Vendored check

The vendor-* family

Eight dependency-free scripts every estate repository carries: check-charter, check-directory, check-frontdoor, vendor-shiplog, vendor-backlog, vendor-directory, vendor-checkpoint, vendor-check-activation. They run before an install, in repositories with no node_modules and sometimes no package.json.

source: flashyos/scripts + per-repository copies

copied byte-identical from canon; run with bare node

A vendored file fails by disagreeing, not by breaking: a stale copy silently disagrees about exactly the field somebody just changed at canon. estate-hygiene compares every copy byte-for-byte against canon and reports an incomparable copy as unknown rather than stale.

Every vendored checker is differentialled against its package, never eyeballed: both run over the same documents and any disagreement about the verdict fails — comparing constants is how eleven identical copies agreed with each other and disagreed with the spec in four places.

Edge cases — each one paid for once

Re-vendor before you trust a vendored change

Adding a feature to canon does nothing in the sixteen repositories that vendored an hour earlier — they mark the very field you just added with its old default, and nothing errors. This shipped a hold-flag that sixteen copies marked public.

Adoption gate: alone, in an empty directory, with bare node

adoptable.test.mjs copies each vendored script into an empty directory, runs it with no node_modules, and validates its output with the package’s own validator. It found two real defects in its first hour.

for d in */ does not match a dotfile

That glob has cost the estate a repository three times (.github). The byte-identity sweep now enumerates with readdir, and the third time a test caught it instead of a person.

← Full catalog · The doctrine behind the tools · Adopt one