[{"data":1,"prerenderedAt":397},["ShallowReactive",2],{"docs-navigation:en":3,"content-page:docs:jJ7M7PfH2CkUPhCNeMBhugs-gC5B1G3M-8lrEqtg1is":223,"content-page-surround:docs:jJ7M7PfH2CkUPhCNeMBhugs-gC5B1G3M-8lrEqtg1is":394},[4,25,83,141,168],{"title":5,"id":6,"canonicalKey":7,"locale":8,"draft":9,"icon":10,"path":11,"children":12},"Lupinum OSS handbook","content:docs:1.get-started:1.index.md","1","en",false,"lucide:book-open","\u002Fdocs\u002Fget-started",[13,19],{"title":14,"id":15,"canonicalKey":16,"locale":8,"draft":9,"icon":17,"path":18},"Choose a repository profile","content:docs:1.get-started:2.choose-a-profile.md","1\u002F2","lucide:git-branch","\u002Fdocs\u002Fget-started\u002Fchoose-a-profile",{"title":20,"id":21,"canonicalKey":22,"locale":8,"draft":9,"icon":23,"path":24},"New project path","content:docs:1.get-started:3.new-project-path.md","1\u002F3","lucide:route","\u002Fdocs\u002Fget-started\u002Fnew-project-path",{"title":26,"page":9,"canonicalKey":27,"locale":8,"children":28},"Standards","2",[29,35,41,47,53,59,65,71,77],{"title":30,"id":31,"canonicalKey":32,"locale":8,"draft":9,"icon":33,"path":34},"Repository structure","content:docs:2.standards:1.repository-structure.md","2\u002F1","lucide:folders","\u002Fdocs\u002Fstandards\u002Frepository-structure",{"title":36,"id":37,"canonicalKey":38,"locale":8,"draft":9,"icon":39,"path":40},"Documentation ownership","content:docs:2.standards:2.documentation-ownership.md","2\u002F2","lucide:files","\u002Fdocs\u002Fstandards\u002Fdocumentation-ownership",{"title":42,"id":43,"canonicalKey":44,"locale":8,"draft":9,"icon":45,"path":46},"GitHub and contributions","content:docs:2.standards:3.github-and-contributions.md","2\u002F3","lucide:github","\u002Fdocs\u002Fstandards\u002Fgithub-and-contributions",{"title":48,"id":49,"canonicalKey":50,"locale":8,"draft":9,"icon":51,"path":52},"Dependency policy","content:docs:2.standards:4.dependencies.md","2\u002F4","lucide:package-search","\u002Fdocs\u002Fstandards\u002Fdependencies",{"title":54,"id":55,"canonicalKey":56,"locale":8,"draft":9,"icon":57,"path":58},"Release security","content:docs:2.standards:5.release-security.md","2\u002F5","lucide:shield-check","\u002Fdocs\u002Fstandards\u002Frelease-security",{"title":60,"id":61,"canonicalKey":62,"locale":8,"draft":9,"icon":63,"path":64},"Package previews","content:docs:2.standards:6.package-previews.md","2\u002F6","lucide:package-open","\u002Fdocs\u002Fstandards\u002Fpackage-previews",{"title":66,"id":67,"canonicalKey":68,"locale":8,"draft":9,"icon":69,"path":70},"Documentation sites","content:docs:2.standards:7.documentation-sites.md","2\u002F7","lucide:panel-top","\u002Fdocs\u002Fstandards\u002Fdocumentation-sites",{"title":72,"id":73,"canonicalKey":74,"locale":8,"draft":9,"icon":75,"path":76},"Analytics and feedback","content:docs:2.standards:8.analytics-and-feedback.md","2\u002F8","lucide:chart-no-axes-combined","\u002Fdocs\u002Fstandards\u002Fanalytics-and-feedback",{"title":78,"id":79,"canonicalKey":80,"locale":8,"draft":9,"icon":81,"path":82},"Security and agents","content:docs:2.standards:9.security-and-agents.md","2\u002F9","lucide:bot-message-square","\u002Fdocs\u002Fstandards\u002Fsecurity-and-agents",{"title":84,"page":9,"canonicalKey":85,"locale":8,"children":86},"Procedures","3",[87,93,99,105,111,117,123,129,135],{"title":88,"id":89,"canonicalKey":90,"locale":8,"draft":9,"icon":91,"path":92},"Create a repository","content:docs:3.procedures:1.create-a-repository.md","3\u002F1","lucide:folder-plus","\u002Fdocs\u002Fprocedures\u002Fcreate-a-repository",{"title":94,"id":95,"canonicalKey":96,"locale":8,"draft":9,"icon":97,"path":98},"First npm release","content:docs:3.procedures:2.first-npm-release.md","3\u002F2","lucide:package-plus","\u002Fdocs\u002Fprocedures\u002Ffirst-npm-release",{"title":100,"id":101,"canonicalKey":102,"locale":8,"draft":9,"icon":103,"path":104},"Normal release","content:docs:3.procedures:3.normal-release.md","3\u002F3","lucide:package-check","\u002Fdocs\u002Fprocedures\u002Fnormal-release",{"title":106,"id":107,"canonicalKey":108,"locale":8,"draft":9,"icon":109,"path":110},"Prerelease","content:docs:3.procedures:4.prerelease.md","3\u002F4","lucide:flask-conical","\u002Fdocs\u002Fprocedures\u002Fprerelease",{"title":112,"id":113,"canonicalKey":114,"locale":8,"draft":9,"icon":115,"path":116},"Hotfix","content:docs:3.procedures:5.hotfix.md","3\u002F5","lucide:ambulance","\u002Fdocs\u002Fprocedures\u002Fhotfix",{"title":118,"id":119,"canonicalKey":120,"locale":8,"draft":9,"icon":121,"path":122},"Rollback","content:docs:3.procedures:6.rollback.md","3\u002F6","lucide:undo-2","\u002Fdocs\u002Fprocedures\u002Frollback",{"title":124,"id":125,"canonicalKey":126,"locale":8,"draft":9,"icon":127,"path":128},"Dependency update","content:docs:3.procedures:7.dependency-update.md","3\u002F7","lucide:refresh-cw","\u002Fdocs\u002Fprocedures\u002Fdependency-update",{"title":130,"id":131,"canonicalKey":132,"locale":8,"draft":9,"icon":133,"path":134},"Documentation change","content:docs:3.procedures:8.documentation-change.md","3\u002F8","lucide:file-pen-line","\u002Fdocs\u002Fprocedures\u002Fdocumentation-change",{"title":136,"id":137,"canonicalKey":138,"locale":8,"draft":9,"icon":139,"path":140},"Credential incident","content:docs:3.procedures:9.credential-incident.md","3\u002F9","lucide:key-round","\u002Fdocs\u002Fprocedures\u002Fcredential-incident",{"title":142,"page":9,"canonicalKey":143,"locale":8,"children":144},"Checklists","4",[145,151,156,162],{"title":146,"id":147,"canonicalKey":148,"locale":8,"draft":9,"icon":149,"path":150},"Repository launch checklist","content:docs:4.checklists:1.repository-launch.md","4\u002F1","lucide:list-checks","\u002Fdocs\u002Fchecklists\u002Frepository-launch",{"title":152,"id":153,"canonicalKey":154,"locale":8,"draft":9,"icon":97,"path":155},"First release checklist","content:docs:4.checklists:2.first-release.md","4\u002F2","\u002Fdocs\u002Fchecklists\u002Ffirst-release",{"title":157,"id":158,"canonicalKey":159,"locale":8,"draft":9,"icon":160,"path":161},"Production acceptance checklist","content:docs:4.checklists:3.production-acceptance.md","4\u002F3","lucide:monitor-check","\u002Fdocs\u002Fchecklists\u002Fproduction-acceptance",{"title":163,"id":164,"canonicalKey":165,"locale":8,"draft":9,"icon":166,"path":167},"Quarterly audit checklist","content:docs:4.checklists:4.quarterly-audit.md","4\u002F4","lucide:calendar-check","\u002Fdocs\u002Fchecklists\u002Fquarterly-audit",{"title":169,"id":170,"canonicalKey":171,"locale":8,"draft":9,"icon":172,"path":173,"children":174},"Troubleshooting","content:docs:5.troubleshooting:1.index.md","5","lucide:wrench","\u002Fdocs\u002Ftroubleshooting",[175,181,187,193,199,205,211,217],{"title":176,"id":177,"canonicalKey":178,"locale":8,"draft":9,"icon":179,"path":180},"npm trusted publishing","content:docs:5.troubleshooting:2.npm-trusted-publishing.md","5\u002F2","lucide:shield-alert","\u002Fdocs\u002Ftroubleshooting\u002Fnpm-trusted-publishing",{"title":182,"id":183,"canonicalKey":184,"locale":8,"draft":9,"icon":185,"path":186},"GitHub Actions","content:docs:5.troubleshooting:3.github-actions.md","5\u002F3","lucide:workflow","\u002Fdocs\u002Ftroubleshooting\u002Fgithub-actions",{"title":188,"id":189,"canonicalKey":190,"locale":8,"draft":9,"icon":191,"path":192},"GitHub Action SHA errors","content:docs:5.troubleshooting:4.action-sha-errors.md","5\u002F4","lucide:git-commit-horizontal","\u002Fdocs\u002Ftroubleshooting\u002Faction-sha-errors",{"title":194,"id":195,"canonicalKey":196,"locale":8,"draft":9,"icon":197,"path":198},"Dependency quarantine","content:docs:5.troubleshooting:5.dependency-quarantine.md","5\u002F5","lucide:timer","\u002Fdocs\u002Ftroubleshooting\u002Fdependency-quarantine",{"title":200,"id":201,"canonicalKey":202,"locale":8,"draft":9,"icon":203,"path":204},"Vercel deployment","content:docs:5.troubleshooting:6.vercel.md","5\u002F6","lucide:triangle","\u002Fdocs\u002Ftroubleshooting\u002Fvercel",{"title":206,"id":207,"canonicalKey":208,"locale":8,"draft":9,"icon":209,"path":210},"Plausible analytics","content:docs:5.troubleshooting:7.plausible.md","5\u002F7","lucide:chart-no-axes-column-increasing","\u002Fdocs\u002Ftroubleshooting\u002Fplausible",{"title":212,"id":213,"canonicalKey":214,"locale":8,"draft":9,"icon":215,"path":216},"Package preview failures","content:docs:5.troubleshooting:8.package-previews.md","5\u002F8","lucide:package-x","\u002Fdocs\u002Ftroubleshooting\u002Fpackage-previews",{"title":218,"id":219,"canonicalKey":220,"locale":8,"draft":9,"icon":221,"path":222},"GitHub CLI authentication","content:docs:5.troubleshooting:9.github-cli-authentication.md","5\u002F9","lucide:terminal","\u002Fdocs\u002Ftroubleshooting\u002Fgithub-cli-authentication",{"title":78,"description":224,"icon":81,"body":225,"type":381,"id":79,"canonicalKey":80,"draft":9,"partial":9,"locale":8,"collection":382,"navigationFile":9,"file":383,"route":389,"resolution":391},"Keep security reporting private and give coding agents durable operating limits.",{"type":226,"children":227,"toc":372},"root",[228,236,243,254,260,270,310,329,345,351,356,361,367],{"type":229,"tag":230,"props":231,"children":232},"element","p",{},[233],{"type":234,"value":235},"text","Security controls must remain understandable without a specific coding agent.\nThe repository is the operational record.",{"type":229,"tag":237,"props":238,"children":240},"h2",{"id":239},"report-vulnerabilities-privately",[241],{"type":234,"value":242},"Report vulnerabilities privately",{"type":229,"tag":230,"props":244,"children":245},{},[246,252],{"type":229,"tag":247,"props":248,"children":249},"code",{},[250],{"type":234,"value":251},"SECURITY.md",{"type":234,"value":253}," names the supported versions and the current private reporting\nmethod. Do not route vulnerabilities through a public issue. Give the reporter\nthe response expectations and the information needed for a useful report.",{"type":229,"tag":237,"props":255,"children":257},{"id":256},"give-agents-exact-local-instructions",[258],{"type":234,"value":259},"Give agents exact local instructions",{"type":229,"tag":230,"props":261,"children":262},{},[263,268],{"type":229,"tag":247,"props":264,"children":265},{},[266],{"type":234,"value":267},"AGENTS.md",{"type":234,"value":269}," records:",{"type":229,"tag":271,"props":272,"children":273},"ul",{},[274,280,285,290,295,300,305],{"type":229,"tag":275,"props":276,"children":277},"li",{},[278],{"type":234,"value":279},"source and package ownership,",{"type":229,"tag":275,"props":281,"children":282},{},[283],{"type":234,"value":284},"architectural boundaries,",{"type":229,"tag":275,"props":286,"children":287},{},[288],{"type":234,"value":289},"public contracts and invariants,",{"type":229,"tag":275,"props":291,"children":292},{},[293],{"type":234,"value":294},"exact verification commands,",{"type":229,"tag":275,"props":296,"children":297},{},[298],{"type":234,"value":299},"release restrictions,",{"type":229,"tag":275,"props":301,"children":302},{},[303],{"type":234,"value":304},"prohibited actions, and",{"type":229,"tag":275,"props":306,"children":307},{},[308],{"type":234,"value":309},"active migrations when applicable.",{"type":229,"tag":230,"props":311,"children":312},{},[313,315,320,322,327],{"type":234,"value":314},"Do not tell agents to use ",{"type":229,"tag":247,"props":316,"children":317},{},[318],{"type":234,"value":319},"codex\u002F*",{"type":234,"value":321},", ",{"type":229,"tag":247,"props":323,"children":324},{},[325],{"type":234,"value":326},"claude\u002F*",{"type":234,"value":328},", or another tool-specific branch\nname. Use the repository's normal branch and pull request policy.",{"type":229,"tag":230,"props":330,"children":331},{},[332,337,339,343],{"type":229,"tag":247,"props":333,"children":334},{},[335],{"type":234,"value":336},"CLAUDE.md",{"type":234,"value":338}," contains a short instruction to read ",{"type":229,"tag":247,"props":340,"children":341},{},[342],{"type":234,"value":267},{"type":234,"value":344},". It does not fork\nthe policy.",{"type":229,"tag":237,"props":346,"children":348},{"id":347},"keep-the-skill-thin",[349],{"type":234,"value":350},"Keep the skill thin",{"type":229,"tag":230,"props":352,"children":353},{},[354],{"type":234,"value":355},"The Lupinum OSS Codex skill reads this handbook and the target repository. It\ncan create, audit, and prepare work. It must not contain a second copy of the\nfleet policy.",{"type":229,"tag":230,"props":357,"children":358},{},[359],{"type":234,"value":360},"The skill must not silently publish a package, bypass quarantine, add a token,\nrename a trusted workflow, or claim that an external setting is correct without\nchecking it.",{"type":229,"tag":237,"props":362,"children":364},{"id":363},"preserve-evidence",[365],{"type":234,"value":366},"Preserve evidence",{"type":229,"tag":230,"props":368,"children":369},{},[370],{"type":234,"value":371},"Keep release manifests, hashes, CI links, and external-setting audit results in\ntheir defined locations. Do not put credentials, authentication URLs, or local\ntokens into logs or repository files.",{"title":373,"searchDepth":374,"depth":374,"links":375},"",4,[376,378,379,380],{"id":239,"depth":377,"text":242},2,{"id":256,"depth":377,"text":259},{"id":347,"depth":377,"text":350},{"id":363,"depth":377,"text":366},"markdown","docs",{"source":384,"path":385,"stem":386,"dir":387,"extension":388},"content","docs\u002F2.standards\u002F9.security-and-agents.md","docs\u002F2.standards\u002F9.security-and-agents","standards","md",{"requestedPath":82,"resolvedPath":82,"alternates":390},[],{"requested":392,"resolved":393,"usedFallback":9},{},{"locale":8},{"previous":395,"next":396},{"title":72,"id":73,"canonicalKey":74,"locale":8,"draft":9,"path":76},{"title":88,"id":89,"canonicalKey":90,"locale":8,"draft":9,"path":92},1786663362822]