ECC/docs
Samarjeet Singh Tomar 754b8dd76c
fix: make the installer runtime pass strict supply-chain vetting (#2503)
* fix: make the installer runtime pass strict supply-chain vetting

Remediate the four enterprise supply-chain vetting blockers from
affaan-m/ECC#2502 so the installer runtime (package.json + manifests +
scripts/lib/**) passes strict exact-pin evidence policy:

1. Remove the package.json `postinstall` lifecycle script (it only echoed a
   post-install banner) and move that banner to an explicit opt-in
   `npm run welcome` command. No install-time lifecycle script remains.
2. Exact-pin every dependency in package.json (dependencies + devDependencies)
   to the versions already resolved in package-lock.json; no ^/~ ranges.
3. Replace non-ASCII characters on the installer runtime script/config surface:
   em-dashes (U+2014) in scripts/lib/{path-safety,install-executor,
   install/link-rewrite}.js comments and the two "Itô" (U+00F4) occurrences in
   manifests/{install-components,install-modules}.json descriptions become
   ASCII, so strict-surface Unicode scanners are clean.
4. Drop the bare `require("ajv")` from scripts/lib/install-state.js; the file
   already carries a complete hand-rolled validator enforcing the same
   schemas/install-state.schema.json (ecc.install.v1) constraints, so the
   installer closure is dependency-free (zero non-builtin bare requires).

Refs affaan-m/ECC#2502

* fix: avoid unpinned welcome invocations

Signed-off-by: Samar Tomar <samar_tomar@hotmail.com>

* fix: validate translated skill frontmatter

Signed-off-by: Samar Tomar <samar_tomar@hotmail.com>

* fix: repair skill frontmatter YAML

Signed-off-by: Samar Tomar <samar_tomar@hotmail.com>

* fix: add MIT license to core skill manifests; pin verification-loop tsc invocation

* fix: preserve tsc/pyright exit status in verification-loop type-check (set -o pipefail)

* chore(deps): sync lockfiles with exact-pinned package.json

Regenerate package-lock.json and yarn.lock so the pinned dependency
specs are reflected in both lockfiles. npm ci and Yarn's --immutable
install now pass the sync check. The resolution tree is unchanged
(231 yarn resolutions, byte-identical set; zero npm transitive drift);
only the root descriptor strings move from ranges to the versions
already resolved in the committed lockfiles.

Addresses the Codex P1 on #2503.

---------

Signed-off-by: Samar Tomar <samar_tomar@hotmail.com>
Co-authored-by: Samarjeet Singh Tomar <samartomar@gmail.com>
2026-07-17 17:13:49 -04:00
..
architecture docs: define ECC platform value loop (#2119) 2026-06-02 19:51:02 +08:00
business feat: add dynamic workflow team orchestration surface 2026-06-04 21:45:13 +08:00
de-DE fix: context-size /compact trigger, Codex marketplace plugin path, live README badges (#2237) 2026-06-11 16:21:53 -04:00
design feat: Plan Canvas, a browser review canvas for plans (#2467) 2026-07-08 17:12:48 -04:00
drafts docs: mirror agentshield fleet ticket evidence 2026-05-18 10:24:21 -04:00
es fix: resolve open-issue cluster (#2295, #2298, #2303–#2306, #2340) + createdTime fallback bug (#2408) 2026-07-03 21:10:45 -07:00
examples feat: add product capability planning lane 2026-04-05 16:58:02 -07:00
fixes fix: make plugin hooks run on Node 21+ and green the suite under modern Node (#2184) 2026-06-07 16:05:28 +08:00
ja-JP fix: make the installer runtime pass strict supply-chain vetting (#2503) 2026-07-17 17:13:49 -04:00
ko-KR fix: resolve open-issue cluster (#2295, #2298, #2303–#2306, #2340) + createdTime fallback bug (#2408) 2026-07-03 21:10:45 -07:00
pt-BR fix: resolve open-issue cluster (#2295, #2298, #2303–#2306, #2340) + createdTime fallback bug (#2408) 2026-07-03 21:10:45 -07:00
releases release: 2.0.0 — the agent harness operating system 2026-06-09 21:40:40 -04:00
ru fix: context-size /compact trigger, Codex marketplace plugin path, live README badges (#2237) 2026-06-11 16:21:53 -04:00
security docs: sync AgentShield adapter evidence 2026-05-19 20:54:15 -04:00
th fix(docs): sync marketplace add URL across translated READMEs (#2050) (#2068) 2026-06-07 13:26:58 +08:00
tr fix: make the installer runtime pass strict supply-chain vetting (#2503) 2026-07-17 17:13:49 -04:00
ur fix: context-size /compact trigger, Codex marketplace plugin path, live README badges (#2237) 2026-06-11 16:21:53 -04:00
vi-VN fix(docs): sync marketplace add URL across translated READMEs (#2050) (#2068) 2026-06-07 13:26:58 +08:00
zh-CN fix: make the installer runtime pass strict supply-chain vetting (#2503) 2026-07-17 17:13:49 -04:00
zh-TW fix: make the installer runtime pass strict supply-chain vetting (#2503) 2026-07-17 17:13:49 -04:00
ANTIGRAVITY-GUIDE.md docs: add Antigravity setup and usage guide (#552) 2026-03-20 00:21:37 -07:00
ARCHITECTURE-IMPROVEMENTS.md fix: route continuous learning observe hooks through node 2026-04-29 21:28:59 -04:00
ATLAS-CLOUD-GUIDE.md feat: add Atlas Cloud as LLM/AI provider (#2279) 2026-06-18 16:29:11 -04:00
capability-surface-selection.md docs: add capability surface selection guide 2026-04-06 14:21:28 -07:00
COMMAND-AGENT-MAP.md feat: Plan Canvas, a browser review canvas for plans (#2467) 2026-07-08 17:12:48 -04:00
COMMAND-REGISTRY.json feat: Plan Canvas, a browser review canvas for plans (#2467) 2026-07-08 17:12:48 -04:00
continuous-learning-v2-spec.md feat: deliver v1.8.0 harness reliability and parity updates 2026-03-04 14:48:06 -08:00
ECC-2.0-GA-ROADMAP.md docs: sync live native payments gate evidence 2026-05-19 23:25:38 -04:00
ECC-2.0-REFERENCE-ARCHITECTURE.md docs: add release plugin publication checklist 2026-05-18 08:56:17 -04:00
ECC-2.0-SESSION-ADAPTER-DISCOVERY.md feat: orchestration harness, selective install, observer improvements 2026-03-14 12:55:25 -07:00
ECC-PRO-SECURITY-ROADMAP.md docs: MRR-biased ECC Pro + AgentShield security roadmap (#2321) 2026-07-03 20:35:58 -07:00
HERMES-OPENCLAW-MIGRATION.md feat: add ecc2 legacy plugin migration import 2026-04-10 11:53:17 -07:00
HERMES-SETUP.md docs: close ecc2 rc1 release policy drift 2026-04-29 19:52:09 -04:00
hook-bug-workarounds.md docs: add canonical hook bug workaround guide 2026-04-06 14:12:21 -07:00
JOYCODE-GUIDE.md feat: add JoyCode install target 2026-05-11 11:10:59 -04:00
legacy-artifact-inventory.md Track legacy localization tail in readiness dashboard 2026-05-17 14:47:29 -04:00
MANUAL-ADAPTATION-GUIDE.md docs: add manual adaptation guide for non-native harnesses 2026-04-05 14:39:55 -07:00
MCP-CONNECTOR-POLICY.md feat(mcp): single-connector default set + connector policy (#2219) 2026-06-09 23:28:35 -04:00
MEGA-PLAN-REPO-PROMPTS-2026-03-12.md feat: orchestration harness, selective install, observer improvements 2026-03-14 12:55:25 -07:00
MIGRATION-1X-TO-2.0.md fix: community-reported issues — pyproject URLs, dashboard Tkinter error, 1.x→2.0 migration guide, cyber-safeguards docs (#2481) 2026-07-09 03:53:51 -04:00
PHASE1-ISSUE-BUNDLE-2026-03-12.md feat: orchestration harness, selective install, observer improvements 2026-03-14 12:55:25 -07:00
PLAN-PRD-PATTERN.md feat: add PRD planning command flow 2026-05-12 00:06:41 -04:00
PR-399-REVIEW-2026-03-12.md feat: orchestration harness, selective install, observer improvements 2026-03-14 12:55:25 -07:00
PR-QUEUE-TRIAGE-2026-03-13.md feat: orchestration harness, selective install, observer improvements 2026-03-14 12:55:25 -07:00
QWEN-GUIDE.md feat: add Qwen install target 2026-05-11 11:27:46 -04:00
SELECTIVE-INSTALL-ARCHITECTURE.md release: 2.0.0 — the agent harness operating system 2026-06-09 21:40:40 -04:00
SELECTIVE-INSTALL-DESIGN.md feat: orchestration harness, selective install, observer improvements 2026-03-14 12:55:25 -07:00
SESSION-ADAPTER-CONTRACT.md feat(session): add worker health alongside state in ecc.session.v1 (#751) 2026-03-22 15:39:51 -07:00
skill-adaptation-policy.md docs: add skill adaptation policy 2026-04-06 14:30:23 -07:00
SKILL-DEVELOPMENT-GUIDE.md refactor: move project guidelines example into docs 2026-04-05 15:03:59 -07:00
SKILL-PLACEMENT-POLICY.md feat: define skill placement and provenance policy (#748) 2026-03-22 15:39:48 -07:00
stale-pr-salvage-ledger.md docs: finish owner queue cleanup 2026-05-18 06:35:44 -04:00
token-optimization.md fix: add context monitor cost warning opt-out 2026-05-17 01:53:57 -04:00
TROUBLESHOOTING.md fix: community-reported issues — pyproject URLs, dashboard Tkinter error, 1.x→2.0 migration guide, cyber-safeguards docs (#2481) 2026-07-09 03:53:51 -04:00