for optional Initiative-family candidate binding and typed product-owned release evidence attachments while retaining Kungfu native Family State authority and the newer v3 post-activation released-evidence stage.                                                                                         | #2089 |\n| 2026-07-30 | extend-minor | `v3.0`  | reusable-build-workflow, observed-evidence-bundle, release-passport-json-reader, web-surface-release-governance                                                              | additive | Add bounded artifact compression and remote-read controls plus transactional derived evidence projections while repairing release-PR runtime handoff so production remains protected-main-only.                                                                                                                                        |       |\n| 2026-07-29 | extend-minor | `v3.0`  | artifact-signing-config, apple-developer-id-authority, artifact-signing-evidence                                                                                             | additive | Extend the consumer-neutral signing declaration to macOS compound archives, including nested wheel Mach-O signing, PEP 427 RECORD repair, safe archive reconstruction, and whole-product notarization under the same protected authority.                                                                                              |       |\n| 2026-07-28 | extend-minor | `v3.0`  | auditable-demo-workflow, auditable-demo-media-profile, auditable-demo-media-receipt                                                                                          | additive | Add opt-in archive, web-delivery, and site-hero profiles; independently bind codec, container, audio, layout, byte-budget, role, and fast-start facts into a v2 media receipt while preserving the existing archive default.                                                                                                           |       |\n| 2026-07-26 | extend-minor | `v3.0`  | auditable-demo-workflow, auditable-demo-evidence                                                                                                                             | additive | Forward-port the consumer-neutral reusable Gate that binds exact same-run GitHub Artifacts to checked-in adapters and immutable renderer evidence, with optional media rendering only from the exact passing Gate bundle.                                                                                                              | #1862 |\n| 2026-07-23 | extend-minor | `v2.14` | credential-island-macos-input, protected-signer-job, macos-signing-evidence, action-subpaths                                                                                 | additive | The reusable build surface can seal an exact source-bound macOS app and hand it to a protected caller environment, where an immutable Buildchain action signs, notarizes, staples, Gatekeeper-assesses, and returns an auditable additional release-candidate platform without exposing credentials to consumer lifecycle jobs.        |       |\n| 2026-07-20 | extend-minor | `v2.14` | anchored-derived-version-material, build-controller-evidence, release-passport, package-subpaths, release-propagation-controller                                             | additive | Anchored/manual consumers can declare derived version witnesses that Buildchain regenerates and verifies before heavy builds, binds to exact alpha/release trees and passports, and admits during protected promotion; propagation receipts now model their existing optional consumer stages.                                         |       |\n| 2026-07-17 | extend-minor | `v2.14` | merge-queue-config, release-line-governance-inheritance                                                                                                                      | additive | Buildchain config can explicitly enable, inherit, or disable exact dev-channel merge queues, and release-line bootstrap reconciles the declared or inherited policy before moving the repository default branch.                                                                                                                       |       |\n| 2026-07-16 | open-minor   | `v2.14` | dev-merge-queue-governance                                                                                                                                                   | additive | The public CLI adds a dry-run-first, idempotent merge-queue governance command that verifies required workflow event compatibility before applying an exact dev-channel ruleset and removing the strict up-to-date race.                                                                                                               |       |\n| 2026-07-15 | open-minor   | `v2.13` | artifact-verification-envelope, package-subpaths                                                                                                                             | additive | The public envelope seals exact artifact, provenance, identity, lifecycle, revocation, and existing KFD assessment roots into one consumer-ready KFX admission input, with a dedicated Node API export and fail-closed verifier.                                                                                                       |       |\n| 2026-07-11 | open-minor   | `v2.12` | channel-build-router, channel-selection-protocol                                                                                                                             | additive | The public `build.yml` reusable workflow lets consumers declare one build job while Buildchain selects generic major alpha for development/prerelease intent and stable major for production release intent, with explicit overrides, separate locks, and fail-closed ambiguity handling.                                              |       |\n| 2026-07-08 | open-minor   | `v2.9`  | build-facts-contract                                                                                                                                                         | additive | Build Facts add a public CLI command family, Node API export, config protocol, module/product fact contracts, release-passport evidence section, and Kungfu legacy buildinfo projection from the same source facts.                                                                                                                    |       |\n| 2026-07-06 | open-minor   | `v2.8`  | kfd-1-contract-world-release-gate, kfd-2-release-trust-passport-audit, kfd-3-collaboration-interface-trust-proof, publish-source-lock-enforcement, required-check-protection | additive | KFD release gates add KFD-1 self contract verification, KFD-2 public release trust claim audit, KFD-3 collaboration-interface trust proofs, publish-side source-lock enforcement for promote-only wrappers, and protected channel required checks repaired to bind GitHub Actions check runs instead of legacy commit status contexts. |       |\n| 2026-07-04 | open-minor   | `v2.5`  | scheduled-integration-governance                                                                                                                                             | additive | Scheduled integration governance adds scheduled feature-branch discovery, conflict-free integration, reporting, and agent-visible governance automation for dev-line maintenance.                                                                                                                                                      |       |\n| 2026-07-03 | open-minor   | `v2.4`  | infra-contract-lifecycle                                                                                                                                                     | additive | Infra contract lifecycle adds the provider-neutral `infra-contract` CLI command family, project type, adapter capability contract, lifecycle evidence bundle, propagation evidence, CI evidence mode, and consumer-facing contract artifacts.                                                                                          |       |\n| 2026-07-02 | open-minor   | `v2.3`  | web-surface-host-mapping                                                                                                                                                     | additive | Web surface host mapping adds first-class multi-host surface bindings, reusable workflow URL outputs, per-surface deployment overrides, and an agent-readable fixture contract.                                                                                                                                                        |       |\n| 2026-07-02 | open-minor   | `v2.2`  | release-passport, binary-distribution                                                                                                                                        | additive | Release passport and binary distribution add agent-readable release passport files, artifact evidence, impact ledger, agent index, GitHub Release collection and verification commands, and standalone binary assets.                                                                                                                  |       |\n| 2026-07-02 | open-minor   | `v2.1`  | logging-sdk, cli-observability, package-subpaths                                                                                                                             | additive | Buildchain toolkit observability adds the public logging SDK, CLI observability commands, and package subpaths that consumers can import.                                                                                                                                                                                              |       |\n\n## Runner Policy\n\nThe `v2.2` binary distribution lane uses GitHub-hosted runners for production\nassets because that is the easiest release path for external users to reproduce:\n\n- `ubuntu-24.04`\n- `macos-latest`\n- `windows-2022`\n\nSelf-hosted runners remain compatibility fixtures. They prove Buildchain's\nprotocol does not depend on GitHub-hosted images, but they do not define the\npublic binary distribution path."
    },
    {
      "id": "manual:web-surface-deployments",
      "title": "Web-Surface Deployment Contract",
      "route": "/docs/web-surface-deployments",
      "category": "manual",
      "capabilityGroup": "site-and-propagation",
      "audience": [
        "site",
        "release-operator"
      ],
      "maturity": "stable",
      "sourcePath": "docs/web-surface-deployments.md",
      "digest": "sha256:484e896746d2f4cca4f9f18d29c14784ec20143c12affc3dbb9ccfbf8f221b55",
      "headings": [
        {
          "level": 1,
          "title": "Web-Surface Deployment Contract",
          "anchor": "web-surface-deployment-contract"
        },
        {
          "level": 2,
          "title": "Configuration",
          "anchor": "configuration"
        },
        {
          "level": 1,
          "title": "Optional. Defaults to \"buildchain\".",
          "anchor": "optional-defaults-to-buildchain"
        },
        {
          "level": 1,
          "title": "Use \"external\" when an existing viewer-request CloudFront Function already",
          "anchor": "use-external-when-an-existing-viewer-request-cloudfront-function-already"
        },
        {
          "level": 1,
          "title": "owns preview alias, surface-prefix, and directory-index routing.",
          "anchor": "owns-preview-alias-surface-prefix-and-directory-index-routing"
        },
        {
          "level": 1,
          "title": "Optional. Defaults to HTTP for public channels and S3 object evidence for",
          "anchor": "optional-defaults-to-http-for-public-channels-and-s3-object-evidence-for"
        },
        {
          "level": 1,
          "title": "managed-network channels. Use \"s3-object\" when CI should verify uploaded",
          "anchor": "managed-network-channels-use-s3-object-when-ci-should-verify-uploaded"
        },
        {
          "level": 1,
          "title": "objects and manifests instead of waiting for public edge convergence.",
          "anchor": "objects-and-manifests-instead-of-waiting-for-public-edge-convergence"
        },
        {
          "level": 3,
          "title": "Multi-Surface Host Mapping",
          "anchor": "multi-surface-host-mapping"
        },
        {
          "level": 3,
          "title": "Floating Runtime Contract Lock",
          "anchor": "floating-runtime-contract-lock"
        },
        {
          "level": 2,
          "title": "Preview Aliases",
          "anchor": "preview-aliases"
        },
        {
          "level": 2,
          "title": "Deployment Manifest",
          "anchor": "deployment-manifest"
        },
        {
          "level": 2,
          "title": "Deploy Plans",
          "anchor": "deploy-plans"
        },
        {
          "level": 2,
          "title": "Explicit Apply",
          "anchor": "explicit-apply"
        },
        {
          "level": 3,
          "title": "Explicit cache classes",
          "anchor": "explicit-cache-classes"
        },
        {
          "level": 3,
          "title": "Immutable publication paths",
          "anchor": "immutable-publication-paths"
        },
        {
          "level": 3,
          "title": "Qualified publication package-pin fast path",
          "anchor": "qualified-publication-package-pin-fast-path"
        },
        {
          "level": 2,
          "title": "Production Preflight And Health",
          "anchor": "production-preflight-and-health"
        },
        {
          "level": 2,
          "title": "Cleanup Plans",
          "anchor": "cleanup-plans"
        },
        {
          "level": 2,
          "title": "Reusable Workflow Shape",
          "anchor": "reusable-workflow-shape"
        },
        {
          "level": 2,
          "title": "Site Repository Shape",
          "anchor": "site-repository-shape"
        },
        {
          "level": 2,
          "title": "Signed bootstrap installer publications",
          "anchor": "signed-bootstrap-installer-publications"
        },
        {
          "level": 2,
          "title": "Boundaries",
          "anchor": "boundaries"
        }
      ],
      "markdown": "---\nstatus: draft\nperiod: ongoing\ntheme: web-surface-deployments\ndoc_type: contract\nsource_level: local-files\nconfidence: high\nsensitivity: public\nevidence_grade: A\nreview_state: unreviewed\nlast_reviewed: 2026-07-30\nai_provenance:\n  model_family: GPT-5\n  product: Codex\n  generated_at: 2026-07-30\n  invisible_context_boundary: No credentials, private logs, or unpublished deployment values are included.\n---\n\n# Web-Surface Deployment Contract\n\nBuildchain supports `project.type = \"web-surface\"` for repositories that publish\nsites, docs, product pages, operator consoles, or browser apps. These projects\nneed auditable deployment semantics, but they are not package release lines and\nshould not be forced into `dev/alpha/release` version-state automation.\n\nThe release object for a web surface is:\n\n```text\nsource commit + build artifact + deploy target + channel + deployment manifest\n```\n\nThis keeps the evidence chain clear:\n\n- the source SHA explains what code was built;\n- the artifact hash explains exactly what was deployed;\n- the channel explains who can see it and whether it is promotable;\n- the deploy target and adapter explain where it would be published;\n- the deployment manifest records retention, rollback, security, and secret\n  reference metadata.\n\n## Configuration\n\n`.buildchain/buildchain.toml` is the source of truth. Web-surface projects must declare\npreview, staging, and production channels plus a deploy adapter for each.\n\n```toml\nschema = 1\n\n[project]\ntype = \"web-surface\"\nname = \"site-kungfu-tech\"\nsite = \"kungfu-tech\"\n\n[channels.preview]\nurl_pattern = \"https://{alias}.preview.kungfu.tech\"\nvisibility = \"ephemeral\"\nrequires_auth = false\nnoindex = true\n\n[channels.staging]\nurl = \"https://staging.kungfu.tech\"\nvisibility = \"protected\"\naccess_control = \"managed-network\"\nedge_auth = \"none\"\nnoindex = true\npromotable = true\n\n[channels.production]\nurl = \"https://kungfu.tech\"\nvisibility = \"public\"\ncanonical = true\nnoindex = false\n\n[deploy.preview]\nadapter = \"aws-s3-cloudfront\"\nbucket = \"kungfu-tech-preview\"\ncloudfront_distribution = \"E-PREVIEW\"\nartifact_path = \"dist\"\nsecret_refs = [\"AWS_ROLE_ARN\"]\n# Optional. Defaults to \"buildchain\".\n# Use \"external\" when an existing viewer-request CloudFront Function already\n# owns preview alias, surface-prefix, and directory-index routing.\ndirectory_index_rewrite = \"buildchain\"\n# Optional. Defaults to HTTP for public channels and S3 object evidence for\n# managed-network channels. Use \"s3-object\" when CI should verify uploaded\n# objects and manifests instead of waiting for public edge convergence.\nhealth_strategy = \"http\"\n```\n\n### Multi-Surface Host Mapping\n\nSome site repositories publish more than one first-class web surface from the\nsame artifact. For example, `site-libkungfu-dev` has a hub plus separate\nhostnames for core, Buildchain, and Kung Fu Decisions. These are not just\nnavigation paths; staging, production preflight, and post-deploy health checks\nmust verify host-level behavior for each surface.\n\nDeclare named surfaces with per-channel URLs:\n\n```toml\n[surfaces.hub]\npath = \"/\"\nproduction_url = \"https://libkungfu.dev\"\nstaging_url = \"https://staging.libkungfu.dev\"\npreview_url_pattern = \"https://{alias}.preview.libkungfu.dev\"\n\n[surfaces.core]\npath = \"/core/\"\nproduction_url = \"https://core.libkungfu.dev\"\nstaging_url = \"https://core.staging.libkungfu.dev\"\npreview_url_pattern = \"https://core-{alias}.preview.libkungfu.dev\"\n\n[surfaces.buildchain]\npath = \"/buildchain/\"\nproduction_url = \"https://buildchain.libkungfu.dev\"\nstaging_url = \"https://buildchain.staging.libkungfu.dev\"\npreview_url_pattern = \"https://buildchain-{alias}.preview.libkungfu.dev\"\n\n[surfaces.kfd]\npath = \"/kfd/\"\nproduction_url = \"https://kfd.libkungfu.dev\"\nstaging_url = \"https://kfd.staging.libkungfu.dev\"\npreview_url_pattern = \"https://kfd-{alias}.preview.libkungfu.dev\"\n```\n\nBuildchain resolves every `(channel, surface)` pair. A preview alias such as\n`pr-12` becomes:\n\n```text\nhub:        https://pr-12.preview.libkungfu.dev\ncore:       https://core-pr-12.preview.libkungfu.dev\nbuildchain: https://buildchain-pr-12.preview.libkungfu.dev\nkfd:        https://kfd-pr-12.preview.libkungfu.dev\n```\n\nWhen `surfaces` is omitted, Buildchain preserves the legacy single-surface\ncontract by creating an implicit `default` surface from the channel URL. When a\nsurface is intentionally path-only, declare it explicitly:\n\n```toml\n[surfaces.docs]\npath = \"/docs/\"\npath_only = true\n```\n\n`path_only = true` is an exception, not the default. Without it, every named\nsurface must declare `preview_url_pattern`, `staging_url`, and\n`production_url`. This makes staging/production mismatches fail during\nvalidation instead of becoming invisible deploy drift.\n\nAdapter strategy remains explicit. The default `aws-s3-cloudfront` plan uses the\nchannel deploy target for every surface, and each binding records its own\nbucket, distribution id, object prefix, manifest key, source path, and URL. A\nchannel can override target details per surface:\n\n```toml\n[deploy.staging.surfaces.core]\nbucket = \"libkungfu-dev-core-staging\"\ncloudfront_distribution = \"E-CORE-STAGING\"\norigin_path = \"/core\"\n```\n\nBuildchain validates these hard constraints:\n\n- `channels.preview.url_pattern` is required and must contain the alias shape\n  used by preview deployments.\n- `channels.staging.access_control` must protect staging. Supported modes are\n  `managed-network`, `edge-basic-auth`, `oidc`, and `app-auth`.\n- `channels.staging.edge_auth` records whether the edge layer owns auth. Use\n  `edge_auth = \"none\"` when staging is protected by managed network controls\n  such as WAF/IP allowlists or VPN access.\n- `channels.staging.noindex = true` is required.\n- `channels.production.url` is required.\n- deploy adapters must be declared per channel.\n- named surfaces must declare first-class URLs for every channel unless\n  `path_only = true` is explicitly set.\n- secret material must be declared as reference names, such as\n  `secret_refs = [\"AWS_ROLE_ARN\"]`; inline secret-like deploy keys are rejected.\n\n### Floating Runtime Contract Lock\n\nWeb-surface repositories can consume the stable Buildchain workflow shell with a\nfloating ref, such as:\n\n```yaml\njobs:\n  web:\n    uses: kungfu-systems/buildchain/.github/workflows/.web-surface.yml@v3\n    with:\n      buildchain-contract-lock-path: .buildchain/contract-lock.json\n      buildchain-contract-compatibility-policy: major-compatible\n      buildchain-contract-drift-issue-mode: compatible-and-breaking\n      build-command: pnpm build\n      artifact-path: dist\n```\n\nThe caller repository commits `.buildchain/contract-lock.json` after reviewing an\naccepted Buildchain runtime SHA and contract digest. The reusable workflow then\nresolves the floating runtime to an immutable SHA, checks the lock before the\ncaller build command, and applies these rules:\n\n- unchanged lock: continue without feedback;\n- compatible drift: continue, write the drift summary, and open or update a\n  caller-repository issue when permissions allow;\n- breaking drift: fail closed before rendering, deployment planning, deploy\n  apply, or release publication.\n\nThe caller no longer needs to run `scripts/buildchain-contract-lock.mjs` inside\nits own build command. That check belongs to Buildchain because the actual\ncontract world is stored in the Buildchain runtime ref being used.\n\nSupported adapter names are:\n\n| Adapter | Initial use |\n| --- | --- |\n| `aws-s3-cloudfront` | Static site artifact sync plus CDN invalidation plan |\n| `aws-elastic-beanstalk` | Future dynamic app environment adapter |\n| `aws-ecs-service` | Future dynamic service adapter |\n\nThe channel ontology is independent of the adapter. A future dynamic staging\nenvironment still remains `channel = \"staging\"` with protected/noindex/security\nrequirements.\n\n## Preview Aliases\n\nPreview uses subdomains, not path prefixes:\n\n```text\nhttps://pr-123.preview.kungfu.tech\nhttps://sha-abcdef123456.preview.kungfu.tech\n```\n\nAlias semantics are explicit:\n\n| Alias | Meaning | Mutable | Retention |\n| --- | --- | --- | --- |\n| `pr-123` | Current preview for a pull request | yes | short-lived |\n| `sha-abcdef123456` | Immutable preview for one source SHA | no | longer-lived |\n\nThis allows PR comments to stay stable while preserving immutable evidence for a\nspecific source commit.\n\n## Deployment Manifest\n\nBuildchain emits a manifest with the deployment facts that matter for audit and\nrollback:\n\n```json\n{\n  \"schemaVersion\": 1,\n  \"contract\": \"kungfu-buildchain-web-surface-deployment\",\n  \"site\": \"libkungfu-dev\",\n  \"channel\": \"preview\",\n  \"alias\": \"sha-abcdef123456\",\n  \"url\": \"https://sha-abcdef123456.preview.libkungfu.dev\",\n  \"generatedAt\": \"2026-07-01T00:00:00.000Z\",\n  \"publishedAt\": \"2026-07-01T00:00:00.000Z\",\n  \"reproducible\": true,\n  \"timestampPolicy\": \"ci-injected\",\n  \"deterministicInputs\": [\n    \"web-surface artifact content\",\n    \"buildchain.toml web-surface channels/deploy/surfaces\",\n    \"sourceSha\",\n    \"artifactHash\",\n    \"deployment channel\",\n    \"deployment alias\"\n  ],\n  \"sourceRevision\": \"...\",\n  \"timestampPolicyDetails\": {\n    \"contract\": \"kungfu-buildchain-surface-timestamp-policy\",\n    \"timestampFields\": [\"generatedAt\", \"publishedAt\", \"deployedAt\"],\n    \"timestampFieldsParticipateInArtifactDigest\": false,\n    \"artifactDigestScope\": \"web-surface artifactHash excludes deployment manifest timestamps\"\n  },\n  \"sourceSha\": \"...\",\n  \"artifactHash\": \"...\",\n  \"deployTarget\": \"libkungfu-dev-preview\",\n  \"adapter\": \"aws-s3-cloudfront\",\n  \"deployedAt\": \"2026-07-01T00:00:00.000Z\",\n  \"retentionClass\": \"preview-sha-immutable\",\n  \"expiresAt\": \"2026-09-29T00:00:00.000Z\",\n  \"accessControl\": \"none\",\n  \"edgeAuth\": \"none\",\n  \"noindex\": true,\n  \"secretRefs\": [\"AWS_ROLE_ARN\"],\n  \"surfaceBindings\": [\n    {\n      \"surface\": \"hub\",\n      \"channel\": \"preview\",\n      \"alias\": \"sha-abcdef123456\",\n      \"url\": \"https://sha-abcdef123456.preview.libkungfu.dev\",\n      \"sourcePath\": \"/\",\n      \"artifactPathPrefix\": \"\",\n      \"viewerPathPrefix\": \"/\",\n      \"directoryIndex\": \"index.html\",\n      \"directoryIndexResolution\": true,\n      \"canonicalUrl\": \"https://libkungfu.dev\",\n      \"bucket\": \"libkungfu-dev-preview\",\n      \"distributionId\": \"E-PREVIEW\",\n      \"originPath\": \"\",\n      \"objectPrefix\": \"sha-abcdef123456\",\n      \"manifestKey\": \".buildchain/deployments/sha-abcdef123456/hub.json\",\n      \"routing\": {\n        \"contract\": \"kungfu-buildchain-web-surface-path-prefix-rewrite\",\n        \"viewerPathPrefix\": \"/\",\n        \"artifactPathPrefix\": \"\",\n        \"objectPrefix\": \"sha-abcdef123456\",\n        \"directoryIndex\": \"index.html\",\n        \"directoryIndexResolution\": true\n      },\n      \"smokeUrls\": [\n        {\n          \"kind\": \"root\",\n          \"requestPath\": \"/\",\n          \"url\": \"https://sha-abcdef123456.preview.libkungfu.dev/\",\n          \"required\": true\n        }\n      ],\n      \"noindex\": true,\n      \"accessControl\": \"none\"\n    }\n  ]\n}\n```\n\nDynamic adapters can also fill `runtimeId`, `configFingerprint`,\n`healthCheck`, `migrationState`, `rollbackPointer`, and\n`rollbackLimitations`. Buildchain records secret reference names only, never\nsecret values.\n\nThe timestamp policy is shared with package site bundles. Public deployment\nmanifests should expose real workflow generation/publication times while\nseparately declaring why the deployed artifact remains reproducible. For\nweb-surface deployment manifests, `artifactHash` is the static site artifact\ndigest and does not include deployment timestamp fields; the manifest itself\nstill records those fields for human and agent audit.\n\n## Deploy Plans\n\nDeploy planning is the default behavior. It plans the adapter steps and writes\nmanifest JSON, but it does not touch AWS, DNS, CloudFront, or deployment\ncredentials.\n\n```bash\nnode scripts/web-surface.mjs \\\n  --mode deploy-plan \\\n  --cwd fixtures/web-surface-shaped \\\n  --source-sha aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \\\n  --alias sha-aaaaaaaaaaaa\n```\n\nFor manifest-only output:\n\n```bash\nnode scripts/web-surface.mjs \\\n  --mode manifest \\\n  --cwd fixtures/web-surface-shaped \\\n  --source-sha aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \\\n  --alias pr-123 \\\n  --output .buildchain/web-surface-manifest.json\n```\n\nThe CLI emits GitHub outputs when `GITHUB_OUTPUT` is present:\n\n- `web-surface-channel`\n- `web-surface-alias`\n- `web-surface-url`\n- `web-surface-urls-json`\n- `web-surface-artifact-hash`\n- `web-surface-manifest-json`\n\nThe reusable workflow resolves that same effective channel before running the\ncaller build or verify command. Both steps receive\n`BUILDCHAIN_WEB_SURFACE_CHANNEL` (`preview`, `staging`, or `production`) and\n`BUILDCHAIN_PREVIEW_ALIAS` for previews. Compatibility aliases\n`BUILDCHAIN_SURFACE_CHANNEL` and `BUILDCHAIN_WEB_SURFACE_ALIAS` are also\nprovided. Callers should consume these variables instead of reconstructing the\nrelease-intent state machine from raw GitHub events.\nAn unapproved manual canary resolves to `staging`; a trusted manual dispatch\nwith `production-approved=true` resolves to `production` through the same path.\n\n## Explicit Apply\n\n`deploy-apply` and `cleanup-apply` are explicit execution modes for the\n`aws-s3-cloudfront` static-site adapter. They still default to `--dry-run true`;\nlive AWS mutation requires `--dry-run false`.\n\nDeploy apply syncs the artifact, writes the deployment manifest, and invalidates\nCloudFront when a distribution id is configured:\n\n```bash\nnode scripts/web-surface.mjs \\\n  --mode deploy-apply \\\n  --cwd fixtures/web-surface-shaped \\\n  --channel staging \\\n  --source-sha aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \\\n  --artifact-path dist \\\n  --dry-run false \\\n  --output .buildchain/web-surface-staging-apply.json\n```\n\n### Explicit cache classes\n\nThe S3/CloudFront adapter can declare cache metadata per deploy channel or\nsurface override:\n\n```toml\n[deploy.production]\nadapter = \"aws-s3-cloudfront\"\ncache_control_default = \"public,max-age=3600\"\ncache_control_mutable = \"public,max-age=300,must-revalidate\"\ncache_control_immutable = \"public,max-age=31536000,immutable\"\n```\n\n`cache_control_default` applies to the ordinary artifact sync.\n`cache_control_mutable` is then applied to HTML, JSON, XML, generated directory\nindex aliases, and the deployment manifest. `cache_control_immutable` applies\nto append-only publication roots discovered through the archive policy below.\nMutable metadata updates exclude those append-only roots, so HTML or JSON inside\nan immutable version archive keeps the immutable class.\nThe deploy plan, surface binding, apply operations, and deployment manifest all\nrecord the effective values. Existing consumers that omit these fields retain\ntheir prior upload behavior.\n\nCache metadata complements, rather than replaces, invalidation. Every deploy\nstill records and creates the exact surface wildcard and deployment-manifest\ninvalidation paths.\n\n### Immutable publication paths\n\nWhen a surface artifact contains `manifest.json` with\n`archivePolicy.contract = \"kungfu-buildchain-publication-archive-policy\"`,\nBuildchain treats every declared `publications[].versions[].immutablePath` as\nan append-only publication boundary. This applies identically to preview,\nstaging, and production adapters.\n\nThe adapter derives the protected archive root from those declared version\npaths and applies four ordered safeguards:\n\n1. every local immutable file is checked against an existing S3 object;\n2. missing files are uploaded with `aws s3 sync --no-overwrite` and a SHA-256\n   checksum;\n3. every immutable file is checked again after upload, closing the race between\n   the first check and the no-overwrite transfer;\n4. mutable site content keeps normal `sync --delete` behavior, but every parent\n   or owning surface sync excludes the protected archive root from deletion.\n\nAn existing object with a different SHA-256 digest fails apply before mutable\ncontent is changed. Older objects without a stored S3 SHA-256 checksum are read\nand byte-hashed for compatibility. Directory-index alias writes are skipped\nunder protected roots so they cannot overwrite immutable route objects; viewer\nrequest rewriting remains the directory-index authority.\n\nThe deploy plan and manifest record `immutablePublication`,\n`mutableDeleteExcludes`, and the parent-surface coverage. Apply output records\n`immutablePreservation` plus every pre-check, no-overwrite sync, post-check, and\nmutable sync operation. Health output adds an `__immutable__` check proving that\nthe owning and parent surface syncs carried their required delete exclusions.\nThe runner must provide an AWS CLI version whose `s3 sync` supports\n`--no-overwrite`.\n\n### Qualified publication package-pin fast path\n\nA consumer may narrow one deployment to the exact paper version introduced by\na package-pin-only PR. The artifact root `manifest.json` must carry a\nconsumer-owned qualification envelope:\n\n```json\n{\n  \"publicationFastPath\": {\n    \"contract\": \"kungfu-buildchain-publication-package-pin-fast-path\",\n    \"mode\": \"package-pin-only\",\n    \"targetSurface\": \"papers\",\n    \"qualificationRoot\": \"sha256:...\",\n    \"immutablePrefixes\": [\n      \"archive/observer-declared-timelines/v0.1.0-alpha.10\"\n    ],\n    \"mutableFiles\": [\n      \"archive/index.html\",\n      \"index.html\",\n      \"manifest.json\",\n      \"observer-declared-timelines/index.html\",\n      \"observer-declared-timelines/latest/index.html\",\n      \"registry.json\"\n    ],\n    \"invalidationPaths\": [\n      \"/\",\n      \"/archive/\",\n      \"/archive/observer-declared-timelines/v0.1.0-alpha.10*\",\n      \"/observer-declared-timelines/\",\n      \"/observer-declared-timelines/latest/\",\n      \"/manifest.json\",\n      \"/registry.json\"\n    ]\n  }\n}\n```\n\nBuildchain validates that the target surface exists, every immutable prefix is\ndeclared by that surface's archive manifest, every mutable file exists outside\nthose prefixes, and the qualification root is exact. A qualified plan:\n\n- selects only `targetSurface`;\n- verifies/uploads only the declared immutable prefixes with the normal\n  no-overwrite digest safeguards;\n- copies only the declared mutable files;\n- skips full `sync --delete` and directory-index alias writes;\n- invalidates only the declared viewer paths plus the deployment manifest.\n\nAny missing, malformed, or unqualified envelope keeps the normal full-surface\nplan. The fast path narrows bytes; it does not weaken channel controls.\n`package-published`, `alpha-complete`, `staging-visible`, and\n`production-visible` remain separate facts, and a package qualification never\nauthorizes production by itself.\n\nPublication manifests may retain release history without rematerializing every\nhistorical package into the current site artifact. When at least one version\ndeclares `immutableIndex`, Buildchain treats that field as the materialization\nenvelope: all declared version prefixes remain protected from deletion, while\nonly prefixes with `immutableIndex` must exist locally and are eligible for\nupload. Manifests without the envelope retain the legacy rule that every\ndeclared prefix must exist.\n\nFor multi-surface sites, each surface host is treated as a root-relative view\nof that surface's artifact path prefix. For example, a `buildchain` surface with\n`path = \"/buildchain/\"` and preview URL\n`https://buildchain-pr-29.preview.libkungfu.dev` syncs the artifact subtree\n`dist/buildchain/` to the preview object prefix `pr-29/buildchain`. A viewer\nrequest for `https://buildchain-pr-29.preview.libkungfu.dev/docs/` therefore\nresolves against the artifact's `dist/buildchain/docs/index.html`, not\n`dist/docs/index.html` and not the hub surface root. The deployment manifest\nrecords this as `routing.contract =\n\"kungfu-buildchain-web-surface-path-prefix-rewrite\"` with\n`viewerPathPrefix = \"/\"`, `artifactPathPrefix = \"buildchain\"`, and\n`directoryIndexResolution = true`.\n\nWhen a surface uses an S3 object prefix, directory-index routing must be handled\nat the viewer-request layer. By default, `directory_index_rewrite =\n\"buildchain\"` makes Buildchain install or update one CloudFront Function per\ndistribution before uploading payloads. The function rewrites any request path\nending in `/` to the corresponding `index.html`, so\n`https://buildchain-pr-29.preview.libkungfu.dev/` resolves to\n`pr-29/buildchain/index.html` and\n`https://buildchain-pr-29.preview.libkungfu.dev/docs/` resolves to\n`pr-29/buildchain/docs/index.html`. This keeps multi-host preview roots\ncompatible with S3 REST origins, where copying alias objects such as\n`pr-29/buildchain` or `pr-29/buildchain/` is not a reliable substitute for an\nedge rewrite.\n\nIf the distribution already has a viewer-request function that owns preview\nalias routing and surface-prefix routing, set `directory_index_rewrite =\n\"external\"` on the deploy channel or surface override. In that mode Buildchain\ndoes not create, update, or attach a generic directory-index function. Instead,\nthe deployment manifest records `directoryIndexRewrite = \"external\"` and\n`directoryIndexStrategy = \"external-viewer-request-function\"`, then the normal\nhealth check still verifies every required root and nested surface URL. This is\nthe correct contract for shared preview distributions such as\n`site-libkungfu-dev`, where a generic function cannot replace the existing\nprefix router.\n\nBuildchain still writes directory-index alias objects during apply as\ncompatibility evidence, but root correctness comes from the viewer-request\nrewrite contract, not from extensionless S3 keys. If Buildchain-managed mode\nfinds a distribution with a different viewer-request function, apply fails\nclosed and records that conflict in the apply result instead of silently serving\n403s. If CloudFront rejects `UpdateDistribution` because its optimistic-lock\nETag became stale, Buildchain re-reads the distribution and retries with the\nnew ETag at most twice. A concurrent update that already attached the intended\nfunction is accepted as converged; a different viewer-request function or any\nnon-ETag AWS error still fails immediately. The reusable workflow uploads\n`buildchain-web-surface-*-diagnostics`\nartifacts containing the apply and health JSON so the failing AWS operation or\nHTTP check is visible from the consumer run.\n\nIt can also execute a previously saved deploy plan. In that mode Buildchain\nrecomputes the local artifact hash before running AWS commands and fails closed\nif the artifact no longer matches the saved plan. Before any adapter operation,\nit also checks channel-aware JSON manifests in the artifact: top-level\n`canonicalHost` and declared `pages[].host` facts must belong to the plan's\nsurface hosts. A production plan therefore rejects staging/preview host facts\nbefore AWS apply:\n\n```bash\nnode scripts/web-surface.mjs \\\n  --mode deploy-apply \\\n  --cwd fixtures/web-surface-shaped \\\n  --plan .buildchain/web-surface-staging-plan.json \\\n  --dry-run false \\\n  --output .buildchain/web-surface-staging-apply.json\n```\n\nCleanup apply deletes preview content, deletes the preview manifest, and\ninvalidates CloudFront:\n\n```bash\nnode scripts/web-surface.mjs \\\n  --mode cleanup-apply \\\n  --cwd fixtures/web-surface-shaped \\\n  --event pull-request-closed \\\n  --pull-number 123 \\\n  --source-sha aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \\\n  --dry-run false \\\n  --output .buildchain/web-surface-cleanup-apply.json\n```\n\nCleanup apply can also execute a saved cleanup plan:\n\n```bash\nnode scripts/web-surface.mjs \\\n  --mode cleanup-apply \\\n  --cwd fixtures/web-surface-shaped \\\n  --plan .buildchain/web-surface-cleanup-plan.json \\\n  --dry-run false \\\n  --output .buildchain/web-surface-cleanup-apply.json\n```\n\nApply output records the channel, alias, source SHA, artifact hash, target\nbucket, object prefix, manifest key, all surface URLs, all surface bindings, CDN\ninvalidation paths, actor/run metadata, immutable preservation evidence, and\nevery adapter operation with\n`executed`, `exitCode`, `stdout`, and `stderr`. If an operation fails,\nBuildchain records the failed operation, stops subsequent adapter operations,\nand exits non-zero after writing the result JSON. Buildchain records secret\nreference names only; the runner must provide the AWS CLI and credentials\noutside Buildchain, typically through OIDC and the declared `secret_refs`.\n\n## Production Preflight And Health\n\nProduction promotion is not just `deploy-apply --channel production`. Before a\nlive production apply, the reusable workflow runs:\n\n```bash\nnode scripts/web-surface.mjs \\\n  --mode production-preflight \\\n  --cwd fixtures/web-surface-shaped \\\n  --plan .buildchain/web-surface-production-plan.json \\\n  --execute true \\\n  --output .buildchain/web-surface-production-preflight.json\n```\n\nThe production preflight checks that:\n\n- `channels.production` is canonical and indexable;\n- every surface has concrete production bucket and CloudFront targets;\n- every production surface URL is HTTPS;\n- the production AWS role can inspect the declared bucket and distribution;\n- CloudFront aliases cover every surface host, including product hosts such as\n  `kfd.libkungfu.dev`;\n- DNS resolves for every surface host.\n\nAfter preview, staging, and production apply, the workflow runs:\n\n```bash\nnode scripts/web-surface.mjs \\\n  --mode health-check \\\n  --cwd fixtures/web-surface-shaped \\\n  --result .buildchain/web-surface-production-apply.json \\\n  --output .buildchain/web-surface-production-health.json\n```\n\nWhen the apply result includes CloudFront invalidations from the\n`aws-s3-cloudfront` adapter, health check waits for those invalidations to reach\n`Completed` before fetching public smoke URLs. This avoids reporting stale\nCloudFront 403 responses as deployment failures immediately after a successful\nS3 sync and invalidation request.\n\nAfter the invalidation wait, HTTP smoke checks also retry transient 403, 404, and\n5xx responses before recording failure. This keeps the public health signal\nstrict while absorbing short CloudFront edge propagation windows that can remain\nvisible after the invalidation waiter returns. By default, Buildchain attempts\neach HTTP smoke URL 12 times with a 10 second interval. Consumers can override\nthat window with `BUILDCHAIN_WEB_SURFACE_HEALTH_HTTP_RETRY_ATTEMPTS` and\n`BUILDCHAIN_WEB_SURFACE_HEALTH_HTTP_RETRY_INTERVAL_MS` when they need a\nsite-specific health policy.\n\nThe health check fetches every surface root URL and any nested smoke URLs\nrecorded in each surface binding. Nested smoke URLs are derived from nested HTML\nartifact files under the surface path prefix, with directory index resolution\nsuch as `dist/buildchain/docs/index.html` becoming `/docs/` on the buildchain\npreview host. If a surface has no nested HTML route, Buildchain records only\nthe root smoke URL; absence of nested HTML is not a deployment failure. When a\nnested route is present, the check fails closed if a deploy reports success but\nthat child page returns 403 or another unexpected status. Surface root checks\nexpect the apply result to have installed the directory-index rewrite, so a\nmulti-host preview root such as `https://buildchain-pr-29.preview.libkungfu.dev/`\nmust resolve to the surface `index.html`, not the bare prefix directory.\nProduction additionally fails if a response is unreachable, returns an\nunexpected status, or still sends `x-robots-tag: noindex`. The health check also\nverifies that each surface binding recorded a deployment manifest pointer. The\nproduction release passport embeds the deploy plan, apply result, production\npreflight, and health check so a reviewer or agent can audit why the production\nsite changed and whether every declared host and every existing nested route was\nactually covered.\n\nPublic channels can opt into object-level health with\n`deploy.<channel>.health_strategy = \"s3-object\"` when the deployment contract is\nalready covered by S3 manifest/object writes and public edge convergence is not\nthe right CI gate. This is useful for preview distributions whose viewer-request\nrouting is owned by an external CloudFront Function. The channel remains public;\nonly the CI health evidence changes from HTTP fetches to S3 `head-object`\nchecks.\n\nChannels declared with `access_control = \"managed-network\"` use a different\nhealth strategy by default. Buildchain does not require a GitHub-hosted runner\nto fetch a URL that is intentionally reachable only from an approved network.\nInstead, after a live apply the health check uses the deploy role to run S3\n`head-object` checks for each surface manifest and the smoke target object, such\nas the surface `index.html` or a nested `docs/index.html`. The check records\n`healthStrategy = \"s3-object\"` and skips the public HTTP fetch. Dry-run and\nplan-only checks fall back to deployment evidence: each surface must have a\nmanifest key, bucket, object prefix, `sync-static-artifact`, and\n`write-deployment-manifest` evidence, recorded as\n`healthStrategy = \"deployment-evidence\"`. If the workflow is running on a runner\nthat is allowed to reach the managed network, set\n`BUILDCHAIN_WEB_SURFACE_HEALTH_ALLOWED_RUNNER=true` or pass\n`--allowed-managed-network-runner true` to keep the normal HTTP smoke checks.\nSet `BUILDCHAIN_WEB_SURFACE_HEALTH_S3_OBJECTS=false` or pass\n`--managed-network-s3-object-verification false` only when an external channel\npolicy owns managed-network object verification.\n\n## Cleanup Plans\n\nPreview cleanup is an auditable cleanup contract. It can run as a dry-run plan,\nan apply-mode plan, or the explicit `cleanup-apply` executor with preview-only\ncredentials:\n\n```bash\nnode scripts/web-surface.mjs \\\n  --mode cleanup-plan \\\n  --cwd fixtures/web-surface-shaped \\\n  --event pull-request-closed \\\n  --pull-number 123 \\\n  --aliases pr-123,sha-abcdef123456\n```\n\nThe plan and apply result keep mutable PR aliases and immutable SHA aliases\ndistinct so a caller can expire them with different retention windows. Closed-PR\ncleanup can derive `pr-N` from `--pull-number`, records the event, source SHA,\nactor, run id, preview bucket/prefix, manifest key, and adapter steps, and is an\nauditable no-op when no aliases are requested.\n\n## Reusable Workflow Shape\n\nBuildchain ships `.github/workflows/.web-surface.yml` for repositories that want\nthe standard PR review and promotion flow without copying bespoke glue:\n\n```yaml\njobs:\n  web-surface:\n    uses: kungfu-systems/buildchain/.github/workflows/.web-surface.yml@v3\n    with:\n      build-command: npm run build\n      verify-command: npm run check\n      artifact-path: dist\n```\n\nThe reusable workflow maps GitHub events to Buildchain web-surface semantics:\n\n| Event | Buildchain behavior |\n| --- | --- |\n| `pull_request` opened / synchronized / reopened | validate, build, verify, and plan `preview` for `pr-N` |\n| `pull_request` closed | plan apply-mode cleanup for the `pr-N` preview alias and manifest |\n| `pull_request` closed for a matching release PR | verify the release intent and exact workflow-shell runtime, then wait for the protected `main` push; do not plan or apply production from `refs/pull/*/merge` |\n| `push` to `main` | validate, build, verify, plan and apply `staging` from the merged `main` SHA, then optionally open a production release PR |\n| `push` to `main` from a matching release PR merge | validate the associated release PR, plan `production`, and enter the configured GitHub Environment gate from the protected mainline ref |\n| `workflow_dispatch` with `production-approved = true` | plan `production` and enter the configured GitHub Environment gate |\n\nThe optional `buildchain-ref` input is empty by default. Empty keeps the\nweb-surface run on the stable Buildchain runtime selected by the reusable\nworkflow ref, normally `@v3`. A trusted maintainer can expose a\n`workflow_dispatch` input and pass it through for one-off train validation.\nSee [`runtime-train-validation.md`](runtime-train-validation.md) for the shared\ntrain protocol and notification template:\n\n```yaml\non:\n  workflow_dispatch:\n    inputs:\n      buildchain-ref:\n        description: \"Temporary Buildchain runtime ref for trusted manual validation\"\n        required: false\n        default: \"\"\n\njobs:\n  web-surface:\n    uses: kungfu-systems/buildchain/.github/workflows/.web-surface.yml@v3\n    with:\n      buildchain-ref: ${{ inputs.buildchain-ref || '' }}\n      build-command: pnpm run build\n      verify-command: pnpm run check\n      artifact-path: dist\n```\n\nOnly trusted `workflow_dispatch` runs by repository actors with write,\nmaintain, or admin permission may use a non-empty runtime override. Train refs\nsuch as `train/v3/v3.0/site-source-of-truth` are temporary validation refs, not\nstable production dependencies or pending merge targets. They may remain for a\nretention window after release as a fast-use and rollback channel, with old\ntrains handled by periodic Buildchain cleanup. The web-surface deployment\nmanifest records the resolved runtime SHA as `runtimeId` and the stable\nrollback ref as `rollbackPointer`.\n\nThe workflow deliberately plans and emits manifests by default. Live mutation is\nopt-in per channel:\n\n```yaml\npermissions:\n  contents: read\n  id-token: write\n  pull-requests: write\n\njobs:\n  web-surface:\n    uses: kungfu-systems/buildchain/.github/workflows/.web-surface.yml@v3\n    with:\n      build-command: pnpm run build\n      verify-command: pnpm run check\n      artifact-path: dist\n      preview-apply: true\n      preview-cleanup-apply: true\n      preview-aws-role-arn: arn:aws:iam::123456789012:role/site-preview-github-actions\n      staging-apply: true\n      staging-aws-role-arn: arn:aws:iam::123456789012:role/site-staging-github-actions\n      production-apply: false\n      production-release-on-main: false\n      production-aws-role-arn: arn:aws:iam::123456789012:role/site-production-github-actions\n      production-environment: production\n      release-feedback-actor-privacy: public\n```\n\nWhen enabled, Buildchain owns the full release apply state machine:\n\n- PR preview deploys run `deploy-apply --dry-run false` with the preview role\n  and update a single idempotent PR comment.\n- Closed PR cleanup runs `cleanup-apply --dry-run false` with the preview role\n  only.\n- Pushes to `main` run staging `deploy-apply --dry-run false` with the staging\n  role, then write a staging release feedback passport artifact and comment the\n  associated merged PR with the staging URL, source SHA, artifact identity, run\n  URL, and failure context when apply did not complete.\n- When `production-release-on-main=true`, successful staging applies open or\n  update a Buildchain-owned release PR from\n  `release/<channel>-<short-sha>` to `main`, unless the current push already\n  came from a matching release PR merge. The release PR contains one empty\n  release-intent commit, carries `production-release-label`, and includes the\n  staging URLs, source SHA, artifact hash, and staging release-passport artifact\n  link in the PR body.\n- Production release PR handoff is permission-aware. Staging apply and staging\n  health remain successful even when the repository or organization has\n  GitHub Actions workflow permissions set to read-only. In that case Buildchain\n  records `release-pr-status=permission-denied`, uploads the release PR handoff\n  summary/body plus staging release passport artifacts, and writes an exact\n  manual `gh pr create` command to the step summary. Set\n  `fail-on-release-pr-error=true` only when PR creation failure should fail the\n  whole workflow.\n- Release pull requests that match the configured production gate get a\n  Buildchain review comment with the staging URL and production target, so the\n  operator can verify staging from the PR page and use merge as the approval\n  action. Consumers do not need to hand-write `gh pr create` or production\n  release-intent glue.\n- `production-apply=true` enables the production capability; it does not request\n  production for every event. Ordinary `main` pushes remain staging-only and\n  can create or update a release PR. Production runs only when the capability\n  is enabled and either:\n  - a `workflow_dispatch` passes `production-approved=true` and the triggering\n    actor currently has `write`, `maintain`, or `admin` permission; or\n  - `production-release-on-main=true` and the `main` push commit is associated\n    with exactly one same-repository, merged release pull request matching\n    `production-release-label` and `production-release-head-prefix`.\n  The production job is then gated by the configured GitHub Environment.\n- Before production artifact download, Buildchain assembles a managed sealed\n  publication capability from the exact source/runtime SHAs, production plan\n  and artifact hash, a qualifying pre-publication controller receipt, the\n  trusted manual or reviewed-release-PR decision, production Environment and\n  AWS role target, an ephemeral-runner receipt, and a fresh nonce. Production\n  revalidates that capability against the downloaded plan before it downloads\n  product bytes. The later AWS OIDC exchange remains the provider's final\n  transaction-time authorization decision and fails closed before deploy apply.\n- The `publication-*-json` inputs are an advanced external-evidence\n  compatibility path, not a prerequisite for the standard release-PR or trusted\n  manual mechanisms. External evidence must now include\n  `publication-gate-aggregate-json`; supplying only a partial set still fails\n  closed.\n- Production apply writes a production release feedback passport artifact and\n  comments the release PR with the production URL, source SHA, artifact\n  identity, run URL, rollback pointer, and failure context when apply did not\n  complete.\n\nThe feedback passport records the release responsibility chain:\n\n- human decision actor;\n- trigger actor;\n- runner/execution actor;\n- OIDC/deploy identity reference;\n- decision type and time;\n- source event, PR number, merge commit, and required gate label/head-prefix.\n\n`release-feedback-actor-privacy` controls actor values in the passport and\ncomments. `public` records GitHub actor names, `redacted` records only the actor\nrole, and `private-ref` records a stable private reference hash without exposing\nthe actor name.\n\nFor release-PR publishing, callers opt in explicitly:\n\n```yaml\njobs:\n  web-surface:\n    uses: kungfu-systems/buildchain/.github/workflows/.web-surface.yml@v3\n    with:\n      build-command: npm run build\n      verify-command: npm run check\n      artifact-path: dist\n      production-apply: true\n      production-release-on-main: true\n      production-release-label: buildchain-release\n      production-release-head-prefix: release/\n      production-release-branch-channel: production\n      production-release-pr-mode: auto\n      production-aws-role-arn: arn:aws:iam::123456789012:role/site-production-github-actions\n      production-environment: production\n```\n\nKeep `production-apply` enabled in the caller when the repository supports\nproduction. Buildchain derives whether the current event may use that\ncapability: an ordinary `main` push plans and applies staging, a matching\nreviewed release PR merge authorizes production, and an approved trusted manual\ndispatch authorizes production. Inputs from an untrusted event cannot turn that\ndecision on.\n\n`production-release-pr-mode` controls the post-staging handoff:\n\n| Mode | Behavior |\n| --- | --- |\n| `auto` | Generate release PR facts, create/update the empty release-intent branch and PR, and label it when token permissions allow. This is the default. |\n| `summary-only` | Generate and upload release PR facts, body, passport evidence, and manual command, but do not call the GitHub PR API. |\n| `disabled` | Record a disabled handoff and skip release PR API calls. |\n\nAutomatic release PR creation normally uses the workflow `github.token`.\nConsumers that cannot enable \"GitHub Actions can create and approve pull\nrequests\" globally should prefer the first-class GitHub App path. Pass the App\nclient id as an input and the private key as a reusable workflow secret; Buildchain\ncreates an installation token inside the release PR job and uses it only for the\nrelease-intent branch, PR, and label operations:\n\n```yaml\nwith:\n  production-release-app-client-id: ${{ vars.KUNGFU_RELEASE_APP_CLIENT_ID }}\nsecrets:\n  production-release-app-private-key: ${{ secrets.KUNGFU_RELEASE_APP_PRIVATE_KEY }}\n```\n\nWhen either side of the App configuration is missing, Buildchain does not hide\nthat behind the fallback `github.token`. The handoff JSON and job summary report\n`status: \"app-token-unavailable\"` with an `appTokenStatus` such as\n`missing-client-id`, `missing-private-key`, or `create-failed`, and still include\nthe manual PR creation command. If the repository intentionally uses another\nnarrow token, pass it through `production-release-pr-token`.\n\n`production-release-app-id` remains accepted as a deprecated alias for the input\nname, but the value should be the GitHub App client id. GitHub App numeric App\nIDs and client IDs are distinct, and Buildchain passes the value to\n`actions/create-github-app-token` through its non-deprecated `client-id` input so\nnew runs do not emit the deprecated `app-id` warning.\n\nIf a repository already generates its own narrow token or PAT, it can still pass\nthat through `production-release-pr-token`:\n\n```yaml\nwith:\n  production-release-pr-token: ${{ secrets.BUILDCHAIN_RELEASE_PR_TOKEN }}\n```\n\nToken priority is: generated GitHub App installation token,\n`production-release-pr-token`, then `github.token`.\n\nThe merge button becomes the production approval only for a PR that carries the\nrelease label and comes from the configured source-branch prefix. Ordinary pull\nrequests merged into `main` deploy staging and open a release-intent PR; merging\nthat release PR triggers production. A release PR merge push does not open\nanother release PR.\n\nApply-only inputs are validated before the caller build or verification command\nruns. If the current event would run preview, staging, or production apply,\nmissing role inputs, a production apply without `production-approved=true` on\nmanual dispatch, or a manual actor without repository write authority fail\nimmediately instead of spending the build and plan jobs first.\n\nCallers must grant `id-token: write` for OIDC role assumption. Preview comments\nneed `pull-requests: write`. Automatic release PR creation also needs\n`contents: write`, `pull-requests: write`, and `issues: write` so Buildchain can\ncreate the release branch, write the empty release-intent commit, open or update\nthe PR, and apply the release label. If these permissions are unavailable,\nBuildchain degrades the release handoff instead of marking a successful staging\ndeployment as failed, unless `fail-on-release-pr-error=true`. The AWS roles remain caller-owned and\nshould be scoped by channel: preview can mutate only preview resources, staging\ncan mutate only staging resources, and production can mutate only production\nresources.\n\nApply mode fails closed when the deploy config still contains placeholder AWS\ntargets such as `pending-preview-distribution`. Planning can use placeholders\nfor dry-run-only design work, but live apply requires concrete bucket and\nCloudFront distribution identifiers.\n\n## Site Repository Shape\n\nA site repository can start with:\n\n```toml\nschema = 1\n\n[project]\ntype = \"web-surface\"\nname = \"site-kungfu-tech\"\nsite = \"kungfu-tech\"\n\n[lifecycle.build]\ncommand = \"pnpm run build\"\n\n[lifecycle.verify]\ncommand = \"pnpm run check\"\n```\n\nThen add the channel, deploy, retention, and security declarations shown above.\nThe project may use pnpm, npm, yarn, Vite, Astro, Next static export, Sphinx,\nMkDocs, CMake-generated docs, or another lifecycle command source. Buildchain\nonly needs a deterministic artifact path and the manifest facts.\n\n## Signed bootstrap installer publications\n\nA web-surface artifact that contains `installer-publication.json` opts into the\n`kungfu.bootstrap-installer-publication/v1` seam. During planning, Buildchain\nfails closed unless the manifest binds:\n\n- one signed-channel payload root and exact channel-file digest;\n- one source SHA and Release Passport;\n- unique platform/architecture entries with manifest, artifact, and archive\n  digest roots; and\n- byte-identical friendly and immutable `install.sh` / `install.ps1` assets.\n\nThe resulting `kungfu-buildchain-installer-publication-evidence/v1` object and\nroot are welded into the deployment manifest. This does not make Buildchain the\nproduct installer authority: Kungfu generates the installer from its signed\nrelease channel, while the site owns only routes and presentation.\n\nThe site artifact should also declare the existing\n`kungfu-buildchain-publication-archive-policy` in its root `manifest.json`, with\nthe versioned installer directory as `immutablePath`. Buildchain then performs\npre-upload object digest checks, `--no-overwrite` upload, post-upload checks, and\nexcludes the immutable root from mutable deletion.\n\nLocal verification:\n\n```sh\nnode scripts/installer-publication.mjs \\\n  --manifest dist/installer-publication.json \\\n  --artifact-root dist\n```\n\nAfter preview, staging, or production apply, public read-back verifies exact\nbytes plus route semantics. Friendly routes require a revalidated cache policy\nwith `max-age` no greater than 300 seconds; immutable routes require at least\none year and the `immutable` directive:\n\n```sh\nnode scripts/installer-publication.mjs \\\n  --manifest dist/installer-publication.json \\\n  --public-readback\n```\n\nRedirects are not accepted as successful read-back. The evidence retains\ncontent type, cache control, ETag, object version id when exposed, size, digest,\nURL, channel root, source SHA, and Release Passport coordinates.\n\n## Boundaries\n\nBuildchain only performs live AWS mutations in explicit apply modes with\n`--dry-run false`. Production deploys must still be gated by a human-controlled\nworkflow, release, or GitHub Environment. DNS changes, staging auth\nimplementation, CloudFront distribution creation, and credential provisioning\nremain explicitly authorized infrastructure operations outside the web-surface\nartifact apply contract."
    },
    {
      "id": "fixture:infra-contract-aws-cdk-shaped",
      "title": "AWS CDK-shaped Infra Contract Fixture",
      "route": "/fixtures/infra-contract-aws-cdk-shaped",
      "category": "fixture",
      "capabilityGroup": "reusable-build",
      "audience": [
        "developer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "fixtures/infra-contract-aws-cdk-shaped/README.md",
      "digest": "sha256:87304783102305824523d0d2214a9072a38cc3f0904c23e7c38145804f1e596e",
      "headings": [
        {
          "level": 1,
          "title": "AWS CDK-shaped Infra Contract Fixture",
          "anchor": "aws-cdk-shaped-infra-contract-fixture"
        }
      ],
      "markdown": "# AWS CDK-shaped Infra Contract Fixture\n\nThis fixture proves the infra-contract model can represent AWS CDK synthesized\nassembly metadata and observed CloudFormation output shapes without deploying a\nstack.\n\nIt is static evidence only: no `cdk deploy` command is executed and no AWS\ncredentials are required."
    },
    {
      "id": "fixture:infra-contract-aws-cli-shaped",
      "title": "AWS CLI-shaped Infra Contract Fixture",
      "route": "/fixtures/infra-contract-aws-cli-shaped",
      "category": "fixture",
      "capabilityGroup": "reusable-build",
      "audience": [
        "developer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "fixtures/infra-contract-aws-cli-shaped/README.md",
      "digest": "sha256:78f4c30dc5ebf03bc591616d93a4adb5c7c913f5746bfb1cc8a404d4e73a538b",
      "headings": [
        {
          "level": 1,
          "title": "AWS CLI-shaped Infra Contract Fixture",
          "anchor": "aws-cli-shaped-infra-contract-fixture"
        }
      ],
      "markdown": "# AWS CLI-shaped Infra Contract Fixture\n\nThis fixture proves the infra-contract model can represent a generic AWS CLI\ndesired request and observed response shape without calling a live AWS service.\n\nIt is static evidence only: no AWS CLI command is executed and no AWS\ncredentials are required."
    },
    {
      "id": "fixture:infra-contract-cloudformation-shaped",
      "title": "CloudFormation-shaped Infra Contract Fixture",
      "route": "/fixtures/infra-contract-cloudformation-shaped",
      "category": "fixture",
      "capabilityGroup": "reusable-build",
      "audience": [
        "developer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "fixtures/infra-contract-cloudformation-shaped/README.md",
      "digest": "sha256:c25dc4d1651198bf3fa9ac0e32189ca59efba79952075d210dad7f8371023d74",
      "headings": [
        {
          "level": 1,
          "title": "CloudFormation-shaped Infra Contract Fixture",
          "anchor": "cloudformation-shaped-infra-contract-fixture"
        }
      ],
      "markdown": "# CloudFormation-shaped Infra Contract Fixture\n\nThis fixture proves the infra-contract model can represent CloudFormation\ndesired templates and observed stack outputs without making live AWS calls.\n\nIt is static evidence only: no change set is created, no stack is updated, and\nno AWS credentials are required."
    },
    {
      "id": "fixture:infra-contract-opentofu-shaped",
      "title": "OpenTofu-shaped Infra Contract Fixture",
      "route": "/fixtures/infra-contract-opentofu-shaped",
      "category": "fixture",
      "capabilityGroup": "reusable-build",
      "audience": [
        "developer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "fixtures/infra-contract-opentofu-shaped/README.md",
      "digest": "sha256:473e6960ef31e119539c7e6fe21fda157b29bbdcbfc9e90f4f2356c1432a86d0",
      "headings": [
        {
          "level": 1,
          "title": "OpenTofu-shaped Infra Contract Fixture",
          "anchor": "opentofu-shaped-infra-contract-fixture"
        }
      ],
      "markdown": "# OpenTofu-shaped Infra Contract Fixture\n\nThis fixture proves the infra-contract model can represent OpenTofu desired\nconfiguration and observed output shapes without reading OpenTofu state files.\n\nIt is static evidence only: no `tofu apply` command is executed and no provider\ncredentials are required."
    },
    {
      "id": "fixture:infra-contract-pulumi-shaped",
      "title": "Pulumi-shaped Infra Contract Fixture",
      "route": "/fixtures/infra-contract-pulumi-shaped",
      "category": "fixture",
      "capabilityGroup": "reusable-build",
      "audience": [
        "developer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "fixtures/infra-contract-pulumi-shaped/README.md",
      "digest": "sha256:9d0f29b5d4064c437baa5e6b7ca96e52ac0c8e64daa06a8e4cd3e4b69692f97e",
      "headings": [
        {
          "level": 1,
          "title": "Pulumi-shaped Infra Contract Fixture",
          "anchor": "pulumi-shaped-infra-contract-fixture"
        }
      ],
      "markdown": "# Pulumi-shaped Infra Contract Fixture\n\nThis fixture proves the infra-contract model can represent Pulumi preview and\nstack output shapes without reading Pulumi state or secrets files.\n\nIt is static evidence only: no `pulumi up` command is executed and no Pulumi\nsecrets material is committed."
    },
    {
      "id": "fixture:infra-contract-shaped",
      "title": "Infra Contract Shaped Fixture",
      "route": "/fixtures/infra-contract-shaped",
      "category": "fixture",
      "capabilityGroup": "reusable-build",
      "audience": [
        "developer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "fixtures/infra-contract-shaped/README.md",
      "digest": "sha256:c78c9fc097666d177f67be702d16a7b5f7bf2204759f1f29279cacc96dd12a8e",
      "headings": [
        {
          "level": 1,
          "title": "Infra Contract Shaped Fixture",
          "anchor": "infra-contract-shaped-fixture"
        }
      ],
      "markdown": "# Infra Contract Shaped Fixture\n\nThis fixture models an infrastructure repository that already has live resources\nand wants to publish observed output contracts before full IaC ownership exists.\n\nIt proves that `project.type = \"infra-contract\"` can validate desired files,\nread reviewed observed outputs, publish a deterministic contract artifact, and\nplan downstream consumer pull requests without mutating cloud infrastructure."
    },
    {
      "id": "fixture:infra-contract-terraform-shaped",
      "title": "Terraform-shaped Infra Contract Fixture",
      "route": "/fixtures/infra-contract-terraform-shaped",
      "category": "fixture",
      "capabilityGroup": "reusable-build",
      "audience": [
        "developer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "fixtures/infra-contract-terraform-shaped/README.md",
      "digest": "sha256:c32c5a512d742c0862c551e39dd757c8817535ea23e6846a82590134183886ce",
      "headings": [
        {
          "level": 1,
          "title": "Terraform-shaped Infra Contract Fixture",
          "anchor": "terraform-shaped-infra-contract-fixture"
        }
      ],
      "markdown": "# Terraform-shaped Infra Contract Fixture\n\nThis fixture proves the infra-contract model is not CloudFormation-specific.\nIt uses Terraform-shaped desired and output JSON fixtures as static evidence.\nNo Terraform state file is read and no provider command is executed."
    },
    {
      "id": "fixture:libnode-shaped",
      "title": "Libnode-shaped Fixture",
      "route": "/fixtures/libnode-shaped",
      "category": "fixture",
      "capabilityGroup": "reusable-build",
      "audience": [
        "developer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "fixtures/libnode-shaped/README.md",
      "digest": "sha256:d12514739c2caac789f0fadbd3f7999ce5cc06bdce52044bec2751d13c8e391b",
      "headings": [
        {
          "level": 1,
          "title": "Libnode-shaped Fixture",
          "anchor": "libnode-shaped-fixture"
        }
      ],
      "markdown": "# Libnode-shaped Fixture\n\nThis fixture models the Buildchain contract needed by `kungfu-systems/libnode`\nwithout running the real native build.\n\nIt is intentionally small, but it keeps the important shape:\n\n- `package.json` is the package version-state file;\n- `libnode.release.json` is the explicit upstream anchor manifest;\n- `buildchain.toml` declares `install`, `build`, `verify`, and `publish`\n  lifecycle stages;\n- `version.strategy = \"anchored\"` and `version.next = \"manual\"` tell\n  Buildchain to validate the current anchor instead of deriving the next Node\n  anchor automatically;\n- lifecycle commands are Node-based and cross-platform;\n- build output lands under `dist/`, which the reusable build workflow uploads\n  with a deterministic artifact name and manifest;\n- `.github/workflows/build.yml` exercises the public `build.yml@v3` channel\n  router with a caller job named `build`, including its stable top-level\n  `build / Summarize build contract` aggregate;\n- the fixture can be resolved through a publish-gate source lock, which binds\n  the requested consumer version to `package.json` and `libnode.release.json`\n  before any publish side effect is allowed;\n- `[publish]` declares the normal token-free path:\n  `mode = \"publish-final-version\"` with `auth = \"trusted-publishing\"`, `latest`\n  as the release dist-tag, and platform packages published before the main\n  package."
    },
    {
      "id": "fixture:publication-artifact-shaped",
      "title": "Publication Artifact Fixture",
      "route": "/fixtures/publication-artifact-shaped",
      "category": "fixture",
      "capabilityGroup": "reusable-build",
      "audience": [
        "developer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "fixtures/publication-artifact-shaped/README.md",
      "digest": "sha256:7a5c99ca68898f742782812babf84cf032bc97de81d05314880a3ac08b3c5bba",
      "headings": [
        {
          "level": 1,
          "title": "Publication Artifact Fixture",
          "anchor": "publication-artifact-fixture"
        }
      ],
      "markdown": "# Publication Artifact Fixture\n\nThis fixture models a paper repository that produces publication artifacts\nwithout becoming a web-surface repository.\n\nIt declares:\n\n- `project.type = \"publication-artifact\"`;\n- a primary PDF artifact;\n- source paths that Buildchain archives into a source bundle;\n- metadata paths that a future papers site can consume as a single fact source."
    },
    {
      "id": "fixture:publish-transaction-shaped",
      "title": "publish-transaction-shaped",
      "route": "/fixtures/publish-transaction-shaped",
      "category": "fixture",
      "capabilityGroup": "reusable-build",
      "audience": [
        "developer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "fixtures/publish-transaction-shaped/README.md",
      "digest": "sha256:e6114ec1f74727c7a14123f5680d6bebfba1866b80d0c9737f381c7037cfac09",
      "headings": [
        {
          "level": 1,
          "title": "publish-transaction-shaped",
          "anchor": "publish-transaction-shaped"
        }
      ],
      "markdown": "# publish-transaction-shaped\n\nFixture for the Buildchain publish transaction contract.\n\nIt represents a release unit with three required artifact families:\n\n- npm package metadata;\n- OCI image digest;\n- binary archive digest.\n\nThe fixture does not publish to external services. `lifecycle.publish` writes\ngeneric Buildchain evidence to `BUILDCHAIN_PUBLISH_EVIDENCE`, which is enough for\ntests and for consumers to understand the expected shape.\n\n```bash\nBUILDCHAIN_VERSION=1.0.0 \\\nBUILDCHAIN_CHANNEL=release \\\nBUILDCHAIN_SOURCE_SHA=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa \\\nBUILDCHAIN_RELEASE_SHA=bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb \\\nBUILDCHAIN_RELEASE_MATERIAL_SHA=bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb \\\nBUILDCHAIN_PUBLISH_TOOLING_SHA=cccccccccccccccccccccccccccccccccccccccc \\\nBUILDCHAIN_TARGET_REF=release/v1/v1.0 \\\nBUILDCHAIN_EVIDENCE_DIR=.buildchain/release-evidence/v1.0.0 \\\nBUILDCHAIN_PUBLISH_EVIDENCE=.buildchain/release-evidence/v1.0.0/evidence.json \\\nnode scripts/publish.mjs\n```"
    },
    {
      "id": "fixture:release-propagation-shaped",
      "title": "Release Propagation Fixture",
      "route": "/fixtures/release-propagation-shaped",
      "category": "fixture",
      "capabilityGroup": "reusable-build",
      "audience": [
        "developer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "fixtures/release-propagation-shaped/README.md",
      "digest": "sha256:6134eee39673dd29e019f941c241ddf8a9aba68f2e06dca9367d3fd304385cfa",
      "headings": [
        {
          "level": 1,
          "title": "Release Propagation Fixture",
          "anchor": "release-propagation-fixture"
        }
      ],
      "markdown": "# Release Propagation Fixture\n\nThis fixture demonstrates a generic release propagation graph with a\n`kfd -> site-libkungfu-dev` shaped edge. It is safe test data only; tests use it\nto prove that Buildchain preserves alpha/release channels and writes an exact\nupstream release lock."
    },
    {
      "id": "fixture:web-surface-shaped",
      "title": "Web Surface Shaped Fixture",
      "route": "/fixtures/web-surface-shaped",
      "category": "fixture",
      "capabilityGroup": "reusable-build",
      "audience": [
        "developer",
        "agent"
      ],
      "maturity": "stable",
      "sourcePath": "fixtures/web-surface-shaped/README.md",
      "digest": "sha256:87b8f216f1b112cd17e4acbefaea5b024e5d374c8d682f324b0b0d5f4df606c5",
      "headings": [
        {
          "level": 1,
          "title": "Web Surface Shaped Fixture",
          "anchor": "web-surface-shaped-fixture"
        }
      ],
      "markdown": "# Web Surface Shaped Fixture\n\nThis fixture models a static site repository that wants Buildchain deployment\nsemantics without opting into package release lines.\n\nIt proves that `project.type = \"web-surface\"` can declare preview, staging, and\nproduction channels, named surface host mappings, deterministic deployment\nmanifests, and dry-run deploy and cleanup plans without touching AWS.\n\nThe fixture is shaped like a `site-libkungfu-dev` repository with four\nfirst-class surfaces:\n\n```text\nhub        https://libkungfu.dev\ncore       https://core.libkungfu.dev\nbuildchain https://buildchain.libkungfu.dev\nkfd        https://kfd.libkungfu.dev\n```\n\nFor preview and staging, Buildchain resolves the same surface names to the\nchannel-specific hosts and records them in `surfaceBindings`. Path-only pages\ncan still be declared with `path_only = true`, but this fixture intentionally\nuses first-class hosts for every surface so validation can catch missing\nchannel mappings."
    }
  ],
  "pageRegistry": {
    "path": "page-registry.json",
    "contract": "kungfu-buildchain-site-page-registry",
    "pageCount": 75,
    "categories": [
      "action",
      "api",
      "fixture",
      "manual",
      "overview"
    ]
  },
  "homepage": {
    "title": "Buildchain",
    "lead": "<!-- buildchain-auditable-demo:start -->",
    "mechanismSummary": [],
    "sections": [
      {
        "id": "install-and-verify",
        "sourcePath": "README.md",
        "sourceHeading": "Install and Verify",
        "title": "Install and Verify",
        "renderRole": "primary",
        "homepagePriority": 10,
        "defaultPresentation": "release-passport-install",
        "includeInFirstScreen": true,
        "markdown": "New repository adopters should follow the [15–30 minute Golden Path](docs/getting-started.md).\nThe commands below are the shorter verification-only route for an existing\nconsumer.\n\nFor v4, use the published npm package and verify the release passport before\ntrusting release evidence:\n\n```bash\ncurl -LO https://github.com/kungfu-systems/buildchain/releases/download/v4.0.0/buildchain.release.json\ncurl -LO https://github.com/kungfu-systems/buildchain/releases/download/v4.0.0/artifact-evidence.json\nnpx @kungfu-tech/buildchain@4.0.0 verify release-passport buildchain.release.json\nnpx @kungfu-tech/buildchain@4.0.0 version\n```\n\nThe v4.0.0 release publishes evidence assets and platform archives through the\nsame protected promotion transaction.\nThe names below describe the optional archive contract used by legacy release\nlines:\n\n- `buildchain-x86_64-unknown-linux-gnu.tar.gz`\n- `buildchain-aarch64-apple-darwin.tar.gz`\n- `buildchain-x86_64-pc-windows-msvc.zip`\n- `checksums.txt`\n- `buildchain.release.json`\n- `artifact-evidence.json`\n- `product-mechanism.json`\n- `impact.json`\n- `agent-index.json`\n- `check-report.json`\n- `llms.txt`\n- `buildchain-release-bundle.tar.gz`\n- `buildchain-release-bundle.json`\n\nLoose top-level `buildchain` and `buildchain.exe` assets are intentionally not\npublished. The executable lives inside each platform archive, which prevents\nLinux and macOS artifacts from overwriting each other in a merged release lane.\n\nFor npm consumers:\n\n```bash\nnpm install -D @kungfu-tech/buildchain\nnpx buildchain version\nnpx buildchain doctor --json\n```\n\nThe npm package is also the Buildchain toolkit. Use the command when a workflow\nor shell step needs an executable; use the ESM APIs directly from JavaScript\nbuild scripts. JavaScript callers should import the package instead of spawning\nthe CLI or unpacking the standalone binary:\n\n```js\nimport {\n  createBuildchainLogger,\n  verifyBuildchainLogEvents,\n} from \"@kungfu-tech/buildchain/logging\";\n\nconst logger = createBuildchainLogger({\n  path: \".buildchain/logs/native-build.jsonl\",\n  source: \"user\",\n  component: \"native-build\",\n});\n\nawait logger.span(\"native.compile\", { phase: \"build\" }, async () => {\n  await compileNativeTargets();\n});\n\nconst report = verifyBuildchainLogEvents({\n  path: logger.path,\n  requireEvents: [\"native.compile.start\", \"native.compile.end\"],\n});\n```\n\nThe package also ships `dist/site/` as the Buildchain-owned fact source for\n`buildchain.libkungfu.dev`.\n\nRepositories can also generate README status badges from Buildchain-owned facts\ninstead of hand-maintaining badge Markdown:\n\n```bash\nbuildchain badges bundle --check\nbuildchain badges bundle --write\nbuildchain badges readme --check\nbuildchain badges readme --write\n```"
      },
      {
        "id": "use-buildchain",
        "sourcePath": "README.md",
        "sourceHeading": "Use Buildchain",
        "title": "Use Buildchain",
        "renderRole": "primary",
        "homepagePriority": 20,
        "defaultPresentation": "workflow-surface-list",
        "includeInFirstScreen": true,
        "markdown": "Bootstrap a repository:\n\n```bash\nnpx @kungfu-tech/buildchain init --type package --package-manager pnpm\nnpx @kungfu-tech/buildchain validate --require-version-state\nnpx @kungfu-tech/buildchain release --dry-run --target-ref alpha/v4/v4.0\n```\n\nBootstrap and inspect a governed paper repository through one interface:\n\n```bash\nnpx @kungfu-tech/buildchain paper scaffold \\\n  --package @kungfu-tech/paper-example \\\n  --repository kungfu-systems/paper-example\npnpm add -D @kungfu-tech/buildchain@<exact-v4-version>\npnpm exec buildchain paper work start <topic>\npnpm exec buildchain paper work submit\npnpm exec buildchain paper preflight --offline\npnpm exec buildchain paper status\n```\n\nThe paper surface is dry-run first. Add `--write` only to create missing\nscaffold files. `work start` and `work submit` validate the canonical remote,\nexact development SHA, clean source, safe branch, and fast-forward boundary\nbefore changing local or GitHub state. External mutations such as npm\nbootstrap, Alpha PR creation, and release resumption require `--execute`. See\n[`docs/publication-artifacts.md`](docs/publication-artifacts.md) for the\nevidence-state model and operator flow.\n\nBuildchain supports package and non-package projects through\n`.buildchain/buildchain.toml`. Legacy root `buildchain.toml` files remain\nreadable, but new consumers should keep Buildchain-owned files under\n`.buildchain/`:\n\n```text\n.buildchain/buildchain.toml\n.buildchain/contract-lock.json\n.buildchain/kfd/kfd-3/surfaces.json\n.buildchain/release-passport/buildchain.release.json\n```\n\nLifecycle commands can call pnpm, npm, yarn, pip, Conan, CMake, Make, custom\nscripts, or any other command that can run in the repository checkout.\n\nThe KFD entrypoint is `buildchain kfd`. Buildchain provides concrete KFD-1\ncontract-world, KFD-2 trust-claim, and KFD-3 collaboration-surface workflows,\nplus fail-closed product-evidence gates for KFD-4, KFD-5, and KFD-7. These\ngates preserve product-owned qualification and support decisions; they do not\nturn a schema-valid record into certification or shipped support.\n\nBuildchain's action registry currently contains seven active entries. Five are\ndirect consumer integration actions:\n\n- `actions/validate-config`\n- `actions/run-lifecycle`\n- `actions/promote-buildchain-ref`\n- `actions/report-buildchain-issue`\n- `actions/release-tail`\n\nTwo additional release-authority components are also registered and versioned:\n\n- `actions/github-artifact-attestation`\n- `actions/macos-credential-island`\n\n`dist/site/workflow-registry.json#actions` is the machine-readable inventory;\nthis split keeps the older four-action consumer snapshot from being mistaken for\nthe complete current registry.\n\nThe active reusable workflow surfaces are:\n\n- `.github/workflows/.gate-profile.yml` for project-neutral Shifu Gate profile\n  planning, capability-aware runner dispatch, receipt validation, and one\n  stable aggregate check;\n- `.github/workflows/.auditable-demo.yml` for exact-artifact demo\n  qualification, transcript-bound renderer smoke, optional media rendering\n  from the exact passing Gate bundle, and opt-in content-addressed web-delivery\n  profiles with independently verified rendition roles;\n- `.github/workflows/.declarative-auditable-demo.yml` for standalone binary\n  consumers that provide only a versioned multi-demo argv scenario and exact\n  same-run binary artifact coordinates; Buildchain owns isolated native\n  capture, Gate, Release Passport, materialization, and protected README PRs;\n- `.github/workflows/.build.yml` for deterministic multi-platform build and\n  artifact contracts;\n- `.github/workflows/build.yml` for the single-config channel router that uses\n  `vN-alpha` during development/prerelease work and `vN` for stable releases;\n- `.github/workflows/release-candidate-promote.yml` for post-merge\n  promote-only publication from a PR-stage release candidate, without a second\n  heavy build;\n- `.github/workflows/.web-surface.yml` for preview, staging, production, and\n  cleanup plans for site/app repositories;\n- `.github/workflows/buildchain-ref-promotion.yml` for protected release\n  promotion and version-state transactions;\n- `.github/workflows/binary-distribution.yml` for Buildchain's own release\n  passport proof case.\n\nStable consumers should reference actions and workflows through floating major\nrefs after reviewing the exact release passport:\n\n```yaml\nuses: kungfu-systems/buildchain/actions/validate-config@v4\n```\n\n```yaml\nuses: kungfu-systems/buildchain/.github/workflows/build.yml@v4\n```\n\n```yaml\nuses: kungfu-systems/buildchain/.github/workflows/release-candidate-promote.yml@v4\n```"
      },
      {
        "id": "release-model",
        "sourcePath": "README.md",
        "sourceHeading": "Release Model",
        "title": "Release Model",
        "renderRole": "primary",
        "homepagePriority": 30,
        "defaultPresentation": "release-model-table",
        "includeInFirstScreen": false,
        "markdown": "Buildchain treats a reviewed branch merge as release intent:\n\n| Merge path                              | Meaning                                                | Exact tag        | Floating refs                                        |\n| --------------------------------------- | ------------------------------------------------------ | ---------------- | ---------------------------------------------------- |\n| `dev/vX/vX.Y -> alpha/vX/vX.Y`          | publish the next testable alpha for a minor line       | `vX.Y.Z-alpha.N` | `vX.Y-alpha`, `alpha/vX/vX.Y`, `dev/vX/vX.Y`         |\n| `alpha/vX/vX.Y -> release/vX/vX.Y`      | publish production for that minor line                 | `vX.Y.Z`         | `vX.Y`, usually `vX`, `release/vX/vX.Y`              |\n| `release/vX/vX.Y -> publish-gate/major` | publish the next major from a reviewed production line | `v(X+1).0.0`     | `v(X+1)`, `v(X+1).0`, new dev/alpha/release branches |\n\nExact tags are immutable. Floating channel tags and branches are machine-updated\nby Buildchain and must remain writable by the release authority.\n\nAfter a production release, Buildchain prepares the next alpha source commit for\nthe same minor line. That keeps production consumers pinned to the production\npassport while development can continue on the next testable patch.\n\n`publish-gate/major` is not an active development trunk. It is a reviewed\npromotion gate used when maintainers decide that the next production release\nshould open a new major line."
      },
      {
        "id": "toolkit-observability",
        "sourcePath": "README.md",
        "sourceHeading": "Toolkit Observability",
        "title": "Toolkit Observability",
        "renderRole": "support",
        "homepagePriority": 40,
        "defaultPresentation": "toolkit-example",
        "includeInFirstScreen": false,
        "markdown": "Buildchain includes a logging toolkit for release and build steps. Inside\nJavaScript build code, prefer the package API:\n\n```js\nimport { createBuildchainLogger } from \"@kungfu-tech/buildchain/logging\";\n\nconst logger = createBuildchainLogger({ source: \"user\", component: \"conan\" });\nlogger.mark(\"conan.profile.ready\", { phase: \"configure\" });\nawait logger.span(\"conan.install\", { phase: \"dependencies\" }, runConanInstall);\n```\n\nIn workflows or shell scripts, use the equivalent CLI:\n\n```bash\nbuildchain mark --event native.configure --phase configure --component cmake\nbuildchain span --event native.build --phase build -- cmake --build build\nbuildchain log summary --json\nbuildchain verify observability-log .buildchain/logs/events.jsonl --min-events 4\n```\n\nEvery event records a timestamp. `span` records duration. The API form can be\nimported from repository scripts so heavy builds can mark phases from inside\ntheir own code."
      },
      {
        "id": "site-fact-source",
        "sourcePath": "README.md",
        "sourceHeading": "Site Fact Source",
        "title": "Site Fact Source",
        "renderRole": "support",
        "homepagePriority": 50,
        "defaultPresentation": "site-fact-source",
        "includeInFirstScreen": false,
        "markdown": "`@kungfu-tech/buildchain` publishes `dist/site/`:\n\n- `buildchain-site.json`\n- `site-manifest.json`\n- `page-registry.json`\n- `cli-registry.json`\n- `workflow-registry.json`\n- `release-model.json`\n- `artifact-schemas.json`\n- `product-mechanism.json`\n- `release-provenance.json`\n- `agent-index.json`\n\n`buildchain.libkungfu.dev` should render from these package-owned facts, then\nlayer presentation around them. The site should not hand-write Buildchain's\ncurrent release mechanics. `page-registry.json` is the complete markdown page\nsource for the public site: README homepage content, all packaged `docs/*.md`\nmanuals, action READMEs, the Node API package overview, and fixture guides."
      }
    ],
    "displayPlan": {
      "firstScreen": {
        "include": [
          "title",
          "lead",
          "install-and-verify",
          "use-buildchain"
        ],
        "maxPrimarySections": 2,
        "note": "The first viewport should establish Buildchain identity, release-passport trust, and the primary reusable workflow entrypoint without rendering implementation notes."
      },
      "primary": [
        "install-and-verify",
        "use-buildchain",
        "release-model"
      ],
      "support": [
        "toolkit-observability",
        "site-fact-source"
      ],
      "rendererContract": [
        "homepage-content-contract"
      ]
    },
    "rendererContract": {
      "id": "homepage-content-contract",
      "sourcePath": "README.md",
      "sourceHeading": "Homepage Content Contract",
      "title": "Homepage Content Contract",
      "renderRole": "renderer-contract",
      "homepagePriority": 90,
      "defaultPresentation": "developer-note",
      "includeInFirstScreen": false,
      "markdown": "This README is also the homepage text source for `buildchain.libkungfu.dev`.\nWhen a site repository consumes the `@kungfu-tech/buildchain` npm package, it\nshould use the generated `dist/site/buildchain-site.json` homepage fields\ninstead of parsing this README or maintaining separate homepage copy.\n\nThe first screen should be derived from:\n\n- Page identity: the top-level heading.\n- Lead: the opening paragraph that defines Buildchain Release Passport.\n- Trust signal: the start of `Install and Verify`, especially passport-first\n  binary verification.\n- Use signal: the start of `Use Buildchain`, especially the reusable workflow\n  and action surfaces.\n\nThe package-owned site bundle exposes ordered `homepage.sections`,\n`homepage.displayPlan`, `homepage.rendererContract`, and a complete\n`pages` collection mirrored from `page-registry.json`. A site renderer may adapt\nlayout, navigation, typography, examples, and visual assets, but it should not\nmaintain separate wording for Buildchain's release mechanics, workflow surface,\noperation manuals, Node API overview, fixture guides, or release-passport trust\nmodel. Renderer-contract text is machine/implementation metadata, not ordinary\nhomepage content.",
      "renderAsHomepageContent": false,
      "note": "This is a machine/renderer contract for site implementers. It should not be rendered as ordinary homepage content."
    }
  },
  "docs": [
    {
      "id": "map",
      "title": "Buildchain documentation map",
      "path": "docs/MAP.md",
      "plane": "use",
      "exists": true,
      "digest": "sha256:94a4866f5a44f97ab10ad460c4d9ff39c58aa28e231311425af2fcb857aa8c72"
    },
    {
      "id": "getting-started",
      "title": "Golden Path",
      "path": "docs/getting-started.md",
      "plane": "use",
      "exists": true,
      "digest": "sha256:72adec660d001a3fb77cd990f2bacdb6f46c8eb4927533d408c3755dab02a94e"
    },
    {
      "id": "auditable-demo",
      "title": "Auditable demo artifact pipeline",
      "path": "docs/auditable-demo.md",
      "plane": "verify",
      "exists": true,
      "digest": "sha256:c49e734fdfe3b74d317e23a523e198f1194b2c7cd16cca87e8e3a3ffc7bf589f"
    },
    {
      "id": "install",
      "title": "Install and verify Buildchain",
      "path": "docs/install.md",
      "plane": "use",
      "exists": true,
      "digest": "sha256:c04ba24a8bed696c02f68af4dd05bd2363fa06b85c54d49a4316efb36b7cf865"
    },
    {
      "id": "release-passport",
      "title": "Release Passport protocol",
      "path": "docs/release-passport.md",
      "plane": "verify",
      "exists": true,
      "digest": "sha256:4ce3c2edb095d7a103b3b1d22033b4ac3709ce709f8990b21995d491898bd051"
    },
    {
      "id": "github-artifact-attestation",
      "title": "GitHub-native Linux artifact attestation",
      "path": "docs/github-artifact-attestation.md",
      "plane": "verify",
      "exists": true,
      "digest": "sha256:51f28b0b01fae4e3f80a7433f6c491d0c795bd091bff64ca1264c5cc0819c545"
    },
    {
      "id": "controller-evidence",
      "title": "Controller evidence contract",
      "path": "docs/controller-evidence.md",
      "plane": "verify",
      "exists": true,
      "digest": "sha256:442e1b72e3977af56a8ae5e081ffd89c2f3ebcd9cfd50f07af730344bdf9fb0e"
    },
    {
      "id": "publication-authority",
      "title": "Sealed publication authority",
      "path": "docs/publication-authority.md",
      "plane": "verify",
      "exists": true,
      "digest": "sha256:a1650158943d95b979d164ca98a73d7919fda577d648e4a4a9d04588ec698796"
    },
    {
      "id": "github-governance-authority",
      "title": "GitHub governance authority",
      "path": "docs/github-governance-authority.md",
      "plane": "verify",
      "exists": true,
      "digest": "sha256:197ae7a949817f60f46b67b060731df14d0343d9daecd7d6eacfae9a526b6a12"
    },
    {
      "id": "release-candidate",
      "title": "Release Candidate Passport",
      "path": "docs/release-candidate.md",
      "plane": "verify",
      "exists": true,
      "digest": "sha256:d76bbd75aab3c4dd94756c1c64562a125e74369c7c8b97342dbcacc5d7561602"
    },
    {
      "id": "release-train",
      "title": "Release Train and Release Cut",
      "path": "docs/release-train.md",
      "plane": "verify",
      "exists": true,
      "digest": "sha256:6989ada03d381e68fdec55b26b76b2070fb37969826eadc0a989844a732ba557"
    },
    {
      "id": "release-propagation",
      "title": "Release propagation",
      "path": "docs/release-propagation.md",
      "plane": "use",
      "exists": true,
      "digest": "sha256:6e8417ff70db290ee6197f064ed9b7a7da3770738509fac06161dad05b3fca7f"
    },
    {
      "id": "readme-badges",
      "title": "README badge blocks",
      "path": "docs/readme-badges.md",
      "plane": "use",
      "exists": true,
      "digest": "sha256:d032ddd27db62bdb21031cbd0673d9ae61af0250c12522fe6106e7aff835fb21"
    },
    {
      "id": "homebrew",
      "title": "Homebrew distribution indexes",
      "path": "docs/homebrew.md",
      "plane": "use",
      "exists": true,
      "digest": "sha256:e690ea465d4289f2246d93765776b057c6aca1c68dc290abcee94c947e5d5c47"
    },
    {
      "id": "binary-distribution",
      "title": "Binary distribution contract",
      "path": "docs/binary-distribution.md",
      "plane": "verify",
      "exists": true,
      "digest": "sha256:b1611dcf0e6825e53921e4c9d31d1afe16fca81e6868360bfad1902587cd52ef"
    },
    {
      "id": "consumer-issue-reporting",
      "title": "Consumer issue reporting",
      "path": "docs/consumer-issue-reporting.md",
      "plane": "use",
      "exists": true,
      "digest": "sha256:324342b10e69ca5ce6d04a267fb5fc2a6b52e674f6252eec2121557c5542f729"
    },
    {
      "id": "infra-contract",
      "title": "Infra Contract",
      "path": "docs/infra-contract.md",
      "plane": "use",
      "exists": true,
      "digest": "sha256:7826e8c70ac2d90ddd8d4e38bcdd1bcfa36eef5106431d7ad94b2fe9c8d3d5dc"
    },
    {
      "id": "toolkit-observability",
      "title": "Toolkit observability",
      "path": "docs/toolkit-observability.md",
      "plane": "use",
      "exists": true,
      "digest": "sha256:1a08331cdca2b48e622ecbb799a7465a59cc4a779dd73d36f559f9bc1b98578c"
    },
    {
      "id": "site-bundle-contract",
      "title": "Site bundle contract",
      "path": "docs/site-bundle-contract.md",
      "plane": "use",
      "exists": true,
      "digest": "sha256:36a4e60e91f500ea1dcdbef97cd0250a2c26562b98d8d3622e8e0f9df2aad23b"
    },
    {
      "id": "migration-inventory",
      "title": "Migration inventory",
      "path": "docs/migration-inventory.md",
      "plane": "verify",
      "exists": true,
      "digest": "sha256:25d896711f4efebffa9a8960b7eb97438d9fd4892aa08bef0339026e83a53bdf"
    },
    {
      "id": "ownership",
      "title": "Ownership",
      "path": "docs/ownership.md",
      "plane": "why",
      "exists": true,
      "digest": "sha256:91a1b59f0f71067c58ffd685a23b29e14a4d6fe33c1a44f8708b7d0512e4baa5"
    },
    {
      "id": "product-mechanism",
      "title": "Product mechanism",
      "path": "docs/product-mechanism.md",
      "plane": "why",
      "exists": true,
      "digest": "sha256:da50022f96f8876bb275a7832190cb1f6ab0fa6aab9d045dda924a7abddc3edf"
    },
    {
      "id": "cli",
      "title": "CLI and npm package",
      "path": "docs/cli.md",
      "plane": "use",
      "exists": true,
      "digest": "sha256:fad47682ed909f7b16f58bb8c24c51a943eb704a0a50ab6e033d745ee16a809a"
    },
    {
      "id": "cli-reference",
      "title": "Generated CLI reference",
      "path": "docs/cli-reference.md",
      "plane": "use",
      "exists": true,
      "digest": "sha256:0aa0c937ca4f3f239f67c10a3e656ca0934cd3618bf84639525ea1fbd685c055"
    },
    {
      "id": "node-api-reference",
      "title": "Generated Node API reference",
      "path": "docs/node-api-reference.md",
      "plane": "use",
      "exists": true,
      "digest": "sha256:f8200ba1fbe5779408b4a1e82a0e28a5e8f696b05f97efd2d286d3008755fdbb"
    },
    {
      "id": "build-facts",
      "title": "Build Facts",
      "path": "docs/build-facts.md",
      "plane": "use",
      "exists": true,
      "digest": "sha256:75dcf7a6628dac9e982a455de9966044ae771611d4efc04e7264a2d4adb0bd3e"
    },
    {
      "id": "kfd-support",
      "title": "KFD support and KFD-3 surface registration",
      "path": "docs/kfd-support.md",
      "plane": "verify",
      "exists": true,
      "digest": "sha256:4efc8fb6f94293b75606aa0631dfa122edccc970c2cfc00c7e35f81817ea8335"
    },
    {
      "id": "kfd-agent-hub",
      "title": "KFD Agent Hub Builder flow",
      "path": "docs/kfd-agent-hub.md",
      "plane": "use",
      "exists": true,
      "digest": "sha256:9bfba0a872590bb1b4f260ddbe71b54572ef291f3fc11d32bcd04e79f5e740ff"
    },
    {
      "id": "lifecycle-protocol",
      "title": "Lifecycle protocol",
      "path": "docs/lifecycle-protocol.md",
      "plane": "use",
      "exists": true,
      "digest": "sha256:4b7a8efe1d22751ded069f46a23490db70cda9e9e14641acab600ab781245b19"
    },
    {
      "id": "reusable-build-surface",
      "title": "Reusable build surface",
      "path": "docs/reusable-build-surface.md",
      "plane": "use",
      "exists": true,
      "digest": "sha256:54cadd6e2f168ca40d9ed66d2f9848d5d56c9d05759bf0454f5027b1df274796"
    },
    {
      "id": "publish-transaction",
      "title": "Publish transaction",
      "path": "docs/publish-transaction.md",
      "plane": "verify",
      "exists": true,
      "digest": "sha256:72466943bb459f6857f23ac6f92bcf4714dcd2f535c38a9f0e34864b36404e06"
    },
    {
      "id": "release-tail-contract",
      "title": "Declarative release-tail contract",
      "path": "docs/release-tail-contract.md",
      "plane": "verify",
      "exists": true,
      "digest": "sha256:db5d38df0af0f7ce76ff93cc78a0d96a0738a40f6f40f7c1a0cfd78ca9f4f22a"
    },
    {
      "id": "release-tail-provider-plane",
      "title": "Declarative release-tail provider plane",
      "path": "docs/release-tail-provider-plane.md",
      "plane": "use",
      "exists": true,
      "digest": "sha256:80b39ba4f0a8ed723e2a03e7efff0fee1e891245f7d1bf343edc75011aded801"
    },
    {
      "id": "release-governance",
      "title": "Release governance",
      "path": "docs/release-governance.md",
      "plane": "why",
      "exists": true,
      "digest": "sha256:6dfe8a9b974040fc1465b0da696519b4e97b0b901e30d852ffacda0d193810af"
    },
    {
      "id": "release-flow",
      "title": "Release flow",
      "path": "docs/release-flow.md",
      "plane": "verify",
      "exists": true,
      "digest": "sha256:f2086d06a64f9321d7c1d62f93b37a169f781ba5bed4b714b5a8cb6509953c6e"
    },
    {
      "id": "runtime-train-validation",
      "title": "Runtime train validation",
      "path": "docs/runtime-train-validation.md",
      "plane": "verify",
      "exists": true,
      "digest": "sha256:f0a1cdb7fe5f72fc2ed921f1aeadbd16184dda16be3727e4193fa2af250325db"
    },
    {
      "id": "versioning",
      "title": "Versioning",
      "path": "docs/versioning.md",
      "plane": "why",
      "exists": true,
      "digest": "sha256:7f6e377abf976e9eb9c5f0fd2baec96922ca44d9ab7dd08178608657fa858978"
    },
    {
      "id": "web-surface-deployments",
      "title": "Web surface deployments",
      "path": "docs/web-surface-deployments.md",
      "plane": "use",
      "exists": true,
      "digest": "sha256:484e896746d2f4cca4f9f18d29c14784ec20143c12affc3dbb9ccfbf8f221b55"
    }
  ],
  "releaseModel": {
    "schemaVersion": 1,
    "contract": "kungfu-buildchain-release-model",
    "exactTags": "v-prefixed exact tags are immutable release records.",
    "floatingTags": "vX, vX-alpha, vX.Y, and vX.Y-alpha are channel pointers updated by Buildchain transactions; vX-alpha follows the highest minor in major X with a published alpha.",
    "channelBranches": [
      "dev/vX/vX.Y",
      "alpha/vX/vX.Y",
      "release/vX/vX.Y",
      "publish-gate/major"
    ],
    "protectedDevelopmentBranches": [
      "dev/vX/vX.Y"
    ],
    "releasePassport": {
      "entrypoint": "buildchain.release.json",
      "bundle": "buildchain-release-bundle.tar.gz",
      "contract": "kungfu-buildchain-release-passport",
      "schema": "schemas/release-passport-v1.schema.json",
      "checkManifest": "release-passport-check-manifest.json"
    },
    "releasePropagation": {
      "graphContract": "kungfu-buildchain-release-propagation-graph",
      "planContract": "kungfu-buildchain-release-propagation-plan",
      "lockContract": "kungfu-buildchain-release-propagation-lock",
      "workContract": "kungfu-buildchain-release-propagation-work",
      "stageReceiptContract": "kungfu-buildchain-release-propagation-stage-receipt",
      "workControlBindings": [
        "kungfu.assignment-graph.work-ref/v1",
        "kungfu.work-control.initiative-family-state/v2"
      ],
      "completionBoundary": "production-online-readback-plus-accepted-work-control-decision",
      "defaultChannelPolicy": "preserve",
      "defaultChannelMap": {
        "alpha": "alpha",
        "release": "release"
      }
    },
    "npm": {
      "package": "@kungfu-tech/buildchain",
      "command": "./bin/buildchain.mjs",
      "versionSource": "package.json#version",
      "alphaDistTag": "alpha",
      "stableDistTag": "latest"
    },
    "githubRelease": {
      "exactTagRelease": true,
      "authoritativeIntent": "Buildchain publication channel controls prerelease/latest metadata when available",
      "alphaChannel": "alpha publication sets prerelease=true and make_latest=false",
      "stableChannels": "release, stable, and major publication set prerelease=false and make_latest=true",
      "tagFallback": "ordinary callers without publication intent use semver prerelease syntax",
      "evidenceAssets": [
        "publish evidence JSON",
        "buildchain.release.json",
        "release passport assets",
        "GitHub artifact attestation Sigstore bundle and Buildchain evidence JSON"
      ],
      "owner": "promote-buildchain-ref"
    },
    "distributionIndexes": {
      "homebrewTap": {
        "projectType": "distribution-index",
        "manifest": "tap-manifest.json",
        "command": "buildchain homebrew check",
        "sourceOfTruth": "upstream release passport and sibling evidence"
      }
    }
  },
  "renderingBoundary": {
    "ownedByBuildchain": [
      "homepage title and text",
      "homepage section projection from README.md",
      "complete markdown page registry for Buildchain public docs, action manuals, Node API overview, and fixtures",
      "capability-grouped navigation registry for docs, CLI, Node API, workflows, actions, and KFD claims",
      "release model facts",
      "workflow and action registries",
      "controller evidence descriptors and input classification",
      "CLI command registry",
      "public surface reverse audit",
      "manual and Node API registries",
      "KFD claim registry",
      "KFD upstream aggregate registry",
      "release-passport evidence vocabulary",
      "publication archive registry and immutable papers surface facts"
    ],
    "ownedBySite": [
      "HTML structure",
      "CSS",
      "responsive layout",
      "navigation layout",
      "visual assets",
      "decorative images",
      "markdown-to-HTML renderer",
      "section presentation and progressive disclosure within Buildchain displayPlan constraints"
    ]
  }
}
