# Supply chain and continuity

> What installing each burgee package puts on disk, how releases are published and signed, the licence, and what a fork inherits. Every statement links the check that holds it.

Source: https://burgee.interlace.tools/docs/supply-chain

This page states what the burgee family installs, how it is published, and what a team that
forks it keeps. Each statement links the check that holds it in CI. Where a check is missing,
the statement is not on this page.

## What an install brings in

Installing any burgee package installs that package and the burgee packages it depends on,
and nothing else. Each package below was installed alone into an empty directory, offline, from
the tarballs `npm pack` builds from this repository, and its tree listed with
`npm ls --all --parseable`.

{/* install-graph:start */}

| `npm install` | Packages installed | Which |
| :--- | ---: | :--- |
| `bellpull` | 1 | `bellpull` |
| `burgee` | 6 | `bellpull`, `burgee`, `closeout`, `linegauge`, `roundel`, `seniority` |
| `caique` | 5 | `caique`, `closeout`, `linegauge`, `paratext`, `roundel` |
| `closeout` | 1 | `closeout` |
| `controlroom` | 7 | `caique`, `closeout`, `controlroom`, `flagstaff`, `linegauge`, `paratext`, `roundel` |
| `flagstaff` | 5 | `closeout`, `flagstaff`, `linegauge`, `paratext`, `roundel` |
| `linegauge` | 1 | `linegauge` |
| `paratext` | 1 | `paratext` |
| `roundel` | 1 | `roundel` |
| `seniority` | 1 | `seniority` |

Generated by `npm run install-graph` from an offline install of each package alone, from the tarballs `npm pack` builds; do not edit by hand.

{/* install-graph:end */}

- **Every installed package is a burgee package.** The one exception the check allows is an
  optional peer a family package declares: `controlroom/ink` renders through the program's own
  `react` and `react-reconciler`, which npm does not install unless the program asks for them.
  Held by
  [`install-graph-lock`](https://github.com/ofri-peretz/burgee/blob/main/scripts/install-graph-lock.test.ts),
  which also requires the table above to equal a fresh measurement.
- **Nothing runs at install time.** No installed package declares a `preinstall`, `install` or
  `postinstall` script, or ships a `binding.gyp`, which npm would build without a script asking
  it to. Held by the same lock, reading the manifests as they land in `node_modules`.
- **Each package loads alone.** Every entry in each package's `exports` map is imported from
  that install, and no import reaches a package it does not declare. Held by
  [`independence-install-lock`](https://github.com/ofri-peretz/burgee/blob/main/scripts/independence-install-lock.test.ts).
- **The dependency counts in the READMEs match the manifests.** Held by
  [`dependency-claim-lock`](https://github.com/ofri-peretz/burgee/blob/main/scripts/dependency-claim-lock.test.ts).
  The direction of every edge is on [The family](/docs/concepts/family).

burgee parses argv with Node's own `util.parseArgs`, so the tokeniser a program depends on
ships with Node rather than with a package.

## How a release is published

- **Trusted publishing, with no npm token.** Every package is published from the
  [`release.yml`](https://github.com/ofri-peretz/burgee/blob/main/.github/workflows/release.yml)
  workflow through npm trusted publishing (OIDC). No workflow names an npm token, and the publish
  job reads no secret but `GITHUB_TOKEN`. Held by
  [`trusted-publishing-lock`](https://github.com/ofri-peretz/burgee/blob/main/scripts/trusted-publishing-lock.test.ts).
- **SLSA provenance on every version.** The publish runs with `--provenance`, held by the same
  lock. To verify a version yourself, run `npm view burgee dist.attestations` for the registry's
  attestation, or `npm audit signatures` in a project that installs it.
- **An SBOM on every GitHub Release.** The release workflow attaches a CycloneDX SBOM of what
  installing the package brings in, from the lockfile with development, optional and peer
  dependencies left out. Held by the same lock. Attaching it is a separate step after the
  publish: if it fails, the release workflow logs a warning and the npm publish stands.

## Security posture

- **Reporting.** [SECURITY.md](https://github.com/ofri-peretz/burgee/blob/main/SECURITY.md)
  says how to report a vulnerability privately and which versions are supported. Its supported
  versions are read against the manifests by
  [`stable-status-lock`](https://github.com/ofri-peretz/burgee/blob/main/scripts/stable-status-lock.test.ts).
- **OpenSSF Scorecard.** [Scorecard](https://scorecard.dev/viewer/?uri=github.com/ofri-peretz/burgee)
  runs weekly from
  [`scorecard.yml`](https://github.com/ofri-peretz/burgee/blob/main/.github/workflows/scorecard.yml).
  It scored this repository 7.1 of 10 on 2026-10-10; the badge on the README is the live
  figure. Four checks scored 0: Maintained, Code-Review and CII-Best-Practices, which
  SECURITY.md explains no file in the repository can close, and Contributors. Vulnerabilities
  scored 1 of 10. It reads the repository's lockfile, which holds the development tooling; the
  table above is what an adopter installs. The same question is now asked daily, and on every
  pull request that changes the lockfile or a manifest, by
  [`check:osv`](https://github.com/ofri-peretz/burgee/blob/main/scripts/osv-check.ts), which
  queries OSV for every locked package. One advisory with no fixed release, in a development
  tool, is waived until 2026-11-30, and
  [the decision](https://github.com/ofri-peretz/burgee/blob/main/.sdlc/decisions/D-20261011-osv-lockfile-zero.md)
  says why.

## Licence and continuity

- **MIT, every package.** The repository is under the
  [MIT licence](https://github.com/ofri-peretz/burgee/blob/main/LICENSE), and every installed
  package's manifest declares `MIT`, held by
  [`install-graph-lock`](https://github.com/ofri-peretz/burgee/blob/main/scripts/install-graph-lock.test.ts).
- **One repository.** All ten packages are built, tested and released from
  [one repository](https://github.com/ofri-peretz/burgee) through one release workflow, so a
  fork of that repository is a fork of the whole family.
- **A fork keeps its conformance tests.** Each incumbent's own test suite is vendored under
  [`packages/compat-oracle/vendor`](https://github.com/ofri-peretz/burgee/tree/main/packages/compat-oracle/vendor)
  and run in CI against the drop-in path by
  [`compat.yml`](https://github.com/ofri-peretz/burgee/blob/main/.github/workflows/compat.yml),
  which fails below the committed baseline. A fork inherits those suites and that gate, so a
  change that alters behaviour the incumbent's tests pin fails there, in the fork's own CI. The
  rates are on [Compatibility](/docs/compatibility).
